Privacy policy

U.S. Privacy Policy

This policy explains how Baby Phat (“Baby Phat,” “we,” “us,” or “our”) collects, uses, retains, and discloses personal information through the Baby Phat online store and related services (the “Services”).

It should be read with our Cookie Policy, Privacy Rights Requests page, and Notice of Financial Incentive, where applicable.

Contents

  • Notice at Collection
  • Information we collect and sources
  • How we use information
  • Disclosures, sale, sharing, and targeted advertising
  • Retention
  • Privacy choices and rights requests
  • California disclosures for the preceding 12 months
  • Children’s privacy
  • Security and changes
  • Contact

Notice at Collection

This notice explains the categories of personal information we collect, why we use it, whether we disclose it for business purposes or in ways that applicable law may define as a sale, sharing, or targeted advertising, and how we determine how long to retain it. What we collect depends on how you use the Services.

Identifiers and contact information

Examples: Name, email, phone, postal address, account and online identifiers, and IP address.

Purposes: Accounts, orders, support, communications, fraud prevention, and marketing choices.

Potential sale, sharing, or targeted advertising: Online identifiers and associated activity may be disclosed to advertising partners for cross-context behavioral or targeted advertising, depending on configuration and choices.

Commercial and transaction information

Examples: Products viewed, cart activity, purchases, returns, discounts, and transaction history.

Purposes: Orders, service, accounting, fraud prevention, analytics, personalization, and advertising measurement.

Potential sale, sharing, or targeted advertising: This information may be associated with advertising measurement or targeted-advertising activity; it is not described as a monetary sale.

Internet, device, and network activity

Examples: Browser, device, IP, cookie or pixel identifiers, pages, clicks, referrer, session, and message interactions.

Purposes: Store operation, security, preferences, analytics, troubleshooting, campaign measurement, and advertising.

Potential sale, sharing, or targeted advertising: This information may be disclosed for cross-context behavioral or targeted advertising, subject to applicable opt-out rights.

Account, preferences, and communications

Examples: Login, settings, marketing and privacy choices, inquiries, support communications, loyalty activity, and reviews.

Purposes: Account administration, support, requested features, marketing, and compliance records.

Potential sale, sharing, or targeted advertising: Associated online activity may be used in configured advertising; direct communications are not described as a monetary sale.

Inferences

Examples: Preferences or interests inferred from browsing, cart, purchase, or engagement activity.

Purposes: Product or content personalization, audience understanding, and advertising measurement or delivery.

Potential sale, sharing, or targeted advertising: Inferences may be used or disclosed for targeted advertising, subject to applicable opt-out rights.

User-generated content

Examples: Reviews, ratings, optional review media, and other content submitted to us.

Purposes: Publish and administer reviews, support, quality assurance, and fraud or abuse prevention.

Potential sale, sharing, or targeted advertising: We do not disclose the content of reviews or review media for cross-context behavioral advertising.

Payment or credential data

Examples: Payment method, transaction confirmation or status, and account credentials needed for requested functions.

Purposes: Payment processing, refunds, account access, security, and legal or accounting obligations.

Potential sale, sharing, or targeted advertising: Payment-card details and account credentials are not used for targeted advertising. Processors may receive information needed to complete a transaction.

We do not characterize the potential disclosures above as a sale for money. Applicable privacy laws may nevertheless define some disclosures to advertising or analytics providers as a “sale,” “sharing,” or processing for “targeted advertising.” See Privacy choices and rights requests.

Information we collect and sources

Depending on your interaction with the Services, we may collect the categories listed above directly from you; automatically through browsers, devices, cookies, pixels, tags, and similar technologies; from the store platform and providers supporting payments, communications, reviews, loyalty, fraud prevention, hosting, and analytics; and from advertising or social-media partners.

Examples include information submitted when you place an order, create or access an account, contact us, subscribe to messages, search or browse the store, submit a review, or use a privacy preference control. We may also receive transaction status or related information from payment providers and event/measurement information from configured partners.

