Privacy Policy and U.S. State Privacy Notice
Effective date: July 29, 2026
Last updated: July 29, 2026
This Privacy Policy and U.S. State Privacy Notice (“Privacy Policy”) explains how EasyCommerce GmbH, doing business as familypresent (“familypresent,” “we,” “us,” or “our”), collects, uses, discloses, retains, and protects personal information in connection with:
- the website https://family-present.com, including its product-personalization features and checkout;
- purchases, payments, production, fulfillment, shipping, digital artwork, gift cards, and related services;
- customer support and other communications;
- reviews, referrals, marketing, analytics, and advertising; and
- any other service that links to this Privacy Policy.
This Privacy Policy is intended for customers and visitors in the United States. Because EasyCommerce GmbH is established in Austria, the EU General Data Protection Regulation (“GDPR”) may also apply to processing carried out in the context of our Austrian establishment. Part II of this Privacy Policy contains additional disclosures and rights for residents of U.S. states with applicable privacy laws.
This Privacy Policy does not apply to information processed solely in an employment or business-to-business context where a different notice applies.
Quick links: Notice at Collection · U.S. Privacy Rights · California Privacy Notice · Consumer Health Data Privacy Policy · Your Privacy Choices
Part I - General Privacy Policy
1. Who We Are and How to Contact Us
The controller of personal information covered by this Privacy Policy is:
EasyCommerce GmbH
Delugstraße 7/2/3
1190 Vienna
Austria
Company register number: FN 588118f
Company register court: Commercial Court of Vienna
Managing Director: Florian Jakob Grafinger
Privacy requests: office@easy-commerce.at
Customer support: support@family-present.com
Online contact form: https://family-present.com/pages/contact
For requests to opt out of sale, sharing, or targeted advertising, please also use:
Your Privacy Choices: https://family-present.com/pages/data-sharing-opt-out
2. Notice at Collection
California Notice at Collection. This Section 2 is our Notice at Collection for California consumers. It identifies the categories of personal information, including sensitive personal information, that we collect; the purposes for which each category is collected or used; whether each category is sold or shared; and the period for which each category is retained or the criteria used to determine that period. For a complete description of our practices, rights and request methods, see this Privacy Policy. Our Consumer Health Data Privacy Policy is in Section 29. To opt out of sale or sharing, use Your Privacy Choices.
The following table summarizes the categories of personal information we collect, why we collect them, whether they may be sold or shared as those terms are defined by certain U.S. privacy laws, and our general retention periods. “Sale” and “sharing” are statutory terms that may include certain advertising-related disclosures even when no money is exchanged. We do not sell customer-uploaded photos, artwork files, payment-card information, or sensitive personal information.
| Category | Examples | Main purposes | Sold or shared for targeted advertising? | General retention |
|---|---|---|---|---|
| Identifiers and contact information | Name, email address, telephone number, billing and shipping address, account or order number, IP address, cookie ID, device ID, hashed contact identifiers | Operate the Shop; process orders; communicate; provide support; prevent fraud; deliver marketing where permitted; measure advertising | Online identifiers and, where enabled and permitted, hashed contact identifiers may be sold or shared with advertising and analytics partners. Ordinary order-contact data is not sold for money | Order and accounting records generally 7 years; non-contract support generally 12 months; contract-related communications generally up to 3 years; advertising and cookie data according to the relevant cookie or platform setting |
| Customer records and account information | Contact details, account credentials, transaction references, billing details, delivery information | Account administration, checkout, payment, delivery, fraud prevention, legal compliance | Certain identifiers may be shared for advertising measurement or targeted advertising where permitted; account credentials and payment-instrument data are not | Account life plus applicable legal periods; order and accounting records generally 7 years |
| Commercial information | Products viewed or purchased, order history, personalization selections, discounts, gift-card and referral activity, cart and checkout activity | Fulfill orders; provide digital artwork; support; analytics; offers; advertising measurement | May be sold or shared with advertising and analytics partners for measurement and targeted advertising, subject to your choices | Order records generally 7 years; advertising data according to cookie and platform settings |
| Internet or electronic network activity | Pages viewed, clicks, searches, referring URL, browser, device, operating system, language, timestamps, interaction and event data | Site operation, security, troubleshooting, analytics, attribution, advertising and audience measurement | May be sold or shared with advertising and analytics partners, subject to your choices | Security logs for as long as reasonably necessary; analytics and advertising data according to configured cookie and platform periods |
| Approximate geolocation | Country, state, city, or region inferred from IP address or checkout information | Site localization, estimated delivery, security, fraud prevention, analytics and advertising | Approximate location may be sold or shared for advertising and analytics; we do not request precise GPS location for ordinary Shop use | According to the associated transaction, log, cookie, or advertising record |
| Payment and financial information | Payment method, billing address, transaction amount and status, fraud signals, payment token or transaction reference | Process payments, prevent fraud, issue refunds, keep accounting records | No | We generally do not receive complete card numbers; payment providers retain payment data under their own policies; our transaction and accounting records are generally retained 7 years |
| Photos, artwork, personalization content and other sensory information | Private order photos, selected crop, names, dates and custom text, previews, prompts, generated variants, working files and final artwork | Create the requested personalized artwork; provide previews; perform AI-assisted and human editing; produce and deliver the product; provide support | No. We do not use customer-uploaded order photos or artwork files for targeted advertising | Image files under our control are deleted no later than 90 days after completion of the order, unless needed for an active complaint, correction, dispute, or legal claim; Teeinblue order-personalization metadata may be retained up to 12 months; non-image order metadata follows the order-record period |
| Potentially sensitive information | Account login data; information incidentally visible in a photo or voluntarily included in personalization text, such as racial or ethnic origin, religious dress, health or disability information, or information relating to a known child | Only to provide the product or service requested, secure the account, comply with law, or resolve a request or dispute; we do not use photos to infer sensitive characteristics | No | Follows the applicable photo, account, order, or support retention period |
| Communications, reviews and user-generated content | Emails, chat messages, support records, review text, review photos, survey responses, consent and opt-out records | Respond to requests; provide support; publish reviews submitted for publication; prevent abuse; document consent and privacy choices | Not ordinarily. Interaction with marketing communications may be used for analytics and advertising where permitted | Non-contract inquiries generally 12 months; contract or claim-related communications generally up to 3 years or longer if required; published reviews until removed or no longer needed; consent records generally for the period relied upon and up to 3 years afterward |
| Inferences | Product interests, likely preferences, marketing segments, campaign attribution, purchase propensity | Personalize our own marketing, measure campaigns and create advertising audiences | May be sold or shared with advertising partners for targeted advertising, subject to your choices | According to the relevant cookie, audience, or advertising-platform setting |
We may retain information longer where required by law or reasonably necessary to establish, exercise, or defend legal claims, investigate fraud or security incidents, complete a pending request, or comply with a preservation obligation. We do not retain personal information longer than reasonably necessary for the disclosed purpose.
You can exercise advertising opt-out rights through Your Privacy Choices. Where required by law, we also recognize qualifying browser-based universal opt-out preference signals, including Global Privacy Control (“GPC”).
3. Sources of Personal Information
We collect personal information from the following categories of sources:
- Directly from you, including when you browse the Shop, upload a photo, personalize a product, create an account, place an order, contact us, subscribe to marketing, submit a review, participate in a referral program, or exercise a privacy right.
