Privacy policy

Privacy Policy

Effective Date: September 8, 2026

Last Updated: September 8, 2026

Northaven Company ("Northaven Company", "we", "us" or "our") operates the website northavencompany.com and sells luxury timepieces and related accessories to customers in the United States and internationally.

This Privacy Policy explains what personal information we collect, how we use and disclose it, the choices and rights available to you, and how you can contact us. It is written to comply with United States federal and state privacy laws, the European Union and United Kingdom General Data Protection Regulation, and the privacy and data-protection requirements applicable to merchants on the Shopify platform.

Table of Contents

  1. Who We Are and How to Contact Us
  2. Scope of This Privacy Policy
  3. Categories of Personal Information We Collect
  4. Sources of Personal Information
  5. How and Why We Use Your Personal Information
  6. Legal Bases for Processing (EEA/UK)
  7. Cookies, Pixels and Similar Technologies
  8. Interest-Based Advertising, "Sale" and "Sharing" of Personal Information
  9. How We Disclose Personal Information
  10. Payment Processing and Financial Information
  11. Order Fulfillment, Shipping, Customs and Import Data
  12. Marketing Communications: Email and SMS
  13. Data Retention
  14. Information Security
  15. International Data Transfers
  16. Your United States Privacy Rights
  17. Your Rights Under the GDPR and UK GDPR
  18. How to Submit a Privacy Request
  19. Children's Privacy
  20. Automated Decision-Making, Profiling and Fraud Prevention
  21. Third-Party Websites, Plug-ins and Social Media
  22. Do Not Track and Global Privacy Control Signals
  23. Accessibility of This Policy
  24. Changes to This Privacy Policy
  25. Contact Us

1. Who We Are and How to Contact Us

Northaven Company is an online retailer of luxury watches and related accessories. For the purposes of applicable data protection legislation, the entity responsible for your personal information (the "data controller" under the GDPR, and the "business" under United States state privacy laws) is:

Legal entity: RONDINELLI PATRIX SILVA TOLEDO

Trading as: Northaven Company

Registered address: 11 Fernando Maurício Street, Lisbon, Lisbon 1950-447, Portugal

Website: northavencompany.com

Privacy contact e-mail: help@northavencompany.com

All privacy-related enquiries, rights requests, complaints and opt-out requests should be sent to help@northavencompany.com. We aim to acknowledge every privacy request within ten (10) business days and to resolve it within the timeframes required by applicable law.

Please read this Privacy Policy together with our Terms of Service, Shipping Policy, Refund and Return Policy, and any other notice we provide on a specific occasion when we collect or process personal information about you.

2. Scope of This Privacy Policy

This Privacy Policy applies to personal information we collect, use and disclose when you:

  • visit, browse or interact with our website and any of its subdomains;
  • create an account, save a wish list, or subscribe to notifications;
  • place an order, complete checkout, or request a return, exchange or warranty service;
  • subscribe to our newsletter, SMS programme, or promotional communications;
  • contact our customer support team by e-mail, contact form, chat or social media;
  • participate in a survey, giveaway, referral programme, review request or loyalty offer; or
  • interact with our advertising on third-party platforms.

Our online store is hosted by Shopify Inc., which provides the e-commerce platform that allows us to sell our products to you. Shopify processes personal information on our behalf as a service provider and processor, and also processes certain information as an independent controller as described in Shopify's own privacy policy. Data submitted through our store is stored on Shopify's infrastructure and secure servers, databases and applications.

This Privacy Policy does not apply to third-party websites, applications or services that we do not own or control, even where we link to them. Please review the privacy notices of those third parties before providing them with your information.

3. Categories of Personal Information We Collect

In the twelve (12) months preceding the effective date of this Privacy Policy, we have collected the categories of personal information described in the table below. The categories are presented using the classifications set out in the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the "CCPA").

