Heart Lake Quilts – Privacy Policy
Last updated: July 17, 2025

Heart Lake Quilts (“we,” “us,” “our”) operates an e‑commerce website based in Charlottesville, Virginia, where we sell handcrafted quilts and related products. Protecting your privacy is important to us. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit heartlakequilts.com (the “Site”) or purchase from our WooCommerce store.


1. Information We Collect

CategoryExamplesPurpose
Account & Checkout DataName, billing & shipping address, email, phone number, payment method, order detailsTo process and fulfill orders, communicate about your purchase, handle returns & warranty
Payment DataLast four digits of card number, transaction ID (processed securely by Stripe / PayPal)Fraud prevention, refunds, bookkeeping
Technical Data (via Google Analytics)IP address (anonymized where possible), device/browser type, pages visited, referring URLs, time spent on pagesSite analytics, performance monitoring, improvement of user experience
Cookies & Similar TechnologiesWooCommerce session cookies, GA cookies, cart retention cookiesKeep items in cart, remember preferences, compile aggregate statistics

Sensitive data: We do not intentionally collect sensitive personal information (e.g., SSN, health data, precise geolocation).


2. How We Use Your Information

We use your information only for:

  1. Order Processing & Fulfillment – creating invoices, arranging shipping, and providing customer support.

  2. Communication – sending order confirmations, shipping updates, and responding to inquiries.

  3. Site Improvement & Analytics – understanding aggregate user behavior via Google Analytics to improve navigation, product selection, and performance.

  4. Legal & Security – detecting fraud, complying with tax and accounting obligations, and enforcing our Terms of Service.

We do not use personal data for interest‑based advertising, and we do not sell or rent your information to third parties.


3. Information Sharing

RecipientWhat We ShareWhy
Shipping Carriers (USPS, UPS, FedEx)Name, address, phone/email, order weightDeliver your order, send tracking updates
Payment Processors (Stripe, PayPal)Payment credentials, transaction totalComplete your purchase securely
Service Providers (Web hosting, IT support)Limited technical data as neededMaintain site reliability & security
Analytics Provider (Google Analytics)Device & usage data (pseudonymized)Site performance insights

All third‑party partners are contractually required to keep your data confidential and to use it only for the intended service.


4. Legal Bases for Processing

For residents of the European Economic Area (EEA) or United Kingdom, we rely on:

  • Contractual necessity – to fulfill our agreement with you.

  • Legitimate interests – to analyze and improve our services, prevent fraud, and secure our Site (balanced against your rights).

  • Legal obligations – to satisfy tax, accounting, and regulatory requirements.

  • Consent – for optional cookies or marketing emails (you may withdraw at any time).


5. Your Rights & Choices

  • Access / Correction – request a copy of the personal data we hold or correct inaccuracies.

  • Deletion – ask us to delete certain data (subject to record‑keeping laws).

  • Opt‑Out of Analytics Cookies – adjust your browser settings or install the Google Analytics Opt‑out Browser Add‑on.

  • Do‑Not‑Track – we honor Global Privacy Control (GPC) signals where technically feasible.

  • Virginia Residents (VCDPA) – right to appeal denial of a privacy request; contact details below.

  • California Residents (CCPA/CPRA) – right to know, delete, and correct; no sale or sharing for cross‑context advertising means no opt‑out is needed.

To exercise any right, email kristin@heartlakequilts.com. We will respond within 30 days.


6. Data Retention

Data TypeRetention Period
Order records & invoices7 years (tax/accounting laws)
Customer service correspondence3 years after ticket closure
Google Analytics data14 months (auto‑delete setting)
Abandoned carts (WooCommerce)60 days

When retention periods expire, data is securely deleted or anonymized.


7. Data Security

  • TLS/SSL encryption for all data in transit

  • Payment details handled exclusively by PCI‑DSS‑compliant processors

  • Role‑based access controls & 2‑factor authentication for administrative accounts

  • Regular software updates, malware scans, and off‑site backups

Despite safeguards, no online transmission can be guaranteed 100% secure.


8. International Transfers

Our servers are located in the United States. If you access the Site from outside the U.S., you consent to transferring your data to the U.S., where privacy laws may differ. For EEA/UK residents, transfers rely on Standard Contractual Clauses or an adequacy mechanism.


9. Children’s Privacy

Our Site is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us data, contact us for deletion.


10. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with a new “Last updated” date. Material changes will be communicated via email or a prominent Site notice.


11. Contact Us

Heart Lake Quilts
Email: kristin@heartlakequilts.com

If you have questions about this Privacy Policy, your personal information, or wish to file a complaint, please reach out using the details above.