PRIVACY POLICY
1. An overview of data protection
Introduction
This privacy policy sets out how Star Registration (Star Register SIA, Aleksandra Caka iela 125 - 7, Riga, Latvia) Reg. Nr.: 40203031753 ("we") collects, uses, discloses, and protects personal information provided by users ("user / you") of our website starcertificate.co.uk and related services. The purpose of this Privacy Policy is to inform you about your rights regarding your personal information and to ensure transparency about our data practices.
Personal information refers to any data with which you can be personally identified. Detailed information on the subject of data protection is provided below.
Data Collcted on our Website
The data collected on this website are processed by the website operator.
What data we collect?
We collect various types of data when you interact with our services, including:
-
Personal Data: Name, email address, shipping address, phone number, payment information, and other details needed to process orders and provide customer support.
-
Usage Data: Data collected automatically through cookies and tracking technologies, including IP addresses, browser types, and browsing behavior.
How do we collect your data?
Data is collected through the following methods:
-
Direct Data Collection: Data you provide when completing forms (e.g., at checkout or account registration) or when communicating with us through email, live chat, or voice messages.
-
Automatic Data Collection: Data gathered automatically using cookies and analytics tools as you browse our website.
How we use your data?
The data we collect is used to ensure proper functionality of the website and to analyze and improve users' experience on the website.
Specifically, we use the information for the following purposes:
-
To process and deliver your orders.
-
To provide customer service and respond to inquiries.
-
To send marketing communications (if you have opted in).
-
To improve and personalize your experience on our website.
-
To analyze usage patterns to improve our services.
User Rights Regarding to the Collected Data
As a user of our website, you have certain rights regarding your personal data, which may vary based on your location. We respect your rights and aim to facilitate the exercise of these rights regarding your personal data as outlined below:
-
Access: Request a copy of your personal data and confirmation of its processing.
-
Rectification: Request correction of inaccurate or incomplete data.
-
Correction: You can request corrections to your personal data.
-
Right to Deletion: Request deletion of your personal data when it is no longer needed or if you withdraw consent.
-
Restriction: Request restriction of processing under certain conditions.
-
Portability: Receive your personal data in a structured format and transfer it to another service.
-
Objection: Object to processing based on legitimate interests or for direct marketing.
-
Withdraw Consent: Withdraw consent at any time if processing is based on consent.
If you have any questions or concerns regarding data protection, or wish to exercise your rights, you can contact us at any time via email [email protected].
Compliance Statement
We are protecting your privacy and ensuring that your personal information is processed in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR) for users in the European Union and the California Consumer Privacy Act (CCPA) for users in California.
-
User Rights under GDPR: If you are a resident of the EU, you have certain rights regarding your personal data, including the right to access, rectify, delete, restrict processing, and data portability.
-
User Rights under CCPA: If you are a California resident, you have the right to know what personal data we collect about you, to whom we sell it, and to request deletion of your personal information.
Analytics and Third-Party Tools
When visiting our website, statistical analyses of your browsing behavior may be conducted using cookies and analytics services. These analyses are primarily anonymized, meaning that we will not be able to identify you from this data.
You have the option to object to such analyses or prevent them by adjusting your browser settings or avoiding the use of specific tools. For more information on how to exercise your options, please see the relevant sections on cookies and third-party modules and analytics in this Privacy Policy.
2. General and Mandatory Information
Confidentiality and Security of Personal Information
We take the protection of your personal data seriously and treat it confidentially, applying all appropriate security measures to safeguard it against unauthorized access, alteration, disclosure, or destruction and wherever possible we use adequate security software and working procedures to ensure the security of your personal data.
Our security measures include:
-
Data Encryption: We use industry-standard encryption protocols (e.g., SSL/TLS) to protect your data during transmission over the internet.
-
Access Controls: Access to personal data is restricted to authorized personnel only, and all employees are trained in data protection and security practices.
-
Regular Security Audits: We conduct regular audits and assessments of our security practices to identify and mitigate potential vulnerabilities.
-
Data Breach Response Plan: In the event of a data breach, we have a response plan in place to address the issue promptly and notify affected users as required by law.
However, while we strive to use best practices to protect your personal data, please note that no method of transmission of data and information over the internet or electronic storage is completely secure.
Data Retention
We retain your personal data only for as long as is necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. The specific retention periods for different types of data are determined based on our legitimate business needs and applicable laws.
-
Order Data: We retain order-related information for a minimum of (needs to insert duration) to comply with tax and accounting regulations.
-
Account Data: If you have an account with us, we will retain your account information until you request its deletion or until your account is inactive for a period of (needs to insert duration).
-
Communication Data: Any correspondence you have with us, including emails and chat messages, may be retained for up to (needs to insert duration) for quality assurance and training purposes.
