LEGAL & TRANSPARENCY
Privacy Policy
This policy explains, in plain language, what personal information elimsclothing collects, why we use it, which service providers receive it, how long we keep it, and how you can exercise your privacy rights.
EFFECTIVE: 21 September 2026 · VERSION 4.0
1. Who controls your data
elimsclothing, operated by Elims Clothing's LLC, is the business responsible for personal information collected through the elimsclothing website, online store, customer-support channels, and related services. Our commercial address is .
Privacy requests should be sent to our privacy contact at [email protected]. Customer service requests may be sent to [email protected].
This policy is designed to provide the transparency required by United States federal and state privacy laws that apply to our business, including Section 5 of the Federal Trade Commission Act, the California Online Privacy Protection Act (CalOPPA), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA), comparable comprehensive state privacy laws (such as those of Virginia, Colorado, Connecticut, Utah, Texas, and Oregon), the Children's Online Privacy Protection Act (COPPA), and the CAN-SPAM Act. General information about consumer privacy is available from the Federal Trade Commission and, for California residents, the California Attorney General. Where a newer law or binding regulation applies, that law or regulation prevails.
2. Personal data we collect
| Category | Examples | How collected |
|---|---|---|
| Identity and contact | Name, email, telephone number, account details | Account, checkout, customer support, newsletter |
| Order and delivery | Products, sizes, measurements, delivery address, order history | Cart, checkout, order fulfilment, returns |
| Payment and transaction | Amount, currency, transaction reference, payment status | Stripe and other payment providers |
| Device and usage | IP address, browser, device type, pages viewed, time zone, logs | Cookies, local storage, security logs, analytics |
| Communications | Messages, reviews, support records, return photographs | Email, forms, chat, customer-support channels |
We do not ask for your full card number, CVV, PIN, or online-banking password. Payment credentials are entered directly into the payment provider's secure environment and are handled under that provider's privacy and security terms.
For California residents, these categories correspond to the CCPA categories of identifiers, customer records, commercial information, internet or other electronic network activity, and inferences drawn from that information. We do not knowingly collect sensitive personal information as defined by the CCPA (such as government identifiers, precise geolocation, or account log-in credentials combined with a password) beyond what is needed to provide the services you request.
3. Why we use personal data and our business purposes
We use only the information reasonably necessary and proportionate for the purpose described. Depending on the activity, we use personal information to perform a contract with you, to take steps you request before a contract, to comply with legal obligations, for our legitimate business purposes in operating and securing the store, or with your consent where the law requires it.
| Purpose | Legal or business basis |
|---|---|
| Create and manage an account | Contract or requested pre-contract steps |
| Process orders, payments, delivery, returns, and refunds | Contract; legal obligations; fraud prevention |
| Respond to questions and support requests | Contract or legitimate business purpose |
| Secure the website, prevent fraud, and maintain records | Legitimate business purpose; legal obligation |
| Send optional marketing communications | Your consent where required (for example, marketing text messages); you may opt out free of charge at any time |
4. Consent and marketing choices
Where we rely on consent, it must be freely given, specific, informed, and unambiguous. A checkout purchase is not conditional on agreeing to optional marketing. Marketing emails are sent in accordance with the CAN-SPAM Act and include a working unsubscribe link and our postal address; we process opt-out requests within ten business days. We send marketing text messages only with your prior express written consent as required by the Telephone Consumer Protection Act, and you may stop them at any time by replying STOP. You may also withdraw marketing consent by contacting [email protected]. Withdrawal does not affect processing already carried out lawfully before withdrawal. Transactional messages about your order or account may still be sent.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We will not use your data for unrelated purposes without additional notice or, where required, your consent. If our practices change, we will update this policy and provide a “Do Not Sell or Share My Personal Information” link and any other opt-out mechanisms the law requires.
5. Cookies, local storage, and similar technology
We use essential cookies and browser local storage to keep you signed in, protect sessions, remember preferences, maintain a guest shopping cart, prevent fraud, and operate checkout. For example, the guest cart may be stored on your device until you remove it, complete checkout, or sign in and synchronize it to your account.
If we use non-essential analytics or advertising cookies, we will provide the required notice and an opt-out mechanism (and consent where the law requires it) before activating them. We treat recognized opt-out preference signals, such as the Global Privacy Control, as valid requests to opt out of the sale or sharing of personal information where the law requires. Because there is no uniform industry standard, our site does not currently change its practices in response to “Do Not Track” browser signals. You can control cookies through your browser, but disabling essential storage may prevent cart or checkout functions from working.
6. Who receives personal data
We disclose personal information only where necessary for the purposes in this policy, to service providers and contractors bound by a written contract that limits their use of the information, and subject to confidentiality and security obligations.
| Provider or recipient | Purpose |
|---|---|
| Stripe or the payment provider shown at checkout | Payment authorization, settlement, fraud monitoring, refunds, and transaction support |
| Firebase / Google Cloud services used by elimsclothing | Authentication, database, hosting, storage, security, and application operation |
| Courier, logistics, and customs partners | Delivery, tracking, customs clearance, and returns |
| Professional advisers, law enforcement, and government authorities | Legal compliance, responding to lawful requests, dispute resolution, fraud investigation, or protection of rights |
| Analytics or marketing providers, if enabled | Only the measurement or marketing functions disclosed at the time of collection |
We do not authorize service providers to use your personal information for their own unrelated marketing. If our business is sold, merged, or reorganized, personal information may be transferred to the successor entity, which must honor this policy or give you notice of any material change.
7. Where data is processed and transferred
Personal information is primarily processed and stored in the United States. Some providers that support payment, hosting, authentication, security, email, analytics, or delivery may process personal information in other countries. Where we transfer information across borders, we use contractual and technical safeguards appropriate to the risk, and we will not transfer more data than necessary for the stated purpose.
By placing an order that requires an overseas payment, hosting, courier, or customs provider, you acknowledge that the data needed for that service may be processed in the provider's country. If you access our services from outside the United States, you understand that your information will be transferred to and processed in the United States. Contact [email protected] if you need information about the safeguards for a specific transfer.
8. Retention
We keep personal information only for as long as reasonably necessary for the purpose collected, including order fulfilment, customer support, fraud prevention, accounting, tax, legal claims, and regulatory obligations. As a guide, order and payment records are retained for the period required by federal and state tax, accounting, payment-network, and other legal rules; support and return records are retained for as long as needed to resolve the matter and defend or establish a claim; and account data is deleted or anonymized after account closure unless a lawful retention reason remains.
When retention is no longer required, we securely delete, anonymize, or irreversibly de-identify the data. Backups may retain deleted data for a limited disaster-recovery cycle before secure overwriting.
9. Security and data breaches
We use reasonable technical and organizational measures appropriate to the risk, including access controls, authentication, least privilege, provider security controls, encrypted connections, monitoring, backups, and staff confidentiality obligations. Payment card credentials are handled by the payment provider and are not stored by elimsclothing in full.
No online system is completely risk-free. If we identify a security breach involving personal information, we will investigate, contain, document, and remedy it, and notify affected individuals, state attorneys general, and other regulators as required by applicable state breach-notification laws, without unreasonable delay. We will communicate practical steps you can take and provide a contact for questions.
10. Your privacy rights
Depending on where you live, and subject to applicable legal exceptions and identity verification, you may have the right to know and access the personal information we hold about you and how it is used and disclosed; correct inaccurate information; delete your personal information; obtain a portable copy of your data; opt out of the sale or sharing of personal information, targeted advertising, and certain profiling; limit the use of sensitive personal information; and withdraw consent where we rely on it. You may object to direct marketing free of charge. We will not discriminate or retaliate against you for exercising any of these rights.
Send a request to [email protected] with the subject “Data Rights Request”, the right you wish to exercise, the email or order identifier connected with your request, and any details needed to locate the data. We may request reasonable information to verify your identity by matching it to information we already hold. We will confirm receipt within ten business days and respond within 45 days of receiving a verifiable request; where the law allows and it is reasonably necessary, we may extend this once by a further 45 days and will tell you why. If a request is complex, excessive, or repetitive, we will explain any lawful limitation or refusal and the reason.
Authorized agents. You may designate an authorized agent to submit a request on your behalf. We may require written proof of the agent's authority and may verify your identity directly with you.
Appeals. If we decline to act on your request and your state's law gives you a right to appeal, you may reply to our response, or email [email protected] with the subject “Appeal”, and we will respond in writing within the time required by law. If your appeal is denied, you may contact your state attorney general.
California residents. In addition to the rights above, under California's “Shine the Light” law you may request information about personal information disclosed to third parties for their direct marketing purposes. We do not disclose personal information to third parties for their own direct marketing purposes. Nevada residents may submit a request to opt out of the sale of covered information; we do not sell it.
11. Children
The Services are not directed to children under 18. We do not knowingly collect personal information from children under 13, in accordance with COPPA, and we do not sell or share the personal information of anyone we know to be under 16. If you believe a child has provided personal information, contact [email protected] so we can review and delete it where appropriate.
12. Complaints and remedies
If you believe we have handled your personal information improperly, contact us first at [email protected]. We will review the complaint, provide a written response, and take corrective action where appropriate. If you are not satisfied, you may contact your state attorney general, the California Privacy Protection Agency (for California residents), the Federal Trade Commission, or another competent regulatory or judicial authority in accordance with applicable law.
13. Changes to this policy
We may update this policy when our services, providers, technology, or legal obligations change. We will publish the new effective date at the top of the policy. For material changes, we will provide a prominent notice or direct communication where required, and we will not use previously collected personal information for materially different purposes without any notice or consent the law requires.
