Contract performance
When you place an order, processing your account and order data is necessary to perform the contract of sale. This covers order fulfilment, shipping, returns, and refunds.
This page covers how this site collects, uses, stores, and shares personal data — and the rights you have under the EU and UK General Data Protection Regulation. Written in plain English, with the legal references named where they apply.
The legal entity responsible for the processing described on this page.
This site is operated by [REGISTERED COMPANY NAME], the legal entity registered as the operator of this online store. Full company details — including registered office, commercial register number, legal representative, and VAT registration — are listed in our Imprint.
For all matters relating to personal data, the primary contact is [PRIVACY EMAIL]. We respond to data protection inquiries within one working day during business hours.
Where the data controller is established outside the European Economic Area, GDPR Article 27 requires the appointment of an EU representative. The current representative is named in the Imprint, Section 06.
The data the site collects falls into five categories. Each one is listed below with what it includes, when it is collected, and how long it is kept.
When you place an order or create an account: name, email, shipping address, billing address, telephone (optional), order history, and language/currency preference. This data is necessary to fulfil the contract of sale and to provide customer support afterwards.
Payment is processed by our payment service providers (Shopify Payments, regional alternatives where applicable). We do not store full card numbers or CVV codes on our servers. What we receive from the processor is a transaction reference, the last 4 digits of the card, the card brand, and the success/failure status.
When you write to us — by email, contact form, or chat — we keep the message content and our reply, the email address, and the time of the exchange. This is so we can pick up follow-up questions in context.
Server logs collect IP address, browser user-agent, page URL, referrer URL, and timestamp for every request. Logs are retained for 30 days for security and abuse-prevention purposes, then deleted automatically.
If you subscribe to our newsletter or opt into marketing cookies, we collect: email, opt-in timestamp, country, language, open/click behaviour on our emails, and conversion data from advertising platforms. See the Cookie Policy for the full picture on tracking.
GDPR requires that every category of data has a clearly stated purpose. The list below maps each category to what it is used for.
We do not process personal data for any purpose not in the list above. We do not sell personal data to third parties under any circumstances.
Every act of processing must rest on one of six lawful bases listed in Article 6 of the GDPR. This site uses four of them.
When you place an order, processing your account and order data is necessary to perform the contract of sale. This covers order fulfilment, shipping, returns, and refunds.
EU and national tax law require us to retain invoices and order records for set periods (typically 7–10 years). Consumer protection law requires we keep records of complaints and returns.
Security logs, fraud prevention, and the customer support function rest on legitimate interests — running a safe, functional commerce site. We have weighed these against your interests and rights and consider the balance reasonable.
Marketing emails, optional analytics cookies, and advertising cookies all require your active opt-in. You can withdraw consent at any time, and we make that withdrawal as easy as the initial opt-in.
Some processors are based outside the European Economic Area. Where this happens, we use the safeguards required by GDPR Chapter V.
The primary platform provider, Shopify, processes data in Canada and the United States. These transfers are covered by the EU–US Data Privacy Framework (where applicable for US transfers) and by Standard Contractual Clauses under Article 46 GDPR. Canada has been designated by the European Commission as providing adequate protection under Article 45 GDPR.
You have the right to request a copy of the transfer mechanism applicable to a specific processor. Write to [PRIVACY EMAIL] and we will provide the relevant Standard Contractual Clauses or adequacy decision reference.
We keep personal data only for as long as needed for the purpose, or as required by law. The schedule below is the working framework.
At the end of the retention period, data is either deleted or fully anonymised (such that re-identification is no longer possible). Anonymised data may be retained for statistical purposes without restriction.
GDPR Article 32 requires appropriate technical and organisational measures. The measures below are the working baseline.
In the unlikely event of a personal data breach that creates risk to your rights and freedoms, we will notify the supervisory authority within 72 hours of becoming aware, and notify affected individuals without undue delay where required by Article 34 GDPR.
GDPR grants every data subject eight rights. The table below summarises each, with a brief note on how to exercise it on this site.
You can request a copy of the personal data we hold about you, along with the purposes of processing, recipients, retention periods, and the source if not collected from you directly.
You can ask us to correct inaccurate data, or complete data that is incomplete. For account-related fields you can also edit them yourself at /account.
Also called the right to be forgotten. You can ask us to delete your personal data, subject to legal retention obligations (e.g., tax records must be kept 10 years regardless).
You can ask us to stop processing your data while a dispute is resolved (e.g., during a rectification request, or if you object to processing on legitimate-interest grounds).
You can request your data in a structured, commonly used, machine-readable format (we typically provide CSV or JSON), and have it transmitted to another controller where technically feasible.
You can object to processing based on legitimate interests, and to direct marketing at any time (unsubscribe is the standard channel for the latter).
We do not use automated decision-making, including profiling, that produces legal effects on you or similarly significantly affects you. Marketing segmentation does not meet this threshold.
If you believe we mishandle your data, you can complain to the supervisory authority in your country of residence, place of work, or place of the alleged infringement.
For any exercise of rights, complaint, or general question about how we handle personal data, write to [PRIVACY EMAIL]. We respond within one working day.
You can lodge a complaint with the data protection authority in your country. In the UK: the Information Commissioner's Office. In Germany: the relevant Bundesbeauftragte für den Datenschutz. In France: the CNIL. A full list of EU/EEA authorities is available at edpb.europa.eu/about-edpb/about-edpb/members.
Privacy policies are often pages of legalese designed to deter reading. We have tried for the opposite: clear sections, plain English, the legal references named when they apply. If something here is unclear, write — we read every message.