Category Examples of Data Collected Collected Categories of Recipients
A. Identifiers First and last name, billing and shipping address, e-mail address, telephone number, account username, order number, IP address, device identifiers, cookie identifiers, advertising identifiers. YES E-commerce platform, payment processors, shipping and fulfillment partners, customer-service tools, marketing and analytics providers, fraud-prevention providers.
B. Customer records
(Cal. Civ. Code § 1798.80(e))
Name together with billing address, telephone number and payment card information (in truncated/tokenised form only). YES E-commerce platform, payment processors, accounting and tax advisors.
C. Protected classifications We do not intentionally collect information about race, religion, sexual orientation, disability, veteran status or similar characteristics. Age may be inferred where a customer voluntarily provides a date of birth for a gift or warranty registration. NO (except as noted) Not applicable.
D. Commercial information Products viewed, added to cart, purchased or returned; order history and value; shipping selections; refunds, exchanges and warranty claims; product reviews. YES E-commerce platform, fulfillment partners, analytics and advertising providers, review platforms.
E. Internet or network activity Pages viewed, referring and exit pages, session duration, clickstream data, search terms used on our store, browser type and version, operating system, device type, screen resolution, language and time-zone settings. YES Analytics providers, advertising networks and platforms, e-commerce platform.
F. Geolocation data Approximate location derived from IP address (country, state/region, city) and the shipping address you supply. We do not collect precise GPS geolocation. YES (approximate only) E-commerce platform, fraud-prevention providers, tax calculation providers, carriers.
G. Audio, electronic and visual information E-mails, chat transcripts, contact-form submissions and any photographs or documents you send us in support of a warranty, damage or return claim. YES Customer-service platform providers, e-commerce platform.
H. Professional or employment information Company name and business tax identifiers, where you place an order as a business or corporate gift purchaser. YES (where provided) E-commerce platform, accounting and tax advisors, carriers.
I. Education information Not collected. NO Not applicable.
J. Inferences Product and style preferences, likely interest in particular collections or price segments, purchase propensity, and audience segments used for advertising. YES Advertising and analytics providers, e-commerce platform.
K. Sensitive personal information Account log-in credentials in combination with a password. We do not collect government identification numbers, precise geolocation, racial or ethnic origin, religious beliefs, union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation. LIMITED E-commerce platform only.

Sensitive personal information. We do not use or disclose sensitive personal information for purposes other than those permitted under Section 7027(m) of the CCPA regulations — namely, performing the services you request, security and fraud prevention, and ensuring the physical safety of individuals. Accordingly, we are not required to offer, and do not offer, a separate right to limit the use of sensitive personal information. We do not process sensitive personal information for the purpose of inferring characteristics about you.

Payment card data. We never receive or store your full payment card number, expiry date or security code (CVV/CVC). That information is transmitted directly to and processed by PCI DSS compliant payment processors. See Section 10 below.

Providing personal information is voluntary, but certain information is necessary for us to enter into and perform a contract with you. If you do not provide the information marked as required at checkout — for example, your name, shipping address, e-mail address and payment details — we will not be able to process or deliver your order.

4. Sources of Personal Information

We obtain the categories of personal information described above from the following sources:

  • Directly from you — when you create an account, place an order, complete a form, subscribe to marketing, leave a review, or contact customer support.
  • Automatically from your device — through cookies, pixels, tags, software development kits, server logs and similar technologies when you browse our store.
  • From our e-commerce platform and applications — Shopify and the applications installed on our store generate order, session, checkout and abandoned-cart data.
  • From payment and fraud-prevention providers — authorisation results, risk scores, chargeback and dispute information, and address-verification results.
  • From logistics and shipping partners — tracking events, delivery confirmations, customs status and delivery exceptions.
  • From advertising and analytics platforms — aggregated campaign performance, conversion events and audience segment information.
  • From other people — for example, where someone purchases a watch as a gift and provides the recipient's name and delivery address.

5. How and Why We Use Your Personal Information

We use personal information for the following business and commercial purposes:

5.1 To provide our products and services

  • Creating and administering your customer account;
  • Processing, verifying and confirming your order and payment;
  • Calculating applicable taxes, duties and shipping charges;
  • Arranging packaging, dispatch, customs clearance and delivery of your timepiece;
  • Sending transactional messages such as order confirmations, payment receipts, dispatch notifications and tracking updates;
  • Managing returns, exchanges, refunds, repairs and warranty claims.

5.2 To communicate with you

  • Responding to your enquiries, requests and complaints;
  • Providing pre-sale advice on models, sizing, movements and authenticity;
  • Notifying you of changes to our terms, policies or the status of your order;
  • Sending service messages that are not promotional in nature.

5.3 For marketing and advertising

  • Sending newsletters, new-arrival announcements, restock alerts and promotional offers where you have consented or where permitted by law;
  • Sending abandoned-cart and browse-abandonment reminders;
  • Displaying and measuring interest-based advertising on third-party platforms and websites;
  • Building and refining custom and lookalike audiences for advertising campaigns;
  • Administering referral programmes, giveaways, surveys and loyalty offers.

