Privacy Policy

1

Data Controller

The data controller responsible for data processing under the Swiss Federal Act on Data Protection (revFADP) and the EU General Data Protection Regulation (GDPR) is:

Vladyslav Payik, Margaretenweg 7, 4310 Rheinfelden, Switzerland.

Email: payikvladyslav@gmail.com

Online store: spinscrubi.store

2

Scope

This policy applies to the processing of personal data through our online store spinscrubi.store and related marketing activities. The Swiss revFADP applies; for visitors from the EU/EEA, the GDPR additionally applies.

3

What Data We Process

  • Order and customer data: name, shipping and billing address, email, phone number, order history.
  • Payment data: processed by our payment providers; we do not store full card details.
  • Account data: if a customer account is created (login details, preferences).
  • Communication data: inquiries via email or contact form.
  • Usage and device data: IP address, browser and device type, pages visited, timestamps, referrer.
4

Purposes and Legal Bases

  • Contract performance and order processing (Art. 6(1)(b) GDPR; Art. 31 revFADP)
  • Customer service and communication (lit. b/f)
  • Marketing and reach measurement (lit. a consent or lit. f legitimate interest)
  • Compliance with legal obligations (lit. c)
5

Platform and Hosting: Shopify

Our store is hosted by Shopify International Ltd. / Shopify Inc. As our data processor, Shopify processes customer and usage data (e.g. cookies, checkout, customer accounts) on our behalf and may transfer this data to third parties and other countries in order to provide its services. More information: shopify.com/legal/privacy.

6

Payment Providers

For payment processing, we use Shopify Payments and PayPal. Payment and transaction data is transmitted directly to the respective provider and processed in accordance with its own privacy policy.

7

Cookies and Tracking

We use technically necessary cookies as well as, with the consent of visitors from the EU/EEA, analytics and marketing cookies. In Switzerland, the use of non-essential cookies can be objected to.

8

Pinterest Tag and Pinterest API (Marketing)

We use services from Pinterest (Pinterest Inc., USA) for marketing and reach measurement:

  • Pinterest Tag / Conversions API: if active, collects information about your visit (e.g. pages visited, actions, device/cookie identifiers) and transmits it to Pinterest. This data may be used for interest-based advertising. Pinterest and we are joint controllers in this regard.
  • Opt-out: via Pinterest's personalization settings as well as via optout.aboutads.info.
  • Pinterest API: used solely to publish our own marketing pins from our business account. No personal data of our shop customers is transmitted to Pinterest.
  • Pinterest's privacy policy: policy.pinterest.com/en/privacy-policy.
9

Recipients and Data Processors

We share personal data with the following categories of recipients, to the extent necessary for the purposes stated: hosting/store platform (Shopify), payment providers (Shopify Payments, PayPal), shipping and logistics providers, marketing and analytics services (including Pinterest), IT and email service providers.

10

International Data Transfers

Some recipients are located abroad, including in the USA. Transfers only take place where an adequate level of protection is ensured, namely for companies certified in the USA under the Swiss-U.S. Data Privacy Framework, or otherwise on the basis of standard contractual clauses or other safeguards under Art. 16(2) revFADP / Art. 46 GDPR.

11

Retention

We retain personal data only for as long as necessary for the purposes stated or as required by statutory retention periods, after which it is deleted or anonymized.

12

Your Rights

Subject to the revFADP and the GDPR, you have the right to access, rectify, erase, restrict, and port your data, as well as the right to object and to withdraw any consent given at any time. Please send requests to payikvladyslav@gmail.com. EU/EEA data subjects also have the right to lodge a complaint with their data protection supervisory authority; in Switzerland, with the Federal Data Protection and Information Commissioner (FDPIC).

13

Data Security

We take appropriate technical and organizational measures, including TLS/HTTPS encryption, to protect your data.

14

Changes

We may update this privacy policy. The version published on spinscrubi.store at any given time applies.