Currency
This Privacy Policy explains how the merchant operating fostania.shop under the Fostania trade name collects, uses, discloses, retains, and protects personal information. It also explains choices and rights. The Privacy Officer may be contacted at info@fostania.shop. This policy is designed for a Shopify-powered U.S. online store and must be kept aligned with the store's actual apps, settings, and business practices.
This policy applies when an individual visits the website, creates an account, makes or attempts a purchase, joins a mailing list, submits a form or review, communicates with support, participates in a promotion, or otherwise interacts with the store. It does not govern a third party's independent website or service, even when linked from the store.
For personal information used to operate the store and customer relationship, the merchant is responsible for deciding why and how the information is handled. Shopify provides the commerce platform and may process information for the merchant or for Shopify's own stated purposes, depending on the feature. Payment providers, carriers, app providers, analytics vendors, advertising partners, and other suppliers have their own roles and legal duties.
The United States does not have one comprehensive federal privacy law governing every ordinary retailer. Depending on the merchant, customer, data, purpose, and statutory thresholds, processing may be governed by the Federal Trade Commission Act, Children's Online Privacy Protection Act, state comprehensive privacy laws, state data-breach laws, biometric or health privacy laws, and sector-specific rules.
Potentially applicable comprehensive laws include the California Consumer Privacy Act as amended by the CPRA, Colorado Privacy Act, Texas Data Privacy and Security Act, Oregon Consumer Privacy Act, and other state laws effective for the relevant period. The merchant must determine actual coverage and exemptions rather than presenting every state right as universally available.
Core practices include notice, purpose specification, data minimization, reasonable security, retention control, vendor oversight, honoring applicable rights, and avoiding materially misleading privacy statements. The categories, purposes, sources, recipients, retention periods, and opt-out methods in the live notice must match the store's actual Shopify configuration and installed apps.
The merchant is accountable for personal information under its control, including information transferred to a service provider for processing. The Privacy Officer coordinates questions, access or correction requests, complaints, incident response, retention practices, and review of service-provider arrangements. The public contact for the Privacy Officer is info@fostania.shop.
The merchant should maintain a privacy management program proportionate to the sensitivity and volume of information it handles. That program includes documented purposes, access controls, service-provider review, staff instructions, retention and destruction practices, incident response, complaint handling, and periodic checks that this published policy matches the technologies and actual practices in use.
We may collect identifiers and contact details such as name, billing and delivery address, email address, telephone number, account username, and communication preferences. We collect order information such as products viewed or purchased, quantities, price, discount, tax, delivery option, returns, support history, gift message, and transaction status.
When a customer contacts us, we collect the content of the message and attachments supplied, which may include photographs, video, model or serial numbers, proof of purchase, packaging, delivery labels, and information needed to diagnose or resolve an issue. A customer should avoid sending unnecessary sensitive information and should obscure unrelated payment or identity details.
Payments are generally processed by Shopify Payments or another payment provider selected at checkout. The store normally receives transaction status, amount, currency, payment method type, billing verification results, risk signals, and limited account details such as the last digits or token, but does not need to receive or store a complete card number or security code.
Payment providers collect and use information under their own terms and privacy notices, including for authorization, fraud prevention, chargebacks, regulatory checks, and settlement. If financing, instalments, digital wallets, or buy-now-pay-later services are offered, the provider may make an independent eligibility or credit decision. Customers should review the provider's notice before choosing that method.
When a person uses the site, servers and commerce tools may collect internet protocol address, browser type, device type, operating system, language, approximate location derived from network information, referring and exit pages, timestamps, session identifiers, pages viewed, searches, cart actions, checkout events, errors, and security or fraud signals.
This information helps deliver pages, remember preferences, secure accounts, keep carts functioning, measure performance, detect abuse, troubleshoot errors, understand navigation, and improve merchandising. We seek to avoid using precise location, sensitive inference, or persistent cross-site tracking unless the feature is disclosed, lawfully configured, and supported by appropriate consent or another legal basis.
The store may use cookies, pixels, local storage, tags, software development kits, and similar technologies for checkout, security, preferences, analytics, performance, fraud prevention, and advertising. Technologies must be classified accurately, and the merchant must identify which providers act as processors, service providers, contractors, third parties, or independent businesses under applicable law.
Where required, users receive notice and a choice before or when tracking occurs. Covered businesses must provide applicable opt-outs for sale, sharing, targeted advertising, or certain profiling and must recognize qualifying universal opt-out mechanisms, such as Global Privacy Control, where required by state law. Consent is obtained for sensitive data, secondary uses, minors' data, or other processing where an applicable law requires it.
We use personal information to present the store, create and maintain accounts, process payments, accept or decline orders, provide order confirmation, fulfil and deliver purchases, support returns and warranties, communicate about service issues, maintain transaction records, prevent fraud, protect customers and systems, comply with law, and establish or defend legal claims.
