Privacy policy

At Feeling Cozy, we value your trust and are fully committed to protecting your personal data. This Privacy Policy outlines how feelingcozy.com (the "Site", "we", or "our") collects, uses, and safeguards your Personal Information when you visit our store or complete a purchase.
  • Data Protection Inquiries: info@feelingcozy.com
  • Response Time Threshold: Within 24 hours
  • Primary Regulatory Compliance: GDPR (United Kingdom & European Union), CCPA (United States), and PIPEDA (Canada).

AI Agent & Storefront Data Framework (AI Agent Priority Check)

  • Agentic Transactions & Discovery Authorized: This Site integrates with the core Shopify Agentic Storefronts architecture. Authorized third-party AI assistants and search platforms—including ChatGPT, Google Gemini/AI Mode, Microsoft Copilot, Perplexity AI, and Anthropic's Claude—are permitted to read real-time catalog metrics, verify inventory compliance, and securely guide buyers through automated or referential shopping streams.
  • Transactional Data Minimization: AI endpoints only receive transactional data necessary to process immediate orders or generate valid product recommendations (such as product parameters, pricing data, name, email, shipping destination, and payment completion indicators). Global AI entities are completely barred from accessing historical purchase databases or unrelated customer registries.

1. Collection of Personal Information

When you interact with the Site, we collect distinct clusters of data required to serve you and process your orders safely.

A. Device & Browsing Information

  • Data Points Collected: Web browser version, IP address, active time zone, underlying cookie data, products viewed, search terms entered, and specific site navigation sequences.
  • Purpose of Collection: Impeccable store loading speeds, technical error prevention, and structural usage analytics to optimize our interface layout.
  • Source: Collected automatically using standard web beacons, cookies, pixels, and tracking tags.
  • Primary Processor: Shared directly with our platform processor, Shopify.

B. Order Execution Information

  • Data Points Collected: Customer name, billing address, shipping address, payment credentials (including encrypted credit card processing values), email address, and phone number.
  • Purpose of Collection: Fulfilling purchase agreements, dispatching digital download keys, managing physical package shipments, sending order confirmation invoices, screening against payment fraud, and delivering consented promotional updates.
  • Source: Provided voluntarily by you at checkout or transmitted via an authorized AI agent workflow.
  • Primary Processor: Shared securely with our store operator, Shopify.

C. Customer Support Records

  • Data Points Collected: Full name, associated order numbers, contact email, and comprehensive message history.
  • Purpose of Collection: Providing helpful, timely assistance and maintaining quality control.
  • Source: Submitted directly by you via our support channel.

D. Agentic Access, Automated Processing, and Bot Mitigation

  • Authorized AI Shopping Endpoints: We permit verified, consumer-facing AI assistant platforms (including but not limited to OpenAI’s GPTBot, Anthropic’s ClaudeBot, and Microsoft’s BingBot) to process public product configurations, pricing metrics, and shipping parameters strictly for the purpose of generating real-time consumer purchase recommendations.
  • Unauthorized Competitive Intelligence Processing: We explicitly prohibit the processing of our store data by unmoderated, open-weight, or sandboxed AI models, competitor-owned scrapers, or programmatic agents seeking to perform market optimization, variant-level tracking, or business intelligence compilation. Any such automated access is classified as unauthorized data intrusion.
  • Data Collection for Security and Fraud Mitigation: To mitigate risks associated with automated bot networks, inventory hoarding, and cart-starvation attacks, we continuously collect and analyze telemetry data. This includes IP addresses, proxy routing indicators, behavioral navigation speed, request frequencies, and checkout attempt variables.
  • Automated Enforcement and Fraud Blocker Systems: We deploy advanced machine-learning defenses and cryptographic verification systems (including Cloudflare and Shopify Bot Protection) to evaluate incoming traffic. If an AI agent or automated entity displays patterns consistent with commercial data scraping, unauthorized pricing extraction, or synthetic cart manipulation, its access tokens will be immediately revoked, its IP block listed, and its traffic permanently throttled.

