Privacy Policy
Last updated: August 30, 2026
Olympus Flowers, LLC (“Olympus Flowers,” “we”) operates olympusflowers.com and delivers arrangements in Southwest Florida and Miami. This policy explains what personal information we collect, how we use it, who we share it with — including Meta (Facebook) if you accept advertising cookies — and your rights in the United States.
This also serves as our notice at collection (California and similar states). You can opt out of sharing for targeted advertising at Your Privacy Choices.
1. Information we collect
You give us: name, phone, email, delivery and billing addresses, recipient details, order notes, delivery date and time, and messages from our forms (events, funeral, weddings, holiday reminders).
Payments: Stripe, Inc. processes cards. We do not store full card numbers on our servers. Stripe is PCI-DSS compliant.
Technical and usage: IP address, browser type, pages viewed, clicks, cart, checkout start, purchases, cookie or pixel IDs, and the referring page (including fbclid or other ad click IDs if you arrive from an ad).
Location: the delivery address you type, and an approximate location from IP or the browser only to suggest your region (Miami or SWFL). That is for fulfillment, not ads, unless you accept advertising cookies.
2. How we use it
- Process, deliver, and charge for orders; send confirmations and updates.
- Handle inquiries and support.
- Prevent fraud and meet legal duties (tax, accounting, disputes).
- Our own anonymous metrics (a random ID on our server — not sold, not used for ads). If you choose essential only, that ID lasts only for the browser tab. You can also switch these metrics off entirely in Cookie settings.
- If you accept: third-party analytics and advertising — including the Meta pixel once we enable it — as described below.
3. Cookies, analytics, and advertising (including Meta)
Essential (always on): cart, language, region, account session. The site does not work properly without them.
Analytics and ads(only if you click “Accept analytics & ads” and your browser is not sending Global Privacy Control):
- Google Analytics
- Microsoft Clarity (heatmaps and session recordings — replays of how you scroll, tap, and move through pages). We instruct the recording tool to mask sensitive fields such as email, name, phone, address, and message inputs, and Stripe card fields are never visible to it.
- Meta Pixel (Facebook) — sends PageView, ViewContent, AddToCart, InitiateCheckout, Purchase, and Lead, and Meta may use that data to measure ads, retarget, and build audiences. If you enter your email address at checkout, the pixel also sends a hashed (scrambled) copy of that email address, plus a random browser identifier, so Meta can tell whether an ad it showed you led to your order. The scrambling is one-way and happens in your browser before anything is sent; we never send a hashed copy of a gift recipient’s details, only the contact information you provide about yourself. None of this happens unless you accept advertising cookies.
- TikTok or Pinterest, if we later configure those IDs.
We do not load those scripts until you accept. “Essential only” or a GPC signal stops data from going to Meta or other ad companies. You can change your mind in the footer (Cookie settings) or at Your Privacy Choices.
Cookie settings has three tiers: (1) essential — always on; (2) our own anonymous first-party statistics (a random ID, our own server, never sold or shared) — on by default, and you can switch it off entirely, which stops all of our first-party usage events for your browser; (3) advertising & analytics partners (Meta, Google Analytics, Microsoft Clarity including session recordings) — strictly opt-in, and forced off while your browser sends GPC.
4. Sharing; “sale” and targeted advertising
To fulfill an order (not advertising): Stripe, hosting and email (AWS / Resend), and delivery drivers. They should use the data only to provide that service.
We do not sell customer lists for money. If you accept ads cookies, we share identifiers and internet activity with Google, Microsoft, and similar companies — and with Meta once we enable its pixel — for targeted advertising. Under the California CPRA that is “sharing.” Other states may call it a “sale” or “targeted advertising.” You have the right to opt out. That opt-out is Do Not Sell or Share My Personal Information.
We honor Global Privacy Control (GPC) as a valid opt-out of sale/sharing, even if you previously accepted.
5. Retention
Orders and delivery details: as long as needed for fulfillment, tax, fraud, and claims (typically years, not months). Leads and reminder signups: until you unsubscribe or ask us to delete. Ad cookies: per each vendor’s settings. Our own metrics: aggregated or expired in the ordinary course of business. Coupon redemptions and other transaction records: retained with orders for tax and accounting purposes. The privacy-request trail itself (the email, IP address, and browser of each verified request) is kept for about 24 months as legally required compliance evidence. Note that third-party cookies set by Microsoft (Clarity and Bing domains) can persist in your browser after you withdraw consent; you can remove them in your browser settings by clearing cookies for clarity.ms and bing.com.
6. Your rights in the United States
Depending on your state (including California, Colorado, Connecticut, Virginia, Texas, Florida, and others), you may have the right to: know what we collect; access a copy; correct; delete; data portability; and opt out of sale, sharing, or targeted advertising. California also has a right not to be discriminated against for exercising these rights, and to limit certain sensitive information (we do not use sensitive information to infer characteristics; delivery address is for the order).
Self-serve privacy portal. The fastest way to exercise these rights is Your Privacy Choices. It is fully automatic: we verify your identity with a 6-digit code emailed to your address (only someone with access to that inbox can proceed), and verified requests are fulfilled instantly — well inside the 45-day window state laws allow. You can: export a readable copy of everything we hold for your email (orders, delivery details you provided, saved carts, inquiries, reminder signups, recovery-email history, emails we sent you, and your suppression status), delete your data, or record account-level opt-outs of ad sharing, marketing email, and SMS.
What deletion does: it erases your saved carts, event inquiries, holiday reminders, recovery-email sequences, login codes, and analytics events tied to your email, turns off all marketing and SMS consent, and places your address on a permanent suppression list so we never market to you again. Order and transaction records are retained — including the delivery details on those orders — because tax, accounting, fraud-prevention, and dispute-resolution laws require it; they are no longer used for marketing. Email send logs are reduced to redacted metadata kept as compliance evidence.
You can also email support@olympusflowers.com or call +1 (786) 822-9164. We will verify your identity (for email requests, by confirming control of the address on file). A California authorized agent may write us with signed permission. If we deny a request, you may appeal to the same email; if we still disagree, you may contact your state attorney general.
Nevada: we do not sell personal information covered by NRS 603A. To record a request anyway, use the same email.
7. Children
This site is not directed at children under 13 (COPPA). We do not knowingly collect children’s data. If you think a child sent us information, email us and we will delete it.
8. Security and international
We use reasonable safeguards (HTTPS, limited access, Stripe for payments). No system is 100% secure. Servers are in the United States. If you write us from outside the U.S., your data is processed in the U.S.
9. Changes
If we change this policy in a material way (for example, a new ad pixel), we will update the date above. Continued use after a change means the new version applies, unless the law requires a fresh consent.
10. Contact
Olympus Flowers, LLC — Florida, USA
Privacy: support@olympusflowers.com
Phone: +1 (786) 822-9164