Privacy Policy
PRIVACY POLICY
Effective Date: July 29, 2026
Domain: www.shopatbearhugs.com
This Privacy Policy ("Policy") governs the collection, processing, disclosure, and protection of personal data by Bear Hugs ("Company," "We," "Us," or "Our"), operating the e-commerce platform shopatbearhugs.com ("Website").
We are committed to processing personal data in accordance with applicable data protection legislation, including the EU General Data Protection Regulation (Regulation (EU) 2016/679), the UK General Data Protection Regulation (UK GDPR), and the Data Protection Act 2018.
1. DATA CONTROLLER & REPRESENTATIVE
1.1. Data Controller: For the purposes of the GDPR, Bear Hugs is the Data Controller responsible for Your personal data.
1.2. Contact Details: For all data protection inquiries, rights requests, or supervisory notifications, please contact Our Data Protection Officer / Privacy Lead at:
-
Email: care@shopatbearhugs.com
-
Website: www.shopatbearhugs.com
2. CATEGORIES OF PERSONAL DATA COLLECTED
We collect and process the following categories of personal data:
A. Personal Data Provided Directly by You:
-
Identity & Contact Data: Full name, billing address, shipping address, email address, telephone number, and account credentials.
-
Financial & Transaction Data: Order history, items purchased, transaction value, payment confirmation receipts, and communications with customer support. (Note: Full payment card details are collected and processed directly by PCI-DSS compliant payment gateways and are never stored on Our servers).
-
Communications & Preferences: Marketing communication preferences, customer support inquiries, feedback, and unboxing verification submissions.
B. Personal Data Collected Automatically:
-
Technical & Device Data: Internet Protocol (IP) address, login data, browser type and version, time zone setting and location, operating system, device hardware details, and network provider.
-
Usage Data: Clickstream patterns, pages viewed, session durations, cart additions, page response times, and referring URLs collected via cookies and analytical tags.
3. LEGAL BASES FOR PROCESSING UNDER GDPR (ARTICLE 6)
We process Your personal data strictly under one or more of the following statutory legal bases:
3.1. Performance of a Contract (Art. 6(1)(b) GDPR): Processing is necessary to perform a contract to which You are a party, including processing sales transactions, shipping physical goods, managing returns, and providing customer support.
3.2. Compliance with Legal Obligations (Art. 6(1)(c) GDPR): Processing is necessary to comply with legal, tax, accounting, customs, and regulatory obligations.
3.3. Legitimate Interests (Art. 6(1)(f) GDPR): Processing is necessary for Our legitimate commercial interests, provided these interests are not overridden by Your fundamental rights and freedoms. This includes fraud prevention, network security, operational analytics, service improvement, and direct marketing to existing customers.
3.4. Consent (Art. 6(1)(a) GDPR): Where You have provided explicit consent for specific processing activities, such as subscribing to electronic marketing newsletters or accepting non-essential analytical cookies. You maintain the right to withdraw consent at any time.
4. PURPOSES OF PROCESSING
| Purpose / Activity | Type of Data | Lawful Basis for Processing |
| Processing, fulfilling, and delivering orders | Identity, Contact, Financial, Transaction | Performance of a Contract |
| Managing prepaid payments and preventing checkout fraud | Identity, Contact, Technical, Financial | Legitimate Interests; Legal Obligation |
| Providing customer care and handling return verification | Identity, Contact, Transaction, Communications | Performance of a Contract; Legitimate Interests |
| Sending transactional updates (order status, tracking links) | Identity, Contact, Transaction | Performance of a Contract |
| Delivering direct marketing communications | Identity, Contact, Preferences | Consent (Opt-in) / Legitimate Interests |
| Site optimization, security, and usage analytics | Technical, Usage, Cookies | Consent (Cookies) / Legitimate Interests |
5. PAYMENT PROCESSING & PREPAID MANDATE
5.1. All monetary transactions on shopatbearhugs.com are executed through secure, PCI-DSS certified third-party payment gateways.
5.2. Prepaid Requirement: Cash on Delivery (COD) is not accepted on shopatbearhugs.com. All purchases must be completed using authorized prepaid payment instruments at checkout.
5.3. Financial data transmitted during checkout is encrypted using Secure Sockets Layer (SSL) / Transport Layer Security (TLS) technology directly by payment service providers.
6. COOKIES AND TRACKING TECHNOLOGIES
6.1. We utilize essential, functional, performance, and targeting cookies to operate the Website, store cart state, analyze user behavior, and personalize content.
6.2. Non-essential cookies (analytical and advertising cookies) are deployed strictly upon obtaining Your prior consent via Our Cookie Banner.
6.3. You may manage, restrict, or block cookies through Your browser preferences. However, disabling essential technical cookies may impair core functionality, including account access and checkout.
