You are here

This Privacy Policy describes how and when Howl at the Moon Gems collects, uses and shares information when a customer purchases from, contacts or otherwise uses Howl at the Moon Gems services through any selling platforms or related sites or services.

This Privacy Policy does not apply to the practices of third parties that Howl at the Moon Gems does not control, including PayPal, Etsy, Amazon, Ebay or any third party services accessed through our sites and the sites of the platforms we use. The customer can reference the Privacy Policy of third parties to learn more about their privacy practices. Howl at the Moon Gems does not collect or store your personal payment information.

To fulfill an order, a customer must provide certain information (which the customer authorizes) such as name, email address, postal address, payment information and the details of the product ordered. The customer may also choose to provide additional personal information if they contact Howl at the Moon Gems directly. Howl at the Moon Gems relies on a number of legal bases to collect, use, and share information, including:

  • As needed to provide services, such as fulfilling an order, settle disputes or provide customer support.
  • With affirmative consent, which may be revoked at any time, such as signing up for a mailing list.
  • If necessary to comply with a legal obligation or court order or in connection with a legal claim, such as retaining information about purchases as required by tax law.

As necessary for the purpose of Howl at the Moon Gems legitimate interests, if those interests are not overridden by the customer’s right or interests, such as:

  • Providing and improving services
  • Compliance with third parties’ policies and terms of use.

Information about my customers is important to my business. I share personal information for very limited reasons and in limited circumstances, as follows:

  • I  may engage certain trusted third parties to perform functions and provide services to my store, such as delivery companies.
  • I will only share personal information with these third parties to perform these services.

If I sell or merge my business, I may disclose customer information as a part of that transaction, only to the extent permitted by law. I may collect, use, retain, and share information if I have a good faith belief that it is reasonably necessary to:

  • Respond to legal process or to government requests Enforce agreements, terms or policies
  • Prevent, investigate, and address fraud and other illegal activity, security, or technical issues
  • Protect the rights, property and safety of our customers or others.

I retain customer personal information only for as long as necessary to provide services and as described in my Privacy Policy. However, I may also be required to retain this information to comply with legal and regulatory obligations, to resolve disputes, and to enforce agreements. I generally keep data for a period of 10 years. I may store and process information through third-party hosting services in the US and other jurisdictions. As a result, I may transfer personal information to a jurisdiction with different data protection and government surveillance laws than the customer’s jurisdiction.

If I transfer customer information to another jurisdiction, I rely on Privacy Shield as the legal basis for the transfer, as Google Cloud is Privacy Shield certified. If the customer resides in certain territories, including the EU, the customer has a number of rights in relation to the customer’s personal information. While some of these rights apply generally, certain rights apply only in certain limited cases. I describe these rights below:

  • The customer may have the right to access and receive a copy of the personal information we hold about the customer by contacting us using my contact form.
  • The customer may also have the rights to change, restrict my use of, or delete their personal information. Absent exceptional circumstances such as the requirement to store data for legal reasons, personal information will generally be deleted upon request.

The customer can object to:

  • My processing of some information based on my legitimate interests
  • Receiving marketing messages, email or mail from Howl at the Moon Gems after providing express consent to receive them. In such cases, Howl at the Moon Gems will delete the customer’s personal information unless there are compelling and legitimate grounds to continue using that information or if it is needed for legal reasons.
  • If the customer resides in the EU and wishes to raise a concern about Howl at the Moon Gems use of personal information (and without prejudice to any other rights the customer may have) the customer has the right to do so with the customer’s local data protection authoriy.

For the purpose of EU data protection law, Howl at the Moon Gems, is the data controller of the customer’s personal information.

For questions or concerns, contact orders@howlatm.com, Howl at the Moon Gems, Elkhorn, WI 53121 USA