Get in touch with us at info@new.com
The Sugar Skull Collective
dba amber-kaye, am berkaye, & amberkaye81
PRIVACY POLICY
Effective Date: 04/28/1999
Last Updated: 09/09/2026
​
1. Introduction
The Sugar Skull Collective ("we", "us", or "our") operates https://www.thesugarskullcollective.com and provides the products and services described on that site (collectively, the "Service"). We are the entity responsible for determining how and why your personal information is processed.
Under US state privacy laws we are the "controller" of your personal information, or the "business" where the CCPA (as amended by the CPRA) applies.
This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and the rights you have over it. It applies to anyone who uses the Service, regardless of where they are located.
If you do not agree with this Privacy Policy, please do not use the Service.
Definitions. For purposes of this Privacy Policy:
​
-
"Personal information" (also "personal data") means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household, as defined under applicable data protection law.
-
"Sensitive personal information" is the subset of personal information that receives heightened protection under applicable law, as defined in Section 2.
-
"Processing" means any operation or set of operations performed on personal information, including collection, recording, organization, structuring, storage, adaptation, retrieval, use, disclosure, transmission, dissemination, restriction, erasure, or destruction.
-
"Service" has the meaning given in the opening paragraph of this Section.
-
"You" means the individual whose personal information is described in this Privacy Policy.
​
Under the CCPA (as amended by the CPRA), "sale" means disclosing personal information for monetary or other valuable consideration, and "share" means disclosing it to a third party for cross-context behavioral advertising, with or without monetary consideration.
​
2. Information We Collect
Notice at Collection. Consistent with the CCPA (as amended by the CPRA), we provide notice at or before the point of collection of the categories of personal information collected and the purposes for which they will be used. This Privacy Policy may form part of our notice at collection. Where required, we also provide additional just-in-time notices, cookie consent banners, or privacy-choices links at the specific point where personal information is collected. If we begin collecting additional categories or use personal information for materially different purposes, we will provide updated notice at the time of collection.
​
We collect the following categories of personal information:
​
Information you provide to us directly:
​
-
Identity and contact information, including your name, email address, phone number, postal address, and similar identifiers.
-
Account information, including your username, password, profile preferences, and account settings.
-
Payment information, processed by our third-party payment processors.
-
Communications you send us, including support requests, survey responses, and content you submit through the Service.
​
Information we collect automatically:
​
-
Device and connection information, including IP address, browser type, operating system, device identifiers, and language settings.
-
Location information, including approximate location derived from your IP address (typically at the city or region level) and, where you grant permission, precise location data from your device's GPS or similar sensors.
-
Usage information, including pages you visit, features you use, the time and duration of your visits, and the referring URL.
-
Cookies and similar technologies, as described in Section 5.
​
Information we receive from third parties:
​
-
Information from third-party authentication providers if you sign in using a service such as Google or Apple.
-
Information from analytics, advertising, and fraud-prevention services that help us operate and improve the Service.
​
Inferences:
We may derive inferences from the personal information described above, such as predicted preferences, behavior patterns, or product affinities. Where applicable law treats inferences as a separate category of personal information, we treat them as personal information for purposes of this Privacy Policy.
​
Sensitive personal information:
​
We collect sensitive personal information only where specifically disclosed in this Policy and only where necessary for the relevant purpose, with your consent where required by applicable law. Sensitive personal information has overlapping but not identical definitions across jurisdictions.
​
Under the CCPA (as amended by the CPRA) and similar US state privacy laws, "sensitive personal information" includes the categories above and may additionally cover government-issued identifiers, account log-in and financial account credentials, precise geolocation, contents of mail and communications, and certain other categories defined by the relevant law.
Where the categories already described above include sensitive personal information (for example, account credentials used for authentication, payment information you provide, or precise location when you grant permission), we process that information only as necessary to deliver the Service, for the limited purposes for which it was provided, and with the additional protections required by applicable law. Where applicable law provides this right, you may request that we limit our use of sensitive personal information as described in Section 7.
