Privacy Policy
A short note before the legal part
We collect very little about you. We use it for fewer things than most shops. We don't sell it. We don't share it with strangers.
This page explains all that in detail, because the law requires it. But if you ever just want a plain answer to "what do you do with my data?" β write us at help@fromhimtoyou.com. A real person will tell you.
OVERVIEW
This Privacy Policy describes how From Him To You ("we," "us," or "our") collects, uses, stores, and shares your information when you visit our website, place an order, or interact with us in any way.
By using our site, you consent to the practices described here. If you don't agree with anything below, please don't use our site, and write us if you'd like us to delete any data we may already hold about you.
SECTION 1 β WHAT WE COLLECT
1.1 Information you give us directly
When you place an order, create an account, sign up for our newsletter, or write to us, we may collect:
- Your name
- Your email address
- Your shipping address
- Your billing address (if different)
- Your phone number (when required by the shipping carrier)
- The contents of any message you send us
- Any voluntary contribution amount you choose to add at checkout
We do not see or store your full credit or debit card number. Payment information is collected and processed directly by our payment providers (Shopify Payments, Stripe, PayPal, or similar). We only receive a confirmation that the payment cleared and the last four digits of the card for our records.
1.2 Information collected automatically
When you visit our site, we automatically collect some technical information:
- Your IP address
- Your browser type and version
- Your device type (desktop, mobile, tablet)
- Your operating system
- The pages you visit on our site and how long you spend on each
- The website that referred you to us (if any)
- Your approximate location (usually city-level, derived from your IP)
This is collected through cookies and similar technologies β see Section 4 below.
1.3 Information from third parties
If you arrive at our site through a partner, an ad, or a social media link, we may receive limited information from that source β for example, that you clicked a specific ad, or that you came from a particular Pinterest pin. We don't receive your social media password or private content from these platforms.
SECTION 2 β HOW WE USE YOUR INFORMATION
We use the data we collect for a small set of purposes:
2.1 Fulfilling your order
- To process your purchase
- To ship your package and provide tracking
- To communicate with you about your order
- To handle returns, replacements, or shipping issues
2.2 Running and improving the shop
- To understand which products people like and which need work
- To fix bugs and improve site performance
- To prevent fraud and protect against abuse
- To meet our legal and tax obligations
2.3 Communicating with you
- To answer your emails and messages
- To send order confirmations and shipping updates (these are required for service β you can't opt out unless you stop placing orders)
- To send our monthly newsletter (only if you signed up β you can unsubscribe at any time with one click)
2.4 What we don't do with your data
- We don't sell your personal information to anyone
- We don't share it with advertisers or data brokers
- We don't use it to build profiles for targeted advertising on third-party platforms (beyond what's noted in Section 4 about cookies)
- We don't read your messages to train AI models or for any purpose unrelated to answering you
SECTION 3 β WHO WE SHARE INFORMATION WITH
We share your information only with the service providers we need to run the shop. These include:
- Shopify β the platform that hosts our store
- Payment processors (Shopify Payments, Stripe, PayPal) β to process your payment
- Shipping carriers (USPS, UPS, FedEx, DHL, and international postal services) β to deliver your order
- Email service providers (Shopify Email or similar) β to send order confirmations and newsletters
- Analytics providers (Google Analytics, Meta) β to understand how the site is used
- Customer service tools β if we use a help desk software, your messages may be stored there
Each of these companies has their own privacy practices. We work only with partners that meet reasonable industry standards for data protection.
We may also share your information when legally required:
- In response to a valid subpoena, court order, or government request
- To protect our rights, property, or safety, or that of our customers
- In the event of a merger, acquisition, or sale of our business β in which case we'll notify affected customers
SECTION 4 β COOKIES AND TRACKING
4.1 What cookies are
Cookies are small text files that websites store on your device to remember information about your visit. We use cookies for several purposes:
- Essential cookies β required for the site to work (cart, login, checkout). These cannot be turned off.
- Analytics cookies β help us understand how people use the site (e.g., which pages are popular). Used through Google Analytics.
- Marketing cookies β used by Meta (Facebook/Instagram) and similar platforms to measure the effectiveness of any ads we run. These can be turned off.
4.2 Your cookie choices
When you first visit our site, you'll see a cookie banner where you can choose which categories to allow. You can change your preferences any time by clicking the cookie icon in the footer.
You can also block cookies entirely in your browser settings β but if you do, parts of the site (like the cart) may stop working.
4.3 Do Not Track signals
Some browsers send "Do Not Track" signals. There's no industry standard for how to respond to these, so we don't currently change our behavior based on them. But you can use the cookie banner to control tracking instead.
SECTION 5 β YOUR RIGHTS
Depending on where you live, you have rights regarding your personal information. Below are the main ones, though some may vary by jurisdiction.
5.1 Rights for everyone
Regardless of where you live, you can always:
- Ask what data we have about you
- Ask us to correct anything that's inaccurate
- Ask us to delete your data (with some legal exceptions)
- Unsubscribe from marketing emails at any time (one click in any email we send)
To exercise any of these, write to help@forhimtoyou.com. We'll respond within 30 days.
