Privacy policy
OTTO FINCH
Privacy Policy
Last updated: April 19, 2026
This Privacy Policy describes how OTTO FINCH (the "Site", "we", "us", or "our") collects, uses, and discloses your personal information when you visit, use our services, or make a purchase from ottofinch.com (the "Site") or otherwise communicate with us regarding the Site (collectively, the "Services"). For purposes of this Privacy Policy, "you" and "your" means you as the user of the Services, whether you are a customer, website visitor, or another individual whose information we have collected pursuant to this Privacy Policy.
Please read this Privacy Policy carefully.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time, including to reflect changes to our practices or for other operational, legal, or regulatory reasons. We will post the revised Privacy Policy on the Site, update the "Last updated" date and take any other steps required by applicable law.
How We Collect and Use Your Personal Information
To provide the Services, we collect and have collected over the past 12 months personal information about you from a variety of sources, as set out below. The information that we collect and use varies depending on how you interact with us.
In addition to the specific uses set out below, we may use information we collect about you to communicate with you, provide or improve the Services, comply with any applicable legal obligations, enforce any applicable terms of service, and to protect or defend the Services, our rights, and the rights of our users or others.
What Personal Information We Collect
The types of personal information we obtain about you depends on how you interact with our Site and use our Services. When we use the term "personal information", we are referring to information that identifies, relates to, describes or can be associated with you. The following sections describe the categories and specific types of personal information we collect.
Information We Collect Directly from You
Information that you directly submit to us through our Services may include:
• Contact details including your name, address, phone number, and email.
• Order information including your name, billing address, shipping address, payment confirmation, email address, and phone number.
• Account information including your username, password, security questions and other information used for account security purposes.
• Customer support information including the information you choose to include in communications with us, for example, when sending a message through the Services.
Some features of the Services may require you to directly provide us with certain information about yourself. You may elect not to provide this information, but doing so may prevent you from using or accessing these features.
Information We Collect about Your Usage
We may also automatically collect certain information about your interaction with the Services ("Usage Data"). To do this, we may use cookies, pixels, tags, software development kits (SDKs) and similar technologies ("Cookies"). Usage Data may include information about how you access and use our Site and your account, including device information, browser information, information about your network connection, your IP address, approximate location, pages viewed, products viewed or added to cart, clicks, referring and exit pages, timestamps, session duration, and other information regarding your interaction with the Services.
Information We Obtain from Third Parties
Finally, we may obtain information about you from third parties, including from vendors and service providers who may collect information on our behalf, such as:
• Companies who support our Site and Services, such as Shopify.
• Our payment processors, who collect payment information (e.g., bank account, credit or debit card information, billing address) to process your payment in order to fulfill your orders and provide you with products or services you have requested, in order to perform our contract with you.
• Analytics providers, such as Google (including Google Analytics 4, or "GA4"), who provide us with aggregated and individual-level data about how visitors find and interact with our Site.
• Advertising partners, such as Meta Platforms, Inc. (operator of Facebook, Instagram, Messenger, Threads and WhatsApp), Google (including Google Ads), and other advertising networks, who provide us with information about how users interact with advertisements and our Site.
When you visit our Site, open or click on emails we send you, or interact with our Services or advertisements, we, or third parties we work with, may automatically collect certain information using online tracking technologies such as pixels, web beacons, software developer kits, third-party libraries, and cookies.
Any information we obtain from third parties will be treated in accordance with this Privacy Policy. Also see the section below, Third Party Websites and Links.
How We Use Your Personal Information
Providing Products and Services. We use your personal information to provide you with the Services in order to perform our contract with you, including to process your payments, fulfill your orders, to send notifications to you related to your account, purchases, returns, exchanges or other transactions, to create, maintain and otherwise manage your account, to arrange for shipping, facilitate any returns and exchanges and other features and functionalities related to your account. We may also enhance your shopping experience by enabling Shopify to match your account with other Shopify services that you may choose to use. In this case, Shopify will process your information as set forth in its Privacy Policy and Consumer Privacy Policy.
