At Subconscious Cannabis, your privacy matters. In compliance with the General Data Protection Regulation (GDPR), this policy explains how we collect, use, store, and protect your personal data if you are located in the European Economic Area (EEA) or interacting with our services from within the EU.
1. Who We Are
Subconscious Cannabis is the data controller for your personal information collected through our website https://subconsciouscannabis.com.
2. What Data We Collect
We may collect and process the following personal data:
-
Name
-
Email address
-
Shipping and billing address
-
Phone number
-
IP address and device/browser type
-
Order and payment details (processed securely via third-party payment providers)
-
Communication preferences and customer service inquiries
3. How We Use Your Data
We use your personal data to:
-
Process and fulfill orders
-
Respond to customer inquiries
-
Send transactional or promotional emails (if opted in)
-
Improve website experience and security
-
Comply with legal obligations
4. Legal Basis for Processing
We process personal data under the following legal grounds:
-
Contractual necessity (to fulfill your order)
-
Consent (e.g., for email marketing)
-
Legal obligation (e.g., recordkeeping)
-
Legitimate interest (e.g., fraud prevention, site improvement)
5. Data Sharing
We do not sell your personal data. We may share it only with:
-
Payment processors (e.g., Stripe, PayPal)
-
Shipping providers
-
Customer support platforms
-
Analytics and email marketing tools
-
Legal or regulatory authorities, if required
All third parties are required to protect your data in accordance with GDPR.
6. Your Rights Under GDPR
You have the right to:
-
Access your personal data
-
Correct inaccurate or incomplete data
-
Request erasure (“right to be forgotten”)
-
Restrict or object to processing
-
Withdraw consent at any time
-
Data portability (receive your data in a usable format)
-
Lodge a complaint with a data protection authority
To exercise any of these rights, please contact us using the form on our website.
7. Data Retention
We retain personal data only as long as necessary for the purposes stated above, or to comply with legal obligations (e.g., tax laws).
8. Data Security
We take appropriate technical and organizational measures to protect your personal data from loss, misuse, unauthorized access, or disclosure.
9. International Transfers
If your data is transferred outside the EEA (e.g., to a U.S.-based provider), we ensure adequate protections are in place such as Standard Contractual Clauses or Privacy Shield-certified partners (where applicable).
10. Cookies and Tracking
We use cookies and similar tracking technologies to personalize content, analyze traffic, and improve user experience. You can manage cookie preferences via your browser settings.