5.4 For analytics, optimisation and product development

  • Understanding how visitors find, navigate and use our store;
  • Measuring the performance of pages, collections, product listings and campaigns;
  • Conducting A/B testing and improving merchandising, search and checkout;
  • Informing our assortment, pricing and inventory decisions.

5.5 For security, fraud prevention and risk management

  • Detecting, investigating and preventing fraudulent orders, payment fraud and chargeback abuse — a particular concern for high-value luxury goods;
  • Verifying identity and validating billing and shipping addresses;
  • Protecting our store, systems and customers against malicious, deceptive or illegal activity;
  • Debugging, error identification and repair of technical faults.

5.6 For legal, regulatory and compliance purposes

  • Complying with accounting, tax, customs, consumer-protection, sanctions and anti-money-laundering obligations;
  • Responding to lawful requests from public authorities, courts and regulators;
  • Establishing, exercising or defending legal claims;
  • Maintaining records of consent, opt-outs and privacy requests.

5.7 For corporate transactions

In connection with a merger, acquisition, financing, reorganisation, sale of assets, bankruptcy or similar transaction, personal information may be transferred or disclosed as part of, or during the due-diligence process for, that transaction. We will notify you as required by applicable law.

We will not use your personal information for a materially different, unrelated or incompatible purpose without first providing you with notice and, where required, obtaining your consent.

6. Legal Bases for Processing (EEA/UK)

Because our company is established in Portugal, our processing of personal information is also governed by Regulation (EU) 2016/679 (the "GDPR") and, where applicable, the UK GDPR and the Data Protection Act 2018. Where the GDPR applies, we rely on the following legal bases:

Legal Basis Processing Activities
Performance of a contract
Art. 6(1)(b)
Creating your account, processing and delivering your order, handling payments, returns, exchanges and warranty service, and providing customer support in relation to a purchase.
Consent
Art. 6(1)(a)
Sending marketing e-mails and SMS messages where consent is required, placing non-essential cookies and advertising pixels, and disclosing data to advertising partners for targeted advertising. You may withdraw consent at any time.
Legitimate interests
Art. 6(1)(f)
Preventing fraud and securing our store; analysing and improving our website and product range; direct marketing to existing customers about similar products; establishing and defending legal claims; and administering our business. We balance these interests against your rights and freedoms.
Legal obligation
Art. 6(1)(c)
Retaining invoices and transaction records for tax and accounting purposes, complying with customs and consumer-protection law, and responding to lawful requests from authorities.
Vital interests / public interest
Art. 6(1)(d)–(e)
Applied only in exceptional circumstances, such as preventing serious harm to an individual.

7. Cookies, Pixels and Similar Technologies

A cookie is a small text file placed on your device when you visit a website. We and our partners also use pixels (also called tags or web beacons), local storage, software development kits and server-side tracking. Together, we refer to these as "cookies".

7.1 Categories of cookies we use

  • Strictly necessary cookies. Required for the store to function. They maintain your session, keep items in your cart, enable secure checkout, apply discount codes, balance server load and protect against fraud and cross-site request forgery. These cookies cannot be switched off through our store.
  • Functional cookies. Remember your preferences, such as language, currency, country of delivery and recently viewed products, so that we can offer enhanced and personalised features.
  • Performance and analytics cookies. Collect information about how visitors use our store — which pages are visited, how long sessions last, where errors occur — so that we can measure and improve performance. This information is generally aggregated.
  • Advertising and targeting cookies. Set by us and by advertising networks to build a profile of your interests, deliver relevant advertising on other websites and applications, limit the number of times you see an advertisement, and measure the effectiveness of our campaigns.

7.2 Third-party cookies and tracking on our store

Depending on the applications and integrations active on our store at any given time, cookies and similar technologies may be set by service providers including, without limitation: Shopify (platform, checkout, Shop Pay and fraud analysis), Google (Google Analytics, Google Ads, Google Tag Manager), Meta Platforms (Facebook and Instagram advertising pixel and Conversions API), TikTok, Microsoft Advertising, Pinterest, Snap, Klaviyo or similar e-mail and SMS marketing platforms, customer-review platforms, live-chat and helpdesk providers, and site-optimisation tools.

7.3 Managing cookies

You can manage cookies in several ways:

  • Where a cookie banner or preference centre is displayed on our store, you may accept, reject or configure non-essential cookies at any time;
  • Most browsers allow you to block or delete cookies through their settings menu. Blocking strictly necessary cookies will prevent checkout from functioning;
  • You may opt out of many advertising cookies through industry tools such as the Digital Advertising Alliance's YourAdChoices programme (optout.aboutads.info), the Network Advertising Initiative (optout.networkadvertising.org), or the European Interactive Digital Advertising Alliance (youronlinechoices.eu);
  • Mobile devices offer controls such as "Limit Ad Tracking" (iOS) and "Opt out of Ads Personalisation" (Android).

