Privacy policy

Last updated: October 4, 2026

This policy explains what personal information Arctic Grey collects, why we collect it, who helps us handle it and the choices you have. It covers our website, our sales and client work, our meetings and our hiring.

  • Client data stays the client’s. When we work inside a client’s store, we use its customer data only to do the work the client asked for, under the client’s agreement with us.
  • People check what AI produces. AI helps us work faster. A qualified person reviews AI output before it goes into anything we deliver.
  • One inbox for every request. Email support@arcticgrey.com to see, correct or delete your information, or to stop marketing emails. We answer within the time the law allows.

Who we are

In short: Arctic Grey, Ltd. is a UK company that designs, builds and supports Shopify stores. We are responsible for the personal information this policy describes, and we are easy to reach.

Arctic Grey, Ltd. (“Arctic Grey,” “we,” “us” or “our”) is a private limited company registered in England and Wales (company number 10123951). Our address is International House, 142 Cromwell Road, London SW7 4EF, United Kingdom.

For the personal information we collect for our own purposes, as described in this policy, Arctic Grey is the controller under UK data protection law (the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations) and, where it applies, the EU GDPR.

How to reach us

  • Email: support@arcticgrey.com. For privacy matters, put “Privacy request” in the subject line.
  • Phone: +1 (650) 288-0533, or toll free +1 (844) 311-6962.
  • Post: Arctic Grey, Ltd., International House, 142 Cromwell Road, London SW7 4EF, United Kingdom.

What this policy covers

In short: This policy covers people who visit our site, talk to us, buy from us, work with us or apply to join us. Customer data we handle inside a client’s store is governed by that client’s agreement with us.

This policy applies to personal information about:

  • visitors to arcticgrey.com and to other pages we host that link to this policy, such as our audit, Test Drive and client report pages on arcticgrey.org;
  • people who fill out our forms, book calls or contact us;
  • customers who buy Bulk Hours or other services on arcticgrey.com, and the people who work for our clients;
  • people who take part in our sales calls and client meetings;
  • people at businesses we believe we can help, whose work details we obtain from business data sources; and
  • people who apply to work with us.

It does not cover:

  • personal information inside our clients’ stores and systems that we process on their behalf. We explain our role in Client store data below, but each client’s own privacy notice tells its customers how their data is used;
  • information about our own team members, which we handle separately; or
  • third-party websites, apps and services, including processing that Shopify carries out for its own purposes. See Shopify’s privacy policy.

This policy sits alongside our Terms of Service. Where a signed Master Service Agreement, Order Form, Statement of Work or data processing agreement contains data protection terms, those terms prevail for the data they cover.

Which laws apply

In short: We’re a UK company that works with businesses around the world, mostly in the United States and Canada. UK data protection law is our baseline for everyone, and we add local rights wherever a local law applies to us.

Arctic Grey is established in the United Kingdom, so UK data protection law is the standard we apply to all the personal information we handle, wherever you are. Our site and services are designed for businesses, not consumers, and most people we deal with are acting for a business.

Many privacy laws apply only to certain businesses or in certain situations. For example, most US state privacy laws apply only to businesses above revenue or volume thresholds, and many do not cover information about people acting in a business or employment role. Where a law of the place you live does apply to how we handle your information, such as the EU GDPR, Canadian privacy law or a US state privacy law, you also have the rights that law gives you, as described in this policy.

This policy is governed by the laws of England and Wales, the same law as our Terms of Service. Nothing in this policy takes away a right that the law where you live gives you and that cannot be waived.

What we collect and why

In short: We collect what we need to run our site, answer your questions, deliver our work and grow the business. The table shows what we collect, why, and the legal basis we rely on in the UK and EU.

