Privacy Policy
PRIVACY POLICY
TAND Cosmetics – www.tandcosmetics.com
1. Data Controller
The data controller is:
Simon Kralj s.p.
Savska loka 21
4000 Kranj
Slovenia
Company registration number: 6022855000
VAT ID: SI88423042
Contact for privacy matters:
📧 info@tandcosmetics.com
No Data Protection Officer has been appointed.
2. Scope
This Privacy Policy applies to the website:
Sales are limited to the European Union.
Orders are shipped from Slovenia.
We operate B2C and B2B sales.
3. Personal Data We Collect
a) When placing an order or creating an account:
- full name
- delivery address
- postal code and city
- country
- email address
- phone number
- order details
- payment information (processed by payment providers)
b) When subscribing to newsletter:
- name (if provided)
- email address
c) When browsing the website:
- IP address
- device and browser information
- website usage data
- advertising interaction data
4. Legal Bases for Processing
We process personal data based on:
a) Performance of a contract
- order processing
- shipping
- invoicing
- customer accounts
b) Legal obligations
- tax and accounting obligations (10-year retention)
c) Consent
- email marketing
- remarketing and advertising cookies
- abandoned cart emails
Consent can be withdrawn at any time.
d) Legitimate interest
- fraud prevention
- business protection
- basic analytics
5. Payment Providers
Payments are processed via:
- Shopify Payments (Visa / Mastercard)
- PayPal (EU – Luxembourg)
- Cash on delivery
- Bank transfer (proforma invoice)
Payment details are processed directly by the payment provider.
6. Shipping
We use:
- GLS
Only necessary delivery data is shared.
7. Email Marketing & Advertising
We use:
- MailerLite
- Meta Pixel + Conversions API
- Google Analytics 4
- Google Ads remarketing
- TikTok Ads
- Pinterest Ads
Some providers may process data outside the EU (e.g., USA). Transfers are based on Standard Contractual Clauses (SCC) in accordance with GDPR.
8. Cookies
The website uses:
- necessary cookies
- analytics cookies
- advertising cookies
Users manage preferences through the cookie banner.
Details are provided in a separate Cookie Policy.
9. Giveaways
Giveaway participant data is stored for up to 12 months after completion.
10. User Generated Content (UGC)
Customer photos are published only with prior explicit written consent.
11. Age Requirement
Minimum age for using the website is 18 years.
12. Data Retention
- Invoices: 10 years
- Marketing data: until consent withdrawal
- Contact inquiries: 12 months
- Giveaways: 12 months
13. Data Subject Rights
You have the right to:
- access
- rectification
- erasure
- restriction
- data portability
- objection
- withdraw consent
Requests can be sent to:
📧 info@tandcosmetics.com
14. Changes
We reserve the right to update this policy.
The latest version published on the website applies.