Opt-out choices are stored in a cookie on the browser and device where you make them. If you clear your cookies, use a different browser, or use a different device, you will need to renew your choices.

8. Interest-Based Advertising, "Sale" and "Sharing" of Personal Information

We do not sell personal information for money. However, several United States state privacy laws define "sale" and "sharing" broadly to include the disclosure of personal information — including online identifiers, device identifiers and browsing activity — to advertising and analytics partners for cross-context behavioural advertising or targeted advertising, even where no money changes hands.

Disclosure under the CCPA and comparable state laws. In the twelve (12) months preceding the effective date of this Privacy Policy, we have "shared" — and, as those terms are defined by law, may be deemed to have "sold" — the following categories of personal information for cross-context behavioural advertising and targeted advertising purposes:

  • Category A: Identifiers (including cookie, device and advertising identifiers, and hashed e-mail addresses);
  • Category D: Commercial information (products viewed, added to cart and purchased);
  • Category E: Internet or other electronic network activity information;
  • Category F: Approximate geolocation data;
  • Category J: Inferences drawn from the above.

These categories were disclosed to advertising networks, social media platforms, data analytics providers and internet service platforms.

We do not sell or share the personal information of consumers we actually know to be under sixteen (16) years of age. We do not knowingly collect personal information from minors under the age of sixteen.

8.1 How to opt out

You have the right to opt out of the sale or sharing of your personal information and of targeted advertising. You may exercise that right by any of the following means:

  • Sending an e-mail to help@northavencompany.com with the subject line "Do Not Sell or Share My Personal Information";
  • Using the "Do Not Sell or Share My Personal Information" link or cookie-preferences control displayed on our store, where available;
  • Rejecting advertising and targeting cookies in our cookie banner or preference centre; or
  • Transmitting an opt-out preference signal such as the Global Privacy Control (see Section 22).

We will process opt-out requests within fifteen (15) business days of receipt, or sooner where required by law. You do not need to create an account or verify your identity to submit an opt-out request, and we will not discriminate against you for exercising this right.

9. How We Disclose Personal Information

We disclose personal information only as described in this Privacy Policy, and only to the categories of recipients set out below. We require our service providers to process personal information solely on our documented instructions, to protect it appropriately, and not to retain, use or disclose it for any purpose other than performing the services we have engaged them for.

  • E-commerce platform. Shopify Inc. and its affiliates host our store, power our checkout and provide core commerce services.
  • Payment processors and financial institutions. Providers such as Shopify Payments, Stripe, PayPal and card networks, which process transactions, perform address verification and manage chargebacks and disputes.
  • Fulfillment, logistics and shipping partners. Warehouses, fulfillment centres, freight forwarders, customs brokers and carriers such as USPS, UPS, FedEx and DHL, which require your name, delivery address, telephone number and e-mail address to deliver your order and to provide tracking.
  • Marketing and communication providers. E-mail and SMS platforms, review-request services and marketing-automation tools.
  • Advertising and analytics providers. Advertising networks, social media platforms and analytics vendors, as described in Sections 7 and 8.
  • Customer-service and helpdesk providers. Ticketing, chat and telephony platforms used to answer your enquiries.
  • Fraud-prevention, identity-verification and security providers. Vendors that help us assess order risk and protect our store.
  • Professional advisers. Accountants, auditors, insurers and lawyers, bound by duties of confidentiality.
  • Public authorities and law enforcement. Where we are required to do so by law, subpoena, court order or other legal process, or where disclosure is necessary to protect our rights, property or safety, or those of our customers or the public.
  • Acquirers and successors. In connection with a corporate transaction as described in Section 5.7.

We do not disclose your personal information to unrelated third parties for their own independent direct-marketing purposes.

10. Payment Processing and Financial Information

When you make a purchase, your payment is processed through the payment gateways integrated with our Shopify checkout. Your full payment card details are transmitted directly to the payment processor over an encrypted connection and are not stored on our systems.

All direct payment gateways used by our store adhere to the standards set by the PCI Security Standards Council (PCI DSS), a joint effort of brands including Visa, Mastercard, American Express and Discover. PCI DSS requirements help ensure the secure handling of credit card information by our store and its service providers.

