Privacy policy
Privacy Policy
Last updated: August 25, 2025
This Privacy Policy describes how Ollie & Jo (“Ollie & Jo,” “we,” “us,” or “our”) collects, uses, discloses, and retains personal information when you visit or shop on ollieandjo.com, engage with our marketing and customer service, or otherwise interact with our services. It also explains your rights and choices, including how to opt out of the sale/sharing of personal information and targeted advertising, and how we honor required browser-based opt-out signals.
Contact: contact@ollieandjo.com
Mail: 38045 47th St E, Ste E #404, Palmdale, CA 93552, United States
1) Scope
This Privacy Policy applies to information collected through our website, customer support channels, order processing, in-email or SMS interactions, social interactions we control, and integrated apps or services we use to operate our store. It does not apply to third-party websites or services we do not control. Where local laws provide additional rights or obligations, those appear in the State Privacy Addendum below.
2) Key Definitions
- Personal Information / Personal Data: information that identifies, relates to, describes, or could reasonably be linked to a particular person or household.
- Sensitive Personal Information: certain data defined by law (for example, account log-in and password). We describe our limited use of this below.
- Sale and Share: as used under California law; “sale” includes disclosure for valuable consideration and “share” covers cross-context behavioral advertising.
- Targeted Advertising: ads based on an individual’s activities across non-affiliated sites/apps.
- Opt-out Preference Signal: recognized browser/device signal (for example, Global Privacy Control) indicating a consumer’s opt-out choice.
- Service Providers/Processors: companies that process data on our behalf under contract (hosting, payments, shipping, support, analytics, advertising partners acting as processors, security, and similar services).
3) What We Collect (Categories, Purposes, Retention)
We collect the categories of personal information in the table below. “Sell/Share” refers to use for targeted advertising or disclosures that meet state law definitions. Retention reflects typical periods and may vary by business, legal, or tax requirements.
| Category | Examples | Main Purposes | Sell/Share for Ads | Typical Retention | Common Recipients |
|---|---|---|---|---|---|
| Identifiers | Name, email, phone; shipping/billing address; order ID; online identifiers | Orders, shipping, account management, customer support, fraud prevention, legal recordkeeping | May share certain online identifiers for ads unless you opt out | Orders: 7 years; accounts: while active + 2 years; support logs: 3 years | Payment processor; carriers; support tools; analytics/ads partners |
| Commercial information | Cart contents, items viewed, order history, returns, gift messages | Fulfillment/returns, personalization, analytics, forecasting | No sale; may share pseudonymous activity for ads unless you opt out | Orders/returns: 7 years; browsing/cart: 24 months | Same as above |
| Internet/technical | IP address, device/browser type, pages viewed, cookie IDs, pixels/SDKs, performance logs | Site operations, security, debugging, analytics, advertising | May share for ads unless you opt out or send an opt-out signal | Logs: 24 months; cookie IDs: up to 24 months | Hosting/security, analytics, ad tech |
| Approximate geolocation | City/region inferred from IP | Fraud prevention, tax/shipping estimates, localization | May share as part of analytics/ads unless you opt out | 24 months | Hosting, analytics/ads |
| Payment data (via processor) | Tokenized card data, last 4, billing ZIP | Payments, refunds, fraud prevention | No sale/share; we do not store full card numbers | Per processor schedule | PCI-compliant payment processor |
| Inferences | Preferences/segments (for example, size or color affinity) | Personalization and marketing where permitted | May share for ads unless you opt out | 24 months | Email/SMS platform; ad tech |
| User content | Product reviews, survey responses, support messages | Display reviews, improve products/services, customer support | No sale/share | Reviews: while displayed; support threads: 3 years | Reviews platform; support tools |
| Sensitive Personal Information (limited) | Account log-in and password | Account access and security only | No sale/share; Right to Limit not applicable | While account active + 2 years in security logs | Hosting/security |
Sources of Personal Information
- Directly from you: checkout, forms, account, support messages, reviews.
- Automatically: cookies, pixels, SDKs, logs, and similar technologies.
- Service providers and partners: payments, shipping, support, analytics, advertising.
Combining Information
Where permitted, we may combine information from different sources to operate, secure, and improve our services and to personalize experiences.
4) How We Use Personal Information
- Provide, personalize, and secure the Site, accounts, and orders.
- Process payments, fulfill and deliver orders, and handle returns.
- Customer support, communications, and order notifications.
- Analytics, debugging, quality and safety improvements.
- Interest-based advertising and measurement where permitted or with consent.
- Fraud detection, incident response, and legal compliance.
- Business transfers (for example, merger or acquisition).
