Privacy policy
Last updated: [date]
1. Who is responsible for your data
The data controller is [business name], [registered address], VAT / tax ID [VAT or tax ID]. For any question about your data, write to us at [contact email].
2. What data we collect and why
When you place an order, we collect your name, email address, phone number and delivery address. We use them strictly to fulfil your order: so you receive the confirmation and the tracking number by email, so we can hand the parcel to the courier, and so we can issue the invoice (a legal obligation). The legal basis is the performance of the contract (art. 6(1)(b) GDPR) and our legal invoicing obligations (art. 6(1)(c)).
We don't collect your card details โ they are entered directly on the secure Stripe page and never reach us.
3. How long we keep it
We keep order data for as long as the law requires for accounting records (currently [5 / 10] years from the end of the financial year). We don't use it for marketing without your explicit consent.
4. Who else sees the data (our processors)
For the shop to work, the data passes through a few providers that process it on our behalf, each with its own GDPR safeguards:
โข Stripe โ payment processing (Stripe Payments Europe, Ireland);
โข Supabase โ the shop's database (the servers are in [the region chosen when creating the project โ e.g. Frankfurt, EU]);
โข Resend โ sending the confirmation and shipping emails;
โข [the courier's name] โ delivering the parcel (receives the name, phone and address);
โข [your invoicing service โ if you use one].
We never sell or rent your data to anyone.
5. Cookies
The site doesn't use tracking or advertising cookies. [If you add Google Analytics or other measurement tools, write here what you use and add a consent banner โ ask Claude.]
6. Your rights
You have the right to request access to your data, its correction, erasure (within the limits of our accounting obligations), restriction or portability, and to object to its processing. Write to us at [contact email] and we'll reply within 30 days at most. If you're not satisfied, you can lodge a complaint with [your national data protection authority].
7. Security
Data is transmitted encrypted (https), stored in a protected database that only the shop's administrator can access, and payments are processed by a PCI-DSS certified provider.