- From your browser or device, through cookies, pixels, local storage, tags, server logs and similar technologies.
- From another customer acting at your direction or for a gift, for example where someone identifies you as a recipient, uploads a photo in which you appear, or provides your shipping or gift-delivery information.
- From service providers and business partners, such as Shopify, payment providers, fraud-prevention providers, production and shipping partners, marketing providers, analytics providers, referral platforms, and customer-support tools.
- From advertising and social-media platforms, including campaign, attribution, audience, engagement and conversion information.
- From public or user-directed sources, for example when you choose to interact with our public social-media pages or publish a review.
4. How We Use Personal Information
We use personal information for the following purposes:
- providing, operating, maintaining and securing the Shop;
- displaying products, saving carts, administering accounts and remembering choices;
- receiving, checking, accepting, producing, fulfilling and delivering orders;
- processing payments, refunds, discounts, gift cards and transaction records;
- creating and delivering personalized artwork and associated digital artwork;
- providing previews, quality control, corrections, replacements and customer support;
- preventing fraud, misuse, unauthorized transactions, security incidents and technical errors;
- sending order, payment, artwork, production and shipping communications;
- sending marketing communications when permitted and recording opt-outs;
- administering reviews, referrals, promotions and post-purchase offers;
- measuring traffic, conversions, campaign performance and customer experience;
- creating audiences and delivering targeted advertising, subject to consent and opt-out rights;
- improving our products, Shop, content, operations and customer service;
- maintaining accounting, tax, corporate and legal records;
- enforcing our terms, resolving disputes and protecting rights, safety and property;
- complying with legal obligations and responding to lawful requests; and
- carrying out a corporate transaction, such as a merger, financing, reorganization, sale of assets or acquisition, subject to applicable law.
Where we process deidentified information, we take reasonable measures to prevent it from being associated with an individual, publicly commit to maintaining it in deidentified form where required by law, and do not attempt to reidentify it except as permitted to test whether our deidentification measures are effective.
5. Shopify, Hosting, Accounts and Checkout
The Shop is operated using Shopify. For merchants established in the European Economic Area, the contracting Shopify entity is generally Shopify International Limited in Ireland. Shopify group companies and service providers in Canada, the United States and other countries provide technical infrastructure and related services.
When you access the Shop, Shopify and we may process IP address, requested URL, referrer, date and time, browser and device information, operating system, language, approximate region, technical identifiers, security signals, and server or error logs. We use this information to deliver the Shop, maintain security and stability, troubleshoot errors, prevent fraud and operate the cart and checkout.
If you use Shopify services such as Shop or Shop Pay, Shopify may process certain information for its own purposes under its consumer privacy notice. Shopify privacy choices are available at https://privacy.shopify.com.
When you create an account or place an order, we process the information needed to administer the account and transaction, including contact and delivery details, products, variants, personalization choices, custom text, prices, discounts, currency, order and transaction status, and communications.
6. Orders, Payments, Production, Digital Artwork and Shipping
6.1 Orders and gift recipients
We use order information to evaluate and fulfill your purchase, associate personalization data with the correct order, provide the included digital artwork, communicate about corrections or production, handle complaints and replacements, and maintain records.
If you provide information about a gift recipient, alternate delivery recipient, or gift-card recipient, you confirm that you are authorized to provide the information for the requested gift or delivery. We use that information only as reasonably necessary to provide the requested service and related communications.
6.2 Payments
Payments may be processed through Shopify Payments, Shop Pay, PayPal, Apple Pay, Google Pay, payment-card networks, and the payment, banking, authentication, fraud-prevention and infrastructure providers connected to the payment method selected at checkout. PaymentHero may be used to display, order or optimize available checkout payment methods.
We generally do not receive full payment-card or account-access credentials. We receive information such as payment status, transaction reference, amount, currency and limited fraud signals. Payment providers may process information as independent controllers under their own privacy notices and legal obligations.
6.3 Production and fulfillment
Our U.S. production and fulfillment partners receive the final production file, product and order details, and the recipient information needed to produce and deliver the order. We do not provide them with the original raw customer photo.
6.4 Shipping
We disclose the recipient’s name, delivery address, parcel and order information, and, where needed for delivery notifications, email address or telephone number to our production and shipping partners. U.S. carriers may include USPS, OnTrac, FedEx and their delivery partners. Carriers may process information under their own legal obligations and privacy notices.
6.5 Digital artwork
The digital artwork associated with a physical personalized product may be delivered electronically. We use your email address, order number and final artwork file for this purpose. You should download and retain your digital artwork if you wish to keep it, because our internal image copy remains subject to the image-deletion period described below.
7. Photo Uploads, AI-Assisted Image Processing and Human Review
7.1 Information processed
To create a personalized product, we may process:
- the original image or an image sent later by email at our request;
- the selected crop and personalization instructions;
- names, dates, captions or other custom text;
- product, size and variant information;
- previews and editing instructions;
- prompts used to direct an image-processing model;
- generated image variants;
- Photoshop or other working files; and
- the final artwork and production file.
An uploaded photo may show adults, children, pets, homes, vehicles or other subjects. A photo may also incidentally reveal visible personal characteristics. We process the photo to create the artwork requested by the customer, perform quality control, associate the result with the order, produce the item and provide related support.
7.2 Typical processing workflow
Depending on the product and the amount of manual correction required, the workflow may include:
Customer → Teeinblue → Google Gemini → Teeinblue → EasyCommerce GmbH → optional Adobe Photoshop or OpenAI processing → Teeinblue → production partner
Not every service is used for every order.
7.3 Teeinblue Product Personalizer
We use Teeinblue Product Personalizer, provided by TEEINBLUE PTE. LTD., Singapore, for customer uploads, live previews, personalization, order association and creation or transfer of production files.
Teeinblue may process the uploaded image, personalization text, preview, product variant, order identifier, and the limited contact, order and delivery information needed to associate and fulfill the order. Teeinblue acts as our processor for this customer information.
Under Teeinblue’s current published retention terms, customer-uploaded files are automatically and permanently deleted after up to 90 days, and order-related personalization metadata may be retained for up to 12 months unless earlier deletion is requested. Teeinblue may process information in Singapore and through subprocessors in other countries.
7.4 Google Gemini
We use Google Gemini image-generation services, including through a merchant-configured API integration in Teeinblue, to create the requested stylized artwork. We send the original image or necessary image area, a design-focused prompt, and receive the generated result. We do not include the customer’s name, email address, order number, payment information or shipping address in the prompt sent for image generation.
We use a billing-enabled, business-managed account or EEA Cloud project subject to the applicable Google data-processing terms. Feedback, voluntary dataset sharing and model-tuning uses are not enabled for customer images. Under the currently applicable terms for this paid-service configuration, prompts, images and outputs are not used to improve Google’s general models. Google may transiently log prompts and responses for security, abuse-prevention and legal-compliance purposes. If developer-controlled project logging is enabled, those private project logs are retained for the configured period, which may be up to 55 days, and are not shared with Google for model improvement.
7.5 Adobe Photoshop, Firefly and cloud-assisted editing
We may edit artwork locally using Adobe Photoshop. Local editing does not, by itself, require sending the file to Adobe. We do not intentionally synchronize customer images through Adobe Cloud Documents.
