Privacy Policy for Customer

Last updated: September 11th, 2024

We at Forged Steel Tools are determined to manufacture the highest quality tools for wood, leather crafting, and any other creative endeavors of yours. We also apply the same level of quality to safeguarding your Personal Data recognizing its value as a powerful tool in today’s world.

This Privacy Policy establishes the terms and conditions, based on which Forged Steel Tools will process your Personal Data – certain information that identifies you as a specific individual or can be used to contact or identify you. 

1. Binding Agreement

By conducting a purchase from us or registering the account at our Site, you agree to be bound by this Privacy Policy which is an integral part of the User Agreement. 

This Privacy Policy constitutes a legally binding agreement between you, as the Customer (hereinafter - “you”, “Customer”), and us – Forged Steel Tools, operated by FST 106906 LLC,  the company duly established under the laws of the state of Florida, USA, with registered address at: 3500 W HALLANDALE BEACH BLVD, STE 156, HOLLYWOOD, FL 33023, (hereinafter – the “Company”, also may refer to “Forged Steel Tools”, "we", “us” "our", “ours” in the Privacy Policy or any Policies referred hereto). 

All definitions used hereto have the same meaning as defined in the User Agreement.

2. Data Processing Roles

We act as the Controller for the purposes of your Personal Data processing. This means we manage all matters related to your Personal Data. We will outline below the principles and methods we use to handle the Personal Data.

Forged Steel Tools online store is powered by the Shopify ecommerce platform (hereinafter – “Shopify”). All Personal Data we receive from you during the purchase checkout stage are transferred directly to the Shopify data centers. Shopify acts as the Data Processor for the purposes of your Personal Data processing. You may find more information how Shopify handles users’ Personal Data in their general Privacy Policy and their Privacy Policy for the Consumer (this applies to you directly).

In case you have any questions or requests related to your Personal Data, please refer them to us. If your requests fall under the responsibilities of the Data Processor, we will forward them to Shopify and ensure they are addressed. We will keep you informed with the latest updates regarding your data requests.

3. Categories of Personal Data We Collect from You

During the purchase checkout stage and only in case you finalize the purchase we collect the following categories of Personal Data from you:

  1. Email;
  2. Country/region;
  3. First and Last Name;
  4. Address (including apartment/suite);
  5. Phone number.

Also during the purchase checkout stage you will be asked to provide your payment details to conduct the payment for the Product. Please be aware that we do not see, process and store any of your payment details. All your payment details go directly to Shopify as Data Processor and Shopify’s sub-processors who operate special financial instruments licenses like PCI DSS to collect, process and protect financial information. You can find more info here how Shopify protects your credit card details.

During the account registration at our Site we collect the following categories of Personal Data from you:

  1. Email;
  2. First and Last Name.

4. Purposes for Which We Process Your Personal Data

We collect Your First and Last Name, country/region, address and phone number to organize your purchase shipment. These are the ordinary data required by any postal services provider to deliver the parcel.

We collect your email to send you the order details and shipping updates. 

You can also decide to create a user account with us. In this case we will need your email for the account registration and future logins. However, account registration is non-obligatory to purchase from us, and you are not required to do so.

During the checkout process you may actively opt in to receive the marketing materials from us. In this case, we will need your email as well to send marketing materials.

Shopify will use your phone number for faster checkouts next time you decide to buy anything at Shopify powered stores. They will send a code by text message to securely purchase with Shop Pay. In this case only Shopify acts as the Data Controller, we do not use your phone number for this purpose. 

During the account registration at our Site we collect your email, First and Last Name in order to create your account, send you the account confirmation email and send you the personalized technical emails about Site and Products’ updates.

We do not process any special categories of your personal data (they may also be called “sensitive data” in some jurisdictions).

5. The legal basis to process your Personal Data

We process your Personal Data to perform our duties as a seller under the User Agreement to finalize a purchase from our side and organize the Product shipment to you (legal basis: GDPR Article 6-1-(b)).

In certain specific situations like sending marketing materials to you, replying to your request received through the contact form, we may also process Your Personal Data based on Your consent (legal basis: GDPR Article 6-1-(a)). In those situations, we process your Personal Data on the terms as provided in the consent that you have granted to us.

Please note that if you gave your consent to use your Personal Data for purposes above, You can withdraw your consent by simply notifying us at the email: support@forgedsteeltools.com.

