Code copied to clipboard

Privacy Policy

Effective Date: April 9, 2026  ·  Last Updated: April 9, 2026

Introduction

Privacy Policy

This Privacy Policy describes how Shoe Zero ("we," "us," or "our") collects, uses, shares, and protects your personal information when you visit shoezero.com, place an order, create an account, or communicate with us.

If you have questions or requests related to this policy, contact us at any time:

Email Team@shoezero.com
Phone +1 (857) 380-2244
Mail Shoe Zero, 14712 Arbor St, Omaha, NE 68144, United States

Your rights: You can opt out of targeted advertising and request access to or deletion of your personal information at any time. See Section 8 for advertising opt-out instructions and Section 9 for your full privacy rights.

Section 1

Information We Collect

We collect the following categories of personal information:

A. Information You Give Us Directly
Identifiers First and last name, email address, phone number, shipping address, billing address, IP address, account username
Commercial information Products purchased, customization details, order amounts, order history, items added to cart or saved to wishlist
Payment information Credit or debit card number, expiration date, and security code. Payment details are transmitted directly to our payment processors and are not stored on our servers
Account information Username, password, and saved preferences
Communications Messages you send us by email, phone, or contact form, and our replies
Design information Custom shoe designs you create or submit using our design tool
Marketing preferences Your email and SMS opt-in or opt-out choices
B. Information We Collect Automatically
Internet or other electronic network activity Pages visited, time spent on pages, links clicked, products viewed, items added to cart, searches performed on our site, referring website, and date and time of your visit
Device and browser data IP address, browser type and version, operating system, device type, screen resolution, and unique device identifiers
Location data General geographic location (city and country) derived from your IP address. We do not collect precise GPS-level location data
Inferences Profiles or inferences about your preferences, interests, or likely purchasing behavior derived from the data above
Cookie and pixel data Information collected through cookies, tracking pixels, and similar technologies (see Section 6 for the full list)
C. Information from Third Parties
Advertising platforms Audience match or event data from advertising partners such as Meta and Google, used to measure ad performance and personalize ads
Fraud prevention Device fingerprint and risk signals from our fraud detection service
Review platforms Public reviews or ratings you submit on Google or Trustpilot that reference our products or services

Sensitive personal information: We do not intentionally collect sensitive personal information, including Social Security numbers, driver's license numbers, financial account credentials, precise geolocation, racial or ethnic origin, religious beliefs, health data, biometric identifiers, or sexual orientation.

Section 2

How We Collect Your Information

Checkout and order forms When you place an order, we collect your name, address, email, phone number, and payment details
Account registration When you create an account, we collect your email address, name, and password
Email sign-up When you subscribe to our newsletter or marketing emails
SMS opt-in When you opt in to text message marketing at checkout or through a sign-up form
Custom design tool When you use our shoe designer, we store your design to fulfill your order
Contact forms and customer support When you send us a message through our website, email, or phone
Cookies and tracking technologies Automatically when you browse our website — see Section 6 for full details
Advertising pixels Through tracking pixels that report events (such as page views and purchases) back to advertising partners when you interact with our website
Section 3

Why We Collect Your Information

We collect and use personal information only for specific, disclosed purposes:

Purpose Data Used
Process and fulfill your order Name, address, email, phone, order details, payment information
Send order confirmations and shipping updates Email address, phone number, order details
Respond to customer support requests Name, email, order history, communications
Send marketing emails (with your consent) Email address, purchase history, browsing behavior
Send marketing text messages (with your consent) Phone number, purchase history
Detect and prevent fraud IP address, device data, payment information, order details
Improve our website and products Browsing behavior, device data, analytics data
Show you relevant ads on other websites and apps Browsing behavior, purchase history — shared with advertising partners.

This may constitute a "sale" or "sharing" under certain US state privacy laws. See Section 8 to opt out.

Measure ad campaign performance Conversion events, ad click data, campaign data
Comply with legal obligations (tax, accounting) Order history, payment information, billing address
Personalize email and SMS communications Purchase history, browsing behavior, engagement data

We do not use your personal information for any purpose not listed above without your prior consent.

