PRIVACY POLICY

1. INTRODUCTION

2. INFORMATION WE COLLECT

2.2 Information Collected Automatically

3. BIOMETRIC DATA AND FACIAL INFORMATION

3.1 What We Process

3.2 How Biometric Data is Used

3.3 Third-Party AI Processing (Google Gemini)

3.4 Image Storage on Our Servers

  • Uploaded images are stored on our servers for the duration of your Account to enable you to access your content library, reorder Products, and manage your previously generated coloring pages
  • Generated Output (sketch-style coloring pages) is also stored on our servers for the duration of your Account
  • You may delete individual images or your entire content library at any time through your Account settings
  • Upon Account termination (whether by you or by us), all stored images and Generated Content will be permanently deleted from our active servers within thirty (30) days
  • Backup copies may persist in encrypted backups for up to ninety (90) days after deletion from active systems, after which they are permanently purged

3.5 Consent for Biometric Data Processing

Where required by applicable law (including but not limited to the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act, and Washington’s biometric privacy provisions), we will obtain your informed, written consent before collecting, capturing, or otherwise obtaining your biometric data. You have the right to refuse consent, although this will prevent you from uploading images containing human faces. We will not sell, lease, trade, or otherwise profit from your biometric data, except as required to provide the Services.

3.6 Third-Party Images and Consent

If you upload images depicting identifiable individuals other than yourself, you represent and warrant that you have obtained express, informed consent from each such individual for the upload, AI processing, and use of their image and any biometric data as described in this Policy. You are solely responsible for obtaining such consent and agree to indemnify Coloring Me Happy against any claims arising from your failure to do so.

4. HOW WE USE YOUR INFORMATION

  • To create, maintain, and secure your Account
  • To process your uploaded images through Google’s Gemini AI to generate sketch-style coloring pages
  • To compile Generated Content into coloring books and calendars as selected by you
  • To process, manufacture, and fulfill Product orders (both digital downloads and physical shipments)
  • To process payments and prevent fraudulent transactions
  • To provide customer support and respond to your inquiries
  • To store your images and Generated Content in your Account library for ongoing access
  • To analyze usage patterns and improve the functionality, performance, and user experience of our Services
  • To develop new features, products, and services (e.g., new product types, Package options, or customization features)
  • To conduct aggregated, de-identified analytics to better understand our User base (we do not use your individual images for these purposes)
  • To send transactional communications: order confirmations, shipping notifications, digital download delivery, and Account notifications
  • To send marketing communications about our products, services, and promotions (only with your consent where required by applicable law)
  • To respond to your inquiries and provide customer support
  • To comply with applicable legal obligations, regulations, and legal processes
  • To enforce our Terms and Conditions
  • To protect the rights, property, and safety of Coloring Me Happy, our Users, and the public
  • To detect, prevent, and address fraud, security breaches, and technical issues

5. HOW WE SHARE YOUR INFORMATION

We do not sell your personal information, including biometric data, to third parties. We may share your information in the following limited circumstances:

  • Google (Gemini API): Your uploaded images are transmitted to Google’s Gemini API for AI processing. Google processes this data as a data processor under the terms of the Gemini API Additional Terms of Service.
  • Payment Processor(s): Payment card information is transmitted directly to our third-party payment processor for transaction processing and fraud detection.
  • Cloud Hosting Provider: Your Account data and stored images are hosted on our cloud infrastructure provider’s servers.
  • Printing and Fulfillment Partners: When you order physical Products, the Generated Content (sketch-style coloring pages) and your shipping information are shared with our printing and fulfillment partners to manufacture and ship your order. These partners do not receive your original uploaded photographs—only the Generated Output.
  • Shipping Carriers: Your shipping name and address are shared with shipping carriers to deliver your Products.
  • Email Service Provider: Your email address is shared with our email service provider to deliver transactional and (where you have opted in) marketing communications.
  • Analytics Providers: Aggregated and/or de-identified usage data may be shared with analytics providers to help us understand how Users interact with our Services.

These service providers are contractually obligated to process your information only on our behalf, in accordance with our instructions, and subject to confidentiality and security obligations consistent with this Policy and applicable law.

5.2 Legal Requirements

We may disclose your information if we believe in good faith that such disclosure is necessary to comply with applicable laws, regulations, or legal processes; enforce our Terms and Conditions; detect, prevent, or address fraud, security, or technical issues; or protect the rights, property, or safety of Coloring Me Happy, our Users, or the public.

5.3 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or other sale or transfer of some or all of Coloring Me Happy’s assets, your information may be among the assets transferred. We will notify you via email and/or a prominent notice on our Site of any such change in ownership.

5.4 With Your Consent

We may share your information with third parties when you have given us your explicit consent to do so.

6. INTERNATIONAL DATA TRANSFERS

Coloring Me Happy is a United States-based company, and our servers are located in the United States. If you are accessing our Services from outside the United States (including from Europe, Canada, Australia, or other jurisdictions), please be aware that your information will be transferred to, stored in, and processed in the United States. Additionally, your uploaded images are transmitted to Google’s Gemini API, which may process data in any country where Google or its agents maintain facilities.

