Ah-Ha! Privacy Policy

Effective Date: June 9, 2025. Our website address is: https://ah-ha.shop. Ah-Ha! (“the Site”) is owned and operated by Brook Soelberg. Brook Soelberg is the data
controller and be contacted at: support@ah-ha.shop

Purpose

The purpose of this privacy policy (this “Privacy Policy”) is to inform users of our Site of the following: the personal data we will collect; use of collected data; who has access to the data collected; the rights of Site users; and the Site’s cookie policy. This Privacy Policy applies in addition to the terms and conditions of our Site.

GDPR

For users in the European Union, we adhere to the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, known as the General Data Protection Regulation (the”GDPR”). For users in the United Kingdom, we adhere to the GDPR as enshrined in the Data Protection Act 2018. We have not appointed a Data Protection Officer as we do not fall within the categories of controllers and processors required to appoint a Data Protection Officer under Article 37 of the GDPR. By using our Site users agree that they consent to the conditions set out in this Privacy Policy. We collect and process personal data about users in the EU only when we have a legal basis for doing so under Article 6 of the GDPR. We rely on the following legal basis to collect and process the personal data of users in the EU: processing of user personal data is necessary to a task carried out in the public interest or in the exercise of our official authority. We transfer user personal data to the following countries: United States. When we transfer user personal data, we will protect that data as described in this Privacy Policy and comply with applicable legal requirements for transferring personal data internationally. If you are located in the United Kingdom or the European Union, we will only transfer your personal data if: the country your personal data is being transferred to has been deemed to have adequate data
protection by the European Commission or, if you are in the United Kingdom, by the United Website Privacy Policy Kingdom Adequacy Regulations. We have implemented appropriate safeguards in respect of the transfer. For example, the recipient is a party to binding corporate rules, or we have entered into standard EU or United Kingdom data protection contractual clauses with the recipient. Your rights as a User under the GDPR include: Right to be informed; Right of access; Right to rectification; Right to erasure; Right to restrict processing; and Right to data portability.

Personal Data We Collect

We only collect data that helps us achieve the purpose set out in this Privacy Policy. We will not collect any additional data beyond the data listed below without notifying you first. We may also collect the following data when you perform certain functions on our Site: First and last name; Email address; Phone number; Address; and Payment information. This data may be collected using the following methods: Customer enters this information at the time of purchase.; and Customer chooses to create an account on the Ah-Ha! website. Data collected on our Site will only be used for the purposes specified in this Privacy Policy or indicated on the Terms and Conditions pages of our Site. We will not use your data beyond what we disclose in this Privacy Policy. The data we collect when the user performs certain functions may be used for the following purposes: Communication; Shipping products to customers; and Processing customer payments.

How We Manage the Data We Collect

We may disclose user data to any member of our organization who reasonably needs access to user data to achieve the purposes set out in this Privacy Policy. We may share user data with the following third parties: Printful, a third-party order fulfillment company; Stripe, a third-party payment processing company; third party marketing companies. We may share the following user data with third parties: Product selection; Name; Address; and Payment information. We share user data with third parties for the following purposes: Order fulfillment; and Marketing Purposes. Third parties will not be able to access user data beyond what is reasonably necessary to achieve the given purpose. We will not sell or share your data with other third parties, except in the following cases: If the law requires it; If it is required for any legal proceeding; To prove or protect our legal rights; or To buyers or potential buyers of this company in the event that we seek to sell the company. If you follow hyperlinks from our Site to another Site, please note that we are not responsible for and have no control over their privacy policies and practices. User data will be stored until dissolution of business unless specifically requested by the customer. Customer request of personal data cannot take precedent over legal data collection and retention regulations. In order to protect customer security, we use the strongest available browser and payment encryption. All of our data is stored on servers in secure facilities. All data is only accessible to our employees. Our employees are bound by strict confidentiality agreements and a breach of this agreement would result in the employee’s immediate termination. While we take all reasonable precautions to ensure that user data is secure and that users are protected, there always remains the risk of harm. The Internet as a whole can be insecure at times and therefore we are unable to guarantee the security of user data beyond what is reasonably practical. We do not knowingly collect or use personal data from children under 16 years of age. If we learn that we have collected personal data from a child under 16 years of age, the personal data will be deleted as soon as possible. If a child under 16 years of age has provided us with personal data their parent or guardian may contact our privacy officer. When visitors leave comments on this site, we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help with spam detection. An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment. If you request a password reset, your IP address will be included in the reset email.

Media

If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.

Cookies

IA cookie is a small file, stored on a user’s hard drive by a website. Its purpose is to collect data relating to the user’s browsing habits. You can choose to be notified each time a cookie is transmitted. You can also choose to disable cookies entirely in your internet browser, but this may decrease the quality of your user experience. We use the following types of cookies on our Site: Functional cookies (Functional cookies are used to remember the selections you make on our Site so that your selections are saved for your next visits); Analytical cookies (Analytical cookies allow us to improve the design and functionality of our Site by collecting data on how you access our Site, for example data on the content you access, how long you stay on our Site, etc.); and Targeting cookies (Targeting cookies collect data on how you use the Site and your preferences. This allows us to
personalize the information you see on our Site for you). If you leave a comment on our site, you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year. If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser. When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.

Embedded content from other websites

This site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website. These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.

How long we retain your data

If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue. For users that register on our website, we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.

What rights you have over your data

If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes. If you would like to know if we have collected your personal data, how we have used your personal data, if we have disclosed your personal data and to who we disclosed your personal data, if you would like your data to be deleted or modified in any way, or if you would like to exercise any of your other rights under the GDPR, please contact our privacy officer here: support@ah-ha.shop. Do Not Track (“DNT”) is a privacy preference that you can set in certain web browsers. We do not track the users of our Site over time and across third party websites and therefore do not respond to browser-initiated DNT signals. We are not responsible for and cannot guarantee how any third parties who interact with our Site and your data will respond to DNT signals. In addition to the method(s) previously described, we provide the following specific opt-out methods for the forms of collection, use, or disclosure of your personal data specified below: Marketing emails. You can opt-out by clicking unsubscribe on the bottom of any marketing email or by updating their email preferences under “Account Details”.

Modifications

This Privacy Policy may be amended from time to time in order to maintain compliance with the law and to reflect any changes to our data collection process. When we amend this Privacy Policy, we will update the “Effective Date” at the top of this Privacy Policy. We recommend that our users periodically review our Privacy Policy to ensure that they are notified of any updates. If necessary, we may notify users by email of changes to this Privacy Policy.

Complaints

If you have any complaints about how we process your personal data, please contact us through the contact methods listed in the Contact Information section so that we can, where possible, resolve the issue. If you feel we have not addressed your concern in a satisfactory manner you may contact a supervisory authority. You also have the right to directly make a complaint to a supervisory authority. You can lodge a complaint with a supervisory authority by contacting the Information Commissioner’s Office in the UK. If you have any questions, concerns or complaints, you can contact our privacy officer, Brook Soelberg, at:support@ah-ha.shop

Shopping Cart
0
    0
    My Shopping Cart
    Your cart is emptyReturn to Shop