Privacy policy

This Privacy Policy describes how shop-raritangallery.com (the “Site” or “we”) collects, uses, and discloses your Personal Information when you visit or make a purchase from the Site.

Contact

After reviewing this policy, if you have additional questions, want more information about our privacy practices, or would like to make a complaint, please contact us by e-mail at shop.raritangallery@gmail.com or by mail using the details provided below:

888 Newark Ave, B35, Jersey City NJ 07306, United States

Collecting Personal Information

When you visit the Site, we collect certain information about your device, your interaction with the Site, and information necessary to process your purchases. We may also collect additional information if you contact us for customer support. In this Privacy Policy, we refer to any information about an identifiable individual (including the information below) as “Personal Information”. See the list below for more information about what Personal Information we collect and why.

  • Device information

    • Purpose of collection: to load the Site accurately for you, and to perform analytics on Site usage to optimize our Site.

    • Source of collection: Collected automatically when you access our Site using cookies, log files, web beacons, tags, or pixels

    • Disclosure for a business purpose: shared with our processor Squarespace

    • Personal Information collected: version of web browser, IP address, time zone, cookie information, what sites or products you view, search terms, and how you interact with the Site 

  • Order information

    • Purpose of collection: to provide products or services to you to fulfill our contract, to process your payment information, arrange for shipping, and provide you with invoices and/or order confirmations, communicate with you, screen our orders for potential risk or fraud, and when in line with the preferences you have shared with us, provide you with information or advertising relating to our products or services.

    • Source of collection: collected from you.

    • Disclosure for a business purpose: shared with our processor Squarespace or Klarna.

    • Personal Information collected: name, billing address, shipping address, payment information (including credit card numbers, Paypal, Shop Pay, Klarna), email address, and phone number.

  • Customer support information

    • Purpose of collection:

    • Source of collection:

    • Disclosure for a business purpose:

    • Purpose of collection: to provide customer support.

    • Source of collection: collected from you

 

Sharing Personal Information

We share your Personal Information with service providers to help us provide our services and fulfill our contracts with you, as described above. For example:

  • We use Squarespace to power our online store. You can read more about how Squarespace uses your Personal Information here: https://www.squarespace.com/privacy

  • We may share your Personal Information to comply with applicable laws and regulations, to respond to a subpoena, search warrant or other lawful request for information we receive, or to otherwise protect our rights.

Behavioral Advertising

As described above, we use your Personal Information to provide you with targeted advertisements or marketing communications we believe may be of interest to you. For example:

You can opt out of targeted advertising by:

  1. FACEBOOK - https://www.facebook.com/settings/?tab=ads

  2. GOOGLE - https://www.google.com/settings/ads/anonymous

Additionally, you can opt out of some of these services by visiting the Digital Advertising Alliance’s opt-out portal at: https://optout.aboutads.info/.

Using Personal Information

We use your personal Information to provide our services to you, which includes: offering products for sale, processing payments, shipping and fulfillment of your order, and keeping you up to date on new products, services, and offers.

Lawful basis

Pursuant to the General Data Protection Regulation (“GDPR”), if you are a resident of the European Economic Area (“EEA”), we process your personal information under the following lawful bases:

  • Your consent;

  • The performance of the contract between you and the Site;

  • Compliance with our legal obligations;

  • To protect your vital interests;

  • For our legitimate interests, which do not override your fundamental rights and freedoms.

RETENTION

When you place an order through the Site, we will retain your Personal Information for our records unless and until you ask us to erase this information. For more information on your right of erasure, please see the ‘Your rights’ section below.

AUTOMATIC DECISION-MAKING

If you are a resident of the EEA, you have the right to object to processing based solely on automated decision-making (which includes profiling), when that decision-making has a legal effect on you or otherwise significantly affects you.

We DO NOT engage in fully automated decision-making that has a legal or otherwise significant effect using customer data.

Our processor Squarespace uses limited automated decision-making to prevent fraud that does not have a legal or otherwise significant effect on you.

Services that include elements of automated decision-making include:

  • Temporary blacklist of IP addresses associated with repeated failed transactions. This blacklist persists for a small number of hours.

  • Temporary blacklist of credit cards associated with blacklisted IP addresses. This blacklist persists for a small number of days.

Selling Personal Information

Our Site sells Personal Information, as defined by the California Consumer Privacy Act of 2018 (“CCPA”).

  • categories of information sold;

  • IF USING SQUARESPACE AUDIENCES: information about your use of the Site, your purchases, and the email address associated with your purchase

  • instructions on how to opt-out of sale;

  • whether your business sells information of minors (under 16) and whether you obtain affirmative authorization;

  • if you provide a financial incentive to sell information, provide information about what that incentive is.]

 

Your rights

GDPR

If you are a resident of the EEA, you have the right to access the Personal Information we hold about you, to port it to a new service, and to ask that your Personal Information be corrected, updated, or erased. If you would like to exercise these rights, please contact us through the contact information above. [OR INSERT ALTERNATIVE INSTRUCTIONS FOR SENDING ACCESS, ERASURE, CORRECTION, AND PORTABILITY REQUESTS]

Your Personal Information will be initially processed in Ireland and then will be transferred outside of Europe for storage and further processing, including to Canada and the United States. For more information on how data transfers comply with the GDPR, see Squarespace’s GDPR White-paper: https://support.squarespace.com/hc/en-us/articles/360036134672-Data-privacy-and-Squarespace

CCPA

If you are a resident of California, you have the right to access the Personal Information we hold about you (also known as the ‘Right to Know’), to port it to a new service, and to ask that your Personal Information be corrected, updated, or erased. If you would like to exercise these rights, please contact us through the contact information above. 