In the light of the mentioned above, we process your Personal Data: 

  • To sell you the Product and perform the User Agreement;
  • To create the account at our Site for you;
  • To provide the functionality of the Site;
  • To respond to your inquiries and fulfill your requests, when you contact Us, or when You request any information about the Products.

Please note that if you do not provide the information requested, we may not be able to provide you with the necessary communication, Site functionality or sell the Products to you.  

6. When we can share your Personal Data

In order to sell you the Product, conduct the analytical activities, and improve our Products in future, we engage our third-party service providers.

We will share your Personal Data with our third-party service providers for the purposes above. We will disclose only those Personal Data which are specifically required for the particular services and purposes and ensure the third-party service providers follow all the required security measures. Such transfers may include transferring your personal data to third countries by third-party service providers under their privacy policies. We do not conduct cross-border data transfers by ourselves.

Our third-party service providers will act as the Data Processors in relation to your Personal Data which means they process our Customers’ Personal Data on our behalf. 

Our main Data Processor is Shopify where we are registered as a merchant and use Shopify's ecommerce facilities to conduct sales. Shopify utilizes multiple Sub-processors to manage your Personal Data and their privacy rules are outlined in Privacy Policy for the Consumer.

Thus, we have our Data Processors and Shopify has their Sub-processors.

For the purpose of this clause the term "Sub-processor" shall mean another data processor, including but not limited to group companies, subsidiaries and auxiliary suppliers, engaged by the data processor to perform specific processing activities on behalf of the data controller.

We use the following Data Processors and platform integrations with Shopify who acts as sub-processors to manage your Personal Data:

Our Data Processors: 

  • Shopify

Shopify sub-processors we use:

  • Keycrm.app (client management system);
  • Judge.me Reviews (product review tool for the website);
  • Trustpilot Reviews (product review tool for the website);
  • Hotjar (customer behavior analytics tool);
  • UpPromote Affiliate (referral & affiliate program app);
  • Microsoft Channel and Clarity (integration that allows to bring the Shopify product catalog online to Microsoft Merchant Center);
  • TikTok Shop (TikTok platform to showcase and sell products);
  • Linktree (link-in-bio solution);
  • Facebook
  • Pinterest
  • Gmail

We also disclose your Personal Data to the third parties when we are obliged by law or other applicable legislation.

We will share information with government agencies as required by law. We cooperate with government and law enforcement officials and private parties to enforce and comply with the law. We will disclose information about you to government or law enforcement officials if it is necessary or appropriate to respond to claims and legal process, at the request of governmental authorities or other third parties conducting an investigation, to protect the property and rights of us or a third party, to protect the safety of the public or any person, or to prevent or stop activity we may consider to be illegal, fraudulent or unethical.

We may share your Personal Data with our affiliates – related to us legal entities, which are ruled by the same management as we and/or have the same owners. 

7. How do we store your Personal Data?

Your Personal Data is hosted on servers provided by Shopify on Amazon Web Services in its USA data centers. The AWS infrastructure puts strong safeguards in place to protect your Personal Data. All data is stored in highly secure AWS data centers. 

The following is a partial list of assurance programs with which AWS complies:

SOC 1/ISAE 3402, SOC 2, SOC 3

FISMA, DIACAP, and FedRAMP

PCI DSS Level 1

ISO 9001, ISO 27001, ISO 27017, ISO 27018.

8. How do we protect your Personal Data?

To protect your Personal Data from unauthorized access, unlawful processing or disclosure, accidental loss, modification or destruction, we use the appropriate technical and organizational measures:

1) Encryption

Transfers of your data are encrypted via HTTPS which also adds an additional layer of protection for our Customers data during transmission.

2) Limited access to Personal Data

We work with your Personal Data under the principle of strict access role distribution. The list of those, who have access to your Personal Data is strictly limited and grounds on a need-to-know basis. 

9. Retention period

According to the storage limitation principle of data processing we will store Your Personal Data only as long as it is required to sell you the Product and perform the User Agreement, or until you withdraw your consent (if we process the data under your consent) or inform us directly to delete your Personal Data, or delete your account (if you decided to register before).

Also Shopify as our Data Processor stores your Personal Data under the terms defined in their Privacy Policy for the Consumer and according instructions provided by us. If you have any questions related to Shopify data retention period, please, contact us.

