Summer Sale — 40% OFF STORE-WIDE · SHIPS FREE WORLDWIDE
Currency
Currency
Montclair Collective

Privacy Policy

Last updated August 23, 2026 info@montclaircollective.com

Made to order, so the window to change your mind is short: you can change or cancel for 12 hours after ordering — email info@montclaircollective.com with your order number. After that it is on the press.

The short version. We collect what an order needs — your name, delivery address, email address and what you bought — and we measure how this site, our advertising and our email perform, including whether an email we sent you was opened. Analytics, advertising and session-recording tools start running the moment a page loads. Nothing is sold. To see what we hold, or to have it deleted, email info@montclaircollective.com.

Who we are

montclaircollective.com is operated by Montclair Collective, and Montclair Collective is the organisation responsible for the personal information described on this page. Where another company handles something on our behalf, it is named below rather than described vaguely as “our partners”.

Everything on this page — a question, an access request, a deletion request or a complaint — goes to info@montclaircollective.com. One inbox, answered by a person.

What we collect

  • Order details — your name, email address, delivery address, the prints and sizes you bought, the order total and the currency.
  • Payment details — card numbers are typed into our payment processor’s own hosted fields, not into a form on this site, and are not stored here. We see the billing details, the amount and whether the payment succeeded.
  • Messages — anything you send us by email, and what we send back.
  • Marketing sign-ups — your email address, an optional first name, and a record of when and how you consented, including a one-way hash of the IP address it came from. The hash lets us prove a consent exists without keeping the address itself.
  • Cart activity — what is in your bag while you shop and, if you type it at checkout, your email address, so we can send you a link back to an unfinished order. The session identifier and IP address stored alongside it are hashed, not held in the clear.
  • Whether an email we sent you was opened — the date and time an image inside one of our emails was first and last loaded, and how many times. It is stored against a one-way hash of your address and the order or bag the message was about, never against your address in the clear. There is its own section on this below, including why the figure is unreliable.
  • A review, if you write one — the name you sign it with, your email address, the rating, what you wrote and, if you attach one, a photograph. The name, the rating, the words and the photo are published on the product page. Your email address is not: it is held so we can send you the thank-you code and answer you if something is wrong. There is a section on reviews below.
  • Technical and usage data — IP address, browser and device, pages viewed, the site you arrived from, and how you moved around a page. This comes in through the tools in the next two sections.

You do not need an account to buy from us or to track an order, so there is no password and no profile for us to hold.

Why we collect it

  • To produce, pay for and deliver your order, and to help you afterwards.
  • To take payment and to reduce fraud and chargebacks.
  • To answer your messages.
  • To measure how the site and our advertising perform, and to fix what is not working.
  • To send marketing email where you have asked for it, or where the law allows it after a purchase — see the CASL section below.

We do not sell your personal information and we do not hand it to data brokers. We do share it with the advertising platforms named below so that our own advertising can be measured, and that is described in full rather than glossed over.

Cookies, analytics and advertising

These run on this site, and they start on the first page you load. There is no cookie banner on this site today, so nothing here waits for a click before it fires. If that changes, this page will say so.

  • Google Tag Manager — the container that loads several of the tools below.
  • Google Analytics 4, through Google Site Kit — how many people visit, which pages they look at, roughly where in the world they are, and which visits end in an order.
  • Meta Pixel and the Meta Conversions API — records page views, adds to bag, checkouts and purchases and reports them to Meta so our Facebook and Instagram advertising can be measured. Some of those events are sent from your browser; some are sent from our server, which is what “Conversions API” means — the event leaves our server rather than your device, so blocking scripts in the browser does not stop it.
  • Pinterest tag and the Pinterest Conversions API — the same thing for Pinterest advertising. On this site it is the server-side half that is currently sending events.
  • Microsoft Claritythis records a replay of your visit. It is the one most worth reading about, so it has its own section immediately below.

Separately from all of the above, WooCommerce sets the cookies it needs to remember your bag and carry you through checkout. Those are not tracking cookies and the shop cannot work without them.

Session recording

Microsoft Clarity records what happens inside the browser window while you are on this site and plays it back to us afterwards. That includes mouse movement, taps and clicks, scrolling, how far down a page you reached and how long you stayed. It also builds heatmaps that aggregate the same information across many visits.

We use it to find where the site is confusing or broken — a size chip that is awkward to tap on a phone, a checkout field people give up on. We are not watching individual people for the sake of it.

What it is not: it does not use your camera or your microphone, it does not see your screen outside this site, and it does not follow you to other websites. Card numbers are typed into the payment processor’s own hosted fields rather than into a form on this site, so they are not something this site is able to record.

Even so, a recording is a recording. If you would rather not be recorded, Microsoft publishes an opt-out for Clarity, and blocking this site’s third-party cookies and scripts also stops it — see “Refusing cookies” below.

Advertising click identifiers

When you arrive here from a Meta or Pinterest advertisement, the link carries an identifier for that click. This site stores it in a first-party cookie so that a later add to bag, checkout or purchase can be credited to the advertisement that brought you, instead of appearing to come from nowhere.

