ANNIVERSARY SALE UP TO 70% OFF
ONLY TODAY FREE SHIPPING ON ALL ORDERS
30-DAY MONEY-BACK GUARANTEE
Cart
Your cart is currently empty.

Privacy Policy

1) Information on the Collection of Personal Data and Controller Details

We’re pleased that you’re visiting our website and thank you for your interest. This notice explains how we handle your personal data when you use our website. “Personal data” means any information relating to an identified or identifiable person.

The controller under the General Data Protection Regulation (GDPR) is The Marlow Sisters - Canmore (“we”, “us”, “our”). The controller is the natural or legal person who determines the purposes and means of processing personal data.

For security and to protect the transmission of personal data and other confidential content (e.g., orders or enquiries), our website uses SSL/TLS encryption. You can recognize an encrypted connection by “https://” and the lock icon in your browser bar.

2) Data Collected When Visiting Our Website (Server Logs)

If you use our website for information only (i.e., you do not register or otherwise submit data), we collect only the data your browser transmits to our server (“server log files”), which are technically necessary to display the website:

  • Page visited (URL)
  • Date and time of access
  • Amount of data transferred
  • Referrer URL (source page)
  • Browser and operating system used
  • IP address (possibly in anonymized form)

Processing is based on our legitimate interests (Art. 6(1)(f) GDPR) in ensuring website stability and functionality. We do not disclose these data nor use them for other purposes. However, we reserve the right to review server logs retrospectively if there are concrete indications of unlawful use.

3) Cookies

We use cookies to make our website more attractive and to enable certain functions. “Session cookies” are deleted after you close your browser; “persistent cookies” remain on your device and allow us or partners to recognize your browser on your next visit. Cookies may process browser, location and IP data. Persistent cookies are automatically deleted after their set lifetime.

Some cookies simplify ordering (e.g., remembering your cart). If personal data are processed by cookies set by us, processing is either for contract performance (Art. 6(1)(b) GDPR) or based on our legitimate interests in optimal website functionality and a user-friendly experience (Art. 6(1)(f) GDPR). We may also use third-party cookies for advertising and analytics; details appear in the relevant sections below.

You can configure your browser to notify you about cookie placement, accept cookies on a case-by-case basis, block them in specific cases or generally, and delete cookies. If you do not accept cookies, website functionality may be limited.

4) Contact

If you contact us (e.g., via form or email), we collect your personal data solely to process and respond to your enquiry and for related technical administration. Legal basis is our legitimate interest in handling your request (Art. 6(1)(f) GDPR). If your enquiry relates to a contract, the basis is Art. 6(1)(b) GDPR. We delete your data once your enquiry is resolved, unless statutory retention duties apply.

5) Customer Accounts & Contract Fulfilment

We collect and process personal data when you open a customer account or share data to perform a contract (Art. 6(1)(b) GDPR). Required data appear in the respective forms. You can request deletion of your account at any time via the contact details below. We store and use your data to process the contract and, after completion, block and delete them after tax and commercial retention periods unless you consent to further use or we are legally permitted to retain them.

6) Use of Your Data for Direct Marketing

6.1 Email Newsletter (Opt-In)

If you subscribe to our newsletter, we will send you updates about our offers. Only your email address is required; other details are optional and help personalize messages. We use a double opt-in process. By confirming your subscription, you consent to processing under Art. 6(1)(a) GDPR. We log your IP, date, and time of subscription for evidence of consent. You may unsubscribe at any time via the link in each email or by contacting us; your email will then be removed from our list unless you consent to further use or we are legally permitted to retain it.

6.2 Newsletter to Existing Customers

If you provided your email during a purchase, we may email you offers for similar products/services based on our legitimate interests in direct advertising (Art. 6(1)(f) GDPR). You can object at any time at no additional cost beyond basic transmission charges.

7) Data Processing for Orders & Payments

We share necessary data with carriers for delivery and with banks/payment providers for payment processing (Art. 6(1)(b) GDPR).

