Privacy Policy
Privacy Policy
1. About this policy, and who is responsible for your information
BarklyPaw is the brand name of this store. The seller of record, and the business legally responsible for the personal information collected here, is Stickwall, a business registered in Israel under registration number 314619487. In this policy, "we", "us", and "our" mean Stickwall operating the BarklyPaw store. Under United States state privacy laws we act as the "business" or "controller" for the information described below. Our full registered business address is available by email on request.
This policy is linked from the footer of every page of this store and from our checkout, and it serves as our notice at collection: it tells you what we collect and why before you give it to us.
What we sell, and where. We sell one product, the BarklyPaw Dog Cooling Mat. We price in US dollars and ship to the United States, Canada, Israel, and Australia. We do not currently offer or sell into the European Union or the United Kingdom, so this policy is written around United States federal and state privacy law, with the additional sections for Canada, Australia, and Israel further down. If that changes, we will publish an updated policy before we start selling there.
What this policy covers: our online store, product pages, cart and checkout; order confirmations, shipping notifications, and other transactional email; our order tracking page, powered by a third party tracking service called Track123; email you send to our support address and our replies; and advertising we run on Meta, Google, and Pinterest, including the measurement data those ads send back to us.
What this policy does not cover. We are not responsible for how other companies handle information you give them directly on their own properties, including PayPal's own payment pages, the Facebook, Instagram, Google, and Pinterest platforms themselves, shipping carrier websites, and any site you reach by clicking a link from ours. Those companies act as independent businesses for their own purposes and publish their own privacy policies.
How to reach us, stated plainly. Support is email only, at mybarklypaw@gmail.com. We do not operate a phone line, a call center, a live chat window, or a support ticket portal, and we will not pretend otherwise. Email is the way to reach us for orders, returns, and every privacy request described here.
2. The personal information we collect, and where each piece comes from
Below is every category of personal information we actually handle, using the category names from the California Consumer Privacy Act so the list can be compared against the law directly. We do not ask for information we do not need to sell you a dog mat and get it to your door.
A. Identifiers. Your first and last name, shipping address, billing address, email address, and a phone number if you enter one. Also an order number, a customer or session identifier assigned by our store platform, your device's IP address, and cookie or advertising identifiers. Most of this comes from you at checkout; IP address and identifiers come automatically from your browser. Name, shipping address, and email are required to buy, because we cannot ship a mat or confirm an order without them. A phone number is optional and is used only so a carrier can reach you about a delivery.
B. Customer records information. The combination of name, address, phone number, and payment related details that make up your order record, including the last four digits of your card, the card brand, and the billing name and country returned to us by the payment processor. We never receive your full card number. See section 3.
C. Commercial information. What you bought, the size and color, the quantity, the price paid in USD, the fact that the free second mat was added, order date and status, shipment and delivery status, tracking number, returns, refunds, and chargeback records.
D. Internet and other electronic network activity. Pages you viewed and in what order, referring URL, the ad or link that brought you here, store search terms, items added to cart, checkout steps started and completed or abandoned, time on page, scroll and click events, browser type and version, operating system, device type, screen size, and language settings.
E. Approximate location. A rough location, usually a city, region, and country, derived from your IP address, used for currency, shipping eligibility, fraud checks, and ad reporting. We do not read your device's GPS, Bluetooth, or Wi-Fi location sensors, and we do not collect the precise geolocation that California law defines. The shipping address you type in is obviously a precise street address; we collect it because you asked us to deliver a parcel to it, and we use it for that, plus tax, fraud, and record keeping.
F. Communications with us. The full content of emails you send to our support address, including your email address, subject line, anything you write about your order or your dog, and any photos or attachments, for example a picture of a mat that arrived damaged. Our support mailbox is hosted by Google, so Google stores that email on our behalf as our email provider. We use photos only to assess your claim. We do not publish them, use them in advertising, or share them outside the people handling your case, unless you separately tell us in writing that we may.
G. Inferences. Simple, order driven inferences such as bought a large mat, started checkout but did not finish, repeat customer, or opened our marketing email. Meta, Google, and Pinterest build their own interest and audience profiles about their users, partly from signals our tags send them. Those profiles live on their systems, not ours, and section 7 explains how to stop it.