  • _fbc — Meta’s click identifier. Kept for 90 days, which is the click-through attribution window Meta itself documents.
  • _epik and mc_epik — Pinterest’s click identifier. Kept for 365 days, matching the one-year lifetime Pinterest documents for its own cookie.

These hold an advertising identifier issued by Meta or Pinterest. They do not hold your name, your email address or anything you typed. They are only ever written on the page you land on from an advertisement — every other page on this site writes none of them — and if your browser sends a Global Privacy Control signal, none is written at all.

We are telling you this because Canadian privacy law lets us rely on your implied consent for something like this only if we describe it. If you would rather we did not, refuse cookies as described next.

Refusing cookies

  • Your browser. Every major browser can block or delete cookies, usually under Privacy or Site settings, and can clear the ones this site has already set. Blocking third-party and advertising cookies stops the analytics, advertising and session-recording tools described above from recognising your visit.
  • Global Privacy Control. If your browser sends the Sec-GPC signal, this site treats it as an opt-out and writes no advertising click identifier.
  • At the source. Microsoft publishes an opt-out for Clarity, Google publishes an opt-out browser add-on for Google Analytics, and Meta and Pinterest each have advertising controls inside your account settings on their own platforms.

One warning worth giving plainly: blocking all cookies, rather than third-party ones, will break checkout, because WooCommerce uses a cookie to know which bag is yours. If you cannot get an order through, email info@montclaircollective.com and we will take it by hand.

Who your information is shared with

These companies process personal information on our behalf, and this is what each of them gets:

  • Gelato — print production and fulfilment. Because every print is made after you order it, Gelato receives your name, your delivery address and what you ordered, so that it can print the piece and ship it to you. There is no way to send you a print without this.
  • WooPayments — card payment. It receives the billing details and the amount, and processes the card itself.
  • FluentSMTP — the mechanism that sends this site’s email. It handles the address a message goes to and the message itself: order confirmations, shipping notices, order-recovery links and replies.
  • Google — Tag Manager, Analytics 4 and Site Kit, for usage measurement.
  • Meta — browser-side and server-side advertising measurement.
  • Pinterest — server-side advertising measurement.
  • Microsoft — Clarity, for session recording and heatmaps.
  • Our web host — this website, its orders and its database physically live on their servers.

We may also disclose information where the law requires it, or where it is needed to establish or defend a legal claim. If the business is ever sold or merged, customer records would transfer with it, and this page would be updated to say so.

Where it goes. Several of the companies above are outside Canada, so information handled by them may be stored or processed in the United States or in Europe. While it is there it is subject to the laws of that country, including lawful access by that country’s courts and authorities. Canadian privacy law requires us to tell you that, and it is not something we can contract away on your behalf.

Marketing email, and CASL

Canada’s Anti-Spam Legislation governs commercial email. It recognises two kinds of permission and we rely on both, so here is which is which.

  • Express consent — you filled in a sign-up form or ticked an unticked box and asked for our email. We record when you did it, which form it was, and a one-way hash of the IP address. Express consent lasts until you withdraw it.
  • Implied consent — you bought something. CASL allows us to email you about our own prints for two years from that purchase without a separate opt-in. We date that from the order itself, not from today, and we let it expire on its own.

Every marketing message carries a working unsubscribe link, and unsubscribing takes effect on our side immediately. You can also simply email info@montclaircollective.com and we will do it by hand. A box for marketing consent on this site is never pre-ticked — a pre-ticked box is not consent.

Order email is a different thing. A receipt, a shipping notice or a reply to your question is not marketing, and it does not stop because you unsubscribed from the list.

Unfinished orders

If you start checking out and type your email address, we save it with your bag before you submit, so that we can send you one link back to the unfinished order. You are told this beside the field, before you type, rather than afterwards.

That message is order help rather than a marketing campaign: the address is not added to any mailing list, nothing is sent to it about anything other than that one bag, and the email carries an unsubscribe that erases the address from the cart record entirely. The bag itself is stored against a hashed session identifier and a hashed IP address, never against your name.

It may carry a discount code for that bag. If it does, the code is generated for your bag alone, locked to the address you typed, valid once and dated — it is not a code we hand out, and nobody else has it. You can switch the whole thing off for good with the unsubscribe link in the message.

Knowing whether an email was opened

Emails we send you contain a single invisible image, one pixel across. When your mail program loads that image, our server records the first time it happened, the most recent time, and how many times in total, against the order or unfinished bag the message was about. We use it to see whether our email is arriving and being read at all, and to stop sending a kind of message nobody opens.

What is stored is a one-way hash of your email address, not the address itself, together with which message it was and those timestamps. No name, no address and no order number is in the image’s web address, so a message forwarded to somebody else carries nothing about you. We do not record what you clicked inside the message, we do not record where you were when you opened it, and we do not build a profile from it.

