Privacy Policy
Effective date:
The short version
- We do not have user accounts and we do not ask you to log in.
- Your visit passes through Cloudflare, our network provider, which records standard request information including your IP address. A request cannot be delivered without it. Our own server does not store your IP address.
- Everything beyond those logs — page views, scroll depth, which product links you click — runs only if you accept the cookie banner.
- We do not sell your personal information, and we never have.
- When you click through to Amazon, you leave our site and that retailer's privacy policy takes over.
Who we are
The Pampered Hippie (thepamperedhippie.com) is operated by AIMAZING Advertising LLC, an Ohio limited liability company, at 6545 Market Ave N, Ste 100, Canton, OH 44721. For anything in this policy, contact [email protected]. AIMAZING Advertising LLC is the controller of the personal data described here.
Information we collect
1. Server and security logs (always collected)
Every request to this site passes through Cloudflare, which acts as our network provider. Cloudflare records standard request information — your IP address, your browser and device user-agent string, the page requested, the referring page, and the date and time — and uses it to route traffic, terminate encryption, and filter malicious requests. This happens before any consent banner appears, because a request cannot be delivered without it. Cloudflare retains that information under its own policy, linked under Service providers below.
Our own server does not record your IP address. It is deliberately discarded rather than stored: the only logs we keep are error reports, which record the page path that failed and the technical details of the failure. They do not contain your IP address, your user-agent string, anything from your cookies, or the query string of the page you were on. We keep them to find and fix breakages, and because they identify nobody they are not personal data about you.
2. Analytics (only with your consent)
If you accept our cookie banner, we collect first-party analytics: pages viewed, how far you scroll, which product links you click, a randomly generated session identifier stored in your browser, the site or ad that referred you, and campaign (UTM) parameters from the link that brought you here. If you arrived from one of our Instagram, Facebook, TikTok, Google, or Meta campaigns, the UTM tags tell us which campaign, not who you are.
These events do not include your name, email address, or account details — we do not have accounts. The session identifier is random and is not linked to any identity we hold.
3. Information you send us
If you email us, we receive your email address and whatever you put in the message. We keep correspondence for 24 months unless we need it longer to resolve a dispute or meet a legal obligation.
4. Email list
We do not currently offer an email newsletter and do not collect email addresses for marketing. This section will be updated before any signup form goes live.
5. Advertising and retargeting pixels
This site does not run Google Analytics, the Meta Pixel, the Google Ads tag, or any other third-party advertising or analytics tracker. No third-party script loads on this site at all.
We may advertise on platforms such as Google and Meta, but those platforms measure our campaigns on their own side — from the click that brought you here, not from code running in your browser while you read this page. The only thing we learn from an ad click is the campaign tag on the link, and only if you accept analytics.
Why we use it, and our legal basis
| What | Why | Legal basis (GDPR) |
|---|---|---|
| Request logs, recorded by Cloudflare | Deliver pages, keep the site up, prevent abuse | Legitimate interests (Art. 6(1)(f)) — running and securing the site |
| Analytics and click tracking | See which content is useful, measure ad campaign performance | Consent (Art. 6(1)(a)) |
| Email you send us | Answer your question | Legitimate interests (Art. 6(1)(f)) — responding to enquiries |
We do not use your information to make automated decisions with legal or similarly significant effects, and we do not build advertising profiles about individuals on this site.
Cookies and browser storage
We use the following, and nothing else:
- Consent preference (strictly necessary, stored in localStorage): remembers whether you accepted or declined, so we do not ask again. Written only once you answer the banner — if you ignore it, nothing is stored.
- Session identifier and campaign parameters (analytics, consent-gated): a random ID plus any UTM tags from your arrival link, used to connect events within a single visit. Written only after you accept. Cleared when your browser session ends.
Ignoring the banner is the same as declining it. Until you actively accept, we store nothing on your device beyond what you see above, and no analytics event is sent — not held back, not queued, not sent later if you accept further into your visit. Declining does the same thing and additionally records that you were asked.
