Privacy & Cookie Policy

This Privacy Policy describes how ghostlygoods.co.uk (the “Site” or “we”) collects, uses, and discloses your Personal Information when you visit or make a purchase from the Site.

Collecting Personal Information

When you visit the Site, we collect certain information about your device, your interaction with the Site, and information necessary to process your purchases. We may also collect additional information if you contact us for customer support. In this Privacy Policy, we refer to any information about an identifiable individual (including the information below) as “Personal Information”. See the list below for more information about what Personal Information we collect and why.

  • Device information
    • Purpose of collection: to load the Site accurately for you, and to perform analytics on Site usage to optimize our Site.
    • Source of collection: Collected automatically when you access our Site using cookies, log files, web beacons, tags, or pixels.
    • Disclosure for a business purpose: shared with our processor Shopify and Google Analytics.
    • Personal Information collected: version of web browser, IP address, time zone, cookie information, what sites or products you view, search terms, and how you interact with the Site.
  • Order information
    • Purpose of collection: to provide products or services to you to fulfill our contract, to process your payment information, arrange for shipping, and provide you with invoices and/or order confirmations, communicate with you, screen our orders for potential risk or fraud, and when in line with the preferences you have shared with us, provide you with information or advertising relating to our products or services.
    • Source of collection: collected from you.
    • Disclosure for a business purpose: shared with our processor Shopify. We will also share your name, address, email and phone number with a delivery service.
    • Personal Information collected: name, billing address, shipping address, payment information (including credit card numbers), email address, and phone number.

 

Sharing Personal Information

We share your Personal Information with service providers to help us provide our services and fulfill our contracts with you, as described above. For example:

  • We use Shopify to power our online store. You can read more about how Shopify uses your Personal Information here: https://www.shopify.com/legal/privacy.
  • We may share your Personal Information to comply with applicable laws and regulations, to respond to a subpoena, search warrant or other lawful request for information we receive, or to otherwise protect our rights.

Behavioural Advertising

As described above, we use your Personal Information to provide you with targeted advertisements or marketing communications we believe may be of interest to you. For example:

For more information about how targeted advertising works, you can visit the Network Advertising Initiative’s (“NAI”) educational page at https://www.networkadvertising.org/understanding-online-advertising/how-does-it-work.

You can opt out of targeted advertising by:

  • FACEBOOK - https://www.facebook.com/settings/?tab=ads
  • GOOGLE - https://www.google.com/settings/ads/anonymous
  • Additionally, you can opt out of some of these services by visiting the Digital Advertising Alliance’s opt-out portal at: https://optout.aboutads.info/.

    Using Personal Information

    We use your personal Information to provide our services to you, which includes: offering products for sale, processing payments, shipping and fulfilment of your order, and keeping you up to date on new products, services, and offers.

    Lawful basis

    Pursuant to the General Data Protection Regulation (“GDPR”), if you are a resident of the European Economic Area (“EEA”), we process your personal information under the following lawful bases:

    • Your consent;
    • The performance of the contract between you and the Site;
    • Compliance with our legal obligations;
    • To protect your vital interests;
    • For our legitimate interests, which do not override your fundamental rights and freedoms.

    Retention

    When you place an order through the Site, we will retain your Personal Information for our records unless and until you ask us to erase this information. For more information on your right of erasure, please see the ‘Your rights’ section below.

    Automatic decision-making

    If you are a resident of the EEA, you have the right to object to processing based solely on automated decision-making (which includes profiling), when that decision-making has a legal effect on you or otherwise significantly affects you.

    We DO NOT engage in fully automated decision-making that has a legal or otherwise significant effect using customer data.

    Our processor Shopify uses limited automated decision-making to prevent fraud that does not have a legal or otherwise significant effect on you.

    Services that include elements of automated decision-making include:

    • Temporary blacklist of IP addresses associated with repeated failed transactions. This blacklist persists for a small number of hours.
    • Temporary blacklist of credit cards associated with blacklisted IP addresses. This blacklist persists for a small number of days.

    Your rights

    GDPR

    If you are a resident of the EEA, you have the right to access the Personal Information we hold about you, to port it to a new service, and to ask that your Personal Information be corrected, updated, or erased. If you would like to exercise these rights, please initiate a data subject request via the form.