If cloud-based functions such as Adobe Firefly, Generative Fill or internet-dependent Neural Filters are used, the selected image or image area, editing instruction and generated result may be processed by Adobe and its service providers. We do not submit customer images to Adobe Stock or voluntarily provide them for model training or general product improvement.
7.6 OpenAI / ChatGPT Business or Enterprise
For limited quality control or correction of an image area, we may use a business-managed ChatGPT Business or Enterprise workspace provided by OpenAI. We do not use personal Free, Plus or Pro workspaces for customer images. We send only the image or necessary image area and an editing instruction, without the customer’s name, contact details, order number, payment information or shipping address.
Business data is not used by OpenAI to train its general models by default, and training or feedback sharing is not enabled for this workflow. We delete relevant chats and files from the business workspace within the image-retention period. After deletion, OpenAI may retain limited data for up to 30 days for security or legal purposes, subject to its applicable terms.
7.7 Human review and no significant automated decision
AI-assisted systems create or modify artwork; they do not decide whether a customer is eligible for a product, price, job, credit, housing, insurance, education, health service or other legally significant opportunity. We review each artwork before physical production and may manually correct it. We do not make a solely automated decision that produces legal or similarly significant effects through this image-processing workflow.
7.8 No use for facial recognition, biometric identification or sensitive-trait profiling
We do not use customer images to:
- identify or authenticate a person;
- create or maintain a faceprint or face-geometry template for identification;
- perform facial recognition;
- infer race, ethnicity, religion, health, disability, sexual orientation, immigration status, emotion or other sensitive traits;
- profile an individual; or
- make a legal or similarly significant decision.
AI systems necessarily process image pixels to create the requested visual transformation, but our purpose is artistic transformation, not identification or sensitive-trait analysis.
We do not use provider-generated content or safety classifications to profile a customer or depicted person or to make a decision about that person.
7.9 No advertising or general model training with private customer images
We do not publish private customer uploads or use them in advertising, portfolios, testimonials or social-media content unless we first obtain a separate, explicit and documented permission for that additional use.
We do not use customer images to train our own general-purpose AI model or intentionally provide them to third parties for general model training. We configure the business services described above to restrict training or product-improvement use where applicable. We do not intentionally send customer-uploaded photos, artwork files, image URLs or image content to Meta, Google Ads, TikTok or other advertising platforms.
We do not collect, use, disclose or sell personal information for the purpose of training large language models or other general-purpose AI models. Our use of third-party generative AI is limited to creating or correcting the personalized product requested by the customer, and we do not permit the providers used for this workflow to train general-purpose models on customer-uploaded photos or artwork.
Advertising integrations are disabled on private upload, preview and digital-artwork delivery pages. Advertising events do not include customer photos, image or preview URLs, custom personalization text, or support or review attachments.
7.10 Photos of other people and minors
If a photo contains another person, the person placing the order is the source of the image. We generally do not receive the depicted person’s contact details and do not try to identify that person from the image.
The uploader must be at least 18 years old and must be the person depicted or have the authority and permissions necessary to request the processing. For a recognizable minor, the uploader must be the parent or legal guardian or must have authorization from the parent or legal guardian.
Do not upload health-related information about another person unless that person has expressly authorized the upload or you are the person’s legally authorized representative. If an image contains consumer health data about another person, we may reject the upload or require consent directly from that person or the person’s legally authorized representative.
When an adult customer voluntarily selects and uploads an image for a personalized product, the customer requests the image processing reasonably necessary to create, review, produce, deliver and support that product as described in this Privacy Policy. The uploader must have the authority and permissions described above. We do not treat the upload as permission for advertising, public display, general-purpose AI training, sensitive-trait inference or any unrelated use. Acceptance of general terms alone is not consent to sensitive-data processing. Where applicable law requires separate consent or another authorization for particular processing and no requested-product or other legal exception applies, the upload alone does not provide that consent; we may request additional authorization, request alternative content or decline to process the affected content. A person depicted in a customer image, or the person’s parent or legal guardian, may contact us to exercise applicable privacy rights. To locate the relevant file without collecting unnecessary identity information, we may request an order number, approximate order date, uploader information or a copy of the affected image.
7.11 Image retention
We delete original uploads, previews, prompts, generated variants, Photoshop or other working files, and final internal artwork files from systems under our control no later than 90 days after the order has been fully completed.
If a correction, complaint, replacement, charge dispute, fraud investigation or legal claim remains open, we retain only the files reasonably needed until the matter is resolved. Processor security logs, restricted backups or legally required records may remain for their documented technical retention periods.
Non-image order and personalization metadata, such as the product, variant, custom text, order number and processing status, may remain in the Shopify order or accounting record for the applicable order-retention period. A temporary image link in an older order may stop working after the underlying file is deleted.
8. Customer Support, Email, Chat and Security Tools
When you contact us, we process the information you provide, such as your name, email address, telephone number, order information, message and attachments, to respond, provide support and document the matter.
We use IONOS for business email and related hosting. We may use Chatty through Shopify for chat and support functions. Chat tools may process contact details, IP and device information, chat content and relevant order information. Please do not upload additional customer photos through chat unless we specifically request them for support.
If we receive an order photo through email or chat for a requested correction, we move it to the restricted image workflow where needed and delete the image and accessible support attachment from systems under our control within the image-retention period. The non-image support record follows the support or contract-communication period described in this Privacy Policy.
Shopify may use hCaptcha, provided by Intuition Machines, Inc., to protect forms, accounts and checkout functions against automated abuse. hCaptcha may process IP address, browser and device information, interaction signals and risk indicators.
Support tools may use automated functions to route requests or assist with draft responses. They are not used to make legal or similarly significant decisions. You may request human assistance.
9. Transactional Messages, Email Marketing and SMS
We send communications needed to provide the service, including order confirmations, payment or production updates, digital artwork, requests for clarification, shipping notices, support messages and responses to complaints. These messages are not marketing subscriptions.
If you subscribe to email marketing, we may process your email address, name, signup source, timestamp, IP address, consent record, campaign engagement, product interests, cart activity and purchase information. We use Klaviyo to send and analyze email and, where offered, SMS communications. You may unsubscribe through the link in each marketing email or by contacting us.
If you separately opt in to marketing text messages, we may process your mobile number, consent record, message activity and opt-out status. Consent to marketing SMS is not a condition of purchase. You can opt out using the instructions in the message, including by replying STOP where supported.
We retain marketing information until you unsubscribe or we no longer need it. After an opt-out, we retain a minimal suppression record to honor your choice. Consent evidence is generally retained for the period we rely on it and up to three years afterward where reasonably necessary to demonstrate compliance.
10. Reviews, Customer Photos, Referrals, Discounts and Post-Purchase Offers
We use Loox to administer product reviews and review invitations. Depending on your choices and the applicable law, Loox may receive name, email address, delivery country, order number, purchased product, purchase date and invitation status. If you submit a review, review name, text or photo for publication, the information you choose to publish may be displayed publicly.
We may display a Trustpilot widget or link. A simple link connects to Trustpilot only when selected. An embedded third-party widget may process device and interaction information when loaded.
We may use BixGrow or similar tools to administer referral programs, including referral links, referring and referred customer identifiers, order status, reward eligibility and anti-fraud information. We may use AfterSell to display our own post-purchase offers and may process order, product, offer and interaction information for that purpose.