Marketing and Advertising. We use your personal information for marketing and promotional purposes, such as to send marketing, advertising and promotional communications by email, text message or postal mail, and to show you advertisements for products or services on our Site and on third-party platforms including Facebook, Instagram and other Meta-owned properties, Google, and other advertising networks. This includes using your personal information to build audiences, to measure the performance of our campaigns, to retarget visitors who have previously interacted with our Site, and to create lookalike or similar audiences of people who may be interested in our products. If you are an EEA or UK resident, the legal basis for these data processing activities is your consent (Art. 6 (1) (a) GDPR) where required, and our legitimate interest in selling our products (Art. 6 (1) (f) GDPR) where consent is not required.
Analytics and Service Improvement. We use analytics tools such as Google Analytics 4 (GA4) and the Meta Pixel / Conversions API to understand how visitors find, navigate and interact with our Site, measure the effectiveness of our marketing, diagnose technical issues, and improve our products, content and user experience. These tools may collect information such as your IP address (which may be truncated or anonymised), device and browser information, pages viewed, items viewed or purchased, and events you trigger on the Site (such as add-to-cart or checkout).
Security and Fraud Prevention. We use your personal information to detect, investigate or take action regarding possible fraudulent, illegal or malicious activity. If you choose to use the Services and register an account, you are responsible for keeping your account credentials safe. We highly recommend that you do not share your username, password, or other access details with anyone else. If you believe your account has been compromised, please contact us immediately. If you are an EEA resident, the legal basis for these data processing activities is our legitimate interest in keeping our website secure for you and other customers, according to Art. 6 (1) (f) GDPR.
Communicating with You and Service Improvement. We use your personal information to provide you with customer support and improve our Services. This is in our legitimate interests in order to be responsive to you, to provide effective services to you, and to maintain our business relationship with you according to Art. 6 (1) (f) GDPR.
Cookies and Similar Tracking Technologies
Like many websites, we use Cookies on our Site. For specific information about the Cookies that we use related to powering our store with Shopify, see https://www.shopify.com/legal/cookies. We use Cookies to power and improve our Site and our Services (including to remember your actions and preferences), to run analytics and better understand user interaction with the Services (in our legitimate interests to administer, improve and optimise the Services). We may also permit third parties and service providers to use Cookies on our Site to better tailor the services, products and advertising on our Site and other websites.
Analytics Cookies
We use Google Analytics 4 (GA4), a web analytics service provided by Google LLC ("Google"), to analyse how users interact with our Site. GA4 uses cookies and similar technologies to collect information such as your IP address (which is truncated before storage in line with Google's IP anonymisation), device and browser characteristics, pages visited, and actions taken on the Site. This information is transmitted to and stored by Google on servers that may be located outside your country of residence. You can learn more about how Google uses data from sites or apps that use its services at https://policies.google.com/technologies/partner-sites. You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on available at https://tools.google.com/dlpage/gaoptout.
Advertising and Social Media Cookies
We use advertising technologies provided by Meta Platforms, Inc. ("Meta"), including the Meta Pixel, the Meta Conversions API, and advertising SDKs, to deliver, measure and optimise advertisements shown on Facebook, Instagram, Messenger, Threads, WhatsApp and across the Meta Audience Network. These technologies allow us to understand which ads led visitors to our Site, to measure conversions (such as purchases) that result from our advertising, to build custom audiences (including from visitors to our Site or customers who have purchased from us), and to create lookalike audiences of people with similar characteristics. Meta may process this information as an independent controller or as a joint controller with us, depending on the activity. You can learn more about Meta's data practices at https://www.facebook.com/privacy/policy and manage your ad preferences in your Facebook or Instagram settings.
We also use Google Ads and related Google advertising products (including remarketing tags and conversion tracking) to show you relevant ads on Google properties and across the Google Display Network and YouTube, and to measure the effectiveness of those ads. You can manage your Google ad preferences at https://adssettings.google.com.
In addition, we may use other advertising networks, affiliate platforms, and measurement providers from time to time. These partners may set their own cookies or use similar technologies on our Site subject to this Privacy Policy and your cookie preferences.
Managing Your Cookie Preferences
Most browsers automatically accept Cookies by default, but you can choose to set your browser to remove or reject Cookies through your browser controls. Where required by applicable law, we will ask for your consent before setting non-essential Cookies (including analytics and advertising Cookies) via a cookie banner or preference centre on our Site, and you can change your preferences at any time. Please keep in mind that removing or blocking Cookies can negatively impact your user experience and may cause some of the Services, including certain features and general functionality, to work incorrectly or no longer be available. Additionally, blocking Cookies may not completely prevent how we share information with third parties such as our advertising partners.
