The controller of the personal data of the online shop is suckors.com (registry code 12777641), located at Lootsi 19, Kuressaare, 93810 ESTONIA and email firstname.lastname@example.org. The controller has designated a data protection officer who can be contacted by via email email@example.com.
What personal data are processed
- name, phone number and email address;
- delivery address;
- IP address;
- bank account number and bank information;
- cost of goods and services and data related to payments (purchase history);
- customer support data.
Why personal data are processed
Personal data are used to manage the customer’s orders and deliver goods.
Purchase history details (date of purchase, goods, quantity, customer’s data) are used for preparing summaries of goods and services purchased and for analysing customer preferences.
The bank account number is used to reimburse payments to the customer.
Personal data such as email, phone number and the customer's name are processed to handle any issues relating to the provision of goods and services (customer support).
The IP address or other web identifiers of a user of the online shop are processed for the provision of the online shop as an information society service and for web use statistics.
Personal data are processed for the purpose of performing a contract concluded with the customer.
Personal data are processed for performing legal obligations (such as accounting and the settlement of consumer complaints).
Data are processed with the customer's consent for sending e-mails about the store, new products and other updates.
Recipients of personal data
Personal data are transmitted to the customer support of the online shop for managing purchases and purchase history and for settling any problems that the customers may have.
The name, phone number and email address are transmitted to the transport service provider selected by the customer. When the goods are delivered by a courier, the customer’s address is also transmitted together with the contact details.
If the accounts of the web shop are kept by a service provider, the personal data are transmitted to the service provider for performing accounting operations.
Personal data may be transmitted to IT service providers if this is necessary for ensuring the functionality of the online shop or for data hosting.
As defined by applicable data protection laws, Maksekeskus AS (as data processor) processes personal data on behalf of the data controller.
The store is hosted on Shopify Inc., who provides controller with the online e-commerce platform that allows us to sell the products. Personal data is stored through Shopify’s data storage, databases and the general Shopify application. They store Personal data on a secure server behind a firewall.
If a direct payment gateway is chosen to complete the purchase, then Shopify stores credit card data. It is encrypted through the Payment Card Industry Data Security Standard (PCI-DSS). The purchase transaction data is stored only as long as is necessary to complete the purchase transaction. After that is complete, the purchase transaction information is deleted.
All direct payment gateways adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, MasterCard, American Express and Discover. PCI-DSS requirements help ensure the secure handling of credit card information by controller’s store and its service providers.
Here is a list of cookies that are used. You can choose if you want to opt-out of cookies or not.
_session_id, unique token, sessional, Allows Shopify to store information about your session (referrer, landing page, etc)._shopify_visit, no data held, Persistent for 30 minutes from the last visit, Used by our website provider’s internal stats tracker to record the number of visits _shopify_uniq, no data held, expires midnight (relative to the visitor) of the next day, Counts the number of visits to a store by a single customer. cart, unique token, persistent for 2 weeks, Stores information about the contents of your cart.
_secure_session_id, unique token, sessional storefront_digest, unique token, indefinite If the shop has a password, this is used to determine if the current visitor has access. Security and access to data
Personal data are stored in the servers of Shopify, which are located on the territory of a member state of the European Union or states of the European Economic Area. Data may be transferred to the countries whose data protection levels have been assessed as adequate by the European Commission and to the companies in the USA who have joined the Privacy Shield framework.
Personal data can be accessed by the staff of the online shop in order to settle technical issues related to the use of the online shop and to provide customer support.
The online shop takes appropriate physical, organisational and IT security measures to protect personal data against accidental or unlawful destruction, loss, alteration or unauthorised access and disclosure.
Personal data are transmitted to the data processors of the online shop (such as the providers of transport and data hosting services) and processed under contracts concluded between the online shop and the processors. The processors must ensure appropriate safeguards when processing personal data.
Access to and rectification of personal data
Personal data can be accessed and rectified in the user profile of the online shop. When a purchase has been made without a user account, personal data can be accessed through customer support.
Withdrawal of consent
Where personal data are processed on the basis of the customer’s consent, the customer has the right to withdraw his/her consent by notifying customer support by email to firstname.lastname@example.org.
Personal data are erased upon the closure of a customer account of the online shop, unless the storage of the data is necessary for accounting purposes or for the settlement of consumer disputes.
For online purchases made without a customer account, the purchase history is stored for three years.
In the event of disputes concerning payments and consumer disputes, the personal data are stored until the claim is satisfied or until the end of the limitation period.
Personal data needed for accounting purposes are stored for seven years.
For the erasure of the personal data, customer support must be contacted via e-mail email@example.com. Requests of erasure are responded to no later than within one month and the period of erasure shall be specified.
Requests to transmit personal data submitted via email are responded to within one month. Customer support identifies the person and indicates what personal data are to be transmitted.
Direct marketing messages
Email address and phone number are used for sending direct marketing messages if the customer has given the respective consent. If the customer does not want to receive direct marketing messages, the customer should select the relevant link at the footer of the email or contact us firstname.lastname@example.org.
Where personal data are processed for direct marketing purposes (profiling), the customer has the right to object at any time both to the initial and further processing of his/her personal data, including profiling related to direct marketing by notifying customer support thereof via email to email@example.com.
Questions and contact information
If you would like to: access, correct, amend or delete any personal information we have about you, register a complaint, or simply want more information contact
firstname.lastname@example.org. The supervisory authority is the Estonian Data Protection Inspectorate (email@example.com)