Advertising, Analytics, and Cross-Context Behavioral Advertising
We may use analytics and advertising technologies to understand performance and deliver relevant offers. Where laws treat certain uses as a “sale” or “sharing,” you may opt out as described below. We do not knowingly sell or share the personal information of consumers under 16.
5) Disclosing Personal Information
We disclose personal information to the following categories of recipients:
- Service providers/processors: hosting, cloud services, payments, shipping, support, reviews, analytics/advertising partners acting as processors, security.
- Advertising/marketing partners: for targeted advertising and measurement where permitted or with consent.
- Affiliates and business transferees: in the event of a reorganization, merger, sale, or acquisition.
- Authorities and others: to comply with law or protect rights, safety, and property.
California-Style 12-Month Disclosure Summary
- Sold or Shared for targeted advertising in the last 12 months: identifiers, internet/technical data, and inferences may have been shared with advertising/analytics partners unless you opted out or sent a valid opt-out signal.
- Disclosed for a business purpose in the last 12 months: all categories listed above may be disclosed to service providers for processing activities such as hosting, fulfillment, payments, customer support, and security.
6) Your Choices
- Do Not Sell or Share / Targeted Advertising Opt-Out: use Do Not Sell or Share / Your Privacy Choices.
- Cookie Preferences: manage non-essential cookies by category in Cookie Preferences.
- Email: unsubscribe using the link in any marketing email.
- SMS: reply STOP to opt out of marketing texts. Transactional messages may still be sent.
7) Opt-Out Preference Signals
If your browser or extension sends a recognized opt-out preference signal (for example, Global Privacy Control), we treat it as a request to opt out of the sale/sharing of personal information and targeted advertising for that browser where required by law. Use on-site controls for other browsers or devices.
8) Your Privacy Rights and How to Exercise Them
Depending on your state of residence, you may have rights to access/know, delete, correct, obtain a portable copy, opt out of sale/sharing/targeted advertising and certain profiling, and to appeal a decision.
Submit a request: email contact@ollieandjo.com with “Privacy Request,” or use the options provided on the Your Privacy Choices page.
Verification: we may request information to verify your identity and state of residence, including for authorized agents where permitted.
Timing: we generally respond within 45 days and may extend once by 45 days when reasonably necessary. If we deny your request, you may appeal by replying to our decision; we will respond within the applicable timeframe and explain our decision.
Non-discrimination: we will not discriminate against you for exercising your rights.
9) Sensitive Personal Information and the California Right to Limit
We process account log-in credentials to operate and secure your account. We do not use or disclose Sensitive Personal Information for purposes that require offering a “Limit the Use of My Sensitive Personal Information” option. If that changes, we will provide the required control.
10) Notice of Financial Incentive
From time to time, we may offer programs that provide a price or service difference (for example, a sign-up discount). Participation is voluntary and you may opt out at any time.
- Program example: new-subscriber email discount (one-time percentage off).
- Categories of data: email address; engagement metrics; purchase attribution.
- How to opt in/out: submit your email; unsubscribe via the link in any email.
- Good-faith data valuation: based on average revenue per subscriber, offer value, and program costs.
11) Cookies and Similar Technologies
We use strictly necessary, preferences/functional, performance/analytics, and advertising/retargeting technologies. For details and controls, see our Cookie Policy and adjust settings in Cookie Preferences.
12) Deidentified Data
Where we maintain and use deidentified data, we take reasonable measures to ensure the data cannot be associated with an individual, commit to maintaining it in deidentified form, and do not attempt to reidentify it except as permitted by law for testing and security.
13) Security
We implement reasonable administrative, technical, and physical safeguards appropriate to the nature of the information, including access controls, encryption in transit where applicable, backup and recovery procedures, and monitoring for suspicious activity. No method of transmission or storage is guaranteed to be 100% secure.
14) Children’s Privacy
Our services are intended for general audiences and are not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, contact contact@ollieandjo.com so we can delete it.
15) International Visitors (EEA/UK)
Where European or UK laws apply, we rely on appropriate legal bases (for example, contract, legitimate interests, consent) and honor local rights (access, deletion, correction, portability, objection, restriction, and withdrawal of consent). Non-essential cookies and advertising require prior consent. You may adjust preferences in Cookie Preferences.
16) Shopify-Specific Notes
- Shop and Shop Pay: when you use Shop or Shop Pay, certain data may be controlled by the platform provider. Manage those choices in your app or account settings.
- Platform enforcement of choices: we use platform privacy tooling so your cookie/consent choices and sale/sharing opt-outs propagate to pixels, checkout, audiences, and related services.