    Your Personal Information will be initially processed in Ireland and then will be transferred outside of Europe for storage and further processing, including to Canada and the United States. For more information on how data transfers comply with the GDPR, see Shopify’s GDPR Whitepaper: https://help.shopify.com/en/manual/your-account/privacy/GDPR.

     

    Cookies

    A cookie is a small amount of information that’s downloaded to your computer or device when you visit our Site. We use a number of different cookies, including functional, performance, advertising, and social media or content cookies. Cookies make your browsing experience better by allowing the website to remember your actions and preferences (such as login and region selection). This means you don’t have to re-enter this information each time you return to the site or browse from one page to another. Cookies also provide information on how people use the website, for instance whether it’s their first time visiting or if they are a frequent visitor.

    We use the following cookies to optimize your experience on our Site and to provide our services.

    Cookies Necessary for the Functioning of the Store

    Name Function Duration
    _ab Used in connection with access to admin. 2y
    _secure_session_id Used in connection with navigation through a storefront. 24h
    _shopify_country Used in connection with checkout. session
    _shopify_m Used for managing customer privacy settings. 1y
    _shopify_tm Used for managing customer privacy settings. 30min
    _shopify_tw Used for managing customer privacy settings. 2w
    _storefront_u Used to facilitate updating customer account information. 1min
    _tracking_consent Tracking preferences. 1y
    c Used in connection with checkout. 1y
    cart Used in connection with shopping cart. 2w
    cart_currency Used in connection with shopping cart. 2w
    cart_sig Used in connection with checkout. 2w
    cart_ts Used in connection with checkout. 2w
    cart_ver Used in connection with shopping cart. 2w
    checkout Used in connection with checkout. 4w
    checkout_token Used in connection with checkout. 1y
    dynamic_checkout_shown_on_cart Used in connection with checkout. 30min
    hide_shopify_pay_for_checkout Used in connection with checkout. session
    keep_alive Used in connection with buyer localization. 2w
    master_device_id Used in connection with merchant login. 2y
    previous_step Used in connection with checkout. 1y
    remember_me Used in connection with checkout. 1y
    secure_customer_sig Used in connection with customer login. 20y
    shopify_pay Used in connection with checkout. 1y
    shopify_pay_redirect Used in connection with checkout. 30 minutes, 3w or 1y depending on value
    storefront_digest Used in connection with customer login. 2y
    tracked_start_checkout Used in connection with checkout. 1y
    checkout_one_experiment Used in connection with checkout. session

    Reporting and Analytics

    Name Function Duration
    _landing_page Track landing pages. 2w
    _orig_referrer Track landing pages. 2w
    _s Shopify analytics. 30min
    _shopify_d Shopify analytics. session
    _shopify_s Shopify analytics. 30min
    _shopify_sa_p Shopify analytics relating to marketing & referrals. 30min
    _shopify_sa_t Shopify analytics relating to marketing & referrals. 30min
    _shopify_y Shopify analytics. 1y
    _y Shopify analytics. 1y
    _shopify_evids Shopify analytics. session
    _shopify_ga Shopify and Google Analytics. session

     

    We use CookiePro to scan our website, please see below the full cookie overview (Monstermart was our old domain name before Ghostly Goods):