When What we collect Why we use it Legal basis (UK and EU)
You browse our site IP address and the approximate location it suggests; browser, device and operating system; pages viewed, links clicked, scrolling and time on page; the site or ad that sent you, including campaign tags; and identifiers set by cookies and pixels. To run and secure the site, remember your cart and choices, understand which pages help visitors, test page variations, and measure and target our advertising. Legitimate interests for the cookies and logs the site needs to work and stay secure. Consent for analytics and advertising cookies where the law requires it.
Our tools recognize your business from a visit Your company’s name and details and, in some cases, your name, job title, work email and professional profile, matched by visitor identification providers (Apollo and RB2B) from your device, IP address or cookies. To understand which businesses are interested in our services and to follow up with relevant ones. Legitimate interests. For visitors in the UK, the EEA and Switzerland, these tools run only if you accept marketing cookies.
You fill out a form, such as our contact, audit, Bulk Hours quote, Test Drive, feedback or project forms Name, work email, phone, company, website or store URL, role, budget, timeline, project details, files you upload and your answers. Technical details such as your browser, the page you used, how long the form took and signals that help us filter spam. Once you enter your email address, our forms save your answers as you go, so we may hold a partly completed form even if you never press submit. To reply, prepare the audit, quote or Test Drive you asked for, let you pick up where you left off, follow up, decide which inquiries to answer first and keep spam out. If you start a form but do not submit it, we may send you one follow-up email about it. Steps you ask us to take before entering a contract. Legitimate interests in responding to and following up on business inquiries.
You book, join or are invited to a call or meeting Name, email, company and booking details, including through Calendly. If the meeting is recorded: audio, video and screen shares, a transcript, speaker names, and an AI-generated summary and action items. See Meetings and recordings. To schedule and run the meeting, keep an accurate record, deliver and follow up on the work, and improve the quality of our calls. Legitimate interests. Performance of our contract where you are the client. Consent where a law requires it for recording.
You buy on arcticgrey.com or pay an invoice Name, company, email, phone, billing address, tax details, what you bought, order and payment history, and limited payment details (such as card type, last four digits and expiry) from our payment processors. For recurring plans, a token that lets the processor charge your stored payment method. We do not receive full card numbers, and we never ask for them by phone, by email or on an invoice. To process orders and payments, run recurring hour plans, issue invoices and receipts, keep accounting and tax records, prevent fraud and give support. Performance of our contract. Legal obligations for accounting and tax. Legitimate interests in preventing fraud and collecting what is owed.
You work with us as a client, or for a client Work contact details; messages and files exchanged by email, Slack, Zendesk and Monday.com; signed documents and signing records (name, email, signature, IP address and timestamps) through DocuSign; weekly report recipients; and feedback or reviews you give us. To deliver the services, communicate, report hours, manage the account, handle complaints and enforce our agreements. Performance of our contract where you are the client. Legitimate interests where you act for a client business.
We identify you as a potential client Name, job title, employer, work email and phone, professional profile URL, company size and technology, and public information about your business and store, from business data providers such as Apollo, public sources and referrals. How you engage with our emails. See Prospects and business data. To research businesses we may be able to help and to contact the right people with relevant offers. Legitimate interests in business-to-business marketing. Consent where email marketing rules require it.
You receive our marketing emails Email address, name, company, preferences, whether you open our emails and which links you click and, through Klaviyo, the pages you view on our site once you are known to us. To send updates and offers that are relevant to you and to measure what works. Consent, or legitimate interests for clients and business contacts, always with a simple way to opt out.
You contact support or chat on our site Your messages, attachments and contact details, including conversations with our AI quote assistant, which Anthropic (Claude) processes to generate replies and which we may pass to our team so we can follow up. To answer you, resolve issues and improve our support. Legitimate interests. Performance of our contract where you are a client.
You apply for a role Name, email, location, professional profile URL, the role you want, your written answers, any CV you send, your video introduction (recorded on our page or shared as a link), interview notes, interview recordings and transcripts, and references. See Job applicants. To assess your application, communicate with you and make a hiring decision. Steps you ask us to take before entering a contract. Legitimate interests in hiring well. Legal obligations, such as right-to-work checks, where they apply.
In all cases, where needed Records of our dealings with you. To meet legal, tax and regulatory obligations, respond to lawful requests, and establish, exercise or defend legal claims. Legal obligations. Legitimate interests in protecting our business and our rights.

