Privacy policy

Privacy Policy

Last updated: August 25, 2025

This Privacy Policy describes how Ollie & Jo (“Ollie & Jo,” “we,” “us,” or “our”) collects, uses, discloses, and retains personal information when you visit or shop on ollieandjo.com, engage with our marketing and customer service, or otherwise interact with our services. It also explains your rights and choices, including how to opt out of the sale/sharing of personal information and targeted advertising, and how we honor required browser-based opt-out signals.

Contact: contact@ollieandjo.com
Mail: 38045 47th St E, Ste E #404, Palmdale, CA 93552, United States


1) Scope

This Privacy Policy applies to information collected through our website, customer support channels, order processing, in-email or SMS interactions, social interactions we control, and integrated apps or services we use to operate our store. It does not apply to third-party websites or services we do not control. Where local laws provide additional rights or obligations, those appear in the State Privacy Addendum below.

2) Key Definitions

  • Personal Information / Personal Data: information that identifies, relates to, describes, or could reasonably be linked to a particular person or household.
  • Sensitive Personal Information: certain data defined by law (for example, account log-in and password). We describe our limited use of this below.
  • Sale and Share: as used under California law; “sale” includes disclosure for valuable consideration and “share” covers cross-context behavioral advertising.
  • Targeted Advertising: ads based on an individual’s activities across non-affiliated sites/apps.
  • Opt-out Preference Signal: recognized browser/device signal (for example, Global Privacy Control) indicating a consumer’s opt-out choice.
  • Service Providers/Processors: companies that process data on our behalf under contract (hosting, payments, shipping, support, analytics, advertising partners acting as processors, security, and similar services).

3) What We Collect (Categories, Purposes, Retention)

We collect the categories of personal information in the table below. “Sell/Share” refers to use for targeted advertising or disclosures that meet state law definitions. Retention reflects typical periods and may vary by business, legal, or tax requirements.

Category Examples Main Purposes Sell/Share for Ads Typical Retention Common Recipients
Identifiers Name, email, phone; shipping/billing address; order ID; online identifiers Orders, shipping, account management, customer support, fraud prevention, legal recordkeeping May share certain online identifiers for ads unless you opt out Orders: 7 years; accounts: while active + 2 years; support logs: 3 years Payment processor; carriers; support tools; analytics/ads partners
Commercial information Cart contents, items viewed, order history, returns, gift messages Fulfillment/returns, personalization, analytics, forecasting No sale; may share pseudonymous activity for ads unless you opt out Orders/returns: 7 years; browsing/cart: 24 months Same as above
Internet/technical IP address, device/browser type, pages viewed, cookie IDs, pixels/SDKs, performance logs Site operations, security, debugging, analytics, advertising May share for ads unless you opt out or send an opt-out signal Logs: 24 months; cookie IDs: up to 24 months Hosting/security, analytics, ad tech
Approximate geolocation City/region inferred from IP Fraud prevention, tax/shipping estimates, localization May share as part of analytics/ads unless you opt out 24 months Hosting, analytics/ads
Payment data (via processor) Tokenized card data, last 4, billing ZIP Payments, refunds, fraud prevention No sale/share; we do not store full card numbers Per processor schedule PCI-compliant payment processor
Inferences Preferences/segments (for example, size or color affinity) Personalization and marketing where permitted May share for ads unless you opt out 24 months Email/SMS platform; ad tech
User content Product reviews, survey responses, support messages Display reviews, improve products/services, customer support No sale/share Reviews: while displayed; support threads: 3 years Reviews platform; support tools
Sensitive Personal Information (limited) Account log-in and password Account access and security only No sale/share; Right to Limit not applicable While account active + 2 years in security logs Hosting/security

Sources of Personal Information

  • Directly from you: checkout, forms, account, support messages, reviews.
  • Automatically: cookies, pixels, SDKs, logs, and similar technologies.
  • Service providers and partners: payments, shipping, support, analytics, advertising.

Combining Information

Where permitted, we may combine information from different sources to operate, secure, and improve our services and to personalize experiences.


4) How We Use Personal Information

  • Provide, personalize, and secure the Site, accounts, and orders.
  • Process payments, fulfill and deliver orders, and handle returns.
  • Customer support, communications, and order notifications.
  • Analytics, debugging, quality and safety improvements.
  • Interest-based advertising and measurement where permitted or with consent.
  • Fraud detection, incident response, and legal compliance.
  • Business transfers (for example, merger or acquisition).

Advertising, Analytics, and Cross-Context Behavioral Advertising

We may use analytics and advertising technologies to understand performance and deliver relevant offers. Where laws treat certain uses as a “sale” or “sharing,” you may opt out as described below. We do not knowingly sell or share the personal information of consumers under 16.


