Last updated: February 3, 2026
Heart & Thorn operates this website and related services (the “Services”). This Privacy Policy explains how we collect, use, and disclose personal information when you visit, use, or make a purchase through the Services or otherwise communicate with us.
If there is a conflict between our Terms of Service and this Privacy Policy, this Privacy Policy governs with respect to the collection, processing, and disclosure of personal information.
By using the Services, you acknowledge that you have read and understand this Privacy Policy.
“Personal information” refers to information that identifies or can reasonably be linked to you. It does not include information that is anonymous or has been de-identified.
Depending on how you interact with the Services, we may collect:
We may collect personal information:
We use personal information to:
Provide and Manage Services
Process payments, fulfill orders, manage accounts, coordinate delivery, and support transactions.
Improve the Services
Maintain functionality, analyze usage, and improve performance and user experience.
Marketing and Advertising
Send promotional communications and display relevant advertising based on your interactions with the Services.
Security and Fraud Prevention
Protect accounts, detect and prevent fraud or misuse, and maintain platform security.
Communications
Provide customer support and respond to inquiries.
Legal Compliance
Comply with applicable laws, enforce policies, and respond to legal requests.
We may disclose personal information:
Our Services are hosted on a third-party commerce platform that enables us to operate the website and process transactions. Personal information may be processed by this platform and its service providers as necessary to deliver the Services.
The Services may include links to third-party websites or platforms. We are not responsible for the privacy practices or content of those sites. You should review their policies before providing personal information.
The Services are not intended for children, and we do not knowingly collect personal information from individuals under the age of majority in their jurisdiction.
If you believe a child has provided personal information, you may contact us to request deletion.
We use reasonable safeguards to protect personal information. However, no system is completely secure, and we cannot guarantee absolute security.
Personal information is retained only as long as necessary to:
Depending on your location, you may have rights regarding your personal information, including:
These rights may be limited under applicable law.
You may also opt out of marketing communications at any time using the unsubscribe option included in those communications. Transactional messages may still be sent as needed.
We may require identity verification before processing requests.
Where supported, we recognize Global Privacy Control (GPC) signals as a request to opt out of certain data uses for the browser or device sending the signal.
If you have concerns about how your personal information is handled, you may contact us. Depending on your location, you may also have the right to file a complaint with a data protection authority.
Personal information may be transferred, stored, or processed outside your country.
Where required, appropriate safeguards are used to protect personal information during international transfers.
We may update this Privacy Policy from time to time for operational, legal, or regulatory reasons. Updates will be posted on this page with a revised “Last updated” date.
For questions about this Privacy Policy or to exercise your rights, please contact us through the contact methods listed on our website.