Last Updated: May 22, 2024
This Privacy Policy describes how Pixelflake Oy (referred to as “the Site”, “we”, “us”, or “our”) collects, uses, and discloses your personal information when you visit, use our services, or make a purchase from our website desksetupsensei.com.
1. DATA CONTROLLER
2. PERSONAL INFORMATION WE COLLECT
We collect various types of information to provide and improve our services:
- Contact Information: Name, shipping address, billing address, email address, and phone number.
- Order & Transaction Information: Details about products purchased, order date, total amount, and payment status.
- Payment Information: Payment processing is handled by Stripe. We do not store full credit card numbers on our servers; Stripe provides us with secure tokens and payment status.
- Device & Technical Information: IP address, browser type, time zone, operating system, and unique device identifiers.
- Interaction Data: How you browse our site, products viewed, cart additions, and the website or search term that referred you to our site.
- Marketing Data: Your preferences for receiving marketing from us and your communication preferences.
3. HOW WE COLLECT YOUR DATA
- Direct Interaction: When you fill out forms, create an account, or communicate with us by email.
- Automated Technologies: As you interact with our site, we use cookies, server logs, and pixels (Meta Pixel, TikTok Pixel, Google Tags) to collect technical data.
- Third Parties: We receive information from technical service providers (WooCommerce), payment processors (Stripe), and advertising networks.
4. PURPOSES AND LEGAL BASES FOR PROCESSING
Under the GDPR, we process your data based on:
- Performance of a Contract: To process and ship your orders.
- Consent: For email marketing (newsletters) and non-essential cookies.
- Legal Obligation: For tax and accounting purposes (e.g., Finnish Accounting Act).
- Legitimate Interest: For fraud prevention, website analytics, and improving our store’s functionality.
5. DATA SHARING AND DISCLOSURE
We share your personal information with service providers to help us provide our services, including:
- E-commerce Platform: WooCommerce.
- Logistics: Shipit.fi (and its integrated carriers such as Posti, DHL, UPS, etc.) to deliver your packages.
- Payment Processing: Stripe.
- Analytics: Google Analytics, Google Search Console.
- Marketing & Advertising: Meta (Facebook/Instagram), TikTok.
We may also share your information to comply with applicable laws and regulations, to respond to a subpoena, or other lawful request for information we receive.
6. CROSS-BORDER DATA TRANSFERS
As we use service providers like Google, Meta, and Stripe, your information may be transferred to, and processed in, the United States or other countries outside the European Economic Area (EEA).
- For such transfers, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission.
- We ensure that the data recipient offers an adequate level of protection through the EU-U.S. Data Privacy Framework where applicable.
7. YOUR RIGHTS
Depending on where you live, you have specific rights regarding your personal information:
EU/EEA (GDPR): Right to access, correct, or delete your data; Right to data portability; Right to object to or restrict processing; Right to withdraw consent.
California/USA (CCPA/CPRA): Right to Know what data is collected; Right to Opt-Out of the “sharing” of personal information for targeted ads; Right to Non-Discrimination.
Canada (PIPEDA): Right to access and correct personal information and challenge compliance.
8. RETENTION OF DATA
We retain your personal information for as long as necessary:
- Accounting: Transaction data is kept for 6 years + the current year, as required by Finnish law.
- Marketing: Until you unsubscribe.
- General Orders: For the duration of the warranty period and to handle legal claims.
9. COOKIES
Our website uses cookies. Functional cookies are necessary for the shop to work. Performance and Marketing cookies (Google Analytics, Meta Pixel) are only used if you provide consent via our cookie banner.
10. CHILDREN’S PRIVACY
Our Services are not intended for use by children. We do not knowingly collect Personal Information from children under the age of 16 (EU) or 13 (USA).
11. SECURITY
We use industry-standard security measures, including SSL/TLS encryption for all data transmissions. Access to customer data is strictly limited to authorized personnel only.
12. LODGING A COMPLAINT
If you are unhappy with how we process your data, you have the right to complain to your local data protection authority. In Finland, this is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto).