Privacy Policy
  • Updated on 18 February 2026
  • 29 min read

Revised 02/17/2026 and effective 02/17/2026

Download

Big Cartel, LLC (“Big Cartel”, “we”, or “us”) takes your privacy seriously and we know you do too. This Privacy Policy (“Policy”) describes how we collect, process, and share Personal Data, your Rights & Choices, and other important information about how we handle your Personal Data

SCOPE OF THIS POLICY

This Policy applies to your use of our “Services,” which include the following:

  • Our “Merchant Services”:
    - Products, software programs, and technical services for independent vendors, creators, or sellers, (“Merchants”) who set up accounts with us to allow them to host online storefronts (“Stores”) and sell goods to their customers;
    - Merchant facing Mobile Application (“Mobile App”); 
  • Our websites, mobile applications, social media pages, and other online services where this Policy is posted (including bigcartel.com, but excluding Stores) (“Site”); and
  • Any other product, service, or technology provided tomerchants or individuals who contact or interact with Big Cartel directly.

As a convenience to individuals who visit Stores (“Customers”), we provide information about the Personal Data we collect through Stores operated by Big Cartel on behalf of Merchants. Please note, however, that this Policy governs only the Personal Data we process as a “controller” i.e. the Personal Data we collect from and about Merchants, as well as individual users who visit our website, sign up for communications with Big Cartel, or contact Big Cartel directly. 

All online Stores hosted or supported by Big Cartel, whether on Merchant-specific subdomains of bigcartel.com (“Merchant Subdomains”) or on merchant-hosted domains, are operated on behalf of the Merchant. Big Cartel is a service provider to the Merchant (who is the “controller” or “business” under applicable privacy laws). Big Cartel is not responsible for the privacy practices of its Merchants. If you visit any Merchant storefront provided or hosted by Big Cartel, we encourage you to review their privacy policy and to direct any questions or concerns you have about their data practices to the appropriate Merchant.

HOW TO CONTACT US/CONTROLLER

The controller of your Personal Data under this Policy is Big Cartel, LLC. You may contact our Data Privacy Team as follows:

General Inquiries: privacy@bigcartel.com

Opt-Out of Data Sharing/Targeted Advertising: Use the “Manage Cookies” link in the footer of this page, or in your account management settings in our Mobile App.

Opt-out of Sales / Limit use of Sensitive Personal Data: You may visit our Privacy Choices Form 

Regional Data Rights: Visit the Privacy Rights Request Form  or mail to the address below.

Direct Marketing Disclosure Inquiries: mail to the address below or email privacy@bigcartel.com

Physical Address:

Big Cartel, LLC
Attn: Privacy
50 W. Broadway #333 PMB 40632
Salt Lake City, UT 84101, U.S.A.

CATEGORIES AND SOURCES OF PERSONAL DATA

The following describes how we process data relating to identified or identifiable individuals and households (“Personal Data”).

Categories of Personal Data We Process

The categories of Personal Data we process may include:

Contact Data-Identity Data we can use to contact you, such as email and physical addresses, phone numbers, social media or communications platform usernames/handles.

Device / Network Data-Browsing history, search history, and information regarding your interaction with a website, application, or advertisement (e.g. IP Address, MAC Address, SSIDs, application ID/AdID/IDFA, session navigation history and similar browsing metadata, and other data generated through applications and browsers, including cookies and similar technologies or other device identifiers or persistent identifiers), online user ID, device characteristics (such as browser/OS version), web server logs, application logs, first party cookies, third party cookies, web beacons, clear gifs and pixel tags.

General Location Data- Non-precise location data, e.g. location information derived from IP address or similar information.

Identity Data-Information such as your name; address; email address; telephone number; gender; date of birth, age and/or age range; account login details, e.g. username and password, avatar, or other account handles/usernames.

Preference Data-Personal Data generated reflecting your preferences, characteristics, predispositions, behavior, demographics, household characteristics, market segments, likes, favorites and similar data or analytics.

Sensitive Personal Data-Personal Data deemed “sensitive” under California or other laws, such as social security, driver’s license, state identification card, or passport number; account log-in and password, financial account, debit card, or credit card number; precise location data; racial or ethnic origin, religious or philosophical beliefs, etc. We collect the following categories of Sensitive Personal Data:

  • “Payment Data” Information such as bank account details, payment card information, including similar data protected as Sensitive Data under applicable law, and relevant information in connection with a financial transaction.

