LEGAL & TRANSPARENCY

Privacy Policy

This policy explains, in plain language, what personal information elimsclothing collects, why we use it, which service providers receive it, how long we keep it, and how you can exercise your privacy rights.

EFFECTIVE: 21 September 2026 · VERSION 4.0

1. Who controls your data

elimsclothing, operated by Elims Clothing's LLC, is the business responsible for personal information collected through the elimsclothing website, online store, customer-support channels, and related services. Our commercial address is .

Privacy requests should be sent to our privacy contact at [email protected]. Customer service requests may be sent to [email protected].

This policy is designed to provide the transparency required by United States federal and state privacy laws that apply to our business, including Section 5 of the Federal Trade Commission Act, the California Online Privacy Protection Act (CalOPPA), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA), comparable comprehensive state privacy laws (such as those of Virginia, Colorado, Connecticut, Utah, Texas, and Oregon), the Children's Online Privacy Protection Act (COPPA), and the CAN-SPAM Act. General information about consumer privacy is available from the Federal Trade Commission and, for California residents, the California Attorney General. Where a newer law or binding regulation applies, that law or regulation prevails.

2. Personal data we collect

CategoryExamplesHow collected
Identity and contactName, email, telephone number, account detailsAccount, checkout, customer support, newsletter
Order and deliveryProducts, sizes, measurements, delivery address, order historyCart, checkout, order fulfilment, returns
Payment and transactionAmount, currency, transaction reference, payment statusStripe and other payment providers
Device and usageIP address, browser, device type, pages viewed, time zone, logsCookies, local storage, security logs, analytics
CommunicationsMessages, reviews, support records, return photographsEmail, forms, chat, customer-support channels

We do not ask for your full card number, CVV, PIN, or online-banking password. Payment credentials are entered directly into the payment provider's secure environment and are handled under that provider's privacy and security terms.

For California residents, these categories correspond to the CCPA categories of identifiers, customer records, commercial information, internet or other electronic network activity, and inferences drawn from that information. We do not knowingly collect sensitive personal information as defined by the CCPA (such as government identifiers, precise geolocation, or account log-in credentials combined with a password) beyond what is needed to provide the services you request.

3. Why we use personal data and our business purposes

We use only the information reasonably necessary and proportionate for the purpose described. Depending on the activity, we use personal information to perform a contract with you, to take steps you request before a contract, to comply with legal obligations, for our legitimate business purposes in operating and securing the store, or with your consent where the law requires it.

PurposeLegal or business basis
Create and manage an accountContract or requested pre-contract steps
Process orders, payments, delivery, returns, and refundsContract; legal obligations; fraud prevention
Respond to questions and support requestsContract or legitimate business purpose
Secure the website, prevent fraud, and maintain recordsLegitimate business purpose; legal obligation
Send optional marketing communicationsYour consent where required (for example, marketing text messages); you may opt out free of charge at any time

4. Consent and marketing choices

Where we rely on consent, it must be freely given, specific, informed, and unambiguous. A checkout purchase is not conditional on agreeing to optional marketing. Marketing emails are sent in accordance with the CAN-SPAM Act and include a working unsubscribe link and our postal address; we process opt-out requests within ten business days. We send marketing text messages only with your prior express written consent as required by the Telephone Consumer Protection Act, and you may stop them at any time by replying STOP. You may also withdraw marketing consent by contacting [email protected]. Withdrawal does not affect processing already carried out lawfully before withdrawal. Transactional messages about your order or account may still be sent.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We will not use your data for unrelated purposes without additional notice or, where required, your consent. If our practices change, we will update this policy and provide a “Do Not Sell or Share My Personal Information” link and any other opt-out mechanisms the law requires.

5. Cookies, local storage, and similar technology

We use essential cookies and browser local storage to keep you signed in, protect sessions, remember preferences, maintain a guest shopping cart, prevent fraud, and operate checkout. For example, the guest cart may be stored on your device until you remove it, complete checkout, or sign in and synchronize it to your account.

If we use non-essential analytics or advertising cookies, we will provide the required notice and an opt-out mechanism (and consent where the law requires it) before activating them. We treat recognized opt-out preference signals, such as the Global Privacy Control, as valid requests to opt out of the sale or sharing of personal information where the law requires. Because there is no uniform industry standard, our site does not currently change its practices in response to “Do Not Track” browser signals. You can control cookies through your browser, but disabling essential storage may prevent cart or checkout functions from working.

6. Who receives personal data

We disclose personal information only where necessary for the purposes in this policy, to service providers and contractors bound by a written contract that limits their use of the information, and subject to confidentiality and security obligations.