You can change your mind at any time using the Cookie preferences link in the footer of every page, or by clearing this site's storage in your browser settings, which resets the banner.
Service providers and third parties
We do not sell your personal information and we do not share it with third parties for their own marketing. A small number of providers process data on our behalf, under contract, to keep the site running:
- Our own server, located in the United States — serves the site and stores the analytics database. The site runs on hardware we own and operate ourselves, so no third-party hosting company holds this data or has access to it.
- Cloudflare — carries traffic between you and our server, terminates HTTPS, and filters malicious requests. Every request to this site passes through Cloudflare, which processes your IP address and request metadata in the course of doing so. See Cloudflare's privacy policy.
- Google Workspace — hosts our email, so it receives and stores messages you send to the addresses on this page. It is involved only if you choose to write to us, and it has no part in serving the site or in our analytics.
That is the complete list. We use no third-party analytics service, no error monitoring service, no advertising or tag manager, no form handler, and no comment system. Error logs and backups stay on the same server that serves the site and are not sent anywhere else.
We may also disclose information if the law requires it, to enforce our terms, or to protect our rights or someone's safety. If the site is ever sold or merged, personal information may transfer with it; we will post notice here first.
Affiliate links and outbound clicks
This site contains affiliate links to third-party retailers, currently Amazon. Two separate things happen when you click one:
- On our side, if you accepted analytics, we record that a link for a given product was clicked, tied to your random session ID and campaign tags. We do not know whether you bought anything, and we do not receive your name, address, payment details, or order contents from the retailer — only anonymous, aggregated commission reports.
- On their side, the retailer receives your click along with our affiliate tag, and sets its own cookies to attribute any purchase to us. That processing is governed by the retailer's privacy policy, not this one. See Amazon's Privacy Notice.
Our commercial relationships are described in full in our Affiliate Disclosure.
How long we keep things
- Analytics events: 24 months, after which they are deleted or irreversibly aggregated into counts that identify no one. A scheduled job on our server performs this deletion; it is not a policy we rely on ourselves to remember.
- Email correspondence: 24 months, unless we need it longer to resolve a dispute or meet a legal obligation.
- Request logs: held by Cloudflare, not by us, and retained under Cloudflare's own policy rather than a period we set.
- Our error logs: these identify nobody — no IP address, user-agent, cookie or query string — so there is nothing in them to expire.
Security
The site is served over HTTPS, the analytics database is not publicly readable, and administrative access requires an individual account. No system is perfectly secure, and we cannot guarantee that a determined attacker will never succeed.
Where your data goes
We operate from the United States and our server is located in the United States. If you are in the EEA, the UK, or Switzerland, your information will be transferred to and processed in the United States, which does not have an equivalent data protection regime. Where such a transfer involves one of our processors, we rely on that processor's own safeguards: Cloudflare and Google Workspace are each certified under the EU–US Data Privacy Framework and offer the European Commission's Standard Contractual Clauses in their standard terms. You may request details of the safeguards in place.
Do Not Track and Global Privacy Control
Some browsers send a “Do Not Track” (DNT) signal. There is no agreed standard for what a site must do in response, and we do not respond to DNT signals. We do not need to: our analytics do not run at all unless you affirmatively accept them.
We do honour the Global Privacy Control (GPC) signal. If your browser or extension sends GPC, we treat it as a request to opt out of any sale or sharing of personal information and as a refusal of non-essential tracking, and we apply it automatically without asking you again.
Third-party tracking across sites: we do not permit third parties to collect personal information about your online activities over time and across differentwebsites through this site.
Do Not Sell or Share My Personal Information
We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined by California law. We have never done either. We also do not sell or share the personal information of anyone we know to be under 16.
Because there is nothing to opt out of, we do not currently offer a “Do Not Sell or Share My Personal Information” link. If that ever changes, the link will appear in the footer of every page before the tracker that made it necessary goes live.