7.1 PayPal

If you pay via PayPal (including card, direct debit, “Pay in 3/installments”, or “invoice” where available), we share payment data with PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg, as needed (Art. 6(1)(b) GDPR). PayPal may run credit checks based on legitimate interests (Art. 6(1)(f) GDPR). See PayPal’s privacy policy: paypal.com/privacy. You may object directly to PayPal, though PayPal may still process data if necessary for contractual payments.

7.2 SOFORT (Klarna)

If you choose “SOFORT”, payments are processed by SOFORT GmbH (Klarna Group), Germany/Sweden. We share necessary order and customer details for payment (Art. 6(1)(b) GDPR). Privacy: klarna.com/sofort/privacy-policy.

8) Review Reminders

With your explicit consent (Art. 6(1)(a) GDPR), we may send a one-time reminder to review your order. You can revoke consent at any time via our contact details below.

9) Social Media Plugins (Shariff)

For enhanced privacy, social buttons for Facebook, Instagram, and Google are implemented as simple HTML links (Shariff). No connection to their servers occurs until you click the button, which opens the provider’s page in a new window. For details, see their privacy policies:

10) Online Marketing

10.1 Google Marketing Platform (DoubleClick)

We use DoubleClick (Google LLC) to show relevant ads, prevent duplicates, and measure performance via cookies. Processing is based on our legitimate interests in optimal marketing (Art. 6(1)(f) GDPR). You can manage ad settings here: adssettings.google.com. More info: policies.google.com/privacy.

10.2 Google Ads Conversion Tracking

When you click our Google ad, a cookie tracks conversions (expires after ~30 days). We receive aggregated statistics only. If you do not wish to participate, you can disable conversion cookies in your browser. Legal basis: Art. 6(1)(f) GDPR (legitimate interests in targeted advertising).

11) Web Analytics (Google Analytics)

We use Google Analytics with IP anonymization (“_anonymizeIp()”). In rare cases, full IPs may be sent to the US and shortened there. Processing is based on our legitimate interests in statistical analysis for optimization and marketing (Art. 6(1)(f) GDPR). You can install the opt-out add-on: tools.google.com/dlpage/gaoptout. For mobile, you can also set an opt-out cookie via your cookie preferences on our site.

12) Retargeting / Remarketing

Facebook Pixel

With your consent (Art. 6(1)(a) GDPR), we use the Facebook Pixel to measure and improve our ads. Data may be associated with your Facebook account and used per Facebook’s policy: facebook.com/about/privacy. You can opt out via your Facebook settings and the Digital Advertising Alliance: aboutads.info/choices.

Google Ads Remarketing

We use Google Ads Remarketing. Google sets a cookie to display interest-based ads using a pseudonymous ID. If you’re logged into your Google Account and consented to personalized ads, Google may link your browsing history across devices. Manage ads: adssettings.google.com.

13) Your Rights

Under applicable data protection law, you have the following rights regarding your personal data:

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction (Art. 18 GDPR)
  • Notification (Art. 19 GDPR)
  • Data portability (Art. 20 GDPR)
  • Withdraw consent at any time (Art. 7(3) GDPR)
  • Complain to a supervisory authority (Art. 77 GDPR)

Right to Object (Art. 21 GDPR)

If we process your personal data based on our legitimate interests, you have the right to object at any time on grounds relating to your particular situation. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is for the establishment, exercise, or defense of legal claims.

If we process your data for direct marketing, you may object at any time. We will then stop processing your data for these purposes.

14) Retention Periods

We store personal data for the duration of statutory retention periods (e.g., tax or commercial law). After expiry, we routinely delete the data unless needed for contract performance/initiation or if we have a legitimate interest in continued storage.

15) Updates to This Policy

We may update this Privacy Policy from time to time. The latest version is always available on this page. Continued use of our website after changes indicates acceptance of the updated terms.

16) Contact

If you have questions about this Privacy Policy or wish to exercise your rights, please contact us



Privacy Policy