This website use cookies to ensure you get the best experience on our website
Privacy Policy
Last updated: July 1, 2026
This Privacy Policy explains how TREA’SA DAHL, operating as Quill of Curiosities ("we," "us," or "our"), collects, uses, and shares personal information through quill-of-curiosities.com (the "Site") and our related services — our email newsletter, book downloads and giveaways, and astrology readings.
Please read it alongside any separate giveaway rules and reading service terms we provide (see Section 15).
1. Who we are (Data Controller)
For the purposes of the EU and UK General Data Protection Regulation (GDPR/UK GDPR), the data controller responsible for your personal information is:
EU/UK representative: If you are in the EEA or UK, an Article 27 representative may be required for businesses without an establishment there. [Add representative name and contact once appointed, OR state: "We are assessing whether an Article 27 representative is required for our processing."]
2. Information we collect
a. Information you give us directly
b. Information collected automatically
c. Sensitive information
3. Why we use your information, and our legal bases
Under GDPR we must have a lawful basis for each use of your information:
Where we rely on legitimate interests, those interests are running and improving a small creative business, communicating with people who contact us, and keeping our Site secure. We balance these interests against your rights and freedoms.
Where we rely on consent, you may withdraw it at any time (see Sections 8 and 11); withdrawing consent does not affect processing already carried out. Providing your information is voluntary, but if you do not provide what a service needs (for example, an email for the newsletter, or birth data for a reading), we may be unable to provide that service.
We do not use your information for automated decision-making or profiling that produces legal or similarly significant effects.
4. Cookies and analytics
Our Site uses cookies. Strictly necessary cookies (which make the Site work and remember your cookie choices) are always active. Non-essential cookies — including Google Analytics — are set only after you give consent through our cookie banner. You can change or withdraw your choice at any time via [your cookie settings link / the banner].
Cookies we use include:
We have configured Google Analytics to [confirm: e.g., limit data retention and disable advertising features / Google Signals]. You can also install Google's browser opt-out add-on to block Analytics across sites.
5. "Do Not Track" and third-party tracking (California — CalOPPA)
Some browsers send a "Do Not Track" (DNT) signal. Because there is no common industry standard for responding to DNT, [state your actual practice: "we do not currently respond to DNT signals" OR describe how you respond]. Where required, we honor recognized opt-out preference signals such as Global Privacy Control (GPC) (see Sections 8 and 9). Third parties, including Google, may collect information about your activity over time and across other websites when you use our Site, as described in Section 4.
6. Who we share your information with
We do not sell your personal information for money. We share it only with service providers who act on our behalf under contract:
Regarding "sharing" for cross-context behavioral advertising under U.S. state privacy laws: [confirm against your Google Analytics settings — if advertising features/Google Signals are off, state: "we do not share personal information for cross-context behavioral or targeted advertising." If they are on, this must be disclosed and an opt-out offered.]
We may also disclose information where required by law, to enforce our terms, or to protect our rights, safety, or property.
7. International data transfers
We are based in the United States, and our service providers may process data in the U.S. and elsewhere. Where we transfer personal data of individuals in the EEA or UK, we rely on a lawful transfer mechanism, which — depending on the provider — may include an adequacy decision, a provider's participation in the EU-U.S. Data Privacy Framework, the Standard Contractual Clauses, or the UK International Data Transfer Agreement / Addendum. You can contact us to ask which mechanism applies to a specific provider.
8. Your privacy rights (EEA, UK, and general)
Depending on where you live, you may have the right to:
To exercise any of these rights, email author@blossomseafarrer.com. We may need to verify your identity before acting on a request.
9. California privacy rights (CCPA/CPRA — if applicable)
Many small businesses fall below the CCPA/CPRA thresholds and are not a "business" under the law. This section applies to the extent the CCPA/CPRA covers us; regardless, we honor the core choices below for California residents.
10. Astrology readings and birth information
Your date, time, and place of birth, and anything you share during a reading, receive extra care:
11. Email marketing and CAN-SPAM
Marketing consent is separate from receiving a service. Downloading a book, entering a giveaway, or booking a reading does not by itself enroll you in our newsletter — you opt in separately, and that consent is specific, informed, and withdrawable.
Every marketing email we send includes accurate sender information, a valid physical postal address, and a working unsubscribe link, consistent with the U.S. CAN-SPAM Act. Transactional emails (such as delivering a book you requested or confirming a booking) are separate from promotional emails. When you unsubscribe, we stop sending marketing emails promptly and keep only a minimal suppression record so we can honor your choice.
12. Data retention
We keep personal information only as long as needed for the purpose it was collected, then delete or anonymize it. As a guide:
Some limited records may persist in tax records, fraud-prevention files, or unsubscribe suppression lists after you ask us to delete your data.
13. Children's privacy
Our services are intended for adults. We do not knowingly collect personal information from children under 13. Where the GDPR applies, we do not knowingly collect information from a child below the applicable age of digital consent without appropriate consent. If you believe a child has provided us information, contact us and we will delete it.
14. Data security
We take reasonable technical and organizational measures to protect your information. However, no method of transmitting or storing data is completely secure, so we cannot guarantee absolute security.
15. Giveaways and readings — separate terms
Some activities are governed by their own terms in addition to this policy:
16. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top shows the most recent revision.