The measurement is genuinely unreliable, and it would be wrong of us to imply otherwise. Apple Mail loads that image the moment a message arrives on your device, whether or not you ever look at it — so an “open” may be your phone rather than you. Gmail stores a copy of the image, so reading a message twice often counts once. And if your mail program blocks images, as many do, reading every word of it registers as nothing at all. We treat the figure as a rough direction of travel and not as a fact about any one person.

If you would rather not be counted: turn off automatic image loading in your mail program, which every major one can do, and nothing is recorded. Unsubscribing from unfinished-order email also stops it, and you can ask us to delete what we hold at info@montclaircollective.com.

Reviews, photos and the thank-you code

About two weeks after an order is completed we send one email asking whether you would review what you bought. One, per order, ever — you are not put on a list, nothing follows it, and it carries an unsubscribe link that stops us asking you again for good.

If you write a review, the name you sign it with, the rating and your words are published on that product’s page. Your email address is not published. Every review is held for a person to read before it appears, and we do not edit what anyone writes.

If you attach a photograph, it is published too. Please only send one you are happy to have on a public web page — assume it can be seen and saved by anybody. Before it is stored we strip the metadata out of the file: the GPS coordinates a phone writes into a photo, the camera and phone model, the date and any caption the phone attached. That is done to the file itself, before it is written to our server, so those details are not kept anywhere and are not in the copy that gets published. What remains is the picture. A photo is never shown until somebody here has approved it.

We send a discount code for leaving a review, and you should know that when you read one. Once a review is approved, the person who wrote it is emailed a single-use code off a future order. It is sent for writing a review, never for a positive one — a critical review earns exactly the same code, and nothing about the code depends on the rating or on what the review says. We do not ask for changes to a review, and we do not withhold a code over one. Any review that earned a code is marked as such on the product page, so you can weigh it accordingly.

We do not write reviews ourselves, we do not buy them, and we do not import them from anywhere. Every review on this site was written by somebody who bought the print.

To have a review or a photo removed, email info@montclaircollective.com from the address you wrote it with and it will be deleted, photograph and all.

How long we keep it

  • Orders — kept for as long as tax and accounting rules require, and so that we can still help you with an old order.
  • Unfinished-cart records — deleted automatically on a timer set in the store settings. The shipped default is 90 days, and the restore link inside a recovery email dies after 7.
  • Email-open records — the hashed address, which message it was and the open timestamps, deleted automatically after 400 days.
  • Marketing contacts — kept until you unsubscribe or ask to be removed. Implied consent from a purchase expires by itself two years after the order.
  • Reviews and review photographs — kept while they are published, because a review with its evidence removed is no longer the review anyone wrote. Ask us and both are deleted.
  • Advertising click identifiers — 90 days for Meta’s, 365 days for Pinterest’s, as set out above.
  • Analytics and session-recording data — held by Google and Microsoft under the retention period configured on those accounts, not on this server.

Your rights, and how to use them

The Personal Information Protection and Electronic Documents Act — PIPEDA — is the federal Canadian law that governs how a private-sector business handles personal information, and it is the framework this policy is written against. Under it you can:

  • ask what personal information we hold about you, and why;
  • ask for a copy of it;
  • ask us to correct anything that is wrong;
  • ask us to delete it — and we will, unless we are required to keep it, which in practice means the invoice attached to a completed sale;
  • withdraw your consent to marketing at any time;
  • complain if you think we have handled any of this badly.

Email info@montclaircollective.com from the address you ordered with, or give us the order number, so that we can be sure we are answering the right person rather than someone claiming to be you. We aim to answer within 30 days, which is the period PIPEDA sets. There is no charge.

If our answer does not satisfy you, you can take the matter to the Office of the Privacy Commissioner of Canada. And if you live somewhere with its own privacy law — Quebec, the European Union or the United Kingdom, for example — those rights sit alongside these and we will honour a request made under them.

Children

This shop is not aimed at children, and our Terms of Service require you to be 18, or old enough to enter a binding contract where you live, to order. We do not knowingly collect personal information from a child. If you believe we have, email info@montclaircollective.com and we will delete it.

Security

The site runs over HTTPS. Card numbers are never held on this server. Consent records store a one-way hash of the IP address rather than the address itself, and unfinished-cart rows do the same with the session identifier — so a copy of that table is worth considerably less than it looks.

No system is perfect and we are not going to pretend otherwise. If you find a security problem here, please tell us at info@montclaircollective.com before you tell anybody else.

Changes to this policy

When this changes, the new version is published on this page and the “Last updated” date at the top changes with it. The version in force when you place an order is the one that applies to that order.

Contact

Montclair Collective — info@montclaircollective.com. Questions, access requests, deletion requests and complaints all go to the same inbox and get an answer from a person, usually within one business day.

This page describes what this website actually does. It is a description of our practices, not legal advice, and it does not claim certification or approval under any standard, seal or programme.

Still unsure

Ask us before you order.

Sizing, framing, a wall you are not sure about — send a photo and we will tell you straight.

The Paddock List

Join the list and we will send you a VIP code worth ₼10 off any order of ₼60 or more — on top of the sale price, on any print in the collection. New plates reach members before release, and nothing else lands in your inbox.