Legal
Privacy Policy
Last updated: 2 July 2026
This policy explains what personal data we collect when you buy from sofiavitrine.com, why we collect it, and the rights you have. We keep it short and plain because we ask for very little.
1. Who is responsible for your data
The controller of your personal data is [TRADER LEGAL NAME], a sole trader registered in the Slovak Republic, of [REGISTERED ADDRESS]. For anything about your privacy, email us at [CONTACT EMAIL]. We are a small trader and are not required to appoint a Data Protection Officer.
2. What we collect
- The email address you enter at checkout.
- Your delivery details — name, shipping address, and phone number for the carrier.
- Your order details — the item, the amount, and the date.
- Security logs from Cloudflare, which helps keep the site online and safe (for example, IP address and basic request data).
Your card details are handled entirely by Stripe — we never see or store your full card number. To be clear about what we do not do: we have no user accounts, we do not run a newsletter, and we do not use any analytics or tracking tools.
3. Why we use it, and our lawful bases
- To fulfil your order — taking payment, dispatching your item, and communicating with you about it. Lawful basis: performance of a contract (Article 6(1)(b) GDPR).
- To meet our legal obligations — keeping accounting and tax records. Lawful basis: legal obligation (Article 6(1)(c) GDPR).
- To prevent fraud and keep the site secure. Lawful basis: our legitimate interests in protecting our business and our customers (Article 6(1)(f) GDPR).
4. Who we share it with
We only share data with the providers we need to run the shop:
- Stripe — processes your payment. You enter your card details directly with Stripe, which confirms the payment to us. See stripe.com/privacy.
- Cloudflare — hosts and protects the website.
- Our delivery carrier and its insurer — to ship and insure your order.
- Our accountant and the tax authorities — to keep and file our records as the law requires.
5. International transfers
Some providers, such as Stripe and Cloudflare, may process data in the United States. Where this happens, the transfer is protected by appropriate safeguards — the EU–US Data Privacy Framework and its UK Extension, and Standard Contractual Clauses where relevant.
6. How long we keep it
We keep order and invoice data for [10 YEARS — CONFIRM] to comply with Slovak accounting and tax law. Anything we do not need to keep for that purpose is held only as long as it is needed to complete and support your order, then deleted.
7. Your rights
Under data protection law you have the right to:
- access the data we hold about you;
- have inaccurate data corrected;
- have your data erased, where the law allows;
- restrict how we use your data;
- receive your data in a portable format;
- object to processing based on our legitimate interests.
To exercise any of these, email us at [CONTACT EMAIL]. We will respond within one month.
8. Complaints
We hope you will come to us first. You also have the right to complain to a data protection authority — the Slovak Office for Personal Data Protection (Úrad na ochranu osobných údajov Slovenskej republiky), the authority in your own country, or, in the United Kingdom, the Information Commissioner's Office (ICO).
9. Cookies
Our site sets no cookies of its own. When you reach the checkout, Stripe's payment tools set a small number of strictly-necessary cookies (of the __stripe_mid and __stripe_sid kind) to process your payment safely and prevent fraud. Because these are essential to the checkout, no consent banner is needed. You can read more in Stripe's cookie policy.
10. Changes and contact
We may update this policy from time to time; the date at the top shows when it last changed. For any question about your privacy, email us at [CONTACT EMAIL].