5) Disclosing Personal Information

We disclose personal information to the following categories of recipients:

  • Service providers/processors: hosting, cloud services, payments, shipping, support, reviews, analytics/advertising partners acting as processors, security.
  • Advertising/marketing partners: for targeted advertising and measurement where permitted or with consent.
  • Affiliates and business transferees: in the event of a reorganization, merger, sale, or acquisition.
  • Authorities and others: to comply with law or protect rights, safety, and property.

California-Style 12-Month Disclosure Summary

  • Sold or Shared for targeted advertising in the last 12 months: identifiers, internet/technical data, and inferences may have been shared with advertising/analytics partners unless you opted out or sent a valid opt-out signal.
  • Disclosed for a business purpose in the last 12 months: all categories listed above may be disclosed to service providers for processing activities such as hosting, fulfillment, payments, customer support, and security.

6) Your Choices

  • Do Not Sell or Share / Targeted Advertising Opt-Out: use Do Not Sell or Share / Your Privacy Choices.
  • Cookie Preferences: manage non-essential cookies by category in Cookie Preferences.
  • Email: unsubscribe using the link in any marketing email.
  • SMS: reply STOP to opt out of marketing texts. Transactional messages may still be sent.

7) Opt-Out Preference Signals

If your browser or extension sends a recognized opt-out preference signal (for example, Global Privacy Control), we treat it as a request to opt out of the sale/sharing of personal information and targeted advertising for that browser where required by law. Use on-site controls for other browsers or devices.

8) Your Privacy Rights and How to Exercise Them

Depending on your state of residence, you may have rights to access/know, delete, correct, obtain a portable copy, opt out of sale/sharing/targeted advertising and certain profiling, and to appeal a decision.

Submit a request: email contact@ollieandjo.com with “Privacy Request,” or use the options provided on the Your Privacy Choices page.

Verification: we may request information to verify your identity and state of residence, including for authorized agents where permitted.

Timing: we generally respond within 45 days and may extend once by 45 days when reasonably necessary. If we deny your request, you may appeal by replying to our decision; we will respond within the applicable timeframe and explain our decision.

Non-discrimination: we will not discriminate against you for exercising your rights.

9) Sensitive Personal Information and the California Right to Limit

We process account log-in credentials to operate and secure your account. We do not use or disclose Sensitive Personal Information for purposes that require offering a “Limit the Use of My Sensitive Personal Information” option. If that changes, we will provide the required control.

10) Notice of Financial Incentive

From time to time, we may offer programs that provide a price or service difference (for example, a sign-up discount). Participation is voluntary and you may opt out at any time.

  • Program example: new-subscriber email discount (one-time percentage off).
  • Categories of data: email address; engagement metrics; purchase attribution.
  • How to opt in/out: submit your email; unsubscribe via the link in any email.
  • Good-faith data valuation: based on average revenue per subscriber, offer value, and program costs.

11) Cookies and Similar Technologies

We use strictly necessary, preferences/functional, performance/analytics, and advertising/retargeting technologies. For details and controls, see our Cookie Policy and adjust settings in Cookie Preferences.

12) Deidentified Data

Where we maintain and use deidentified data, we take reasonable measures to ensure the data cannot be associated with an individual, commit to maintaining it in deidentified form, and do not attempt to reidentify it except as permitted by law for testing and security.

13) Security

We implement reasonable administrative, technical, and physical safeguards appropriate to the nature of the information, including access controls, encryption in transit where applicable, backup and recovery procedures, and monitoring for suspicious activity. No method of transmission or storage is guaranteed to be 100% secure.

14) Children’s Privacy

Our services are intended for general audiences and are not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, contact contact@ollieandjo.com so we can delete it.

15) International Visitors (EEA/UK)

Where European or UK laws apply, we rely on appropriate legal bases (for example, contract, legitimate interests, consent) and honor local rights (access, deletion, correction, portability, objection, restriction, and withdrawal of consent). Non-essential cookies and advertising require prior consent. You may adjust preferences in Cookie Preferences.

16) Shopify-Specific Notes

  • Shop and Shop Pay: when you use Shop or Shop Pay, certain data may be controlled by the platform provider. Manage those choices in your app or account settings.
  • Platform enforcement of choices: we use platform privacy tooling so your cookie/consent choices and sale/sharing opt-outs propagate to pixels, checkout, audiences, and related services.

