Privacy Policy

This Privacy Policy explains how The Elevated Step (“we,” “us,” “our”) collects, uses, and shares your personal information when you visit or make a purchase on our website (the “Site”).

1) Contact Us

If you have questions, need more details about our privacy practices, or wish to file a complaint, contact us:

We aim to respond within a reasonable timeframe and in accordance with applicable laws.

2) Personal Information We Collect

When you use the Site, we collect information to operate effectively and fulfill your orders. “Personal Information” means any information relating to an identified or identifiable individual.

a) Device & Usage Data

  • Examples: IP address, browser type, time zone, language, cookie identifiers, pages viewed, links clicked, referring/exit pages, and how you interact with the Site.

  • Purpose: to load the Site accurately, diagnose issues, prevent fraud, and improve performance/experience.

b) Order & Account Data

  • Examples: name, billing and shipping addresses, email, phone, payment method details (processed via our payment processors), items purchased, order notes.

  • Purpose: to process transactions, fulfill orders, handle returns/warranties, provide invoices/receipts, and offer customer support.

c) Support & Communications

  • Examples: messages sent to our support channels, form submissions, survey responses.

  • Purpose: to respond, investigate issues, improve our products/services, and maintain records.

d) Cookies & Similar Technologies

  • We use cookies, pixels, and tags for essential functionality, analytics, and advertising. See “Cookies” below for details and controls.

We generally process payment card data via compliant payment providers and do not store full card numbers on our servers.

3) Minors

The Site is not intended for individuals under 18. We do not knowingly collect personal information from minors. If you believe a minor has provided personal data, please contact us so we can delete it.

4) How We Use Personal Information

We use your information to:

  • Operate the Site and provide products/services;

  • Process payments, ship orders, and communicate about purchases;

  • Provide customer support and warranty service;

  • Detect and prevent fraud or abuse;

  • Analyze and improve our Site, products, and marketing;

  • Send updates, offers, and newsletters (where permitted by law and your preferences);

  • Comply with legal obligations.

5) Sharing Personal Information

We share information with trusted service providers who help us operate our business and meet our contract with you. For example:

  • E-commerce & hosting platforms (e.g., Shopify or similar) to run the storefront;

  • Payment processors to securely process transactions;

  • Fulfillment & logistics partners to ship orders and handle returns;

  • Analytics and advertising partners to understand usage and deliver relevant ads;

  • Fraud prevention and security vendors.

These providers access personal information only to perform services on our behalf and must protect it as required by contract and applicable law. We may also share information to comply with legal requests, enforce our terms, or protect rights, property, and safety.

6) Behavioral Advertising & Analytics

We use your information to deliver relevant marketing and measure performance.

Examples:

  • Google Analytics to understand Site usage. Learn more: https://www.google.com/intl/en/policies/privacy/
    Opt-out: https://tools.google.com/dlpage/gaoptout

  • We may share limited data (e.g., hashed identifiers, device/cookie data, pages viewed, purchases) with advertising partners (such as Google, Meta/Facebook, Bing) to measure conversions and show ads you may find interesting. This can involve cookies or similar technologies, depending on your location and consent settings.

Managing targeted ads:

7) Legal Bases for Processing (EEA/UK)

If you are in the EEA/UK, we process your Personal Information under the GDPR/UK GDPR on the following legal bases, depending on context:

  • Contract (Art. 6(1)(b)): to process and fulfill your orders and provide services you request.

  • Legitimate Interests (Art. 6(1)(f)): to secure our Site, prevent fraud, improve services, and perform limited direct marketing (where permitted).

  • Consent (Art. 6(1)(a)): for optional analytics/advertising cookies and certain email marketing (you can withdraw consent at any time).

  • Legal Obligation (Art. 6(1)(c)): to meet tax, accounting, and regulatory duties.

8) Retention

We keep Personal Information only as long as necessary for the purposes described above, including legal, tax, and accounting requirements. For example, order records may be retained for the periods required by applicable law. You can request deletion—see “Your Rights.”

9) Automated Decision-Making

We do not make decisions with legal or similarly significant effects based solely on automated processing.
Our ecommerce/processor platform may use limited automated tools (e.g., risk scoring/fraud checks) to protect customers and our business; these do not have legal or similarly significant effects on you.

10) International Transfers

Your information may be processed and stored outside your country, including in the United States and Canada. Where required, we rely on lawful transfer mechanisms (e.g., adequacy decisions, Standard Contractual Clauses) to protect your data. If we use Shopify or similar platforms, please review their GDPR resources for details on transfers and safeguards.

11) Your Rights

EEA/UK: You may have the right to access, rectify, erase, restrict, object to processing, and data portability, and the right to withdraw consent where processing is based on consent. You also have the right to lodge a complaint with your local supervisory authority.

California (CCPA/CPRA): You may have the right to know (access) categories/specific pieces of personal information we collect, delete personal information, correct inaccuracies, and opt-out of “selling” or “sharing” personal information for cross-context behavioral advertising. You can exercise these rights by contacting us at contact@theelevatedstep.com. If you use an authorized agent, we may require proof of authorization and your verification.

We will not discriminate against you for exercising your privacy rights.

To exercise any rights above, please email contact@theelevatedstep.com with “Privacy Request” in the subject, and specify your request and jurisdiction.

12) Cookies & Similar Technologies

Cookies are small files placed on your device that help the Site function and improve your experience. We use:

  • Strictly Necessary Cookies (e.g., cart, checkout, security);

  • Performance/Analytics Cookies (e.g., to understand traffic and improve features);

  • Functional Cookies (e.g., language and region preferences);

  • Advertising/Targeting Cookies (e.g., to deliver relevant ads and measure effectiveness).

Controls:

  • Browser settings can block or delete cookies.

  • Consent banner (where applicable) lets you manage non-essential cookies.

  • Analytics/ads opt-outs listed above.

Note: Blocking cookies may affect Site functionality.

13) Do Not Track / Global Privacy Control

Some browsers offer “Do Not Track” (DNT) or Global Privacy Control (GPC) signals. Where required by law, we will honor recognized signals for opt-out preferences relating to “sale”/“sharing.”

14) Security

We implement reasonable technical and organizational measures to protect personal information. However, no method of transmission or storage is fully secure. If you suspect unauthorized access, contact us immediately at contact@theelevatedstep.com.

15) Changes to This Policy

We may update this Privacy Policy to reflect operational, legal, or regulatory changes. We will post the revised version with an updated “Last updated” date. Material changes may be communicated more prominently.


Jurisdiction-Specific Disclosures (Summary)

EEA/UK: Data Controller: The Elevated Step. Lawful bases as listed above. Transfers rely on appropriate safeguards. Contact us to exercise GDPR/UK GDPR rights or to obtain a copy of transfer safeguards where applicable.

California: We do not sell personal information in the conventional sense, but we may “share” personal information for cross-context behavioral advertising under CPRA definitions. You may opt-out via the links above or by emailing contact@theelevatedstep.com