H. Categories we do not collect. We do not collect government identification numbers such as Social Security, driver's license, or passport numbers; financial account login credentials; biometric information; genetic data; health, medical, or insurance information about you; racial, ethnic, religious, or philosophical information; union membership; sexual orientation or sex life information; precise device geolocation; employment, professional, or education records; or the contents of your private messages on other platforms. If a form or an email ever appears to ask you for any of these, treat it as fraud and contact us.
Information about your dog. Some customers tell us their dog's breed, weight, or age, usually to get help picking a size. That is information about an animal, not personal information about a human being, and no US privacy law treats it as sensitive. We use it to answer your question and nothing else. It is not veterinary or medical advice, because the mat is a comfort product and not a medical or veterinary device.
3. Payment information and sensitive data: what we never receive
We never see your full card number. Payments are processed by third party providers, currently Shopify Payments and PayPal. Your card or account credentials go from your browser to that provider over an encrypted connection, and they handle card data under the Payment Card Industry Data Security Standard. Your full card number, your card security code, and your PayPal password never reach our systems and are never stored by us. We could not disclose them even if asked, because we do not have them.
What we do get back: the last four digits and card brand, so we can match a payment to an order and help with a refund; the billing name, country, and sometimes postal code; a payment status, transaction reference, and the amount in USD; and a fraud or risk indicator generated by the processor's automated screening.
Automated fraud screening. Our store platform and payment processors run automated checks on orders, comparing signals such as IP address, address match, and order patterns, to flag likely fraudulent transactions. If an order is flagged, a human being looks at it before anything is canceled. We do not use automated decision making that produces legal or similarly significant effects on you, and we do not profile you for credit, insurance, housing, employment, or any other consequential decision.
Sensitive personal information. California and several other states define a narrow category of sensitive personal information. We do not collect it, we do not use it to infer characteristics about you, and we do not sell or share it. Because we hold none, there is nothing for us to limit under the California right to limit the use of sensitive personal information. That right is still listed in section 8 for completeness, and if our practices ever change we will update this policy first and provide a working limitation mechanism. For Texas customers specifically: we do not sell sensitive personal data and we do not sell biometric personal data.
A security note we would rather say out loud. We will never email you asking for your full card number, your card security code, your bank details, a password, or a one time code. Any message that does is not from us. Our only customer service address is mybarklypaw@gmail.com. If you receive order email from an address you do not recognize, forward it to us and we will confirm whether it was genuinely ours.
4. Why we use your information
- To sell you the product and fulfill the order: taking and confirming your order, applying the Buy One Get One Free offer, taking payment, packing, shipping, customs and import paperwork, delivery, and tracking.
- To communicate about your order: confirmations, shipping and delivery updates, delay notices, and answering your emails.
- To handle returns, refunds, and fault claims, including our voluntary 30 day window and any statutory rights on top of it.
- To prevent fraud, abuse, and loss, including screening suspicious orders, investigating chargebacks, and defending disputes.
- To keep the store working: hosting, page loading, cart function, currency and shipping country logic, bug fixing, and security monitoring.
- To measure and improve, understanding at an aggregate level which pages, sizes, colors, and prices work, and where checkouts break.
- To advertise: measuring which ads produced sales, avoiding showing you an ad for something you already bought, and the audience work described in section 5.
- To send marketing email, only if you asked for it. See section 12.
- To comply with law and keep required records, including tax, accounting, consumer protection, and customs rules, and to respond to lawful requests.
Our basis for processing. United States law generally does not require us to name a legal basis for each use, but you are entitled to know why we think we are allowed to do this. Order, shipping, and payment data are necessary to perform our contract with you. Security, debugging, fraud prevention, and service provider work are necessary for our legitimate business operations. Tax, bookkeeping, and customs records are a legal obligation. Non essential cookies and tags, targeted advertising, and marketing email run with your consent or subject to your opt out, as described in sections 7 and 11.
Purpose limitation. We will not use your personal information for a materially different, unrelated, or incompatible purpose without telling you first and, where the law requires it, getting your consent. We do not sell your data to data brokers, we do not build a profile of you for anyone else's commercial use, and we do not buy extra information about you from third party data vendors.
5. Cookies, pixels, tags, and similar technologies
A cookie is a small file stored by your browser. A pixel or tag is a small piece of code that fires when a page loads or when you take an action, and reports it back to a company. We use all three, plus a server to server method described below.
