Privacy Policy and GDPR Rights

Please read this Privacy Policy carefully before using this website.

Privacy Policy Consent

The website and its content is owned by By the Rock and Weed (“Company”, “I”, or “me”). The term “you” refers to the user or viewer of bytherockandweed.com (“Website”).

This Privacy Policy describes how I collect, use, process and distribute your information, including Personal Data (as defined below) used to access this Website. I will not use or share your information with anyone except as described in this Privacy Policy. The use of information collected through my Website shall be limited to the purposes under this Privacy Policy and my Terms of Use for customers.

Please read this Privacy Policy carefully. I reserve the right to change this Privacy Policy on the Website at any time without notice.

Use of any personal information or contribution that you provide to me, or which is collected by me on or through my Website or its content is governed by this Privacy Policy. By using my Website or its content, you consent to this Privacy Policy, whether or not you have read it.

Information I May Collect

I rely on a number of legal bases to collect, use, and share your information, including:

  • as needed to sell my products and answer any messages

  • if necessary to comply with state and federal laws

  • tax reporting purposes 

Analytics

This website collects personal data to power my site analytics, including:

  • Information about your browser, network, and device

  • Web pages you visited prior to coming to this website

  • Your IP address

This information may also include details about your use of this website, including:

  • Clicks

  • Internal links

  • Pages visited

  • Scrolling

  • Searches

  • Timestamps

I share this information with Squarespace, my website analytics provider, to learn about site traffic and activity.

Cookies

This website uses cookies and similar technologies, which are small files or pieces of text that download to a device when a visitor accesses a website or app. For information about viewing the cookies dropped on your device, visit About the cookies Squarespace uses.

Customer Accounts

If you create a customer account on this website, I collect personal information to improve my checkout experience and customer service.

This information may include your:

  • Billing and shipping address(es)

  • Details about your orders (for example, your shirt size)

  • Email address

  • Name

  • Phone number

I share this information with Squarespace, my website hosting provider, so they can provide website services to me.

Emails

Abandoned Cart Emails

You’ll receive an automated email within 24 hours after you abandon your shopping cart, if all of the following occur:

1. You enter your email address at checkout, or are logged into your Customer Account.

2. You add a product which is in stock to your shopping cart.

3. You close your browser or leave this website without completing your purchase.

You can unsubscribe from these messages at the bottom of the email.

The email will link back to this website, where you can pick up where you left off and complete your purchase.

Marketing Emails

I may send you marketing emails, which you can unsubscribe from by clicking the link at the bottom of the email. I share your contact information with Squarespace, my email marketing provider, so they can send these emails on my behalf.

Order and Account Emails

I may email you with messages about your order or account activity. For example, I may email you to tell you that:

  • You’ve created a Customer Account

  • Your Customer Account password has been reset or updated

  • You’ve made a purchase

  • Your order has shipped

It’s not possible to unsubscribe from these messages.

I share your contact information with Squarespace, my website hosting provider, so they can send these emails to you on my behalf.

Fonts

This website uses font files from Google Fonts and Adobe Fonts. To properly display this site to you, servers where the font files are stored may receive personal information about you, including:

  • Information about your browser, network, or device

  • Your IP address

Visitor Data

For Customers

When you buy something on this website, I collect personal information from you to fulfill the order. I may collect information like your:

  • Billing and shipping address

  • Details relating to your purchase (for example, your shirt size or a custom engraving)

  • Email address

  • Name

  • Phone number

I share this information with Squarespace, my online store hosting provider, so that they can provide website services to me.

As you go through checkout, this site may auto-complete your shipping and billing address by sharing what you type with the Google Places API and returning suggestions to you to improve your checkout experience.

For Website Visitors

This website is hosted by Squarespace. Squarespace collects personal data when you visit this website, including:

  • Information about your browser, network and device

  • Web pages you visited prior to coming to this website

  • Your IP address

Squarespace needs the data to run this website, and to protect and improve its platform and services. Squarespace analyzes the data in a de-personalized form.

