1. Introduction
At Blooming Joy Flower Company, we respect your privacy and are committed to protecting your personal information. This Privacy Policy outlines how we collect, use, and safeguard your data.
2. Information We Collect
- Personal information such as name, email, phone number, and address when you choose to provide it.
- Payment details when needed to process a transaction.
- Website usage information such as pages viewed, visit times, referral source, campaign tags, entry and exit pages, device, operating system and browser details, browser language and time zone, screen and viewport size, browser-reported device capabilities, connection hints when the browser provides them, scroll depth, active reading time, headings or sections reached, aggregate click or tap position, link and call-to-action interactions, dead-click or repeated-click signals, copy actions without the copied text itself, form visibility and progress events without the contents typed into form fields, and real-user page performance measurements such as response, rendering, interaction, layout-shift, transfer-size, and load timing.
- Network information including the public IP address observed by our server, an encrypted copy of that IP for a limited retention period, one-way network identifiers, approximate IP-based location, autonomous system number (ASN), and internet provider or network organization when available. IP-based location is approximate and may identify the location of an internet provider, mobile gateway, proxy, VPN, or relay rather than a person's physical location.
- A random first-party visitor identifier used to recognize the same browser across visits and build a website activity profile. The site also creates first-party continuity signals from browser-reported characteristics such as operating system, browser family, screen characteristics, language, locale, time zone, touch and pointer capabilities, graphics renderer information, selected device capability hints, and browser request characteristics. A random first-party browser continuity token may also be stored in this site's first-party browser storage (including local storage and, where available, IndexedDB as a same-origin recovery copy) and sent to our server in one-way protected form so separate visitor profiles from the same browser can be recognized more reliably. These signals are not hardware identifiers and may change. First-party identity and continuity signals may also be used to recognize when multiple browser profiles likely represent the same visitor so aggregate analytics are not distorted by profile splits. Raw profiles carrying the same random first-party Blooming Joy browser continuity token may be grouped into a reversible browser-continuity record for analytics reporting when there is no contradictory submitted-contact context. This token indicates the same site-local browser storage context; it does not verify the identity of the human using that browser. Submitted names, email addresses, phone numbers, and other form values are treated as provided contact information and supporting context, not proof of identity. Raw browser activity remains separately recorded underneath that reporting layer, and similarities such as submitted contact details, IP address, network, device, browser request characteristics, location, or behavior are used only as supporting or possible-match evidence rather than automatically combining separate browser contexts. When several independent signals strongly align, we may place separate browser contexts into an evidence-only probable-device cluster using factors such as compatible device and operating-system characteristics, network continuity, request characteristics, a close chronological or page-journey handoff, or repeated compatible evidence that recurs across separate visits and network environments over time. A probable-device cluster does not merge visitor identities, does not change visitor counts, is not a hardware identifier, and is not proof that the contexts came from the same physical device or person. If you submit a contact or partnership form, the information you provide may be associated with the browser profile that submitted it so we can understand the website journey that led to the inquiry.
3. How We Use Your Information
- To process orders and payments.
- To improve our website and customer experience.
- To send promotional emails if you opt in.
4. Sharing of Information
We do not sell your personal information. We use service providers when necessary to operate the website and business. For IP-based location and network enrichment, the website server may send a visitor's public IP address to an IP intelligence provider solely to obtain approximate location and network information. Other service providers may include payment processors and shipping companies when applicable.
5. Data Security
We implement security measures to protect your personal information from unauthorized access.
6. Cookies and Tracking
Our website uses first-party analytics processed by our website server. A persistent first-party visitor cookie may remain for up to two years so we can recognize returning browsers, measure sessions and engagement, understand visitor journeys, and attribute inquiries to website activity. We also classify traffic as likely human, uncertain, or automated using signals such as crawler identifiers, JavaScript execution, trusted interactions, engagement, browser automation indicators, request speed, and suspicious request paths. We may measure page-level reading activity, section reach, aggregate click positions, form-stage progress, browser-reported site performance, device characteristics, and network characteristics so we can understand content performance, improve usability, and recognize likely continuity between anonymous visits. The server records the public IP address it directly observes through the trusted hosting proxy path. Exact IP values are encrypted at rest and are retained for a limited period, currently up to 90 days, while one-way network identifiers and derived approximate location or network information may remain with the analytics profile for the normal analytics retention period. We may use a server-side IP intelligence service to derive approximate city, region, country, postal area, time zone, latitude/longitude, ASN, and internet provider information. This information is approximate and may reflect an internet provider, mobile network, proxy, VPN, or relay rather than a visitor's exact physical location. First-party device, request, browser-storage, and environment signatures may be created from browser-reported characteristics to help identify likely split profiles and, when multiple independent signals align either closely in time or repeatedly across separate retained visits and network environments, to create evidence-only probable-device clusters across isolated browser contexts. These clusters do not merge identities or alter visitor counts. These signals are not an IMEI, serial number, MAC address, UDID, or other hardware identifier, and a probable-device assessment is not hardware-level proof. The browser-storage continuity token is random, limited to this site, and stored server-side only as a one-way protected identifier. When you use a Blooming Joy share or copy-link control, the site may create a random first-party share identifier and add it to the shared URL so we can measure whether that specific shared link is opened later. The raw random share token is not retained in the analytics database; the server retains a one-way protected token reference, the page that was shared, the share method available to the website (for example, native share or copy link), and aggregate downstream activity such as human opens, completed reads, or inquiries. Automated link-preview fetches are kept separate from human downstream visits. A native operating-system share sheet does not tell this website which app you selected or who received the link, and Blooming Joy does not attempt to identify the recipient from the share action. Browsers sending Global Privacy Control do not receive a tracked share token. We do not store copied text, form-field contents, or passwords in analytics. We do not use Google Analytics or third-party advertising trackers. Browsers that send a Global Privacy Control signal are excluded from visitor profiling. When GPC is enabled, a contact or partnership form you choose to submit is still delivered, but the submission is not attached to an analytics visitor profile and does not create an analytics conversion event. Clearing this site's cookies resets the cookie-based visitor identifier, but a separate first-party browser continuity token in this site's first-party website storage may remain until the site's stored website data is also cleared. Essential cookies are also used for restricted administrative features.
Device-continuity evidence. Analytics may record viewport and orientation history, safe-area geometry when exposed by the browser, graphics capability limits, transport-stack fingerprints supplied by Blooming Joy's trusted reverse proxy, and short-lived one-way protected connection or TLS-resumption lineage signals generated by that trusted edge. These lineage signals are opaque edge metadata rather than raw TLS tickets, keys, or other protocol secrets and are retained for a substantially shorter period than the main analytics history. All of these signals are supporting evidence only, are not hardware identifiers, and do not automatically merge separate browser contexts.
Rapid ephemeral-session adjustment. Analytics may detect a rapid sequence of at least four newly created, short-lived browser contexts when each context contains one brief session, the resets occur within seconds, and strong device/request or authenticated edge-continuity evidence persists across the entire sequence. This is intended to reduce obvious Private Browsing or other ephemeral-storage churn from inflating the adjusted unique-visitor metric. The underlying raw and resolved profiles remain stored and auditable, the contexts are not merged into one identity, and ordinary longer visits or weaker similarity are not suppressed by this adjustment.
7. Your Rights
You can request access, correction, or deletion of your personal data by contacting us.
8. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page.
9. Contact Information
For privacy-related inquiries, please contact us at kara@bloomingjoyflowerco.com.