Privacy policy

Privacy Policy - because privacy is safety
Effective date: 1.8.2025

1. General Information

This Privacy Policy explains how Futurelya OÜ ("we", "our", "us") collects, uses, and protects your personal data in accordance with applicable data protection laws, in particular the General Data Protection Regulation (EU 2016/679, "GDPR").

By using our website, online store, services, or contacting us, you consent to the processing of your personal data as described in this policy. If you do not agree, we may not be able to provide you with our services.

We may update this Privacy Policy due to operational or legal changes. The latest version is always available on our website.

2. Data Controller & Contact Details

Data Controller: Futurelya OÜ
Business ID: 12837074 / EE102858558
Address: Tiskrevälja tn 59-12, 13516, Harju maakond, Tallinn, Haabersti linnaosa
Email: essi@futurelya.ee

For privacy matters: essi@futurelya.ee

3. Purpose of Processing

We process your personal data for the following purposes:

  • Contract performance: order processing, shipping, customer service
  • Legal obligations: bookkeeping, tax compliance, regulatory requests
  • Customer communication and support
  • Marketing (with your consent): newsletters, campaigns, targeted advertising
  • Website and service improvement: analytics, UX optimization
  • Fraud prevention and security measures

4. Categories of Personal Data Collected

We collect personal data primarily from you, via orders, account registration, contact forms, or cookies.

This may include:

  • Name, address, email, phone number
  • Order and payment information (via Shopify’s payment partners)
  • Shipping details and tracking information
  • Customer account details (if applicable)
  • Communication history
  • Website usage data (IP address, browser type, device information)
  • Marketing preferences (based on consent)

5. Legal Basis for Processing (GDPR Art. 6 & 9)

We process personal data based on:

  • Contract performance
  • Legal obligations
  • Legitimate interest (customer relationship, direct marketing to existing customers)
  • Consent (email marketing, cookies, targeted advertising)

6. Data Sharing & Recipients

We will not share your data with anyone who is not directly related in providing the service we offer for you. We may share your data with:

  • E-commerce platform & hosting
  • Payment providers 
  • Shipping companies 
  • Marketing & analytics providers 
  • IT service providers
  • Accounting & bookkeeping services
  • Authorities when legally required

All processors are bound by GDPR-compliant contracts.

7. Data Transfers Outside the EU/EEA

Some of our providers (including Shopify) may process data outside the EU/EEA (e.g., Canada, USA). These transfers are safeguarded through:

  • EU Standard Contractual Clauses (SCCs)
  • EU–U.S. Data Privacy Framework participation (if applicable)

8. Data Retention

We store personal data only for as long as necessary:

  • Orders: 6 years (accounting law)
  • Customer service messages: 1–3 years
  • Marketing lists: until you withdraw consent

9. Data Security

We use Shopify’s security standards and industry best practices:

  • Data encryption (SSL/TLS)
  • Access control via user accounts & passwords
  • Physical and digital server protection
  • Regular security updates

10. Cookies & Similar Technologies

We use cookies for website functionality, analytics, and marketing.

Types of cookies:

  • Essential for e-commerce platform
  • Analytics 
  • Marketing 

You can manage cookies via your browser or our site’s cookie banner.

11. Your GDPR Rights

You have the right to:

  • Access your data
  • Correct inaccurate data
  • Request deletion ("right to be forgotten")
  • Restrict processing
  • Object to processing (including direct marketing)
  • Data portability
  • Withdraw consent

To exercise your rights, contact us via email and provide proof of identity.

12. Complaints

If you believe we process your data unlawfully, you may contact your local data protection authority:
Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon)www.aki.ee