Privacy Policy
Last Updated: 2 February 2026
Effective Date: 2 February 2026
1. INTRODUCTION
Maria Creative Arts ("we," "us," "our," or "MCA") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you visit our website at https://maria-creative-arts-shop.fourthwall.com (the "Website") or purchase our products and services.
This Privacy Policy is intended to comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, and it applies to all users of our Website and customers located in the United Kingdom, European Economic Area, and worldwide.
By using our Website or services, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access or use our Website.
2. INFORMATION WE COLLECT
2.1 Personal Information You Provide
We collect personal information that you voluntarily provide to us when you:
- Create an account or register on our Website
- Place an order for products or commission custom artwork
- Subscribe to our newsletter or marketing communications
- Contact us with inquiries or customer service requests
- Participate in surveys, promotions, or contests
The personal information we collect may include:
- Contact Information: Name, email address, telephone number, billing address, shipping address
- Payment Information: Credit card details, billing information (processed securely through third-party payment processors)
- Account Information: Username, password, purchase history, preferences
- Commission Details: Custom artwork specifications, photographs, reference materials, and other information you provide for commissioned work
- Communications: Content of messages, emails, or other communications you send to us
2.2 Information Collected Automatically
When you visit our Website, we automatically collect certain information about your device and browsing activity, including:
- Device Information: IP address, browser type, operating system, device identifiers
- Usage Data: Pages visited, time spent on pages, links clicked, referring website addresses
- Location Data: General geographic location based on IP address
- Cookies and Tracking Technologies: Information collected through cookies, web beacons, and similar technologies (see Section 9)
2.3 Information from Third Parties
We may receive information about you from third-party platforms and service providers, including:
- Fourthwall: Our e-commerce platform provider, which processes transactions and manages our online shop
- Payment Processors: Information necessary to complete transactions
- Shipping Carriers: Delivery status and tracking information
- Social Media Platforms: If you interact with us through social media
3. HOW WE USE YOUR INFORMATION
We use the personal information we collect for the following purposes:
3.1 To Fulfill Orders and Provide Services
- Process and complete your purchases of artwork and merchandise
- Create and fulfill custom art commissions according to your specifications
- Arrange shipping and delivery of products
- Communicate with you about your orders, including order confirmations and shipping updates
- Handle returns, exchanges, and refunds
3.2 To Manage Your Account
- Create and maintain your customer account
- Authenticate your identity and prevent fraud
- Provide customer support and respond to your inquiries
- Remember your preferences and settings
3.3 To Communicate with You
- Send you newsletters, marketing materials, and promotional offers (with your consent)
- Notify you about new products, services, and special events
- Request feedback and reviews
- Respond to your questions and requests
3.4 To Improve Our Business
- Analyze Website usage and customer behavior to improve our services
- Conduct research and analytics to understand customer preferences
- Test new features and functionalities
- Monitor and prevent fraud, security breaches, and illegal activities
3.5 For Legal and Compliance Purposes
- Comply with legal obligations and regulatory requirements
- Enforce our Terms of Service and other agreements
- Protect our rights, property, and safety, and those of our customers
- Resolve disputes and enforce our legal rights
4. LEGAL BASIS FOR PROCESSING (UK GDPR)
Under the UK GDPR and the Data Protection Act 2018, we process your personal information based on the following legal grounds:
- Performance of a Contract: Processing is necessary to fulfill our contractual obligations to you when you purchase products or commission artwork
- Legitimate Interests: We process data to operate and improve our business, prevent fraud, and ensure Website security, provided your rights do not override these interests
- Consent: Where you have given explicit consent for marketing communications or certain data processing activities
- Legal Obligation: Where we must process data to comply with legal or regulatory requirements
You have the right to withdraw consent at any time where processing is based on consent.
5. HOW WE SHARE YOUR INFORMATION
We do not sell, rent, or trade your personal information to third parties for their marketing purposes. We may share your information with the following categories of recipients:
5.1 Service Providers
We share information with trusted third-party service providers who perform services on our behalf, including:
- Fourthwall: Our e-commerce platform provider that hosts our shop and processes transactions
- Payment Processors: Secure payment gateway providers (e.g., Stripe, PayPal) that handle payment transactions
- Shipping Carriers: Delivery and logistics companies that fulfill and ship orders
- Email Service Providers: Platforms that help us send newsletters and marketing communications
- Cloud Storage Providers: Services that store and secure our data
- Analytics Providers: Tools that help us understand Website usage and customer behavior
These service providers are contractually obligated to protect your information and may only use it for the purposes we specify.
5.2 Business Transfers
If MCA is involved in a merger, acquisition, sale of assets, bankruptcy, or other business transaction, your personal information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have regarding your information.