Your rights — California (CCPA/CPRA)
In the 12 months before the effective date of this policy we collected the following categories of personal information, as those categories are defined by the CCPA:
| Category | Examples we actually collect | Source | Purpose | Disclosed to |
|---|---|---|---|---|
| Identifiers | IP address, random session ID, email address if you write to us | You and your device | Serving the site, security, analytics, replying to you | Hosting and network providers (as processors) |
| Internet or network activity | Pages viewed, scroll depth, product links clicked, referrer, UTM tags | Your device, with consent | Understanding content performance and ad campaigns | Hosting provider (as processor) |
| Commercial information | Which products you showed interest in by clicking | Your device, with consent | Editorial and campaign decisions | Hosting provider (as processor) |
We do not collect sensitive personal information, biometric data, geolocation beyond coarse IP-derived location, or information about your education, employment, or finances. We have not sold or shared personal information in the preceding 12 months, and we have not disclosed it for a business purpose beyond the processors named above.
California residents have the right to:
- Know what personal information we have collected, the sources, purposes, and who received it;
- Delete personal information we hold about you;
- Correct inaccurate personal information;
- Opt out of sale or sharing for cross-context behavioral advertising (we do neither);
- Limit our use of sensitive personal information (we collect none);
- Not be discriminated against for exercising any of these rights. We will not degrade the site or charge you differently.
To make a request, email [email protected] with “Privacy Request” in the subject line, or write to us at 6545 Market Ave N, Ste 100, Canton, OH 44721. We will confirm receipt within 10 business days and respond within 45 calendar days, extendable once by another 45 days if we tell you why.
Because we do not have accounts, the only way we can find your data is by the session identifier stored in your browser. If you want analytics tied to your visits deleted, include that identifier — it is stored under the key tph.consent's companion session key in your browser's storage, and we are happy to walk you through retrieving it. If you cannot provide it, we may be unable to verify which records are yours, and we will tell you so rather than delete someone else's data. An authorised agent may submit a request on your behalf with written permission that we can verify.
Your rights — other U.S. states
Residents of states with comprehensive privacy laws — including Colorado, Connecticut, Virginia, Texas, Oregon, Montana, Delaware, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, and others — have broadly similar rights to access, correct, delete, obtain a portable copy of their data, and opt out of targeted advertising, sale, and profiling. Use the same contact details above.
If we deny your request, you may appeal by replying to our decision. We will respond to an appeal within 45 days and, if we deny it again, tell you how to complain to your state Attorney General.
Your rights — EEA, UK, and Switzerland (GDPR)
We operate from the United States and this site is aimed at a US audience. We do not target or market to the EEA or the UK, and we have not appointed a representative under Article 27 of the GDPR.
That said, we will honour the rights below for anyone who asks, wherever you live. We hold very little about you — a random session identifier, campaign tags, and whatever you send us by email — so there is no reason to make you prove where you are before we help.
Where the GDPR or UK GDPR applies, you have the right to access your personal data, correct it, erase it, restrict or object to our processing of it (including objecting to processing based on legitimate interests), receive it in a portable format, and withdraw consent at any time. Withdrawing consent does not affect processing that already happened while consent was in place.
Withdraw analytics consent using the cookie preferences control in the footer, or by clearing this site's browser storage. Exercise any other right by emailing [email protected]; we respond within one month. You also have the right to lodge a complaint with your national supervisory authority, or with the UK Information Commissioner's Office if you are in the UK.
Children
This site is intended for adults. It is not directed to children under 13, we do not knowingly collect personal information from children under 13, and we do not knowingly sell or share the personal information of anyone under 16. If you believe a child has given us personal information, email [email protected] and we will delete it.
Governing law
This policy is governed by the laws of Ohio, United States, without regard to conflict of laws principles. This does not take away rights you have under the privacy law of the state or country you live in.
Changes
We will update this policy when what we do changes — and, for anything new that collects data, before it goes live rather than after. The effective date at the top reflects the latest revision. Material changes will be flagged on the site for at least 30 days.
Contact
AIMAZING Advertising LLC
6545 Market Ave N, Ste 100
Canton, OH 44721
[email protected]
