occult box Privacy Policy 

https://www.occultmysterybox.co.uk/ Privacy Policy

Type of website: Ecommerce
Effective date: 27/09/2023

https://www.occultmysterybox.co.uk/ (the "Site") is owned and operated by occult box. occult box is the data controller and can be contacted at:


enquiries@occultmysterybox.co.uk


Purpose
The purpose of this privacy policy (this "Privacy Policy") is to inform users of our Site of the following:

The personal data we will collect;
Use of collected data;
Who has access to the data collected;
The rights of Site users; and
The Site's cookie policy.
This Privacy Policy applies in addition to the terms and conditions of our Site.

GDPR
For users in the European Union, we adhere to the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, known as the General Data Protection Regulation (the "GDPR"). For users in the United Kingdom, we adhere to the GDPR as enshrined in the Data Protection Act 2018.

We have not appointed a Data Protection Officer as we do not fall within the categories of controllers and processors required to appoint a Data Protection Officer under Article 37 of the GDPR.

Consent
By using our Site users agree that they consent to:

The conditions set out in this Privacy Policy.
Legal Basis for Processing
We collect and process personal data about users in the EU only when we have a legal basis for doing so under Article 6 of the GDPR.

We rely on the following legal basis to collect and process the personal data of users in the EU:

Processing of user personal data is necessary for us to take, at the request of a user, steps before entering a contract or for the performance of a contract to which a user is a party. If a user does not provide the the personal data necessary to perform a contract the consequences are as follows: Unable to ship orders.
Personal Data We Collect
We only collect data that helps us achieve the purpose set out in this Privacy Policy. We will not collect any additional data beyond the data listed below without notifying you first.


Data Collected Automatically
When you visit and use our Site, we may automatically collect and store the following information:

IP address;
Location;
Hardware and software details;
Clicked links; and
Content viewed.
Data Collected in a Non-Automatic Way
We may also collect the following data when you perform certain functions on our Site:

First and last name;
Email address;
Phone number;
Address; and
Payment information.
This data may be collected using the following methods:

Creating an account / placing an order/ contact/ mail list sign up.
How We Use Personal Data
Data collected on our Site will only be used for the purposes specified in this Privacy Policy or indicated on the relevant pages of our Site. We will not use your data beyond what we disclose in this Privacy Policy.

The data we collect automatically is used for the following purposes:

Statistics & analytics.
The data we collect when the user performs certain functions may be used for the following purposes:

Communication, fulfilling orders, promotion emails.
Who We Share Personal Data With
Employees
We may disclose user data to any member of our organisation who reasonably needs access to user data to achieve the purposes set out in this Privacy Policy.

Third Parties
We may share user data with the following third parties:

Google analytics.
We may share the following user data with third parties:

Links clicked when using site.
We may share user data with third parties for the following purposes:

Analytics.
Third parties will not be able to access user data beyond what is reasonably necessary to achieve the given purpose.

Other Disclosures
We will not sell or share your data with other third parties, except in the following cases:

If the law requires it;
If it is required for any legal proceeding;
To prove or protect our legal rights; and
To buyers or potential buyers of this company in the event that we seek to sell the company.
If you follow hyperlinks from our Site to another Site, please note that we are not responsible for and have no control over their privacy policies and practices.

How Long We Store Personal Data
User data will be stored until the purpose the data was collected for has been achieved.

You will be notified if your data is kept for longer than this period.

How We Protect Your Personal Data
In order to protect your security, we use the strongest available browser encryption . All data is only accessible to our employees. Our employees are bound by strict confidentiality agreements and a breach of this agreement would result in the employee's termination

While we take all reasonable precautions to ensure that user data is secure and that users are protected, there always remains the risk of harm. The Internet as a whole can be insecure at times and therefore we are unable to guarantee the security of user data beyond what is reasonably practical.

Your Rights as a User
Under the GDPR, you have the following rights:

Right to be informed;
Right of access;
Right to rectification;
Right to erasure;
Right to restrict processing;
Right to data portability; and
Right to object.
Children
We do not knowingly collect or use personal data from children under 16 years of age. If we learn that we have collected personal data from a child under 16 years of age, the personal data will be deleted as soon as possible. If a child under 16 years of age has provided us with personal data their parent or guardian may contact our privacy officer.

How to Access, Modify, Delete, or Challenge the Data Collected
If you would like to know if we have collected your personal data, how we have used your personal data, if we have disclosed your personal data and to who we disclosed your personal data, if you would like your data to be deleted or modified in any way, or if you would like to exercise any of your other rights under the GDPR, please contact our privacy officer here:
enquiries@occultmysteyrbox.co.uk

Do Not Track Notice
Do Not Track ("DNT") is a privacy preference that you can set in certain web browsers. We do not track the users of our Site over time and across third party websites and therefore do not respond to browser-initiated DNT signals. We are not responsible for and cannot guarantee how any third parties who interact with our Site and your data will respond to DNT signals.

How to Opt-Out of Data Collection, Use or Disclosure
In addition to the method(s) described in the How to Access, Modify, Delete, or Challenge the Data Collected section, we provide the following specific opt-out methods for the forms of collection, use, or disclosure of your personal data specified below:

. You can opt-out by emailing enquiries@occultmysterybox.co.uk
Cookie Policy
A cookie is a small file, stored on a user's hard drive by a website. Its purpose is to collect data relating to the user's browsing habits. You can choose to be notified each time a cookie is transmitted. You can also choose to disable cookies entirely in your internet browser, but this may decrease the quality of your user experience.