We do not use a private order photo or a review photo in paid advertising merely because it was uploaded or published as a review. Advertising, testimonial or broader social-media use requires a separate permission where required.
Our current referral program may provide a referred customer with a 15% discount and the referring customer with USD 15 in store credit after a qualifying purchase. To operate it, we process the participants’ email addresses, optional names, referral link and identifier, referral and qualifying-order status, reward information, and fraud-prevention data. The good-faith value of this information is estimated from the program’s incremental sales and engagement, less the reasonably anticipated cost of providing and administering the benefit. The value varies by participant and is reasonably related to the benefit offered.
Participation is voluntary. A participant opts in by using or submitting the referral feature after receiving the program notice and may withdraw from future participation by contacting us. Withdrawal may end eligibility for unearned benefits but does not affect an already earned benefit except as provided in the program terms or by law. A separate, program-specific Notice of Financial Incentive is presented at or before enrollment where California law applies. Other mailing-list discounts, rewards or benefit programs are covered by a program-specific notice where required.
11. Cookies, Similar Technologies and Consent Management
We use cookies, pixels, tags, local storage, software development tools and similar technologies.
11.1 Necessary technologies
Necessary technologies support functions such as site delivery, security, fraud prevention, shopping cart, checkout, payments, language, account access and storage of privacy choices.
11.2 Analytics and advertising technologies
Subject to applicable consent and opt-out requirements, we use analytics and advertising technologies to understand Shop use, attribute purchases, measure campaigns, create audiences and deliver targeted advertisements. These technologies may process IP address, online and advertising identifiers, device and browser information, referring and viewed URLs, page and product views, search, cart, checkout and purchase events, order value and campaign parameters.
Where enabled and permitted, Enhanced Conversions, Advanced Matching, Conversions API and similar functions may transmit normalized and hashed identifiers, such as email address, telephone number, name or address, together with purchase or event information. Hashing is a form of pseudonymization and does not make the information anonymous.
11.3 Consent and preference management
We use Pandectes GDPR Compliance to collect, store and apply cookie and privacy choices. Pandectes may process a consent or preference ID, timestamp, selected categories, banner version, country, browser and device information, and a shortened IP address.
Where consent is required, nonessential categories remain disabled unless you make an affirmative selection. You can change or withdraw your selection through the Cookie Preferences link in the Shop footer. Where applicable U.S. law provides an opt-out right, you may also use Your Privacy Choices.
11.4 Google Analytics, Google Ads and Google & YouTube
Subject to your choices, we use Google Analytics 4, Google Ads conversion measurement, remarketing, Enhanced Conversions and the Google & YouTube Shopify channel. Google may associate information with a Google account and use information under its own terms for measurement, security, modeling and personalized advertising.
We use Google Consent Mode to communicate consent states to Google tags. Where configured in advanced mode, refusing advertising or analytics cookies prevents those cookies from being set, but limited cookieless signals may still be sent, such as consent state, timestamp, URL and referrer, browser and device information, and the IP address technically required for the connection. We do not include hashed contact, order or payment information in those limited denied-consent signals.
11.5 Meta
Subject to your choices, we use Meta Business Tools, including Meta Pixel, Conversions API and, where enabled, Advanced Matching. Meta may receive device, browser, URL, cookie, interaction, product, cart, checkout and purchase data, as well as permitted hashed identifiers. Meta may associate the information with a Meta account and use it for measurement, audiences and personalized advertising.
11.6 TikTok
Subject to your choices, we use TikTok Pixel and, where enabled, server-side event or matching functions. We may use TiXel as a Shopify pixel-integration service to transmit the disclosed event data to the advertising destinations enabled in the Shop, including TikTok. TikTok may receive device, browser, IP, cookie, page, product, interaction, cart, checkout and purchase information and permitted hashed identifiers. TikTok may associate the information with a TikTok account and use it for measurement, audiences and personalized advertising.
11.7 Do Not Track and Global Privacy Control
Some browsers offer a “Do Not Track” (“DNT”) setting. Because there is no uniform industry standard for DNT, the Shop does not respond to DNT signals as such. We do, however, process qualifying opt-out preference signals, including Global Privacy Control (“GPC”), as requests to opt out of sale, sharing and targeted advertising where required by applicable law.
A qualifying signal applies to the browser or device sending it and to every consumer profile, including a pseudonymous profile, that we associate with that browser or device. If we know which consumer sent the signal, for example, because the consumer is logged in or the browser is associated with a customer account, we also apply the opt-out to that consumer, the known account and associated account-level sale, sharing or targeted advertising as required by applicable law. We do not require additional information to honor the browser- or device-level request.
We may offer you the option to provide an email address solely to extend an opt-out request when you are not otherwise known to us. Declining to provide an email address does not affect the browser- or device-level opt-out. We do not treat the absence of a signal on a later visit or another device as consent to opt in.
You can send a GPC signal by enabling GPC in a supported browser or browser extension. More information is available at https://globalprivacycontrol.org/. Our Your Privacy Choices interface indicates whether an opt-out has been processed for the browser or device.
12. Shopify Apps, Internal Automation, Accounting and Business Analytics
We use Shopify functions and selected apps to operate and analyze the business. Depending on which functions are enabled, these may include:
- Shopify Flow and Translate & Adapt for internal automation and content management;
- AfterSell for our own post-purchase offers;
- TrueProfit for cost, revenue, margin and marketing-performance analysis;
- TiXel for integration of disclosed advertising pixels and events;
- BixGrow for referral administration;
- DELM for estimated-delivery displays;
- PaymentHero for checkout payment-method presentation;
- sevdesk integrations, sevDesk and BMD for bookkeeping and accounting;
- Microsoft 365 and OneDrive for business collaboration and temporary working storage; and
- IONOS services for email, hosting and business operations.
We may disclose necessary records to our accountants, tax advisors, auditors, insurers, banks and legal advisors, including Deloitte group professionals in Austria where engaged. Customer raw photos are not ordinarily included in accounting or tax-advisory systems. Temporary image or artwork copies stored in OneDrive remain subject to the 90-day image-deletion period.
13. How We Disclose Personal Information
We disclose personal information to the following categories of recipients as reasonably necessary for the purposes described in this Privacy Policy:
- E-commerce, hosting and infrastructure providers, including Shopify and related infrastructure providers.
- Personalization and AI-processing providers, including Teeinblue, Google, Adobe and OpenAI when used for the relevant order.
- Production, fulfillment and shipping providers, which receive final production files and the order and recipient information needed to make and deliver the item.
- Payment and fraud-prevention providers, including Shopify Payments, Shop Pay, PayPal, connected banks and authentication services.
- Email, SMS, support and security providers, including Klaviyo, IONOS, Chatty and hCaptcha providers.
- Review, referral and post-purchase providers, including Loox, Trustpilot, BixGrow and AfterSell.
- Analytics, advertising and social-media companies, including Google, Meta and TikTok, subject to consent and opt-out rights.
- Business operations, cloud, accounting and professional advisors, including Microsoft, bookkeeping providers, accountants, auditors, banks, insurers, tax advisors and legal advisors.
- Government authorities, courts and other lawful recipients, where disclosure is required or reasonably necessary to protect rights, safety and security.
- Parties to a corporate transaction, subject to appropriate confidentiality and legal requirements.
- Other persons at your direction or with your consent.
