Privacy policy

Handle & Mould Living ("we", "us", "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose and protect your personal information when you visit or make a purchase from handlemouldliving.com (the “Site”). By using the Site or purchasing from us, you accept the practices described in this policy.

1. Information we collect

We collect information in three ways:

  • Information you provide directly: name, billing & shipping address, email, phone number, order details, support messages, returns requests, and any other information you submit.
  • Automatically-collected information: device and browser data (IP address, user agent, screen size), cookies and similar technologies, pages visited, search terms, referral/advertising data, and interaction data.
  • Information from third parties: payment processors, analytics providers, advertising platforms, and shipping partners (e.g., Shopify, PayPal, Google, Meta, TikTok).

2. How we use your information

We use personal information for the following purposes:

  • To process and fulfill orders, including payments and shipping.
  • To communicate order status, customer service responses, and important account notifications.
  • To operate, maintain and improve the Site, product offerings and customer experience.
  • To detect and prevent fraud, abuse or illegal activity and to protect the rights, property or safety of our business or others.
  • To deliver marketing, promotional messages and retargeting ads (where you have consented or where permitted by law).
  • To comply with legal obligations and to respond to lawful requests by public authorities.

3. Legal bases for processing (EEA / GDPR)

If you are located in the European Economic Area (EEA), we process personal data under one or more of these legal bases:

  • Performance of a contract: to fulfill your orders and related services;
  • Legal obligation: to comply with applicable law;
  • Legitimate interests: for fraud prevention, Site operation, analytics and to improve our services (provided these interests are not overridden by your rights);
  • Consent: for marketing communications and certain cookie-based tracking, where required by law.

4. Cookies & tracking technologies

We and our partners use cookies, pixels and similar technologies to operate the Site, understand usage and deliver relevant advertising.

Typical cookies we use include:

Cookie Type Purpose
Essential Enable core site functionality (cart, checkout, account login).
Performance & analytics Measure traffic and improve Site performance (e.g., Google Analytics).
Advertising Deliver personalized ads and measure ad performance (e.g., Meta, Google, TikTok).
Functional Remember preferences such as language or region.

You can control cookies via your browser settings. Disabling cookies may affect Site functionality and the shopping experience.

5. Third-party services and sharing

We share information with third parties strictly as needed to provide the Service, including:

  • Shopify: our e-commerce platform and data host. See Shopify’s privacy documentation for additional details.
  • Payment processors: Shopify Payments, PayPal, Stripe, etc., to process transactions (we do not store full card numbers).
  • Shipping & fulfillment partners: to deliver orders.
  • Analytics & advertising partners: Google, Meta (Facebook/Instagram), TikTok and other ad platforms to measure and personalize advertising.
  • Service providers: email platforms, CRM providers, support tools and fraud detection services.

We require our service providers to process personal data only on our instructions and to maintain appropriate security measures.

6. International transfers

Our operations and service providers may be located in countries outside your own, including the United States, Canada and Hong Kong. Personal data may therefore be transferred internationally.

We take commercially reasonable steps to protect personal data during transfer, including using standard contractual clauses or other lawful transfer mechanisms where required by applicable law.

7. Retention

We retain personal data for as long as necessary to provide our services, comply with legal obligations, resolve disputes, and enforce agreements. Typical retention periods:

  • Order records and transactional data: minimum 2 years or as required by law.
  • Marketing data: until you opt out or unsubscribe.
  • Analytics data: typically aggregated or retained for up to 26 months (subject to provider retention settings).

8. Your rights

Depending on where you live, you may have the right to:

  • Request access to the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of personal data (the “right to be forgotten”), subject to legal exceptions.
  • Obtain a copy of your personal data in a portable format.
  • Object to or restrict certain processing activities (e.g., direct marketing).
  • Withdraw consent where processing is based on consent.

To exercise any rights, contact us at support@handlemouldliving.com. We may require identity verification before fulfilling requests. We respond to requests in accordance with applicable laws.

9. GDPR-specific information

If you are in the EEA: you have the right to lodge a complaint with a supervisory authority in your country. We will process your personal data following the lawful bases described above. For data transfers from the EEA to countries without an adequacy decision, we rely on appropriate safeguards such as Standard Contractual Clauses.

10. CCPA / California residents

If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA), including the right to request disclosure of categories of personal data collected, purposes for collection, categories of third parties with whom we share your data, and the right to opt out of the sale or sharing of personal information for targeted advertising. To make a California privacy request, contact support@handlemouldliving.com. We will verify and respond in accordance with the CCPA and related regulations.

11. Security

We use reasonable administrative, technical and physical safeguards to protect personal data. These include SSL/TLS encryption for the Site and industry-standard controls provided by Shopify and other service providers. No system is completely secure; absolute security cannot be guaranteed.

12. Children

The Site is not intended for individuals under 18. We do not knowingly collect personal information from children under 18. If you believe we have inadvertently collected information from a child, contact us and we will take steps to delete the data.

13. Automated decision-making & profiling

We may use automated tools for fraud prevention, risk assessment and advertising. Where such automated processing produces legal or similarly significant effects for individuals in the EEA, you have the right to request human review and to challenge decisions—contact us to discuss.

14. Marketing & opt-out

If you have opted in to marketing, we may send promotional emails about new products, offers or updates. You can unsubscribe from marketing emails at any time by clicking the “unsubscribe” link in any email or by contacting support@handlemouldliving.com.

15. Links to other websites

Our Site contains links to third-party websites. We are not responsible for the privacy practices or content of those sites. Please review the privacy policies of any third-party sites you visit.

16. Changes to this Policy

We may update this Privacy Policy from time to time. The “Effective date” at the top will reflect the most recent version. Material changes will be posted on the Site and—where appropriate—communicated to customers.

17. Contact us

If you have questions, wish to exercise your rights, or want to report a privacy concern, contact us:

Handle & Mould Living
Email: support@handlemouldliving.com

Note: This Privacy Policy is provided for informational purposes and should be adjusted to match your actual data practices and legal requirements. If you process sensitive personal data or operate in regulated industries, we recommend consulting a qualified data protection attorney to ensure full compliance with GDPR, CCPA and other applicable laws.