Privacy Policy
Veronica Mishaan
Effective date: September 11, 2026
Website: veronicamishaan.com
New York office: 401 Broadway, #2316, New York, NY 10013
Bogotá office: Cra 9 No. 81A – 26, Oficina 802, Bogotá, Colombia
Privacy contact: info@veronicamishaan.com
1. Scope and Who We Are
This Privacy Policy explains how Veronica Mishaan (“Veronica Mishaan,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information in connection with veronicamishaan.com (the “Site”), inquiries, client and project relationships, vendor and professional relationships, marketing activities, and other business interactions.
We operate from New York and Bogotá and provide interior design, interior architecture, procurement, and related project services to clients and projects located in New York, Florida, the Caribbean, Colombia, and other locations as our work requires. Because privacy rights vary by jurisdiction, certain portions of this Policy apply only where required by the law of the place where you live or where the relevant processing occurs.
For purposes of this Policy, “personal information” or “personal data” means information that identifies, relates to, describes, is reasonably capable of being associated with, or can reasonably be linked to an identifiable individual, as defined under applicable law. It does not include information that has been lawfully made public, de-identified, or aggregated where applicable law excludes such information.
2. Personal Information We Collect
A. Information you provide directly
We may collect information that you provide when you contact us, submit an inquiry, request a proposal, become a client, communicate with us, apply to work with us, attend an event, subscribe to communications, or otherwise interact with our business. This may include:
Identifiers and contact information, such as name, email address, telephone number, mailing address, company, title, and professional contact details;
Project information, such as property addresses, project scope, budget, timeline, preferences, plans, photographs, drawings, access instructions, and other information relevant to design, procurement, installation, or project management;
Transaction and commercial information, such as proposals, contracts, invoices, purchase records, procurement records, delivery information, and payment status;
Communications and correspondence, including emails, messages, meeting notes, feedback, and records of requests;
Vendor, consultant, contractor, architect, fabricator, installer, broker, developer, and other professional information necessary to manage projects and business relationships; and
Any other information you choose to provide to us.
Please do not provide sensitive personal information that is not necessary for our relationship or the purpose of your communication.
B. Information collected automatically
When you use the Site, we and our service providers may automatically collect internet, device, and usage information. Depending on the technologies enabled on the Site and your privacy choices, this may include IP address, browser and device type, operating system, referring and exit pages, pages viewed, links clicked, approximate location derived from IP address, dates and times of visits, cookie or device identifiers, and information about how you interact with the Site.
C. Information from third parties and public sources
We may receive personal information from referral sources, clients, project collaborators, professional contacts, brokers, developers, architects, vendors, public professional directories, social and professional platforms, event organizers, media or public sources, and marketplaces or platforms through which our products or services are promoted or sold, including 1stDibs. We may combine this information with information we already hold where permitted by law.
D. Payment information
We do not intend to collect payment-card information directly through the Site. Client and vendor payments may be processed through banks, accounting platforms, payment processors, or other financial-service providers. Those providers process payment information under their own terms and privacy practices. We may retain transaction records, payment status, and accounting information necessary for business, tax, audit, and legal purposes.
3. How We Use Personal Information
We may use personal information for the following business and commercial purposes:
Responding to inquiries and communicating about our services;
Evaluating potential projects and preparing proposals, estimates, scopes, contracts, and presentations;
Providing interior design, interior architecture, procurement, logistics, project management, styling, art direction, creative direction, and related services;
Coordinating with clients, architects, contractors, suppliers, fabricators, installers, logistics providers, consultants, and other project participants;
Processing purchases, invoices, payments, deliveries, returns, warranties, and other transactions;
Administering our business, records, accounting, insurance, compliance, and internal operations;
Operating, maintaining, securing, troubleshooting, analyzing, and improving the Site and our services;
Measuring Site performance and understanding how visitors find and use the Site;
Sending marketing or business-development communications where permitted by law, and honoring unsubscribe and suppression requests;
Protecting our rights, property, systems, clients, personnel, and others; preventing fraud, misuse, security incidents, or unlawful activity;
Establishing, exercising, or defending legal claims; complying with contracts, legal obligations, court orders, and lawful governmental requests; and
Carrying out a merger, financing, acquisition, reorganization, sale, transfer, or other business transaction, subject to applicable law.
