Privacy & Security Policy

Who we are

We are Gems By The Creek. Our website address is: https://www.gemsbythecreek.com. Our operations are run from an office in Loveland, CO, USA. Gems By The Creek is first and foremost in the business of selling vintage and antique jewelry. The information we collect is used to improve your experience on our website, process your orders, ship you the product(s) that you order, receive communications regarding your order, and send you special offers if you opt-in to receive them. We are not data brokers and we do not sell your information to anybody. We are mindful of what data we collect and how it is stored, which is why never see and never have access to your credit card information. Credit card information is securely transmitted to our payment processing vendor, and a “success” token is sent back to us to let us know the transaction was successful. For more details, continue reading.

What personal data we collect and why we collect it

While you visit our site, we’ll track:

  • Products you’ve viewed: we’ll use this to, for example, show you products you’ve recently viewed
  • Location, IP address and browser type: we’ll use this for purposes like estimating taxes and shipping
  • Shipping address: we’ll ask you to enter this so we can, for instance, estimate shipping before you place an order, and send you the order!

We’ll also use cookies to keep track of cart contents while you’re browsing our site.

When you purchase from us, we’ll ask you to provide information including your name, billing address, shipping address, email address, phone number, credit card/payment details and optional account information like username and password. We’ll use this information for purposes, such as, to:

  • Send you information about your account and order
  • Respond to your requests, including refunds and complaints
  • Process payments and prevent fraud
  • Set up your account for our store
  • Comply with any legal obligations we have, such as calculating taxes
  • Improve our store offerings
  • Send you marketing messages, if you choose to receive them

If you create an account, we will store your name, address, email and phone number, which will be used to populate the checkout for future orders.

We generally store information about you for as long as we need the information for the purposes for which we collect and use it, and we are not legally required to continue to keep it. For example, we will store order information for 5 years for tax and accounting purposes. This includes your name, email address and billing and shipping addresses.

We will also store comments or reviews, if you choose to leave them.

MailChimp: When shopping, we keep a record of your email and the cart contents for up to 30 days on our server. This record is kept to repopulate the contents of your cart if you switch devices or needed to come back another day. Read our privacy policy here.

WooCommerce Services: For taxes: the value of goods in the cart, value of shipping, destination address. For checkout rates: destination address, purchased product IDs, dimensions, weight, and quantities. For shipping labels: customer’s name, address as well as the dimensions, weight, and quantities of purchased products. For payments: we send the purchase total, currency and customer’s billing information to the respective payment processor. Please see the respective third party’s privacy policy (Square’s Privacy Policy) for more details. For automated taxes we send the value of goods in the cart, the value of shipping, and the destination address to TaxJar. Please see TaxJar’s Privacy Policy for details about how they handle this information. For checkout rates we send the destination ZIP/postal code and purchased product dimensions, weight and quantities to USPS. For shipping labels we send the customer’s name, address as well as the dimensions, weight, and quantities of purchased products to EasyPost. We also store the purchased shipping labels on our server to make it easy to reprint them and handle support requests.

Contact forms

There are several forms located on our website that allow you to contact us. The data collected by these forms include all of the fields in the form as well as your IP address. The data collected by these forms is purged periodically and is used for no other purpose except

Embedded content from other websites

We display a feed from our Instagram account.

Who we share your data with and where we send your data

Gems By The Creek

Members of our team have access to the information you provide us. For example, both Administrators and Shop Managers can access:

    • Order information like what was purchased, when it was purchased and where it should be sent, and
    • Customer information like your name, email address, and billing and shipping information.

Our team members have access to this information to help fulfill orders, process refunds and support you. Out team members never have access to your credit card information.

MailChimp

When shopping, we keep a record of your email and the cart contents for up to 30 days on our server. This record is kept to repopulate the contents of your cart if you switch devices or needed to come back another day. Read our privacy policy here.

Jetpack WooCommerce Services

For taxes: The value of goods in the cart, value of shipping, destination address. For automated taxes we send the value of goods in the cart, the value of shipping, and the destination address to TaxJar. Please see TaxJar’s Privacy Policy for details about how they handle this information. 

For checkout rates: Destination address, purchased product IDs, dimensions, weight, and quantities. For checkout rates we send the destination ZIP/postal code and purchased product dimensions, weight and quantities to USPS.

