1. Overview
This privacy policy describes how Blackbird Pharma ("we", "us", "our") collects, uses and discloses your personal data when you visit blackbirdpharma.com or place an order with us. We use your personal data only to fulfil orders made through the service and to operate and improve the service. We do not sell your data, and we do not pass it to third parties for advertising or profiling.
2. Definitions
For the purpose of this policy:
- Account — a unique account created for you to access the service.
- Company — Blackbird Pharma, the operator of the service.
- Cookies — small files placed on your device by your browser, containing details of your browsing history.
- Device — any device that can access the service such as a computer, smartphone or tablet.
- Personal Data — any information relating to an identified or identifiable natural person.
- Service — the website blackbirdpharma.com, our shop, and any related online interactions.
- Usage Data — data automatically collected by the service describing how you use it (page visits, time on page, IP address, browser).
- Website — blackbirdpharma.com, accessible from this domain.
3. Data we collect
3.1 Personal data
While using the service we may ask you to provide personal data so we can identify you, contact you and ship your order. This includes:
- email address;
- first name and last name;
- phone number;
- shipping and billing address (street, city, region, postal code, country);
- usage data (see 3.2 below).
We collect this data solely to fulfil orders made through our service, communicate about those orders, and operate the service.
3.2 Usage data
Usage data is collected automatically when you use the service. It can include your device's IP address, browser type and version, the pages you visit, the time and date of each visit, the time spent on each page, unique device identifiers and other diagnostic data. When you access the service from a phone or tablet, we may also collect device type, operating system and mobile network information.
3.3 Tracking and cookies
We use cookies and similar tracking technologies to operate the service and to understand how it is being used. You can refuse all non-essential cookies through the consent banner shown on your first visit, or change your choice at any time from the "Cookie settings" link in the footer. Refusing cookies does not affect your ability to browse the catalogue or place an order. Read our Cookies policy for full details, including the categories of cookies we use and how to manage them in your browser.
4. How we use your data
Your personal data is used to:
- provide and maintain the service, including creating and managing your account;
- process and ship your orders, and to contact you about them;
- respond to your messages and support requests;
- send transactional emails (order confirmations, shipping notices, security notices);
- operate, secure and improve the service (for example, performance monitoring and fraud prevention).
We do not use your personal data for advertising or profiling. We do not sell your data. We do not voluntarily share your data with law enforcement, courts, government agencies or any other third-party institution. If we ever receive a request of that kind we will refuse it and will not action it; the only data we hold is the minimum needed to fulfil your active order, and once that order is delivered the data is permanently deleted.
5. Sharing your data
We share personal data only in the following limited situations, and only to the minimum extent required to fulfil your order:
- Service providers — shipping carriers and payment processors handle only the data they need to deliver the parcel and clear the payment (recipient name, shipping address, order amount). They are bound by confidentiality and may not use your data for any other purpose.
- Business transfers — if we are involved in a merger, acquisition or asset sale your data may be transferred. You will be notified before that happens.
We do not voluntarily share your data with law enforcement, courts, government agencies, regulators or any similar institution. Customer privacy is the entire point of how this service is built — we collect the minimum amount of data, we delete it as soon as your order is complete, and we will not hand over what little we hold to any third party that asks. If you want a copy of, or the deletion of, the data we currently hold about you, contact us using section 12.
6. Data retention
We retain personal data only for as long as is necessary for the purposes set out in this policy. Once your order is completed and any associated returns / customer-service window has passed, the personal data attached to that order is permanently deleted from our active systems. Aggregated, anonymised usage statistics may be retained longer to monitor and improve the service.
7. Security
We use industry-standard technical and organisational measures to protect your personal data — TLS in transit, hashed and salted passwords, principle-of-least-privilege access controls, and encrypted backups. No method of transmission over the internet or electronic storage is fully secure, however, and we cannot guarantee absolute security.
8. Your rights under the GDPR
If you are in the European Economic Area or the United Kingdom you have the following rights regarding your personal data:
- the right to access — request a copy of the personal data we hold about you;
- the right to rectification — correct inaccurate or incomplete data;
- the right to erasure ("right to be forgotten") — request deletion of your data;
- the right to restrict processing — limit how we use your data;
- the right to data portability — receive your data in a portable, machine-readable format;
- the right to object — object to certain processing activities;
- the right to withdraw consent — at any time, where processing is based on consent;
- the right to lodge a complaint with your local data-protection authority.
To exercise any of these rights, contact us using the details in section 12 below.
9. International transfers
Your data is processed inside the European Union by default. Where we use service providers based outside the EU, we put in place appropriate safeguards (Standard Contractual Clauses or equivalents) to ensure your data continues to receive an adequate level of protection.
10. Children's privacy
The service is not directed at people under 18. We do not knowingly collect personal data from anyone under 18, and we will promptly delete any such data on learning of it. If you believe a minor has provided us with personal data, contact us.
11. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top reflects the most recent revision. Material changes will be highlighted on the website and, where appropriate, communicated by email. Continued use of the service after a change indicates acceptance of the updated policy.
12. Contact
For privacy-related questions, requests or complaints:
- Email: info@blackbirdpharma.com
- Contact form: https://blackbirdpharma.com/contact