The categories we use. Strictly necessary cookies keep your cart and session, route your traffic, remember your currency and country, protect against fraud, and make checkout work, so they are not optional. Functional cookies remember preferences. Analytics cookies count page views, sessions, add to carts, and completed checkouts, so we can tell whether a page works. Advertising and targeting tags are the Meta pixel, Google tags, and the Pinterest tag described next, and they are the ones you can opt out of.
The Meta pixel and the Meta Conversions API. We advertise on Facebook and Instagram, so we run both the browser side Meta pixel and the server side Meta Conversions API. They report the same events twice on purpose, once from your browser and once from a server, with a shared event ID so Meta can remove the duplicate. What gets sent:
- Event names and details: page view, view content, add to cart, initiate checkout, purchase, plus the product, size and color, order value in USD, currency, and the order or event ID.
- Browser and device signals from the pixel: IP address, user agent, referring page, page URL, and Meta's own advertising cookies if your browser has them.
- Customer matching data from the Conversions API: your email address, your phone number if you gave one, your first and last name, and your city, state, postal code, and country. These are hashed before they are sent, meaning converted into a scrambled string by a one way function. We do not send Meta a plain text list of our customers.
Being honest about what hashing does and does not do: Meta does not read your email address off the wire, but Meta can hash the addresses of its own users the same way and compare, which is how the match is made. So the practical effect is that Meta can often connect a purchase on our store to a Facebook or Instagram account. If you are not comfortable with that, section 7 tells you how to stop it, and opting out does not affect your order, your price, or your rights in any way.
Google and Pinterest tags. We also operate Google advertising and measurement tags and a Pinterest tag. These send similar signals: page views, add to cart and purchase events, order value and currency, a conversion ID, your IP address, user agent, and the platform's own advertising cookies. Depending on configuration, Google's conversion tagging can also receive a hashed email address for conversion matching.
Other third party technologies on our pages. Our ecommerce platform, Shopify, sets essential and analytics cookies as part of running the store and checkout. PayPal sets its own cookies when its payment button or page is loaded. Track123 powers our order tracking page and, when you look up an order there, processes your tracking number, your order or email identifier, and carrier and delivery status, and may set its own cookies.
Your controls. Your browser can block or delete cookies, and most browsers offer tracking protection or private browsing that limits third party advertising cookies. Blocking strictly necessary cookies will break the cart and checkout, which is how browsers and stores work rather than a penalty we impose. Section 11 covers browser signals and platform level opt outs, and section 7 covers the email route, which is the one that reaches our server side events as well.
6. How we share information
We disclose personal information only to the categories of recipients listed here, only for the purposes listed, and, where a vendor offers them, under contracts that require the vendor to use the information only to perform services for us and prohibit them from selling it or using it for their own unrelated purposes. Not every vendor we use offers such a contract on the plan we are on, and we would rather say so than imply a protection that is not in place. We do not post your information publicly and we do not hand it to anyone who simply asks.
- Ecommerce platform and hosting (Shopify): effectively everything, because it runs the storefront, cart, checkout, order records, and customer records.
- Payment processors (Shopify Payments and PayPal): your payment credentials, which they receive directly from you, plus order amount, currency, billing details, and fraud signals. These companies also act as independent controllers for their own legal, anti money laundering, and fraud obligations.
- Our fulfillment partner, shipping carriers, freight forwarders, and customs brokers: recipient name, shipping address, email address, and phone number if provided, parcel weight and contents description, and the commercial invoice or customs declaration data that international shipping legally requires. Because our goods ship internationally, this includes disclosure to customs and border authorities in the destination country. Our fulfillment partner is located outside the countries we ship to.
- Order tracking provider (Track123): tracking numbers, carrier identity, delivery scan events and status, and the identifier used to look up your order.
- Email provider and email sending tools: our support mailbox is hosted by Google, so the content of your emails to us and our replies is stored on Google's systems. The tools that send order and, where applicable, marketing email receive your email address, name, and the order details needed to compose the message, plus delivery, open, and click data.
- Cloud infrastructure and serverless functions that we use to transmit order events to advertising platforms. These receive the order and hashed customer matching data described in section 5.
- Advertising and analytics platforms (Meta, Google, Pinterest): the event and matching data described in section 5. These platforms act as independent businesses for their own advertising purposes, which is why the sale and sharing analysis in section 7 applies to them.
- Professional advisors such as accountants, bookkeepers, and lawyers, on a need to know basis and under duties of confidentiality.