Your purchase transaction data is stored only as long as is necessary to complete your order. After that is complete, your purchase transaction information is deleted from active processing systems, except where retention is required for accounting, tax, warranty, chargeback or legal purposes as described in Section 13.

If you choose a direct payment gateway to complete your purchase, the payment processor stores your data in accordance with its own privacy policy and terms of use. Certain wallets and accelerated checkout services — including Shop Pay, PayPal, Apple Pay and Google Pay — may store your payment credentials and shipping details under their own privacy policies to enable faster checkout across merchants. We encourage you to review those policies.

We may receive from our payment and fraud-prevention providers limited information such as the last four digits and brand of your card, the card issuer's country, authorisation and decline codes, address-verification results and risk scores. We use this information solely to complete your order, to prevent fraud and to manage disputes.

11. Order Fulfillment, Shipping, Customs and Import Data

Our estimated delivery time is 8 to 30 business days from the date your order is processed. To fulfil your order within that window, it is necessary for us to disclose certain personal information to our fulfillment and logistics partners.

Specifically, we share your full name, delivery address, telephone number, e-mail address, order number and a description and declared value of the goods with warehouses, freight forwarders, customs brokers and delivery carriers. This is necessary to package, dispatch, clear and deliver your timepiece, and to provide you with tracking information and delivery notifications.

Where an order is shipped across an international border, applicable customs and import legislation may require that this information — together with commercial invoice and product-classification data — be provided to United States Customs and Border Protection or to the customs authority of the destination country. We disclose such information only to the extent legally required to import and deliver your order.

Our carriers and logistics partners may process your information as independent controllers for their own delivery, network-security and compliance purposes, in accordance with their own privacy policies.

12. Marketing Communications: Email and SMS

12.1 Email marketing

With your permission, or where otherwise permitted by law, we may send you e-mails about new arrivals, restocks, offers, editorial content and other updates. Our e-mail practices comply with the CAN-SPAM Act of 2003 and, where applicable, the GDPR and ePrivacy rules:

  • We do not use false or misleading header information or deceptive subject lines;
  • Promotional messages are identified as advertisements where required;
  • Every marketing e-mail contains our valid physical postal address;
  • Every marketing e-mail contains a clear and conspicuous unsubscribe mechanism; and
  • We honour opt-out requests promptly, and in any event within ten (10) business days.

You may unsubscribe at any time by clicking the "Unsubscribe" link at the bottom of any marketing e-mail, or by writing to help@northavencompany.com. Please note that even after you unsubscribe from marketing, we will continue to send you transactional and service messages relating to your orders.

12.2 SMS and text-message marketing

Where we operate an SMS programme, participation is entirely voluntary and requires your prior express written consent in accordance with the Telephone Consumer Protection Act (TCPA) and applicable state telemarketing laws. Consent to receive marketing text messages is not a condition of any purchase.

  • Message frequency varies. Message and data rates may apply.
  • Reply STOP to any message to unsubscribe at any time.
  • Reply HELP for assistance, or contact help@northavencompany.com.
  • Carriers are not liable for delayed or undelivered messages.

Mobile telephone numbers and consent data collected for the SMS programme are not sold or shared with third parties or affiliates for their own marketing purposes. Mobile opt-in data is disclosed only to the messaging service providers that deliver messages on our behalf.

12.3 Push notifications and browser alerts

If you enable browser or push notifications, you may disable them at any time through your browser or device settings.

13. Data Retention

We retain personal information only for as long as is necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, tax, warranty or reporting requirements, and to establish, exercise or defend legal claims.

Type of Data Retention Period
Order, invoice and transaction records Up to ten (10) years from the date of the transaction, to meet accounting, tax and commercial-record obligations.
Customer account data For as long as your account remains active, and for up to twenty-four (24) months of inactivity thereafter, unless you request deletion earlier.
Customer-support correspondence Up to thirty-six (36) months from the date of the last exchange.
Marketing subscription and consent records Until you withdraw consent or unsubscribe, plus a further period sufficient to evidence compliance and to honour your suppression request.
Cookie, analytics and advertising data Typically between one (1) day and twenty-six (26) months, depending on the specific cookie or provider.
Fraud and security logs Up to twenty-four (24) months, or longer where necessary for an ongoing investigation or dispute.
Privacy-request records Twenty-four (24) months, as required by the CCPA regulations.

When personal information is no longer required, we securely delete, destroy or irreversibly anonymise it.

