Privacy Policy · CreatePins – Custom Enamel Pins
Your privacy, our promise

Privacy Policy

Last Updated: February 2026

CreatePins.com (“CreatePins,” “we,” “our,” or “us”) operates the website www.createpins.com and acts as the data controller of your personal data.

This Privacy Policy explains how we collect, use, process, disclose, and safeguard your personal information when you visit or make a purchase from our website. By using our website, you agree to the practices described in this Policy.

We are committed to protecting your privacy and handling your personal data in a transparent and secure manner.

1 Information We Collect

1.1 Information Collected Automatically (“Device Information”)
When you visit CreatePins.com, we automatically collect:

  • IP address
  • Browser type and version
  • Device type
  • Time zone
  • Referring website
  • Pages viewed and browsing behavior
  • Cookies and tracking technologies

This information is used for analytics, fraud prevention, and website optimization.

1.2 Information You Provide to Us
We collect personal information that you voluntarily provide, including:

First and last name Company name Billing/shipping address Email address Telephone number Payment information Order details & artwork files Communications via forms/email

This information is required to process orders, respond to inquiries, and provide customer support.

2 Legal Basis for Processing (GDPR – EU/EEA Residents)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data under the following lawful bases:

  • Performance of a contract – To fulfill orders and provide services
  • Legal obligation – To comply with tax, accounting, and regulatory requirements
  • Legitimate interests – Fraud prevention, business analytics, and website improvement
  • Consent – For marketing communications or optional cookies

You may withdraw consent at any time.

3 Your Rights Under GDPR

If you are an EU/EEA resident, you have the right to:

  • Right to be informed
  • Right of access – Request a copy of your personal data
  • Right to rectification – Correct inaccurate data
  • Right to erasure (“Right to be forgotten”)
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing
  • Rights related to automated decision-making and profiling
To exercise your rights, contact:

We will respond within one month as required by GDPR. If you believe your rights have been violated, you may lodge a complaint with your local Data Protection Authority.

4 California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):

  • 4.1 Right to Know – Categories and specific pieces of personal information collected, sources, business purpose, third parties.
  • 4.2 Right to Delete – Request deletion, subject to exceptions.
  • 4.3 Right to Correct – Correct inaccurate information.
  • 4.4 Right to Opt-Out of Sale or Sharing – CreatePins does not sell personal information. If this changes, you will have opt-out rights.
  • 4.5 Right to Non-Discrimination – No discrimination for exercising rights.

4.6 How to Exercise California Rights
To submit a verifiable consumer request, contact: hello@createpins.com. We may need to verify your identity.

5 Categories of Personal Information Collected (CCPA Disclosure)

In the past 12 months, we may have collected:

  • Identifiers (name, email, IP address)
  • Commercial information (order history)
  • Internet activity (browsing behavior)
  • Financial information (payment details processed securely via payment providers)

We collect this information directly from you or automatically through website usage.

6 Cookies and Tracking Technologies

7 Data Transfers

Your information may be transferred to and processed in countries outside your residence, including the United States and Canada.

Where required under GDPR, we implement appropriate safeguards such as: Standard Contractual Clauses (SCCs) and data processing agreements with service providers.

8 Data Retention

We retain personal data only as long as necessary to: fulfill contractual obligations, comply with legal requirements, resolve disputes, and enforce agreements. When no longer needed, data is securely deleted or anonymized.

9 Data Security

We implement reasonable administrative, technical, and physical safeguards to protect your data. However, no internet transmission method is completely secure.

10 Third-Party Links

Our website may contain links to third-party websites. We are not responsible for their privacy practices. Please review their privacy policies separately.

11 Children’s Privacy

Our services are not directed to individuals under 13 years of age. We do not knowingly collect personal data from children.

12 Changes to This Policy

We may update this Privacy Policy periodically. The updated version will be posted on this page with a revised “Last Updated” date.

13 Contact Information

If you have questions about this Privacy Policy or wish to exercise your rights:

hello@createpins.com www.createpins.com