Privacy policy
At MerikaArt ("MerikaArt", "we", "us" or "our") we value the privacy of our visitors, users, customers. MerikaArt respects your privacy and is committed to protecting it through our compliance with this policy.
This Privacy Policy describes the types of information we collect from you or that you provide to us when you visit www.merikaart.com (our "website"), our practices for collecting, using, protecting and disclosing this information, and the choices you have in connection with this information.
General Information
What is Personal Information?
Personal Information is any information relating to personal or material circumstances that relates to an identified or identifiable individual. This includes, for example, your name, date of birth, e-mail address, postal address, or telephone number as well as online identifiers such as your IP address. In contrast, information of a general nature that cannot be used to determine your identity is not Personal Information. This includes, for example, the number of users of a website.
What is Special Category Data?
Special category data is Personal Information that needs more protection because it is sensitive. This includes Personal Information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data. As well as, data concerning health, a person’s sex life; and a person’s sexual orientation. In order to lawfully process Special Category Data, it is necessary to explicitly consent to the processing.
What is processing?
"Processing" means any operation or set of operations which is performed upon Personal Information, whether or not by automatic means. The term is broad and covers virtually any handling of data.
When do we process Personal Information?
We only process your Personal Information if we at least one of the following applies:
you have given your consent,
the information is necessary for the fulfillment of a contract / pre-contractual measures,
the information is necessary for the fulfillment of a legal obligation or
the information is necessary to protect our legitimate interests, provided that your interests are not overridden.
Data we collect automatically
Log data
Each time you visit our website, our system automatically records the following data from the visiting device and stores it in a so-called log file: i) Name of the retrieved file, ii) date and time of the visit, iii) amount of data transferred, iv) message about successful retrieval, type of browser and version used, v) IP address (identification of the user's device), vi) Operating system of the visiting device, vii) Internet service provider of the visiting device, viii) website from which you access our website, and ix) which of our website pages you are accessing.
Content Delivery Network
We use a Content Delivery Network (CDN) to distribute our online content. Our CDN is a network of regionally distributed servers of our technical service providers connected via the Internet. When our website is visited, your device`s browser transmits information to these service providers, which is collected in corresponding server log files. Server log files are generally anonymized and then transmitted without any personal reference. Server log files include, in particular, i) details of the browser and operating system used, ii) the previously visited pages (so-called referral URL), iii) the IP address of the device used, iv) the name of the Internet provider, as well as v) the date, time of all page views including the amount of data transmitted.
Cookies
We use so-called cookies on our website. Cookies are pieces of information that are transmitted from our web server or third-party web servers to your web browser and stored there for later retrieval. Cookies may be small files or other types of information storage. There are different types of cookies: i) Essential Cookies. Essential cookies are cookies to provide a correct and user-friendly website; and ii) Non-essential Cookies. Non-essential Cookies are any cookies that do not fall within the definition of essential cookies, such as cookies used to analyze your behavior on a website (“analytical” cookies) or cookies used to display advertisements to you (“advertising” cookies).
Shopify
Provision of the Shop
We use the store system Shopify of the service provider Shopify International Limited, for the purpose of hosting and displaying the shop. All data collected on our website is processed on Shopify's servers.
Shopify Statistics
We use the Shopify Statistics feature on our website. This allows us to measure the reach of our website and provides us with statistical analysis of visitor behavior on our website. The data is processed on servers of Shopify, which we have commissioned with the processing.
Shopify Analytics
We use Shopify Analytics, a web analytics service provided by Shopify, on our website. Shopify Analytics uses cookies, which are text files placed on your device, to help the website analyze how users use the site. The information generated by these cookies, such as the time, place, and frequency of your web site visit, including your IP address, is transmitted to Shopify and stored there. In this case, your IP address will already be shortened by Shopify and thus anonymized.
Shopify will use this information for the purpose of evaluating your use of our website, compiling reports on website activity for us and providing other services relating to website activity and internet usage. Shopify may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Shopify's behalf.
Google Analytics
We use Google Analytics based on our legitimate interest and your consent, a web analytics service provided by Google LLC, on our website. Google Analytics also uses cookies to enable our website to analyze how users use our website across multiple devices. The information generated by the cookies about your use of our website is transmitted to and stored by Google, including transmission to the United States. The following data is processed through the use of Google Analytics:
- 3 bytes of the IP address of the called system of the website visitor (anonymized IP address),
- the website called up,
- the website from which the user reached the accessed page of my website (referrer),
- the subpages accessed from the website,
- the time spent on the website, and
- the frequency with which the website is accessed.
Google states that it will not associate your IP address with any other data held by Google.
You can disable tracking by Google Analytics with future effect by downloading and installing the Google Analytics Opt-out Browser Add-on for your current web browser following this link http://tools.google.com/dlpage/gaoptout?hl=en.
Data we collect directly
Contacting us
In addition to your name, and e-mail address, IP address or telephone number, if provided, we usually collect the context of your message which may also include certain Personal Information. The Personal Information collected when contacting us is to handle your request and the legal basis is both your consent and Contract.
We are present on social media on the basis of our legitimate interest. If you contact or connect with us via social media platforms, we and the relevant social media platform are jointly responsible for the processing of your data and enter into a so-called joint controller agreement. The legal basis is our legitimate interest, your consent or, in some cases, the initiation of a contractual service, if any.
For the Chat, we use the Tidio Life Chat of the company Tidio LLC. Tidio Life Chat uses cookies to enable you to personalize your online experience. We have no knowledge of the storage period at Tidio LLC and no possibility to influence it.