- Authorities, courts, and law enforcement, where we are legally required to disclose, or where disclosure is necessary to establish, exercise, or defend legal claims, or to protect someone's safety. We will not volunteer your data without a valid legal basis, and where we are permitted to tell you about a request, we will.
- A buyer or successor, if the business or its assets are sold, merged, or reorganized. The buyer would be bound by this policy for information collected under it, and we would post notice here.
What we do not do. We do not rent, trade, or sell customer lists to data brokers or marketing companies. We do not disclose your personal information to third parties for their own direct marketing, which is also our answer to California's Shine the Light law, Civil Code section 1798.83: we have no such disclosures to report. We do not share your information with other pet brands or partner stores.
Categories disclosed in the last 12 months. For CCPA purposes: identifiers, customer records information, commercial information, internet or other electronic network activity information, approximate location, communications content, and inferences. We disclosed no sensitive personal information, because we collect none.
7. We do not sell your information for money, and what "sharing" means
No sale for money. We do not sell your personal information for money and we have never done so. No money changes hands for your data at any point in our business.
The honest part about the legal definitions. California's CCPA as amended defines "sale" more broadly than a cash transaction, covering disclosure to a third party for other valuable consideration, and separately defines "share" to mean disclosure for cross context behavioral advertising, meaning targeting ads to you based on your activity across sites you do not own. Other states use "targeted advertising" for the same idea. Applying those definitions honestly to what we do: our use of the Meta pixel and Conversions API, the Google tags, and the Pinterest tag can qualify as sharing for cross context behavioral advertising, and some regulators would treat parts of it as a sale under the broad definition. Rather than argue the point in fine print, we treat it as covered and give you a real opt out. Everything we publish, including our Terms of Service, says the same thing.
- Categories shared for cross context behavioral advertising: identifiers, including hashed email address and advertising cookie identifiers; internet or other electronic network activity information; commercial information, meaning what you viewed, added to cart, or purchased and its value; and approximate location derived from IP address.
- Recipients: Meta Platforms, Google, and Pinterest.
- Sensitive personal information shared or sold: none.
- Personal information of consumers we know to be under 16 sold or shared: none.
Your right to opt out. You may direct us to stop selling or sharing your personal information and to stop processing it for targeted advertising, at any time, for any reason. You do not have to give a reason and you do not have to be a customer.
- The route that always works: email us at mybarklypaw@gmail.com with the subject line Do Not Sell or Share My Personal Information, and tell us the email address you use with us. We suppress it at our end, remove you from our advertising audiences, and stop sending both browser side and server side advertising events tied to you. We action it and confirm.
- Browser controls. Your browser's tracking protection, or a cookie or privacy control shown on our store, will stop advertising tags loading on that device. See section 11 for what a browser level signal can and cannot do.
We do not require you to create an account or verify your identity to submit an opt out, because the law does not permit that and it would be an unfair obstacle.
What an opt out does and does not do. It stops us sending your future events to advertising platforms and removes you from our audiences. It does not stop you seeing ads; you will see less relevant ones. It does not reach back and erase data those platforms already hold in their own right, and we will not pretend we can delete something sitting in Meta's or Google's systems as their data. We pass a deletion or opt out signal to a platform where the platform provides a mechanism, and we tell you honestly when one does not. It does not affect essential order emails, which are not marketing, and it has no effect at all on your prices, your Buy One Get One Free offer, your shipping, or your return rights.
8. Your California privacy rights
This section applies to California residents. Every right listed is available at no charge. Residents of other states should read section 10, and in practice we extend most of these protections to all US customers because running two standards would be more trouble than it is worth.
- Right to know the categories of personal information we collected, the sources, our purposes for collecting, selling, or sharing it, and the categories of third parties we disclosed it to.
- Right to access the specific pieces of personal information we hold about you, subject to the verification in section 9 and narrow legal exceptions such as information whose disclosure would create a security risk.
- Right to delete the personal information we collected from you, and we will direct our service providers to do the same.
- Right to correct inaccurate personal information. Order addresses, name spellings, and email addresses are the usual cases and we fix them promptly.
- Right to data portability, in a portable, readily usable electronic format. We provide CSV or JSON by email.
- Right to opt out of sale or sharing, including cross context behavioral advertising. See section 7.
- Right to limit the use of sensitive personal information. Listed for completeness. We collect none, so there is nothing to limit today.
