Below is a comprehensive, WordPress-ready Privacy Policy you can paste into a page at staging2.tellthebees.garden/. Replace bracketed items (e.g., [email], [address], [plugin name]) with your details and delete any optional sections that don’t apply.


Privacy Policy

Last updated: August 1, 2025

We respect your privacy. This policy explains what data we collect on staging2.tellthebees.garden/, why we collect it, how we use it, and the choices you have.


Who We Are

Website: https://tellthebees.garden/
Contact: hello {at} staging2.tellthebees.garden/


What Personal Data We Collect and Why

We collect only what we need to provide our services, operate this website, secure it, and understand how it’s used.

1) Site Accounts and Profiles (if enabled)

  • Data: Name, email, password (hashed), optional profile details.
  • Purpose: Account creation, authentication, customer service.
  • Legal basis (EEA/UK): Contract; Legitimate interests (site operation); Consent where applicable.

2) Purchases & Order Data (if you run a store)

  • Data: Name, billing/shipping address, email, phone, order items, IP, and payment confirmations from processors (we do not store full card numbers).
  • Purpose: Fulfillment, fraud prevention, tax/accounting.
  • Legal basis (EEA/UK): Contract; Legal obligation; Legitimate interests (fraud prevention).

3) Payments

  • Processors: [Stripe/PayPal/Other].
  • Note: Payment details are processed by the provider under their policies. See: [Stripe Privacy URL], [PayPal Privacy URL].

4) Contact Forms & Inquiries

  • Data: Name, email, message content, attachments, IP, timestamp.
  • Purpose: Responding to inquiries and support.
  • Legal basis (EEA/UK): Consent; Legitimate interests (responding to you).

5) Newsletter / Email Marketing (if used)

  • Provider: [Mailchimp/ConvertKit/Other].
  • Data: Email, name, engagement metrics.
  • Purpose: Send updates you request; manage subscriptions.
  • Legal basis (EEA/UK): Consent (opt-in); Legitimate interests (unsubscribe logs).

6) Comments (if enabled)

  • Data: Comment text, name, email, site (optional), IP, user agent; an anonymized string may be provided to the Gravatar service to check if you use it.
  • Purpose: Publish comments, prevent spam.
  • Third parties: Gravatar may show your profile image after approval. Their privacy policy: https://automattic.com/privacy/
  • Legal basis (EEA/UK): Consent; Legitimate interests (community moderation).

7) Media Uploads (if enabled)

  • Avoid uploading images with embedded location data (EXIF/GPS). Visitors can download and extract location data from images on the site.

8) Cookies

Essential WordPress cookies

  • Login/Account: Set when you log in to remember your session and display your preferences.
  • Comments: If you leave a comment, you may opt-in to saving your name, email, and site in cookies for convenience.

Analytics & performance cookies (if enabled)

  • Provider: [Google Analytics 4/Matomo/Other].
  • Data: Pseudonymous identifiers, IP (may be truncated), device/browser info, pages viewed, events.
  • Purpose: Understand usage and improve the site.
  • Controls: You can opt out via our banner or your browser settings.

Marketing cookies (only if you use ads/retargeting)

  • Provider: [e.g., Meta Pixel/Google Ads].
  • Purpose: Measure campaigns and, where applicable, personalize ads.
  • Controls: Consent banner and “Do Not Sell or Share” choices (see California rights).

9) Embedded Content from Other Websites

Articles may include embedded content (e.g., videos, images, maps). Embedded content behaves as if you visited the other site, which may collect data about you, use cookies, and monitor your interaction according to their policies.

10) Security, Anti-spam, and Performance

  • Tools: [Akismet/Cloudflare/Wordfence/Other].
  • Data: IP addresses, request URLs, headers, device info, site activity needed to detect and block malicious traffic.
  • Purpose: Site security, uptime, performance.

Who We Share Your Data With

We share data only with service providers who help us deliver the site and services, under contracts that protect your information:

  • Hosting & Infrastructure: [Host/CDN]
  • Email & Marketing: [Mailchimp/Other]
  • Payments: [Stripe/PayPal/Other]
  • Analytics: [Google/Matomo/Other]
  • Security/Anti-spam: [Akismet/Cloudflare/Wordfence]
  • Shipping/Logistics (if store): [Carrier/Fulfillment partner]

We do not sell personal data. If you use marketing/retargeting tools, see California Privacy Rights regarding “sell or share” definitions.


How Long We Retain Your Data

  • Accounts: While the account is active; backups may persist for [X] days.
  • Orders & Tax Records: Up to 7 years (legal obligation).
  • Contact Form Entries: Up to [24] months or until resolved.
  • Newsletter Data: Until you unsubscribe or request deletion.
  • Comments: Indefinitely unless you request removal.
  • Analytics: Kept for [14/26/38] months (configure with your provider).
  • Security Logs: Typically [90] days unless needed for investigation.

Your Rights

If You Are in the EEA/UK

You may have the right to access, correct, delete, restrict processing, object, and data portability. Where processing is based on consent, you can withdraw it at any time.

California Privacy Rights (CCPA/CPRA)

California residents can:

  • Request to know the categories and specific pieces of personal information collected.
  • Request deletion of personal information (subject to exceptions).
  • Request correction of inaccurate information.
  • Opt out of the sale or sharing of personal information, and limit the use of sensitive personal information where applicable.
    Use our “Do Not Sell or Share My Personal Information” link (if applicable) or contact us.

Exercising Your Rights

Email with your request. We may verify your identity and, if needed, ask for additional details to process the request. Authorized agents may act on your behalf under applicable law.


Where Your Data Is Processed

We operate in [United States] and may transfer data to service providers in other countries. Where required, we use safeguards such as Standard Contractual Clauses or equivalent mechanisms.


How We Protect Your Data

  • HTTPS across the site.
  • Access controls and least-privilege practices.
  • Regular updates and security monitoring.
  • Vendor due diligence and data processing agreements.
    No method is 100% secure, but we work to protect your information.

Data Breach Procedures

If we become aware of a data incident affecting your personal information, we will investigate, mitigate risk, notify affected users and/or regulators when required, and take corrective steps.


Automated Decision-Making and Profiling

We do not make decisions with legal or similarly significant effects based solely on automated processing. If we introduce such features, we will describe them here and provide choices as required by law.


Children’s Privacy

This site is not intended for children under 13 (or the age required by your jurisdiction). We do not knowingly collect data from children. If you believe a child has provided personal data, contact us to request deletion.

Changes to This Policy

We may update this policy to reflect changes in our practices or for legal reasons. Revisions will be posted here with a new “Last updated” date. Material changes may also be communicated by notice on the site.

WordPress-Specific Notes

WordPress may set the following cookies and behaviors:

  • Comment convenience cookies: If you leave a comment, you may opt-in to saving your name, email, and website in cookies for one year.
  • Login cookies: Temporary cookies determine if your browser accepts cookies; additional cookies keep you logged in and record your screen display choices.
  • Embedded services: Plugins and embeds (e.g., YouTube, Vimeo, Maps) may set their own cookies and collect usage data according to their policies.
  • Spam detection: Comments and form submissions may be checked through an automated spam detection service such as Akismet.