Our legitimate interests

Where we rely on legitimate interests, those interests are running and growing a business-to-business agency: answering inquiries, marketing our services to businesses, delivering and improving our work, keeping accurate records, securing our systems and protecting our legal rights. We weigh those interests against your rights and reasonable expectations, and you can object at any time (see Your rights).

Automated scoring

We use automated scoring, based on information such as the forms you start, the pages you visit and your business details, to help our team decide which inquiries and prospects to follow up first. Scoring affects the order and the way we follow up. It is not used to make decisions that have legal or similarly significant effects on you.

If you choose not to give us information

Most information we ask for is optional. If you don’t give us what a form, order or application asks for, we may not be able to reply, complete your order or consider your application.

Meetings and recordings

In short: We often record and transcribe calls so nothing gets lost and everyone works from the same notes. If you would rather we didn’t, tell us and we won’t.

We use Fireflies to record, transcribe and summarize many of our sales calls and client meetings, and some job interviews. A recording captures audio and video: what you say, your name, your image if your camera is on, anything you share on screen and the meeting chat. Fireflies and its AI features turn the recording into a transcript, a summary and action items.

When a meeting is recorded, the Fireflies notetaker joins the call as a named participant that everyone can see. Recordings, transcripts and notes are our business records, as our Terms of Service explain. We use them to keep an accurate record, deliver and follow up on work, bring team members up to speed on an account, improve quality and resolve disagreements.

Your choices:

  • Tell us before or at the start of a meeting if you do not want it recorded, and we will turn the notetaker off.
  • Ask us to stop recording at any point during a meeting.
  • Ask for a copy of a recording or transcript that includes you, or ask us to delete it. We will delete it unless we need to keep it for a legal or contractual reason, and we will tell you if so.

Some places, including several US states such as California, require everyone on a call to agree to it being recorded. Where that applies, we rely on the notice above and your choice to continue, or we ask for your agreement directly.

Access to recordings is limited to the team members who need them and the providers that store and process them. A member of our team may share a summary or transcript with the other people who attended the meeting.

Prospects and business data

In short: We reach out to businesses we think we can help, using work contact details. One reply or one click takes you off our list.

To find businesses that may benefit from our services, we obtain work-related information about people from:

  • business contact data providers, mainly Apollo;
  • visitor identification tools on our site (Apollo and RB2B), described in Cookies and tracking;
  • public sources, such as company websites, online stores, press coverage and professional networks like LinkedIn; and
  • referrals from partners, such as Shopify, and from people who introduce us.

This information typically includes your name, job title, employer, work email and phone number, professional profile and facts about your company, such as its size, the platform its store runs on and how its store performs publicly. We use it to research whether we can help, to personalize outreach by email, phone or LinkedIn, and to prepare material such as a review of your public website. Some of this research and writing is done with AI tools, and some outreach, such as a personalized review of your public website, is prepared with AI and sent automatically.

We rely on our legitimate interests in business-to-business marketing. In the UK, we email people at companies under the rules for corporate subscribers, and we ask for consent where the rules require it, for example for sole traders and partnerships. In Canada, we email only business addresses that are published or given to us and that relate to the recipient’s role, as Canadian anti-spam law allows. Every message tells you who we are, and you can opt out at any time by replying to it or by emailing support@arcticgrey.com.

If you ask us to stop, we will. We keep a minimal record, such as your email address, on a suppression list so that we do not contact you again, including if your details reach us again from another source.

We do not sell prospect data to anyone, and we do not contribute your details to Apollo’s or any other provider’s shared contact database.

Job applicants

In short: When you apply, we use what you send us to get to know you and make a hiring decision. A person reviews every application, and we never use AI to score or reject one.

Our careers pages ask for your name, email, location, professional profile URL, the role you want and short written answers, plus a short video introduction that you either record on the page or share as a link. Applications and video introductions sent from our careers pages are stored in our Google Workspace. We may also keep interview notes, assessment results, recordings and transcripts of video interviews (see Meetings and recordings) and, with your knowledge, references. We do not run background checks.