- Right to non discrimination and non retaliation. Exercising any of these rights will never cause us to deny you goods or services, charge you a different price, apply a different offer, give you a lower level of service, refuse a return, or hint that any of those might happen. We operate no loyalty or financial incentive program, so there are no incentive terms to disclose.
Limits on deletion, stated fairly. The law lets a business keep certain information despite a deletion request. We rely on these only where they genuinely apply, and we tell you specifically which one we used rather than sending a vague refusal: to complete a transaction you asked for, including a mat still in transit or a refund in progress; to keep tax, accounting, and customs records we are legally required to retain, which is the most common reason a completed order record survives; to detect and prevent fraud and maintain security; to exercise or defend legal claims or comply with a legal obligation; and for internal uses reasonably aligned with your expectations. Where an exception covers part of your data, we still delete the rest.
Metrics. California requires businesses handling personal information of ten million or more consumers a year to publish request metrics. We are far below that threshold, so we do not publish metrics. We will start if we ever cross it.
9. How to submit a privacy request, and how we handle it
How to submit. Email mybarklypaw@gmail.com with the request type in the subject line, for example "Access request", "Delete my data", "Correct my data", "Portability request", or "Do Not Sell or Share My Personal Information". Tell us what you want and which email address you used to order. Email is the only channel we operate, so there is no phone number or web form to point you to.
How we verify who you are. We verify because handing your order history to a stranger would be worse than a slow response, and we ask for the minimum. For a request about orders: the email address used on the order, plus the order number or approximate order date, plus the shipping postal code or the last four digits of the card. Two matching data points are usually enough. For a request from someone with no order history: the email address itself, so we can search for it and either produce what we hold or confirm we hold nothing. For opt out requests we do not verify anything, as the law requires. We will not ask you for a government ID, a Social Security number, a photo of yourself, or your card number to prove identity, and you should refuse if anyone claiming to be us does. Information sent purely for verification is used only for that and deleted afterward, aside from a minimal log that the request happened.
If we cannot verify you, we tell you why in plain language and give you one clear chance to provide something else. If we still cannot, we decline the access or deletion request and explain why. We still process any opt out, because that needs no verification.
Authorized agents. You may use one. We will ask the agent for written permission signed by you and may contact you to confirm. If the agent holds a valid power of attorney we will not ask you separately. We do not charge for agent submitted requests.
Timing, stated as commitments we can keep. We are a small team on email, so here is what we actually promise rather than a corporate service level we would miss. We aim to acknowledge a request within 10 business days and to respond substantively within 45 calendar days. If a request is unusually complex we may take up to 45 additional days, and we will tell you within the first 45 days that we are doing so and why. In practice most requests are answered in a couple of business days. If we are ever late, write again and we will treat it as urgent.
Fees and frequency. Requests are free. The law lets a business refuse or charge for a manifestly unfounded or excessive request, particularly a repetitive one. If we ever intend to rely on that, we will explain why first and give you a chance to narrow the request. You may make a free access or portability request twice in a 12 month period; deletion, correction, and opt out requests are not capped.
10. Your rights in other states
Several states have comprehensive privacy laws giving residents a similar set of rights. If you live in one of them, you may generally ask us to confirm whether we process your personal data and access it; correct inaccuracies; delete it, subject to the same legal record keeping exceptions in section 8; obtain a copy in a portable format; and opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions producing legal or similarly significant effects. We do not carry out that kind of profiling at all.
- Virginia, Colorado, Connecticut, and Texas. Full rights as above. We aim to respond within 45 days, extendable once by 45 days. You may appeal a refusal, and we will respond to an appeal within 60 days, telling you how to contact your state Attorney General if we deny it.
- Utah. Rights to confirm, access, delete, obtain a copy, and opt out of targeted advertising and sale. Utah's law includes no correction right and no appeal process, but we accept both anyway, because refusing would be petty.
- Nevada. Nevada residents may direct us not to sell certain covered information. We do not sell it for money, and we will still record and honor your request.
- Other states. More states are bringing similar laws into force. Rather than track each one in fine print, we extend the rights in this section and in section 8 to every United States customer, whether or not your state has passed a law yet.
Appeals. If we refuse a request, our reply will say so clearly, give the reason, and tell you how to appeal. To appeal, reply with the word "Appeal" and anything you want us to consider. We will look at it again with fresh eyes and explain the outcome in writing.
