Skip to content

Privacy policy

1. What We Collect

When you purchase from or sign up with FELTORA, we may collect:

  • Identity data — name, email address, billing/delivery address.
  • Transaction data — order details, purchase history, gift note content.
  • Account data — login credentials, saved addresses, collection history.
  • Marketing preferences — whether you are in the Collectors' Circle, email opt-in status.
  • Device and usage data — IP address, browser type, pages visited (via cookies and analytics tools).

We do not collect payment card data directly — this is handled by our payment processor (Shopify Payments / Stripe) under PCI DSS compliance.

2. Why We Collect It

We use your data to:

  • Process and fulfil your order, including customs documentation.
  • Communicate about your order (confirmation, dispatch, delivery, returns).
  • Manage your Collectors' Circle membership and collection history.
  • Send you seasonal drop notifications and brand news — only if you have opted in.
  • Improve the site and product experience (analytics, A/B testing, search).
  • Meet legal obligations (tax records, fraud prevention, customs declarations).

3. Legal Basis for Processing (GDPR / UK GDPR)

Processing Purpose Legal Basis
Order fulfilment Contract performance
Marketing emails / Collectors' Circle Consent (explicit opt-in, double opt-in for EU/UK)
Fraud prevention Legitimate interest
Analytics and site improvement Legitimate interest (with cookie consent)
Legal / tax record retention Legal obligation

4. Data Sharing

We share your data with:

  • Our fulfilment and shipping partners — to process and deliver your order.
  • Customs authorities — as required for international shipments.
  • Our email/SMS marketing platform (e.g., Klaviyo) — only for customers who have opted in.
  • Analytics tools (e.g., Google Analytics) — under their respective data processing agreements.
  • Payment processors — under PCI DSS standards.

We do not sell your data. We do not share it with advertisers. We do not send it to any country without ensuring adequate protection under applicable law (Standard Contractual Clauses for EU transfers, adequacy decisions where available).

5. Your Rights

Depending on your market, you have the right to:

  • Access — see what data we hold about you.
  • Rectification — correct inaccurate data.
  • Erasure — request deletion of your data ('right to be forgotten'), subject to our legal retention obligations.
  • Restriction — ask us to limit how we use your data.
  • Portability — receive your data in a machine-readable format.
  • Objection — object to processing based on legitimate interest, including profiling for marketing.
  • Withdraw consent — for any processing based on consent (e.g., marketing emails), at any time.

To exercise any right, email privacy@feltora.com. We respond within 30 days (UK/EU GDPR standard).

6. Cookies

We use cookies for essential site operation, analytics, and (with your consent) marketing. A cookie consent banner is shown on first visit in all markets where legally required. You may manage or withdraw cookie consent at any time via the cookie settings link in the footer.

We do not track you across other websites for advertising purposes without explicit consent.

7. Data Retention

We retain order and transaction data for 7 years (to meet tax obligations in most markets). Marketing preferences and collection history are retained while your account is active. You may request deletion of marketing data at any time without affecting your ability to make purchases or access order history.

8. Children's Data

FELTORA does not knowingly collect data from children under 16 (or 13 in the USA under COPPA). Our site is not directed at children. If you believe a child has provided personal data through our site, contact us at privacy@feltora.com and we will delete it promptly.

9. Market-Specific Compliance Notes

Market Key Legal Framework Action Required
EU (DE / NL / SE / NO / DK / FI) GDPR (Regulation 2016/679) + ePrivacy Directive Cookie banner, double opt-in, DPA for processors, IOSS VAT registration
United Kingdom UK GDPR + PECR UK ICO registration, separate UK Privacy Policy, cookie consent
United States State privacy laws (CCPA/CPRA CA, VCDPA VA, etc.) Do Not Sell / Share opt-out, Privacy Policy covering each enacted state law
Germany GDPR + TTDSG (German Telecommunications Act) TTDSG-compliant cookie consent; stricter than standard GDPR
Japan APPI (Act on Protection of Personal Information) Japanese-language Privacy Policy; data transfer restrictions
South Korea PIPA (Personal Information Protection Act) Korean-language Privacy Policy; local representative if required
Canada PIPEDA / Quebec Law 25 Consent for collection; Quebec privacy assessment obligations
China PIPL (Personal Information Protection Law) Data localization requirements; market-specific approach