16A) Payments & Financing Providers

Depending on availability in your region and the options you select at checkout, payments may be processed by one or more of the providers below. These providers receive the information necessary to process your transaction (for example, name, billing details, order total) and handle it under their own privacy notices:

Provider What they do Privacy link
Shopify Payments (Stripe) Primary card processing, tokenization, fraud screening Shopify Privacy · Stripe Privacy
Shop Pay / Shop Pay Installments (Affirm) Express checkout; installment financing (where available) Shop App Privacy · Affirm Privacy
PayPal Wallet payments, PayPal balance, PayPal Credit (where available) PayPal Privacy
Apple Pay Express checkout on Apple devices Apple Privacy
Google Pay Express checkout on Android/Chrome Google Privacy
Meta Pay Wallet checkout via Facebook/Instagram (if enabled) Meta Privacy
Klarna / Afterpay / Sezzle / Amazon Pay Alternative payments or “buy now, pay later” (if offered) Klarna · Afterpay · Sezzle · Amazon Pay

We disclose only the information needed for each service to function (for example, shipping address to carriers; order details to payments). Where a provider acts as our processor, it is bound by contract to use the information only to perform services for us.

16B) Third-Party Providers Index

To operate our store, we use third parties under contracts that limit their use of your data. Below are common providers we use or may use (depending on your choices, your device, and region). Each item links to the provider’s privacy notice:

Analytics & Advertising
Google
Meta (Facebook/Instagram)
TikTok
Pinterest
Microsoft Ads
X (Twitter)
Hotjar
Email & SMS
Klaviyo
Mailchimp
Attentive
Postscript
Reviews & UGC
Judge.me
Loox
Stamped
Yotpo
Order Tracking & Logistics
Tracktor (Shop app integration)
USPS
UPS
FedEx
DHL
Customer Support
Gorgias
Zendesk
Help Scout

We disclose only the information needed for each service to function (for example, shipping address to carriers; order details to payments). Where a provider acts as our processor, it is bound by contract to use the information only to perform services for us.

17) Data Retention Schedule (Detail)

Data Type Examples Default Period Basis Disposition
Order & transaction records Order ID, items, price, taxes, delivery 7 years Tax, accounting, legal Deletion or deidentification
Account profile Name, contact info, addresses While active + 2 years Operational necessity; fraud prevention Deletion or deidentification
Customer support threads Emails, chat logs, attachments (if any) 3 years Operational records; dispute resolution Deletion
Analytics & ads identifiers Cookie IDs, event logs Up to 24 months Performance measurement; improvement Deletion or aggregation
Payment tokens Tokenized card; last 4; billing ZIP Per processor schedule PCI compliance; fraud prevention Deletion by processor
Reviews Display name, rating, comments While displayed User-generated content Deletion upon removal
Security & access logs Login attempts, IP, device details Up to 24 months Security monitoring Deletion

18) Authorized Agents and Verification

Where permitted, you may use an authorized agent to submit a privacy request on your behalf. We may require proof of authorization, verification of your identity, and confirmation through your email or account.

19) Non-Discrimination

We will not deny goods or services, charge different prices, or provide a different level or quality of goods or services because you exercised a privacy right, except to the extent permitted when differences are reasonably related to the value of your data or as part of a lawful financial incentive program.

20) California Shine the Light and Minor Users

California residents may request information about certain disclosures of personal information to third parties for their direct marketing purposes. If you are a California resident and under 18 and have an account, you may request removal of content you publicly posted on our Site, subject to certain exceptions. To submit either request, email contact@ollieandjo.com.

21) Nevada Do Not Sell

Nevada residents may direct us not to sell certain personal information. Submit a “Nevada Do Not Sell” request to contact@ollieandjo.com.

22) Accessibility

Individuals who need this Policy in an alternative format can email contact@ollieandjo.com. We will work to provide the content in a format that is accessible to you.

23) Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page and, where appropriate, provide additional notice (for example, by email or on-site banner).


State Privacy Addendum (United States)

This Addendum summarizes rights for residents of certain U.S. states. Thresholds and exemptions may apply. Use Do Not Sell or Share / Your Privacy Choices or email contact@ollieandjo.com to exercise rights.

State Core Rights Opt-Outs Appeal Window Signals
California Access/Know, Delete, Correct, Portability Sale/Sharing, Certain Profiling GPC honored
Colorado Access, Delete, Correct, Portability Sale, Targeted Ads, Profiling 45 days Universal signal
Connecticut Access, Delete, Correct, Portability Sale, Targeted Ads, Profiling 45 days Signal required
Oregon Access, Delete, Correct, Portability Sale, Targeted Ads, Profiling 45 days Signal required (date-based)
Texas, Utah, Virginia, Delaware, New Jersey, Iowa, Nebraska, New Hampshire, Montana, Nevada Vary by state: generally Access, Delete, Correct (in most), Portability Targeted Ads, Sale (and profiling in some states) Typically 45–60 days Signals honored where required

Your Privacy Choices (Quick Links)