Privacy Policy
Privacy Policy for Example Goods
- Effective date
- 2026-09-23
01Introduction
This Privacy Policy explains how Example Retail Ltd (fictional) processes personal information in connection with Example Goods at https://example.net. It takes effect on 2026-09-23. It is based on the service practices described by its operator and should be read together with notices shown when information is collected.
02Who operates this service
Example Retail Ltd (fictional) is the business responsible for this policy and is established in Ireland, with a postal address at 2 Example Street, Example City.
03Scope
This policy applies to the website and online store offered under the Example Goods name. It does not govern independent third-party services that publish their own privacy terms.
05Sources of information
Information comes from users directly, automatic collection from the devices used to access the service, and service providers or partners. Information received from another source is handled for the purposes described in this policy and subject to applicable restrictions.
06How we use information
Information is used for providing and securing the service; managing accounts, support, payments, and communications; analytics and product improvement; and marketing, advertising, and personalization. It may also be used to prevent misuse, establish or defend legal claims, meet legal obligations, and enforce service terms where those activities are relevant and permitted.
07Messages and email
The service sends transactional service and marketing messages using Mailchimp. Contact details are used for delivery, service administration, and the purposes described when the details are collected.
Marketing messages can be stopped through the unsubscribe link in every marketing email or the account settings page. The operator measures message opens or link interactions; those events are used to understand delivery and engagement.
08EU legal bases for processing
For processing governed by the EU GDPR, the relied-on legal bases are performance of a contract or steps requested before a contract, compliance with a legal obligation, and consent. The operator's purpose-to-basis mapping is: orders and delivery: contract; accounting records: legal obligation; marketing email and advertising cookies: consent. Consent can be withdrawn for future processing at any time without affecting processing that was lawful before withdrawal.
09Cookies and tracking technologies
The service uses essential storage and cookies, analytics technologies, and advertising and social tracking technologies. The operator states that non-essential technologies are handled as follows: non-essential technologies start only after the user consents. Preferences can be reviewed or changed through the Cookie settings link in the store footer. Browser controls may also limit storage, but blocking essential storage can prevent features from working.
10Analytics
The service uses privacy-focused analytics with Plausible to understand service operation, usage, errors, and improvements. Analytics data may include technical, device, interaction, approximate-location, and identifier information according to the selected configuration and provider controls.
11Advertising
The service uses personalized advertising through Meta Pixel. Depending on configuration, advertising data can include device identifiers, interactions, conversions, and inferred interests. Available consent and opt-out controls are described in the rights section.
12Payments
Payments are processed using Stripe for one-time purchases. The operator does not directly store full payment-card information; the payment provider handles card details under its own privacy terms.
13Sharing and disclosures
Information may be disclosed to service providers, business or advertising partners, and authorities or professional advisers for the purposes described in this policy, subject to contracts and legal limits where required. It may also be disclosed to authorities, courts, advisers, or transaction counterparties when reasonably necessary for law, safety, claims, or a business reorganization. Selected service providers include Stripe, Mailchimp, and Meta.
14International transfers
Information may be processed outside Ireland. The stated location and safeguard approach is: European Commission standard contractual clauses. For EU information, the transfer mechanism is: European Commission standard contractual clauses. Users may request information about the mechanism used.
15Data retention
The retention model is: records are kept while the account or relationship remains active and for a justified period afterward. Records may be kept longer when reasonably necessary for security, disputes, tax, accounting, fraud prevention, legal obligations, or enforcement. Deletion or de-identification follows the stated model and applicable law.
16Security
The operator uses encryption and access restrictions, selected according to the nature and risk of the information. No transmission or storage method is completely secure, so absolute security cannot be guaranteed.
17Children's privacy
The service is intended for a general audience. If the operator learns that information was collected from a child contrary to the stated audience or applicable law, it will take reasonable steps to delete it and may ask for age or authority verification.
18Your choices and privacy rights
Depending on location and processing, users may ask to access, correct, delete, restrict, or receive information; withdraw consent; unsubscribe; object; or opt out of sale, sharing, or targeted advertising. Requests are supported through the account settings or by email to privacy@example.net. The operator may verify identity and authority, apply legal exceptions, and explain a denial and available appeal where required.
19European Economic Area privacy rights
The EU GDPR has applied since May 25, 2018. Where it applies, people may request access, rectification, erasure, restriction, and portability; object to processing; withdraw consent for future processing; and complain to the competent supervisory authority. Rights depend on the processing, lawful basis, and statutory exceptions. Requests may be made through the account settings or at privacy@example.net.
20Canada PIPEDA privacy rights
Where Canada's PIPEDA applies, the operator follows accountability, identified purposes, meaningful consent, limited collection, limited use and retention, accuracy, safeguards, openness, individual access, and complaint-handling principles. Individuals may ask about the existence, use, and disclosure of their personal information, request access or correction, or challenge compliance through the account settings or at privacy@example.net. Complaints may also be directed to the Office of the Privacy Commissioner of Canada where applicable.
21Account and data deletion
Users can request account and associated-data deletion through email to privacy@example.net or the account settings. Some records may remain for security, legal, tax, payment, dispute, fraud-prevention, or backup-cycle needs and will remain restricted to those purposes.
22Third-party links and services
The service integrates or links to Stripe, Mailchimp, and Meta. Those providers may act independently and publish separate privacy terms. The operator is not responsible for an independent service's practices, and users should review its notice before supplying information.
23Changes to this policy
This policy may be updated to reflect service, legal, or operational changes. The current version will be posted at https://example.net with a revised effective date. Additional notice or consent will be provided only when required by applicable law.