Privacy policy
Privacy Policy
Effective date: August 29, 2026
Last updated: August 29, 2026
1. Who We Are
Teifi Digital Inc. ("Teifi Digital", "we", "us", "our") is a Shopify development agency operating this website at teifi.com.
Registered address: 948 W 7th Avenue, Vancouver, BC, V5Z 1C3, Canada
Data controller contact: admin@teifi.com
2. Scope of This Policy
This Privacy Policy explains how we collect, use, store, and share personal information when you visit teifi.com. It covers our obligations under:
- GDPR and UK GDPR: visitors from the European Economic Area (EEA) and United Kingdom
- US state privacy laws (including CCPA / CPRA): residents of California and other US states with comprehensive consumer privacy laws
- PIPEDA and BC PIPA: residents of Canada
3. What Data We Collect
Information You Provide
- Contact form submissions: name, business email address, company name, and message content
- Direct email communications sent to our team
Data Collected Automatically
- IP address and approximate location (city/region level)
- Browser type and version, operating system, device type
- Pages visited, time spent on page, referral source
- Cookie identifiers and analytics event data (see Section 10 and our Cookie Policy)
Business Identification Data
Where you have consented, we also work with third-party providers who help us identify the organisation associated with a visit to our website. This is described in Section 6 and can include the company associated with your IP address, its industry, size, location, and website domain.
4. How We Use Your Data
| Purpose | Details |
|---|---|
| Responding to inquiries | To reply to contact form submissions and email requests |
| Analytics | To understand how visitors use our website and improve content |
| Business visitor identification | To understand which organisations are researching our services, and to prioritise our sales and marketing effort (see Section 6) |
| Sales pipeline management | To store and manage inbound leads in our internal CRM |
| Marketing performance | To measure advertising campaign effectiveness (consent required) |
| Legal compliance | To meet our obligations under applicable privacy laws |
We do not use business identification data to make any automated decision that has a legal or similarly significant effect on you. We do not use it to infer or record sensitive personal information, and we do not sell personal information.
5. Legal Bases for Processing (GDPR / UK GDPR)
| Processing Activity | Legal Basis |
|---|---|
| Responding to contact form inquiries | Legitimate interests / Contract performance |
| Processing form submissions via Formstack | Legitimate interests |
| Storing contact details in our CRM | Legitimate interests |
| Website analytics (Google Analytics 4) | Consent |
| Marketing and advertising tracking | Consent |
| Placing or reading any visitor identification script, cookie, or identifier on your device | Consent |
| Identifying the organisation associated with an IP address, after consent has been given | Legitimate interests (Art. 6 (1) (f) GDPR) in optimising our products, services, sales and marketing |
| Retaining records of communications | Legitimate interests |
| Legal obligations | Legal obligation |
Where we rely on legitimate interests, we have assessed that our interests do not override your rights and freedoms. You may object to this processing at any time (see Section 9).
6. Website Visitor Identification
teifi.com is a business-to-business website. We use third-party technology that helps us recognise which organisations visit our website, so that our team can follow up with businesses that may need our services.
6.1 What we identify
We identify organisations, not individuals. Our providers match the IP address of a visit to the business that IP address belongs to, and return information about that business such as company name, industry, size, and location. We do not use person-level visitor identification, and we do not receive the name, email address, job title, or personal profile of any individual visitor from these providers. If that ever changes, we will update this policy before switching it on.
We may use more than one provider at the same time for a limited period while we evaluate which one suits us. The providers in use at any given time are listed in the third-party services table in Section 7, which we keep current.
6.2 Consent
Visitor identification is treated as marketing under our cookie banner. It is switched off by default, and no visitor identification technology is loaded unless you accept marketing cookies. You can withdraw your consent at any time via Cookie Settings in the footer of our website.
6.3 Disclosure required by our providers
When you visit or log in to our website, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including by association with your email. We (or service providers on our behalf) may then send communications and marketing to these email addresses. You may opt out of receiving this advertising by visiting https://app.retention.com/optout. You also have the option to opt out of the collection of your personal data in compliance with GDPR by visiting https://www.rb2b.com/rb2b-gdpr-opt-out.
Our website uses the technologies of Leadfeeder (Leadfeeder Finland Oy, part of Leadfeeder Group GmbH) to analyse visitor behaviour. In this process, the IP address of a visitor is processed. The purpose of this processing is to help us understand which businesses are visiting our site, by enriching IP addresses with associated information such as company name or industry code. We have concluded a data processing agreement with Leadfeeder in order to ensure compliance with applicable data protection standards.
6.4 How to stop it
- Decline marketing cookies in our cookie banner, or withdraw your consent at any time via Cookie Settings in the footer of our website.
- Opt out of the provider databases directly at app.retention.com/optout and rb2b.com/rb2b-gdpr-opt-out. These opt-outs apply across every website using those providers, not just ours.
- Email us at admin@teifi.com and ask us to suppress your details. We will remove you from our records and add you to our suppression list.
- Use a browser-level control such as an ad blocker or a script blocker.