Transaction Data-Information about the Services we provide to you and about transactions you make with us and similar information. 

User Content-Unstructured/free-form data that may include any category of Personal Data, e.g. data that you give us in free text fields such as comment boxes.

Sources of Personal Data We Process

We collect Personal Data from various sources, which include:

Data you provide us-We receive Personal Data when you provide them to us, when you purchase our products or services, complete a transaction via our Services, or when you otherwise use our Services.

Data we collect automatically-We collect Personal Data about or generated by any device used to access our Services.

Service Providers-We receive Personal Data from service providers, such as our mailing list providers, who transfer Personal Data to us when performing services on our behalf, like sending marketing emails.

Merchants- if you are an individual user, we may receive Personal Data from the Merchants, who transfer Personal Data to us when you visit their online storefront hosted or supported by Big Cartel.

Advertising Service- We receive Personal Data from advertising services (e.g. third-party advertising platforms) and social media companies such as Meta (i.e. Facebook and Instagram) (“Advertisers”). We might collect this data when you use portions of our services that contain advertising pixels operated by that Advertiser or similar advertising integrations. 

Data we create or infer-We, certain partners, social media companies, and third parties operating on our behalf, create and infer Personal Data such as Preference Data or Aggregate Data based on our observations or analysis of other Personal Data processed under this Policy, and we may correlate this data with other data we process about you. 

DATA PROCESSING CONTEXTS / NOTICE AT COLLECTION

The following described how we collect and process data in when you interact with us in certain contexts. We provide additional information in our regional supplements and data retention disclosures, below.

Merchant Services

Accounts; Registration

We process Identity Data, Preference Data, Device/Network, General Location Data, and Contact Data when you register and create an account for Merchant Services. We process Transaction Data and Payment Data if you purchase a premium subscription, such as a Platinum or Diamond plan, and if you begin accepting transactions through your store’s account and associate your payment information with that account. 

We use this Personal Data to create and maintain your account, to provide the products and services you request, and for our Business Purposes. We may process Identity Data, Preference Data, and Contact Data for Marketing Communications. We do not sell or “share” Payment Data or use it for Business Purposes not permitted under applicable law.

Mobile App

If you use our mobile app to manage your Merchant Services, we may process Identity Data, Device/Network Data, Preference Data, and General Location Data.

We process this Personal Data to provide our mobile app, to deliver notifications that you request, and help Merchants interact with and manage their Merchant Services. We also process this Personal Data for our Business Purposes, and our other legitimate interests, such as: 

  • Optimizing the display and functionality of the mobile app on your device; 
  • Understanding how users use our mobile app, the features they use, and display relevant information to you; and
  • Creating deidentified and aggregate information about Merchant usage, which we use to help improve our Services. 

We may process this Personal Data in relation to our Marketing Communications or for Targeted Advertising.

Our Site

Generally

When you visit our Site, we process Device/Network Data, Contact Data, Identity Data, General Location Data, and Inference Data. You may also be able to register for a Merchant Account, enroll in Marketing Communications, or Contact Us through our Site. 

We use this Personal Data as necessary to operate our Site, for our Business Purposes, and our other legitimate interests, such as to ensure the security of our websites, mobile applications and other technology systems and to analyze the use of our Site, including navigation patterns, clicks, etc. to help understand and make improvements to the Site.

If you have a Merchant Account, we may process this Personal Data to keep you logged in to your account. We may process this Personal Data in relation to our Marketing Communications.

Cookies and other tracking technologies

We process Identity Data, Device/Network Data, Contact Data, Inference Data, General Location Data, and other non-identifying data in connection with our use of cookies and similar technologies on our Site. We may collect this data automatically. 

We and our third party service providers may use cookies and similar technologies for the following purposes:

  • For “essential” purposes necessary for our Site to operate (such as maintaining user sessions, CDNs, and the like);
  • For “functional” purposes, such as to enable certain features of our Site (for example, to enable shopping carts or similar functions); 
  • For “analytics” purposes and to improve our Site, such as to analyze the traffic to and on our Site (for example, we can count how many people have looked at a specific page, or see how visitors move around the website when they use it, to distinguish unique visits/visitors to our Site, and what website they visited prior to visiting our website, and use this information to understand user behaviors and improve the design and functionality of the website);
  • For “Targeted Advertising”, or similar advertising and marketing purposes, including technologies that process Inference Data or other data so that we can deliver, buy, or target advertisements which are more likely to be of interest to you. We and our social media partners may also engage in targeted advertising using data collected using cookies or similar technologies operated by a third-party social media platform, or when you otherwise link your account or engage with our content on or through a social networking website such as Facebook.