Revocation of your Consent to the Processing of your Data
Certain data processing activities are only possible with your explicit consent. You may withdraw this consent at any time with future effect by simply contacting us via email at [email protected]. Any data processed before we receive your request may still be legally processed.
SSL or TLS encryption
This site uses SSL or TLS encryption to ensure the security of your data during transmission, such as when submitting confidential content like inquiries or order details. You can recognize an encrypted connection in the browser's address bar when it switches from "http://" to "https://" and the lock icon is displayed.
When SSL or TLS encryption is activated, any data you transmit to us cannot be accessed by unauthorized third parties.
Encrypted Payments on this Website
If you enter into a contract that requires providing payment information (e.g., credit card numbers or other payment details), these transactions are processed securely using encrypted SSL or TLS connections.
You can identify an encrypted connection in your browser’s address bar, which changes from "http://" to "https://", along with a lock symbol. In the case of encrypted communication, your payment details are protected and cannot be accessed by third parties.
Opposition to Promotional emails
We strictly prohibit the use of contact information provided on our site for the purpose of sending unsolicited promotional or informational materials. Users who receive unsolicited emails or marketing communications are encouraged to report such incidents to us. We reserve the right to take appropriate legal action against any entity that engages in unsolicited email practices.
If you wish to opt-out of our promotional communications, you may do so by following the unsubscribe link in our emails or by contacting us directly at [email protected].
International Data Transfers
If you are located outside the European Economic Area (EEA), please note that your information may be transferred to and processed in countries that may not provide the same level of data protection as your home jurisdiction. We ensure that appropriate safeguards, such as Standard Contractual Clauses (SCCs), are in place to protect your data.
Third Party Websites
Our website may include links to external websites. Please note that we are not accountable for the privacy practices of these external sites. We encourage users to review the privacy policies of any linked websites to ensure they align with your expectations before interacting with them. Including a link does not imply our endorsement of the content, views, or accuracy of information found on those websites.
Children’s Online Privacy
We comply with the Children’s Online Privacy Protection Act (COPPA) in the United States, which restricts the collection of personal information from children under the age of 13. Additionally, we adhere to the General Data Protection Regulation (GDPR) in Europe, which sets forth guidelines for the collection and processing of personal information for individuals under the age of 16.
Our services are not intended for use by individuals under 13 years old, and we do not knowingly collect or solicit personal information from children without verified parental consent. In compliance with GDPR, if we process personal data of children aged 16 or younger, we ensure that we have the necessary consent from a parent or guardian.
If we become aware that we have inadvertently collected data from a child under 13 in violation of COPPA, or personal data from a child under 16 without proper consent under GDPR, we will take immediate steps to delete that information.
If you believe that we may have collected personal information from a child under 13 or personal data from a child under 16 without appropriate consent, please contact us at [email protected] so we can promptly address the situation.
3. Data Collection
Cookies
Our website uses cookies to enhance user experience, improve efficiency, and provide secure browsing. Cookies are small text files stored on your device that help track certain information or remember your preferences. We primarily use "session cookies," which are automatically deleted after your visit. Some cookies, however, remain stored on your device until you manually delete them, allowing us to recognize your browser the next time you visit our site.
You can configure your browser to reject cookies or notify you when cookies are being sent, allowing you to accept or refuse them. Please note that if you choose to block cookies, certain features of our site, such as the shopping cart, may not function properly.
Cookies necessary for the operation of electronic communications or for providing specific functionalities you request (e.g., shopping cart functionality) are stored in accordance with Art. 6(1)(f) of the GDPR. The website operator has a legitimate interest in storing these cookies to ensure a smooth and error-free service. Any cookies used for tracking or analytics purposes will be addressed separately in this Privacy Policy.
Server log files
When you access our website, certain data is automatically collected and stored in server log files. This may include information such as your IP address, browser type and version, operating system, referring URL, and the time of your visit. This data is collected to ensure the proper functioning of the site, maintain security, and help with troubleshooting. These logs are not linked to any specific individual and are used for operational purposes only.
Contact Form
When you submit information via our contact form, we collect the data you provide, including your name, email address, and any message content, in order to respond to your inquiry. We do not share this information with third parties unless you explicitly provide consent to do so.
Registration on this Website
You may register an account on our website to access additional features and improve your user experience. The data you provide during registration, such as your name and email, will only be used for the purposes of providing services for which you registered. All mandatory fields must be completed to finalize your registration. Failure to provide the required information may result in the rejection of your registration.
We may also use the contact information you provide to inform you about important updates related to the website or technical changes that might affect your user experience.
Your registration data will be stored for as long as your account remains active. Legal retention requirements, however, may necessitate the storage of some data even after account deletion.
