Privacy Policy

PRIVACY POLICY

TAND Cosmetics – www.tandcosmetics.com

1. Data Controller

The data controller is:

Simon Kralj s.p.
Savska loka 21
4000 Kranj
Slovenia
Company registration number: 6022855000
VAT ID: SI88423042

Contact for privacy matters:
📧 info@tandcosmetics.com

No Data Protection Officer has been appointed.


2. Scope

This Privacy Policy applies to the website:

www.tandcosmetics.com

Sales are limited to the European Union.
Orders are shipped from Slovenia.
We operate B2C and B2B sales.


3. Personal Data We Collect

a) When placing an order or creating an account:

- full name

- delivery address

- postal code and city

- country

- email address

- phone number

- order details

- payment information (processed by payment providers)

b) When subscribing to newsletter:

- name (if provided)

- email address

c) When browsing the website:

- IP address

- device and browser information

- website usage data

- advertising interaction data


4. Legal Bases for Processing

We process personal data based on:

a) Performance of a contract

- order processing

- shipping

- invoicing

- customer accounts

b) Legal obligations

- tax and accounting obligations (10-year retention)

c) Consent

- email marketing

- remarketing and advertising cookies

- abandoned cart emails

Consent can be withdrawn at any time.

d) Legitimate interest

- fraud prevention

- business protection

- basic analytics


5. Payment Providers

Payments are processed via:

- Shopify Payments (Visa / Mastercard)

- PayPal (EU – Luxembourg)

- Cash on delivery

- Bank transfer (proforma invoice)

Payment details are processed directly by the payment provider.


6. Shipping

We use:

- GLS

Only necessary delivery data is shared.


7. Email Marketing & Advertising

We use:

- MailerLite

- Meta Pixel + Conversions API

- Google Analytics 4

- Google Ads remarketing

- TikTok Ads

- Pinterest Ads

Some providers may process data outside the EU (e.g., USA). Transfers are based on Standard Contractual Clauses (SCC) in accordance with GDPR.


8. Cookies

The website uses:

- necessary cookies

- analytics cookies

- advertising cookies

Users manage preferences through the cookie banner.
Details are provided in a separate Cookie Policy.


9. Giveaways

Giveaway participant data is stored for up to 12 months after completion.


10. User Generated Content (UGC)

Customer photos are published only with prior explicit written consent.


11. Age Requirement

Minimum age for using the website is 18 years.


12. Data Retention

- Invoices: 10 years

- Marketing data: until consent withdrawal

- Contact inquiries: 12 months

- Giveaways: 12 months


13. Data Subject Rights

You have the right to:

- access

- rectification

- erasure

- restriction

- data portability

- objection

- withdraw consent

Requests can be sent to:
📧 info@tandcosmetics.com


14. Changes

We reserve the right to update this policy.
The latest version published on the website applies.