Privacy Policy
Last updated: 2026-05-31
This policy explains what personal data Secret Hair Vitamins collects when you visit our store or place an order, why we process it, and the rights you have under the EU General Data Protection Regulation (GDPR).
1. Who we are (data controller)
The controller responsible for your personal data is Secret Hair Vitamins (org. no. [Company reg. number]), [Street address], [City, State/Region, Postal code], [Country]. For any privacy question or to exercise your rights, contact us at support@secrethairvitamins.com.
2. What we collect
- Order & contact details — name, email, shipping address, and order contents.
- Payment data — processed directly by our payment provider (Stripe). We never see or store your full card number.
- Technical data — IP address, device/browser type, and basic usage data needed to run the site securely.
3. Why we process it & legal basis
- To fulfil your order (process payment, ship, support) — performance of a contract (GDPR Art. 6(1)(b)).
- To send order confirmations & service emails — performance of a contract.
- To meet accounting/tax obligations — legal obligation (Art. 6(1)(c)).
- To secure and improve the site — our legitimate interest (Art. 6(1)(f)).
- Marketing emails, if any — only with your consent (Art. 6(1)(a)), which you can withdraw at any time.
4. Who we share it with (processors)
We share data only with service providers that help us run the store, under data-processing agreements:
- Stripe — payment processing.
- Resend — sending transactional order emails.
- Vercel — website hosting and infrastructure.
- Shipping/fulfilment partners — to deliver your order.
Some providers may process data outside the EU/EEA; where they do, transfers are protected by EU Standard Contractual Clauses or an equivalent safeguard. We never sell your personal data.
5. How long we keep it
Order and invoicing records are kept for as long as required by the accounting and tax laws that apply to our business. Other data is kept only as long as needed for the purpose it was collected for, then deleted or anonymised.
6. Cookies
We use only the cookies strictly necessary to operate checkout and keep the site secure. If we add analytics or marketing cookies in future, we will ask for your consent first via a cookie banner.
7. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict or object to processing of your data, and to data portability. To exercise any of these, email support@secrethairvitamins.com. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY).
This page is a template provided as a starting point and is not legal advice. Replace the bracketed details and have it reviewed for your specific business before relying on it.