Consent for sensitive data. Virginia, Colorado, Connecticut, and Texas require opt in consent before processing sensitive data. We do not process sensitive data at all, so we rely on no such consent, and we will not start without asking you first.
11. Do Not Track, Global Privacy Control, and your advertising choices
Do Not Track. Some browsers send a Do Not Track header. The industry never agreed a common standard for it, and it has largely been superseded by Global Privacy Control. California law requires us to say plainly how we respond, so: we do not respond to DNT headers.
Global Privacy Control. GPC is a signal your browser or an extension can send telling every site not to sell or share your personal information, and several states require businesses to treat it as a valid opt out. We are bringing our advertising and analytics tags behind an automatic control that reads that signal. Until we can confirm on this page that it is live for every tag on this store, we do not want you relying on a browser signal alone. Two things are true regardless of that work, and you should know both:
- A browser signal only reaches your browser and device. It does not follow you to your phone or another computer, and you would need to enable it in each.
- A browser signal cannot stop server side events. Our Meta Conversions API purchase event is sent from a server, not from your browser, so no browser setting can suppress it.
So use the email route in section 7 if you want a durable, complete opt out. An email opt out is identity level: we suppress your record, take you out of our audiences, and stop both browser side and server side events tied to you. It is the only mechanism that covers everything, and we would rather tell you that than let you believe a browser toggle has done more than it can.
Platform level advertising controls. These sit outside our systems and are the most effective way to limit what those companies do with data about you generally: Meta's ad preferences and the "activity off Meta technologies" area in your Facebook or Instagram settings; Google's My Ad Center and Activity Controls; Pinterest's personalization settings; the Digital Advertising Alliance and Network Advertising Initiative opt out pages, which are cookie based and need redoing if you clear cookies; and your device's own controls, such as iOS App Tracking Transparency and Android ad personalization.
What none of these change. Order confirmations, shipping notices, delivery updates, refund confirmations, and replies to your own emails are transactional messages tied to a purchase you made. They are not marketing and they continue regardless of your advertising choices, because you need them to know where your parcel is.
12. Marketing emails and your communication choices
Transactional messages. When you place an order we send order confirmation, shipping confirmation, and delivery related emails, and we reply to messages you send us. These are necessary to perform our contract with you and continue while an order is live.
Marketing messages. We send promotional email only to people who asked for it, for example by subscribing on the store or checking a marketing consent box at checkout. If you never opted in, you should not be receiving marketing from us; if you are, tell us and we will fix it. Every marketing email carries an unsubscribe link, identifies us as the sender, and includes a valid postal address.
- Unsubscribe using the link in any marketing email, or email us and ask. We act on unsubscribes promptly and well within the ten business days the CAN-SPAM Act allows.
- Suppression list. When you unsubscribe we keep your email address on a suppression list, because that is the only way to make sure we do not email you again by accident. It is a narrow, protective use and we never market to that list.
- Cart reminders. If you entered your email at checkout, did not complete the purchase, and have consented to marketing, you may receive a reminder about the items left in your cart. Unsubscribing stops these too.
SMS and phone. We do not run an SMS marketing program and we do not operate a phone line. A phone number given at checkout goes to the carrier for delivery purposes only. We will not call you and we will not text you marketing.
What we never do with your email address. We do not sell it, rent it, or hand it to other brands. Within our advertising it is used in hashed form as described in section 5, and section 7 explains how to stop that.
13. How long we keep information
We keep personal information only as long as we have a reason to, judged against how long it is needed for its purpose, how long the law requires us to keep it, how long a customer could still bring a claim or a payment dispute, whether it is needed to detect fraud or defend a claim, and whether you have asked us to delete it. The periods below are the ones we control and apply.
- Order and transaction records, meaning who bought what, when, for how much, and where it shipped: at least 7 years from the order date, because tax and bookkeeping rules that apply to us require records of that age. This is the main reason a purchase record survives a deletion request.
- Shipping, customs, delivery, return, and refund records: the same 7 year period, because they are part of the financial record.
- Payment records held by us, meaning last four digits, amount, status, and reference: the same 7 year period. Full card data is never held by us at all.
- Chargeback and dispute evidence: for the duration of the dispute plus the applicable card network window, then folded into the order record.
