Our website address is https://ganchillo.co.nz.
Section 1 – Personal data we collect and why we collect it
When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.
If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.
When you purchase something from our store, as part of the buying and selling process, we collect the personal information you give us such as your name, address and email address.
When you browse our store, we also automatically receive your computer’s internet protocol (IP) address in order to provide us with information that helps us learn about your browser and operating system.
Email marketing: With your permission, we may send you emails about our store, new products, promotions and other updates.
What are Cookies
This site requires small data files called cookies and are sometimes placed on your devices. This is a general practice across websites.
Cookies are text files that are being downloaded and saved to your devices whenever you browse a website. This process enables your devices to remember your recent website activities such as logging into your accounts including remembering your website settings. This helps browsers tailor the data that you see on your devices.
Cookies are used to provide the content, product or any service that you have requested. Essential cookies help devices download the needed information enabling you to navigate around websites and enjoy the provided features. Without cookies, there will be issues around the information a user has requested from the website being accessed. An example of this is when you sign up to an account and a cookie is not enabled, you will have to re-login again every time you navigate to the next page.
Additional scenarios are listed below,
- Remembering the preference or settings that you have set during your browser activities like advertising preference or marketing preference.
- Any surveys you already have filled in will be asked again without cookie files
- Remembering if you have visited the website before
- Showing you only information that has relevance to the contents, products, or services that you have requested and received
- Cookies will also give you access to social media platforms that we use subsequently
- Showing only related articles relevant to the information you are looking at
For us to start capturing cookies, the following will be a deemed consent.
- Continuously accessing and navigating through our website, ignoring our banner alert about cookies
- Clicking “Accept” in the banner asking you to accept our cookie terms
- Closing the banner by clicking the “X” button
Embedded content from other websites
Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.
We will also use your information for research purposes to understand the behavioural patterns of customers to be able to improve our services. Should you not want your information to be included in this area please let us know and we will remove your data from our list.
Who we share your data with
We will never share or sell your personal information to anyone unless mandated by law. We will only use your personal information such as Credit card details to process your payments for the product/s you are buying. Just like any other online stores, your payment details will be captured by Paypal and/or Stripe (depending on your chosen gateway). This will facilitate the processing of your order. Payments made through Paypal and Stipe are safe and secured. Refer to our Payment Methods guideline for more information.
Refer to Stripe Security Policy for more information on how your data will be secured.
Refer to Paypal Security Policy for more information on how your data will be secured.
If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue.
For users that register on our website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.
What rights you have over your data
If you have an account on this site or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.
Where we send your data
Visitor comments may be checked through an automated spam detection service.
Your contact information
How do you get my consent?
When you provide us with personal information to complete a transaction, verify your credit card, place an order, arrange for a delivery or return a purchase, we imply that you consent to our collecting it and using it for that specific reason only.
If we ask for your personal information for a secondary reason, like marketing, we will either ask you directly for your expressed consent or provide you with an opportunity to say no.
How do I withdraw my consent?
If after you opt-in, you change your mind, you may withdraw your consent for us to contact you, for the continued collection, use or disclosure of your information, at any time, by contacting us at our Contact Us page.
How we protect your data
To protect your personal information, we take reasonable precautions and follow industry best practices to make sure it is not inappropriately lost, misused, accessed, disclosed, altered or destroyed.
If you provide us with your credit card information, the information is encrypted using secure socket layer technology (SSL) and stored with a AES-256 encryption. Although no method of transmission over the Internet or electronic storage is 100% secure, we follow all PCI-DSS requirements and implement additional generally accepted industry standards.
What data breach procedures we have in place
If you think that your personal data is breached, please contact us immediately and we will regenerate your password so you can make sure that it is only you who can access your account with us. We will also notify Paypal and Stripe to decline any payments made from your account if we have a substantial proof that your account has been breached and that you never shared your details to anyone.
For any credit card information breach, please contact your credit card provider so they can implement the appropriate measure.
What third parties we receive data from
In general, the third-party providers used by us will only collect, use and disclose your information to the extent necessary to allow them to perform the services they provide to us.
However, certain third-party service providers, such as payment gateways and other payment transaction processors, have their own privacy policies with respect to the information we are required to provide to them for your purchase-related transactions.
For these providers, we recommend that you read their privacy policies so you can understand the manner in which your personal information will be handled by these providers.
In particular, remember that certain providers may be located in or have facilities that are located in a different jurisdiction than either you or us. So if you elect to proceed with a transaction that involves the services of a third-party service provider, then your information may become subject to the laws of the jurisdiction(s) in which that service provider or its facilities are located.
What automated decision making and/or profiling we do with user data
By using this site, you represent that you are at least the age of majority in your state or province of residence and you have given us your consent to allow any of your minor dependants to use this site.
Industry regulatory disclosure requirements
We may disclose your personal information if we are required by law to do so or if you violate our Terms of Service.
All direct payment gateways adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, MasterCard, American Express and Discover.
PCI-DSS requirements help ensure the secure handling of credit card information by our store and its service providers.
If our store is acquired or merged with another company, your information may be transferred to the new owners so that we may continue to sell products to you.
Questions and contact information
If you would like to: access, correct, amend or delete any personal information we have about you, register a complaint, or simply want more information contact our Privacy Compliance Officer at our Contact Us page. Please make sure to indicate “Attention to Compliance Officer” in your message so we know we need to direct your concern to the proper business unit.