14. Information Security

We implement and maintain reasonable administrative, technical, organisational and physical safeguards designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures include:

  • Encryption of data in transit using TLS/SSL across our entire store;
  • Encryption of data at rest on our platform provider's infrastructure;
  • Tokenisation of payment credentials, so that we never handle full card numbers;
  • Role-based access control and the principle of least privilege for staff accounts;
  • Two-factor authentication on administrative accounts;
  • Due diligence and written data-processing agreements with our service providers;
  • Ongoing monitoring, logging and incident-response procedures.

No method of transmission over the internet or method of electronic storage is one hundred per cent secure. While we strive to protect your personal information using commercially acceptable means, we cannot guarantee its absolute security. You are responsible for keeping your account password confidential and for any activity conducted through your account.

In the event of a personal-data breach that is likely to result in a risk to your rights, we will notify you and the competent supervisory authorities and regulators without undue delay, and in accordance with applicable breach-notification laws, including United States state breach-notification statutes and Articles 33 and 34 of the GDPR.

15. International Data Transfers

We operate internationally. Personal information we collect may be transferred to, stored in and processed in countries other than your country of residence — including the United States, Canada, the European Economic Area and the United Kingdom — where our company, our platform provider and our service providers maintain operations. Data-protection laws in those countries may differ from those in your jurisdiction.

Where we transfer personal information out of the European Economic Area or the United Kingdom to a country that has not been recognised as providing an adequate level of protection, we implement appropriate safeguards, which may include:

  • The Standard Contractual Clauses approved by the European Commission (and the UK International Data Transfer Addendum, where relevant);
  • Reliance on an applicable adequacy decision, including certification of a United States recipient under the EU–U.S. Data Privacy Framework and its UK Extension, where the recipient is certified; and
  • Supplementary technical and organisational measures, such as encryption and access controls, together with transfer-impact assessments where required.

You may request a copy of the safeguards we rely on by writing to help@northavencompany.com.

16. Your United States Privacy Rights

16.1 Rights available under state privacy laws

Depending on your state of residence, you may have some or all of the following rights. We extend these rights to all United States residents as a matter of policy, regardless of whether your state has enacted a comprehensive privacy law.

  • Right to know / right of access. To request confirmation that we process personal information about you, and to obtain the categories of personal information collected, the categories of sources, the business or commercial purposes for collecting, selling or sharing, the categories of third parties to whom it is disclosed, and the specific pieces of personal information we hold about you.
  • Right to delete. To request deletion of personal information we have collected from you, subject to the exceptions permitted by law (for example, where retention is necessary to complete a transaction, detect security incidents, comply with a legal obligation, or exercise or defend legal claims).
  • Right to correct. To request correction of inaccurate personal information, taking into account the nature of the information and the purposes of processing.
  • Right to data portability. To obtain a copy of the personal information you provided to us in a portable and, to the extent technically feasible, readily usable format.
  • Right to opt out of sale or sharing / targeted advertising. As described in Section 8.
  • Right to opt out of profiling. To opt out of profiling in furtherance of decisions that produce legal or similarly significant effects concerning you. We do not currently engage in such profiling.
  • Right to limit the use of sensitive personal information. As explained in Section 3, we use sensitive personal information only for purposes that are exempt from this right.
  • Right to non-discrimination and non-retaliation. We will not deny you goods or services, charge you a different price, provide a different level or quality of service, or suggest that we will do so, because you exercised a privacy right.
  • Right to appeal. If we decline to act on your request, you may appeal our decision within a reasonable period by replying to our response or writing to help@northavencompany.com with the subject line "Privacy Appeal". We will respond in writing within forty-five (45) days, explaining the reasons for our decision. If your appeal is denied, you may contact your state Attorney General to submit a complaint.

These rights derive from comprehensive state privacy laws including, among others, the California Consumer Privacy Act as amended by the California Privacy Rights Act; the Virginia Consumer Data Protection Act; the Colorado Privacy Act; the Connecticut Data Privacy Act; the Utah Consumer Privacy Act; the Texas Data Privacy and Security Act; the Oregon Consumer Privacy Act; the Montana Consumer Data Privacy Act; the Delaware Personal Data Privacy Act; the Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Tennessee, Indiana, Kentucky and Rhode Island consumer privacy statutes; and the Florida Digital Bill of Rights, in each case as amended from time to time.

16.2 Additional notices for California residents

Notice at collection. The categories of personal information we collect, the purposes for which they are used, whether they are sold or shared, and our retention periods are set out in Sections 3, 5, 8 and 13 of this Privacy Policy, which together constitute our notice at collection.