Our hiring team uses this information to assess your application, communicate with you and decide whether to make an offer. A person reviews every application. We do not use AI or any automated system to score, rank or reject applications or video introductions.

We do not ask for sensitive information, such as health, ethnicity, religion or sexual orientation, so please leave it out. A video introduction will show your appearance; we do not use it to infer any protected characteristic.

If we hire you, your application becomes part of your team member record and our internal team notice applies. If we don’t, see How long we keep data.

Client store data

In short: When we work inside a client’s Shopify store or other systems, the client decides how its customers’ data is used. We follow the client’s instructions and its agreement with us.

Our work often requires access to personal information that our clients control, such as their customers’ names, contact details, addresses, orders, accounts and marketing data held in Shopify, Klaviyo, ERP, support or other systems (“client store data”).

For client store data, the client is the controller and Arctic Grey is its processor under UK and EU data protection law, and its service provider or contractor under US state privacy laws. Our Terms of Service, the client’s signed agreement with us and any data processing agreement govern this processing. Our standard data processing agreement is available to clients on request. If you are a customer of one of our clients, that client’s privacy notice explains how your data is used, and requests about it should go to the client. If you contact us instead, we will pass your request to the client and help it respond.

When we handle client store data:

  • we use it only to perform the work the client has asked for. We do not use it for our own marketing, and we do not sell or share it;
  • we work through access the client grants and can remove at any time, such as a Shopify collaborator or staff account, and we limit copies outside the client’s systems, such as test data or exports, to what the work needs, and we use test data in staging environments where practical;
  • our tools and subprocessors, including the AI tools described in How we use AI, may process it as reasonably necessary to perform the work. A client may ask us in writing to exclude a specific tool;
  • our team logs time with Time Doctor, which may capture screenshots of their screens while they work, so a screenshot can show whatever was on screen, including client store data. Only our managers can see these screenshots, and they are deleted after 6 months;
  • we help clients respond to their customers’ privacy requests, and we tell the client within 72 hours of becoming aware of a personal data breach affecting its data; and
  • within 30 days of the end of an engagement, or earlier on request, we delete or return client store data we hold, including exports and staging copies, unless the law requires us to keep it.

We may use general know-how and anonymized or aggregated learnings from our work to improve our services, without identifying the client or any individual.

How we use AI

In short: We use AI tools across our work, and they may process personal information when a task needs it. We limit what goes in, use providers’ business terms, and a person reviews AI output before it goes into client work.

We use AI tools to research, write, design, code, test, summarize meetings and manage our work. They include Claude (Anthropic), ChatGPT and Codex (OpenAI), Gemini (Google), Grok (xAI) and AI coding environments such as Cursor. Depending on the task, these tools may process personal information, such as the content of emails and messages, meeting transcripts, form submissions, prospect research and, when a client’s work needs it, client store data.

  • Human review. Where we use AI in our work, a qualified person reviews the output, to the degree the deliverable calls for, before it is incorporated into a deliverable. Any deliverable that shows AI-generated renderings to end users says so clearly.
  • Provider terms. AI providers process information for us under their business or API terms, and we choose providers and settings with confidentiality in mind.
  • Only what the task needs. We limit the personal information we put into AI tools to what the task requires.
  • AI features on our site. Some site features, such as the Shopify Test Drive and our quote assistant, use AI to generate a prototype or a reply from what you enter and from public information about your store. What you enter is sent to our AI provider, Anthropic (Claude), for that purpose.
  • No automated decisions about you. We do not use AI to make decisions about you that have legal or similarly significant effects.
  • Exclusions. A client may ask us in writing to exclude a specific AI tool for compliance reasons. We will say whether we can accommodate it within the existing scope and rate.

Sharing and subprocessors

In short: We share personal information with the service providers that help us run Arctic Grey, with our professional advisers and where the law requires it. Here is who they are.