Our website also recognises the Global Privacy Control (GPC) signal, which enables you to opt out of certain uses or disclosures of your information. If you notify us of your preference through GPC, we will treat such signal as a valid request to opt out of sharing / targeted advertising for the associated browser or device, and, if we are able to associate the device sending the signal to a Shopify account, we will apply the opt out request to the account as well. To learn more about Global Privacy Control, you can visit https://globalprivacycontrol.org/. Other than the Global Privacy Control, we do not recognise other "Do Not Track" signals that may be sent from your web browser or device.
How We Disclose Personal Information
In certain circumstances, we may disclose your personal information to third parties for contract fulfilment purposes, legitimate purposes and other reasons subject to this Privacy Policy. Such circumstances may include:
• With vendors or other third parties who perform services on our behalf (e.g., IT management, payment processing, data analytics, customer support, cloud storage, fulfilment and shipping).
• With analytics providers such as Google (including GA4) to help us understand how visitors use our Site.
• With advertising partners including Meta Platforms, Google, and other advertising networks, in order to deliver, target, measure and optimise our advertising and to build custom and lookalike audiences. Our advertising partners will use your information in accordance with their own privacy notices.
• With business and marketing partners to provide services and advertise to you. Our business and marketing partners will use your information in accordance with their own privacy notices.
• When you direct, request us or otherwise consent to our disclosure of certain information to third parties, such as to ship you products or through your use of social media widgets or login integrations, with your consent.
• With our affiliates or otherwise within our corporate group, in our legitimate interests to run a successful business.
• In connection with a business transaction such as a merger or bankruptcy, to comply with any applicable legal obligations (including to respond to subpoenas, search warrants and similar requests), to enforce any applicable terms of service, and to protect or defend the Services, our rights, and the rights of our users or others.
We have in the past 12 months disclosed the following categories of personal information and sensitive personal information about users for the purposes set out above in "How we Collect and Use your Personal Information" and "How we Disclose Personal Information":
|
Category |
Categories of Recipients |
|
Identifiers such as basic contact details and certain order and account information; personal information categories listed in the California Customer Records statute; commercial information such as order information, shopping information and customer support information; internet or other similar network activity, such as Usage Data; geolocation data such as locations determined by an IP address or other technical measures. |
Vendors and third parties who perform services on our behalf (such as internet service providers, payment processors, fulfilment partners, customer support partners and data analytics providers); analytics providers such as Google (GA4); advertising partners such as Meta Platforms and Google; business and marketing partners; affiliates. |
We do not use or disclose sensitive personal information without your consent or for the purposes of inferring characteristics about you.
With your consent (where required by applicable law) we share personal information for the purpose of engaging in advertising and marketing activities, as follows.
We have "sold" and "shared" (as those terms are defined in applicable law, including the California Consumer Privacy Act and the laws of other US states) personal information over the preceding 12 months for the purpose of engaging in advertising and marketing activities, as follows.
|
Category of Personal Information |
Categories of Recipients |
|
Identifiers such as name, e-mail address, phone number and online identifiers (including cookie IDs, device IDs and IP address). |
Advertising partners including Meta Platforms and Google; other business and marketing partners. |
|
Commercial information such as records of products or services viewed or purchased. |
Advertising partners including Meta Platforms and Google; other business and marketing partners. |
|
Usage Data (including information about your interactions with our Site and advertisements). |
Analytics providers including Google (GA4); advertising partners including Meta Platforms and Google; other business and marketing partners. |
Third Party Websites and Links
Our Site may provide links to websites or other online platforms operated by third parties, including social media platforms such as Facebook, Instagram and Threads. If you follow links to sites not affiliated or controlled by us, you should review their privacy and security policies and other terms and conditions. We do not guarantee and are not responsible for the privacy or security of such sites, including the accuracy, completeness, or reliability of information found on these sites. Information you provide on public or semi-public venues, including information you share on third-party social networking platforms may also be viewable by other users of the Services and/or users of those third-party platforms without limitation as to its use by us or by a third party. Our inclusion of such links does not, by itself, imply any endorsement of the content on such platforms or of their owners or operators, except as disclosed on the Services.