"Shine the Light" (Cal. Civ. Code § 1798.83). California residents may request once per calendar year information regarding the disclosure of personal information to third parties for their own direct-marketing purposes. As stated in Section 9, we do not make such disclosures.

Minors under 18 (Cal. Bus. & Prof. Code § 22581). California residents under the age of eighteen who are registered users of our store may request removal of content they have publicly posted by contacting us. Removal does not ensure complete or comprehensive removal of the content from all systems.

Notice of financial incentive. From time to time we may offer a discount, promotional code or loyalty benefit in exchange for signing up to our marketing list. The value of this incentive is reasonably related to the value your personal information provides to us, calculated by reference to the expected marginal revenue attributable to subscribers, less the cost of the incentive. Participation is entirely voluntary, and you may withdraw at any time by unsubscribing.

16.3 Nevada residents

Under Nevada Revised Statutes Chapter 603A, Nevada residents may direct us not to sell certain covered information for monetary consideration. We do not sell covered information for monetary consideration. You may nonetheless submit a verified request to help@northavencompany.com.

16.4 Consumer health data (Washington and Nevada)

We do not collect, use, sell or share "consumer health data" as defined by the Washington My Health My Data Act or Nevada Senate Bill 370. We do not operate a separate consumer health data privacy policy because we do not process such data. If this changes, we will update this Privacy Policy and obtain any consent required by those statutes.

16.5 Other United States federal laws

Our practices are also designed to comply with Section 5 of the Federal Trade Commission Act (prohibiting unfair or deceptive acts or practices), the CAN-SPAM Act, the Telephone Consumer Protection Act, the Children's Online Privacy Protection Act, and applicable state unfair and deceptive trade practice, e-commerce and data-breach notification statutes.

17. Your Rights Under the GDPR and UK GDPR

If you are located in the European Economic Area, the United Kingdom or Switzerland, you have the following rights in relation to your personal information:

  • Right of access — to obtain confirmation of whether we process your data and a copy of it (Art. 15);
  • Right to rectification — to have inaccurate or incomplete data corrected (Art. 16);
  • Right to erasure — the "right to be forgotten", subject to exceptions (Art. 17);
  • Right to restriction of processing — in defined circumstances (Art. 18);
  • Right to data portability — to receive your data in a structured, commonly used, machine-readable format and to have it transmitted to another controller (Art. 20);
  • Right to object — to processing based on our legitimate interests, and an absolute right to object to direct marketing at any time (Art. 21);
  • Rights in relation to automated decision-making — not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects (Art. 22);
  • Right to withdraw consent — at any time, without affecting the lawfulness of processing carried out before withdrawal (Art. 7(3)); and
  • Right to lodge a complaint with a supervisory authority (Art. 77).

Our lead supervisory authority is the Portuguese data protection authority, the Comissão Nacional de Proteção de Dados (CNPD), Av. D. Carlos I, 134 – 1.º, 1200-651 Lisbon, Portugal (www.cnpd.pt). You may also lodge a complaint with the supervisory authority of your habitual residence or place of work. Individuals in the United Kingdom may contact the Information Commissioner's Office (www.ico.org.uk). We would, however, appreciate the opportunity to address your concerns directly before you approach a regulator.

We respond to GDPR requests within one (1) month of receipt. That period may be extended by a further two (2) months where the request is complex or where we have received a number of requests; we will inform you of any such extension within one month, together with the reasons for the delay.

18. How to Submit a Privacy Request

To exercise any of the rights described in Sections 8, 16 and 17, please send an e-mail to help@northavencompany.com and include:

  • The subject line "Privacy Request";
  • Your full name and the e-mail address associated with your account or orders;
  • Your state or country of residence;
  • A clear description of the right you wish to exercise; and
  • Any order numbers that may help us locate your records.

18.1 Verification

To protect your information, we must verify your identity before acting on a request to know, correct, delete or port data. We will generally verify your identity by matching the information you provide against information already in our records, such as your e-mail address, order history and delivery address. For requests seeking specific pieces of personal information, we apply a heightened standard of verification. We will never ask you to send us a copy of a government identity document by unencrypted e-mail, and we use information provided for verification solely for that purpose.

18.2 Authorised agents

You may designate an authorised agent to submit a request on your behalf. The agent must provide written, signed permission from you, and we may require you to verify your own identity directly with us and to confirm that you granted the agent permission, unless the agent provides a valid power of attorney.

