privacy Policy

1. Introduction

Two Bears Design ("we," "us," or "our") is committed to protecting the privacy of individuals who visit our website at twobearsdesign.com and who make use of our services. This Privacy Policy explains what personal information we collect, how we use and share it, how long we retain it, and what rights you have in relation to it.

By using our website, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our website or submit any personal information to us.

2. Information We Collect

2.1 Information You Provide Directly

We collect personal information that you voluntarily provide to us when you interact with our website, including:

  • Contact Form Submissions: Your name, email address, phone number (if provided), and the content of your message when you use our contact or inquiry form.
  • Newsletter Sign-Ups: Your email address and, optionally, your name when you subscribe to our email newsletter.

2.2 Information Collected Automatically

When you visit our website, certain information is collected automatically through cookies and similar technologies:

  • Usage Data: Pages visited, time spent on each page, click patterns, referring URLs, and navigation paths.
  • Device and Browser Information: IP address, browser type and version, operating system, screen resolution, and device type.
  • Location Data: Approximate geographic location derived from your IP address.

For detailed information about the cookies we use, please refer to our Cookie Policy.

3. How We Use Your Information

We use the personal information we collect for the following purposes:

  • To Respond to Inquiries: We use your contact form submissions to respond to your questions, provide quotes, and communicate about potential or existing projects.
  • To Send Newsletters: If you have subscribed, we use your email address to send periodic newsletters containing design insights, company updates, and relevant content. Every email includes an unsubscribe link.
  • To Improve Our Website: We use analytics data to understand how visitors use our site, identify areas for improvement, and optimize performance and user experience.
  • To Measure Advertising Effectiveness: We use marketing cookies and pixels to evaluate the performance of our advertising campaigns on Google and Meta platforms.
  • To Ensure Security: We use server logs and technical data to monitor for unauthorized access, detect threats, and maintain the security of our website.
  • To Comply with Legal Obligations: We may process your data where necessary to comply with applicable laws, regulations, or legal proceedings.

4. Legal Bases for Processing (GDPR)

If you are located in the European Economic Area (EEA) or the United Kingdom, we process your personal data on the following legal bases:

  • Consent (Article 6(1)(a)): For newsletter subscriptions, analytics cookies, and marketing cookies. You may withdraw consent at any time.
  • Legitimate Interest (Article 6(1)(f)): For responding to contact form inquiries, improving our website, and ensuring website security. Our legitimate interests do not override your fundamental rights and freedoms.
  • Legal Obligation (Article 6(1)(c)): Where we are required to process data to comply with applicable law.

5. How We Share Your Information

We do not sell your personal information. We may share your information with the following categories of third parties, solely to support the purposes described in this policy:

5.1 Service Providers

We work with trusted third-party service providers who process data on our behalf. These providers are contractually obligated to protect your information and use it only for the purposes we specify.

Service - Webflow

Purpose - Website hosting and content delivery

Privacy Policy - webflow.com/legal/privacy

Service - Google Analytics

Purpose - Website analytics and visitor tracking

Privacy Policy - policies.google.com/privacy

Service - Google Ads

Purpose - Advertising and conversion tracking

Privacy Policy - policies.google.com/privacy

Service - Meta (Facebook)

Purpose - Advertising and audience measurement

Privacy Policy - facebook.com/privacy/policy

Service - Mailchimp (Intuit)

Purpose - Email newsletter delivery and management

Privacy Policy - intuit.com/privacy/statement

5.2 Legal Requirements

We may disclose your personal information if required to do so by law, in response to a valid legal request (such as a court order or subpoena), or to protect our rights, property, or the safety of our users or the public.

5.3 Business Transfers

In the event of a merger, acquisition, or sale of all or a portion of our assets, your personal information may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your personal information.

6. International Data Transfers

Your personal information may be transferred to, stored, and processed in the United States or other countries where our service providers operate. These countries may have data protection laws that differ from those in your jurisdiction. When we transfer data outside the EEA, we rely on appropriate safeguards, including Standard Contractual Clauses approved by the European Commission, to ensure an adequate level of protection for your data.

7. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. The following table summarizes our retention practices:

Data Type - Contact form submissions

Retention - 2 years

Reason - To respond to inquiries and maintain records of communications.

Data Type - Newsletter subscriber data

Retention - Until unsubscribe

Reason - Retained while you remain subscribed; deleted upon request after unsubscribing.

Data Type - Analytics data

Retention - 26 months

Reason - Google Analytics default retention period for aggregated usage data.

Data Type - Marketing/advertising data

Retention - Up to 13 months

Reason - As set by third-party advertising platforms (Google Ads, Meta).

Data Type - Server and access logs

Retention - 30 days

Reason - Webflow hosting logs retained for security and performance monitoring.

8. Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include SSL/TLS encryption for data in transit, secure hosting through Webflow, and access controls for our internal systems. However, no method of transmission over the Internet or electronic storage is completely secure, and we cannot guarantee absolute security

9. Your Rights Under the GDPR

If you are located in the European Economic Area or the United Kingdom, you have the following rights regarding your personal data:

  • Right of Access: You may request a copy of the personal data we hold about you.
  • Right to Rectification: You may request correction of inaccurate or incomplete personal data.
  • Right to Erasure: You may request deletion of your personal data, subject to certain legal exceptions.
  • Right to Restrict Processing: You may request that we limit how we process your data in certain circumstances.
  • Right to Data Portability: You may request your personal data in a structured, commonly used, and machine-readable format.
  • Right to Object: You may object to processing based on legitimate interests or for direct marketing purposes.
  • Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, please contact us at hello@twobearsdesign.com. We will respond to your request within 30 days. You also have the right to lodge a complaint with your local data protection authority.

10. Your Rights Under the CCPA

If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) provide you with the following rights:

  • Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected, the sources of collection, the business purposes, and the third parties with whom we share it.
  • Right to Delete: You may request that we delete your personal information, subject to certain legal exceptions.
  • Right to Correct: You may request correction of inaccurate personal information.
  • Right to Opt-Out of Sale/Sharing: You have the right to opt out of the sale or sharing of your personal information. We do not sell personal information in the traditional sense; however, certain cookie-based advertising activities may constitute “sharing” under the CCPA.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights.

To submit a request, please email us at hello@twobearsdesign.com. We will verify your identity before processing your request and respond within 45 days.

11. Children’s Privacy

Our website is not directed at children under the age of 16. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately at hello@twobearsdesign.com, and we will take steps to delete such information promptly.

12. Links to Third-Party Websites

Our website may contain links to third-party websites or services that are not operated by us. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party websites you visit.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the "Effective Date" at the top of this page. We encourage you to review this policy periodically to stay informed about how we protect your information.

14. Contact Us

If you have any questions or concerns about this Privacy Policy, wish to exercise your privacy rights, or need to report a data protection issue, please contact us at:

Two Bears Design

Email: hello@twobearsdesign.com

Website: twobearsdesign.com

Ready to start your growth journey

Your digital presence matters way more than you think. Don't waste any more time, drop me a message and we can get started on growing your business.

Get Started