    Cookie Name Hostname Default Category Default Description
    l7_az paypal.com Strictly Necessary Cookies  
    OptanonAlertBoxClosed www.themonstermart.co.uk Strictly Necessary Cookies  
    _secure_session_id www.ghostlygoods.co.uk Strictly Necessary Cookies This cookie is generally provided by Shopify and is used in connection with navigation through a storefront.
    OptanonConsent www.themonstermart.co.uk Strictly Necessary Cookies  
    x-csrf-jwt paypal.com Strictly Necessary Cookies This cookie is generally provided by PayPal and supports payment services within the website.
    tsrce paypal.com Strictly Necessary Cookies This cookie is generally provided by PayPal and supports payment services in the website.
    enforce_policy paypal.com Strictly Necessary Cookies  
    eupubconsent ghostlygoods.co.uk Strictly Necessary Cookies This cookie is used by the IAB Europe Transparency & Consent Framework to store the user's consent to the data collection Purposes. The cookie holds an encrypted consent string that vendors participating in the framework can read and determine the user's consent. 
    OptanonConsent ghostlygoods.co.uk Strictly Necessary Cookies This cookie is set by the cookie compliance solution from OneTrust. It stores information about the categories of cookies the site uses and whether visitors have given or withdrawn consent for the use of each category. This enables site owners to prevent cookies in each category from being set in the users browser, when consent is not given. The cookie has a normal lifespan of one year, so that returning visitors to the site will have their preferences remembered. It contains no information that can identify the site visitor.
    eupubconsent www.themonstermart.co.uk Strictly Necessary Cookies  
    x-pp-s paypal.com Strictly Necessary Cookies This cookie is generally provided by PayPal and supports payment services in the website.
    ts paypal.com Strictly Necessary Cookies This cookie is generally provided by PayPal and supports payment services in the website.
    __cfduid cookiepro.com Strictly Necessary Cookies  
    OptanonAlertBoxClosed ghostlygoods.co.uk Strictly Necessary Cookies This cookie is set by websites using certain versions of the cookie law compliance solution from OneTrust.  It is set after visitors have seen a cookie information notice and in some cases only when they actively close the notice down.  It enables the website not to show the message more than once to a user.  The cookie has a one year lifespan and contains no personal information.
    ts_c paypal.com Strictly Necessary Cookies  
    crumb ghostlygoods.co.uk Strictly Necessary Cookies This cookie is associated with SquareSpace.  It is used to ensure a visitor's browsing security. by preventing cross-site request forgery (CSRF).  
    _orig_referrer ghostlygoods.co.uk Strictly Necessary Cookies This cookie is generally provided by Shopify and is used in connection with a shopping part.
    nsid www.paypal.com Strictly Necessary Cookies  
    cookietest www.ghostlygoods.co.uk Strictly Necessary Cookies Common cookie name could have a number of different origins.  Where this is first party and a session cookie, its most likely to do with checking to see if the browser is set to block or allow cookies.Common cookie name could have a number of different origins.  Where this is first party and a session cookie, its most likely to do with checking to see if the browser is set to block or allow cookies.
    LANG paypal.com Strictly Necessary Cookies  
    secure_customer_sig www.ghostlygoods.co.uk Strictly Necessary Cookies This cookie is generally provided by Shopify and is used in connection with a customer login.
    _shopify_tw ghostlygoods.co.uk Functional Cookies  
    keep_alive www.ghostlygoods.co.uk Functional Cookies  
    cookietest cdn.shopify.com Functional Cookies Common cookie name could have a number of different origins.  Where this is first party and a session cookie, its most likely to do with checking to see if the browser is set to block or allow cookies.Common cookie name could have a number of different origins.  Where this is first party and a session cookie, its most likely to do with checking to see if the browser is set to block or allow cookies.
    localization www.ghostlygoods.co.uk Functional Cookies These cookies are set on pages with the Flickr widget.
    cart_currency www.ghostlygoods.co.uk Functional Cookies  
    shopify_pay_redirect www.ghostlygoods.co.uk Functional Cookies  
    _shopify_m ghostlygoods.co.uk Functional Cookies  
    dynamic_checkout_shown_on_cart www.ghostlygoods.co.uk Functional Cookies  
    _shopify_tm ghostlygoods.co.uk Functional Cookies  
    _tracking_consent ghostlygoods.co.uk Functional Cookies  
    shopify_pay_redirect cdn.shopify.com Functional Cookies  
    _shopify_d co.uk Performance Cookies  
    _ga ghostlygoods.co.uk Performance Cookies This cookie name is associated with Google Universal Analytics - which is a significant update to Google's more commonly used analytics service. This cookie is used to distinguish unique users by assigning a randomly generated number as a client identifier. It is included in each page request in a site and used to calculate visitor, session and campaign data for the sites analytics reports.  By default it is set to expire after 2 years, although this is customisable by website owners.
    _landing_page ghostlygoods.co.uk Performance Cookies This cookie is used to track, report, and analyze on landing pages.
    _gat ghostlygoods.co.uk Performance Cookies This cookie name is associated with Google Universal Analytics, according to documentation it is used to throttle the request rate - limiting the collection of data on high traffic sites. It expires after 10 minutes.
    _shopify_y ghostlygoods.co.uk Performance Cookies This cookie is associated with Shopify's analytics suite.
    _shopify_s ghostlygoods.co.uk Performance Cookies This cookie is associated with Shopify's analytics suite.
    _gid ghostlygoods.co.uk Performance Cookies This cookie name is associated with Google Universal Analytics. This appears to be a new cookie and as of Spring 2017 no information is available from Google.  It appears to store and update a unique value for each page visited.
    _gat_UA-175699448-1 ghostlygoods.co.uk Performance Cookies This is a pattern type cookie set by Google Analytics, where the pattern element on the name contains the unique identity number of the account or website it relates to. It appears to be a variation of the _gat cookie which is used to limit the amount of data recorded by Google on high traffic volume websites.
    _ga co.uk Performance Cookies This cookie name is associated with Google Universal Analytics - which is a significant update to Google's more commonly used analytics service. This cookie is used to distinguish unique users by assigning a randomly generated number as a client identifier. It is included in each page request in a site and used to calculate visitor, session and campaign data for the sites analytics reports.  By default it is set to expire after 2 years, although this is customisable by website owners.
    _shopify_evids cdn.shopify.com Performance Cookies  
    _shopify_sa_p ghostlygoods.co.uk Performance Cookies This cookie is associated with Shopify's analytics suite concerning marketing and referrals.
    _s ghostlygoods.co.uk Performance Cookies This cookie is associated with Shopify's analytics suite.
    _shopify_d ghostlygoods.co.uk Performance Cookies  
    _shopify_sa_t ghostlygoods.co.uk Performance Cookies This cookie is associated with Shopify's analytics suite concerning marketing and referrals.
    _y ghostlygoods.co.uk Performance Cookies This cookie is associated with Shopify's analytics suite.
    _shopify_evids www.ghostlygoods.co.uk Performance Cookies  
    _shopify_evids ghostlygoods.co.uk Performance Cookies  
      www.facebook.com Targeting Cookies This domain is owned by Facebook, which is the world's largest social networking service.  As a third party host provider, it mostly collects data on the interests of users via widgets such as the 'Like' button found on many websites.  This is used to serve targeted advertising to its users when logged into its services.  In 2014 it also started serving up behaviourally targeted advertising on other websites, similar to most dedicated online marketing companies.
    _fbp ghostlygoods.co.uk Targeting Cookies Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers
    NID google.com Targeting Cookies This domain is owned by Google Inc. Although Google is primarily known as a search engine, the company provides a diverse range of products and services. Its main source of revenue however is advertising. Google tracks users extensively both through its own products and sites, and the numerous technologies embedded into many millions of websites around the world. It uses the data gathered from most of these services to profile the interests of web users and sell advertising space to organisations based on such interest profiles as well as aligning adverts to the content on the pages where its customer's adverts appear.
    _fbp co.uk Targeting Cookies Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers
    fr facebook.com Targeting Cookies Contains browser and user unique ID combination, used for targeted advertising.