6.5 If we contact you
If we send a business message to an organisation we identified through this technology, we will identify ourselves clearly, tell you why we are contacting you, and include a working unsubscribe in every message. Ask us to stop and we will stop, permanently.
7. Third-Party Services
We use the following third-party services that may process your personal data on our behalf:
| Service | Purpose | Privacy Policy |
|---|---|---|
| Formstack | Contact form submission handling | formstack.com/privacy |
| Google Analytics 4 | Website analytics | google.com/policies/privacy |
| Google Tag Manager | Tag and script management | google.com/policies/privacy |
| Shopify | Website platform and hosting | shopify.com/legal/privacy |
| Advertising and audience measurement | linkedin.com/legal/privacy-policy | |
| Google Ads | Advertising conversion tracking | google.com/policies/privacy |
| RB2B | Company-level website visitor identification (see Section 6) | rb2b.com/privacy-policy |
| Leadfeeder | Company-level website visitor identification (see Section 6) | leadfeeder.com/privacy |
We also use an internal CRM system to manage inbound leads and business inquiries. Contact details submitted via our website may be stored there for the purpose of following up on your inquiry.
Analytics, advertising, and visitor identification technologies are only activated following your consent via the cookie banner.
8. Data Retention
| Data Type | Retention Period |
|---|---|
| Contact form submissions (Formstack) | 2 years |
| CRM records | 2 years from last contact |
| Analytics data (GA4) | 14 months (Google Analytics default retention setting) |
| Company-level visitor identification data | 12 months from the visit |
| Suppression list entries (so we do not contact you again) | Retained indefinitely, for the sole purpose of honouring your request |
| Cookie consent records | 1 year from consent or withdrawal |
| Email communications | 2 years from last contact |
9. Your Rights
EU / UK Visitors (GDPR / UK GDPR)
- Access: Request a copy of the personal data we hold about you
- Rectification: Ask us to correct inaccurate or incomplete data
- Erasure: Request deletion of your personal data ("right to be forgotten")
- Restriction: Ask us to limit how we use your data while a dispute is resolved
- Portability: Receive your data in a structured, machine-readable format
- Object: Object to processing based on legitimate interests, including visitor identification, or for direct marketing
- Withdraw consent: Withdraw consent for analytics, marketing, or visitor identification at any time via Cookie Settings on our website
US State Privacy Rights
If you are a resident of California (under the CCPA / CPRA) or another US state with a comprehensive consumer privacy law (for example Virginia, Colorado, Connecticut, or Texas), you may have the following rights:
- Know / Access: Know what personal information we collect and how it is used or shared
- Delete: Request deletion of your personal information
- Correct: Request correction of inaccurate personal information
- Opt out: Opt out of the sale or sharing of personal information, of targeted advertising, and of the visitor identification described in Section 6 (we do not sell personal information)
- Limit use of sensitive data: Limit the use and disclosure of sensitive personal information
- Non-discrimination: We will not discriminate against you for exercising these rights
Canadian Residents (PIPEDA / BC PIPA)
- Access: Request access to the personal information we hold about you
- Correction: Request correction of inaccurate personal information
- Withdraw consent: Withdraw consent for non-essential processing, including visitor identification, at any time
To exercise any of these rights, contact us at admin@teifi.com. We will respond within 30 days (GDPR) or 45 days (US state laws). We may need to verify your identity before processing your request.
10. Cookies and Tracking Technologies
We use cookies and similar technologies on teifi.com. You can manage your preferences at any time via the Cookie Settings link in the footer of our website.
For full details of the cookies we use, their purposes, and how to opt out, please see our Cookie Policy.
Do Not Sell or Share: We do not sell personal information. Analytics, advertising, and visitor identification technologies are only activated with your consent. You may opt out by declining non-essential cookies, by using the opt-out links in Section 6.4, or by contacting admin@teifi.com.
11. International Data Transfers
Some third-party services we use (including Formstack, Google Analytics, and RB2B) are based in the United States and may transfer personal data outside Canada, the EEA, or the UK. Where this occurs, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- The UK International Data Transfer Agreement (IDTA)
- Canada's adequacy recognition or equivalent contractual safeguards
12. Children's Privacy
teifi.com is a B2B website directed at business professionals. We do not knowingly collect personal information from anyone under the age of 16. If you believe a minor has submitted information to us, contact admin@teifi.com and we will delete it promptly.
13. Links to Other Websites
Our website may contain links to third-party websites. This Privacy Policy applies only to teifi.com. We are not responsible for the privacy practices of other sites.
14. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date reflects the most recent revision. Continued use of teifi.com after changes constitutes acceptance of the updated policy.
15. Contact and Complaints
Teifi Digital Inc.
948 W 7th Avenue, Vancouver, BC, V5Z 1C3, Canada
Email: admin@teifi.com
Website: teifi.com
For EU/UK privacy complaints, you have the right to lodge a complaint with your local supervisory authority: UK ICO at ico.org.uk, or the Office of the Privacy Commissioner of Canada at priv.gc.ca.