We may also process this Personal Data for our Business Purposes. See your Rights & Choices for information regarding opt-out rights for cookies and similar technologies.

Please note: Merchants may have the ability to install or collect data from cookies and other tracking technologies on their Merchant Stores, which may include such technologies that collect data for analytics, retargeting or social media. Please note that the Merchant, not Big Cartel, is the controller with respect to any cookies placed on a Merchant store by the Merchant or on its behalf, including stores those linked from Bigcartel.com.

Marketing Communications

We process Device/Network Data, Contact Data, Identity Data, and Inference Data in connection with marketing emails, SMS, push notifications, or similar communications marketing or promoting Big Cartel, or our Products and Services (“Marketing Communications”). We may also collect Device/Network Data and Identity Data when you open or interact with those communications. You may receive Marketing Communications if you consent and, in some jurisdictions, as a result of account registration or a transaction. 

We process this Personal Data to contact you about relevant products or services and for our Business Purposes. Marketing Communications may also be personalized as permitted by applicable law. See the “Personalization” section below for more information. See the Rights & Choices section to learn how to opt-out of Marketing Communications.

Contact us; support

We process Identity Data, Contact Data, and User Content when you contact us, e.g. through a contact us form, or for support. We process this Personal Data to respond to your request, and communicate with you, as appropriate, and for our Business Purposes. If you consent or if permitted by law, we may use Identity Data and Contact Data to send you Marketing Communications.

Posts and social media

We process Identity Data, Contact Data, and User Content if you interact with or identify us on social media or communication platforms. If you are a Merchant, we also process Identity Data and Contact Data if you choose to connect social media accounts with your Merchant Shop. We may also process this Personal Data for our Business Purposes.

Posts may be public, or reposted on our Services. Content you provide may be publicly-available when you post it on our Services, or in some cases, if you reference, engage, or tag our official social media accounts or communications platforms.

Feedback and surveys

We process Identity Data, Contact Data, Inference Data, and User Content collected in connection with Merchant or User surveys or questionnaires. 

We process this Personal Data as necessary to respond to requests/concerns, for our Business Purposes, and other legitimate interests, such as analyzing Merchant/User satisfaction and to communicate with Merchants and Users about their experience. In some cases, we may also process this data in connection with Marketing Communications, if relevant to your inquiry.

Contact Us

We process Identity Data, Device/Network Data, and any Personal Data contained within any User Content when you contact us using a contact phone number or via email, to ask a question, or request support. We may process Audio/Visual Data if you contact us via phone, leave a voicemail, or submit a photo with your request. 

We process Identity Data, Contact Data, User Content, and Audio/Visual Data as necessary to communicate with you about the subject matter of your request and related matters. We may also process this Personal Data for our Business Purposes, or in connection with Marketing Communications.

Professional Engagements

We process Identity Data, Contact Data, Biographical Data, and User Content in connection with your application for employment or other professional relationship with Big Cartel. We process this Personal Data as necessary to evaluate, establish, and maintain the professional relationship, and for our Business Purposes.

INFORMATION FOR MERCHANT CUSTOMERS

Big Cartel generally provides its services, solutions, and technical support to Merchants, and enable Merchants to host and operate the Merchant’s Store. If you visit a Store hosted or supported by Big Cartel, including those linked from Bigcartel.com or that are hosted on a Big Cartel subdomain, we may process Identity Data, Contact Data, and Device/Network Data on behalf of the Merchant. We may also process Transaction Data and Payment data if you make a purchase from that store.

We process this Personal Data only on behalf of the Merchant, and the Merchant is the controller of Personal Data processed in connection with the Merchant’s Store. However, note that we may also process some of this Personal Data for our Business Purposes and disclose it to Affiliates, Service Providers, Merchants, our Successors and other Lawful Recipients, in each case to the extent the law permits processors/service providers to do so.

Note, if you use our Site, become a Merchant or use Merchant Services, contact us, or interact with us via posts and social media, we may process your Personal Data for the purposes described further in our Policy.

PROCESSING PURPOSES

Business Purposes

We and our Service Providers process Personal Data we hold for numerous business purposes, depending on the context of collection, your Rights & Choices, and our legitimate interests. We generally process Personal Data for the following “Business Purposes.”