Service providers and processors are contractually restricted where required from using personal information for unrelated purposes. Some recipients, such as payment providers, carriers, social-media platforms and advertising providers, may also act as independent controllers for their own processing.
14. Sale, Sharing and Targeted Advertising
We do not sell personal information for money in the ordinary sense.
However, certain U.S. privacy laws define “sale,” “sharing,” or “targeted advertising” broadly. Subject to your cookie and privacy choices, our use of advertising cookies, pixels, server-side advertising events, audience tools, and hashed matching identifiers may constitute sale or sharing of personal information or processing for targeted advertising.
The categories that may be involved are:
- identifiers and online identifiers;
- customer-record information, limited to permitted matching identifiers;
- commercial and transaction information;
- internet or network activity;
- approximate geolocation; and
- advertising or interest inferences.
The recipient categories are advertising networks, social-media platforms and analytics providers. The purposes are campaign measurement, attribution, audience creation, advertising delivery and cross-context behavioral advertising.
We do not sell or share for targeted advertising:
- customer-uploaded photos;
- generated or final artwork files;
- private personalization text;
- complete payment-card or bank-account credentials;
- precise geolocation;
- biometric identifiers; or
- sensitive personal information.
To opt out, visit Your Privacy Choices or enable GPC in a supported browser. For California consumers, we will wait at least 12 months before asking for consent to sell or share the information again. We follow any other waiting period required by applicable law.
15. International Processing and Transfers
EasyCommerce GmbH is established in Austria, while customers, production partners and service providers may be located in the United States and other countries. Personal information may therefore be accessed or processed in Austria, the United States, Canada, Singapore, Israel, India and other locations where our providers operate.
Where GDPR or another transfer law applies, we use an applicable transfer mechanism, such as:
- an adequacy decision;
- a recipient’s valid participation in the EU-U.S. Data Privacy Framework where applicable;
- the European Commission’s Standard Contractual Clauses;
- binding corporate rules; or
- another legally recognized safeguard.
You may contact us for information about an applicable transfer safeguard, subject to protection of confidential information and third-party rights.
16. GDPR Legal Bases
Where GDPR applies, we rely on the following legal bases:
- Performance of a contract or steps requested before a contract: account, checkout, order, personalization, AI-assisted image processing, payment, production, digital artwork, delivery, corrections and customer support.
- Consent, where applicable and obtained: nonessential cookies and tracking, email or SMS marketing, optional review publication, and any separate permission to use a customer image for advertising or testimonials.
- Legal obligation: tax, accounting, consumer-protection, corporate, sanctions, fraud-reporting and lawful-request obligations.
- Legitimate interests: Shop security and stability, fraud prevention, customer service, internal administration, business analytics, legal claims, and creating a privately delivered personalized artwork from an image supplied by a customer, subject to the safeguards described in this Privacy Policy.
When we rely on legitimate interests, we balance those interests against the rights and reasonable expectations of affected individuals. For photos of other people and children, relevant safeguards include limited access, a narrow production purpose, short image retention, human review, and no advertising, publication, identification or sensitive-trait inference.
17. Data Retention
We use the periods in the Notice at Collection and the following more specific rules:
- Uploaded photos and internal artwork files: no later than 90 days after full completion of the order, unless an active correction, complaint, dispute or legal claim requires limited continued retention.
- Teeinblue uploaded files: up to 90 days under its current published terms.
- Teeinblue order and personalization metadata: up to 12 months under its current published terms, unless earlier deletion is instructed or a lawful exception applies.
- Shopify order, transaction, tax and accounting records: generally 7 years from the end of the relevant calendar year where required by Austrian accounting and tax law.
- Contract and claim-related communications: generally up to 3 years after the matter is completed, and longer for an active proceeding or legal hold.
- Non-contract support inquiries: generally 12 months after final resolution.
- Marketing profiles: until opt-out, withdrawal or the information is no longer needed; minimal suppression records are retained to honor opt-outs.
- Consent and preference records: for the period relied upon and generally up to 3 years afterward where needed for compliance evidence.
- Reviews and public user content: until removed, consent is withdrawn where applicable, or the content is no longer needed, subject to legal and integrity records.
- Security and fraud records: for as long as reasonably necessary to investigate, prevent and document the relevant activity.
- Cookies and advertising identifiers: according to the duration shown in Cookie Settings or the relevant platform configuration.
At the end of the applicable period, we delete or deidentify the information unless continued retention is required by law.
18. Security
We maintain reasonable administrative, technical and organizational safeguards appropriate to the nature of the information and the systems used. Depending on the system and workflow, these safeguards include encrypted transmission, access restrictions, data minimization, account and system security, provider due diligence, contractual protections and deletion routines.
No method of transmission or storage is completely secure. We cannot guarantee absolute security, and you should use a unique password and protect access to your email and account.
19. Children
The Shop is a general-audience service intended for adults. You must be at least 18 years old to place an order or upload a photo.
We do not knowingly solicit personal information directly from children under 13. We do not process personal information for targeted advertising or sell personal information where we have actual knowledge, or willfully disregard, that the consumer is under 18. We also do not knowingly sell or share the personal information of consumers under 16 where California law requires prior opt-in consent. If we learn that a child submitted personal information directly without required parental authorization, we will take appropriate steps to delete it.
An adult customer may upload a family photo that includes a child for a privately delivered personalized product. In that situation, the information is supplied by the adult, not collected directly from the child. The adult must be the parent or legal guardian or have the necessary authorization. We process the child’s image only for the requested product and do not use it for targeted advertising, public display, identification or general model training.
20. Automated Decision-Making and Profiling
We do not use personal information to make solely automated decisions that produce legal or similarly significant effects concerning a consumer.
AI-assisted image processing creates artwork and is subject to human review before production. Advertising providers may create interest or audience profiles, subject to consent and opt-out rights, but we do not use those profiles to make decisions about employment, housing, credit, education, insurance, health care or other legally significant opportunities.
Payment and fraud-prevention providers may use automated risk tools under their own privacy notices.
Part II - U.S. State Privacy Supplement
21. Scope of This U.S. State Privacy Supplement
This Part II provides additional information for residents of states with applicable consumer privacy laws, including California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia, as well as other states whose laws apply to our processing.
The rights available to you depend on your state, our relationship with you, and whether the relevant law applies to us or to the particular information. We may honor a request voluntarily even where a statutory right does not apply. Terms such as “personal data,” “personal information,” “sale,” “sharing,” “targeted advertising,” “sensitive data,” and “consumer” have the meanings assigned by applicable law.
22. U.S. Privacy Rights
Subject to applicable law and exceptions, you may have the right to:
- confirm whether we process your personal information;
- access or know the categories and specific pieces of personal information we maintain;
- learn the categories of sources, purposes and recipients;
- correct inaccurate personal information;
- delete personal information;
- obtain a portable copy of personal information;
- opt out of sale, sharing or processing for targeted advertising;
- opt out of profiling in furtherance of decisions that produce legal or similarly significant effects;
- withdraw consent to processing of sensitive data;
- limit certain uses or disclosures of sensitive personal information;
- obtain a list of specific third parties to which we disclosed personal information where required;
- question or obtain information about certain significant profiling decisions where required;
- appeal our refusal to act on a request; and
- receive equal service and not be discriminated or retaliated against for exercising a privacy right.
