Privacy Policy

Effective date: 16 January 2026

This Privacy Policy explains how NO BORING SHOPS L.L.C-FZ (“XO·Cat”, “we”, “us”) collects, uses, and shares information when you visit or purchase from https://xo-cat.com (the “Site”).

1) Who we are (Controller)

NO BORING SHOPS L.L.C-FZ
Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E.
Email: hello@xo-cat.com
Phone: +1 717-949-7307

2) What we collect

A) Information you provide
  • Order details: name, email, phone (if provided), shipping/billing address, items purchased
  • Customer messages: when you contact us (email/WhatsApp), we process what you send
  • Marketing sign-ups: email and preferences when you subscribe

B) Information collected automatically (website usage)
  • device/browser data, approximate location, pages viewed, clicks, cart activity
  • identifiers like cookies and similar technologies (see Cookies section)
Shopify powers our store and processes customer and order data to provide ecommerce services.  

3) What we use data for
  • Fulfill orders (process payment, ship, send order updates)
  • Customer support (answer questions, resolve issues)
  • Fraud prevention & security
  • Marketing & advertising (measure performance, show relevant ads)
  • Analytics & site improvement

4) Who we share data with (key service providers)

We share information only as needed to run the store and deliver your order:

Shopify (store platform + hosting)

Shopify processes customer data to provide the services we use to operate the store.  

Email + business operations (Google Workspace)

We use Google Workspace to manage business email and internal communications.

Email marketing (Klaviyo)

We use Klaviyo for email marketing and customer messaging automation (e.g., newsletters, flows).  

Advertising + measurement (Meta, Google)

We use tools like:
  • Meta Pixel (and related Meta tools) to measure ad performance and build audiences
  • Google Ads conversion tracking/remarketing
  • Google Tag Manager to manage tracking tags
  • Google Analytics to understand site usage (GA4 has privacy controls and states it doesn’t log/store IP addresses).  
Fulfillment partners (Print-on-Demand)

Because we sell print-on-demand products, we share order and shipping information with production/fulfillment partners and shipping carriers to produce and deliver your order.

Payments (Stripe + PayPal)

When you pay for an order, your payment is processed by Stripe and/or PayPal (depending on the method you choose). This means:

  • We receive confirmation of payment and basic transaction details.
  • We do not receive or store your full card number. Payment details are handled directly by Stripe/PayPal under their security standards. (General card-data storage is discouraged unless absolutely necessary.)  
  • We share with the payment provider the information needed to process the transaction and prevent fraud (such as your name, email, billing/shipping address, order total, and device/transaction identifiers).

Stripe
Stripe may act as a data controller and/or processor depending on the activity and explains what it collects and how it uses it in its privacy materials.  

PayPal
PayPal states it may collect personal data even if you pay without a PayPal account, and that merchants may disclose personal data to PayPal for payment processing.  

For more information, review:

Legal / compliance

We may disclose information if required to comply with law, respond to lawful requests, or protect rights, safety, and security.

5) Cookies, ads, and “targeted advertising”

We use cookies and similar technologies for:
  • essential site functionality (cart, checkout)
  • analytics (Google Analytics)
  • advertising measurement and retargeting (Meta, Google)
Your choices:
  • You can adjust cookie settings via our cookie banner (where available).
  • You can also limit cookies in your browser settings (may affect site functionality).
  • You can opt out of certain targeted ads using industry tools like the NAI/DAA opt-out pages (availability depends on region/device).
Google requires appropriate consent for certain ad features for EEA/UK users; we apply consent controls where required.  

6) Email marketing choices
  • If you subscribe, you can unsubscribe anytime using the link in our emails.
  • Even if you unsubscribe from marketing, we may still send transactional emails (order confirmations, shipping updates).
7) Data retention

We keep personal information as long as needed to:
  • provide services and fulfill orders,
  • comply with legal/accounting requirements,
  • resolve disputes and enforce agreements.
8) International data transfers

We are based in the UAE and we use service providers that may process data in other countries (including the United States). Shopify and other vendors may transfer data internationally and rely on contractual protections for such transfers.  

9) Security

We use reasonable administrative, technical, and physical safeguards designed to protect your information. No method of transmission or storage is 100% secure.

10) Children

The Site is not intended for children under 13. We do not knowingly collect personal information from children under 13.

11) US privacy rights (State laws)

Depending on where you live (e.g., California and other US states), you may have rights to:
  • access the personal information we have about you
  • delete certain personal information
  • correct inaccurate information
  • opt out of “sale” or “sharing” for targeted advertising (definitions vary by state)

Do Not Sell or Share (Targeted Advertising)

We do not sell personal information for money. However, using advertising tools (like Meta/Google) can be considered “sharing” under some US state laws.

To opt out, email hello@xo-cat.com with subject: “Privacy Opt-Out” and include:
  • your name and email used on the Site
  • “Do Not Sell/Share” request

If you use a browser or extension that sends a Global Privacy Control (GPC) signal, we will make reasonable efforts to honor it where legally required.

12) EEA/UK visitors (short version)

If you are located in the EEA/UK, you may have additional rights (access, correction, deletion, portability, objection, restriction, and withdrawal of consent where processing is based on consent). To exercise rights, contact hello@xo-cat.com.

13) Changes to this policy

We may update this Privacy Policy. We’ll post the latest version on this page with a new effective date.

14) Contact

Questions or requests: hello@xo-cat.com