Pillow Pop Privacy Policy
Effective Date: October 21, 2025
At Pillow Pop, we take your privacy and the security of your personal information seriously. This Privacy Policy explains how we collect, use, store, and protect the information you provide when using our website (including mobile and desktop versions), placing orders, customizing products, or interacting with our customer service. By accessing or using our services, you acknowledge that you have read, understood, and agreed to the practices described in this policy. We comply with applicable data protection laws worldwide, including the General Data Protection Regulation (GDPR) for EU residents and the California Consumer Privacy Act (CCPA) for California residents .
1. Information We Collect
We only collect information necessary to provide and improve our services, following the principles of “legitimacy, necessity, and good faith” . The information we gather falls into three categories:
1.1 Information You Voluntarily Provide
- Account & Identity Details: When creating an account, you may provide your full name, email address, phone number, and password. For order fulfillment, we require shipping addresses (including recipient name if different from yours) .
- Transaction & Payment Information: To process purchases, we collect order details (e.g., product type, size, quantity), billing address, and payment method information (e.g., credit card number, PayPal account ID). We do not store full credit/debit card numbers—this data is processed directly by our PCI DSS-compliant payment partners .
- Custom Product Data: For personalized items (e.g., photo print pillows, embroidered text pillows), you may upload images, enter text, or specify design preferences. You confirm that you own or have legal rights to any content you submit .
- Customer Support & Feedback: When contacting our support team (via email, chat, or form), you may share questions, complaints, or feedback—including photos/videos of products (e.g., for return requests) .
1.2 Information Automatically Collected
- Device & Usage Data: We use cookies, web beacons, and server logs to collect your device model, operating system, IP address, browser type, network connection, and browsing behavior (e.g., pages viewed, products clicked, time spent on the site). This helps us optimize site performance and personalize your experience .
- Location Information: If you enable location permissions or enter a shipping address, we collect approximate location data (e.g., city/region) to estimate delivery times and offer region-specific promotions. You can disable this at any time in your device settings .
1.3 Information from Third Parties
With your consent or as required by business needs, we may obtain information from trusted third parties:
- Logistics providers: Shipping and delivery status updates (e.g., tracking numbers, delivery confirmation) .
- Payment processors: Verification of payment status to complete transactions .
- Identity verification services: Only used to confirm your identity for high-value orders or account security checks .
2. How We Use Your Information
We use your personal information exclusively for the purposes disclosed below, and never for unstated reasons without your consent:
2.1 Order Fulfillment & Service Delivery
- Process and track your orders (including custom production for personalized pillows).
- Coordinate with logistics partners to deliver products to your specified address.
- Send order updates (e.g., “order confirmed,” “shipped,” “delivered”) via email or SMS .
- Handle returns, exchanges, and refunds by verifying purchase details and product conditions .
2.2 Customer Support & Account Management
- Respond to your inquiries, resolve issues (e.g., sizing questions, damaged products), and provide post-purchase assistance.
- Manage your account (e.g., update profile details, view order history, save favorite products) .
2.3 Service Improvement & Personalization
- Send promotional content (e.g., sale alerts, new collection announcements) via email or SMS—only if you have opted in. You can unsubscribe at any time using the “unsubscribe” link in messages or through your account settings .
- Display personalized ads on our website or trusted third-party platforms (e.g., social media) based on your browsing history .
2.5 Security & Compliance
- Detect and prevent fraudulent activities (e.g., unauthorized account access, fake orders) .
- Maintain records for tax, accounting, and legal purposes (e.g., retaining order details for 7 years as required by financial regulations) .
- Comply with court orders, subpoenas, or other legal obligations .
3. Sharing Your Information
We never sell your personal information to third parties for marketing purposes. We only share data in the following limited circumstances:
3.1 Trusted Service Providers
We share minimal, necessary information with third parties who assist us in delivering services, all of whom are bound by confidentiality agreements:
- Payment processors: Receive order amounts and payment instructions to process transactions securely (e.g., Visa, PayPal) .
- Logistics partners: Receive shipping addresses and product details to deliver orders (e.g., USPS, FedEx) .
- Custom production vendors: For personalized pillows, we share your uploaded photos or text only to print/embroider your design .
- Technology providers: Receive usage data to maintain our website (e.g., server hosting) or provide analytics (e.g., Google Analytics) .