5.2 If you live in California (CCPA / CPRA)
California residents have additional rights under the California Consumer Privacy Act and the California Privacy Rights Act:
- Right to know what personal information we've collected about you in the last 12 months
- Right to delete that information (with some exceptions for legal compliance)
- Right to correct inaccurate information
- Right to opt out of the "sale" or "sharing" of your personal information β though as noted above, we do not sell or share personal information in the way these terms are defined under the law
- Right to limit the use of sensitive personal information β though we don't collect sensitive personal information as defined under California law
- Right to non-discrimination β we won't treat you differently for exercising any of these rights
To exercise these rights, email help@forhimtoyou.com with the subject "California Privacy Request." We may need to verify your identity before responding.
5.3 If you live in the European Economic Area, UK, or Switzerland (GDPR)
Under the General Data Protection Regulation, you have these rights:
- Right of access β to know what data we hold and how we use it
- Right to rectification β to correct inaccurate data
- Right to erasure ("right to be forgotten") β to have your data deleted
- Right to restrict processing β to ask us to stop using your data temporarily
- Right to data portability β to receive your data in a portable format
- Right to object to certain types of processing (especially direct marketing)
- Right to withdraw consent at any time, where processing is based on consent
- Right to lodge a complaint with your local data protection authority
The legal bases we rely on for processing your data are:
- Contract β to fulfill your order (we can't ship without your address)
- Legitimate interest β to run the shop, prevent fraud, and improve our service
- Consent β for marketing emails and non-essential cookies (you can withdraw at any time)
- Legal obligation β when the law requires us to keep certain records
To exercise any of these rights, write to help@forhimtoyou.com.
5.4 Other US states
Several US states (Virginia, Colorado, Connecticut, Utah, and others) have their own privacy laws. If you live in one of these states, you generally have rights similar to those listed under California above. Email us with your state and request, and we'll honor it under your state's law.
5.5 Other jurisdictions
If you live somewhere else and your local privacy law gives you rights not listed above, please write us. We'll do our best to honor them.
SECTION 6 β INTERNATIONAL DATA TRANSFERS
We're based in [YOUR COUNTRY], and our service providers (Shopify, Stripe, Google, Meta, etc.) are largely based in the United States. If you order from outside these countries, your information will be transferred to and stored on servers in countries that may have different privacy laws than your own.
For transfers from the EEA, UK, or Switzerland to the US or other regions, we rely on:
- Standard Contractual Clauses (the EU-approved data transfer mechanism)
- Service providers that are certified under the EU-US Data Privacy Framework, where applicable
- Other safeguards as required by GDPR
You consent to these transfers by using our site.
SECTION 7 β DATA SECURITY
We use industry-standard security measures to protect your data:
- HTTPS encryption on every page of our site
- PCI-DSS compliant payment processing (handled entirely by Shopify and partner processors)
- Limited access β only team members who need data to do their job can access it
- Regular security reviews of our systems and partners
That said, no system is perfect. If we ever discover a data breach affecting your information, we'll notify you and the relevant authorities as required by law.
To protect yourself: please use a strong, unique password if you create an account, and don't share your account credentials with anyone.
SECTION 8 β DATA RETENTION
We keep your information only as long as we need it:
- Order data: kept for 7 years after the order, to comply with tax and accounting laws
- Email subscribers: kept until you unsubscribe, then deleted within 30 days
- Customer service messages: kept for 2 years, then deleted
- Analytics data: kept in aggregated, anonymized form indefinitely; individual-level data is kept for 14 months (Google Analytics default)
- Account data: kept until you ask us to delete it, or 5 years after your last activity, whichever comes first
If you ask us to delete your data earlier, we will β except where the law requires us to keep it (e.g., to retain proof of a transaction for tax purposes).
SECTION 9 β CHILDREN'S PRIVACY
Our shop is intended for adults. We do not knowingly collect personal information from anyone under 16 (or under 13, where the lower age applies under US COPPA).
If you're a parent or guardian and you believe your child has given us their information, please write to help@forhimtoyou.com and we'll delete it promptly.
SECTION 10 β THIRD-PARTY LINKS
Our site may link to other websites β partner organizations, suppliers, articles we like, scripture references. We're not responsible for the privacy practices of those sites. Please read their privacy policies before sharing your information with them.
SECTION 11 β CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. When we do, we'll change the "Last updated" date at the top of this page.
For minor changes (clarifying wording, adding a service provider), we'll just update the page. For major changes (new categories of data, new uses of your data), we'll notify subscribers by email at least 30 days before the change takes effect.
If you don't agree with a revised version, please stop using our site and write us to delete your data.
SECTION 12 β CONTACT US
For any privacy question, request, or concern, write us:
A real person will respond within 30 days, usually much faster.
If you have an unresolved privacy complaint that we haven't addressed satisfactorily, you can contact your local data protection authority. For EU residents, you can find your authority at edpb.europa.eu. For California residents, you can contact the California Privacy Protection Agency at cppa.ca.gov.