Please note that the information above (“Personal Data”) that you are giving to me is voluntarily, and by you providing this information to me you are giving consent for me to use, collect and process this Personal Data. You are welcome to opt-out or request for me to delete your Personal Data at any point by contacting me at bytherockandweed@gmail.com.

If you choose not to provide me with certain Personal Data, you may not be able to participate in certain aspects of my Website or content.

Other Information I May Collect:

Anonymous Data Collection and Use

To maintain my Website’s high quality, I may use your IP address to help diagnose problems with my server and to administer the Website by identifying which areas of the Website are most heavily used, and to display content according to your preferences. Your IP address is the number assigned to computers connected to the Internet. This is essentially "traffic data" which cannot personally identify you, but is helpful to me for marketing purposes and for improving my services. Traffic data collection does not follow a user’s activities on any other websites in any way. Anonymous traffic data may also be shared with business partners and advertisers on an aggregate basis.

Why I Need Your Information and How I Use It

I rely on a number of legal bases to collect, use, and share your information, including:

  • as needed to provide my services, such as when I use your information to fulfill your order, to settle disputes, or to provide customer support;

  • when you have provided your affirmative consent, which you may revoke at any time, such as by signing up for my mailing list;

  • if necessary to comply with a legal obligation or court order or in connection with a legal claim, such as retaining information about your purchases if required by tax law; and

  • as necessary for the purpose of my legitimate interests, if those legitimate interests are not overridden by your rights or interests, such as 1) providing and improving my services. I use your information to provide the services you requested and in my legitimate interest to improve my services; and 2) Compliance with the Etsy Seller Policy and Terms of Use. I use your information as necessary to comply with my obligations under the Etsy Seller Policy and Terms of Use.

What I Do With Information I Collect

Contact You

I may contact you with information that you provide to me based on these lawful grounds for processing:

  • Consent - I may contact you if you give me your clear, unambiguous, affirmative consent to contact you.

  • Contract - I will contact you under my contractual obligation to deliver goods or services you purchase from me.

  • Legitimate Interest - I may contact you if I feel you have a legitimate interest in hearing from me. For example, if you sign up for a newsletter, I may send you marketing emails based on the content of that newsletter. You will always have the option to opt out of any of my emails.

Process Payments

I will use the Personal Data you give to me in order to process your payment for the purchase of goods or services under a contract. I only use third party payment processors that take the utmost care in securing data and comply with the GDPR.

Share with Third Parties

Information about my customers is important to my business. I share your personal information for very limited reasons and in limited circumstances, as follows:

  • Service providers - I engage certain trusted third parties to perform functions and provide services to my shop, such as delivery companies and payment processors. I will share your personal information with these third parties, but only to the extent necessary to perform these services.

  • Compliance with laws - I may collect, use, retain, and share your information if I have a good faith belief that it is reasonably necessary to: (a) respond to legal process or to government requests; (b) enforce my agreements, terms and policies; (c) prevent, investigate, and address fraud and other illegal activity, security, or technical issues; or (d) protect the rights, property, and safety of my customers, or others.

Viewing by Others

Note that whenever you voluntarily make your Personal Data available for viewing by others online through this Website or its content, it may be seen, collected and used by others, and therefore, I cannot be responsible for any unauthorized or improper use of the information that you voluntarily share (i.e., sharing a comment on Instagram, posting on a Facebook page that I manage, leaving a product review, etc.).

Submission, Storage, Sharing and Transferring of Personal Data

Personal Data that you provide to me is stored internally or through a data management system. Your Personal Data will only be accessed by those who help to obtain, manage or store that information, or who have a legitimate need to know such Personal Data (i.e., my hosting provider, newsletter provider, or payment processors).

It is important to note that I may transfer data internationally. For users in the European Union, please be aware that I transfer Personal Data outside of the European Union. By using my Website and providing me with your Personal Data, you consent to these transfers in accordance with this Privacy Policy.