4. Cookies, Analytics, Advertising, and Tracking Technologies
The Site may use cookies, pixels, tags, local storage, and similar technologies. These technologies may be operated by us or by third parties and may collect information over time and across websites or services, depending on the technology and your settings.
Categories of technologies
Strictly necessary technologies. These support core Site functions, security, network management, and user-requested features. Where permitted by law, they may operate without consent because the Site cannot function properly without them.
Analytics and performance technologies. We use or may use Google Analytics 4 and similar tools to understand Site traffic, visitor interactions, and performance.
Advertising and measurement technologies. We use or may use the Meta Pixel and similar technologies to measure marketing effectiveness, understand interactions with our advertising, and, where enabled and legally permitted, create or reach audiences on third-party platforms.
Where applicable law requires consent before non-essential technologies are used, we will seek consent through our cookie or privacy controls before those technologies are activated. Where applicable law provides an opt-out right, we will provide the required mechanism. You may also control cookies through your browser settings, although blocking some technologies may affect Site functionality.
Our statements about cookies and privacy choices are intended to reflect the Site’s actual configuration. We periodically review our tracking technologies and privacy controls and may update this Policy as those technologies change.
5. Sale, Sharing, and Targeted Advertising
We do not sell personal information for monetary consideration.
Some privacy laws define “sale,” “sharing,” “targeted advertising,” or similar concepts broadly enough to include certain disclosures of online identifiers or activity information to advertising or analytics partners. To the extent our use of advertising or measurement technologies is treated as a sale, sharing, or targeted advertising under applicable law, eligible individuals may exercise the opt-out rights provided by that law through the privacy or cookie controls made available on the Site or by contacting us.
Where required by applicable law and supported by our systems, we will process recognized browser-based opt-out preference signals, such as Global Privacy Control, as a request to opt out for the browser or device sending the signal. Because such signals are browser- and device-specific, you may need to repeat your choice on other browsers or devices.
6. How We Disclose Personal Information
We may disclose personal information where reasonably necessary for the purposes described in this Policy, including to:
Service providers and processors that support hosting, website operation, cloud storage, email, collaboration, CRM, project management, accounting, analytics, security, communications, marketing, logistics, and other business functions;
Project collaborators, including architects, contractors, consultants, suppliers, fabricators, installers, carriers, warehouses, brokers, developers, property managers, and other parties involved in a project or transaction;
Professional advisers, including lawyers, accountants, auditors, insurers, lenders, and other advisers;
Government authorities, courts, regulators, law enforcement, or other parties when disclosure is required or permitted by law or reasonably necessary to protect rights, safety, systems, or property; and
A purchaser, investor, lender, successor, or other relevant party in connection with an actual or proposed financing, merger, acquisition, restructuring, sale, transfer, insolvency, or similar corporate transaction.
We expect service providers that process personal information on our behalf to use appropriate safeguards and to process the information consistently with applicable contractual and legal requirements. Some third parties, such as independent project collaborators, financial institutions, marketplaces, and social-media platforms, may process information for their own purposes under their own privacy notices.
7. International Data Transfers
Because we operate in more than one country, personal information may be transferred to, stored in, or accessed from jurisdictions other than the one in which it was collected, including the United States and Colombia and, where relevant to a specific project, other countries in which we, our clients, or our vendors operate.
Privacy and data-protection laws differ between jurisdictions. Where applicable law restricts international transfers, we take steps intended to provide an appropriate legal basis and level of protection, which may include contractual protections, approved transfer mechanisms, consent where valid and appropriate, or another lawful transfer basis. We limit transfers to information reasonably necessary for the relevant business purpose.
8. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, including to provide services, maintain business and project records, satisfy contractual obligations, comply with legal, tax, accounting, insurance, and professional requirements, resolve disputes, enforce agreements, and protect legitimate business interests.
Retention periods vary according to the nature and sensitivity of the information, the relationship involved, applicable limitation periods, legal requirements, and the risk associated with continued retention. As a general operational guideline, we may retain:
Inquiries that do not become projects for up to 24 months after the last substantive interaction, unless a longer period is appropriate for an ongoing business relationship or permitted marketing;
Client, project, design, procurement, and contractual records for up to 10 years after project completion or termination, or longer where reasonably necessary for warranties, insurance, claims, professional obligations, or applicable law;
Accounting, tax, and transaction records for the period required by applicable law and our professional advisers;
Marketing contact information until you unsubscribe or we otherwise determine that continued retention is no longer appropriate, while retaining limited suppression information as necessary to honor opt-out requests; and
Privacy, security, and compliance records for the period reasonably necessary to demonstrate compliance and address claims or regulatory inquiries.