Service Delivery

We process Personal Data as necessary to provide our Services and the products and services you purchase or request. For example, we process Personal Data to authenticate Merchants and their rights to access their account Services, or as otherwise necessary to fulfill our contractual obligations to you, provide you with the information, features, and services you request, and create relevant documentation.

Internal Processing and Service Improvement

We may use any Personal information Data we process through our Services as necessary in connection with our improvement of the design and functionality of our Services, understanding how the Services are used, for customer service purposes, in connection with the creation and analysis of logs and metadata relating to Services use, and to develop new features of the Services. Additionally, we may use Personal Data information to understand what parts of our Services are most relevant to users, how users interact with various aspects of our Services, how our Services perform or fail to perform, etc.

Security and Incident Detection

We may process Personal Data in connection with our legitimate interest in ensuring that our Services, are secure, identify and prevent crime, prevent fraud, verify or authenticate users/individuals, and ensure the safety of our Merchants and users. Similarly, we process Personal Data as necessary to detect security incidents, protect against, and respond to malicious, deceptive, fraudulent, or illegal activity. We may analyze network traffic, device patterns, and characteristics, maintain and analyze logs and process similar Personal Data in connection with our information security activities.

Personalization

We process certain Personal Data as necessary in connection with our legitimate interest in personalizing our Services. For example, interfaces, content, or aspects of our Services may change so they are more relevant to you and/or your marketplace. We may personalize based on Inference Data and your current interactions with the Service, or obtain it from third parties, using Personal Data we hold about you.

Aggregated Data

We process Personal Data in order to identify trends, including to create aggregated and anonymized data about buying and spending habits, use of our Services, and other similar information (“Aggregated Data”). Aggregated Data that does not contain Personal Data is not subject to this Policy.

Transactional Communications

We may process Contact Data in order to send you transactional communications relating to your account or use of our Services, e.g. as records of transactions, to send alerts (e.g. re downtime, maintenance, or in relation to suspect transactions or logins), or for authentication. 

Compliance, Health, Safety, Public Interest

We may also process Personal Data as necessary to comply with our legal obligations, such as where you exercise your rights under data protection law, for the establishment and defense of legal claims, where we must comply with requests from government or law enforcement officials, and as may be required to meet national security or l

aw enforcement requirements or prevent illegal activity. We may also process data to protect the vital interests of individuals, or on certain public interest grounds, each to the extent required or permitted under applicable law. Please see the data sharing section for more information about how we disclose Personal Data in extraordinary circumstances.

Targeted Advertising

We and our third-party advertising providers may engage in display advertising or place third-party advertisements for third parties’ products and services on our Site. Such advertising may involve the processing of Personal Data in order to tailor the advertisements you see based on your interests (“Targeted Advertising”). The profiles and interests used for Targeted Advertising may be inferred or derived from Personal Data that we or those third parties obtain or infer from your activities across non-affiliated websites, applications, or services (e.g. through Cookies and Similar Technologies). Note that Targeted Adverting includes various parties and service providers, including third party data controllers, engaged in the processing of Personal Data in connection with Targeted Advertising. These parties may be able to identify you across sites, devices, and over time. In some cases, these third parties may build or augment user profiles using your Personal Data, and may track whether you view, interact with, or how often you have seen an ad, or whether you purchased advertised goods or services.

DISCLOSURE/SHARING OF PERSONAL DATA

We may share Personal Data with the following categories of third-party recipients and/or for the following reasons:

Corporate Affiliates

In order to streamline certain business operations and develop products and services that better meet the interests and needs of our customers, we may share your Personal Data with any of our current or future affiliated entities, subsidiaries, and parent companies. 

Service Providers

In connection with our general business operations, product improvements, to enable certain features, and in connection with our other lawful business interests, we may share Personal Data with service providers or subprocessors who provide certain services to us, or process data on our behalf. For example, we may use third party hosting providers to host our sites or content, third-party payment processors to process transactions, or to distribution partners to make sure you receive the product(s) you purchase. 

Merchants

if you are an individual user, we may share certain Personal Data with the Merchants with whom you interact, including via browsing, contacting, or making purchases through their online marketplaces.

Advertisers

We share certain Personal Data with Advertisers in connection with Targeted Advertising. For example, we might share this data when you use portions of our Services that contain pixels or advertising integrations operated by that Advertiser. 

