Privacy Policy
This draft explains how website and enquiry information may be handled by The Sun Sign.
Last updated: July 24, 2026
1. Scope
This Privacy Policy applies to information collected through thesunsign.com, its contact forms, quote requests, email communications, and other online services that link to this page. It does not cover a third-party website or service that has its own privacy policy.
2. Information we collect
You may provide your name, work email, company, telephone number, delivery location, project summary, artwork, product specifications, order requirements, and files attached to an enquiry. If an order proceeds, additional business, shipping, billing, and transaction information may be required.
When the live website is configured, the server and approved service providers may collect technical information such as IP address, browser type, device information, pages viewed, referring page, date, time, and security logs. The final policy must list the actual analytics, advertising, chat, and cookie tools used on the live website.
3. How we use information
We may use information to respond to enquiries, prepare quotations, review artwork and specifications, coordinate samples and orders, arrange inspection and delivery, provide customer support, protect the website, keep business records, comply with legal obligations, and improve website content. Marketing messages should be sent only where permitted, and recipients must have a clear way to unsubscribe.
4. Legal bases for EEA and UK visitors
Where the EU GDPR or UK GDPR applies, processing may rely on steps requested before a contract, performance of a contract, legal obligations, legitimate interests in operating and securing the business, or consent. The applicable basis depends on the purpose and the information involved. Consent can be withdrawn when processing depends on consent.
5. When information may be shared
Information may be shared with approved providers that support website hosting, email, file storage, analytics, security, customer communication, payment, production coordination, inspection, packaging, freight, customs, accounting, and professional advice. A provider should receive only the information needed for its work and must handle it under appropriate contractual and confidentiality terms.
Information may also be disclosed when required by law, to respond to a lawful request, to protect rights or safety, or in connection with a merger, financing, restructuring, or sale of the business. The final live policy must identify any sharing or sale that triggers a statutory opt-out right.
6. International transfers
Enquiries and orders may involve service providers or supply partners in more than one country. Where privacy law requires safeguards for an international transfer, appropriate contractual or legal measures should be used. The final policy must describe the transfer mechanism that applies to the live business and its providers.
7. Cookies and similar technologies
The current local prototype does not use marketing cookies. Before launch, the website must provide accurate information about every necessary, preference, analytics, advertising, or social-media technology that is enabled. Where consent is required, non-essential technologies should remain inactive until the visitor makes a choice.
8. Retention
Information should be kept only for as long as it is needed for the enquiry, order, support request, legal obligation, accounting requirement, dispute, security purpose, or other stated use. Final retention periods must be set after the business confirms its order, accounting, email, file, and backup practices.
9. Security
Reasonable administrative, technical, and physical safeguards should protect personal information. No website or transmission method is completely secure. Visitors should avoid sending unnecessary sensitive information through an enquiry form.
10. Privacy rights
Depending on location, a person may have rights to receive information about processing, request access, correct inaccurate information, request deletion, restrict or object to processing, receive portable data, withdraw consent, or complain to a regulator. Some rights have legal limits and exceptions.
California residents may also have rights to know, delete, correct, opt out of a sale or sharing of personal information, limit certain uses of sensitive personal information, and receive equal service when exercising a privacy right, where the CCPA applies to the business. The final live policy must state whether The Sun Sign sells or shares personal information as those terms are defined by applicable law.
11. Children's privacy
The website is intended for business users and is not directed to children. The business should not knowingly collect personal information from a child through this website.
12. Third-party links
The website may link to social networks, logistics providers, or other third-party sites. Their privacy practices are controlled by their own policies. Review those policies before providing information to them.
13. Policy changes
This page may be updated when the website, business practices, providers, or legal requirements change. The revised version should show a new last-updated date and any material change that visitors should know about.
14. Contact
Questions or privacy requests can be sent to [privacy email to be confirmed]. The controller’s legal name, registered address, and any required representative or data protection contact must be added before publication.