Legal
Privacy Policy
This is a general privacy policy template for an e-commerce store. Replace placeholders such as company identity, contact details, cookie tooling, and processor names with your actual data before publishing.
1. Data controller
Sympatisk Shop acts as the controller of personal data processed through this website. The final published version should identify the legal entity, registered office, company ID, support email, and any designated privacy contact.
2. What personal data we collect
We may collect identification and contact data, billing and delivery data, order history, account credentials, communication records, payment-related metadata, and technical website usage information such as IP address, browser information, and cookies.
3. Why we process personal data
We process personal data to create and manage customer accounts, accept and fulfill orders, deliver goods, handle payments, provide customer service, manage returns and complaints, prevent fraud, comply with legal obligations, and improve the performance and usability of the website.
4. Legal bases
Depending on the situation, personal data may be processed for the performance of a contract, compliance with legal obligations, legitimate interests such as fraud prevention and service improvement, or the customer’s consent where consent is required.
5. Payment and shipping partners
To complete orders, personal data may be shared with payment providers, banks, delivery carriers, IT service providers, accountants, legal advisors, hosting providers, and other processors who support the store’s operation. These parties process only the data necessary for their role.
6. Data retention
We retain personal data only for as long as necessary to fulfill the purpose for which it was collected, including warranty handling, bookkeeping, tax, anti-fraud, and legal archiving obligations. Retention periods should be aligned with applicable local and EU law.
7. Customer rights
Subject to applicable law, customers may request access to their personal data, correction of inaccurate data, deletion, restriction of processing, portability, or objection to certain processing activities. Where processing is based on consent, consent may be withdrawn at any time.
8. Cookies and analytics
The website may use essential cookies for cart, login, and security functionality, and may also use analytics or marketing cookies if enabled. Customers should be informed about cookie categories, retention, and consent choices through a dedicated cookie banner or settings tool.
9. Data security
We apply reasonable organizational and technical safeguards to protect personal data against unauthorized access, misuse, loss, or disclosure. This includes access controls, secure hosting, software updates, and limited internal access on a need-to-know basis.
10. International transfers
If service providers process data outside the European Economic Area, appropriate safeguards should be implemented, such as adequacy decisions, standard contractual clauses, or equivalent lawful transfer mechanisms.
11. Complaints
If a customer believes their personal data is being processed unlawfully, they may contact the store first and also have the right to lodge a complaint with the competent supervisory authority.
12. Policy updates
This Privacy Policy may be updated to reflect changes in law, business operations, or technical tools. The latest version published on the website applies from the effective date shown with the policy.