18.3 Response times and fees

We confirm receipt of requests within ten (10) business days and respond substantively within forty-five (45) days, extendable by a further forty-five (45) days where reasonably necessary, in which case we will notify you of the extension and the reason for it. Requests are handled free of charge. We may charge a reasonable fee, or refuse to act, where a request is manifestly unfounded, excessive or repetitive, and we will explain our reasoning if we do so.

19. Children's Privacy

Our store is intended for adults. It is not directed to children, and we do not knowingly collect personal information from children under the age of thirteen (13) in accordance with the Children's Online Privacy Protection Act (COPPA), nor from individuals under the age of sixteen (16) for the purposes of sale, sharing or targeted advertising.

To place an order you must be at least eighteen (18) years old, or the age of majority in your state or country of residence, and legally capable of entering into a binding contract.

If you are a parent or guardian and believe that a child has provided us with personal information, please contact help@northavencompany.com. We will delete that information from our records promptly.

20. Automated Decision-Making, Profiling and Fraud Prevention

We use automated tools — including the fraud-analysis features of our e-commerce platform and payment providers — to assess the risk associated with an order. These tools evaluate signals such as address-verification results, the relationship between billing and shipping addresses, device and IP characteristics, order velocity and historical chargeback data.

Because luxury timepieces are a frequent target of payment fraud, an order flagged as high risk may be delayed while we carry out additional verification, or may be cancelled and refunded. No order is cancelled solely on the basis of an automated decision without the possibility of human review. If your order is affected, you may contact help@northavencompany.com to obtain human intervention, to express your point of view and to contest the decision.

We also use profiling for marketing purposes — for example, to group customers into audience segments based on browsing and purchase behaviour. This profiling does not produce legal or similarly significant effects, and you may opt out of it as described in Section 8.

21. Third-Party Websites, Plug-ins and Social Media

Our store may contain links to, or embedded content from, third-party websites, applications and services — including social media platforms, review widgets, payment providers, video players and shipment-tracking pages. Clicking a link or interacting with embedded content may allow the third party to collect data about you, including your IP address and browsing behaviour.

We are not responsible for the privacy practices, content or security of third-party services, and this Privacy Policy does not apply to them. We encourage you to read the privacy policy of every website you visit.

If you interact with us through a social media platform, that platform's privacy policy governs its collection and use of your information, and in some cases we and the platform act as joint controllers in respect of audience insights.

22. Do Not Track and Global Privacy Control Signals

Do Not Track. There is no common industry standard for interpreting "Do Not Track" browser signals, and our store does not currently respond to them.

Global Privacy Control and other opt-out preference signals. Where our store is technically able to detect an opt-out preference signal transmitted by your browser or extension — such as the Global Privacy Control (globalprivacycontrol.org) — we treat that signal as a valid request to opt out of the sale and sharing of personal information and of targeted advertising for that browser or device, as required by the CCPA, the Colorado Privacy Act, the Connecticut Data Privacy Act and other state laws that recognise universal opt-out mechanisms.

Because such signals are browser- and device-specific, we may be unable to associate them with a specific account unless you are logged in at the time. To apply an opt-out across all of your devices, please also submit a request to help@northavencompany.com.

23. Accessibility of This Policy

We are committed to making this Privacy Policy accessible to individuals with disabilities. If you use an assistive technology and have difficulty accessing or understanding any part of this Privacy Policy, please contact help@northavencompany.com and we will provide the information to you in an alternative format free of charge.

24. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, our service providers, or legal and regulatory requirements. The revised version will be posted on this page with an updated "Last Updated" date and will take effect immediately upon posting.

Where changes are material — for example, if we begin to process personal information for a materially different purpose — we will provide more prominent notice, such as an e-mail to subscribers or a banner on our store, and, where required by law, obtain your consent.

We encourage you to review this page periodically. Your continued use of our store after a revised Privacy Policy has been posted constitutes your acknowledgement of the updated terms, to the extent permitted by applicable law.

25. Contact Us

If you have any questions about this Privacy Policy, wish to exercise your privacy rights, or would like to make a complaint about how we handle your personal information, please contact us:

Northaven Company

RONDINELLI PATRIX SILVA TOLEDO

11 Fernando Maurício Street, Lisbon, Lisbon 1950-447, Portugal

E-mail: help@northavencompany.com

Website: northavencompany.com

Customer service hours: Monday to Friday, 9:00 a.m. to 6:00 p.m. (WET/WEST). We reply to all messages within 24 to 48 business hours.

This Privacy Policy was prepared for Northaven Company and reflects our data practices as of the effective date shown above. It does not constitute legal advice. We recommend that customers retain a copy for their records.