These rights are subject to exceptions, including where information is needed to complete your order, process a payment, detect fraud, maintain security, comply with law, preserve legal claims, or protect another person’s rights.
23. How to Exercise U.S. Privacy Rights
You may submit a request by:
- emailing office@easy-commerce.at with the subject line “U.S. Privacy Request”; or
- using our online contact form.
For sale, sharing and targeted-advertising opt-outs, use:
https://family-present.com/pages/data-sharing-opt-out
You do not need to create a new account to submit a request. Please identify the right you wish to exercise and provide enough information for us to locate the relevant records. Depending on the request, this may include your email address, order number, approximate order date, delivery ZIP code or other information already associated with your interaction.
We will use commercially reasonable methods to verify that the requester is the consumer concerned or is authorized to act for that consumer. We do not request more information than reasonably necessary. If we cannot verify a request, we may ask for additional information or explain why we cannot fulfill it.
For California requests to know, access, delete or correct, we generally confirm receipt within 10 business days. We respond to a verified request no later than 45 calendar days after receipt. Where reasonably necessary, we may extend the response period once by an additional 45 calendar days, for a maximum of 90 calendar days from receipt, and will notify you during the initial response period and explain the reason for the extension.
We process requests to opt out of sale or sharing as soon as feasibly possible and no later than 15 business days where the CCPA applies. We do not require identity verification for an opt-out request. We may request only the information reasonably necessary to apply the request beyond the browser or device.
We generally respond to other verified requests within 45 days, subject to any shorter period or permitted extension under applicable law. We will explain any extension. Requests are ordinarily free, but applicable law may permit a reasonable fee or refusal for manifestly unfounded, excessive or repetitive requests.
24. Authorized Agents and Requests for Other Individuals
An authorized agent may submit a request where permitted by law. We may require evidence of the agent’s authority and may contact the consumer directly to confirm the request, unless the agent has a legally valid power of attorney or other exception applies.
A parent or legal guardian may act for a minor. A person requesting rights regarding an image uploaded by someone else should provide sufficient information to locate the image without requiring us to collect unnecessary identity data.
For an opt-out request submitted by an authorized agent, we do not require verification of the consumer’s identity, but we may require signed permission showing that the agent is authorized to submit the opt-out unless applicable law provides otherwise.
25. Appeals
If we deny a request and applicable law provides an appeal right, you may appeal by emailing office@easy-commerce.at with the subject line “Privacy Appeal”. Include the date of the original request and a short explanation of why you believe the decision should be reconsidered.
We generally respond to an appeal within 45 days and in all cases within the period required by applicable law. If we deny the appeal, we will provide information about how to contact the appropriate state regulator or attorney general where required.
26. Universal Opt-Out Preference Signals
Where applicable U.S. law requires, we treat a qualifying GPC signal, and any other universal opt-out preference signal we are legally required to recognize, as a request to opt out of sale, sharing and targeted advertising.
A qualifying signal applies to the browser or device sending it and to every consumer profile, including a pseudonymous profile, that we associate with that browser or device. If we know which consumer sent the signal, for example, because the consumer is logged in or the browser is associated with a customer account we also apply the opt-out to that consumer, the known account and associated account-level sale, sharing or targeted advertising as required by applicable law. We do not require additional information to honor the browser- or device-level request.
The Your Privacy Choices form applies the opt-out to the current browser or device without requiring an email address. If the form offers an optional account-level choice, you may select it and provide the email address associated with your customer account solely to request that the opt-out be extended to account-associated information.
Our privacy-choice interface displays whether the browser or device is opted out. We do not treat the absence of a signal on a later visit or another device as consent to reverse a previously recorded account-level opt-out. Deleting cookies or local storage, using another browser or device, or resetting browser settings may prevent the Shop from recognizing a device-level preference; you may submit the choice again or use GPC.
27. California Privacy Notice
This section supplements the remainder of the Privacy Policy for California residents. It is designed to address the California Consumer Privacy Act, as amended (“CCPA”), where the CCPA applies.
27.1 Categories collected and disclosed during the preceding 12 months
| California statutory category | Examples collected | Collected? | Disclosed to service providers or contractors for a business purpose? | Sold or shared to third parties? |
|---|---|---|---|---|
| A. Identifiers | Name, postal address, email, phone, IP address, cookie and device IDs, account and order IDs, hashed identifiers | Yes | Yes | Yes, limited to online identifiers and permitted matching identifiers for advertising and analytics |
| B. Customer Records information | Contact, billing, delivery and limited payment-related information described in Cal. Civ. Code § 1798.80(e) | Yes | Yes | Yes, limited to permitted matching identifiers used for advertising and analytics |
| C. Characteristics of protected classifications | Characteristics such as age, race or ethnicity may be incidentally visible in a customer-provided photo; we do not infer or classify them | Potentially, incidentally | Yes, only where necessary for image processing and fulfillment | No |
| D. Commercial information | Products, purchases, order history, cart, personalization choices, discounts and referral activity | Yes | Yes | Yes, for advertising measurement and targeted advertising |
| E. Biometric information | We do not create or use faceprints, face-geometry templates or other biometric identifiers for identification | No | No | No |
| F. Internet or other electronic network activity | Browsing, search, page, product, cart, checkout, ad and interaction data | Yes | Yes | Yes, for analytics and targeted advertising |
| G. Geolocation data | Approximate location inferred from IP address or address information; not precise GPS location for ordinary Shop use | Yes | Yes | Yes, limited to approximate location used for analytics and advertising |
| H. Sensory information | Customer-uploaded photos, artwork, review photos and other visual information | Yes | Yes | No |
| I. Professional or employment-related information | Not ordinarily requested for consumer purchases | No | No | No |
| J. Education information | Not ordinarily requested | No | No | No |
| K. Inferences | Product interests, likely preferences, marketing segments and campaign attribution | Yes | Yes | Yes, for advertising and audience purposes |
| Sensitive personal information | Account login information in combination with credentials that permit account access; payment-account credentials handled by payment providers; and information incidentally visible in a photo or voluntarily submitted that may reveal racial or ethnic origin, religious or philosophical beliefs, health, sex life or sexual orientation | Potentially | Yes, only for permitted service, security and legal purposes | No |
The categories of sources and purposes are described in Sections 3 and 4. The categories of recipients are described in Section 13.
During the preceding 12 months, we sold or shared categories A, B, D, F, G and K with advertising networks, analytics providers and social-media platforms for measurement, attribution, audience creation and cross-context behavioral advertising. We did not receive money in exchange for this information.
For the preceding 12 months, we disclosed the categories of personal information identified as “Yes” in the business-purpose column to the relevant categories of service providers and contractors for hosting, order processing, personalization, payment, fraud prevention, production, delivery, support, communications, analytics, accounting, security and legal compliance.
We do not have actual knowledge that we sell or share the personal information of consumers under 16 years of age. Customer-uploaded photos that include children are not used for sale, sharing or targeted advertising.
We use and disclose sensitive personal information only to perform the services or provide the goods reasonably expected by a consumer who requests them, process payments, maintain security, prevent fraud, provide related customer support, comply with law, and perform other purposes permitted by applicable CCPA regulations, in each case only where reasonably necessary and proportionate. We do not use sensitive personal information to infer characteristics about a consumer. Accordingly, we do not currently use or disclose sensitive personal information in a manner that is subject to a separate California right to limit. If our practices change, we will provide the required notice and method before beginning the new processing.