​
Sources of personal information. The categories of sources from which we collect personal information are:
​
-
Directly from you, when you create an account, make a transaction, communicate with us, or otherwise interact with the Service.
-
Automatically from your device and use of the Service, including through cookies, SDKs, server logs, and other tracking technologies.
-
From third-party authentication providers (such as Google or Apple) when you choose to sign in using their service.
-
From service providers and processors, including analytics platforms, advertising networks, payment processors, and fraud-prevention services.
-
From publicly available sources, where permitted by applicable law.
-
From other users, where applicable (for example, when another user refers you, sends you content, or names you in their account).
​
3. How We Use Your Information
We use the personal information we collect for the following purposes:
​
-
To provide, operate, and maintain the Service, including processing transactions, fulfilling orders, and providing customer support.
-
To create and manage your account.
-
To communicate with you about your account, the Service, and any changes to our terms or policies.
-
To send you marketing communications, where permitted by applicable law and subject to your preferences.
-
To improve the Service, develop new features, and conduct research and analytics.
-
To detect, investigate, and prevent fraud, security incidents, and other prohibited or illegal activities.
-
To comply with our legal obligations, enforce our agreements, and protect our rights and the rights of others.
Marketing communications. Where we send you marketing communications, we obtain consent or rely on legitimate interests as permitted by applicable law. You can opt out of marketing communications at any time by:
​
-
Clicking the "unsubscribe" link in any marketing email,
-
Adjusting your communication preferences in your account settings, or
-
Contacting us using the details in Section 13.
Opting out of marketing communications does not affect transactional or service-related communications about your account or the Service.
​
4. How We Share Your Information
​
We share personal information with the following categories of recipients:
​
-
Service providers and processors who perform operational services on our behalf, such as hosting, payment processing, email delivery, customer support, and security infrastructure. These providers act only on our documented instructions and are contractually required to protect personal information.
-
Third parties and independent controllers with whom we share personal information for purposes beyond pure service delivery, such as analytics platforms, advertising networks, social media plugins, and fraud-prevention partners. These parties may process the data for their own purposes consistent with their own privacy policies.
-
Business partners and affiliates where necessary to provide a product or service you have requested.
-
Legal and regulatory authorities where required by law, court order, or to protect our legal rights, the safety of our users, or the public.
-
Acquirers or successors in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or a portion of our assets.
-
With your consent or at your direction, including when you authorize us to share information with a third party.
Disclosures in the preceding 12 months. In the 12 months before the Effective Date of this Privacy Policy, we may have disclosed the categories of personal information described in Section 2 to the categories of recipients listed above for the purposes described in Section 3. To the extent any of our disclosures qualify as a "sale" or "share" under the CCPA (as amended by the CPRA), we provide an opt-out as described in Section 7.
​
We may also disclose aggregated or de-identified information that cannot reasonably be linked back to you for research, benchmarking, or other business purposes. This information is not treated as personal information under most privacy laws.
​
Third-party links and services. The Service may contain links to, or be integrated with, third-party websites, applications, or services that are not operated by us. This Privacy Policy does not apply to those third-party services. We do not control the privacy practices of those third parties, and we encourage you to review their privacy policies before providing any personal information to them.
​
Current service providers. A current list of the key service providers and processors with whom we share personal information is available at {Vendor List URL}.
​
5. Cookies and Tracking Technologies
​
We and our service providers use cookies, pixels, software development kits (SDKs), and similar technologies to operate the Service, remember your preferences, measure performance, and personalize content.
​
-
Strictly necessary cookies are required for the Service to function and cannot be disabled in our systems.
-
Functional cookies remember your preferences and improve your experience.
-
Analytics cookies help us understand how the Service is used so we can improve it.
-
Advertising cookies may be set by us or by third parties to measure the effectiveness of advertising campaigns or to deliver relevant ads.
​
You can manage your cookie preferences through {Cookie Settings Link}. You can also configure your browser to refuse some or all cookies, though doing so may affect Service functionality.
​
For more information on online advertising opt-outs, you can visit the Network Advertising Initiative (https://www.networkadvertising.org/) or the Digital Advertising Alliance (https://www.aboutads.info/).