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions by the European Commission or UK Secretary of State
  • The EU-U.S. Data Privacy Framework, UK Extension, and Swiss-U.S. Data Privacy Framework, where applicable
  • Your explicit consent, where applicable

7. DATA RETENTION

  • Account Information: Retained for the duration of your Account. Upon Account deletion, permanently erased within thirty (30) days from active systems.
  • Uploaded Images (User Content): Stored on our servers for the duration of your Account. You may delete individual images at any time. All images permanently deleted within thirty (30) days following Account termination.
  • Generated Content (Coloring Pages): Stored for the duration of your Account. Permanently deleted within thirty (30) days following Account termination.
  • Google Gemini Processing Logs: Google retains prompts and responses for up to fifty-five (55) days for abuse detection, and in-memory cache data for up to twenty-four (24) hours. These retention periods are governed by Google’s policies.
  • Transaction and Order Records: Retained for seven (7) years to comply with tax, accounting, and legal record-keeping obligations.
  • Communication Records: Retained for three (3) years for customer service and legal compliance purposes.
  • Analytics and Log Data: Retained in identifiable form for twelve (12) months, then aggregated or anonymized.
  • Backup Copies: Encrypted backups may persist for up to ninety (90) days after deletion from active systems, after which they are permanently purged.

8. DATA SECURITY

  • Encryption of data in transit using TLS/SSL protocols and encryption of data at rest using AES-256 or equivalent encryption standards
  • Secure, access-controlled cloud infrastructure with physical security measures
  • Role-based access controls limiting employee access to personal information on a need-to-know basis
  • Regular security assessments and vulnerability scanning
  • Employee training on data protection and information security best practices
  • Incident response procedures for detecting, responding to, and reporting data breaches
  • Multi-factor authentication for administrative access to systems containing personal information

While we strive to protect your personal information, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee the absolute security of your information. In the event of a data breach affecting your personal information, we will notify you in accordance with applicable law.

9. YOUR RIGHTS AND CHOICES

  • Access: Request a copy of the personal information we hold about you.
  • Correction: Request correction of inaccurate or incomplete personal information.
  • Deletion: Request deletion of your personal information and uploaded images, subject to certain legal exceptions (e.g., we may retain transaction records for tax compliance).
  • Image Deletion: You may delete individual uploaded images or your entire content library at any time through your Account settings.
  • Account Deletion: Request permanent deletion of your Account and all associated data by contacting us or through your Account settings.
  • Opt-Out of Marketing: Unsubscribe from marketing communications at any time via the “unsubscribe” link in any marketing email.

9.2 Additional Rights for California Residents (CCPA/CPRA)

  • Right to Know: Request disclosure of the categories and specific pieces of personal information collected, the sources, the business purposes, and the categories of third parties with whom it has been shared.
  • Right to Delete: Request deletion of your personal information.
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Opt-Out of Sale/Sharing: We do not sell or share your personal information for cross-context behavioral advertising. If this changes, we will provide a “Do Not Sell or Share My Personal Information” link.
  • Right to Limit Use of Sensitive Personal Information: Direct us to limit the use of sensitive personal information (including biometric data) to purposes necessary to perform the Services.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA/CPRA rights.

To exercise your rights, submit a verifiable consumer request by contacting us at the information in Section 15. We will verify your identity and respond within forty-five (45) days.

  • Right to Restriction of Processing: Request that we restrict the processing of your personal data under certain circumstances.
  • Right to Data Portability: Receive your personal data in a structured, commonly used, and machine-readable format.
  • Right to Object: Object to processing based on legitimate interests, including profiling.
  • Right to Withdraw Consent: Withdraw consent at any time without affecting the lawfulness of prior processing.
  • Right to Lodge a Complaint: Lodge a complaint with your local data protection supervisory authority.

Our legal bases for processing include: performance of a contract (to provide our Services), consent (for biometric data processing and marketing where required), legitimate interests (for analytics, security, and service improvement), and compliance with legal obligations.

9.4 Rights Under Other Jurisdictions

Users in other jurisdictions (including Virginia, Colorado, Connecticut, Texas, and other U.S. states with comprehensive privacy laws, as well as users under Canada’s PIPEDA, Australia’s Privacy Act, Brazil’s LGPD, and other applicable data protection laws) may have additional rights. We will honor all valid rights requests in accordance with applicable law.

  • Strictly Necessary Cookies: Essential for Site operation, including security, authentication, and session management. Cannot be opted out.
  • Performance and Analytics Cookies: Help us understand how Users interact with our Site (e.g., pages visited, time spent, errors). We may use services such as Google Analytics.
  • Functionality Cookies: Remember your preferences and settings, such as language and display preferences.
  • Advertising and Targeting Cookies: Used to deliver relevant advertisements and measure advertising campaign effectiveness, if applicable.

You can manage cookie preferences through your browser settings or through our cookie consent management tool (where available). Disabling certain cookies may affect functionality.

Do Not Track Signals: Our Site currently does not respond to “Do Not Track” (DNT) signals. However, we honor Global Privacy Control (GPC) signals as opt-out requests where required by applicable law.

