Privacy policy
Last updated: November 2025
This Privacy Policy explains how BarePearSkin. (“BarePearSkin.”, “we”, “us”, “our”) collects, uses and protects personal data when you use our website, interact with our services, or purchase our products.
By using our website or services, you agree to the practices described in this Policy.
If you do not agree, please discontinue use of the Site and our services.
1. Types of Data We Collect
1.1. Data you provide voluntarily
When you place an order, contact us, or interact with our services, we may collect:
- Name
- Email address
- Shipping and billing address
- Phone number
- Order information
- Customization instructions
- Customer service communications
We do not store credit card numbers. Payment information is processed exclusively by secure third-party payment providers (e.g., Stripe).
1.2. Data collected automatically
When you browse our website, we use cookies, pixels, and analytics to collect:
- IP address
- Browser type and device type
- Pages viewed and actions taken
- Approximate location (based on IP)
- Session duration
- Referring URLs
1.3. Marketing and analytics data
Through tools such as:
- Google Analytics / Tag Manager
- Meta (Facebook/Instagram) Pixel
- Pinterest Tag
- Klaviyo
These tools collect behavioural and usage data for analytics and advertising optimisation.
1.4. Photos voluntarily shared
We only use photos that customers intentionally share with us after receiving their order (e.g., via email or social media).
Photos uploaded during the ordering process are not used for advertising.
2. How We Use Personal Data
We process personal data for these purposes:
2.1. Contractual necessity
- Processing and shipping orders
- Providing customer support
- Managing returns and replacements
2.2. Legitimate interest
- Improving our services and website
- Preventing fraud
- Understanding website usage
- Marketing to existing customers where permitted
2.3. Consent
- Email marketing
- Analytics and advertising cookies
You may withdraw consent at any time.
3. Cookies
We use cookies to:
- Enable essential website features
- Remember preferences (currency, language)
- Analyse performance
- Deliver relevant advertising
You can disable cookies through your browser settings.
Some features may not function correctly without them.
A more detailed cookie breakdown is available on request.
4. Data Controller Information (GDPR Requirement)
(This section contains legally required identification details.)
The data controller responsible for personal data processing is:
Email: contact@barepearskin.com
5. Sharing of Personal Data
We do not sell or rent personal data.
We may share data with:
5.1. Service providers (processors)
Only when necessary to operate our business:
- Stripe – payment processing
- Klaviyo – email and marketing communication
- Google – analytics and measurement
- Meta (Facebook/Instagram) – advertising
- Pinterest – advertising
All third parties operate under data-processing agreements.
5.2. Legal requirements
We may disclose data to comply with:
- court orders
- law enforcement
- fraud prevention obligations
- regulatory requirements
5.3. Business transfers
In case of a merger, acquisition, or sale of assets, data may be transferred securely to the acquiring party.
6. International Data Transfers
Some providers process data outside the EU (e.g., United States).
In such cases, we use:
- Standard Contractual Clauses (SCCs)
- Additional security measures
This ensures GDPR-level protection even outside the EU.
7. Data Retention
We retain personal data only as long as needed:
- Orders & purchase information: 5–7 years
- Customer communications: up to 3 years
- Marketing data: until consent is withdrawn
- Analytics data: 26–38 months
- Photos voluntarily shared: until removal is requested
8. Your GDPR Rights
You have the right to:
- Access your data
- Correct inaccurate data
- Request deletion (“right to be forgotten”)
- Restrict processing
- Request data portability
- Object to processing (including marketing)
- Withdraw consent at any time
- File a complaint with a supervisory authority
To exercise your rights:
contact@barepearskin.com
9. Children’s Privacy
Our services are not intended for individuals under 18.
We do not knowingly collect data from minors.
10. Data Security
We implement technical and organisational measures such as:
- Encrypted connections (SSL)
- Restricted access
- Secure hosting environments
- Monitoring and incident prevention
- Third-party compliance checks
No system is fully immune to risk, but we strive to protect personal data at a high standard.
11. Changes to This Policy
We may update this Privacy Policy when necessary.
Updates will be published here with a new “Last updated” date.
12. Contact
For questions or privacy requests, contact:
contact@barepearskin.com