     

    The length of time that a cookie remains on your computer or mobile device depends on whether it is a “persistent” or “session” cookie. Session cookies last until you stop browsing and persistent cookies last until they expire or are deleted. Most of the cookies we use are persistent and will expire between 30 minutes and two years from the date they are downloaded to your device.

    You can control and manage cookies in various ways. Please keep in mind that removing or blocking cookies can negatively impact your user experience and parts of our website may no longer be fully accessible.

    Most browsers automatically accept cookies, but you can choose whether or not to accept cookies through your browser controls, often found in your browser’s “Tools” or “Preferences” menu. For more information on how to modify your browser settings or how to block, manage or filter cookies can be found in your browser’s help file or through such sites as: www.allaboutcookies.org.

    Additionally, please note that blocking cookies may not completely prevent how we share information with third parties such as our advertising partners. To exercise your rights or opt-out of certain uses of your information by these parties, please follow the below link to initiate a data subject request:

    https://privacyportal.cookiepro.com/webform/bdbeee4f-8690-4837-a609-534882a80ea8/1aabdbb0-7329-4bea-834d-34056eabee0d

    Changes

    We may update this Privacy Policy from time to time in order to reflect, for example, changes to our practices or for other operational, legal, or regulatory reasons.

    Complaints

    As noted above, if you would like to make a complaint, please contact us by e-mail or by mail using the details provided under “Contact” above.

    If you are not satisfied with our response to your complaint, you have the right to lodge your complaint with the relevant data protection authority. You can contact your local data protection authority, or our supervisory authority here: https://ico.org.uk/make-a-complaint/]

    Last updated: 17/05/2022

     

    Contact

    After reviewing this policy, if you have additional questions, want more information about our privacy practices, or would like to make a complaint, please contact us by e-mail at emily@ghostlygoods.co.uk or by mail using the details provided below:

    2 The Dingle, Bristol BS37 7GA, United Kingdom