Public Disclosure

 If you interact with us or our Services via social media, we may make your post available on our Services or to the general public. We may share, rebroadcast, or redisplay Personal Data or other information in the post to the extent permitted by the relevant social media service.

Corporate Events

Your Personal Data may be disclosed to a third party in the event that we go through a business transition, such as a merger, acquisition, liquidation, or sale of all or a portion of our assets. For example, Personal Data may be part of the assets transferred, or may be disclosed (subject to confidentiality restrictions) during the due diligence process for a potential transaction.

Lawful Recipients

In limited circumstances, we may, without notice or your consent, access and disclose your Personal Data, any communications sent or received by you, and any other information that we may have about you to the extent we believe such disclosure is legally required, to prevent or respond to a crime, to investigate violations of our Terms of Use, in the vital interests of us or any person (such as where we reasonably believe the use or disclosure is necessary to lessen or prevent a serious threat to the life, health or safety of any individual or to public health or safety) or in such other circumstances as may be required or permitted by law. These disclosures may be made to governments that do not ensure the same degree of protection of your Personal Data as your home jurisdiction. We may, in our sole discretion (but without any obligation), object to the disclosure of your Personal Data to such parties.

YOUR RIGHTS & CHOICES

You may have certain rights and choices regarding the Personal Data we process. Please note, these rights may vary based on the country or state where you reside, and our obligations under applicable law. See the following sections for more information regarding your rights/choices in specific regions:

  • US States/California
  • EU/EEA/UK/Switzerland
  • Australia/New Zealand

Your Rights

You may have certain rights and choices regarding the Personal Data we process. See the “Regional Supplements” section below for rights available to you in your jurisdiction. To submit a request, contact our Data Privacy Team. We verify your identity in connection with most requests, as described below.

Verification of Rights Requests

If you submit a request, we typically must verify your identity to ensure that you have the right to make that request, reduce fraud, and to ensure the security of Personal Data. If an agent is submitting the request on your behalf, we reserve the right to validate the agent’s authority to act on your behalf. 

We may require that you match personal information we have on file in order to adequately verify your identity. If you have an account, we may require that you log into the account to submit the request as part of the verification process. We may not grant access to certain Personal Data to you if prohibited by law.

Your Choices

Marketing Communications

You can withdraw your consent to receive marketing communications by clicking on the unsubscribe link in an email (for email), by responding with “OPT-OUT,” “STOP,” or other supported unsubscribe message (for SMS), by adjusting the push message settings for our mobile apps using your device operating system (for push notifications), or for other communications, by contacting us using the information below. To opt-out of the collection of information relating to email opens, configure your email so that it does not load images in our emails.

You may withdraw any consent you have provided at any time. The consequence of you withdrawing consent might be that we cannot perform certain services for you, such as location-based services, personalizing or making relevant certain types of advertising, or other services conditioned on your consent or choice not to opt-out.

Cookies and Similar Technologies

We currently allow merchants to integrate with google analytics and utilize cookies on their online marketplaces. Big Cartel does not place non-essential cookies at this time. If you encounter cookies on a Merchant’s online marketplace, and you do not want information collected through the use of those cookies, you can manage/deny cookies (and certain technologies) using your browser’s settings menu or our Manage Cookies page. You may need to opt out of third-party services directly via the third party. For example, to opt-out of Google’s analytic and marketing services, visit Google Analytics Terms of Use, the Google Policy, or Google Analytics Opt-out.

Targeted Advertising

You may opt out or withdraw your consent to Targeted Advertising by using the “Manage Cookies” link in the footer of this page. In some cases, you may be able to opt-out by submitting requests to third party partners, including for the vendors listed below: 

Global Privacy Control (GPC)

Our Site may support certain automated opt-out controls, such as Global Privacy Control (“GPC”). GPC is a specification designed to allow Internet users to notify businesses of their privacy preferences, such as opting-out of the sale/sharing of Personal Data. To activate GPC, users must enable a setting or use an extension in the user’s browser or mobile device. Please review your browser or device settings for more information regarding how to enable GPC. 

Please note: We may not be able to link GPC signals to your Personal Data in our systems, and as a result, some sales/sharing of your Personal Data may occur even if GPC is active. See the “Regional Supplements” section below for more information regarding other opt-out rights.

Do-Not-Track 

Our Services do not respond to your browser’s do-not-track request. 

