View your shopping cart.

Privacy Policy


Updated: January 1, 2024

(Under the control of Board of Directors and General Manager of the Store)

Condensed Privacy Policy of

Cathedral Book and Gift is committed to protecting your privacy. We have

established this Privacy Policy so that you can understand the manner in

which we collect and use your information and the efforts we use to

protect it. Please note that this policy is for the Cathedral Book and Gift

web site only and does not apply to other 3rd party web sites linked to

from our web site. Please check the privacy policies on those web sites for

more information. Capitalized terms are defined at the end of this Privacy


In order to receive information about your Personal Data, the purposes

and the parties the Data is shared with, contact the Owner.

For more information and to understand your rights, you can view the

complete version of this privacy policy, displayed after this condensed


Contact information

Owner and Data Controller

Cathedral Book & Gift

131 S. Madison Street

Green Bay, Wisconsin

54301 USA 

Owner contact email:

Latest update: August 07, 2020

Complete Privacy Policy of

Types of Data collected

Complete details on each type of Personal Data collected are provided in

the dedicated sections of this privacy policy or by specific explanation

texts displayed prior to the Data collection.

Personal Data may be freely provided by the User, or, in case of Usage

Data, collected automatically when using this Website. If you are visiting

this site to browse or find information about Cathedral Book and Gift's

products or services, you do not need to provide any personal

information; however, information collected automatically through this

Website will continue to be collected. If you decide to make a purchase,

however, we may collect this information so that we can provide you with

the product or service you requested.

Unless specified otherwise, all Data requested by this Website is

mandatory and failure to provide this Data may make it impossible for this

Website to provide its services. In cases where this Website specifically

states that some Data is not mandatory, Users are free not to

communicate this Data without consequences to the availability or the

functioning of the Service.

Users who are uncertain about which Personal Data is mandatory are

welcome to contact the Owner.

Any use of Cookies – or of other tracking tools – by this Website or by the

owners of third-party services used by this Website serves the purpose of

providing the Service required by the User, in addition to any other

purposes described in the present document. 

Users are responsible for any third-party Personal Data obtained,

published or shared through this Website and confirm that they have the

third party's consent to provide the Data to the Owner.

Mode and place of processing the Data

Methods of processing

The Owner takes appropriate security measures by complying with the PCI

DSS V. 3.1 standards and an SSL 256-bit certificate renewed every month

through TIMBER By Herkimer Media to prevent unauthorized access,

disclosure, modification, or unauthorized destruction of the Data.

Data processing is carried out using computers and/or IT enabled tools,

following organizational procedures and modes strictly related to the

purposes indicated. In addition to the Owner, in some cases, the Data may

be accessible to certain types of persons in charge, involved with the

operation of this Website (administration, sales, marketing, legal, system

administration) or external parties (such as third-party technical service

providers, mail carriers, hosting providers, IT companies, communications

agencies) appointed, if necessary, as Data Processors by the Owner. 

Legal basis of processing

The Owner may process Personal Data relating to Users if one of the

following applies:

 Users have given their consent for one or more specific purposes.

Note: Under some legislations, the Owner may be allowed to

process Personal Data until the User objects to such processing

(“opt-out”), without having to rely on consent or any other of the

following legal bases. 

 Provision of Data is necessary for the performance of an agreement

with the User and/or for any pre-contractual obligations thereof;

 Processing is necessary for compliance with a legal obligation to

which the Owner is subject;

 Processing is related to a task that is carried out in the public

interest or in the exercise of official authority vested in the Owner;

 Processing is necessary for the purposes of the legitimate interests

pursued by the Owner or by a third party.

In any case, the Owner will gladly help to clarify the specific legal basis that

applies to the processing, and in particular whether the provision of

Personal Data is a statutory or contractual requirement, or a requirement

necessary to enter into a contract.


The Data is processed at the Owner's operating offices and in any other

electronic online places where the parties involved in the processing are


Data transfers may involve transferring the User's Data electronically. To

find out more about the place of processing of such transferred Data,

Users can check the section containing details about the processing of

Personal Data.

If any such transfer takes place, Users can find out more by checking the

relevant sections of this document or inquire with the Owner using the

information provided in the contact section.

Retention time

Personal Data shall be processed and stored for as long as required by the

purpose they have been collected for.


 Personal Data collected for purposes related to the performance of

a contract between the Owner and the User shall be retained until

such a contract has been fully performed.

 Personal Data collected for the purposes of the Owner’s legitimate

interests shall be retained as long as needed to fulfill such purposes.

Users may find specific information regarding the legitimate

interests pursued by the Owner within the relevant sections of this

document or by contacting the Owner.

The Owner may be allowed to retain Personal Data for a longer period

whenever the User has given consent to such processing, as long as such

consent is not withdrawn. Furthermore, the Owner may be obliged to

retain Personal Data for a longer period whenever required to do so for

the performance of a legal obligation or upon order of an authority.