Data Retention

I retain your Personal Data for the minimum amount of time necessary to provide you with the information and / or services that you requested from me. I may include certain Personal Data for longer periods of time if necessary for legal, contractual and accounting obligations.

Confidentiality

I aim to keep the Personal Data that you share with me confidential. Please note that I may disclose such information if required to do so by law or in the good-faith belief that: (1) such action is necessary to protect and defend my rights or property or those of my users or licensees, (2) to act as immediately necessary in order to protect the personal safety or rights of my users or the public, or (3) to investigate or respond to any real or perceived violation of this Privacy Policy or of my Disclaimer, Terms and Conditions, or any other terms of use or agreement with me.

Passwords

To use certain features of the Website or its content, you may need a username and password. You are responsible for maintaining the confidentiality of the username and password, and you are responsible for all activities, whether by you or by others, that occur under your username or password and within your account. I cannot and will not be liable for any loss or damage arising from your failure to protect your username, password or account information. If you share your username or password with others, they may be able to obtain access to your Personal Data at your own risk.

How You Can Access, Update or Delete Your Personal Data

Your Rights

If you reside in certain territories, including the EU, you have a number of rights in relation to your personal information. While some of these rights apply generally, certain rights apply only in certain limited cases. I describe these rights below:

  • Access - You may have the right to access and receive a copy of the personal information I hold about you by contacting me using the contact information below.

  • Change, restrict, delete - You may also have rights to change, restrict my use of, or delete your personal information. Absent exceptional circumstances (like where I am required to store data for legal reasons) I will generally delete your personal information upon request.

  • Object - You can object to (i) my processing of some of your information based on my legitimate interests and (ii) receiving marketing messages from me after providing your express consent to receive them. In such cases, I will delete your personal information unless I have compelling and legitimate grounds to continue using that information or if it is needed for legal reasons.

  • Complain - If you reside in the EU and wish to raise a concern about my use of your information (and without prejudice to any other rights you may have), you have the right to do so with your local data protection authority.

Unsubscribe

You may unsubscribe from my e-newsletters or updates at any time through the unsubscribe link at the footer of all email communications. If you have questions or are experiencing problems unsubscribing, please contact me at bytherockandweed@gmail.com.

Security

I take commercially reasonable steps to protect the Personal Data you provide to me from misuse, disclosure or unauthorized access. I only share your Personal Data with trusted third parties who use the same level of care in processing your Personal Data. That being said, I cannot guarantee that your Personal Data will always be secure due to technology or security breaches. Should there be a data breach of which I am aware, I will inform you immediately.

Anti-Spam Policy

I have a no spam policy and provide you with the ability to opt-out of my communications by selecting the unsubscribe link at the footer of all e-mails. I will not sell, rent or share your email address.

Third Party Websites

I may link to other websites on my Website. I have no responsibility or liability for the content and activities of any other individual, company or entity whose website or materials may be linked to my Website or its content, and thus I cannot be held liable for the privacy of the information on their website or that you voluntarily share with their website. Please review their privacy policies for guidelines as to how they respectively store, use and protect the privacy of your Personal Data.

Notification of Changes

I may use your Personal Data, such as your contact information, to inform you of changes to the Website or its content, or, if requested, to send you additional information about By the Rock and Weed. I reserve the right, at my sole discretion, to change, modify or otherwise alter my Website, its content and this Privacy Policy at any time. Such changes and/or modifications shall become effective immediately upon posting my updated Privacy Policy. Please review this Privacy Policy periodically. Continued use of any of information obtained through or on the Website or its content following the posting of changes and/or modifications constituted acceptance of the revised Privacy Policy. Should there be a material change to my Privacy Policy, I will contact you via email or by a prominent note on my Website.

Data Controller and Processors

For purposes of EU data protection law, I, Allison Hetzell, am the data controller as I am collecting and using your Personal Data. I use trusted third parties as my data processors for technical and organizational purposes, including for payments and email marketing. I use reasonable efforts to make sure my data processors are GDPR-compliant.

Contact

If you have any questions about this Privacy Policy, please contact me at: bytherockandweed@gmail.com.