If you would like to designate an authorized agent to submit these requests on your behalf, please contact us at the address above.

Cookies

A cookie is a small amount of information that’s downloaded to your computer or device when you visit our Site. We use a number of different cookies, including functional, performance, advertising, and social media or content cookies. Cookies make your browsing experience better by allowing the website to remember your actions and preferences (such as login and region selection). This means you don’t have to re-enter this information each time you return to the site or browse from one page to another. Cookies also provide information on how people use the website, for instance whether it’s their first time visiting or if they are a frequent visitor.

We use the following cookies to optimize your experience on our Site and to provide our services.

 https://support.squarespace.com/hc/en-us/articles/360001264507-The-cookies-Squarespace-uses

Functional and required cookies

Squarespace uses some necessary cookies so visitors can navigate and use key features on your site. These cookies vary from site to site depending on the features it uses. For example, functional and required cookies help these features work:

Name

Purpose, type, and duration

_acloggedin

  • Supports login by Acuity Scheduling client if the client has an account

  • Cookie

  • January 1, 2025

_client_acloggedin

  • Supports login by Acuity Scheduling client if the client has an account

  • Cookie

  • January 1, 2025

_dd_cookie_test

  • Tests if cookies are supported

  • Cookie

  • Expires instantly

_dd_s

  • Tracks browser errors

  • Cookie

  • Four hours

_dd_site_test

  • Tests if cookies are supported

  • Cookie

  • Expires instantly

_grecaptcha

  • Helps reduce spam in Acuity Scheduling

  • Local storage

  • No expiry

CART

  • Shows when a visitor adds a product to their cart

  • Cookie

  • Two weeks

CHECKOUT_WEBSITE

client_username

  • Remembers a logged in Acuity Scheduling client's username between visits

  • Cookie

  • One year

clientUser

  • Stores the Acuity Scheduling client's username, OAuth2 Access Token, and OAuth2 Refresh Token. This cookie is required for functionality of logged-in clients

  • Cookie

  • 30 days

Commerce-checkout-state

  • Stores state of checkout while the visitor is completing their order in PayPal

  • sessionstorage

  • Session

Crumb

hasCart

  • Tells Squarespace that the visitor has a cart

  • Cookie

  • Two weeks

Locked

  • Prevents the password-protected screen from displaying if a visitor enters the correct site-wide password.

  • Cookie

  • Session

orderStatusSessionToken

  • Authenticates a visitor who logs into an order status page.

  • Cookie

  • One year

PHPSESSID

  • Securely authenticates a visitor during their checkout in Acuity Scheduling

  • Cookie

  • One month

RecentRedirect

  • Prevents redirect loops if a site has custom URL redirects. Redirect loops are bad for SEO.

  • Cookie

  • 30 minutes

remember_client

  • Remembers Acuity Scheduling client’s login details if they have an account

  • Cookie

  • 365 days

siteUserCrumb

SiteUserInfo

SiteUserSecureAuthToken

  • Authenticates a visitor who logs into a customer account

  • Cookie

  • Three years

squarespace-announcement-bar

  • Prevents the announcement bar from displaying if a visitor dismisses it

  • localstorage

  • Persistent

squarespace-likes

  • Shows when you've already "liked" a blog post

  • localstorage

  • Persistent

squarespace-popup-overlay

  • Prevents the promotional pop-up from displaying if a visitor dismisses it

  • localstorage

  • Persistent

squarespace-video-player-options

ss_cookieAllowed

  • Remembers if a visitor agreed to placing analytics cookies on their browser if a site is restricting the placement of cookies

  • Cookie

  • 30 days

ss_sd

Test

  • Investigates if the browser supports cookies and prevents errors

  • Cookie

  • Session

TZ

  • Enables a Acuity Scheduling client’s appointments to display correctly based on their time zone preferences.

  • localstorage

  • Persistent

Cross-site request forgery (CSRF)

CSRF is an attack vector that tricks a browser into taking unwanted action in an application when someone’s logged in.

Analytics and performance cookies

We use analytics and performance cookies to collect information on your behalf about how visitors interact with your site. Storing these cookies is how we populate the data you find in Squarespace analytics, such as traffic sources, unique visitors, and cart abandonment.

You can disable Squarespace analytics and performance cookies at any time.

Cookie Name

Duration

Purpose

ss_cid

Two years

Identifies unique visitors and tracks a visitor’s sessions on a site

ss_cpvisit

Two years

Identifies unique visitors and tracks a visitor’s sessions on a site

ss_cvisit

30 minutes

Identifies unique visitors and tracks a visitor’s sessions on a site

ss_cvr

Two years

Identifies unique visitors and tracks a visitor’s sessions on a site

ss_cvt

30 minutes

Identifies unique visitors and tracks a visitor’s sessions on a site

DO NOT TRACK

Please note that because there is no consistent industry understanding of how to respond to “Do Not Track” signals, we do not alter our data collection and usage practices when we detect such a signal from your browser.

Changes

We may update this Privacy Policy from time to time in order to reflect, for example, changes to our practices or for other operational, legal, or regulatory reasons.

Complaints

As noted above, if you would like to make a complaint, please contact us by e-mail or by mail using the details provided under “Contact” above.

If you are not satisfied with our response to your complaint, you have the right to lodge your complaint with the relevant data protection authority. You can contact your local data protection authority, or our supervisory authority here: @shop.raritangalery@gmail.com

Last updated: 2/4/2024