5.3 Legal Requirements
We may disclose your information if required to do so by law or in response to:
- Valid legal requests from government authorities, courts, or law enforcement
- Requests to comply with legal processes (e.g., subpoenas, court orders)
- The need to protect our rights, property, or safety, or that of our customers or the public
- The need to detect, prevent, or address fraud, security, or technical issues
5.4 With Your Consent
We may share your information with third parties when you have given us explicit consent to do so.
6. INTERNATIONAL DATA TRANSFERS
Our business is based in the United Kingdom. However, your information may be transferred to, stored, and processed in countries outside the UK and European Economic Area (EEA), including the United States, where our service providers (such as Fourthwall) may be located.
When we transfer your personal information internationally, we ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses approved by the UK Information Commissioner's Office (ICO)
- Adequacy decisions recognizing equivalent data protection standards
- Other legally approved transfer mechanisms
By using our Website and services, you acknowledge and consent to such international transfers.
7. DATA RETENTION
We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
- Account Information: Retained for as long as your account is active or as needed to provide services
- Purchase Records: Retained for 7 years for tax, accounting, and legal compliance purposes
- Marketing Communications: Retained until you unsubscribe or withdraw consent
- Commission Correspondence: Retained for the duration of the project and up to 2 years afterward for reference and dispute resolution
When we no longer need your information, we will securely delete or anonymize it.
8. RESIDENTS OF THE EEA AND UK — YOUR DATA PROTECTION RIGHTS
If you are located in the UK or the European Economic Area (EEA), the UK GDPR and the Data Protection Act 2018 (and, where applicable, the EU GDPR) give you the following rights regarding your personal information:
8.1 Right to Access
You have the right to request a copy of the personal information we hold about you.
8.2 Right to Rectification
You have the right to request that we correct any inaccurate or incomplete personal information.
8.3 Right to Erasure ("Right to be Forgotten")
You have the right to request that we delete your personal information in certain circumstances, such as when it is no longer necessary for the purposes for which it was collected.
8.4 Right to Restrict Processing
You have the right to request that we restrict the processing of your personal information in certain situations.
8.5 Right to Data Portability
You have the right to receive your personal information in a structured, commonly used, and machine-readable format and to transmit it to another controller.
8.6 Right to Object
You have the right to object to processing of your personal information based on legitimate interests or for direct marketing purposes.
8.7 Right to Withdraw Consent
Where processing is based on consent, you have the right to withdraw your consent at any time.
8.8 Right to Lodge a Complaint
You have the right to complain to the UK Information Commissioner's Office (ICO) if you believe we have not handled your personal information in accordance with the law.
Contact the ICO:
- Website: https://ico.org.uk
- Telephone: 0303 123 1113
To exercise any of these rights, please contact us using the details provided in Section 13.
9. COOKIES AND TRACKING TECHNOLOGIES
We use cookies and similar tracking technologies to collect and track information about your use of our Website and to improve your experience.
9.1 What are Cookies?
Cookies are small text files stored on your device when you visit a website. They help websites remember your preferences and understand how you use the site.
9.2 Types of Cookies We Use
- Essential Cookies: Necessary for the Website to function properly, such as enabling you to log in and make purchases
- Performance Cookies: Collect information about how you use the Website to help us improve its functionality
- Functional Cookies: Remember your preferences and settings
- Marketing Cookies: Track your browsing activity to deliver relevant advertisements
9.3 Third-Party Cookies
Our Website may include cookies from third-party services such as:
- Google Analytics (website analytics)
- Social media platforms (if you interact with social sharing buttons)
- Fourthwall platform cookies
9.4 Managing Cookies
You can control and manage cookies through your browser settings. Most browsers allow you to:
- View and delete cookies
- Block cookies from specific websites
- Block all cookies
- Delete all cookies when you close your browser
Please note that disabling cookies may affect the functionality of our Website and your ability to use certain features.
For more information about cookies and how to manage them, visit https://www.allaboutcookies.org.
10. SECURITY OF YOUR INFORMATION
We implement appropriate technical and organizational security measures to protect your personal information from unauthorized access, disclosure, alteration, and destruction. These measures include:
- Encryption of data in transit using SSL/TLS technology
- Secure storage of data with access controls
- Regular security assessments and monitoring
- Employee training on data protection and privacy
- Secure payment processing through PCI-DSS compliant payment processors
However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee absolute security.
11. CHILDREN'S PRIVACY
Our Website and services are not directed to children under the age of 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately. We will take steps to delete such information from our systems.
12. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will:
- Update the "Last Updated" date at the top of this Privacy Policy
- Post the revised Privacy Policy on our Website
- Notify you of significant changes via email or a prominent notice on our Website
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
13. CONTACT US
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Maria Creative Arts (MCA)
Email: mariacreativearts@gmail.com or contact@support.mariacreativearts.com
Website: https://maria-creative-arts-shop.fourthwall.com
For data protection inquiries or to exercise your rights under UK GDPR, please include "Data Privacy Request" in the subject line of your email.
Your privacy matters to us. Thank you for trusting Maria Creative Arts with your personal information.