Privacy Policy

Privacy Policy – Hurah Shop

Last updated: December, 2025

Hurah Shop (“we”, “us”, “our”) is committed to protecting your personal information and respecting your privacy. This policy explains how we collect, use, and safeguard data when you visit our website, make a purchase, or interact with our services — in compliance with GDPR, CCPA, and other applicable privacy regulations.


1. Information We Collect

a. Personal Information You Provide

When you shop or interact with us, we may collect:

  • Full name
  • Email address
  • Shipping & billing address
  • Phone number
  • Order details
  • Payment information (processed securely by third-party providers; we do not store full credit card numbers)

b. Automatically Collected Data

When browsing our website, we may collect:

  • IP address
  • Device & browser information
  • Cookies and tracking data
  • Pages viewed, referring URLs, session duration

c. Sensitive Data

We do not intentionally collect or process sensitive personal data.


2. How We Use Your Information

We use the data we collect for:

  • Order processing, fulfillment, and delivery
  • Customer support and communication
  • Improving website performance and user experience
  • Fraud detection and security
  • Marketing (with your consent where required)
  • Legal compliance

We do not sell personal information.


3. Legal Bases for Processing (GDPR)

If you are in the EU/EEA, we process your data under the following legal bases:

  • Contractual necessity (to fulfill your order)
  • Legitimate interests (fraud prevention, analytics, business improvement)
  • Consent (newsletters, cookies, marketing)
  • Legal obligation (tax, accounting, recordkeeping)

4. Your Rights – GDPR

If you are located in the EU/EEA, you have the right to:

  • Access your personal data
  • Correct inaccurate information
  • Delete your data (“right to be forgotten”)
  • Restrict processing in some cases
  • Object to processing (including marketing)
  • Data portability (request a copy of your data)
  • Withdraw consent at any time

To submit a GDPR request, contact:
📧 hello@hurah.us

We respond within 30 days.


5. Your Rights – CCPA / CPRA (California Residents)

If you are a California resident, you have the right to:

  • Know what personal information we collect and how we use it
  • Access your personal information
  • Request deletion of your personal data
  • Opt-out of the sale or sharing of personal information
  • Correct inaccurate data
  • Limit use of sensitive information (we do not collect sensitive data)

To submit a CCPA/CPRA request, email:
📧 hello@hurah.us

We do not sell or share your personal information for advertising in a way that constitutes “sale” under CCPA.

We will not discriminate against you for exercising your privacy rights.


6. Data Sharing

We share your data only with essential third parties, such as:

  • Payment processors (e.g., Stripe, PayPal)
  • Shipping carriers & logistics providers
  • Print-on-demand and production partners
  • Marketing & analytics tools (e.g., Google Analytics, Facebook Pixel)

All partners are required to handle your information lawfully and securely.


7. Cookies & Tracking Technologies

We use cookies to:

  • Maintain cart and checkout functionality
  • Enhance website performance
  • Provide personalized content
  • Measure marketing effectiveness

Cookie Consent (GDPR):
EU/EEA visitors will see a cookie consent banner. You may accept or reject non-essential cookies at any time.

Opt-out (CCPA):
California residents may opt out of tracking cookies or marketing tools via our “Do Not Sell or Share My Personal Information” link (add to footer if applicable).


8. Data Retention

We retain personal information as long as necessary for:

  • Order fulfillment
  • Legal, tax, and accounting requirements (typically 5–7 years)
  • Fraud prevention and security

You may request deletion of your data (see sections above).


9. International Data Transfers

Your information may be processed in countries outside your own, including the U.S. and EU.
We rely on:

  • Standard Contractual Clauses (SCCs)
  • GDPR-compliant processors
  • Other legal safeguards

10. Security Measures

We take data protection seriously and use:

  • SSL encryption
  • Secure hosting
  • Restricted data access
  • Encrypted payment processing through PCI-compliant partners

No security system is perfect, but we strive to protect your data to the highest reasonable standard.


11. Children’s Privacy

Our website is not intended for children under 13.
We do not knowingly collect data from children.
If you believe a child has shared information with us, contact us to delete it.


12. Changes to This Policy

We may update this Privacy Policy from time to time.
Changes take effect immediately when posted on this page, with the updated date shown at the top.


13. Contact Information

If you have questions or privacy requests:

📧 hello@hurah.us

For EU residents, you may also contact your local Data Protection Authority (DPA) for unresolved issues.