We may retain information for a longer period where required by law, subject to litigation hold, necessary to establish or defend legal claims, or otherwise permitted by applicable law. We may also retain de-identified or aggregated information that can no longer reasonably identify you.
9. Information Security
We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, acquisition, destruction, loss, alteration, misuse, or disclosure. Our safeguards are intended to be proportionate to the nature of the information and the risks presented and may include access controls, account-security measures, vendor oversight, employee practices, system monitoring, secure disposal, and other reasonable measures.
No website, transmission, storage system, or security measure can be guaranteed to be completely secure. You should use appropriate care when sending sensitive information electronically. If we become aware of a security incident involving personal information, we will investigate and provide notices where required by applicable law.
10. Marketing Communications
We may send business-development or marketing communications where permitted by applicable law. You may unsubscribe from marketing emails at any time by using the unsubscribe mechanism in the message or by contacting us. We may retain limited information about your opt-out request so that we can honor it.
Opting out of marketing does not prevent us from sending non-marketing communications that are necessary for an existing client, vendor, contractual, transaction, security, or other business relationship.
11. Your Privacy Rights
Depending on where you live and the law that applies to our processing, you may have rights concerning your personal information. These rights may include the right to:
Request access to or a copy of personal information we hold about you;
Request correction or updating of inaccurate or incomplete information;
Request deletion of personal information, subject to legal and other permitted exceptions;
Object to or restrict certain processing;
Withdraw consent where processing is based on consent, without affecting processing that occurred before withdrawal;
Request portability of certain information where provided by law;
Opt out of sale, sharing, targeted advertising, or certain profiling where provided by law;
Appeal certain decisions concerning a privacy request where provided by law; and
Exercise applicable privacy rights without unlawful discrimination or retaliation.
These rights are not absolute. We may deny or limit a request where permitted or required by law, including where we cannot reasonably verify the request, where an exception applies, or where retention is required for legal, contractual, security, accounting, claims, or other permitted purposes.
How to exercise your rights
To submit a privacy request, email info@veronicamishaan.com and state that your message concerns a privacy request. Please describe the request and provide enough information for us to identify the relevant records. We may take reasonable steps to verify your identity and authority before responding. If an authorized agent submits a request where permitted by law, we may require proof of authorization and, where permitted, direct verification from the individual.
We will respond within the period required by applicable law. If you believe we have not appropriately addressed a request, you may have the right to appeal to us or complain to the competent privacy or data-protection authority in your jurisdiction.
Colombia
Where Colombian data-protection law applies, including Ley 1581 de 2012 and its implementing rules, data subjects may exercise the rights provided under Colombian law, including to know, update, and rectify personal data; request proof of authorization where applicable; obtain information regarding use; submit complaints to the Superintendencia de Industria y Comercio after applicable internal procedures have been exhausted; revoke authorization or request deletion where legally available; and access personal data free of charge in the circumstances provided by law.
United States
Residents of certain U.S. states, including Florida, may have additional privacy rights if the relevant state privacy law applies to us or to the particular processing. We will honor applicable rights and provide any required notices or opt-out mechanisms. Because statutory thresholds and exemptions vary, not every state privacy right applies to every business or interaction.
Other jurisdictions
If you are located somewhere other than the United States or Colombia and the law of that jurisdiction gives you specific privacy rights in connection with our processing of your personal information, we will honor those rights to the extent they apply to us, even where this Policy does not separately name that jurisdiction. Please contact us using the information in Section 16, identify the jurisdiction and law you are relying on, and describe your request, and we will respond appropriately.
12. Children’s Privacy
The Site is intended for a general audience and is not directed to children under 13. We do not knowingly collect personal information online from children under 13 through the Site. If you believe that a child under 13 has provided personal information to us through the Site, please contact us so that we can review and, where appropriate, delete the information.
Our design work may incidentally involve information relating to children in a client household, such as names, room requirements, photographs, or preferences. Such information is handled as part of the client relationship and should be provided by or with the authority of the responsible adult.