11. CHILDREN’S PRIVACY

  • We do not knowingly collect personal information from children under 13 without verifiable parental consent
  • If we become aware that a child under 13 has created an Account or provided personal information, we will promptly delete such information and terminate the Account
  • Parents and guardians may contact us to request review, deletion, or cessation of collection of their child’s personal information

If you believe a child under 13 has provided us with personal information, please contact us immediately at the information in Section 15.

Note regarding images of minors: While our Services are restricted to Users aged 18 and over, parents and legal guardians may upload appropriate, family-oriented photographs of their children for the purpose of creating coloring books and calendars. By uploading such images, the parent or guardian represents that they have the legal authority to consent to the processing of the minor’s image as described in this Policy.

12. THIRD-PARTY SERVICES AND LINKS

  • Google Gemini API: AI image generation processing. Governed by Google’s Terms of Service and Privacy Policy.
  • Payment Processor(s): Payment processing. Governed by the processor’s own terms and privacy policy.
  • Cloud Hosting Provider: Server infrastructure and data storage.
  • Printing and Fulfillment Partners: Physical product manufacturing and shipping.
  • Shipping Carriers: Product delivery.

We are not responsible for the privacy practices of these third-party services and encourage you to review their respective privacy policies.

13. AI-SPECIFIC PRIVACY DISCLOSURES

13.1 AI Model Training

Coloring Me Happy does not use your uploaded images to train AI models. Our AI image generation is performed by Google’s Gemini API (paid tier), under which Google likewise does not use your images to train or improve its AI models. We may use aggregated, de-identified usage statistics (not your individual images) to improve our Services.

13.2 AI Processing Transparency

  • Your uploaded image is transmitted from your browser to our servers via an encrypted (TLS/SSL) connection
  • Our servers transmit the image to Google’s Gemini API via encrypted connection for AI processing
  • Google’s Gemini AI analyzes the image and generates a sketch-style coloring page version
  • The Generated Output is returned to our servers and delivered to your Account
  • Your original uploaded image and the Generated Output are stored on our servers for ongoing Account access
  • When you place an order, the Generated Output (not your original images) is transmitted to our printing and fulfillment partners

13.3 Automated Decision-Making

Our Services include automated AI processing to convert images to sketch-style illustrations. This automated processing does not make decisions that produce legal effects or similarly significant effects on Users. The AI is used solely for creative image transformation purposes.

14. CHANGES TO THIS PRIVACY POLICY

We may update this Policy from time to time. When we make material changes, we will post the revised Policy with an updated “Effective Date” and notify registered Users by email. Where required by applicable law, we will obtain your consent before changes take effect. Your continued use of the Services after the effective date of any revised Policy constitutes your acceptance of the changes.

15. CONTACT INFORMATION

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Coloring Me Happy LLC

[Street Address]

[City, State, ZIP Code]

Email: [privacy@coloringmehappy.com]

Phone: [phone number]

Website: www.coloringmehappy.com

For CCPA/CPRA requests: Submit a request via email to [privacy@coloringmehappy.com] or call [toll-free number].

For GDPR/UK GDPR inquiries: Our EU/UK representative can be reached at: [Name], [Address], [Email].

16. CALIFORNIA-SPECIFIC DISCLOSURES

16.1 Categories of Personal Information Collected

In the preceding twelve (12) months, we have collected the following categories of personal information: (A) Identifiers (name, email address, IP address, Account ID); (B) Personal information categories listed in the California Customer Records statute (billing address, shipping address, phone number); (C) Protected classification characteristics (age, for eligibility verification only); (D) Commercial information (order history, Package selection, Product preferences); (E) Biometric information (facial geometry data derived from processing uploaded images through Google’s Gemini AI); (F) Internet or other electronic network activity information (browsing history, usage data, interactions with the Site); (G) Geolocation data (approximate location from IP address); (H) Audio, electronic, visual, or similar information (uploaded photographs, AI-generated sketch coloring pages); (K) Inferences drawn from the above (user preferences, usage patterns).

16.2 Sources of Personal Information

We collect personal information from: directly from you (Account registration, image uploads, purchases, communications), automatically through your use of the Services (device data, log data, cookies), and from third-party service providers (payment processors, analytics providers).

16.3 Business Purposes for Collection

We collect and use personal information for the business purposes described in Section 4, including providing the Services, processing images through Google’s Gemini AI, manufacturing and fulfilling Product orders, processing payments, communicating with you, and ensuring security and legal compliance.

16.4 Sale and Sharing of Personal Information

We do not “sell” personal information as defined under the CCPA/CPRA. We do not “share” personal information for cross-context behavioral advertising purposes. If these practices change, we will update this Policy and provide appropriate opt-out mechanisms.

16.5 Sensitive Personal Information

We collect biometric information (facial geometry data derived from processing uploaded images) as sensitive personal information. This sensitive personal information is used solely for the purpose of providing our AI image generation Services (converting photographs to sketch-style coloring pages) and is not used or disclosed for purposes other than those permitted under the CCPA/CPRA.

16.6 Financial Incentives

We do not offer financial incentives or price or service differences related to the collection of personal information.