Palm Oil Free Soap header image

Privacy Policy

Who we are

Shy Sheep Limited. A New Zealand owned business run by New Zealand residents, in Te Anau, Fiordland, New Zealand.

We are The Smith Family Soapmakers.

Our website address is: https://palmoilfreesoap.com. We make the Palm Oil Free Soap, otherwise known as Milk Relief Soap™. We also make the Palm Oil Free Skin Sticks, otherwise known as Lano Relief Skin Stick™. We also run other sister websites, including, but not limited to:

https://MilkRelief.com, https://goat.jphttps://goatmilksoap.co.nz

Our physical address, and the site of manufacture is at our farm, 296 Kakapo Road, RD 2, Te Anau, 9672.

Personal data collected

The data we collect will depend upon the level of and type of information you pass across to us by phone, or electronic means, using our site or aweber.com, our email list provider.

This may include personal data, such as name, email address, personal account preferences; transnational data, such as purchase information; and technical data, such as information about cookies.

We note relevant data of a sensitive nature, such as your experience with dry skin, or such like, when you reveal it to us.

Other data collection.

Not withstanding all that is stated above, we acknowledge that, technically, personal data is also generated from technical processes such as contact forms, comments, cookies, analytics, and third party embeds. Google analytics is a good example of non-personal data collection. We have set Google analytics to dump their data after 26 months.

User – “My Account” Customer data

WordPress does not collect any personal data about visitors, and only collects the data shown on the My Account or User Profile screen from registered users.

Comments

When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.

An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.

Media

As far as we know we have not uploaded any location specific data via media. Some photos product users have been provided by those users and we cannot verify the type of photo data in those photos.

Contact form

We use a contact form plugin. We keep the data you provide us only as long as we need for customer service purposes. We do not use the information submitted through them for marketing purposes.

Cookies

If you leave a comment on our site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.

If you have an account and you log in to this site, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.

When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.

Authorised admins and editors only: if you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.

Embedded content from other websites

Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.

These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.

Analytics (and opt out)

You may opt of Google Analytics [GA] tracking here.
GA privacy policy. https://www.google.com/analytics/terms/us.html

We use Monster Insights [MI] to corral the Google Analytics, and Opt out forms.
https://www.monsterinsights.com/privacy-policy/

We use Yoast SEO to help you find us online. It also corrals Google Analytics data so we can better arrange our site for the benefit of users.

Privacy Policy

By default WordPress does not collect any analytics data. However, many web hosting accounts collect some anonymous analytics data. We may also have installed a WordPress plugin that provides analytics services, such as Yoast SEO.

Who we share your data with

By default WordPress does not share any personal data with anyone.

We use a range of normal business tools to round up day to day business. Personal data is collected securely in customer management software, and accounting software.

Our current software suite includes CapsuleCRM.com and Xero.com. https://capsulecrm.com/dpa/subprocessors/

Payment processors we do or will use include PayPal Inc. and SwipeHQ.co.nz (CyberCom, Auckland)

Banks with transaction details include KiwiBank and ASBBANK, both in New Zealand.

Plugin: Smush

Note: Smush does not interact with end users on your website. The only input option Smush has is to a newsletter subscription for site admins only. If you would like to notify your users of this in your privacy policy, you can use the information below.

Smush sends images to the WPMU DEV servers to optimize them for web use. This includes the transfer of EXIF data. The EXIF data will either be stripped or returned as it is. It is not stored on the WPMU DEV servers.

Smush uses a third-party email service (Drip) to send informational emails to the site administrator. The administrator’s email address is sent to Drip and a cookie is set by the service. Only administrator information is collected by Drip.

Source: BackupBuddy

What personal data we collect and why we collect it

Backups

Per the functionality of this plugin, backups of your website files and/or database are created and stored locally on your server and/or remotely on 3rd party servers based on the settings of this plugin. Archives can include, but are not limited to, file and database assets, including hashed passwords, 3rd party data, uploads and user information. These backups are stored to provide critical functionality of this plugin.

Cookies

Cookies are used to handle importing and restoring backups.

Plugin Settings

Some plugin settings ask for an email address or login credentials to 3rd party services. This is stored to provide functional features to the plugin.

Recent Activity

This plugin tracks dates, times and actions of successful and unsuccessful backups and remote data transfers. This is stored to help make the plugin better and assist with troubleshooting problems.

Logging

This plugin logs some personal information such as email addresses, usernames, database and server information. This is stored to help make the plugin better and assist with troubleshooting problems.