13. Third-Party Websites, Platforms, and Embedded Content
The Site may contain links to, integrations with, or embedded content from third-party websites, social-media services, marketplaces, publications, mapping services, video platforms, or other services. Those third parties may collect information independently and their privacy practices are governed by their own notices. We are not responsible for the privacy, security, or content practices of third-party services that we do not control.
14. Business Transfers and Changes in Control
If all or part of our business, assets, or operations are reorganized, financed, sold, transferred, merged, acquired, or subject to insolvency or similar proceedings, personal information may be disclosed or transferred as part of that transaction, subject to applicable law and appropriate protections.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, services, operations, or legal obligations. The effective date at the top of the Policy indicates when it was last revised. Where required by law, we will provide additional notice of material changes or seek consent before applying a material change to information already collected.
16. Contact Us
Questions, privacy requests, or concerns regarding this Privacy Policy or our handling of personal information may be directed to:
Veronica Mishaan
Attn: Privacy
401 Broadway, #2316
New York, NY 10013
United States
Email: info@veronicamishaan.com
Phone: +1-212-931-1210
For matters specifically involving our Bogotá operations, you may also contact our Bogotá office at:
Cra 9 No. 81A – 26, Oficina 802, Bogotá, Colombia.
Implementation Checklist — Remove Before Website Publication
This page is operational guidance and is not part of the public Privacy Policy. The policy above should not be published unless the Site and business practices match its statements.
Confirm the exact legal entity or entities acting as data controller/business, and add the legal name if different from the Veronica Mishaan brand name.
Confirm the specific countries or territories beyond Colombia where the firm regularly does business (for example, particular Caribbean nations). If any one of them is a recurring, ongoing part of operations rather than occasional project work, consider adding a short dedicated subsection for that jurisdiction in Sections 7 and 11.
Confirm that info@veronicamishaan.com is the desired privacy-request channel, or replace it with a dedicated privacy@ address.
Configure the cookie consent manager so non-essential analytics/advertising technologies are blocked before consent wherever prior consent is required; provide equally prominent accept/reject choices.
Audit Google Analytics 4, Meta Pixel, tag manager, embedded media, fonts, CAPTCHA, social embeds, CRM forms, and any other trackers. Ensure the policy and consent categories match what actually fires.
Determine whether Meta Pixel or other ad technology constitutes sale/sharing/targeted advertising under any applicable state law; if so, deploy the required opt-out link and honor supported opt-out preference signals.
Confirm retention periods with U.S. and Colombian counsel, your accountant, and any professional-indemnity insurer.
Complete a vendor/processor inventory and put appropriate contracts/data-processing terms in place for hosting, cloud storage, email, CRM, project management, accounting, analytics, marketing, logistics, and other processors.
Map international data flows among New York, Bogotá, clients, vendors, and any other locations where client or project data is regularly processed; document the lawful transfer mechanism required for each applicable regime.
For Colombia, confirm and maintain the required Política de Tratamiento de Datos Personales, authorization/notice procedures, complaint channels, and any Registro Nacional de Bases de Datos obligations.
Maintain a written information-security program appropriate to the New York SHIELD Act and other applicable laws, including access controls, MFA, vendor oversight, employee training, incident response, and secure disposal.
Establish a documented privacy-rights request workflow, identity-verification process, response calendar, appeal process where applicable, and request log.
Establish and test an incident-response and breach-notification procedure covering New York, Florida, Colombia, and any other jurisdiction in which affected individuals may reside.
Re-run a privacy and tracker audit after every material website redesign, new marketing technology, new CRM/integration, or expansion into a new jurisdiction.
Drafting basis
This draft was informed by current official guidance from the New York State Attorney General concerning the SHIELD Act and website privacy controls, the Colombian Superintendencia de Industria y Comercio’s data-protection framework, the Florida Statutes, and the U.S. Federal Trade Commission’s CAN-SPAM guidance. It intentionally omits jurisdiction-specific sections (such as EU/UK GDPR or Bermuda PIPA) that were in an earlier draft but do not match the firm’s stated footprint of New York, Florida, the Caribbean, and Colombia; Section 11’s “Other jurisdictions” clause is designed to cover occasional work outside those places without the added length of a full regional buildout. If the firm develops a recurring presence in the EU/UK, Bermuda, or elsewhere, a dedicated subsection should be added back. This drafting basis is not a substitute for legal advice.