- Support emails and attachments: we keep them while they may still be needed for a return, a fault claim, or a dispute, and delete them once they are not. Photos sent about a damaged mat are deleted once the claim is closed, unless the claim is disputed.
- Marketing subscriber records: kept until you unsubscribe or until you have been inactive for a long period, after which we remove you. Suppression list entries, meaning the fact that you asked not to be emailed, are kept indefinitely, because deleting them would cause the exact harm you asked us to prevent.
- Website and server logs, cookie lifetimes, and platform data: these sit on our ecommerce platform, on the advertising platforms, and in your own browser, and they run to those companies' schedules rather than ours. We will not publish a deletion period for data we do not control. What we can do, and will do on request, is remove you from our audiences and stop sending new events.
- Backups. Our platform's backups are overwritten on a rolling cycle. When we delete something at your request it may persist in a backup for a short period until that cycle completes, and it is not restored into active use in the meantime.
When a period ends we delete the information or irreversibly aggregate it so it no longer identifies you. Aggregated statistics, such as how many large mats sold in a month, are not personal information and we keep those.
14. How we protect information, and what we will not promise
What we actually do. The entire store, including checkout, runs over encrypted HTTPS. Card payments are handled by PCI-DSS compliant processors, and card numbers and security codes are never transmitted to or stored on our systems. Customer matching data sent to advertising platforms is hashed before transmission. Access to order and customer data is limited to the small number of people who run the business and to service providers who need it. Administrative accounts on our store platform and email are protected with strong, unique passwords and multi factor authentication. We use established vendors and, where they offer them, contracts that restrict processing to our instructions. And we practice data minimization: we do not collect government IDs, we do not collect precise device location, and we do not keep what we do not need.
The honest part. No website, no company, and no security measure is perfect, and we are not going to claim ours is. Transmitting data over the internet always carries some risk. We cannot and do not guarantee that your personal information will never be accessed, disclosed, altered, or destroyed by an unauthorized party. What we can promise is that we take security seriously, that we do not hold the most dangerous categories of data in the first place, and that we will act quickly and tell you the truth if something goes wrong.
Breach notification. If a security incident affects your personal information, we will investigate promptly and, where notification is required, notify you and the appropriate regulators without unreasonable delay and within the timeframes set by the breach notification law of your state. Our notice will tell you, as far as we know it, what happened and when, what categories of information were involved, what we have done to contain it, what we are doing to prevent a repeat, and what steps you should consider taking. We will not bury a breach in a policy update.
A clause we deliberately left out. Some stores say the customer bears all risk and the seller is not liable for any unauthorized access, however caused. We have not included that. A blanket disclaimer of responsibility for our own security failures would be unfair to you and would very likely be unenforceable anyway. Our responsibility for how we handle your data is governed by applicable law, not by a sentence we wrote to protect ourselves.
Your part. Use a strong, unique password on any account you hold with our store platform or with PayPal, do not share one time codes, and treat any message asking for card details or passwords as fraudulent. If you think someone has gained access to your order information, email us and we will help.
15. Children under 13, and teens under 16
Our store is not for children. It is a general audience retail site intended for adults who can enter a binding purchase contract. It is not directed to children under 13. We do not design our product pages, ads, or creative to appeal to children, we offer no child oriented features, and we do not knowingly collect personal information from anyone under 13.
COPPA. The Children's Online Privacy Protection Act requires verifiable parental consent before collecting personal information from a child under 13 online. We do not seek to collect it and we have no mechanism for obtaining such consent, because we should not be collecting it at all.
If it happens anyway, and we learn we have collected personal information from a child under 13 without verifiable parental consent, we delete it promptly, direct our service providers to do the same, and remove the associated identifiers from any advertising audiences.
For parents and guardians. If you believe a child under 13 has given us personal information, email mybarklypaw@gmail.com with the subject line "Child privacy" and any detail that would let us find the record. We will investigate and delete what we find. We will not require you to prove anything burdensome, and we treat these requests as urgent.
Teens under 16. California requires opt in consent before selling or sharing the personal information of a consumer aged 13 to 16. We do not knowingly sell or share the personal information of any consumer under 16. If we become aware that a customer record belongs to someone under 16, we exclude it from advertising audiences and from any data sent to advertising platforms.