How long BackupBuddy retain site data

Backups

Backup retention is completely up to the website owner. This can vary from less than one minute to indefinitely.

Cookies

Cookies used during the restore/import process expire after 24 hours.

Plugin Settings

Settings are retained indefinitely until they are changed or removed manually.

Where we send your data

Backups

Backups are not automatically sent to remote destinations automatically, however backups can be configured to be sent to third-party servers.

How we protect your data

Backups

Backup zip files are stored with hashed file names to prevent filename guessing and directory browsing is disabled.

What third parties Backup Buddy receive data from

Backup Destinations

Backups can be sent to third-party destination servers, including but not limited to:

Links to third party privacy policies have been included.

Source: WooCommerce (Shopping Cart)

WooCommerce collect transaction information about you during the checkout process on our store.

What we collect and store

While you visit our site, we’ll track:

  • Products you’ve viewed: we’ll use this to, for example, show you products you’ve recently viewed
  • Location, IP address and browser type: we’ll use this for purposes like estimating taxes and shipping
  • Shipping address: we’ll ask you to enter this so we can, for instance, estimate shipping before you place an order, and send you the order!

We’ll also use cookies to keep track of cart contents while you’re browsing our site. You may have already opted out of cookies.

When you purchase from us, we’ll ask you to provide information including your name, billing address, shipping address, email address, phone number, credit card/payment details and optional account information like username and password. We’ll use this information for purposes, such as, to:

  • Send you information about your account and order
  • Respond to your requests, including refunds and complaints
  • Process payments and prevent fraud
  • Set up your account for our store
  • Comply with any legal obligations we have, such as calculating taxes
  • Improve our store offerings
  • Send you marketing messages, if you choose to receive them

If you create an account, we will store your name, address, email and phone number, which will be used to populate the checkout for future orders.

We generally store information about you for as long as we need the information for the purposes for which we collect and use it, and we are not legally required to continue to keep it. For example, we will store order information for the following time frames

Retain inactive accounts 84 months.
Retain pending orders 60 days
Retain failed orders 30 days
Retain cancelled orders 30 days
Retain completed orders until you request we remove it, or we deem it to be of no further use for doing business with us in the future.

This includes your name, email address and billing and shipping addresses.

We will also store comments or reviews, if you choose to leave them.

Who on our team has access

Members of our team have access to the information you provide us. For example, both Website Administrators and Shop Managers can access:

  • Order information like what was purchased, when it was purchased and where it should be sent, and
  • Customer information like your name, email address, and billing and shipping information.

Our team members have access to this information to help fulfill orders, process refunds and support you.

What we share with others

In addition to the technical support services listed above, we share information with third parties who help us provide our orders and store services to you; for example —

New Zealand Post, and CourierPost (Express Couriers Limited), DHL International GmbH, GoSweetSpot.com (Auckland) are all New Zealand post, courier and freight providers we deal with.

They will have access to your address and or phone number while they are carrying items from us to you.

Payments

We accept payments through PayPal. When processing payments, some of your data will be passed to PayPal, including information required to process or support the payment, such as the purchase total and billing information.

Please see the PayPal Privacy Policy for more details.

We will also offer you the use of SwipeHQ.com to process payments in the same way.

Please see the Swipe CyberCom Privacy Policy for more details.

Source: WooCommerce Services

Data Used: For payments with PayPal: purchase total, currency, billing information. For taxes: the value of goods in the cart, value of shipping, destination address. For checkout rates: destination address, purchased product IDs, dimensions, weight, and quantities. For shipping labels: customer’s name, address as well as the dimensions, weight, and quantities of purchased products.

For payments, we send the purchase total, currency and customer’s billing information to the respective payment processor. Please see the respective third party’s privacy policy (PayPal’s Privacy Policy) for more details.

For automated taxes we send the value of goods in the cart, the value of shipping, and the destination address to TaxJar. Please see TaxJar’s Privacy Policy for details about how they handle this information.

In the case of Shy Sheep Limited opting to us the service, Auttomattic |WordPress.com | Jetpack also store the purchased shipping labels on our server to make it easy to reprint them and handle support requests.

Source: Akismet

We collect information about visitors who comment on Sites that use our Akismet anti-spam service. The information we collect depends on how the User sets up Akismet for the Site, but typically includes the commenter’s IP address, user agent, referrer, and Site URL (along with other information directly provided by the commenter such as their name, username, email address, and the comment itself).