Privacy policy

  1. Data Controller The controller responsible for processing your personal data is: Valentyna Leonenko

    Bergstrasse 93

    8706 Meilen

    Switzerland

    Email: Valentyna12art@gmail.com For the purposes of the Swiss Federal Act on Data Protection (revFADP) and the EU General Data Protection Regulation (GDPR), Valentyna Leonenko is the data controller.

  2. Personal Data We Collect We process personal data that you provide to us or that arises when you use our online shop and services, including: • Identification and contact details: name, address, email address, phone number. • Order and contract data: items purchased, order details, commissions, delivery address, billing address, communication related to your order or commission. • Payment data: payment method, transaction details (actual payment data is processed by our payment service provider, not stored in full by us). • Technical and usage data: IP address, device information, browser type, pages visited, interactions with our website, cookie and tracking data (including data from pixels and tags of Google, Meta/Facebook, TikTok and similar tools, if you consent). • Marketing and communication preferences: your choices regarding newsletters, promotions, and cookies. We do not intentionally collect special categories of personal data (such as health information, religious or political opinions).

  3. Purposes and Legal Bases of Processing We process your personal data for the following purposes and on the following legal bases:

To perform and fulfill contracts: • Processing and delivering your orders and commissions, handling payments, customer service. • Legal basis: performance of a contract or steps taken at your request prior to entering into a contract.

To comply with legal obligations: • Accounting, taxation, retention obligations, and other mandatory legal requirements. • Legal basis: compliance with legal obligations under Swiss and, where applicable, EU law.

To pursue legitimate interests: • Operating and improving our website and services, IT security, fraud prevention, internal administration, and statistics (in a privacy‑friendly way). • Legal basis: our legitimate interests, provided your interests and fundamental rights do not override them.

With your consent: • Sending newsletters or promotional emails. • Using non‑essential cookies and similar technologies for analytics and marketing. • Using advertising cookies and pixels from Google Ads, Meta/Facebook, Instagram, and TikTok to measure and optimise campaigns, create audiences, and display personalised advertising, where supported by your consent. • Legal basis: your consent, which you may withdraw at any time for the future.

If we ask for your consent, we will clearly explain the purpose and give you the option to refuse.

  1. Cookies and Tracking Technologies Our website uses cookies and similar technologies (e.g. pixels, tags, SDKs) to operate the shop, analyse usage, and show relevant advertising. We use the following categories:

Essential cookies: required for basic website functions (e.g. shopping cart, checkout, security, language settings).

Analytics/performance cookies: help us understand how visitors use the site so we can improve functionality and usability.

Marketing cookies and pixels: used to display personalised or interest‑based advertising and measure campaigns, for example via: • Google Ads and related Google tags (including Google Consent Mode where implemented) • Meta/Facebook and Instagram pixels • TikTok pixel and TikTok Ads tools.

Visitors from the EU, EEA, UK and Switzerland are shown a cookie banner/consent tool that allows them to: • Accept or reject non‑essential cookies (analytics and marketing). • Change their preferences at any time. • Receive information about the third‑party providers involved.

Non‑essential cookies and marketing pixels (including Google, Meta, TikTok) are only loaded after you have given your explicit consent where required by law. A consent management platform or specialised cookie app may be used to block these scripts until consent is given and to pass your consent choices to Google, Meta and TikTok in a compliant way. You can also disable or delete cookies at any time in your browser settings, although this may affect website functionality.

  1. Data Storage, Locations, and Retention • Our online shop is hosted and operated using Shopify, which stores data on secure servers in various locations (including the EU/EEA or other countries, depending on their infrastructure and sub‑processors). • For order production and fulfillment, we work with a print‑on‑demand provider based in Germany and with shipping partners that process delivery data. If personal data is transferred to countries outside Switzerland or the EU/EEA, we ensure an adequate level of data protection through appropriate safeguards (for example adequacy decisions, standard contractual clauses, or comparable mechanisms). We retain personal data only for as long as necessary: • Order and contract data: for the duration of the contractual relationship and for the statutory retention period (typically up to 10 years under commercial and tax regulations). • Marketing data (including custom audiences used for Google, Meta or TikTok ads where applicable): until you withdraw your consent or object, or after a reasonable period without interaction, in line with our retention practices and legal requirements. • Technical and usage data: for a limited period necessary for security, analysis, and troubleshooting, unless a longer period is required for evidence in legal disputes.
  2. Data Sharing and Processors We do not sell your personal data. We only share it with trusted third parties to the extent necessary for the purposes described above, including:

Print‑on‑demand and production partners (e.g. in Germany) to manufacture and fulfill your orders.

Payment service providers (e.g. Shopify Payments, PayPal or other providers) to process payments securely.

Shipping and logistics partners for delivery of your orders.

IT and hosting providers, email service providers, analytics and marketing partners such as: • Google (e.g. Google Ads, related tags and measurement tools) • Meta Platforms (e.g. Facebook and Instagram marketing and analytics tools) • TikTok (e.g. TikTok Ads, TikTok pixel and related measurement tools)

in each case only where you have consented to the corresponding tracking/marketing cookies or where permitted by law.

These service providers generally act as processors and are contractually bound to process personal data only on our instructions, to use appropriate technical and organisational security measures, and to comply with applicable data protection laws (Art. 28 GDPR or equivalent). Where required, we may also disclose data to authorities, legal advisers, or other third parties if this is necessary to comply with legal obligations or to assert, exercise, or defend legal claims.

  1. Your Rights (unchanged text from previous version still applies; it already fits your tools) You keep: access, rectification, deletion, restriction, portability, objection, withdrawal of consent, and complaint rights as already written.
  2. Marketing Communications and Newsletters (unchanged in substance) If you subscribe to our newsletter, we will use your email address to inform you about new artworks, products, offers, and events. You can unsubscribe at any time via the “unsubscribe” link or by contacting us.
  3. Online Advertising and Personalised Ads We use online advertising tools to show you relevant ads and to measure the success of our campaigns, including: • Google Ads and related Google advertising services • Meta/Facebook and Instagram Ads • TikTok Ads and TikTok business tools. These services may use cookies, pixels, SDKs and similar technologies to: • Measure conversions and campaign performance. • Build target groups and custom audiences. • Display personalised or interest‑based ads across websites, apps and platforms. For visitors from the EU/EEA, UK and Switzerland, we only use cookies or identifiers for personalised advertising where you have given valid consent via our cookie banner or consent management platform. Without consent, we either do not use these tools or use them in a restricted/limited mode where possible (for example, limited data modes or non‑personalised signals). You can change your preferences at any time through the cookie banner or your browser settings. You can also manage preferences directly with advertising providers (for example, via Google’s ad settings, Facebook’s ad preferences, or TikTok settings) and use industry opt‑out pages where available. If we create custom audiences (for example by uploading hashed contact data to Google, Meta or TikTok), we will only do so where we have a suitable legal basis (typically your consent for marketing), and we respect applicable audience, suppression and retention rules.
  4. Security Measures (unchanged; still accurate for Shopify and your stack)

11–13. Third‑Party Websites, Contact, Changes These sections remain as in the previous version and do not need changes for Meta/Google/TikTok.