Children's Data
The Services are not intended to be used by children, and we do not knowingly collect any personal information about children. If you are the parent or guardian of a child who has provided us with their personal information, you may contact us using the contact details set out below to request that it be deleted.
As of the Effective Date of this Privacy Policy, we do not have actual knowledge that we "share" or "sell" (as those terms are defined in applicable law) personal information of individuals under 16 years of age.
Security and Retention of Your Information
Please be aware that no security measures are perfect or impenetrable, and we cannot guarantee "perfect security." In addition, any information you send to us may not be secure while in transit. We recommend that you do not use insecure channels to communicate sensitive or confidential information to us.
How long we retain your personal information depends on different factors, such as whether we need the information to maintain your account, to provide the Services, comply with legal obligations, resolve disputes or enforce other applicable contracts and policies.
Your Rights
Depending on where you live, you may have some or all of the rights listed below in relation to your personal information. However, these rights are not absolute, may apply only in certain circumstances and, in certain cases, we may decline your request as permitted by law.
• Right to Access / Know: You may have a right to request access to personal information that we hold about you, including details relating to the ways in which we use and share your information.
• Right to Delete: You may have a right to request that we delete personal information we maintain about you.
• Right to Correct: You may have a right to request that we correct inaccurate personal information we maintain about you.
• Right of Portability: You may have a right to receive a copy of the personal information we hold about you and to request that we transfer it to a third party, in certain circumstances and with certain exceptions.
• Right to Opt out of Sale or Sharing or Targeted Advertising: You may have a right to direct us not to "sell" or "share" your personal information or to opt out of the processing of your personal information for purposes considered to be "targeted advertising", as defined in applicable privacy laws. Please note that if you visit our Site with the Global Privacy Control opt-out preference signal enabled, depending on where you are, we will automatically treat this as a request to opt-out of the "sale" or "sharing" of information for the device and browser that you use to visit the Site.
• Restriction of Processing: You may have the right to ask us to stop or restrict our processing of personal information.
• Withdrawal of Consent: Where we rely on consent to process your personal information, you may have the right to withdraw this consent. You may withdraw your consent to analytics or advertising cookies at any time via our cookie preference centre.
• Appeal: You may have a right to appeal our decision if we decline to process your request. You can do so by replying directly to our denial.
• Managing Communication Preferences: We may send you promotional emails, and you may opt out of receiving these at any time by using the unsubscribe option displayed in our emails to you. If you opt out, we may still send you non-promotional emails, such as those about your account or orders that you have made.
You may exercise any of these rights where indicated on our Site or by contacting us using the contact details provided below.
We will not discriminate against you for exercising any of these rights. We may need to collect information from you to verify your identity, such as your email address or account information, before providing a substantive response to the request. In accordance with applicable laws, you may designate an authorised agent to make requests on your behalf to exercise your rights. Before accepting such a request from an agent, we will require that the agent provide proof you have authorised them to act on your behalf, and we may need you to verify your identity directly with us. We will respond to your request in a timely manner as required under applicable law.
Complaints
If you have complaints about how we process your personal information, please contact us using the contact details provided below. If you are not satisfied with our response to your complaint, depending on where you live you may have the right to appeal our decision by contacting us using the contact details set out below, or lodge your complaint with your local data protection authority. For the EEA, you can find a list of the responsible data protection supervisory authorities here. In the UK, you may contact the Information Commissioner's Office (ICO) at https://ico.org.uk.
International Users
Please note that we may transfer, store and process your personal information outside the country you live in, including in the United States and other jurisdictions where our service providers, analytics providers, and advertising partners (such as Meta Platforms and Google) are located. Your personal information is also processed by staff and third party service providers and partners in these countries.
If we transfer your personal information out of the UK or European Economic Area, we will rely on recognised transfer mechanisms like the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, or any equivalent contracts issued by the relevant competent authority, unless the data transfer is to a country that has been determined to provide an adequate level of protection.
Contact
Should you have any questions about our privacy practices or this Privacy Policy, or if you would like to exercise any of the rights available to you, please email us at info@ottofinch.com. For the purpose of applicable data protection laws and if not explicitly stated otherwise, we are the data controller of your personal information.