Privacy policy
Last updated: 1 May 2026
This Privacy Policy explains how Prints by Rebekah (“we”, “us”, “our”) collects, uses, and protects your personal data when you visit or make a purchase from https://printsbyrebekah.com (the “Site”).
This Privacy Policy applies to all users globally, including customers located in the European Union, the United Kingdom, and the United States. Where local laws provide additional rights, those rights will apply in addition to the rights described in this Policy.
We are committed to protecting your privacy and complying with the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, and other applicable privacy laws including relevant US state privacy laws (such as California’s CCPA/CPRA where applicable).
1. Who We Are
Data controller:
Prints by Rebekah Location: Portugal (serving customers in the EU, UK, and US) Contact: info@printsbyrebekah.com
If you have any questions about this Privacy Policy or your personal data, you can contact us at the email above.
2. Personal Data We Collect
2.1 Information you provide directly
- Name
- Billing and shipping address
- Email address
- Phone number (if provided)
- Payment details (processed securely by third-party providers; we do not store full card details)
- Order history
- Customer support messages
2.2 Information collected automatically
- IP address
- Browser and device information
- Time zone
- Pages viewed and browsing behaviour
- Referring URLs
- Cookies and similar technologies
3. Legal Basis for Processing (GDPR & UK GDPR)
We process personal data under the following legal bases:
- Contractual necessity: to process and fulfil orders
- Legal obligation: tax, accounting, and regulatory compliance
- Legitimate interests: fraud prevention, analytics, and site improvement
- Consent: marketing communications and non-essential cookies
Where consent is used, you may withdraw it at any time.
4. How We Use Your Data
We use your personal data to:
- Process and fulfil orders
- Communicate with you about purchases
- Provide customer support
- Process payments and prevent fraud
- Improve website performance and user experience
- Comply with legal obligations
- Send marketing emails (only if you opt in)
5. Sharing Your Personal Data
We only share data when necessary to operate our business:
Service providers
- Shopify (ecommerce platform)
- Payment processors (e.g. Stripe, PayPal)
- Shipping and fulfilment partners
- Email and marketing platforms (if used)
- Analytics and advertising platforms (if used)
These providers only process data as required to deliver their services.
Legal requirements
We may disclose data if required by law or to protect our legal rights.
6. International Data Transfers
Your personal data may be transferred and processed outside the UK, EU, or EEA, including in the United States.
Where this occurs, we use appropriate safeguards such as:
- Standard Contractual Clauses (SCCs)
- Data protection agreements with providers
7. Data Retention
We retain personal data only as long as necessary:
- Order and transaction data: up to 7 years (legal/tax obligations)
- Customer support data: up to 2 years
- Marketing data: until you withdraw consent or unsubscribe
- Analytics data: typically 12–24 months (often anonymised)
After this period, data is securely deleted or anonymised.
8. Cookies and Tracking Technologies
We use cookies to:
- Enable site functionality
- Remember preferences
- Analyse website traffic
- Support marketing and advertising (where consented)
Non-essential cookies are only used with your consent.
You can manage or withdraw cookie consent at any time via browser settings or our cookie banner.
9. Your Privacy Rights
Depending on your location, you may have the following rights:
EU/EEA (GDPR)
- Right to access your data
- Right to rectification
- Right to erasure
- Right to restrict processing
- Right to data portability
- Right to object
- Right to withdraw consent
United Kingdom (UK GDPR)
You have the same rights as under GDPR. You may also lodge a complaint with the Information Commissioner’s Office (ICO).
United States (including California where applicable)
You may have additional rights, including:
- Right to know what personal data is collected
- Right to request deletion of personal data
- Right to opt out of certain data sharing or “sale” (if applicable)
- Right not to be discriminated against for exercising privacy rights
10. Marketing Communications
We only send marketing emails if you have explicitly opted in.
You may unsubscribe at any time using the link in our emails or by contacting us directly.
11. Data Security
We use appropriate technical and organisational measures to protect your data against unauthorised access, loss, misuse, or disclosure.
However, no method of transmission over the internet is completely secure.
12. Third-Party Links
Our Site may contain links to third-party websites. We are not responsible for their privacy practices.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Updates will be posted on this page with a revised “Last updated” date.
14. Complaints
If you are in the EU/EEA, you may lodge a complaint with your local data protection authority (in Portugal: CNPD).
If you are in the United Kingdom, you may contact the ICO.
If you are in the United States, you may have rights under applicable state privacy laws and may contact your state regulator where applicable.
15. Contact Us
If you have any questions about this Privacy Policy or your personal data, please contact:
Email: info@printsbyrebekah.com