​
Global Privacy Control (GPC). Some browsers and browser extensions send a Global Privacy Control signal that automatically communicates an opt-out of the sale or sharing of personal information. Where required by applicable law (including California, Colorado, Connecticut, Oregon, Texas, and other US states where the law recognizes GPC as a valid opt-out signal), we treat a recognized GPC signal received from your browser or device as a valid request to opt out of the sale or sharing of personal information for that browser or device.
​
Do Not Track (DNT). Some browsers offer a Do Not Track setting that sends a signal asking websites not to track your activity. Because there is no industry-standard interpretation of DNT signals, we do not currently respond to DNT signals. We honor the Global Privacy Control signal described above, which offers more durable protection. You can also use browser-level controls (such as blocking third-party cookies) for additional protection.
6. Data Retention
​
We retain personal information for as long as necessary to provide the Service, to comply with our legal and contractual obligations, to resolve disputes, and to enforce our agreements. The retention period for each category of personal information is determined by the purpose for which it was collected, applicable legal or regulatory requirements, and, where neither applies, the criteria below.
​
Retention schedule.
​
-
Account profile and credentials are retained for the duration of your account, plus 30 days for backups and account-recovery requests.
-
Transaction and billing records are retained for 7 years, or longer where required by applicable tax, accounting, or financial regulations.
-
Support and communication history is retained for 2 years after your last interaction with us.
-
Usage, analytics, and product telemetry is typically retained for 14 to 26 months, unless aggregated or anonymized.
-
Marketing consent and preference records are retained until you withdraw consent, plus a reasonable period to evidence the basis for past processing.
-
Cookies and online identifiers are retained as described in Section 5; expiration varies per cookie.
-
Security and fraud-prevention logs are retained for up to 12 months from the event, unless a longer period is necessary to investigate or comply with a legal obligation.
-
Legal-hold records are retained for the duration of any legal hold imposed by a regulator, court, or in-house legal team.
​
When personal information is no longer required, we delete or anonymize it so it can no longer be associated with you. Where deletion is not technically feasible (for example, in encrypted backups), we isolate the data and prevent any further processing until deletion is feasible.
​
7. Your Rights
​
Depending on where you live, you have some or all of the following rights over your personal information.
​
If you are in the United States (CCPA/CPRA and similar state laws):
​
-
Know and access - the categories and specific pieces of personal information we collected, the sources, the purposes, and the categories of third parties we disclose to.
-
Delete - deletion of personal information we collected from you, subject to legal exceptions.
-
Correct - correction of inaccurate personal information.
-
Opt out of sale or sharing - to direct us not to sell or share your personal information, including for cross-context behavioral advertising.
-
Limit the use of sensitive personal information - to restrict use of sensitive data (such as precise geolocation, health information, or account credentials) to what is needed to provide the Service.
-
Non-discrimination - we will not deny service, charge different prices, or provide a different quality of service because you exercised a right.
-
Appeal - if we deny a request, you may appeal; we respond within the time your state law allows. This right applies in Colorado, Connecticut, Virginia, and other US states.
​
We respond within 45 days, with one 45-day extension where reasonably necessary. We offer at least two methods to submit requests and may verify your identity first.
​
Privacy choice links. You can exercise these choices directly:
​​
-
Do Not Sell or Share My Personal Information: {Do Not Sell Link}
-
Limit the Use of My Sensitive Personal Information: {Limit Sensitive PI Link}
-
Your Privacy Choices: {Privacy Choices Link}
-
Cookie Settings: {Cookie Settings Link}
​
To exercise any right, contact us through the designated channels in Section 13. We may need to verify your identity before responding, and you may authorize an agent to submit a request on your behalf.
​
8. International Transfers
​
We are based online and may process the personal information we collect in countries other than your own. This means your information may be transferred to and processed in jurisdictions whose data protection laws differ from those of your home country.
​
Because we operate in the United States, we store and process personal information there and in other countries where our service providers operate. We protect that information consistent with this Privacy Policy and require our service providers to apply comparable safeguards, wherever the information is processed.
