Privacy Policy
PRIVACY POLICY
Last Updated:January 3rd, 2025
1. WHO WE ARE
Website: https://www.gacaro.ai/
Operator: HAPPY INTERACTIVE LLC
Business Address: 1200 MAIN ST STE 2315 KANSAS CITY, MO 64105 US
Contact: support@gacaro.ai
2. INFORMATION WE COLLECT
Personal Data:
- Full name, email, phone number
- Shipping/billing addresses (verified via USPS address validation)
- Payment details (processed through PCI-DSS Level 1 compliant gateways)
- Clothing size preferences and style interests
Technical Data:
- IP address and device information
- Browser type and version
- Website usage patterns (pages visited, items viewed)
- Cookies (see Section 4)
User Content:
- Product reviews and ratings
- Uploaded images for customization (EXIF GPS removed automatically)
- Customer support communications
3. HOW WE USE YOUR DATA
Order Processing:
- Verify identity to prevent fraud (using third-party services like Signifyd)
- Process payments and calculate sales tax (Avalara integration)
- Ship orders via our logistics partners
Service Improvement:
- Personalized recommendations based on purchase history
- Size/fit predictions using machine learning algorithms
- Website optimization through Google Analytics (anonymized data)
Legal Compliance:
- Retain transaction records for 7 years per IRS requirements
- Respond to law enforcement requests (with valid subpoena)
- Comply with FTC regulations for e-commerce
4. COOKIES & TRACKING TECHNOLOGIES
Essential Cookies:
- Session cookies: Maintain shopping cart (expire after 24hr)
- Authentication cookies: Remember login (expire after 14 days)
Analytical Cookies:
- Google Analytics: Track traffic sources (opt-out available)
- Hotjar: Record user interactions (anonymized)
Advertising Cookies:
- Facebook Pixel: For retargeting ads (opt-out through AdChoices)
- Google Ads: Track conversion rates
How to Manage:
- Browser settings: Block/delete cookies
- GDPR/CCPA: Opt-out links in footer
- Email preferences: Unsubscribe in account settings
5. DATA SHARING & DISCLOSURE
Service Providers:
- Shipping carriers (FedEx, UPS, USPS)
- Payment processors (Stripe, PayPal)
- Cloud storage (Amazon S3 with AES-256 encryption)
Legal Requirements:
- When required by Missouri state law
- To protect against fraudulent transactions
- During business transfers (merger/acquisition)
Marketing Partners:
- Only with explicit opt-in consent
- Never sell data to third-party brokers
6. YOUR RIGHTS (CCPA/CPRA)
California Residents:
- Access: Request personal data report
- Deletion: Remove non-essential data
- Opt-out: Stop sale/sharing of data
- Correction: Update inaccurate information
Submit requests to: support@gacaro.ai (verified within 45 days)
7. DATA SECURITY
- Encryption: TLS 1.3 for all data transfers
- Storage: AWS servers with daily backups
- Vulnerability: Quarterly penetration testing
- Training: Staff certified in PCI compliance
8. CHILDREN’S PRIVACY
- COPPA Compliance: No services for under-13
- Age verification at checkout
- Parental consent required for teen orders (13-17)
9. POLICY UPDATES
- Notification: Email 30 days before changes
- Archive: Previous versions available on request
- Questions: Contact support@gacaro.ai