We share personal information with service providers that process it on our behalf under their data processing terms. The list below shows the categories we use and representative providers. It changes as we add, replace or upgrade tools.

  • Commerce and payments: Shopify (our store and checkout, including Shopify Payments), PayPal and our bank for transfers.
  • Hosting, code and infrastructure: Amazon Web Services, Cloudflare and GitHub.
  • Email, documents and collaboration: Google Workspace (Gmail, Drive, Docs, Sheets and Calendar) and Slack.
  • Work management and time tracking: Monday.com and Time Doctor.
  • Meetings and scheduling: Fireflies and Calendly.
  • Support and chat: Gorgias and Zendesk.
  • Sales and marketing: Apollo, Klaviyo and RB2B.
  • Artificial intelligence: Anthropic (Claude), OpenAI (ChatGPT and Codex), Google (Gemini), xAI (Grok) and Cursor.
  • Design: Figma.
  • Contracts and e-signature: DocuSign.
  • Analytics, testing and advertising: Google (Analytics, Tag Manager and Ads), LinkedIn, Pinterest, AdRoll, Hotjar and Shoplift. Some of these companies also use the information for their own purposes; see Cookies and tracking.
  • Reviews: Yotpo.

We also share personal information:

  • with Shopify, through Shopify Network Intelligence. Shopify uses information about our store’s visitors and customers, together with other Shopify data, to improve its products and the ad targeting and personalization it provides for our store. Other merchants can’t see your information;
  • with professional advisers, such as lawyers, accountants, auditors and insurers, who owe us duties of confidentiality;
  • with people you ask us to work with, such as your colleagues, other agencies or app partners on a project;
  • with police, regulators, courts or other authorities when the law requires it, and where needed to prevent fraud or to protect the rights, property or safety of Arctic Grey, our clients or others;
  • with a buyer, investor or successor, and their advisers, if we are involved in a merger, acquisition, financing or sale of all or part of our business, under confidentiality terms. The recipient will be bound by this policy or will tell you about any change; and
  • with anyone else when you ask us to or agree to it.

We do not sell or license personal information to anyone, and we do not share it with third parties for their own marketing. Some advertising cookies and pixels on our site may count as “selling” or “sharing” personal information under some US state laws; see Your US state rights for how to opt out.

International transfers

In short: We’re a UK company with a remote team, and many of our tools are run by US companies, so your information often crosses borders. When it does, we use the safeguards UK and EU law require.

Arctic Grey is based in the United Kingdom. Our team works remotely from the United States, Canada, the United Kingdom, Latin America and other countries, and many of our service providers store or process data in the United States and elsewhere. Shopify, for example, processes store data in Canada, the United States and other countries.

When we transfer personal information out of the UK or the European Economic Area, we rely on one or more of these safeguards:

  • adequacy decisions, including the EU’s decision that the UK protects personal data adequately, and the UK and EU decisions covering US companies certified under the EU-US Data Privacy Framework and its UK Extension;
  • the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses; and
  • the EU Standard Contractual Clauses.

For team members and contractors outside the UK, we use contractual safeguards, such as the UK International Data Transfer Agreement. You can ask us for more information about these safeguards, including a copy of the relevant terms with commercial details removed.

Cookies and tracking

In short: Our site uses cookies and pixels to work properly, to show us what visitors find useful and to show our ads elsewhere. You have choices about the ones that aren’t essential.

Cookies are small files stored on your device. Pixels, tags, scripts and local storage work in similar ways. Our site runs on Shopify, which sets the cookies the store and checkout need. Shopify lists them in its cookie policy.