16. International data transfers
Where we are, and what that means. Stickwall is registered in Israel, and the people who run BarklyPaw work from Israel. Wherever you are in the world, your personal information will be accessed from Israel as a matter of routine, because that is where your order is reviewed, your email is answered, and your return is processed. We are telling you this plainly rather than hiding it in a generic sentence about international transfers.
Where the data physically sits. Our store platform, payment processors, email provider, and advertising platforms are primarily United States companies, and most of your data is stored on their infrastructure, which may be located in the United States or elsewhere depending on the vendor. Shipping and customs data necessarily goes to the destination country, including its customs authority. Our fulfillment partner is located outside the countries we ship to and receives the delivery details in section 6. Copies of order and support information may be accessed from, and to a limited extent stored in, Israel.
Protection during transfer. Data in transit is encrypted, and we use vendors bound, where they offer it, by contracts restricting them to processing on our instructions. Israel has been recognized by the European Commission as providing an adequate level of data protection, and Israeli law imposes its own privacy and database obligations on us.
United States law follows the data, not the company. Being based abroad does not exempt us from the CCPA, the Virginia, Colorado, Connecticut, Utah, and Texas laws, COPPA, CAN-SPAM, or state breach notification laws when we sell into those states. We do not claim any such exemption and we will not use our location to avoid a request. Nothing in this policy takes away a right you have under the law of your own state or country, or requires you to bring a privacy complaint somewhere inconvenient.
17. Customers in Canada, Australia, and Israel, and why we do not serve the EU or UK
Canada. Federal law, PIPEDA, and equivalent provincial laws in Quebec, Alberta, and British Columbia give you the right to access the personal information we hold, ask for corrections, and withdraw consent to non essential uses such as marketing. Canada's anti spam legislation applies to our marketing email, which is why we only send it to people who opted in. Quebec residents have further rights under Quebec's privacy law, including rights around consent and automated processing, and under the province's language rules. Those rights apply in full and take precedence over anything on this page. Use the same email address and process as in section 9.
Australia. The Privacy Act and the Australian Privacy Principles give you the right to ask what personal information we hold, access it, and ask us to correct it. The Spam Act applies to our marketing email, and every marketing message carries a working unsubscribe. Same email, same process.
Israel. The Protection of Privacy Law gives you the right to inspect information held about you in a database and to request correction or deletion of information that is incorrect, incomplete, or out of date. Same email, same process.
The European Union and the United Kingdom. We ship worldwide, and where local data-protection law gives you stronger rights than this policy, that law applies. That is why this policy contains no GDPR or UK GDPR language, no lawful basis table in the European format, no data protection officer contact, and no EU representative. We would rather say so honestly than paste in European clauses we do not currently operate under. If we begin selling into those markets, we will publish a compliant policy before the first order, not after.
One standard, applied broadly. Where it is practical, we apply the strongest protection in this policy to everyone. The advertising opt out, the deletion process, the retention limits, the security measures, and the breach commitment are not restricted to residents of any one place.
18. Changes to this policy, and how to contact us
How we change this policy. We review it at least once a year and whenever we add a tool, a vendor, or a market that changes what we do with personal information. When we update it we change the last updated date at the end of this page and post the new version here. We keep a dated record of published versions and will send you the one that applied when you ordered.
- Minor changes, such as clarifying wording or renaming a vendor, take effect when posted.
- Material changes, such as collecting a new category of information, adding a new advertising platform, using your data for a genuinely new purpose, or beginning to sell personal information, are announced before they take effect. Where we hold your email address and the change affects you, we email you. Where the law requires consent for the new use, we ask for it rather than assume it from your continued use of the site.
- We will not apply a material change retroactively to information already collected under an earlier version without giving you notice and, where required, a choice.
Contact us. For any privacy question, any request under sections 7 through 10, a child privacy concern, or a complaint about how we handled your data, email mybarklypaw@gmail.com and put the request type in the subject line. The business responsible is Stickwall, registered business number 314619487, Israel, trading as BarklyPaw; our full registered business address is available by email on request. Email is the only channel we operate. We do not have a phone line, a live chat, or a postal service center, and we will not list contact methods that do not exist.
If you are not satisfied with our answer, tell us first and give us a chance to fix it, because that is usually the fastest route. If you are still not satisfied, you have the right to complain to your state Attorney General, and California residents may also contact the California Privacy Protection Agency. Nothing in this policy prevents, discourages, or penalizes you for doing so, and we will not treat you differently as a customer if you do.
Last updated: July 25, 2026