Privacy policy
1. What We Collect
When you purchase from or sign up with FELTORA, we may collect:
- Identity data: name, email address, billing and delivery address
- Transaction data: order details, purchase history, gift note content
- Account data: login credentials, saved addresses, collection history
- Marketing preferences: whether you are in the Collectors' Circle, and your email opt-in status
- Device and usage data: IP address, browser type, pages visited, via cookies and analytics tools
We do not collect payment card data directly. This is handled by our payment processor, Shopify Payments or Stripe, under PCI DSS compliance.
2. Why We Collect It
We use your data to:
- Process and fulfil your order, including customs documentation
- Communicate about your order: confirmation, dispatch, delivery and returns
- Manage your Collectors' Circle membership and collection history
- Send you seasonal drop notifications and brand news, only if you have opted in
- Improve the site and product experience through analytics, A/B testing and search
- Meet legal obligations covering tax records, fraud prevention and customs declarations
3. Legal Basis for Processing (GDPR / UK GDPR)
| Processing Purpose | Legal Basis |
|---|---|
| Order fulfilment | Contract performance |
| Marketing emails and the Collectors' Circle | Consent, explicit opt-in, double opt-in for the EU and UK |
| Fraud prevention | Legitimate interest |
| Analytics and site improvement | Legitimate interest, with cookie consent |
| Legal and tax record retention | Legal obligation |
4. Data Sharing
We share your data with:
- Our fulfilment and shipping partners, to process and deliver your order
- Customs authorities, as required for international shipments
- Our email and SMS marketing platform, for example Klaviyo, only for customers who have opted in
- Analytics tools, for example Google Analytics, under their respective data processing agreements
- Payment processors, under PCI DSS standards
We do not sell your data. We do not share it with advertisers. We do not send it to any country without ensuring adequate protection under applicable law, using Standard Contractual Clauses for EU transfers and adequacy decisions where available.
5. Your Rights
Depending on your market, you have the right to:
- Access: see what data we hold about you
- Rectification: correct inaccurate data
- Erasure: request deletion of your data, the "right to be forgotten", subject to our legal retention obligations
- Restriction: ask us to limit how we use your data
- Portability: receive your data in a machine-readable format
- Objection: object to processing based on legitimate interest, including profiling for marketing
- Withdraw consent: for any processing based on consent, such as marketing emails, at any time
To exercise any right, email feltora@dekulture.com. We respond within 30 days, the UK and EU GDPR standard.
6. Cookies
We use cookies for essential site operation, analytics, and with your consent, marketing. A cookie consent banner is shown on first visit in all markets where legally required. You may manage or withdraw cookie consent at any time via the cookie settings link in the footer. We do not track you across other websites for advertising purposes without explicit consent.
7. Data Retention
We retain order and transaction data for 7 years, to meet tax obligations in most markets. Marketing preferences and collection history are retained while your account is active. You may request deletion of marketing data at any time without affecting your ability to make purchases or access order history.
8. Children's Data
FELTORA does not knowingly collect data from children under 16, or under 13 in the USA under COPPA. Our site is not directed at children. If you believe a child has provided personal data through our site, contact us at feltora@dekulture.com and we will delete it promptly.
9. Market-Specific Frameworks
We handle your data under the framework that applies where you live:
| Market | Key Legal Framework |
|---|---|
| EU (Germany, Netherlands, Sweden, Norway, Denmark, Finland) | GDPR (Regulation 2016/679) and the ePrivacy Directive |
| United Kingdom | UK GDPR and PECR |
| United States | State privacy laws, including CCPA/CPRA in California and VCDPA in Virginia |
| Germany | GDPR and the TTDSG (German Telecommunications Act) |
| Japan | APPI (Act on Protection of Personal Information) |
| South Korea | PIPA (Personal Information Protection Act) |
| Canada | PIPEDA and Quebec Law 25 |
| China | PIPL (Personal Information Protection Law) |