On the date of this policy, our site uses these types of technology:

Type What it does Representative providers
Strictly necessary Keeps the site, cart, checkout and forms working and secure, remembers your privacy choices and saves form progress on your device. Shopify
Analytics and testing Counts visits, shows how people use our pages (including heatmaps and recordings of clicks, scrolls and mouse movement) and tests page variations. Shopify analytics, Google Analytics through Google Tag Manager, Hotjar, Shoplift
Marketing and advertising Measures our ads and emails, and shows our ads to you on other sites and platforms based on your visits. Google Ads, LinkedIn Insight Tag, Pinterest Tag, AdRoll, Klaviyo
Visitor identification Matches visits to companies and, in some cases, to work contact profiles. Apollo, RB2B
Features you choose to use Lets you book calls, contact support, read reviews and use our quote assistant. These providers may set their own cookies when the feature loads. Calendly, Gorgias, Zendesk, Yotpo, YouTube (embedded videos), AfterSell and Bundle (offers and bundles at checkout), our AI quote assistant, Shopify Forms

Your choices

  • Cookie banner. If you visit from the UK, the EEA or Switzerland, a cookie banner lets you accept or decline non-essential cookies, and analytics, marketing and visitor identification tools wait for your choice. Elsewhere, including the United States and Canada, these tools load when you visit, and you can use the other choices below. You can change your choice at any time through the Cookie preferences link in our site footer or at the end of each policy page.
  • Opting out of sale and sharing. See Your US state rights.
  • Browser settings. Most browsers let you block or delete cookies. Blocking strictly necessary cookies may stop parts of the site, such as checkout, from working. All About Cookies explains how.
  • Advertising controls. You can manage Google ads in My Ad Center, install the Google Analytics opt-out add-on, adjust your LinkedIn advertising settings and Pinterest privacy settings, and opt out of interest-based ads from many companies through the Digital Advertising Alliance, the Network Advertising Initiative or, in the UK and Europe, Your Online Choices.
  • Global Privacy Control. Where the law requires it, we treat a Global Privacy Control signal from your browser as a request to opt out of sale and sharing for that browser.
  • Do Not Track. There is no common standard for Do Not Track signals, so our site does not respond to them.

Marketing emails

In short: We only want to be in your inbox if we’re useful. Every marketing email gives you a way out.

We send marketing emails, mainly through Klaviyo and Apollo, to clients and customers, to people who ask to hear from us and to business contacts we believe we can help (see Prospects and business data). These tools tell us whether an email was opened and which links were clicked, using small tracking images and tracked links.

To stop marketing emails:

  • click the unsubscribe link included in every marketing email;
  • reply and ask us to stop; or
  • email support@arcticgrey.com.

We act on opt-outs promptly, and within 10 business days at the latest, across all of our email tools. Unsubscribing does not stop service messages, such as order confirmations, invoices, weekly hour reports and project updates, while you are a customer or client. We send marketing text messages only to people who have agreed to receive them. Reply STOP to any text to stop them.

How long we keep data

In short: We keep personal information only as long as we need it for the reasons in this policy, then delete or anonymize it.

How long we keep information depends on why we hold it. These are our standard periods. We keep information longer where the law requires it, or where we need it for a legal claim or dispute.

Information How long we keep it
Site analytics and advertising data Google Analytics: 14 months. Hotjar recordings: 365 days. Other tools as each provider sets, generally up to 2 years. Cookies expire on the schedule each provider sets.
Partly completed forms you did not submit Up to 12 months.
Inquiries and form submissions that do not lead to work Up to 3 years after our last contact with you.
Orders, invoices, contracts and accounting records 6 years from the end of the financial year they relate to, in line with UK tax record rules.
Client relationship records, project communications and support tickets For the engagement and 6 years after it ends.
Meeting recordings and transcripts As long as they remain useful for the client relationship, project or hiring decision they relate to, or while a dispute is active. You can ask us to delete a recording that includes you at any time.
Prospect data Up to 2 years after our last meaningful interaction.
Suppression list (people who asked us not to contact them) For as long as we market to businesses, so that we keep honoring the request.
Job applications and video introductions 12 months after the role is filled, or longer if you agree that we can consider you for future roles.
Client store data As the client’s agreement sets out. We delete or return it within 30 days of the end of the engagement, or earlier on request, unless the law requires otherwise.

How we protect data

In short: We protect personal information with access controls, trusted providers and a small circle of people who need it. No system is perfect, so we also plan for the day something goes wrong.