DATA SECURITY

We implement and maintain reasonable security measures to safeguard the Personal Data you provide us. However, we sometimes share Personal Data with third parties as noted above, and though we may take certain measures to help ensure the security of your Personal Data, we do not control third parties’ security processes. We do not warrant perfect security and we do not provide any guarantee that your Personal Data or any other information you provide us will remain secure.

INTERNATIONAL TRANSFERS

If you are located outside the US, we may transfer or process your Personal Data in the US and other jurisdictions where Big Cartel or our service providers operate. Where required by local law, we ensure your data remains protected in connection with any international transfers. See the “Regional Supplements” section below for more information.

CHILDREN

Our Services are neither directed at nor intended for use by persons under the age of 13 in the US, or under the age defining a child under applicable privacy law in other jurisdictions. We do not knowingly collect information from such individuals. If we learn that we have inadvertently done so, we will promptly delete such Personal Data if required by law. Do not access or use the Services if you are not of the age of majority in your jurisdiction unless you have the consent of your parent or guardian.

DATA RETENTION

We retain Personal Data for so long as it is reasonably necessary to achieve the relevant processing purposes described in this Policy, or for so long as is required by law. What is necessary may vary depending on the context and purpose of processing. We generally consider the following factors when we determine how long to retain data (without limitation):

  • Retention periods established under applicable law;
  • Industry best practices;
  • Whether the purpose of processing is reasonably likely to justify further processing;
  • Risks to individual privacy in continued processing;
  • Applicable data protection impact assessments;
  • IT systems design considerations/limitations; and
  • The costs associated continued processing, retention, and deletion.

We will review retention periods periodically and may pseudonymize or anonymize data held for longer periods.

CHANGES TO OUR POLICY

We may change this Policy from time to time. If we make changes, we will notify you by posting here with a revised date at the top of the Policy. We will notify you of any material changes, if required, via email or notices on our Services. We encourage you to review the Policy whenever you access the Services or otherwise interact with us to stay informed about our information practices and the choices available to you. Your continued use of our Services constitutes your acknowledgement of any revised Policy.

REGIONAL SUPPLEMENTS

US States/California

US State & California Privacy Rights & Choices

Under the California Consumer Privacy Act (“CCPA”) and other state privacy laws, residents of certain US states may have the following rights, subject to regional requirements, exceptions, and limitations. 

Confirm- Right to confirm whether we process your Personal Data. 

Access/Know- Right to request any of following: (1) the categories of Personal Data we have collected, sold/shared, or disclosed for a commercial purpose; (2) the categories of sources from which your Personal Data was collected; (3) the purposes for which we collected or sold/shared your Personal Data; (4) the categories of third parties to whom we have sold/shared your Personal Data, or disclosed it for a business purpose; and (5) the specific pieces of Personal Data we have collected about you.

Portability- Right to request that we provide certain Personal Data in a common, portable format. 

Deletion- Right to delete certain Personal Data that we hold about you.

Correction- Right to correct certain Personal Data that we hold about you.

Non-Discrimination- California residents have the right to not to receive discriminatory treatment as a result of your exercise of rights conferred by the CCPA.

List of Direct Marketers- California residents may request a list of Personal Data we have disclosed about you to third parties for direct marketing purposes during the preceding calendar year.

Remove Minors’ User Content- Residents of California under the age of 18 can delete or remove posts using the same deletion or removal procedures described above, or otherwise made available through the Services. If you have questions about how to remove your posts or if you would like additional assistance with deletion, contact us using the information below. We will work to delete your information, but we cannot guarantee comprehensive removal of that content or information posted through the Services.

Submission of Requests

You may submit requests as follows (please our review verification requirements section). If you have any questions or wish to appeal any refusal to take action in response to a rights request, contact us at privacy@bigcartel.com. We will respond to any request to appeal within the period required by law. 