Data transmitted when entering into a contract with online shops, retailers, and mail order
We share your personal data with third parties only when necessary to fulfill your order or complete the legal obligations. This may include providing information to shipping companies responsible for delivering your purchases or financial institutions processing your payments. The following services may receive your personal information for these purposes:
Couriers:
-
Latvijas Pasts VAS;
-
DPD Latvija;
-
DHL Express Latvia SIA;
-
Federal Express Corp. (FedEx) - Latvian Branch;
Payment Services:
-
Paypal;
-
Stripe;
"Find Your Star" App and Data in Star Registry
To offer the "Find Your Star" App, we provide mobile applications available on both the App Store and Google Play. These apps allow users to search for and manage their star registrations seamlessly. Below is an overview of how we handle user data in connection with these apps.
Data Collection Through the App
When using our mobile app, we may collect data necessary for the app's functionality and user experience. This includes:
-
IP Address: We temporarily collect your IP address to establish a secure connection between your device and our servers, ensuring proper service delivery. The IP address is only stored for as long as needed to maintain the connection and resolve any potential technical issues.
-
Anonymized Analytical Data: Usage data is collected in an anonymized format to help us analyze app performance, user engagement, and ensure that the app is serving its intended audience. This data does not include any personally identifiable information.
App Store and Google Play Data
Apple App Store and Google Play may collect certain data in accordance with their respective privacy policies. We encourage you to review these policies to understand how your data may be handled by those platforms:
Star Registry Data
The details of registered stars are stored in a public database, star-register.eu, where anyone can search for registered stars. This can also be done through our app or on the https://star-finder.starregistration.net/ website. Please note, only the star's name is publicly available; no personal data is shared unless it was voluntarily included by the user at the time of star registration. For privacy protection, we recommend providing only the star's name without additional personal identifiers.
4. Social Media and Third-Party Platforms
Social Media Platforms
We utilize various social media platforms, such as Meta (which includes Facebook and Instagram), TikTok, and Twitter. These platforms feed data through tracking pixels that are integrated into our website. The data collected through these pixels may include your order details (such as order number, email address, and name), and this information is used for advertising, tracking, and analytics purposes.
Each platform processes your personal data according to its privacy policies. We encourage users to review the privacy policies of these platforms for more details:
Trustpilot Reviews Platform
We also work with Trustpilot, Inc., a third-party reviews platform that enables us to collect and display customer reviews. When you place an order, we may share your order number, email address, and name with Trustpilot to invite you to leave feedback on your experience. The data shared with Trustpilot is used solely for the purpose of facilitating these review invitations and ensuring the authenticity of customer reviews.
You can read more about Trustpilot's data practices in their Privacy Policy.
Facebook Plugins (Like & Share Buttons)
Our website may include social plugins from Facebook, such as the Like and Share buttons. These plugins are operated by Facebook Inc. You can recognize the Facebook plugins by the Facebook logo or the Like button displayed on our site.
When you visit a page on our website that includes a Facebook plugin, your browser establishes a direct connection to Facebook's servers. Facebook receives information about your visit to our site, including your IP address. If you are logged into your Facebook account, your activity on our website may be linked to your Facebook profile. To prevent this, you can log out of your Facebook account while browsing our website.
For more details, please refer to Facebook’s Privacy Policy.
5. Analytics and Advertising
Google Analytics (GA4)
We use Google Analytics 4 (GA4), a web analytics service provided by Google Ireland Limited, to track and analyze website traffic. This helps us understand how users interact with our website and improve the overall experience. GA4 collects data such as user behavior and engagement while ensuring privacy measures like IP anonymization within the EU/EEA.
GA4 uses cookies to track user activity on our site. You can choose to prevent cookies from being stored by adjusting your browser settings, but note that this may affect website functionality. Google will process the collected data on our behalf, as we have entered into an agreement with Google for data processing in compliance with applicable data protection regulations.
For more information, you can visit the Google Privacy Policy.
Facebook Pixel
We use the Facebook Pixel from Meta Platforms, Inc. to measure the effectiveness of our Facebook ads. The pixel tracks actions users take on our site after interacting with our ads, allowing us to analyze ad performance for future optimization.
The data collected via the Facebook Pixel is anonymous to us and does not reveal users' identities. However, Facebook may associate this data with your Facebook profile and use it for advertising on its platform and third-party websites. For more details, please refer to the Facebook Privacy Policy.
You can opt out of Facebook's custom audience tracking in your Ads Preferences.
Google Ads and Remarketing
We use Google Ads and Google Analytics Remarketing provided by Google Ireland Limited to deliver personalized ads across devices. This feature allows us to show ads based on your past interactions with our website across your mobile phone, tablet, and computer.
If you want to disable personalized ads, you can do so in your Google Ad Settings.
Microsoft Ads
We also use Microsoft Ireland Operations Limited for Pay-Per-Click (PPC) advertising campaigns. Order data, such as order numbers, may be transmitted to Microsoft to track conversions and improve ad performance.