For shipping labels: Customer’s name, address as well as the dimensions, weight, and quantities of purchased products. For shipping labels we send the customer’s name, address as well as the dimensions, weight, and quantities of purchased products to EasyPost. We also store the purchased shipping labels on our server to make it easy to reprint them and handle support requests.

For payments: We send the purchase total, currency and customer’s billing information to the respective payment processor. Please see the respective third party’s privacy policy (Square’s Privacy Policy) for more details.  

Jetpack Activity

This feature only records activities of a site’s registered users, and the retention duration of activity data will depend on the site’s plan and activity type.

Data Used: To deliver this functionality and record activities around site management, the following information is captured: user email address, user role, user login, user display name, WordPress.com and local user IDs, the activity to be recorded, the WordPress.com-connected site ID of the site on which the activity takes place, the site’s Jetpack version, and the timestamp of the activity. Some activities may also include the actor’s IP address (login attempts, for example) and user agent.

Activity Tracked: Login attempts/actions, post and page update and publish actions, comment/pingback submission and management actions, plugin and theme management actions, widget updates, user management actions, and the modification of other various site settings and options. Retention duration of activity data depends on the site’s plan and activity type. See the complete list of currently-recorded activities (along with retention information).

Data Synced (?): Successful and failed login attempts, which will include the actor’s IP address and user agent.

Jetpack Gravatar Hovercards

Data Used: This feature will send a hash of the user’s email address (if logged in to the site or WordPress.com — or if they submitted a comment on the site using their email address that is attached to an active Gravatar profile) to the Gravatar service (also owned by Automattic) in order to retrieve their profile image.

Jetpack Protect

Data Used: In order to check login activity and potentially block fraudulent attempts, the following information is used: attempting user’s IP address, attempting user’s email address/username (i.e. according to the value they were attempting to use during the login process), and all IP-related HTTP headers attached to the attempting user.

Activity Tracked: Failed login attempts (these include IP address and user agent). We also set a cookie (jpp_math_pass) for 1 day to remember if/when a user has successfully completed a math captcha to prove that they’re a real human. Learn more about this cookie.

Data Synced (?): Failed login attempts, which contain the user’s IP address, attempted username or email address, and user agent information.

Jetpack WordPress.com Stats

Data Used: IP address, WordPress.com user ID (if logged in), WordPress.com username (if logged in), user agent, visiting URL, referring URL, timestamp of event, browser language, country code. Important: The site owner does not have access to any of this information via this feature. For example, a site owner can see that a specific post has 285 views, but he/she cannot see which specific users/accounts viewed that post. Stats logs — containing visitor IP addresses and WordPress.com usernames (if available) — are retained by Automattic for 28 days and are used for the sole purpose of powering this feature.

Activity Tracked: Post and page views, video plays (if videos are hosted by WordPress.com), outbound link clicks, referring URLs and search engine terms, and country. When this module is enabled, Jetpack also tracks performance on each page load that includes the Javascript file used for tracking stats. This is exclusively for aggregate performance tracking across Jetpack sites in order to make sure that our plugin and code is not causing performance issues. This includes the tracking of page load times and resource loading duration (image files, Javascript files, CSS files, etc.). The site owner has the ability to force this feature to honor DNT settings of visitors. By default, DNT is currently not honored.

SendGrid

We use SendGrid to facilitate the sending of even-triggered emails such as the completion of a purchase to ourselves and you. See SendGrid’s privacy policy here.

Square

We use Square to facilitate the completion of credit card transactions both over the website and in-person. See Square’s privacy policy here.

How long we retain your data

Accounts are determined to be inactive if the accounts have not logged in or placed an order for 5 years. Once an account has become inactive, it will be deleted and order history for that account will be converted into guest orders. Unpaid or abandoned orders will be discarded after 3 months. Failed and cancelled orders will be discarded after 1 month. Completed orders are retained for 5 years before the personal data is anonymized.

What rights you have over your data

You may delete your account at anytime by visiting https://www.gemsbythecreek.com/delete-account or by requesting to do so using our Contact form. You may request your order history, although this information is readily available on your My Account – Orders page. You may request an export of your personal data using our Contact form. 

How we protect your data

Gems By The Creek utilizes industry accepted best practices to secure this website and your data. Your credit card information is never stored on this website and is securely transmitted to our payment vendor to facilitate your transaction.

What data breach procedures we have in place

In the event of a data breach, if we have your email address located in any of the records on our website, we will notify you by email.