Privacy policy
PRIVACY POLICY
The Goat Woodworks
Website: https://thegoatwoodworks.com
Last updated: September 1, 2026
This Privacy Policy explains how The Goat Woodworks (“the Site,” “we,” “us,” or “our”) collects, uses, shares, and protects personal information when you visit, contact, or buy from thegoatwoodworks.com. It is written for a small custom woodworking shop that sells through Shopify and is intended to meet current U.S. state privacy-notice expectations (including California’s CCPA/CPRA and similar state laws), CalOPPA, and GDPR/UK GDPR disclosures for visitors in the EEA, UK, or Switzerland.
1. Who we are and how to contact us
Controller / business: The Goat Woodworks, operating thegoatwoodworks.com from San Diego County, California, United States.
Privacy contact: terry@thegoatwoodworks.com
After reading this policy, if you have questions, want more information, want to exercise a privacy right, or want to make a complaint, email us at the address above. We will respond as required by applicable law (generally within 45 days, with one permitted extension when reasonably necessary).
2. Personal information we collect
“Personal information” (also called personal data) means information that identifies, relates to, describes, or can reasonably be linked to you or your household.
Information you give us
• Order and account details. Name, billing address, shipping address, email address, phone number, and order notes when you check out or create an account.
• Payment information. Payment card or other payment details are collected at checkout. Card numbers are processed by Shopify and its payment partners (for example Shopify Payments, PayPal, Shop Pay, or Apple Pay). We do not store full card numbers on our own systems.
• Customer support. The content of emails, messages, photos of products, and any other information you send when you contact us.
• Marketing preferences. If you join a mailing list or accept marketing, your email and preference choices.
Information collected automatically
• Device and usage data. IP address, browser type and version, device type, operating system, time zone, referring URL, pages viewed, products viewed, search terms, click path, and approximate location derived from IP address.
• Cookies and similar technologies. Cookies, pixels, tags, local storage, and similar tools used by us and by Shopify, analytics, and advertising partners. See Section 8.
• Order-risk signals. Shopify may use limited automated checks (for example temporary flags on IPs or cards associated with repeated failed transactions) to reduce fraud.
Information we do not intentionally collect
We do not intentionally collect government ID numbers, precise geolocation, biometric identifiers, health data, or other “sensitive personal information” as defined under CPRA and similar laws, except to the limited extent an address or payment method is needed to fulfill an order. We do not use sensitive personal information to infer characteristics about you.
3. Why we use personal information
We use personal information only as reasonably necessary and proportionate for the purposes described here:
• Provide, operate, and secure the Site.
• Fulfill orders: process payment, arrange shipping and delivery, send invoices and confirmations, handle returns or custom-work questions.
• Communicate about an order, a product, or a support request.
• Detect, prevent, and investigate fraud, abuse, and security incidents.
• Comply with tax, accounting, shipping, and other legal obligations.
• Measure how the Site is used and improve products, pages, and checkout (analytics).
• With your choices and as allowed by law, send product updates, offers, or ads that may interest you (including limited targeted advertising through platforms such as Google and Meta).
We do not use personal information for solely automated decisions that produce legal or similarly significant effects. Shopify may apply short-lived, limited automated fraud filters that do not determine credit, employment, housing, or similar outcomes.
4. Legal bases (EEA, UK, and Switzerland)
If European or UK data-protection law applies, we process personal data on these bases:
• Performance of a contract — to take and fulfill your order and provide support.
• Legitimate interests — to secure the Site, prevent fraud, understand Site usage at an aggregate level, and improve the shop, where those interests are not overridden by your rights.
• Consent — for non-essential cookies, certain advertising/analytics cookies, and optional marketing emails. You may withdraw consent at any time.
• Legal obligation — tax, accounting, consumer, and law-enforcement requirements.
5. How we share personal information
We share personal information with service providers that process it on our instructions to run the shop. We do not sell personal information for money. Under California law, some advertising and analytics cookies can still count as “sharing” or a “sale” of personal information for cross-context behavioral advertising. You can opt out as described in Section 7.
Typical recipients:
• Shopify Inc. and its group companies. Our store platform, checkout, hosting, and related commerce tools. Shopify’s consumer privacy policy: https://www.shopify.com/legal/privacy
• Payment processors. Shopify Payments and any wallets or gateways you choose at checkout (for example PayPal or Shop Pay).
• Shipping and fulfillment partners. Carriers and label/print tools needed to deliver your order.
• Analytics. Google Analytics (or equivalent) to understand Site traffic. Google’s policy: https://policies.google.com/privacy Opt-out browser add-on: https://tools.google.com/dlpage/gaoptout
• Advertising partners (if pixels or ads are active). Meta/Facebook and Google Ads may receive device and event data through cookies or pixels so we can measure or retarget ads. You can limit this through the controls in Section 7 and 8.
• Professional and legal. Accountants, insurers, or lawyers when reasonably necessary; and authorities when required by law, a valid legal process, or to protect rights, safety, or the Site.
We do not allow service providers to use your information for their own unrelated marketing. Shopify and major processors publish their own privacy notices and data-processing terms.
6. How long we keep information
We keep personal information only as long as needed for the purposes above, then delete or de-identify it, unless a longer period is required by law.
• Order, invoice, and tax records: generally kept for at least seven (7) years to meet U.S. tax and accounting rules.
• Customer-support emails: typically up to three (3) years after the last relevant message, unless needed longer for a dispute.
• Marketing lists: until you unsubscribe or we delete inactive contacts.
• Cookies: session cookies expire when you close the browser; persistent cookies generally last from minutes up to two years, depending on the cookie.
You may request deletion as described in Section 7. We may retain a limited record of the request and information we must keep for legal, security, or accounting reasons.
7. Your privacy rights
Depending on where you live, you may have some or all of the following rights. We honor applicable rights for residents of California and other U.S. states with comprehensive consumer privacy laws, and for individuals protected by GDPR/UK GDPR.
• Know / access — request the categories and specific pieces of personal information we hold about you.
• Correct — ask us to fix inaccurate personal information.
• Delete — ask us to delete personal information, subject to legal exceptions (for example completed orders we must keep for tax records).
• Portability — receive a copy of certain information in a portable format.
• Opt out of sale / sharing / targeted advertising — including cross-context behavioral advertising.
• Limit use of sensitive personal information — if we ever collected it beyond what is needed to provide the product you requested (we do not currently use SPI to infer characteristics).
• Withdraw consent — where processing is based on consent.
• Appeal — if we deny a request, some state laws let you appeal. Email us and write “Privacy Appeal” in the subject line.
• Lodge a complaint — EEA/UK residents may complain to their local supervisory authority. In the UK that is the ICO (https://ico.org.uk/make-a-complaint/). U.S. residents may contact their state attorney general or, in California, the California Privacy Protection Agency (https://cppa.ca.gov/).
How to submit a request: email terry@thegoatwoodworks.com with enough detail for us to find you in our records (name, email used at checkout, and order number if you have one). You may use an authorized agent; we will take reasonable steps to verify the agent’s authority and your identity. We will not discriminate against you for exercising privacy rights.
We honor Global Privacy Control (GPC) and similar universal opt-out preference signals as a valid request to opt out of “sale” and “sharing” / targeted advertising where those laws apply. California and several other states require this. If your browser sends GPC, we treat it as an opt-out for that browser/device.
You can also use industry opt-out tools:
• Digital Advertising Alliance: https://optout.aboutads.info/
• Network Advertising Initiative: https://optout.networkadvertising.org/
• Google ad settings: https://adssettings.google.com/
• Meta/Facebook ad settings: https://www.facebook.com/settings/?tab=ads
• Microsoft/Bing: https://account.microsoft.com/privacy/ad-settings/
8. Cookies, tracking, and “Do Not Track”
We and our processors use cookies and similar technologies for four main reasons:
• Strictly necessary — cart, checkout, security, fraud prevention, load the Site.
• Functional — remember preferences.
• Performance / analytics — understand how the Site is used.
• Advertising — measure campaigns and, if enabled, show relevant ads on other sites.
You can control cookies in your browser settings. Blocking some cookies can break checkout or login. Browser “Do Not Track” (DNT) is not consistently defined across the industry, so we do not change practices solely because of a DNT signal. We do honor GPC as described above.
A privacy policy is notice, not cookie consent. If you use non-essential pixels (Google Analytics advertising features, Meta Pixel, and similar), use a consent/opt-out banner that blocks those tags until required consent or opt-out rules are met, and that detects GPC. Shopify’s customer-privacy settings can help with this.
9. Children
The Site is intended for adults. We do not knowingly collect personal information from children under 16 (or under 13 where COPPA applies). We do not sell or share personal information of consumers we know are under 16. If you believe a child provided information, email us and we will delete it.
10. International transfers
We are based in the United States. If you visit or order from outside the U.S., your information will be processed in the United States and in other countries where Shopify and our processors operate. Shopify uses approved transfer tools (including Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework and Binding Corporate Rules). See Shopify’s privacy policy and DPA for details.
11. Security
We rely on Shopify’s platform security (encryption in transit, access controls, and payment-industry standards used by Shopify and its payment partners) and on reasonable administrative practices for a small shop (limited access to the store admin, unique passwords, and care with customer emails). No website or transmission is completely secure. Please use a unique password if you create an account and contact us if you suspect unauthorized use of your information.
12. Third-party sites
The Site may link to social media, shipping trackers, or other sites we do not control. Their privacy practices are governed by their own policies.
13. Changes to this policy
We may update this Privacy Policy to reflect changes in our practices, technology, or the law. The “Last updated” date at the top will change. Material changes will be posted on this page. Continued use of the Site after an update means the revised policy applies to later collection and use.
14. Complaints
Email terry@thegoatwoodworks.com first so we can try to resolve the issue. If you are not satisfied, you may contact the privacy regulator that has jurisdiction where you live, including the ICO for the UK and the California Privacy Protection Agency or California Attorney General for California residents.
Notice at collection (California)
At or before the point of collection we collect the categories listed in Section 2 (identifiers, commercial information, internet/electronic activity, and approximate geolocation from IP) for the purposes in Section 3, from you and from your device/cookies, and we disclose them to the service-provider categories in Section 5. Retention is described in Section 6. We do not sell personal information for money. We may “share” personal information for cross-context behavioral advertising if advertising cookies or pixels are active; you may opt out by emailing us, using the Site’s opt-out tools, or enabling GPC. We do not use or disclose sensitive personal information for purposes that require a separate “Limit the Use” link.