3.2 Legal Requirements
We may disclose information if compelled by valid legal processes (e.g., court orders, regulatory investigations) or to protect our rights, safety, or the safety of others .
3.3 Business Transfers
In the event of a merger, acquisition, or sale of all/part of our business, your information may be transferred to the new owner—who will be bound by this Privacy Policy .
3.4 Anonymized/De-Identified Data
We may share data that has been stripped of personal identifiers (e.g., “60% of customers prefer linen pillows”) with industry partners for market research .
4. Data Retention & Security
4.1 How Long We Keep Your Information
- Account & Order Data: Retained for 7 years after your last order (for tax and legal compliance) or until you request account deletion .
- Custom Product Content: Uploaded photos/text are retained for 1 year after order completion (to facilitate reorders) unless you request immediate deletion .
- Marketing Data: Retained until you unsubscribe or request removal .
- Automatically Collected Data: Retained for 2 years unless needed for security purposes .
4.2 Security Measures to Protect Your Data
We use industry-standard technical and administrative safeguards to prevent unauthorized access, loss, or misuse of your information:
- Encryption: Data in transit (e.g., payment details, custom photos) is encrypted via SSL/TLS, and data at rest is stored with AES-256 encryption .
- Access Controls: Only authorized team members (e.g., customer service reps, order processors) have role-based access to your data, and all employees complete privacy training .
- Security Audits: We conduct quarterly security reviews and real-time intrusion detection to identify and fix vulnerabilities .
- Breach Response: If a data breach occurs, we will notify affected users and regulatory authorities within 72 hours (as required by law) and take corrective action .
Your role in security: Keep your account password confidential, avoid using public Wi-Fi for purchases, and notify us immediately if you notice unauthorized account activity .
5. Your Rights & How to Exercise Them
Under applicable data protection laws, you have the following rights regarding your personal information:
5.1 Core Rights
- Access: Request a copy of the personal information we hold about you (e.g., order history, uploaded photos).
- Correction: Update inaccurate or incomplete data (e.g., a wrong shipping address).
- Deletion: Ask us to delete your data (except when retention is required by law, e.g., tax records).
- Withdraw Consent: Opt out of marketing communications or disable data collection for personalization (e.g., cookie settings).
- Data Portability: Request your data in a machine-readable format (e.g., CSV) to transfer to another service provider .
5.2 How to Submit Requests
- Account Portal: Update profile details, unsubscribe from marketing, or request account deletion directly in your “My Account” dashboard.
- Contact Us: For other requests (e.g., access to data, deletion of custom photos), email us at kiaradelma@gmail.com with the subject line “Privacy Request” and your full name/account email.
We will acknowledge your request within 48 hours and complete processing within 30 days (or as required by local law) .
6. Cookies & Tracking Technologies
Cookies are small text files stored on your device to enhance your browsing experience. We use two types of cookies:
6.1 Necessary Cookies
Required for our website to function (e.g., remembering your cart items, enabling login). These cannot be disabled without breaking core features .
6.2 Non-Necessary Cookies
Used for personalization and analytics (e.g., tracking which products you view, measuring site traffic). You can manage these in your browser settings (e.g., Chrome, Safari) by blocking or deleting cookies—though this may limit personalized features .
By continuing to use our website, you consent to our use of cookies as described herein .
7. Custom Product Data Considerations
For personalized pillows (e.g., photo prints, embroidered text), you retain ownership of any content you submit. However, you grant Pillow Pop a limited, non-exclusive license to use this content only to produce and deliver your custom order. We will never use your uploaded photos or text for marketing or other purposes without your explicit written consent .
8. Minors’ Privacy
Our services are not intended for individuals under the age of 13. We do not knowingly collect personal information from minors. If we discover we have collected data from a minor without parental consent, we will delete it immediately. Parents/guardians with questions can contact us at kiaradelma@gmail.com .
9. Changes to This Policy
We may update this Privacy Policy to reflect legal changes, new services (e.g., expanded custom options), or security improvements. When we make material changes, we will:
- Post the updated policy on our website with a new “Effective Date”;
- Notify registered users via email or in-site notification (for significant changes) .
Your continued use of our services after the update means you accept the revised policy. We encourage you to review this page periodically.
10. Contact Us
If you have questions, concerns, or privacy requests, please reach out to our Privacy Team:
- Email: kiaradelma@gmail.com