However, if we are required by law or any mandatory regulation to retain your Personal Data longer or if We need Personal Data to assert or defend against legal claims, We will retain Your Personal Data until the end of the relevant retention period or until the claims in question have been settled.

10. Your data privacy rights

You have the following privacy rights related to your Personal Data processing:

  • Right to be informed 

This right means that you can get the information from us how we use your Personal Data.

  • Right to access

This right entitles you to verify the Personal Data held by us, get informed on the ways it is used and the purposes of the processing. To gain access to your Personal Data, you would need to open your personal account (if you decided to register the account) or contact us at: support@forgedsteeltools.com and we will inform you which of your Personal Data we store and process.

  • Right to rectification

You can edit your Personal Data recorded in your account (if you decided to register the account). You can do this by yourself in your account or you can contact us at: support@forgedsteeltools.com and indicate which data you want to rectify in your request. We will rectify Your data during the 24 hours since receiving your request. 

If you do not have the account, please contact us at: support@forgedsteeltools.com and we will rectify your Personal Data.

  •  Right to erasure, "right to be forgotten"

This right means that you can request the removal of your Personal Data, we hold and process, but please pay attention that we can delete your Personal Data only if there is no legal or regulatory obligation to retain it. If you want us to delete your Personal Data, please make a request by contacting us via email: support@forgedsteeltools.com.

  • Right to restriction of processing

This right means that you can ask us to stop processing your Personal Data, but please kindly note that there are certain categories of data that we need to sell you the Product, and if we stop processing them, you will not be able to buy the Product.

  • Right to object and right to withdraw consent

You can refuse to receive the newsletters and marketing materials on your email, using the “Unsubscribe” button in your email or by contacting us at: support@forgedsteeltools.com

11. Withdrawing Your consent

If we collect and process your Personal Data under your consent as a legal basis, you can withdraw your consent at any time. In order to do it You can contact us at: support@forgedsteeltools.com with a notification about consent withdrawal regarding certain categories of your Personal Data.

In case of withdrawal we will stop processing your Personal Data subject to such consent. But in case when we are required to retain your Personal Data for legal reasons your data will be restricted from further processing and only retained for the term required by law.

Please note that withdrawing your consent will not affect the lawfulness of any processing activities we conducted prior to your withdrawal. And we still can process Your Personal Data on legal grounds other than consent. 

12. Marketing

We can, with your consent, process your Personal Data to provide you with the information about our activities and Product updates. In cases when you gave your consent on receiving marketing materials during the checkout process or account registration, we will send such marketing material to your email.

Please pay attention that if нou did not choose such option during the registration, цe still can send letters to your email, but only in cases when we are obliged under the law or under the User Agreement to provide you with certain information (for example, when we change our User Agreement and Privacy Policy, make any Site updates, etc.,), we can inform you about it by sending you the email.

We can also use your Personal Data (with your prior consent) to provide it to the third parties services in order to set the targeting marketing.

13. Privacy Regulations and Privacy Notice

Our Company is registered in the state of Florida, US. Despite our US jurisdiction we apply worldwide privacy regulations to handle our Customers’ Personal Data at the highest standards. We comply with the GDPR as our Customers’ Personal Data safety is our priority. Forged Steel Tools Customers have full range of their privacy rights under the GDPR.

We also comply with US privacy laws. State of Florida privacy regulations – The Florida Digital Bill of Rights (FDBR) – provides the privacy rights set to data subjects similar to those found in other state privacy laws. However, we as a small business do not have privacy obligations under FDBR, we still provide our Customers from the state of Florida with the rights to access, correct, delete personal data, and withdraw their consent from certain types of Personal Data processing.

The same relates to California residents and residents of any other jurisdictions: you have rights to manage your Personal Data and we are here to facilitate those rights. Please refer to Section 10 thereto to exercise your data privacy rights.

14. Changes to this Privacy Policy

We may update this Privacy Policy in future, if needed to comply with data protection laws and regulations. In such cases, we may send you a letter of notification to your email prior to the change becoming effective. We will always use your Personal Data in accordance with GDPR and other privacy laws requirements and in a manner consistent with the Privacy Policy in effect at the time you submitted the information, unless you consent to the new or revised policy.

15. Contact details

If You have any questions related to this Privacy Policy or the processing of your Personal Data, please contact us at: support@forgedsteeltools.com.