Once the retention period expires, Personal Data shall be deleted.

Therefore, the right to access, the right to erasure, the right to

rectification, and the right to data portability cannot be enforced after the

expiration of the retention period.

Card Payments Information 

As per the PCI DSS V. 3, Cathedral Book and Gift limit the cardholder data

storage and retention time to that which is required for business, legal,

and/ or regulatory purposes, as documented in the data retention policy


The rights of Users

Users may exercise certain rights regarding their Data processed by the


In particular, Users have the right to do the following:

 Withdraw their consent at any time. Users have the right to

withdraw consent where they have previously given their consent to

the processing of their Personal Data.

 Object to processing of their Data. Users have the right to object

to the processing of their Data if the processing is carried out on a

legal basis other than consent. 

 Access their Data. Users have the right to learn if Data is being

processed by the Owner, obtain disclosure regarding certain aspects

of the processing, and obtain a copy of the Data undergoing


 Verify and seek rectification. Users have the right to verify the

accuracy of their Data and ask for it to be updated or corrected.

 Have their Personal Data deleted or otherwise removed. Users

have the right to obtain the erasure of their Data from the Owner.

 Lodge a complaint. Users have the right to bring a claim before

their competent data protection authority.

Details about the right to object to processing

Where Personal Data is processed for a public interest, in the exercise of

an official authority vested in the Owner or for the purposes of the

legitimate interests pursued by the Owner, Users may object to such

processing by providing a ground related to their particular situation to

justify the objection.

Users must know that, however, should their Personal Data be processed

for direct marketing purposes, they can object to that processing at any

time without providing any justification. To learn, whether the Owner is

processing Personal Data for direct marketing purposes, Users may refer

to the relevant sections of this document.

How to exercise these rights

Any requests to exercise User rights can be directed to the Owner through

the contact details provided in this document. These requests can be

exercised free of charge and will be addressed by the Owner as early as

possible and always within one month.

Additional information about Data

collection and processing

Legal action

The User's Personal Data may be used for legal purposes by the Owner in

Court or in the stages leading to possible legal action arising from

improper use of this Website or the related Services. The User declares to

be aware that the Owner may be required to reveal personal data upon

request of public authorities.

Additional information about User's Personal Data

In addition to the information contained in this privacy policy, this Website

may provide the User with additional and contextual information

concerning particular Services or the collection and processing of Personal

Data upon request.

System logs and maintenance

For operation and maintenance purposes, this Website and any third-

party services may collect files that record interaction with this Website

(System logs) use other Personal Data (such as the IP Address) for this


Information not contained in this policy

More details concerning the collection or processing of Personal Data may

be requested from the Owner at any time. Please see the contact

information at the beginning of this document.

How “Do Not Track” requests are handled

This Website does not support “Do Not Track” requests.

To determine whether any of the third-party services it uses honor the “Do

Not Track” requests, please read their privacy policies.

Changes to this privacy policy

The Owner reserves the right to make changes to this privacy policy at any

time by notifying its Users on this page and possibly within this Website

and/or - as far as technically and legally feasible - sending a notice to

Users via any contact information available to the Owner. It is strongly

recommended to check this page often, referring to the date of the last

modification listed at the bottom.

Should the changes affect processing activities performed on the basis of

the User’s consent, the Owner shall collect new consent from the User,

where required.

Definitions and legal references

Personal Data (or Data)

Any information that directly, indirectly, or in connection with other

information — including a personal identification number — allows for the

identification or identifiability of a natural person.

Usage Data

Information collected automatically through this Website (or third-party

services employed in this Website), which can include: the IP addresses or

domain names of the computers utilized by the Users who use this

Website, the URI addresses (Uniform Resource Identifier), the time of the

request, the method utilized to submit the request to the server, the size

of the file received in response, the numerical code indicating the status of

the server's answer (successful outcome, error, etc.), the country of origin,

the features of the browser and the operating system utilized by the User,

the various time details per visit (e.g., the time spent on each page within

the Website) and the details about the path followed within the Website

with special reference to the sequence of pages visited, and other

parameters about the device operating system and/or the User's IT



The individual using this Website who, unless otherwise specified,

coincides with the Data Subject.

Data Subject

The natural person to whom the Personal Data refers.

Data Processor (or Data Supervisor)

The natural or legal person, public authority, agency or other body which

processes Personal Data on behalf of the Controller, as described in this

privacy policy.

Data Controller (or Owner)

The natural or legal person, public authority, agency or other body which,

alone or jointly with others, determines the purposes and means of the

processing of Personal Data, including the security measures concerning

the operation and use of this Website. The Data Controller, unless

otherwise specified, is the Owner of this Website.

This Website

The means by which the Personal Data of the User is collected and



The service provided by this Website as described in the relative terms (if

available) and on this site/website.