Order processing
We process your first name, last name, e-mail address, shipping, and billing address, if different, and the data related to your contract with us data to handle the contractual relationship between you and us. It is also possible for you to register for an account. For this purpose, you can choose a password together with your e-mail address, both of which will enable you to log in more easily without having to enter your data again when you make a future purchase. We store the data you enter to set up a customer account through which your orders are recorded, executed, and processed. We will hold your data for further orders as long as you have your account with us. The legal basis for the data processing is our contract and the fulfillment of our legal obligations.
Payment Data
If you make a purchase your payment will be processed via our payment service provider Shopify (ShopPay) and its associated Payment Methods. Payment data will solely be processed through Shopify and we have no access to any Payment Data you may submit. The legal basis for the provision of a payment system is the establishment and implementation of the user contract for the use of the service.
Newsletter
If you have consented to receive our newsletter, we will use your e-mail address and, if applicable, your name to send you information about us, our books and publications, promotions, and news. You can revoke your consent to receive the newsletter or to the creation of personalized user profiles at any time with effect for the future. You will find the unsubscribe link at the end of each newsletter. The revocation leads to the deletion of the collected user data. Our newsletter is sent as part of processing on our behalf by Shopify to whom we pass on your e-mail address for this purpose.
Direct marketing
Insofar as you have also given us separate consent to process your data for marketing and advertising purposes, we are entitled to contact you for these purposes via the communication channels you have consented to.
Principles of processing Personal Information
Storage and Retention
At the time of data collection, for example in the context of a contractual relationship we process and store Personal Information from you. We process and store your Personal Information only to achieve the respective processing purpose or for as long as a legal retention period exists. Once the purpose has been achieved or the retention period has expired, the corresponding data is routinely deleted.
Security
Our website uses SSL or TLS encryption to ensure the security of data processing and to protect the transmission of confidential content, such as orders, login data or contact requests that you send to us. We have also implemented numerous security measures (“technical and organizational measures”) for example encryption or need to know access, to ensure the most complete protection of Personal Information processed through this website.
Nevertheless, internet-based data transmissions can always have security gaps, so that absolute protection cannot be guaranteed. And databases or data sets that include Personal Information may be breached inadvertently or through wrongful intrusion. Upon becoming aware of a data breach, we will notify all affected individuals whose Personal Information may have been compromised as expeditiously as possible after which the breach was discovered.
COPPA (Children Online Privacy Protection Act)
When it comes to the collection of Personal Information from children under the age of 13 years old, the Children’s Online Privacy Protection Act (COPPA) puts parents in control. The Federal Trade Commission, United States’ consumer protection agency, enforces the COPPA Rule, which spells out what operators of websites and online services must do to protect children’s privacy and safety online. We do not specifically market to children under the age of 13 years old.
CAN SPAM Act
The CAN-SPAM Act is a law that sets the rules for commercial email, establishes requirements for commercial messages, gives recipients the right to have emails stopped from being sent to them, and spells out tough penalties for violations. To be in accordance with CANSPAM, we agree to the following: If at any time you would like to unsubscribe from receiving future emails, you can email us and we will promptly remove you from ALL correspondence.
Controls For Do-Not-Track Features
Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track ('DNT') feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, our website does not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this policy.
Automated decision-making
Automated decision-making is the process of making a decision by automated means without any human involvement. Automated decision-making including profiling does not take place.
Do Not Sell
We do not sell your Personal Information.
Sharing and Disclosure
We will not disclose or otherwise distribute your Personal Information to third parties unless this is i) necessary for the performance of our services including our fulfillment partners and overseas shipping forwards and , ii) you have consented to the disclosure, iii) or if we are legally obliged to do so e.g., by court order or if this is necessary to support criminal or legal investigations or other legal investigations or other legal proceedings; or proceedings at home or abroad or to fulfill our legitimate interests.
International Transfer
We may transfer your Personal Information to other companies and/or staff members as necessary for the purposes described in this Privacy Policy. In order to provide adequate protection for your Personal Information when it is transferred, we have contractual arrangements regarding such transfers. We take all reasonable technical and organizational measures to protect the Personal Information we transfer.
Your Rights and Privileges
Privacy rights
- Right to Know
You can request information about how we have collected, used, shared, sold, disclosed and otherwise processed your Personal Information during the past 12 months, including the right to request the specific pieces of Personal Information that we possess.
- Right of Deletion
You can request that we delete any of the Personal Information that we have collected from you.
- Right of Non-Discrimination
You have the right to not receive discriminatory treatment by us for exercising any of your rights.
- Right to Opt-Out of Sale
We do not sell your Personal Information.
If you have any questions about the nature of the Personal Information we hold about you, or if you wish to exercise any of your rights, please contact us.
Updating your information
If you believe that the information, we hold about you is inaccurate or that we are no longer entitled to use it and want to request its rectification, deletion, or object to its processing, please do so in your account or by contacting us.
Withdrawing your consent
You can revoke consents you have given at any time by contacting us. The legality of the data processing carried out until the revocation remains unaffected by the revocation.
Access Request
In the event that you wish to make a Data Subject Access Request, you may inform us in writing of the same. We will respond to requests regarding access and correction as soon as reasonably possible. Should we not be able to respond to your request within thirty (30) days, we will tell you why and when we will be able to respond to your request. If we are unable to provide you with any Personal Information or to make a correction requested by you, we will tell you why.
Validity and questions
This Privacy Policy was last updated on Tuesday, April 18, 2023, and is the current and valid version. However, we want to point out that from time to time due to actual or legal changes a revision to this policy may be necessary. If you have any data protection questions, please feel free to contact us.