Our measures include:

  • giving team members access only to the information and client systems their work needs, reviewing access regularly, and removing it when they no longer need it or leave;
  • multi-factor authentication on our core business accounts, including Google Workspace, Shopify, GitHub and Slack;
  • encrypted connections (HTTPS) on our site;
  • established providers, such as Shopify, Google, Amazon Web Services and Cloudflare, that run independently audited security programs;
  • confidentiality obligations in every team member and contractor agreement; and
  • working in client systems through accounts the client controls and can revoke.

If a personal data breach is likely to put your rights at risk, we will tell you and the Information Commissioner’s Office as the law requires. If you think information you have shared with us is at risk, email support@arcticgrey.com straight away.

Your rights

In short: Wherever you live, you can ask what we hold about you, and ask us to correct it, delete it or stop using it. You can always say no to marketing.

Because UK data protection law is our baseline, these rights are available to everyone whose information we handle, wherever you live. If you are in the EEA, the EU GDPR gives you the same rights:

  • Access. Ask for a copy of the personal information we hold about you.
  • Correction. Ask us to correct information that is inaccurate or incomplete.
  • Deletion. Ask us to delete your information in certain circumstances.
  • Restriction. Ask us to limit how we use it in certain circumstances.
  • Portability. Receive information you gave us in a structured, machine-readable format, or have it sent to another organization, where we process it by automated means based on your consent or a contract.
  • Objection. Object to processing based on our legitimate interests. If you object to direct marketing, including profiling for marketing, we will stop.
  • Withdrawing consent. Withdraw your consent at any time where we rely on it. This does not affect processing that happened before.
  • Automated decisions. Not be subject to decisions based solely on automated processing that have legal or similarly significant effects on you.

Some rights have limits. For example, we may keep records that the law requires or that we need for a legal claim. If we cannot do what you ask, we will tell you why. To use these rights, see Making a request. You can also complain to a regulator; see Questions and complaints.

Your US state rights

In short: If you live in California or another US state with a privacy law that applies to us, you have similar rights, including the right to opt out of targeted advertising.

Several US states give residents rights over their personal information, including California (under the California Consumer Privacy Act, as amended) and states such as Colorado, Connecticut, Oregon, Texas, Utah and Virginia. These laws apply only to businesses that meet certain thresholds, and some exclude information collected in a business-to-business or employment context. This section applies only to the extent such a law applies to us and to you.

Subject to those laws, you may have the right to:

  • Know and access. Ask what personal information we have collected about you, where it came from, why we use it and who we disclose it to, and get a copy of it.
  • Correct. Ask us to correct inaccurate information.
  • Delete. Ask us to delete information we collected from or about you.
  • Portability. Get your information in a portable format.
  • Opt out. Opt out of the sale of your personal information, its sharing for cross-context behavioral advertising, and targeted advertising.
  • Appeal. Appeal if we decline your request (see Making a request).
  • Equal treatment. We will not discriminate against you for using these rights.

Some states also let you limit the use of sensitive personal information, or opt out of profiling that leads to decisions with legal or similarly significant effects. We use sensitive personal information only for purposes the law allows, and we do not carry out that kind of profiling, so these rights do not change how we handle your information.

Opting out of sale, sharing and targeted advertising

We do not sell personal information for money. However, the advertising cookies and pixels described in Cookies and tracking, for example from Google, LinkedIn, Pinterest and AdRoll, let those companies collect information about your visits, which may count as a “sale,” “sharing” or “targeted advertising” under these laws. To opt out:

  • use the “Your privacy choices” link in our site footer or at the end of each policy page, which opens our “Do not sell my personal information” page;
  • turn on Global Privacy Control in your browser; or
  • email support@arcticgrey.com with “Do not sell or share” in the subject line.

Opt-outs set through a cookie or a browser signal apply to that browser and device. We do not knowingly sell or share the personal information of anyone under 16.