Section 4

Who We Share Your Information With

Companies that receive your data fall into two categories. We disclose both clearly below so you know exactly who has access to your information and why.

Service Providers and Contractors

These companies process personal information on our behalf, under written contracts that prohibit them from using your data for their own purposes. They may only use your data to provide services to us.

Platform and Hosting
Shopify Inc. Our ecommerce platform. Shopify hosts our store, manages customer accounts, processes orders, and operates Shopify Payments. Data may be stored in the United States and Canada. Shopify Privacy Policy
Payment Processing
Shopify Payments / Stripe Processes credit and debit card transactions. Payment card data is transmitted directly to the processor and is not stored on our servers. Both services are PCI-DSS compliant.
Apple Pay / Google Pay Wallet-based payment processing for eligible devices.
Email and SMS Marketing
Klaviyo, Inc. Our email and SMS marketing platform. Klaviyo stores your email address, phone number (if you opted in to SMS), purchase history, and email engagement data. We have a signed Data Processing Agreement (DPA) with Klaviyo. Klaviyo Privacy Policy
OneText Our SMS messaging and conversational commerce platform. Phone numbers and messaging history are stored by OneText to facilitate text-based customer interactions.
Fraud Prevention
NoFraud Our fraud detection service. NoFraud analyzes device fingerprints, IP addresses, and order details to assess fraud risk on each transaction. It uses automated scoring to flag high-risk orders for review.
Customer Reviews
Trustpilot We may send you a review invitation email after your order ships. Trustpilot stores your email address and name to send the invitation and process your review.
SEO and Site Tools
Avada SEO (by Avada Commerce) An SEO optimization tool installed on our store. This tool may read page metadata and product data but does not collect personal information from customers directly.
PopCustoms Our custom product design tool. PopCustoms stores the shoe design files you create to enable order fulfillment of custom products.

Third Parties (Advertising and Analytics Platforms)

These companies receive certain data about your activity on our website and use it for their own purposes, including showing you ads on other platforms. Sharing data with these companies may constitute a "sale" or "sharing" of personal information under certain US state privacy laws.

You have the right to opt out of this data sharing. See Section 8.

What data advertising platforms receive when you visit our site:

Each time a tracking pixel fires on our website, it sends data directly from your browser to the advertising platform. That data typically includes your IP address, device identifier, browser type, the page you are viewing, and any event that occurred (such as viewing a product, adding to cart, or completing a purchase). Here is the specific breakdown per platform:

Meta Platforms, Inc. (Facebook / Instagram) We use the Meta Pixel. When the pixel fires, it sends Meta your IP address, device ID, browser type, pages visited, products viewed, items added to cart, and purchase information (including order value and items). Meta may use this data to show you Shoe Zero ads on Facebook and Instagram, build lookalike audiences, and measure ad campaign performance. Meta may also share this data with its own partners per its privacy policy. Meta Privacy Policy  |  Opt Out of Meta Ads
Google LLC We use Google Analytics 4, Google Ads, and Google Tag Manager. Google Analytics sends Google your IP address (anonymized), device type, browser type, pages visited, session duration, traffic source, and conversion events. Google Ads sends conversion data when you complete a purchase. We use Google Analytics Advertising Features, which means Google may use this data to personalize ads shown to you across Google Search, YouTube, and the Google Display Network. Google Tag Manager is used to load these scripts; it does not collect personal data itself. Google Privacy Policy  |  Opt Out of Google Ads
TikTok Inc. We use the TikTok Pixel. When the pixel fires, it sends TikTok your IP address, device ID, browser type, pages visited, and conversion events (add-to-cart, purchase). TikTok uses this data to measure ad performance and show you Shoe Zero ads on TikTok. TikTok Privacy Policy  |  Opt Out of TikTok Ads
Pinterest, Inc. We use the Pinterest Tag. When the tag fires, it sends Pinterest your IP address, device ID, pages visited, and conversion events. Pinterest uses this data to measure ad performance and show you Shoe Zero ads on Pinterest. Pinterest Privacy Policy  |  Opt Out of Pinterest Ads
Google Customer Reviews After a purchase, you may receive an invitation to submit a review through Google. Any review you submit is subject to Google's privacy policy. Google stores the reviewer's email address and order data.
Legal Disclosure

We may disclose personal information to government authorities, law enforcement, or legal counsel when required by law, subpoena, court order, or to protect the rights, safety, and property of Shoe Zero, our customers, or others. We will notify you when permitted by law before making such a disclosure.