​
9. Children's Privacy
​
The Service is not directed at children under the age of 13, and we do not knowingly collect personal information from children below that age. If we become aware that we have collected personal information from a child without verifiable parental consent, we will delete that information promptly. If you believe a child has provided personal information to us, please contact us at privacy@thesugarskullcollective.com.
​
Where the Service is directed at or intended to be used by children under the age threshold that applies in your jurisdiction, we collect personal information from a child only after obtaining verifiable parental consent. We use commercially reasonable verification methods consistent with applicable law, limit the information we collect from a child to what is reasonably necessary for the child to participate in the Service, do not condition a child's participation on the disclosure of more personal information than is reasonably necessary, and give parents the right to review their child's personal information, to direct us to delete it, and to refuse further collection or use of it by contacting us at privacy@thesugarskullcollective.com.
​
10. Security
​
We implement reasonable technical and organizational measures designed to protect personal information from unauthorized access, disclosure, alteration, and destruction. Examples of the measures we maintain include encryption of personal information in transit and at rest, role-based access controls, multi-factor authentication for administrative access, regular security awareness training for personnel, vendor due diligence, and incident response procedures.
​
If we become aware of a personal data breach affecting your personal information, we will notify the relevant authorities and affected individuals as required by applicable law, without undue delay and within the timeframes the law prescribes.
​
However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential and for notifying us promptly of any unauthorized access to your account.
​
11. Changes to This Policy
​
We may update this Privacy Policy from time to time. When we make non-material changes (such as clarifying language, correcting typographical errors, or updating internal references), we will update the "Last Updated" date at the top of this Policy without separate notice.
​
When we make material changes (including new categories of personal information collected, new processing purposes, new categories of recipients, expanded data sharing, or changes that affect your rights), we will provide notice through one or more reasonable methods, such as: (a) prominent in-product banners or modals, (b) email to the address associated with your account, (c) login-time clickwrap re-acceptance, or (d) other channels reasonably calculated to bring the change to your attention. We will give you at least 30 days' advance notice of material changes before they take effect, unless a shorter period is required by law or the change is required to address an urgent legal or security matter.
​
Your continued use of the Service after the effective date of a change constitutes your acceptance of the revised Policy, except where applicable law requires us to obtain your fresh consent, in which case continued use alone is not sufficient and we will seek your active re-acceptance.
​
Prior versions of this Policy are available on request by contacting us using the details in Section 13.
​
12. Additional Jurisdictional Provisions
​
The provisions below apply only to residents of the jurisdictions named. Delete any subsection that does not apply to your operations before publishing.
​
Other US states. In addition to the rights described above for California, Colorado, Connecticut, and Virginia, where required by applicable state law, residents of other US states with comprehensive privacy laws (including Texas, Oregon, Delaware, New Hampshire, New Jersey, Maryland, Minnesota, Indiana, Iowa, Tennessee, Montana, and similar jurisdictions) may have some or all of the following rights: to access, correct, delete, and port personal information; to opt out of certain processing such as targeted advertising, the sale of personal information, or profiling that produces legal or similarly significant effects; and to appeal a denied request. The specific scope of these rights varies by state law. You may lodge a complaint with the Attorney General of your state.
​
California "Shine the Light." California residents may request, once per year and free of charge, information about the categories of personal information we disclosed to third parties for their direct-marketing purposes in the preceding calendar year, along with the names and addresses of those third parties. To make a request, contact us using the details in Section 13. We do not share personal information with third parties for their own direct marketing unless you have opted in.
​
13. Contact Us
​
If you have questions about this Privacy Policy or our privacy practices, or to exercise any of the rights described in Section 7, please contact us at:
The Sugar Skull Collective
{Mailing Address}
Email: privacy@thesugarskullcollective.com
California toll-free number (if required by law for your business): {Toll-Free Number}
Data Protection Officer / Privacy Lead (if applicable): Amber, privacy@thesugarskullcollective.com, (608) 315-2399
We will acknowledge receipt of your request and respond within the statutory deadlines described in Section 7.