Google reCAPTCHA
To protect our site from spam and abuse, we use Google reCAPTCHA to verify whether form submissions are made by humans. The reCAPTCHA service collects information like your IP address and browsing behavior to determine if the input is automated.
For more details on Google reCAPTCHA, visit Google Privacy Policy.
6. Third- Party Services, Plugins and Tools
Cloudflare Zaraz Service
We use Cloudflare’s Zaraz service provided by Cloudflare, Inc., to streamline and optimize data transfer to our third-party analytics and advertising tools, such as Google Analytics 4 (GA4) and Meta (Facebook Ads). Zaraz helps us manage the loading of third-party scripts while ensuring the efficiency and security of your data.
When using Zaraz, data may be transmitted to GA4 and Meta to measure site performance, improve user experience, and optimize ad campaigns. These data transfers are in line with our data processing agreements with these providers and comply with applicable data protection regulations.
For more information about Cloudflare's privacy practices, please visit Cloudflare Privacy Policy.
Customer Support via ZenDesk
We use Zendesk Support, a customer service platform provided by Zendesk Inc., to manage and process customer inquiries. When you reach out to us through our customer support system, we may collect personal data such as your name, email address, postal address, phone number, and any other relevant details needed to handle your inquiry.
For more information on how Zendesk handles data, please refer to Zendesk’s Privacy Policy.
If you contact us via email or through a form on our website, the personal information you provide will be used solely to address your request. All submitted data, along with the communication history between you and our support team, is stored securely to facilitate follow-up responses and any future interactions.
7. Newsletter
Newsletter Data
We process your personal data to send our newsletter to you if you’ve subscribed to it, either separately or during the order process. To receive our newsletter, we require a valid email address, along with verification that you are the owner of that email address and that you consent to receiving the newsletter. No additional data is collected unless voluntarily provided. This information is used solely for sending the requested newsletter and will not be shared with third parties. The personal data we process for this purpose includes name and Email address.
The legal basis for processing this data is our legitimate interest in keeping you updated about company news, special offers, discount codes, and new products or services. Your data will be used to send the newsletter until you choose to unsubscribe, at which point the data will be deleted from our mailing list.
Third-Party Services Used for Newsletter Distribution and Communication
Klaviyo Inc. (Email Marketing)
We use this email marketing platform for automating eCommerce SMS and email marketing. We transfer all order-related data (name, email address, and order details) to Klaviyo, as well as data from users who have subscribed to the newsletter or created an account on starcertificate.co.uk. To learn more about Klaviyo's privacy practices, please visit their Privacy Policy.
Google Cloud EMEA Limited (Google Workspace)
We utilize Google Workspace to facilitate effective communication with customers via email. For more information, please visit Google’s Privacy Policy.
Amazon AWS (Amazon Web Services)
We utilize Amazon Web Services to host our website, ensuring secure and reliable access. Additionally, we employ Amazon Simple Email Service (SES) for dispatching system-generated emails, such as order confirmations, invoices, shipment updates, and refund notifications. To learn more about Amazon's privacy practices, please visit their Privacy Policy.
Sonetel AB
We use this system to manage voice messages. When a voice message is left, the phone number, along with any personal data such as name or other details mentioned during the call, may be recorded in the message. For more information about Sonetel's privacy practices, please visit their Privacy Policy.
8. Payment Service Providers
PayPal
Our website accepts payments via PayPal. The service provider for this payment method is PayPal (Europe) S.à r.l. & Cie, S.C.A.. When you select PayPal as your payment method, the payment data you provide will be transmitted to PayPal. We share the necessary information with PayPal to ensure secure and reliable payment processing. For more information on how PayPal handles your data, please refer to their Privacy Policy.
Card Payments (Stripe)
If you choose to pay by credit card, your payment will be processed through Stripe Payments Europe Ltd, Block 4, Harcourt Center, Harcourt Road, Dublin 2, Ireland. We will disclose the following information to Stripe during the ordering process: name, address, account number, bank code, credit card number (if applicable), order amount, currency and transaction number.
The transfer of your data to Stripe is solely for the purpose of processing your payment. For more details on Stripe’s data protection practices, please visit their Privacy Policy.
9. Updates and Changes
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. When we make changes, we will revise the "Last Updated" date at the top of this policy.
We encourage users to periodically review this Privacy Policy to stay informed about how we are protecting their information. Your continued use of our services after any modifications to the Privacy Policy constitutes your acceptance of the updated terms.
If we make significant changes that affect your rights or the way we process your personal data, we will notify you through our website or by other means, providing you with the opportunity to review the changes before they take effect.
10. Contact Information
If you have any questions or concerns regarding this Privacy Policy or our data practices, or if you wish to exercise your rights as outlined above, please contact us at Email: [email protected]
We aim to respond to all inquiries and requests promptly.