Privacy Policy
Privacy Policy – Olivia Grace Boutique
1. Information on the Collection of Personal Data and Contact Details of the Controller
1.1
We appreciate your interest in visiting our website and thank you for taking the time to learn about our store. The following statement explains how we handle your personal data when you browse or interact with our website. “Personal data” refers to any information that can identify you personally.
1.2
The data controller responsible for processing on this website, in accordance with the General Data Protection Regulation (GDPR), is Olivia Grace Boutique. The controller is the individual or organization that determines the purpose and method of processing personal data.
1.3
For your security and to protect the transfer of confidential information (such as orders or inquiries), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the “https://” prefix and the padlock symbol in your browser’s address bar.
2. Data Collection When Visiting Our Website
When you visit our website for informational purposes only—without registering or submitting information through forms—we automatically collect certain technical data transmitted by your browser to our servers (server log files).
This data may include:
-
The page you visited
-
Date and time of access
-
Amount of data transferred
-
Source or referral link
-
Browser and operating system used
-
IP address (anonymized where possible)
This information is collected in accordance with Article 6(1)(f) GDPR, based on our legitimate interest in ensuring website functionality, security, and stability. The data is not shared or analyzed in any other way, except in cases where illegal use of our website is suspected.
3. Cookies
To enhance your browsing experience and enable specific features, our website uses cookies — small text files stored on your device.
-
Session cookies are automatically deleted once you close your browser.
-
Persistent cookies remain stored for a set period or until manually removed.
Certain cookies are essential to website operation (e.g., keeping items in your cart), while others help improve usability and analytics.
If cookies involve personal data, processing is based on Article 6(1)(b) (performance of contract) or Article 6(1)(f) (legitimate interest in usability and site optimization).
You can adjust your browser settings to notify you when cookies are being set or to refuse cookies altogether. However, please note that disabling cookies may limit certain features.
Guides for major browsers:
4. Contact
When you reach out to us via contact form or email, we collect the personal data you provide. This information is used only to respond to your inquiry and manage your request.
The legal basis for this processing is Article 6(1)(f) GDPR, reflecting our legitimate interest in customer communication.
If your contact relates to an order or contract, Article 6(1)(b) also applies.
Once your inquiry has been fully resolved, the related data will be deleted unless legal retention obligations apply.
5. Customer Accounts and Contract Fulfilment
When creating an account or placing an order, we collect personal data necessary to process your purchase, such as name, address, email, payment details, and delivery information.
This data is processed in accordance with Article 6(1)(b) GDPR for contractual purposes.
Your data may be retained for accounting and tax purposes as required by law. Once retention periods expire, it will be deleted unless further processing is legally permitted or you have provided consent for continued storage.
6. Use of Data for Direct Marketing
6.1 Newsletter Subscription
If you sign up for our email newsletter, we will send you regular updates about our offers and new collections. Only your email address is required; additional information is optional.
We use a double opt-in system to confirm your consent.
By confirming your subscription, you authorize us to process your data in accordance with Article 6(1)(a) GDPR.
You may unsubscribe anytime by clicking the link in the email or contacting us directly.
6.2 Newsletter to Existing Customers
If you’ve previously purchased from us, we may send you information about similar products. This is done based on our legitimate interest under Article 6(1)(f) GDPR.
You can opt out at any time without incurring any cost other than transmission charges.
7. Order and Payment Processing
7.1 General Order Processing
We share your personal data with shipping providers only when necessary for delivery. Payment information is shared with your selected payment provider solely to process transactions.
7.2 Payment Service Providers
Depending on your choice, payments may be processed through:
-
PayPal – Privacy Policy
-
Afterpay – Privacy Policy
-
Shopify Payments – Privacy Policy
Data sharing with payment processors is conducted according to Article 6(1)(b) GDPR for contract fulfillment.
8. Review Requests
With your consent, we may send you a one-time email asking for feedback on your purchase experience.
You can withdraw consent at any time by contacting us.
Processing is based on Article 6(1)(a) GDPR.
9. Social Media Plugins
To protect your data, we use “Shariff” links for social media buttons instead of direct plugins. This means that no connection to social media servers is established unless you actively click a button.
Platforms may include:
-
Facebook – Privacy Policy
-
Instagram – Privacy Policy
-
TikTok – Privacy Policy
10. Online Marketing and Analytics
We use tracking and analytics tools to measure traffic and improve performance:
-
Google Analytics (GA4) – Anonymized tracking of visitor behavior
-
Google Ads Conversion Tracking – Measures ad performance
-
Meta (Facebook) Pixel – Tracks conversions and remarketing effectiveness
Processing is based on Article 6(1)(a) GDPR (consent).
You can disable or manage cookies at any time in your browser or via the cookie banner on our website.
For more information:
11. Your Rights as a Data Subject
Under the GDPR, you have the following rights regarding your personal data:
-
Right to access (Article 15)
-
Right to rectification (Article 16)
-
Right to erasure (Article 17)
-
Right to restriction of processing (Article 18)
-
Right to data portability (Article 20)
-
Right to object (Article 21)
-
Right to lodge a complaint with a supervisory authority (Article 77)
You may withdraw your consent to data processing at any time with future effect by contacting us directly.
12. Data Retention
Personal data is stored only as long as necessary for the purposes described or as required by legal retention obligations (e.g., tax or accounting). Once these obligations expire, the data is deleted unless further processing is justified.
13. Updates to This Privacy Policy
We may revise this Privacy Policy from time to time to reflect legal or operational changes.
The latest version will always be available on our website, with the “Last Updated” date noted at the top.