Privacy policy
Last updated: 4 September 2026 · CryoTrace Outfit OÜ, Pärnu mnt 141, 11314 Tallinn, Estonia · Reg. 14028871
This policy explains what personal data CryoTrace Outfit OÜ (“we”, “us”) collects when you visit cryotraceroutfit.shop or place an order, why we collect it, how long we keep it, and what rights you have under the EU General Data Protection Regulation (GDPR).
1. Who is responsible for your data
The data controller is CryoTrace Outfit OÜ, Pärnu mnt 141, 11314 Tallinn, Estonia, registry code 14028871. For any privacy question or request you can write to [email protected] or call +372 602 4188 on working days between 09:00 and 18:00 EET.
2. What we collect
- Order data — first and last name, delivery and billing address, e-mail address, telephone number, order contents, order value and order history.
- Payment data — the last four digits of the card and the payment status. Full card numbers never reach our servers; they are handled directly by our payment provider.
- Account data — if you create an account: e-mail, password hash, saved addresses and wish list.
- Communication data — the content of e-mails, chat messages and returns forms you send us, plus our replies.
- Technical data — IP address, browser and device type, referring page, and pages viewed on our site. Analytics data is only collected if you consent to analytics cookies.
- Marketing data — your e-mail address and subscription status if you sign up for the newsletter.
3. Why we use it, and on what legal basis
- To perform the contract (Art. 6(1)(b) GDPR): processing and delivering your order, handling returns, exchanges and warranty claims, and providing customer support.
- To comply with a legal obligation (Art. 6(1)(c)): issuing invoices and retaining accounting records for the period required by Estonian law.
- On the basis of our legitimate interest (Art. 6(1)(f)): preventing payment fraud, securing the website, and improving our products from aggregated, non-identifying usage data.
- With your consent (Art. 6(1)(a)): sending the newsletter, and setting analytics or marketing cookies. You may withdraw consent at any time without affecting processing carried out before withdrawal.
4. Who we share it with
We share the minimum necessary data with processors who act only on our instructions: our payment provider (Stripe Payments Europe Ltd, Ireland), our carriers (DPD Eesti AS and Omniva for EU deliveries), our e-mail and newsletter platform, our accounting provider, and our hosting provider inside the EU. We never sell personal data, and we do not share it with advertising networks for their own purposes.
Where a processor is located outside the European Economic Area, the transfer is covered by the European Commission's Standard Contractual Clauses together with supplementary technical measures.
5. How long we keep it
- Order and invoice data: 7 years from the end of the financial year, as required by the Estonian Accounting Act.
- Account data: until you delete your account, plus 30 days of backup retention.
- Support correspondence: 24 months from the last message.
- Newsletter data: until you unsubscribe, plus a suppression record so we do not contact you again.
- Analytics data: 14 months, in aggregated form.
6. Your rights
Under the GDPR you have the right to request access to your data, to have inaccurate data corrected, to have data erased where we no longer need it, to restrict or object to processing, and to receive your data in a portable, machine-readable format. Write to [email protected] and we will respond within 30 days.
If you believe we have handled your data unlawfully, you may lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, Tatari 39, 10134 Tallinn, www.aki.ee) or with the supervisory authority in your own country of residence.
7. Security
The site is served exclusively over TLS. Passwords are stored as salted hashes, access to production data is limited to named staff with two-factor authentication, and backups are encrypted at rest. We test our checkout for vulnerabilities at least once a year.
8. Children
Our shop is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has provided us with personal data, contact us and we will delete it.
9. Changes to this policy
We may update this policy when our processing changes or the law does. The date at the top always reflects the current version, and material changes are announced on this page for at least 30 days before they take effect.