How we use information

  • Operate, secure, troubleshoot, and improve the Services.
  • Process orders, payments, shipping, returns, and customer-service requests.
  • Create and administer accounts, preferences, reviews, marketing programs, and other requested features.
  • Send transactional communications and, where permitted and selected, marketing communications.
  • Measure, personalize, and provide advertising where configured and permitted by law.
  • Analyze use, prevent fraud or misuse, comply with legal obligations, and establish, exercise, or defend legal claims.

Disclosures, sale, sharing, and targeted advertising

We may disclose personal information for business purposes to providers that support the store platform, payment processing, infrastructure/security, communications, marketing, reviews, customer-facing features, analytics, and fraud prevention. The role of a provider can depend on its contract, product, and configuration.

Shopify

Services: Online store, checkout, order processing, fraud prevention, and related platform services.

Privacy context: Shopify generally processes store information for us. Some enhanced or network services may involve Shopify’s own uses as described in Shopify’s privacy materials.

Google services

Services: Analytics, advertising measurement, and advertising.

Privacy context: Online identifiers, device activity, and commerce events may be processed for analytics or advertising, subject to applicable privacy choices.

HYROS

Services: Marketing attribution, click and source tracking, conversion measurement, and campaign reporting.

Privacy context: HYROS may process online identifiers, advertising-source information, contact information, and commerce or conversion events on our behalf. Advertising-related processing connected through HYROS is subject to applicable privacy choices.

Meta and Pinterest

Services: Advertising delivery, measurement, attribution, and audience services where used.

Privacy context: These activities may constitute sale, sharing, or targeted advertising under applicable privacy laws.

Klaviyo and Mailchimp

Services: Email, SMS, marketing automation, and related measurement.

Privacy context: They process subscription, communication, engagement, and commerce information to provide services to us.

Judge.me, Cloudflare, and Complianz/Iubenda

Services: Reviews, infrastructure or security, and privacy-preference or policy services.

Privacy context: They process information needed to provide their respective store functions.

PayPal and Apple Pay

Services: Payment and transaction services.

Privacy context: These providers process payment and transaction information under their own privacy terms and applicable agreements.

You may opt out of activities that applicable law treats as sale, sharing, or targeted advertising through Your Privacy Choices or the methods described below. We do not knowingly sell or share the personal information of consumers under 16 without the authorization required by law.

Retention

We retain personal information only for as long as reasonably necessary for the purposes described in this policy. We consider the amount, nature, and sensitivity of the information; why we need it; our relationship with you; security and fraud-prevention needs; transaction, tax, accounting, warranty, dispute, and legal requirements; and applicable limitation periods.

  • Transaction records may be retained as needed for transactions, tax, accounting, fraud prevention, legal obligations, and disputes.
  • Marketing information may be retained until you unsubscribe, request deletion, become inactive, or it is no longer needed, subject to legal and operational requirements.
  • Consent and privacy-request records may be retained as needed to demonstrate compliance and resolve requests.
  • Contact inquiries may be retained until resolved and no longer needed for follow-up, records, or legal purposes.
  • Reviews may be retained until removed, the relevant relationship ends, or retention is no longer required.

Google Analytics user- and event-level data are configured for a 14-month retention period. Service providers may retain information under their own documented schedules and legal obligations.

Privacy choices and rights requests

Subject to applicable law and exceptions, U.S. residents may have rights to request confirmation/access, correction, deletion, and a portable copy of personal information; opt out of sale, sharing, targeted advertising, or certain profiling; use an authorized agent; and appeal a denied request. We will not discriminate against you for exercising applicable rights.

Use Privacy Rights Requests or email orders@babyphat.com to submit an applicable request. We may need to verify certain requests as permitted by law and may request reasonable proof from an authorized agent. You do not need to create an account to submit a request.

We will respond within the period required by applicable law. This is generally 45 days, although an extension may be available when permitted and accompanied by the required notice. If we deny an appealable request, we will explain the decision and how to appeal where applicable.

Your Privacy Choices device control

The “Your Privacy Choices” control opens the privacy-preference panel for the browser or device and allows applicable opt-outs. It is distinct from the Privacy Rights Requests workflow, which handles verifiable requests related to an email address or account. A device-level preference may not apply to every browser, device, account, or offline activity.