Business Transfers

If Shoe Zero is involved in a merger, acquisition, or sale of all or part of our assets, your personal information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our website at least 30 days before your information is transferred and becomes subject to a different privacy policy.

Section 5

How Long We Keep Your Information

We keep personal information only as long as necessary for the purpose it was collected, or as required by law. The following are our specific retention periods by data type:

Order and transaction records 7 years from date of purchase — required for US tax and accounting compliance
Customer account data For the life of your account, plus 2 years after your last login or activity
Payment information Payment card details are not stored on our servers. Our payment processors retain transaction records per their own legal obligations
Marketing email list Until you unsubscribe. After unsubscribing, we retain your email address on a suppression list for 12 months to prevent accidental re-enrollment
SMS marketing list Until you reply STOP. After opting out, your number is retained on a suppression list for 12 months
Analytics and behavioral data 26 months (Google Analytics standard retention period)
Customer support communications 3 years from the date of the last message in the conversation
Fraud prevention records 5 years from the order date
Custom shoe design files Life of the order plus 2 years, in case you want to reorder the same design
Advertising pixel event data Retained by advertising platforms per their own policies (typically 180 days to 2 years)

When retention periods expire, we delete or permanently anonymize the data so it can no longer be linked to you.

Section 6

Cookies and Tracking Technologies

Our website uses cookies, tracking pixels, and similar technologies. Below is a complete list organized by purpose. You can opt out of non-essential tracking at any time — see Section 8 for instructions.

Essential Cookies (Cannot Be Turned Off)

These are strictly necessary for the website to work. Blocking them will prevent checkout and account access.

  • Shopping cart contents
  • Session authentication (keeping you logged in)
  • Checkout process continuity
  • Security and fraud prevention checks (NoFraud device signals)
Analytics Cookies

These help us understand how visitors use our site. The data is used to improve page layouts, navigation, and product presentation.

Google Analytics 4 Records page views, session duration, traffic sources, device type, and behavioral flows. IP addresses are anonymized before storage. Google Analytics Advertising Features are enabled, which means Google may also use this analytics data to show you personalized Google ads.
Shopify Analytics Records conversion events and store performance metrics within Shopify's platform.
Advertising and Targeting Pixels

These pixels fire when you visit pages or complete actions on our site. They transmit data to advertising platforms so they can show you relevant Shoe Zero ads elsewhere. This data sharing may constitute a "sale" or "sharing" under certain US state privacy laws.

Meta Pixel Fires on page views, product views, add-to-cart, and purchases. Sends IP address, device ID, browser type, and event data to Meta.
Google Ads Tag Fires on order completion. Sends conversion data and order value to Google Ads.
TikTok Pixel Fires on page views, add-to-cart, and purchases. Sends IP address, device ID, and event data to TikTok.
Pinterest Tag Fires on page views and purchases. Sends IP address, device ID, and event data to Pinterest.
Marketing Personalization
Klaviyo Tracks email opens, link clicks, and website visits (for subscribers) to personalize email and SMS marketing messages.
Your Cookie Controls

You can manage or block cookies through your browser settings. Blocking essential cookies will break checkout and account functionality. To opt out of advertising-specific tracking:

Section 7

Email and SMS Marketing

We send marketing emails and text messages only with your consent. Here is how each channel works:

Email Marketing
  • We send promotional emails only to customers who have opted in during checkout or through a sign-up form
  • Every marketing email includes an unsubscribe link. You can unsubscribe at any time with one click
  • We honor unsubscribe requests within 10 business days as required by the CAN-SPAM Act
  • Every marketing email includes our full business address: Shoe Zero, 14712 Arbor St, Omaha, NE 68144, United States
  • Transactional emails (order confirmations, shipping updates) are sent regardless of marketing preferences because they contain information about your order
SMS / Text Message Marketing
  • We send marketing texts only to customers who have explicitly opted in
  • To opt out of SMS marketing at any time, reply STOP to any text message from us. We will process your opt-out immediately and confirm it by text
  • Message and data rates from your carrier may apply
Section 8

Do Not Sell or Share My Personal Information

We share certain browsing and purchase data with advertising platforms (Meta, Google, TikTok, Pinterest) so they can show you relevant ads. Under certain US state privacy laws, this type of data sharing may be considered a "sale" or "sharing" of personal information, even when no money changes hands.

You have the right to opt out of this data sharing at any time. We will confirm your opt-out has been processed.

How to opt out:

  1. Global Privacy Control (GPC): If your browser has the GPC opt-out preference signal enabled, we will automatically honor it as an opt-out request for all advertising data sharing. This takes effect immediately on your visit. We honor GPC signals for all visitors, not just California residents.
  2. Email request: Email us at Team@shoezero.com with the subject line "Do Not Sell or Share My Personal Information". Include your name and the email address associated with your Shoe Zero account or order. We will confirm your opt-out by email within 15 business days of receiving your request.

Opting out means your browsing and purchase data will no longer be sent to these advertising platforms for targeting purposes. You may still see Shoe Zero ads, but they will not be based on your personal browsing behavior.

Opting out does not affect your ability to use our website, place orders, or receive transactional emails about your orders.

Consumers under 16: We do not sell or share the personal information of any consumer we know to be under 16 years of age without their affirmative authorization (or, for consumers under 13, the authorization of a parent or guardian).

Section 9

Your Privacy Rights

Depending on where you live, you have specific legal rights over your personal information. All customers may submit a request regardless of location using the contact information in Section 10.

Rights Available to All Customers
Right to know Request a copy of the personal information we hold about you
Right to delete Request that we delete your personal information. Requests are subject to legal retention requirements (for example, we cannot delete order records we are required to keep for tax purposes)
Right to correct Request that we correct inaccurate personal information
Right to opt out of email marketing Unsubscribe at any time using the link in any marketing email
Right to opt out of SMS marketing Reply STOP to any text message from us
Right to opt out of targeted advertising See Section 8
Additional Rights

In addition to the rights above, we extend the following to all customers regardless of location:

Right to detailed information You may request the specific categories and pieces of personal information we have collected about you in the past 12 months, the sources of that information, the purposes for collecting it, and the categories of third parties we have shared it with
Right to opt out of sale/sharing See Section 8
Right to non-discrimination We will not deny you service, charge you different prices, or provide a lower quality of service because you exercised a privacy right
Right to appeal If we deny your request, you may appeal by emailing Team@shoezero.com with the subject line "Privacy Rights Appeal." We will respond within 45 days
US State Privacy Laws

Several US states have enacted comprehensive privacy laws, including California, Virginia, Colorado, Connecticut, Texas, Montana, Oregon, Indiana, Kentucky, and Rhode Island. If you are a resident of one of these states, you may have additional rights under your state's law, including rights to access, delete, correct, and opt out of targeted advertising. We honor these rights as described in this policy.

Submit your request using the contact information in Section 10.

European Economic Area, United Kingdom, and Switzerland — GDPR Rights

If you are located in the EEA, UK, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR) or equivalent legislation:

  • Right to access your personal data
  • Right to rectification of inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to restriction of processing
  • Right to data portability
  • Right to object to processing based on legitimate interests
  • Right not to be subject to solely automated decision-making
  • Right to withdraw consent at any time (for processing based on consent, such as marketing emails)
  • Right to lodge a complaint with your local data protection authority
Legal Bases for Processing under GDPR
Performance of a contract Order fulfillment, shipping, customer support
Legal obligation Tax records, accounting, compliance with applicable law
Legitimate interests Fraud prevention, website analytics, security
Consent Marketing emails, SMS marketing, advertising cookies
Section 10