We also may use information to understand product demand, measure site performance, improve navigation, personalize content or recommendations, request feedback, administer promotions, and market products. Non-essential marketing, profiling, or advertising uses are subject to the consent and choice mechanisms required by applicable law. We do not condition a purchase on consent to unnecessary marketing.
We seek meaningful consent by explaining, in accessible language, what information is collected, the purposes, relevant third-party disclosures, and reasonably foreseeable consequences. Consent may be express or implied depending on sensitivity, reasonable expectations, and law. Express consent is generally used for sensitive information or an unexpected use that creates a meaningful residual risk of harm.
An individual may withdraw consent for an optional use, subject to legal or contractual restrictions and reasonable notice. Withdrawal does not invalidate earlier lawful processing and may affect a requested feature. Information necessary to complete an order, detect fraud, comply with tax or accounting duties, resolve a dispute, or protect security may still be used without optional marketing consent where law permits.
Order information is shared as reasonably necessary with warehouses, suppliers, carriers, payment providers, fraud-prevention tools, customer-service systems, and technology providers. Each receives only the categories appropriate to its role, such as a carrier receiving contact and address information needed for delivery or a warehouse receiving product and packing details.
Support records are used to authenticate the request, understand the history, document decisions, coordinate with providers, and improve service. Calls or chats are not recorded unless a notice is provided where required. Photographs or diagnostic evidence should be limited to the product and issue. We do not ask for passwords or full payment-card details through ordinary email.
The store is powered by Shopify. Shopify processes customer and merchant information to provide commerce infrastructure, checkout, hosting, security, fraud prevention, analytics, and other enabled services. In some contexts Shopify acts on the merchant's instructions, while in others it determines its own purposes under its privacy policy, for example certain Shop, Shop Pay, security, or network features.
Shopify may use vendors and infrastructure in multiple jurisdictions. Customers can review Shopify's consumer privacy notice and privacy controls for information about Shopify's own practices. Questions about this merchant's order, marketing choices, or use of data should be directed to the merchant first; questions about Shopify's independent processing may need to be directed to Shopify.
We may engage providers for hosting, commerce, payment, fraud screening, order management, warehousing, shipping, customer support, email, analytics, advertising, reviews, accounting, professional advice, security, and data storage. Providers are expected to use personal information only for authorized services or another lawful disclosed purpose and to protect it with measures appropriate to sensitivity.
Before enabling a provider, the merchant should assess what information the tool receives, where it is processed, its retention, permissions, contract, security, and privacy settings. Removing an app from Shopify does not necessarily erase information already held by the provider; offboarding should include revoking access and requesting return or deletion where appropriate.
If enabled, analytics providers may help measure visits, conversions, device patterns, and campaign performance. Advertising partners may use identifiers, cookie data, or event information to measure ads or show relevant content. Depending on applicable law, this activity may be treated as targeted advertising, sharing, profiling, or another regulated practice requiring notice, consent, or an opt-out.
The store should configure Shopify Customer Privacy settings, cookie controls, and advertising integrations for each market in which it operates. A user may change available choices through the cookie banner, privacy link, provider controls, or browser settings. Opting out of targeted advertising does not necessarily stop contextual advertising or essential measurement that law permits.
Commercial email is managed under the CAN-SPAM Act and applicable state law. Messages must use accurate sender and routing information, non-deceptive subject lines, clear advertising identification where required, a valid physical postal address, and a clear internet-based or reply-email opt-out mechanism. Opt-out requests must be honored within 10 business days, and the mechanism must remain available for at least 30 days after the message is sent.
Text messaging, automated calls, and similar campaigns may be subject to the Telephone Consumer Protection Act, state mini-TCPA laws, carrier rules, platform policies, and consent requirements. The merchant must verify the exact campaign and consent record before use. Marketing opt-out does not stop necessary order, security, recall, warranty, or customer-service communications.
We may disclose personal information when reasonably necessary to comply with applicable law, a court order, subpoena, warrant, regulatory requirement, tax or customs obligation, lawful request, product safety process, or to protect rights, safety, systems, customers, or the public. We assess requests and disclose only what we reasonably believe is required or permitted.
Information may also be disclosed in connection with a proposed or completed financing, merger, acquisition, reorganization, insolvency, sale of assets, or transfer of the store, subject to appropriate confidentiality and lawful-use conditions. If control changes, the successor must handle personal information consistently with applicable law and any commitments that continue to apply.
Shopify and other providers may process or store information outside the customer's state or outside the United States. While in another jurisdiction, information may be subject to that jurisdiction's laws and may be accessible to courts, law enforcement, national security, or regulatory authorities in accordance with those laws.
The merchant remains accountable for information transferred to a provider for processing to the extent required by applicable U.S. law. Reasonable steps may include contract terms, security review, access limits, incident duties, and transparency. A customer may ask the Privacy Officer for general information about relevant processing locations or provider categories.