Opt - Out of Targeted Advertising and data “Sharing”:

  • Use the “Manage Cookies” link in the footer of this pag[1] [2] [3]e.
  • You may enable Global Privacy Control (GPC) to opt out of data sales or “sharing” using Cookies and Similar Technologies. Services supporting GPC (or similar standards) will treat the request as a request to opt - out of such sales or “sharing”

Opt - out of Sales / Limit Use of Sensitive Personal Data:

Access/Know; Confirm Processing; Portability; Deletion; Correction:

Categories of Personal Data Disclosed for Business Purposes

For purposes of the CCPA, we have disclosed to Service Providers for “business purposes” in the preceding 12 months the following categories of Personal Data, to the following categories of recipients: 

  • Data: Identity Data; Contact Data; Device/Network Data; General Location Data; Identity Data; Inference Data; Transactional Data; User Content:
    - Shared With: Service Providers; Merchants; Corporate Events; Corporate Affiliates; Legal Disclosure; Public Disclosure
  • Data: Payment Data
    - Shared With: Service Providers; Corporate Events; Corporate Affiliates; Legal Disclosure

Categories of Personal Data Sold, “Shared,” or Disclosed for Commercial Purposes

For purposes of the CCPA, we have “sold” or “shared” in the preceding 12 months the following categories of Personal Data in the, to the following categories of recipients: 

  • Data: Contact Data (non-SMS); Device/Network Data; General Location Data; Identity Data; Inference Data; Transaction Data; User Content
    - Shared With: Brand Partners and Advertisers; Social Media Companies; Public Disclosure

Categories of Sensitive Personal Data Used or Disclosed

For purposes of CCPA, we may use or disclose the following categories of Sensitive Personal Data: Payment Data. We do not sell or “share” Sensitive Personal Data.

EEA/UK/Switzerland

Controller

The controller of Personal Data relating to residents of the UK/EEA/Switzerland is: Big Cartel, LLC, located at 50 W. Broadway #333 PMB 40632, Salt Lake City, UT 84101, U.S.A. 

Rights & Choices

Residents of the EEA, UK, and Switzerland have the following rights. Please our review verification requirements. Applicable law may provide exceptions and limitations to all rights.

Access-You may have a right to access the Personal Data we process.

Rectification-You may correct any Personal Data that you believe is inaccurate.

Deletion-You may request that we delete your Personal Data. We may delete your data entirely, or we may anonymize or aggregate your information such that it no longer reasonably identifies you. 

Data Export-You may request that we send you a copy of your Personal Data in a common portable format of our choice. 

Restriction-You may request that we restrict the processing of 1a to what is necessary for a lawful basis.

Objection-You may have the right under applicable law to object to any processing of Personal Data based on our legitimate interests. We may not cease or limit processing based solely on that objection, and we may continue processing where our interests in processing are appropriately balanced against individuals’ privacy interests. In addition to the general objection right, you may have the right to object to processing:

  • for “profiling” purposes (if any);
  • for direct marketing purposes (we will cease processing upon your objection); and
  • involving automated decision-making with legal or similarly significant effects (if any).

Regulator Contact-You have the right to file a complaint with regulators about our processing of Personal Data. To do so, please contact your local data protection or consumer protection authority.

Submission of Requests

You can submit your requests as follows:

Access, Rectification, Data Export, Deletion, Restriction, or Correction:

o   You may visit our Privacy Rights Request Form

o   You may send postal mail to our physical address (see Contact Us above) with your email address, phone number and address we have on file, along with your request.

Opt-out of Targeted Advertising

o   Use the “Manage Cookies” link in the footer of this page.

Lawful Basis for Processing

We process your Personal Data on one of the following legal bases, as described below:

Performance of a contract

The processing of your Personal Data is strictly necessary in the context in which it was provided, e.g. to perform the agreement you have with us, to provide Services to you, to open and maintain your Merchant or user accounts, or process requests.

  • Contexts
    - Cookies and other tracking technologies (strictly necessary)
  • Purposes
    - Service Delivery
  • Disclosures
    - Affiliates
    - Merchants
    - Service Providers
    - Public Disclosure
    - Successors
    - Lawful Recipients
Legitimate interests

This processing is based on our legitimate interests. For example, we rely on our legitimate interest to administer, analyze and improve our Websites and related content, to operate our business including through the use of service providers and subcontractors, to send you notifications about our Services or products you have purchase, for archiving, recordkeeping, statistical and analytical purposes, and to use your Personal Data for administrative, fraud detection, audit, training, security, or legal purposes. See the “Business Purposes” section above for more information regarding the nature of processing performed on the basis of our legitimate interests.

  • Contexts
    - Contexts where Personal Data (excluding Sensitive Personal Data) is processed for specified legitimate interests or purposes listed below
  • Purposes
    - Internal Processing and Service Improvement
    - Security and Incident Detection
    - Personalization
    - Aggregated Data
    - Transactional Communications
  • Disclosures
    - Affiliates
    - Merchants
    - Service Providers
    - Successors
    - Lawful Recipients

This processing is based on your consent. You are free to withdraw any consent you may have provided, at any time, subject to your rights/choices, and any right to continue processing on alternative or additional legal bases. Withdrawal of consent does not affect the lawfulness of processing undertaken prior to withdrawal.

