Privacy Policy for CribSaga.com

1. Introduction

At CribSaga.com, we are fully committed to protecting and respecting your personal data and privacy rights. We understand the importance of maintaining your trust and take our responsibilities under relevant data protection laws—including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA)—seriously. This Privacy Policy outlines how we collect, use, disclose, and protect your personal information when you interact with our website and services.

2. Scope of the Policy and Role as Data Controller

This Privacy Policy governs the processing of personal data collected through our website, CribSaga.com, and associated services or communications. For the purposes of applicable data protection legislation, CribSaga.com acts as the “data controller”—that is, the entity responsible for determining the purposes and means of the processing of your personal data.

3. Categories of Personal Data Processed

We may collect, use, store, and transfer the following categories of personal data:

a. Usage Data:
Information about how you interact with CribSaga.com, such as your IP address, browser type, device type, pages viewed, access times, and referral URLs.

b. Account Data:
Information you provide when creating or maintaining an account, including your full name, billing and shipping addresses, email address, and phone number.

c. Profile Data:
Information related to your preferences, shopping behaviors, purchase history, wishlists, and other personalized interactions.

d. Communication Data:
Records of your communications with us, including customer support inquiries, emails sent to [email protected], feedback, and other correspondence.

e. Technical Data:
Details about the device you use to access our website, operating system, mobile network, hardware model, system configuration, and browser settings.

f. Transaction Data:
Details of payments made, order details, delivery addresses, and confirmation of completed transactions.

g. Preference Data:
Information about your preferences for receiving marketing from us and your communication preferences, including consent records and interests in particular products or services.

4. Legal Bases for Processing Personal Data

We rely on the following lawful bases to process your personal information in accordance with GDPR:

– Legitimate Interests: Where we process your data to improve our services, for website analytics, or for fraud detection, provided your rights do not override these interests.
– Contractual Necessity: When processing is necessary to fulfill a contract with you, such as delivering items or managing your account.
– Legal Obligation: Where processing is required to comply with a legal requirement.
– Consent: When we rely on your consent for marketing communications or non-essential cookies. You are free to withdraw your consent at any time.

For individuals protected under the CCPA, we disclose our data practices and respect your additional rights as detailed below.

5. Your Rights

As a data subject under applicable data protection laws, you may have the following rights regarding your personal data:

– Access: Request a copy of the personal data we hold about you.
– Rectification: Ask us to correct any inaccurate or incomplete data.
– Erasure: Request deletion of your personal data, subject to exceptions.
– Restriction: Ask us to limit the processing of your data in certain circumstances.
– Portability: Receive your data in a structured, machine-readable format and have it transmitted to another controller, where feasible.
– Objection: Object to processing based on legitimate interests or for direct marketing.
– Withdrawal of Consent: Withdraw previously given consent without affecting lawfulness of prior consent-based processing.

You may exercise these rights by contacting us at [email protected].

6. Security Measures

We implement appropriate technical and organizational measures to ensure the integrity, confidentiality, and availability of your personal data, including:

– Encryption of data in transit and at rest
– Role-based access control and least-privilege principles
– Regular system backups and disaster recovery protocols
– Employee training and internal data handling policies

Despite our best efforts, no digital platform is entirely immune to risks, and we encourage users to remain vigilant.

7. International Transfers

Certain service providers we work with may be located outside your jurisdiction. Where your personal data is transferred internationally, we ensure appropriate safeguards are in place, including:

– Use of Standard Contractual Clauses approved by the European Commission
– Compliance with regional data protection regulations
– Vetting of third-party processors for data protection adequacy

8. Data Retention

We retain personal data only as long as necessary to fulfill the purposes for which it was collected, including:

– Account Data: As long as your account remains active or until deletion is requested
– Transaction Data: Up to 7 years for financial and regulatory compliance
– Communication Data: Up to 3 years from last interaction
– Marketing Preferences: Until revoked or 2 years after inactivity
– Usage & Technical Data: Anonymized or deleted within 26 months

9. Cookie Policy

CribSaga.com uses cookies and similar tracking technologies to enhance user experience and to collect information about your browsing activity. Our categories of cookies include:

– Essential Cookies: Necessary for basic site functionality and login security.
– Functional Cookies: Enable features like remembering your preferences.
– Analytics Cookies: Collect aggregated data about site usage and traffic patterns.
– Performance Cookies: Help us improve website speed, responsiveness, and error management.

10. Cookie Management and Compliance

We provide clear opt-in choices for cookies through a cookie banner, in compliance with GDPR. You may manage or disable cookies via your browser settings or by using our cookie management tool. California residents have additional rights under CCPA to opt-out of “sale” of personal data, and we honor user-enabled global privacy controls where applicable.

11. Protections for Children

CribSaga.com does not knowingly collect or solicit personal data from children under the age of 13. If you are a parent or guardian and believe that your child has provided us with personal data, please contact us at [email protected] so that we may promptly delete the information.

12. Policy Updates and Notifications

We reserve the right to update or modify this Privacy Policy at any time to reflect changes in our practices or legal obligations. When changes are made, we will update the content on CribSaga.com and, where necessary, provide notice via email or other appropriate methods.

13. Contacting Us

If you have any questions about this Privacy Policy, your data rights, or our overall privacy practices, please contact our Data Protection Officer at:

Email: [email protected]

We are fully committed to complying with all applicable data protection laws and maintaining transparency in how we handle your personal information. You are encouraged to reach out to us with any privacy concerns or requests.