7. RECIPIENTS OF PERSONAL DATA & DISCLOSURE
We do not sell, rent, or trade Your personal data to third parties. We disclose personal data only to the following necessary recipients bound by data processing agreements (DPAs) and confidentiality obligations:
-
Logistics & Delivery Carriers: Third-party global courier services to fulfill, clear through customs, and deliver physical orders.
-
Payment Gateways & Financial Institutions: Payment processors to execute prepaid transactions and prevent fraudulent activities.
-
Technology & Hosting Infrastructure: E-commerce platform hosts (Shopify Inc.), cloud storage providers, and database maintainers.
-
Analytics & Operational Tools: Third-party data analytics services (e.g., Google Analytics) to monitor platform performance.
-
Legal & Regulatory Authorities: Government bodies, law enforcement agencies, or tax authorities where legally mandated by statute or court order.
8. INTERNATIONAL DATA TRANSFERS
8.1. Personal data collected from users in the European Economic Area (EEA) or the United Kingdom (UK) may be transferred to, stored at, or processed in destinations outside the EEA/UK, including Our primary operational and logistical facilities in India, Hong Kong, and the United Kingdom.
8.2. Whenever international transfers occur, We ensure appropriate safeguards are implemented in accordance with Chapter V of the GDPR, including:
-
Standard Contractual Clauses (SCCs) approved by the European Commission or UK International Data Transfer Agreements (IDTAs);
-
Verification that recipient jurisdictions maintain adequate data protection levels; or
-
Explicit contractual security commitments executed with third-party processors.
9. DATA RETENTION PERIODS
9.1. We retain Your personal data only for as long as necessary to fulfill the operational purposes for which it was collected, as outlined in Section 4.
9.2. Transactional and tax-related record data is retained for a mandatory statutory period of up to seven (7) years following transaction completion to satisfy legal, fiscal, and audit compliance obligations.
9.3. Marketing data is retained until You exercise Your right to opt out or withdraw consent.
10. YOUR DATA SUBJECT RIGHTS UNDER GDPR (ARTICLES 15–22)
Subject to statutory conditions and exceptions under applicable data protection laws, You possess the following legal rights regarding Your personal data:
-
Right of Access (Art. 15 GDPR): The right to request confirmation as to whether Your data is being processed and obtain a copy of Your personal data.
-
Right to Rectification (Art. 16 GDPR): The right to request the immediate correction of inaccurate or incomplete personal data.
-
Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR): The right to request the deletion of Your personal data where processing is no longer necessary, consent is withdrawn, or processing is unlawful.
-
Right to Restriction of Processing (Art. 18 GDPR): The right to restrict data processing under specific verification circumstances.
-
Right to Data Portability (Art. 20 GDPR): The right to receive Your personal data in a structured, commonly used, and machine-readable format and transmit it to another controller.
-
Right to Object (Art. 21 GDPR): The right to object at any time to processing based on legitimate interests or direct marketing.
-
Right to Withdraw Consent (Art. 7(3) GDPR): Where processing is based on consent, You may withdraw consent at any time without affecting the lawfulness of processing conducted prior to withdrawal.
Exercising Your Rights: To exercise any of the above rights, please submit a written request to care@shopatbearhugs.com. We will respond to verified requests within one (1) calendar month of receipt.
11. DATA SECURITY MEASURES
We implement appropriate technical and organizational measures to safeguard personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include data encryption in transit (SSL/TLS), access control mechanisms, pseudonymization, and regular security assessments.
12. THIRD-PARTY LINKS
The Website may contain hyperlinks to external third-party websites or services. This Policy applies solely to shopatbearhugs.com. We do not control, endorse, or accept responsibility for the privacy practices or content of third-party platforms. You are encouraged to review the privacy notices of external sites prior to submitting personal data.
13. DIRECT MARKETING & OPT-OUT
1.1. You will receive promotional emails or communications from Us only if You have opted in to receive such marketing during registration, checkout, or via email capture forms.
1.2. You may opt out of receiving promotional communications at any time by clicking the "Unsubscribe" link located at the bottom of Our marketing emails or by contacting Us directly at care@shopatbearhugs.com.
14. COMPLAINTS & SUPERVISORY AUTHORITY
If You believe that Our processing of Your personal data infringes applicable data protection laws, You have the right to lodge a formal complaint with a competent Data Protection Supervisory Authority:
-
In the EU: With the Data Protection Authority in Your EU Member State of habitual residence, place of work, or place of the alleged infringement.
-
In the UK: With the Information Commissioner's Office (ICO) via www.ico.org.uk.
15. AMENDMENTS TO THIS POLICY
We reserve the right to revise or update this Policy at Our discretion. Any amendments shall become effective immediately upon publication of the updated policy on shopatbearhugs.com.