How to Submit a Privacy Request

To exercise any of the rights in Section 9, submit a request using any of the following methods. We accept requests by all three methods to meet legal requirements for multiple accessible contact channels:

Email Team@shoezero.com — Use the subject line "Privacy Request." Include your full name, the email address associated with your account or order, and the specific right you want to exercise
Phone +1 (857) 380-2244
Mail Shoe Zero, 14712 Arbor St, Omaha, NE 68144, United States

Before fulfilling a request, we will verify your identity to protect against unauthorized access to your information. Verification typically requires you to confirm the email address or order number associated with your account.

Response timeline:

Acknowledgment Within 5 business days of receiving your request
Fulfillment Within 45 calendar days
Extension (if needed) If we need more time (up to 45 additional days), we will notify you in writing before the initial 45-day period expires and explain why an extension is needed

We do not charge a fee for privacy requests unless they are manifestly unfounded, excessive, or repetitive. If a fee applies, we will notify you before processing.

Section 11

Children's Privacy

Our website is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13.

If we learn that we have collected personal information from a child under 13 without verifiable parental consent, we will delete that information promptly from our systems and instruct our service providers to delete it as well.

COPPA compliance (updated April 2026): In compliance with the Children's Online Privacy Protection Act (COPPA) and the FTC's updated COPPA Rule (effective June 23, 2025, compliance deadline April 22, 2026), personal information for COPPA purposes now includes biometric identifiers and government-issued identifiers in addition to names, email addresses, and device identifiers. We do not collect any such information from children.

Parental rights: If you are a parent or guardian and believe your child under 13 has provided us with personal information, you have the right to:

  • Review the personal information we have collected about your child
  • Request deletion of your child's personal information
  • Refuse further collection or use of your child's personal information

To exercise these rights, contact us at Team@shoezero.com with your child's name and any order details you are aware of.

Section 12

Automated Decision-Making

We use NoFraud, an automated fraud detection system, to screen orders for potential fraud risk. This system analyzes device fingerprints, IP addresses, billing and shipping address matching, and order patterns to assign each order a risk score. Orders flagged as high-risk may be held for manual review or cancelled without a human reviewing the specific details.

If your order was cancelled or held due to an automated fraud decision and you believe this was an error, you have the right to request human review. Contact us at Team@shoezero.com with your order number and we will review your case manually.

We do not use automated decision-making or profiling for any purpose that produces legal or similarly significant effects beyond order fraud prevention.

Section 13

Data Security

We take the following steps to protect your personal information:

Encryption in transit All data between your browser and our website is encrypted using TLS (Transport Layer Security). Our website uses HTTPS at all times
Payment card security We do not store full payment card numbers on our servers. Card data is processed directly by PCI-DSS-compliant payment processors (Shopify Payments / Stripe)
Access controls Access to personal information is limited to employees and service providers who require it to perform their job functions, governed by written agreements
Fraud detection We use automated tools to identify and block suspicious order activity before it affects customers
Vendor agreements We require all service providers handling personal data to sign Data Processing Agreements (DPAs) committing them to appropriate security practices

No system is completely secure. We cannot guarantee that unauthorized access, hacking, data loss, or breaches will never occur. In the event of a data breach that affects your personal information, we will notify you and the appropriate regulatory authorities as required by applicable law.

Section 14

Changes to This Policy

We review and update this Privacy Policy at least once per year, and whenever our data practices change. When we make updates, we will change the "Last Updated" date at the top of this page.

For material changes — meaning changes that affect what data we collect, how we use it, or with whom we share it — we will notify you by email to the address associated with your account at least 30 days before the change takes effect, and post a prominent notice on our website.

We encourage you to review this policy periodically. The most current version is always available at shoezero.com/pages/privacy-policy.

Section 15

Contact Us

For questions, concerns, or requests about this Privacy Policy or your personal information:

Shoe Zero — Privacy Contact

Mail
Shoe Zero
14712 Arbor St
Omaha, NE 68144
United States

We aim to respond to all privacy inquiries within 5 business days.