Your Privacy Choices

Universal opt-out mechanisms and Global Privacy Control

Where required by applicable law, we treat a qualifying universal opt-out mechanism, such as Global Privacy Control (GPC), as a request to opt out of applicable sale, sharing, or targeted-advertising activity for the browser or device that sends it. We do not treat the absence of a signal as consent or as a reversal of a recorded opt-out. To associate a browser/device choice with an identified account or to exercise rights beyond that browser/device, use Privacy Rights Requests.

Financial incentives

If we offer an eligible marketing discount or another financial incentive, participation is voluntary. See the Notice of Financial Incentive for material terms, withdrawal information, and the value explanation applicable to that program.

California disclosures for the preceding 12 months

The table below describes Baby Phat’s information practices from August 21, 2025 through August 20, 2026. “Personal information,” “sale,” and “sharing” have the meanings used in the California Consumer Privacy Act, as amended. Baby Phat does not sell personal information for money. Certain advertising disclosures may nevertheless be considered a sale or sharing under California law.

Identifiers and contact information

Collected: Yes.

Disclosed for business purposes to: Store, payment, communications, infrastructure, support, and marketing providers.

Sold or shared for cross-context behavioral advertising: Yes. Online identifiers and associated activity may be shared with advertising partners.

Retention criteria: Relationship, support, transaction, legal, fraud, and compliance needs.

Commercial and transaction information

Collected: Yes.

Disclosed for business purposes to: Store, payment, fulfillment, fraud, accounting, and support providers.

Sold or shared for cross-context behavioral advertising: Yes. Commerce events may be shared for advertising measurement or targeting.

Retention criteria: Transactions, tax, accounting, fraud, legal, and dispute needs.

Internet, device, and network activity

Collected: Yes.

Disclosed for business purposes to: Store, infrastructure, analytics, consent, and security providers.

Sold or shared for cross-context behavioral advertising: Yes. Online identifiers and activity may be shared with advertising partners.

Retention criteria: Operational and security needs and provider settings; Google Analytics user and event data are configured for 14 months.

Account, preferences, and communications

Collected: Yes.

Disclosed for business purposes to: Store, communications, support, consent, and marketing providers.

Sold or shared for cross-context behavioral advertising: Associated online identifiers and activity may be shared; message content is not shared for targeted advertising.

Retention criteria: Account relationship, unsubscribe or deletion, resolution, compliance, and legal needs.

Inferences

Collected: Yes.

Disclosed for business purposes to: Analytics and advertising providers.

Sold or shared for cross-context behavioral advertising: Yes. Preferences or interests may be used for targeted advertising.

Retention criteria: Purpose, relationship, provider settings, and legal or compliance needs.

User-generated content

Collected: Yes.

Disclosed for business purposes to: Review and store providers.

Sold or shared for cross-context behavioral advertising: No for the content of reviews or review media. Online identifiers and activity associated with visiting review pages are covered separately above.

Retention criteria: Publication or removal, relationship, moderation, and legal needs.

Payment and credential data

Collected: Yes.

Disclosed for business purposes to: Payment, security, and store providers.

Sold or shared for cross-context behavioral advertising: No for payment-card details or account credentials. Commerce events used for advertising measurement are covered separately above.

Retention criteria: Transaction, security, accounting, legal, and dispute needs.

We do not use or disclose sensitive personal information for purposes that require a right to limit under California law. Payment and account credentials are used only as reasonably necessary to provide requested services, maintain security, prevent fraud, and comply with law.

Children’s privacy

Baby Phat’s Services are intended for a general audience and are not directed to or targeted at children. We do not intentionally solicit personal information directly from children under 13. If you believe a child under 13 has provided personal information through the Services, contact us through the methods below so we can investigate and take appropriate action.

Security and changes

We use administrative, technical, and organizational measures designed to protect personal information. No method of transmission or storage is completely secure. We may update this policy when our practices or legal requirements change. The effective date above shows when this policy was last updated.

Contact

For privacy questions or requests, use Privacy Rights Requests or email orders@babyphat.com. For general questions, call +1 347-241-9226. You may also write to Baby Phat, 4444 Route 27, Kingston, NJ 08528, United States.