27.2 California rights
Subject to applicable exceptions, California residents may request:
- the categories and specific pieces of personal information collected;
- categories of sources;
- business or commercial purposes;
- categories of third parties to which information was disclosed, sold or shared;
- deletion;
- correction;
- opt-out of sale or sharing;
- limitation of non-permitted sensitive-personal-information use, if any; and
- freedom from discrimination or retaliation for exercising CCPA rights.
Instructions for submitting and verifying a request are in Sections 23 and 24. To opt out of sale or sharing, use Your Privacy Choices or GPC.
27.3 Notice of right to opt out of sale or sharing
California law may treat certain advertising-related disclosures as sale or sharing. You have the right to direct us not to sell or share your personal information. Use Your Privacy Choices or send a qualifying GPC signal.
Selecting Opt out in Your Privacy Choices applies the request to the current browser or device; no email address or customer account is required. To extend the request to a related customer account, you may select the optional account choice and enter the email address associated with that account. Information submitted for an opt-out request is used only to process that request. A GPC signal received while you are known to us is applied as described in Section 26.
27.4 Financial incentives
We do not discriminate against a consumer for exercising a CCPA right. We may offer a lawful discount, reward, referral benefit or other program reasonably related to the value of the information involved. If a program qualifies as a financial incentive or price or service difference under California law, we will provide a separate program-specific notice before enrollment and obtain any required opt-in consent.
27.5 California “Shine the Light”
California Civil Code § 1798.83 may permit certain California customers to request information about disclosure of personal information to third parties for those third parties’ own direct-marketing purposes. Sections 11 and 14 describe our advertising-related disclosures and privacy choices. A qualifying request may be sent to office@easy-commerce.at with the subject line “California Shine the Light Request.”
27.6 California online-tracking disclosures
As described in Section 11, advertising and analytics providers may collect online identifiers and browsing, product, cart, checkout and purchase-event information over time and across websites or online services. Section 11.7 explains our response to browser DNT and GPC signals. You may review or request correction of information as described in Sections 22 and 23. Material changes to these practices will be handled as described in Section 32.
28. Additional State-Specific Information
28.1 Sensitive data
We do not request sensitive data for the purpose of inferring or profiling sensitive characteristics. A photo or personalization text may nevertheless incidentally contain information treated as sensitive under certain state laws. We process that content only as reasonably necessary to provide or support the personalized product expressly requested by the customer and for other purposes permitted by law. We rely on a requested-product exception or another lawful basis only where applicable. If separate consent is legally required for particular processing and no exception applies, uploading a file alone does not provide that consent; we may request additional authorization, request alternative content or decline to process the affected content. Sensitive data is not sold or used for targeted advertising.
Where processing is based on consent, you may withdraw that consent for future processing by contacting us. Withdrawal may prevent us from completing a requested personalized product if the relevant information is necessary for that product.
28.2 Connecticut
For Connecticut consumers, sensitive data may include personal data revealing racial or ethnic origin, religious beliefs, health conditions, disability or treatment, sexual activity or orientation, status as nonbinary or transgender, citizenship or immigration status; consumer health, genetic, biometric or neural data or information derived from genetic or biometric data; precise geolocation; specified financial-account or government-identification data; and personal data collected from a person we know, or willfully disregard, is a child. A family or baby photo may incidentally contain some of this information even though we do not infer or classify it.
We process customer-uploaded photos only to create, review, produce, deliver and support the requested product. We do not intentionally infer or classify sensitive characteristics from those photos. Connecticut generally requires affirmative opt-in consent before processing sensitive data, subject to statutory exceptions including processing necessary to provide a product or perform a contract specifically requested by the consumer. Where separate consent is legally required for particular processing and no exception applies, uploading a file or accepting general terms alone does not provide that consent; we may request additional authorization, request alternative content or decline to process the affected content. We do not sell images or use them for targeted advertising. We conduct data-protection and impact assessments for processing that presents a heightened risk of harm where required. We do not collect, use, disclose or sell personal data for the purpose of training large language models or other general-purpose AI models. Connecticut consumers may exercise the rights and appeal process described above, including rights concerning inferences, legally significant profiling and third-party disclosures where applicable.
28.3 Oregon and Minnesota
Where required, Oregon and Minnesota residents may request a list of specific third parties to which we disclosed their personal information. Minnesota residents may also have rights concerning profiling decisions that produce legal or similarly significant effects. We do not currently use profiling to make such decisions.
28.4 Maryland
We do not sell sensitive data. We limit collection to information reasonably necessary and proportionate to provide or maintain the requested product or service and for other purposes permitted by applicable law.
28.5 Nevada
Nevada residents may submit a verified request to opt out of a covered sale under Nevada law by using Your Privacy Choices or by emailing our designated request address, office@easy-commerce.at. We respond within 60 days, subject to a permitted 30-day extension. We do not sell covered information for monetary consideration to a person for that person to license or sell to additional persons.
The categories of information collected and recipient categories are described in Sections 2 and 13. Sections 11 and 14 describe third-party collection over time and across websites, targeted advertising and our response to DNT and GPC. Sections 22 and 23 explain how to review or request changes to covered information, and Section 32 explains how we communicate material changes.
28.6 Rhode Island
For purposes of Rhode Island’s disclosure requirement, the third parties to which we have sold or may sell personally identifiable information, as “sale” is defined by applicable law, are the advertising and analytics companies described in Sections 11 and 14: Google Ireland Limited and Google LLC; Meta Platforms Ireland Limited and Meta Platforms, Inc.; and TikTok Technology Limited and TikTok Inc. This list is current as of the Last updated date. We do not sell customer-uploaded photos, artwork files, private personalization text, payment-card information or sensitive personal information.
28.7 Other state rights
Residents of Colorado, Delaware, Florida, Indiana, Iowa, Kentucky, Montana, Nebraska, New Hampshire, New Jersey, Tennessee, Texas, Utah, Virginia and other states with applicable privacy laws may exercise the rights available under their state law through the methods in Section 23. Where required, we provide an appeal, recognize qualifying universal opt-out signals and do not discriminate for exercise of a right. Sensitive-data processing is limited as described in Section 28.1.
29. Consumer Health Data Privacy Policy
This section is our Consumer Health Data Privacy Policy for purposes of the Washington My Health My Data Act, Nevada’s consumer health data law, Connecticut’s consumer health data provisions and similar state laws, to the extent those laws apply.
29.1 We are not a health service
familypresent is not a health-care provider or health service. We do not request medical records, diagnoses, genetic information or health-service information for ordinary purchases, and we do not use photos, personalization text or browsing activity to infer a person’s health status, pregnancy, disability, diagnosis or treatment.
Please do not upload medical records, genetic information, intimate images or other unnecessary health information.
29.2 Categories of consumer health data that may be collected
A customer may voluntarily upload a photo or provide personalization text that incidentally identifies or reveals information about the customer’s or another person’s physical or mental health, disability, pregnancy or other health status. If that occurs, the possible consumer health data is:
- the health-related information visibly contained in the submitted image;
- health-related wording voluntarily included in personalization instructions or support communications; and
- an uploaded image of a face or other physical characteristic to the extent applicable consumer-health law treats that image as biometric data from which an identifier template could be extracted, even though we do not create or use such a template; and
- the final artwork to the extent it retains the submitted health-related information.