California notice

If the California Consumer Privacy Act applies to us, this notice applies to California residents. In the past 12 months we have collected the following categories of personal information, as the California Consumer Privacy Act defines them, from the sources and for the purposes described in What we collect and why:

  • identifiers, such as name, email address, phone number, IP address and online identifiers;
  • customer records, such as billing address and limited payment details;
  • commercial information, such as purchases and the services you asked about;
  • internet or other electronic network activity, such as how you browse our site and interact with our emails;
  • approximate geolocation derived from your IP address;
  • audio, electronic and visual information, such as call recordings and video introductions;
  • professional or employment-related information, such as job title, employer and job application details; and
  • inferences, such as scores about likely interest in our services.

We disclose each category for business purposes to the service providers and contractors described in Sharing and subprocessors. Identifiers, internet activity and inferences may be sold or shared through advertising cookies and pixels, as explained above. The only sensitive personal information we may collect is the login details for a store account, if you create one, and we use them only to give you access to that account. We keep each category for the periods in How long we keep data. We do not share personal information with third parties for their own direct marketing purposes.

Making a request

In short: Email us or call our toll-free number. We’ll check it’s really you, then respond within the time the law allows.

To use any of your rights:

  • email support@arcticgrey.com with “Privacy request” in the subject line; or
  • call us toll free at +1 (844) 311-6962.

Tell us what you would like us to do, and give us enough information to find your records, such as the email address you used with us.

How we verify requests

To protect your information, we check that a request comes from the person it is about. We usually do this by matching the details you give us against our records and asking you to confirm the request from the email address we hold for you. For requests involving more sensitive information, such as copies of recordings, we may ask for more. We use verification information only to verify your request, and you do not need an account with us. We do not need to verify a request to opt out of sale, sharing or marketing, although we may decline one we believe is fraudulent.

Authorized agents

You can ask someone else to make a request for you. We will ask the agent for your signed permission and may ask you to confirm your identity with us directly, unless the agent holds a valid power of attorney.

Timing and cost

Under UK and EU law, we respond within one month, which we can extend by up to two further months for complex or numerous requests. Under US state laws, we confirm receipt within 10 business days where required and respond within 45 days, which we can extend once by up to 45 more days. We will tell you if we need more time and why. Requests are free, but where the law allows we may charge a reasonable fee for, or decline, requests that are manifestly unfounded or excessive.

Appeals

If you live in a US state that gives you a right to appeal and we decline your request, you can appeal by replying to our decision with “Appeal” in the subject line. We will respond within the time your state’s law requires. If you are not satisfied with the outcome, you can contact your state attorney general.

If your request is about a store run by one of our clients, where you are a shopper, please contact that business. We will pass on any such request we receive.

Children’s privacy

In short: Arctic Grey is a business service for adults.

Our site and services are meant for businesses and are not directed at anyone under 18. We do not knowingly collect personal information from children, and we accept job applications only from people aged 18 or over. If you believe a child has given us personal information, contact us and we will delete it.

Changes to this policy

In short: When our practices change, this page changes too, and the date at the top tells you when.

We may update this policy to reflect changes in our practices, our tools or the law. We will post the updated version on this page and change the “Last updated” date. If we make a material change, we will also tell clients and customers by email or by a notice on our site before the change takes effect.

Questions and complaints

In short: If something isn’t right, tell us first and we’ll work to fix it. You can also go to the UK regulator or the regulator where you live.

Contact us at support@arcticgrey.com, at +1 (650) 288-0533 or toll free at +1 (844) 311-6962, or by post at International House, 142 Cromwell Road, London SW7 4EF, United Kingdom.

You have the right to complain to the UK’s data protection regulator, the Information Commissioner’s Office (ICO), at ico.org.uk/make-a-complaint, on 0303 123 1113, or by post at Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. We would appreciate the chance to resolve your concern first.

If you live in the European Economic Area, you can complain to the data protection authority where you live or work; the European Data Protection Board lists them. If you live in California, you can also contact the California Privacy Protection Agency. In other US states, you can contact your state attorney general. If you live in Canada, you can contact the Office of the Privacy Commissioner of Canada.