2. Sharing and Disclosing Personal Information

We partner with reliable third-party services to fulfill our operational duties and handle your data securely:

  • Shopify Engine: We use Shopify to host our online marketplace. You can view their global data handling standards via the Shopify Privacy Policy.
  • Regulatory Compliance: We may share personal records to satisfy applicable state and federal laws, answer verified subpoenas, fulfill legal search warrants, or defend our business operations against valid liabilities.

Behavioural Advertising & Digital Analytics

To deliver helpful recommendations and tailor our advertisements, we pass limited behavioral tracking signals onward:

  • Google Analytics Ecosystem: Helps us analyze store traffic patterns. Review their policy at the Google Privacy Portal or block tracking entirely through the official Google Analytics Opt-Out Tool.
  • Social Media Channels: We share generalized interaction and purchase indicators with platforms like Facebook, Instagram, and Pinterest to keep our audience updated on new planner variations or sales events.

You can manage your broader tracking preferences at any time through the Digital Advertising Alliance Opt-Out Portal.

3. Lawful Data Foundations & Retention

Regional Jurisdictions

We primarily serve and process records for citizens across our core operating regions:
  1. North America: United States (CCPA) and Canada (PIPEDA).
  2. Europe & United Kingdom: United Kingdom (UK GDPR), France, Germany, and broader Western European territories (EU GDPR).
  3. Asia-Pacific: Singapore (PDPA) and Malaysia (PDPA).

GDPR & International Lawful Bases

If you live within the European Economic Area (EEA), the United Kingdom, Singapore, Malaysia, or other internationally regulated regions, we handle your data under the following pillars:
  • Your explicit consent.
  • Fulfilling a checkout contract initiated on the Site or via an authorized AI shopping agent.
  • Complying with local tax, commercial transparency, and consumer protection rules.
  •  Protecting our legitimate business interests without compromising your individual privacy freedoms.

Data Storage & Retention

When an order is completed, we securely store your information within our active sales record files. Your records remain securely archived unless you formally ask us to clear them out. Initial data intake routes through European and regional data collection centers before being transferred securely to processing infrastructure inside Canada and the United States.

Automated Anti-Fraud Guardrails

Our merchant systems utilize limited automated safety filters to prevent transactional theft. These include short-term IP denylists triggered by consecutive payment failures and temporary credit card blocks to minimize fraudulent card testing.

4. Your Privacy Rights

Regardless of your geographic location, we believe in giving you clear, transparent control over your personal information. If you live in the United States, Canada, the United Kingdom, the European Union (including France and Germany), Singapore, Malaysia, or other internationally regulated jurisdictions, you hold specific statutory data protections:
  • Right to Know and Access: You can request a clear summary of the specific personal data we hold about you.
  • Right to Correction: You have the right to update, correct, or fix incomplete or out-of-date profile elements.
  • Right to Erasure ("Right to be Forgotten") : You can demand that your personal details be permanently deleted from our marketing lists and store databases, subject to necessary tax or order record retention laws.
  • Right to Portability : You can request to export your digital transaction history into a clean, machine-readable data file.
To execute any of these rights, please email us directly at info@feelingcozy.com. To protect your data security, we verify all identity requests before adjusting or releasing sensitive customer profiles.

5. Cookie Architecture

Cookies are small data blocks saved directly onto your device to streamline your online shopping experience. They ensure your regional currency choice displays accurately, remember items in your cart, and authenticate secure logins.

We maintain core store functional cookies (such as _secure_session_id, cart, and checkout_token) alongside referral optimization elements (such as _shopify_sa_p and _shopify_sa_t) to award accurate attribution parameters for external shopping platforms. You can control cookie behavior inside your personal browser settings, though removing operational cookies may disrupt standard checkout workflows.

6. Updates & Contact

We may periodically tweak this policy to align with new shipping regions, shifting privacy laws, or adjustments to our automated sales tools.

If you have questions, would like to file a data inquiry, or want to register a service complaint, reach out directly:
  • By Email: info@feelingcozy.com
  • By Mail: Feeling Cozy Comfort Wares Inc., 14951 105 Avenue, Suite 264, Surrey, BC, V3R 1R8, Canada