We retain personal information only as long as reasonably necessary for identified purposes and legal obligations. Order, invoice, tax, accounting, warranty, fraud, and dispute records may be kept for several years and are generally retained for up to seven years after the relevant transaction or longer when a specific law, claim, investigation, or hold requires it. Marketing records are kept until consent is withdrawn or the purpose ends, with suppression records retained to honour an opt-out.
Support, website, analytics, and security records have shorter or role-specific schedules where practical. When information is no longer required, we delete, securely destroy, or anonymize it, subject to backup cycles and technical constraints. Anonymization is used only where the information is not reasonably expected to identify an individual under the applicable legal standard.
We use administrative, technical, and physical safeguards proportionate to sensitivity, amount, distribution, format, and risk. Measures may include role-based access, unique accounts, multifactor authentication, encryption in transit, platform security features, secure payment processing, logging, backups, provider controls, staff instructions, patching, and procedures for verifying sensitive requests.
No internet transmission or storage system is perfectly secure. Customers should use strong unique passwords, protect devices and email accounts, sign out of shared devices, and contact us if they suspect unauthorized account activity. We will never ask a customer to send a password or complete card security code by ordinary email.
We investigate suspected unauthorized access, acquisition, disclosure, alteration, loss, or destruction of personal information; contain the incident; preserve evidence where appropriate; assess affected systems and people; and take reasonable remedial action. Relevant providers, advisers, insurers, payment partners, law enforcement, and regulators may be involved where lawful and necessary.
All U.S. states, the District of Columbia, and U.S. territories may impose different breach definitions, notice triggers, recipients, content, timing, and regulator-reporting duties. The merchant must follow the law applicable to the affected residents and data rather than relying on one generic deadline. Contractual payment-card or platform incident duties may apply separately.
We seek to keep personal information as accurate, complete, and current as necessary for the purpose. Customers can update some account information directly and should promptly correct delivery or contact details. We may verify a material correction before applying it, particularly when the request affects account access, delivery, payment, fraud risk, or another person's information.
A correction request should identify the disputed information and the accurate replacement. If we do not agree that a record should be changed, we explain the reason where required and may note the disagreement. Historical transaction records may be preserved rather than overwritten when accuracy, tax, audit, or dispute rules require an audit trail.
Where an applicable state privacy law covers the merchant and request, a consumer may have rights to confirm processing, access, correct, delete, or obtain a portable copy of personal data and to opt out of sale, sharing, targeted advertising, or certain profiling. Some laws also provide rights concerning sensitive data, a list of third-party recipients, or an appeal from a denied request.
Requests may be submitted through the live site's privacy request method or to info@fostania.shop. We may verify a request proportionately and may accept an authorized agent where required. We do not discriminate unlawfully because a person exercises a privacy right. Response periods, extensions, authentication, exemptions, and appeal steps follow the law that actually applies.
If the merchant is a business subject to the CCPA, California consumers may have rights to know, access, correct, delete, and obtain information about collection, use, sale, sharing, and disclosure; to opt out of sale or sharing, including through a qualifying Global Privacy Control signal; to limit certain uses and disclosures of sensitive personal information; and to receive equal service and price except as lawfully permitted.
A covered business must provide required notices at or before collection, describe categories and retention criteria, maintain accurate request methods, and display any required 'Do Not Sell or Share My Personal Information' or 'Limit the Use of My Sensitive Personal Information' link or alternative mechanism. The live merchant must determine whether it sells or shares information as those terms are legally defined and must not use a generic statement that conflicts with actual advertising technology.
California's 2026 regulations add requirements concerning certain risk assessments, cybersecurity audits, and automated decisionmaking technology for covered activities and businesses on phased schedules. The merchant must assess applicability using its actual processing, revenue, scale, and technology before making a compliance claim.
The store is intended for adults and is not directed to children under 13. We do not knowingly collect personal information online from a child under 13 without verifiable parental consent where COPPA applies. The merchant must account for the FTC's amended COPPA Rule and its 2026 compliance requirements if the actual site, product, content, or knowledge makes the service child-directed or creates actual knowledge of child users.
State laws may provide additional protections for teens, including restrictions on sale, targeted advertising, or profiling. Age assurance must be proportionate and privacy-conscious. A parent, guardian, or young person who believes data was provided inappropriately may contact the Privacy Contact.
A privacy concern may be sent to the Privacy Contact at info@fostania.shop. Please describe the interaction, data, relevant dates, desired outcome, state of residence, and supporting material. We will investigate and explain the outcome or next step.
Depending on the issue and governing law, a person may contact the Federal Trade Commission, California Privacy Protection Agency, a state attorney general, or another competent regulator. Not every statute provides a private right of action, and this policy does not create one where the law does not.
We may update this policy to reflect legal, platform, provider, technology, or business changes. The current version is posted with an effective date. If a change is material to consent or creates a new use or disclosure outside reasonable expectations, we provide additional notice and seek new consent where required. Earlier versions should be retained internally so the store can demonstrate what notice applied at a relevant time.
Thanks for subscribing!
This email has been registered!