We use the following types of cookies on our Site:

Functional cookies
Functional cookies are used to remember the selections you make on our Site so that your selections are saved for your next visits;
Analytical cookies
Analytical cookies allow us to improve the design and functionality of our Site by collecting data on how you access our Site, for example data on the content you access, how long you stay on our Site, etc;
Targeting cookies
Targeting cookies collect data on how you use the Site and your preferences. This allows us to personalise the information you see on our Site for you; and
Third-Party Cookies
Third-party cookies are created by a website other than ours. We may use third-party cookies to achieve the following purposes:
Monitor user preferences to tailor advertisements around their interests.
Modifications
This Privacy Policy may be amended from time to time in order to maintain compliance with the law and to reflect any changes to our data collection process. When we amend this Privacy Policy we will update the "Effective Date" at the top of this Privacy Policy. We recommend that our users periodically review our Privacy Policy to ensure that they are notified of any updates. If necessary, we may notify users by email of changes to this Privacy Policy.

Complaints
If you have any complaints about how we process your personal data, please contact us through the contact methods listed in the Contact Information section so that we can, where possible, resolve the issue. If you feel we have not addressed your concern in a satisfactory manner you may contact a supervisory authority. You also have the right to directly make a complaint to a supervisory authority. You can lodge a complaint with a supervisory authority by contacting the . Information Commissioner's Office in the UK, Data Protection Commission in Ireland.

Contact Information
If you have any questions, concerns or complaints, you can contact our privacy officer at enquiries@occultmysterybox.co.uk

What information do we collect?

We collect two types of data and information from Users. 

The first type of information is unidentified and non-identifiable information pertaining to a User(s), which may be made available or gathered via your use of the Site (“Non-personal Information”). We are not aware of the identity of a User from which the Non-personal Information was collected. Non-personal Information which is being collected may include your aggregated usage information and technical information transmitted by your device, including certain software and hardware information (e.g. the type of browser and operating system your device uses, language preference, access time, etc.) in order to enhance the functionality of our Site. We may also collect information on your activity on the Site (e.g. pages viewed, online browsing, clicks, actions, etc.).

The second type of information Personal Information , which is individually identifiable information, namely information that identifies an individual or may with reasonable effort identify an individual. Such information includes:
  • Device Information: We collect Personal Information from your device. Such information includes geolocation data, IP address, unique identifiers (e.g. MAC address and UUID) and other information which relates to your activity through the Site.

How do we receive information about you?

We receive your Personal Information from various sources:
  • When you voluntarily provide us with your personal details in order to register on our Site;
  • When you use or access our Site in connection with your use of our services;
  • From third-party providers, services and public registers (for example, traffic analytics vendors).

Cookies

We and our trusted partners use cookies and other technologies in our related services, including when you visit our Site or access our services. 

A "cookie" is a small piece of information that a website assigns to your device while you are viewing a website. Cookies are very helpful and can be used for various different purposes. These purposes include allowing you to navigate between pages efficiently, enabling automatic activation of certain features, remembering your preferences and making the interaction between you and our Services quicker and easier. Cookies are also used to help make sure that the advertisements you see are relevant to you and your interests and to compile statistical data on your use of our Services. 

The Site uses the following types of cookies:

a. 'session cookies' , which are stored only temporarily during a browsing session in order to allow normal use of the system and are deleted from your device when the browser is closed; 

b. 'persistent cookies', which are read only by the Site, saved on your computer for a fixed period and are not deleted when the browser is closed. Such cookies are used where we need to know who you are for repeat visits, for example to allow us to store your preferences for the next sign-in; 

c. 'third-party cookies' , which are set by other online services who run content on the page you are viewing, for example by third-party analytics companies who monitor and analyse our web access.

Cookies do not contain any information that personally identifies you, but Personal Information that we store about you may be linked, by us, to the information stored in and obtained from cookies. You may remove the cookies by following the instructions of your device preferences; however, if you choose to disable cookies, some features of our Site may not operate properly and your online experience may be limited.

We use a tool which is based on the Snowplow Analytics technology to collect information about your use of the Site. The tool collects information such as how often users access the Site, which pages they visit when they do so, etc. The tool does not collect any Personal Information and is only used by our Site hosting and operating service provider to improve the Site and services.

Use of script libraries (Google Web Fonts)

In order to present our contents correctly and make them graphically appealing across all browsers, we use script libraries and font libraries such as Google Web Fonts (https://www.google.com/webfonts) on this website. Google Web Fonts are transferred to your browser's cache to avoid multiple loading. If your browser does not support Google Web Fonts or does not allow access, content will be displayed in a default font. 
  • Calling script libraries or font libraries automatically triggers a connection to the library operator. In theory, it is possible – but currently also unclear whether and, if so, for what purposes – that operators of corresponding libraries collect data.

  • The privacy policy of the library operator Google can be found here: https://www.google.com/policies/privacy.

Third-party collection of information

Our policy only addresses the use and disclosure of information we collect from you. To the extent you disclose your information to other parties or sites throughout the internet, different rules may apply to their use or disclosure of the information you disclose to them. Accordingly, we encourage you to read the terms and conditions and privacy policy of each third party that you choose to disclose information to. 

This Privacy Policy does not apply to the practices of companies that we do not own or control, nor to individuals whom we do not employ or manage, including any of the third parties which we may disclose information to as set out in this Privacy Policy. 

Updates or amendments to this Privacy Policy

We reserve the right to periodically amend or revise the Privacy Policy; material changes will be effective immediately upon the display of the revised Privacy policy. The last revision will be reflected in the "Last modified" section. Your continued use of the Platform, following the notification of such amendments on our website, constitutes your acknowledgment and consent of such amendments to the Privacy Policy and your agreement to be bound by the terms of such amendments.
Share by: