SECTION 1 - PERSONAL INFORMATION COLLECTED


When you purchase something from Astrid Oslo, as part of our buying and selling process, we collect the personal information you provide to us, such as your name, address, email address or telephone number.

When you surf Astrid Oslo, we also automatically receive your computer's IP (Internet Protocol) address, which enables us to obtain additional information about the browser and operating system you are using.

In connection with email marketing, we may, with your permission, send you emails from Astrid Oslo about new products and other updates or about your ongoing orders.

PART 2 - CONSENT

How do we obtain your consent?

When you provide us with your personal information to complete a transaction, verify your credit card, place an order, schedule a delivery, or return a purchase, we assume that you consent to our collection of your information.

If we ask you to provide your personal data for other reasons, such as for marketing purposes, we will either ask you directly for your express consent or give you the opportunity to refuse it.

How can you withdraw your consent?

If after you opt-in, you change your mind and withdraw your consent for us to contact you and collect your information, you may notify us by contacting us at kontakt@astrid-oslo.com.


SECTION 3 - DELIVERY

We may only disclose your personal information if we are required to do so by law or if you violate our terms and conditions.


SECTION 4 - SHOPIFY

Astrid Oslo is hosted by Shopify Inc. They provide us with an online shopping platform that enables us to sell Astrid Oslo's services and products for you.

Your information is stored in Shopify's storage system and databases. In the general Shopify application, your data is stored on a secure server that is protected by a firewall.


For payment, if you make your purchase through a direct payment gateway, Shopify stores your credit card information. This information is encrypted in accordance with the Payment Card Industry Data Security Standard (PCI-DSS). Your transaction information is retained for as long as necessary to complete your order. Once your order is complete, your purchase transaction information is deleted. Therefore, we do not have direct access to the information you used to complete your order. This information is passed through Shopify and payment processors.


All direct payment gateways are PCI-DSS compliant. This Payment Card Industry Data Security Standard (PCI-DSS) was established by the five major card companies (Visa, MasterCard, American Express, Discover Card and JCB). These standards ensure the secure processing of credit card information when you shop at Astrid Oslo and their service providers.

For more information, please see Shopify's Terms of Service here.


SECTION 5 - SERVICES PROVIDED BY THIRD PARTIES


In general, the services provided by the third-party providers we use will only collect, use and disclose your information to the extent necessary to perform the services they provide to us, such as payment processing.

However, some of these providers, such as payment gateways and other payment transaction processors, have their own privacy policies regarding the information we must provide to them for your purchase transactions with us. Astrid Oslo.

For these third-party providers, we recommend that you read their privacy policies carefully so that you can understand how they process your personal information. You can find Visa's here, American Express' here, MasterCard's here, JCB's here and Stripe's here.


You should be aware that some of these third-party providers may be located or have facilities in a jurisdiction other than yours or ours. Therefore, if you choose to enter into a transaction that requires the services of a third-party provider, your information may be subject to the laws of the jurisdiction in which that provider is located, or the jurisdiction in which their facilities are located, for example.

For example, if you are located in Canada and your transaction is processed through a payment gateway in the United States, your information used to complete the transaction may be disclosed under U.S. law, such as the Patriot Act.

When you leave Astrid Oslo's website or are redirected to a third-party website or application for payment, you are no longer subject to this Privacy Policy or Astrid Oslo's terms and conditions.


Links

You can leave Astrid Oslo by clicking on certain links on our website. We assume no responsibility for the privacy practices of these other websites and recommend that you read their privacy statements carefully.


ARTICLE 6 - SECURITY

To protect your personal information, we take reasonable precautions and follow industry best practices to ensure that it is not inappropriately lost, misused, misappropriated, disclosed, altered or destroyed.

If you provide us with your credit card information, it is encrypted using the SSL security protocol and stored using AES-256 encryption. This means that no human will have access to your full card number. Although no method of Internet transmission or electronic storage is 100% secure, we comply with all PCI-DSS requirements and use other generally accepted industry standards.


COOKIES

Below you will find a list of the cookies we use. We have listed them below so that you can choose whether to allow them or not.

session_id, is a unique session identifier that allows Shopify to store information about your session (referrer, landing page, etc.).

shopify_visit, stores cookies for 30 minutes from the last visit. After that, no data is stored. This cookie file is used by the internal statistics tracking system to Astrid Oslo's suppliers to register the number of visits.

This cookie expires at midnight the following day, depending on the visitor's location. This cookie calculates the number of visits to a store per unique customer.

This unique identifier persists for 2 weeks and stores information about your shopping cart.

secure_session_id, is a unique session identifier.

storefront_digest, is also a unique identifier. It is not defined if the storefront has a password. It is used to know whether the current visitor has access or not.


ARTICLE 7 - AGE OF CONSENT

By using Astrid Oslo, you confirm that you are of legal age in the country, state or province where you reside, and that you have given us your consent to allow minors in your care to use Astrid Oslo.


SECTION 8 - CHANGES TO THIS PRIVACY POLICY

We reserve the right to change this Privacy Policy at any time, so please review it periodically. Changes and clarifications will be effective immediately upon posting to the Site. If we make changes to the content of this Policy, we will notify you here that it has been updated so that you are aware of what information we collect, how we use it, and under what circumstances we may disclose it.

If If Astrid Oslo is acquired by or merged with another company, your information may be transferred to the new owners so that we can continue to sell products to you.


ITEM 9 - SMS MARKETING

By providing your phone number at the time of purchase and by subscribing via our marketing subscription list, you consent to receive SMS notifications (for your order, including abandoned cart reminders) or SMS marketing offers.

The number of marketing text messages will not exceed 30 per month. You may opt out of further text messages by replying with the word STOP. When sending text messages or using automations, you must provide the phone numbers or names of recipients. This data will be stored and used to communicate campaign analytics and results, including message delivery status, shipping status, and, in some cases, whether the purchase resulted in a sale to Astrid Oslo.

If you choose to use our link shortener in text messages, we will collect this information to determine whether the link was clicked and use it to display results in analytics. Any other third party services you choose to use outside of smsbump.com, our text messaging operator, the system we use to send text messages (third party link shortener, GA tracking, etc.), you will be directed to their specific third party policies which you must agree to.

When we send text messages, we transfer the data to our SMS operator to send the messages. The information is only shared with our operator in connection with the initiation of a marketing and messaging campaign. If recipients no longer wish to receive messages, they should reply to the message with the word STOP or contact the email address kontakt@astrid-oslo.com so that we can unsubscribe.

QUESTIONS AND CONTACT INFORMATION

If you would like to: access, correct, amend or delete personal information we have about you, file a complaint, or if you simply want more information, please contact our Privacy Officer at kontakt@astrid-oslo.com.