16A) Payments & Financing Providers
Depending on availability in your region and the options you select at checkout, payments may be processed by one or more of the providers below. These providers receive the information necessary to process your transaction (for example, name, billing details, order total) and handle it under their own privacy notices:
| Provider | What they do | Privacy link |
|---|---|---|
| Shopify Payments (Stripe) | Primary card processing, tokenization, fraud screening | Shopify Privacy · Stripe Privacy |
| Shop Pay / Shop Pay Installments (Affirm) | Express checkout; installment financing (where available) | Shop App Privacy · Affirm Privacy |
| PayPal | Wallet payments, PayPal balance, PayPal Credit (where available) | PayPal Privacy |
| Apple Pay | Express checkout on Apple devices | Apple Privacy |
| Google Pay | Express checkout on Android/Chrome | Google Privacy |
| Meta Pay | Wallet checkout via Facebook/Instagram (if enabled) | Meta Privacy |
| Klarna / Afterpay / Sezzle / Amazon Pay | Alternative payments or “buy now, pay later” (if offered) | Klarna · Afterpay · Sezzle · Amazon Pay |
We disclose only the information needed for each service to function (for example, shipping address to carriers; order details to payments). Where a provider acts as our processor, it is bound by contract to use the information only to perform services for us.
16B) Third-Party Providers Index
To operate our store, we use third parties under contracts that limit their use of your data. Below are common providers we use or may use (depending on your choices, your device, and region). Each item links to the provider’s privacy notice:
We disclose only the information needed for each service to function (for example, shipping address to carriers; order details to payments). Where a provider acts as our processor, it is bound by contract to use the information only to perform services for us.
17) Data Retention Schedule (Detail)
| Data Type | Examples | Default Period | Basis | Disposition |
|---|---|---|---|---|
| Order & transaction records | Order ID, items, price, taxes, delivery | 7 years | Tax, accounting, legal | Deletion or deidentification |
| Account profile | Name, contact info, addresses | While active + 2 years | Operational necessity; fraud prevention | Deletion or deidentification |
| Customer support threads | Emails, chat logs, attachments (if any) | 3 years | Operational records; dispute resolution | Deletion |
| Analytics & ads identifiers | Cookie IDs, event logs | Up to 24 months | Performance measurement; improvement | Deletion or aggregation |
| Payment tokens | Tokenized card; last 4; billing ZIP | Per processor schedule | PCI compliance; fraud prevention | Deletion by processor |
| Reviews | Display name, rating, comments | While displayed | User-generated content | Deletion upon removal |
| Security & access logs | Login attempts, IP, device details | Up to 24 months | Security monitoring | Deletion |
18) Authorized Agents and Verification
Where permitted, you may use an authorized agent to submit a privacy request on your behalf. We may require proof of authorization, verification of your identity, and confirmation through your email or account.
19) Non-Discrimination
We will not deny goods or services, charge different prices, or provide a different level or quality of goods or services because you exercised a privacy right, except to the extent permitted when differences are reasonably related to the value of your data or as part of a lawful financial incentive program.
20) California Shine the Light and Minor Users
California residents may request information about certain disclosures of personal information to third parties for their direct marketing purposes. If you are a California resident and under 18 and have an account, you may request removal of content you publicly posted on our Site, subject to certain exceptions. To submit either request, email contact@ollieandjo.com.
21) Nevada Do Not Sell
Nevada residents may direct us not to sell certain personal information. Submit a “Nevada Do Not Sell” request to contact@ollieandjo.com.
22) Accessibility
Individuals who need this Policy in an alternative format can email contact@ollieandjo.com. We will work to provide the content in a format that is accessible to you.
23) Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page and, where appropriate, provide additional notice (for example, by email or on-site banner).
State Privacy Addendum (United States)
This Addendum summarizes rights for residents of certain U.S. states. Thresholds and exemptions may apply. Use Do Not Sell or Share / Your Privacy Choices or email contact@ollieandjo.com to exercise rights.
| State | Core Rights | Opt-Outs | Appeal Window | Signals |
|---|---|---|---|---|
| California | Access/Know, Delete, Correct, Portability | Sale/Sharing, Certain Profiling | — | GPC honored |
| Colorado | Access, Delete, Correct, Portability | Sale, Targeted Ads, Profiling | 45 days | Universal signal |
| Connecticut | Access, Delete, Correct, Portability | Sale, Targeted Ads, Profiling | 45 days | Signal required |
| Oregon | Access, Delete, Correct, Portability | Sale, Targeted Ads, Profiling | 45 days | Signal required (date-based) |
| Texas, Utah, Virginia, Delaware, New Jersey, Iowa, Nebraska, New Hampshire, Montana, Nevada | Vary by state: generally Access, Delete, Correct (in most), Portability | Targeted Ads, Sale (and profiling in some states) | Typically 45–60 days | Signals honored where required |