We do not derive additional health data, create health profiles, identify a person through biometric analysis, or create or maintain faceprints, face-geometry templates or other biometric identifier templates from this information.
29.3 Sources
The source is the adult customer who uploads the image or submits the text, or a person authorized to act for the individual concerned. We do not purchase consumer health data from data brokers.
29.4 Purposes of collection and use
We collect and use this information only:
- to create, preview, edit, produce and deliver the personalized product requested by the consumer;
- to provide a correction, replacement or customer support requested by the consumer;
- to maintain security, prevent fraud, comply with law or establish and defend a legal claim; and
- for another purpose to which the consumer provides a separate legally valid consent.
We do not use browsing, product, cart or purchase events to infer a person’s health status. If a URL, product label or event could reasonably identify a person’s health status, we do not disclose that health-related element to an advertising platform or use it for targeted advertising.
29.5 Categories disclosed, categories shared and recipients
Under the Washington My Health My Data Act, disclosure to a processor acting on our instructions to provide the requested product is not “sharing.” In the current workflow, we do not share consumer health data as that term is defined by that Act. We disclose the following information only to processors acting on our documented instructions and consistently with the disclosed purpose. We do not make disclosures outside the processor or requested-service exceptions described above. If a future disclosure would require separate consent, we will not make it unless and until a legally valid consent mechanism has been implemented.
To provide the requested product, we may disclose the following categories of consumer health data to the identified recipient categories:
| Categories disclosed to processors | Categories of recipients and current recipients | Purpose |
|---|---|---|
| Uploaded image, relevant crop, personalization text, preview and related health information visible or stated in that content | Personalization provider: Teeinblue | Upload, preview, personalization, order association and secure transfer |
| Uploaded image or necessary image area, design or correction instruction, and generated result | AI and image-editing providers used for the relevant order: Google Gemini and, where needed, Adobe or OpenAI business services | Requested artistic transformation, quality control and correction |
| Image or relevant text submitted for an active correction or complaint | Limited cloud, email and customer-support providers used for the request | Respond to and resolve the consumer’s request |
| Final production artwork, which may retain visible health-related information | Production and fulfillment partner | Produce the personalized item; the partner does not receive the original raw photo |
We do not share consumer health data with advertising networks, social-media platforms or data brokers. We do not sell consumer health data. We do not share consumer health data with any corporate affiliate; EasyCommerce GmbH currently has no affiliate that receives such data for an independent purpose.
29.6 Consent and requested-product processing
When consumer health data relates to the customer who requests the personalized product, we collect and disclose it to processors only to the extent reasonably necessary to provide that requested product or service and otherwise as permitted by applicable law. If the information relates to another person, the uploader must be legally authorized to act for that person or must have any express consent required by applicable law. Mere acceptance of general terms or selection of a file is not treated as a substitute for separate consent where separate consent is legally required. We may request evidence of authority, request alternative content or decline to process the affected content. We do not use consumer health data for an unrelated purpose.
We do not share consumer health data where separate consent would be required. We do not sell consumer health data.
Do not upload consumer health data about another person unless that person has expressly consented or you are the person’s legally authorized representative. We may reject the upload or require consent directly from the person concerned or the person’s legally authorized representative.
We will not collect, use or share additional categories of consumer health data, or use existing consumer health data for a materially different purpose, without first updating this notice and obtaining consent where required.
29.7 Consumer health data rights
Subject to applicable law, you may:
- confirm whether we collect, share or sell consumer health data about you;
- access the consumer health data;
- review the consumer health data and request correction of inaccurate information;
- receive a list of all third parties and affiliates with which it was shared or sold, including an active email address or other online contact mechanism for each;
- withdraw consent to future collection or sharing; and
- request deletion from our systems and notification of the request to relevant processors and other recipients.
Submit a request to office@easy-commerce.at with the subject line “Consumer Health Data Request” or use our contact form. We will authenticate and respond to the request within the period required by applicable law. If we deny the request, you may appeal as described in Section 25.
For Washington consumer health data, we notify all affiliates, processors, contractors and other third parties that received the data of a deletion request, and deletion from archived or backup systems will be completed within six months after authenticating the request. For Nevada consumer health data, we generally act on a deletion request within 30 days after authentication; deletion from archived or backup systems may take up to two years where Nevada law permits. We will not use archived information subject to a pending deletion request for another purpose.
29.8 Cross-site collection, changes and effective date
Analytics and advertising providers may collect the general online-activity information described in Section 11 over time and across websites or online services. We do not authorize those providers to collect consumer health data, private image content, personalization text or health-related inferences for those purposes. Section 11.7 explains our response to DNT and GPC signals.
The effective date of this Consumer Health Data Privacy Policy is July 29, 2026. If we make a material change, we will notify affected consumers through the Shop, email or another appropriate direct method where required. We will not collect, use or share an additional category of consumer health data, add a recipient where consent is required, or use consumer health data for a materially different purpose unless and until any legally required disclosure and affirmative-consent mechanism has been implemented.
30. Rights of People Depicted in a Photo or Identified by Another Customer
If you appear in a photo, are identified as a gift or delivery recipient, or are otherwise described in information provided by another customer, we obtained the information from that customer, not from you.
For a depicted person, we ordinarily process only the person’s visual representation and any personalization text supplied by the customer. We generally do not know the person’s identity or contact details and do not attempt to identify the person. The purposes, recipients and retention periods are described in Sections 7 and 17.
For a gift or delivery recipient, we may process name, delivery address, email address, gift message and product or delivery information to provide the requested gift or shipment.
Because we generally lack direct contact details and should not collect additional information merely to send a notice, we make this Privacy Policy publicly available. Where GDPR Article 14 applies, this section provides information to persons whose information was obtained from another person. If we know the person’s contact details and direct notice is reasonably possible and legally required, we will provide it.
You may exercise applicable rights by contacting us. We may require an order number, approximate order date, uploader information or copy of the relevant image to locate the record securely.
31. GDPR and European Privacy Rights
Where GDPR applies, you may have the right to:
- access personal data;
- correct inaccurate or complete incomplete data;
- delete data;
- restrict processing;
- receive certain data in a portable format;
- object to processing based on legitimate interests;
- object at any time to direct marketing;
- withdraw consent for the future; and
- lodge a complaint with a supervisory authority.
Withdrawal does not affect the lawfulness of processing completed before withdrawal. A request may be subject to legal limitations and exemptions.
You may contact the Austrian supervisory authority:
Austrian Data Protection Authority
Barichgasse 40–42
1030 Vienna
Austria
https://www.dsb.gv.at
You may also contact the competent authority at your habitual residence, place of work or place of the alleged infringement where applicable.
32. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our services, providers, technology, practices or legal obligations. The “Last updated” date shows when the current version was issued.
If a change is material, we will provide additional notice where required, such as through the Shop, an account notice or email. We will obtain consent before using personal information for a materially different purpose where required by law.
33. Contact
Questions, complaints and privacy requests may be directed to:
EasyCommerce GmbH
Delugstraße 7/2/3
1190 Vienna
Austria
Privacy: office@easy-commerce.at
Customer support: support@family-present.com
Online form: https://family-present.com/pages/contact
Privacy choices: https://family-present.com/pages/data-sharing-opt-out
100,000+ Happy Customers
Crafted with love – since day one.