  •  Contexts
    - Cookies and other tracking technologies (except strictly necessary)
    - Processing of Sensitive Personal Data
    - Marketing Communications
    - Targeted Advertising
  • Disclosures
    - Advertisers

This processing is based on our need to comply with legal obligations. We may use your Personal Data to comply with legal obligations to which we are subject, including to comply with legal process. See the Business Purposes of Processing section above for more information regarding the nature of processing performed for compliance purposes.

  • Business Purposes
    - Compliance, Health, Safety, Public Interest
  • Disclosures
    - Lawful Recipients
Performance of a task carried out in the public interest

This processing is based on our need to protect recognized public interests. We may use your Personal Data to perform a task in the public interest or that is in the vital interests of an individual. See the Business Purposes of Processing section above for more information regarding the nature of processing performed for such purposes.

  • Business Purposes
    - Compliance, Health, Safety, Public Interest
  • Disclosures
    - Lawful Recipients

International Transfers

We process data in the United States, and other countries where our subprocessors are located. In cases where we transfer Personal Data to jurisdiction that have not been determined to provide “adequate” protections by your home jurisdiction, we will put in place appropriate safeguards to ensure that your Personal Data are properly protected and processed only in accordance with applicable law. Those safeguards may include the use of EU standard contractual clauses, reliance on the recipient’s Binding Corporate Rules program, or requiring the recipient to certify to a recognized adequacy framework. You can obtain more information about transfer measures we use for specific transfers by contacting us using the information above.

Australia/New Zealand

Rights and Choices

Residents of Australia and New Zealand have the following right in their Personal Data under their respective Privacy Acts.

Access - You may request a copy of your Personal Data that we hold about you.

Correction - You may seek to correct any Personal Data that we hold about you. With respect to data processed in the context of your Big Cartel account, you may be able to make changes via your account settings menu.

Withdraw Consent - If you have provided your consent to Process Personal Data, you may withdraw it at any time.

Erasure - You may request that we delete your Personal Data.

Purposes of Processing 

In certain cases, we may not automatically process your Personal Data for certain purposes. We rely on your consent to process Personal Data as follows: 

Sources of Personal Data 

  • Service Providers

Contexts 

  • Cookies and other tracking technologies (except strictly necessary)
  • Any context where we process Sensitive Personal Data
  • Marketing communications 
  • Targeted Advertising

Purposes

  • Marketing Communications
  • Cookies and other tracking technologies for Targeted Advertising

Disclosures

  • Service Providers
  • Advertisers

Consequences of not providing information

If you do not provide information that we need in order to provide our Services, we will not be able to perform certain Services for you, such as personalizing or making relevant certain types of advertising, or other Services conditioned on your consent.

Information about Third Parties 

We receive any Personal Data that you provide to us about third parties on the understanding that you have the relevant individual's consent for us to collect and handle their personal information in accordance with this Policy.

Complaints

If you have a complaint about the way in which Big Cartel handles your personal information under Australian privacy laws, or you believe that a breach of your privacy has occurred, please contact Big Cartel using the details in the section How to Contact Us.

Your complaint will be considered and dealt with by a Big Cartel nominated representative, who may escalate the complaint internally within the organization if the matter is serious or if necessary to resolve it.

Please allow Big Cartel a reasonable time to respond to your complaint. If you are not satisfied with Big Cartel’s resolution, you may make a complaint to the Office of the Australian Information Commissioner, whose contact details can be found at: https://www.oaic.gov.au (if you reside in Australia), or to the Office of the Privacy Commissioner, whose contact details can be found at https://www.privacy.org.nz (if you reside in New Zealand).

Submission of Requests

General Inquiries:  support@bigcartel.com

Data Rights Requests: Visit the Privacy Rights Request Form.

Targeted Advertising: You can opt - out of Targeted Advertising using the “Manage Cookies” link in the footer of this page.

Marketing Communications:  Click unsubscribe in the email

Physical Address: Big Cartel, LLC, Attn: Privacy. 50 W. Broadway #333 PMB 40632, Salt Lake City, UT 84101, U.S.A.