Privacy Policy

Last updated: 13 February 2023

Spice Stash ("we," "us," "our") is committed to protecting your privacy and complying with the European Union's General Data Protection Regulation (GDPR). This privacy policy explains how we collect, use, and protect your personal data when you visit our website or use our services.

Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access the site.

We reserve the right to make changes to this Privacy Policy at any time and for any reason. We will alert you about any changes by updating the “Last Updated” date of this Privacy Policy. Any changes or modifications will be effective immediately upon posting the updated Privacy Policy on the Site, and you waive the right to receive specific notice of each such change or modification.

You are encouraged to periodically review this Privacy Policy to stay informed of updates. You will be deemed to have been made aware of, will be subject to, and will be deemed to have accepted the changes in any revised Privacy Policy by your continued use of the Site after the date such revised Privacy Policy is posted.

Personal Data Collection and Use

We collect personal data from you when you place an order, sign up for our newsletter, or contact us through our website. The personal data we collect may include your name, address, email address, phone number, and payment information. We use this personal data to process your orders, communicate with you, and improve our services.

We may also use your personal data to send you marketing communications about our products or services, but only if you have given us your consent. You may withdraw your consent at any time by contacting us through our website or by following the instructions in our marketing communications.

We will keep your personal data confidential and secure and will not share it with third parties unless required by law or necessary to provide our services to you. We may share your personal data with our service providers, such as payment processors, shipping companies, or marketing agencies, who process your data on our behalf. These service providers are required to maintain the confidentiality and security of your personal data and are not authorized to use your personal data for any other purpose.

Legal Basis for Processing Personal Data

Under the GDPR, we are required to have a lawful basis for processing your personal data. We rely on the following legal bases for processing your personal data:

  • Performance of a contract: We need to process your personal data to fulfill our contractual obligations to you, such as processing your orders and delivering your products.

  • Legitimate interests: We may process your personal data to pursue our legitimate interests, such as improving our services, communicating with you, and marketing our products, as long as those interests do not override your fundamental rights and freedoms.

  • Consent: We will obtain your consent before processing your personal data for marketing purposes or other activities that require your consent.

Cookies

We use cookies and similar technologies to enhance your user experience and to analyze our website traffic. Cookies are small text files that are stored on your device when you visit our website. We use cookies to remember your preferences, provide personalized content, and analyze how users interact with our website.

We use both session cookies, which expire when you close your browser, and persistent cookies, which remain on your device until they expire or you delete them. You can choose to accept or reject cookies through your browser settings, but please note that rejecting cookies may affect your ability to use our website.

Third-party Websites

Our website may contain links to third-party websites, which have their own privacy policies. We are not responsible for the privacy practices or content of these websites and encourage you to review their privacy policies.

Your Rights

You have the right to access, correct, or delete your personal data that we hold. You also have the right to object to the processing of your personal data or to request the restriction of its processing. In certain circumstances, you have the right to data portability or to lodge a complaint with a supervisory authority.

To exercise your rights or for any questions regarding our privacy policy, please contact us using the contact information provided on our website. We will respond to your request within the timeframes required by law and will take reasonable steps to verify your identity before granting your request.

Security

We take appropriate technical and organizational measures to protect your personal data from unauthorized access, use, or disclosure. We use secure servers, firewalls, and encryption to protect your personal data from unauthorized access or use. We also train our employees to handle personal data securely and conduct regular security audits to identify and address security risks.

Updates to our Privacy Policy

We may update our privacy policy from time to time to reflect changes in our services or legal requirements. We encourage you to review our privacy policy regularly to stay informed about how we collect, use, and protect your personal data. We will notify you of any material changes to our privacy policy by email or through a notice on our website.

Contact Us

If you have any questions or concerns about our privacy policy or our handling of your personal data, please contact us through our website or at the following address:

Company Name: Spice Stash OÜ
Address: Sakala tn 7-2, 10141 Tallinn, Estonia
Email: gdpr@thespicestash.com