Provider or recipientPurpose
Stripe or the payment provider shown at checkoutPayment authorization, settlement, fraud monitoring, refunds, and transaction support
Firebase / Google Cloud services used by elimsclothingAuthentication, database, hosting, storage, security, and application operation
Courier, logistics, and customs partnersDelivery, tracking, customs clearance, and returns
Professional advisers, law enforcement, and government authoritiesLegal compliance, responding to lawful requests, dispute resolution, fraud investigation, or protection of rights
Analytics or marketing providers, if enabledOnly the measurement or marketing functions disclosed at the time of collection

We do not authorize service providers to use your personal information for their own unrelated marketing. If our business is sold, merged, or reorganized, personal information may be transferred to the successor entity, which must honor this policy or give you notice of any material change.

7. Where data is processed and transferred

Personal information is primarily processed and stored in the United States. Some providers that support payment, hosting, authentication, security, email, analytics, or delivery may process personal information in other countries. Where we transfer information across borders, we use contractual and technical safeguards appropriate to the risk, and we will not transfer more data than necessary for the stated purpose.

By placing an order that requires an overseas payment, hosting, courier, or customs provider, you acknowledge that the data needed for that service may be processed in the provider's country. If you access our services from outside the United States, you understand that your information will be transferred to and processed in the United States. Contact [email protected] if you need information about the safeguards for a specific transfer.

8. Retention

We keep personal information only for as long as reasonably necessary for the purpose collected, including order fulfilment, customer support, fraud prevention, accounting, tax, legal claims, and regulatory obligations. As a guide, order and payment records are retained for the period required by federal and state tax, accounting, payment-network, and other legal rules; support and return records are retained for as long as needed to resolve the matter and defend or establish a claim; and account data is deleted or anonymized after account closure unless a lawful retention reason remains.

When retention is no longer required, we securely delete, anonymize, or irreversibly de-identify the data. Backups may retain deleted data for a limited disaster-recovery cycle before secure overwriting.

9. Security and data breaches

We use reasonable technical and organizational measures appropriate to the risk, including access controls, authentication, least privilege, provider security controls, encrypted connections, monitoring, backups, and staff confidentiality obligations. Payment card credentials are handled by the payment provider and are not stored by elimsclothing in full.

No online system is completely risk-free. If we identify a security breach involving personal information, we will investigate, contain, document, and remedy it, and notify affected individuals, state attorneys general, and other regulators as required by applicable state breach-notification laws, without unreasonable delay. We will communicate practical steps you can take and provide a contact for questions.

10. Your privacy rights

Depending on where you live, and subject to applicable legal exceptions and identity verification, you may have the right to know and access the personal information we hold about you and how it is used and disclosed; correct inaccurate information; delete your personal information; obtain a portable copy of your data; opt out of the sale or sharing of personal information, targeted advertising, and certain profiling; limit the use of sensitive personal information; and withdraw consent where we rely on it. You may object to direct marketing free of charge. We will not discriminate or retaliate against you for exercising any of these rights.

Send a request to [email protected] with the subject “Data Rights Request”, the right you wish to exercise, the email or order identifier connected with your request, and any details needed to locate the data. We may request reasonable information to verify your identity by matching it to information we already hold. We will confirm receipt within ten business days and respond within 45 days of receiving a verifiable request; where the law allows and it is reasonably necessary, we may extend this once by a further 45 days and will tell you why. If a request is complex, excessive, or repetitive, we will explain any lawful limitation or refusal and the reason.

Authorized agents. You may designate an authorized agent to submit a request on your behalf. We may require written proof of the agent's authority and may verify your identity directly with you.

Appeals. If we decline to act on your request and your state's law gives you a right to appeal, you may reply to our response, or email [email protected] with the subject “Appeal”, and we will respond in writing within the time required by law. If your appeal is denied, you may contact your state attorney general.

California residents. In addition to the rights above, under California's “Shine the Light” law you may request information about personal information disclosed to third parties for their direct marketing purposes. We do not disclose personal information to third parties for their own direct marketing purposes. Nevada residents may submit a request to opt out of the sale of covered information; we do not sell it.

11. Children

The Services are not directed to children under 18. We do not knowingly collect personal information from children under 13, in accordance with COPPA, and we do not sell or share the personal information of anyone we know to be under 16. If you believe a child has provided personal information, contact [email protected] so we can review and delete it where appropriate.

12. Complaints and remedies

If you believe we have handled your personal information improperly, contact us first at [email protected]. We will review the complaint, provide a written response, and take corrective action where appropriate. If you are not satisfied, you may contact your state attorney general, the California Privacy Protection Agency (for California residents), the Federal Trade Commission, or another competent regulatory or judicial authority in accordance with applicable law.

13. Changes to this policy

We may update this policy when our services, providers, technology, or legal obligations change. We will publish the new effective date at the top of the policy. For material changes, we will provide a prominent notice or direct communication where required, and we will not use previously collected personal information for materially different purposes without any notice or consent the law requires.