Privacy Policy
This Privacy Policy explains how we collect, use and protect your personal data when you visit our store and place an order. We are committed to handling your information responsibly and in line with the EU General Data Protection Regulation (GDPR).
1. Who we are
We are the data controller for the personal data collected through this store. For any privacy question you can reach us via our Contact page or by email at privacy@example.com.
2. What personal data we collect
- Contact and account details: name, email address, phone number.
- Order and delivery information: billing and shipping address, order history.
- Payment information: processed by our payment provider; we do not store full card numbers.
- Technical data: IP address, device and browser information, and basic usage analytics.
3. How and why we use your data
We use your data to process and deliver your orders, provide customer support, send order updates, prevent fraud, and — with your consent — send occasional news about new toys and offers.
4. Legal bases for processing
We process your data to perform our contract with you (fulfilling orders), to comply with legal obligations (such as tax and accounting), on the basis of your consent (marketing emails), and for our legitimate interests (keeping the store secure and improving it).
5. Sharing with third parties
We share data only with the processors we need to run the store: payment providers, delivery couriers and analytics services. They act on our instructions and may not use your data for their own purposes. We never sell your personal data.
6. Cookies and tracking
We use cookies to keep your basket working, remember your preferences and understand how the store is used. You can control non-essential cookies through your browser settings or our cookie banner.
7. International transfers
Where a processor is located outside the European Economic Area, we ensure an adequate level of protection through approved safeguards such as the European Commission's Standard Contractual Clauses.
8. Data retention
We keep order records for as long as required by tax and accounting law, account data for as long as your account is active, and marketing data until you unsubscribe. After that, data is securely deleted or anonymised.
9. Your rights
Under the GDPR you have the right to access, correct, delete, restrict or object to the processing of your personal data, and the right to data portability. You may also withdraw consent for marketing at any time.
10. How to exercise your rights
To exercise any of these rights, contact us through our Contact page. If you believe we have not handled your data properly, you may lodge a complaint with the State Data Protection Inspectorate of Lithuania.
11. Data security
We use encryption in transit, access controls and trusted providers to keep your data safe. Payment details are handled by PCI-compliant providers.
12. Changes to this policy
We may update this policy from time to time. Significant changes will be highlighted on this page, and continued use of the store means you accept the current version. This policy works alongside our Terms of Service.