Privacy Policy – idolly.art
1. Who We Are
This website is operated under the name idolly.art.
Website address: https://www.idolly.art
Contact email: dolly@idolly.art
2. What Data We Collect
We collect and process the following personal data when you use our website:
2.1 Account & Contact Data
- Name and surname
- Email address
- Username and password (encrypted)
- Billing and shipping address (if applicable)
2.2 Order Data (E-shop purchases)
When you place an order, we collect:
- Full name
- Email address
- Billing address
- Shipping address
- Order history and purchased products
- Payment confirmation (via payment provider)
We do not store full credit card details. Payments are processed securely by third-party payment providers.
2.3 Technical Data
- IP address
- Browser type and device information
- Cookies and similar tracking technologies
2.4 Comments (if enabled)
When visitors leave comments, we collect:
- Data shown in the comment form
- IP address
- Browser user agent (for spam detection)
3. How We Use Your Data
We use your data for the following purposes:
- Processing and delivering orders
- Managing user accounts
- Customer support and communication
- Legal and tax obligations (accounting records)
- Website security and fraud prevention
- Spam detection for comments
- Improving website functionality
4. Legal Basis for Processing (GDPR)
We process your data based on:
- Contract performance (order processing and account management)
- Legal obligations (tax, accounting, and record-keeping laws)
- Legitimate interest (fraud prevention, website security, spam protection)
- Consent (cookies and optional marketing, if applicable)
5. Payments
All payments are processed by third-party payment providers (such as Stripe, PayPal, or bank processors depending on availability).
These providers may process your personal data according to their own privacy policies.
We do not store full payment card details on our servers.
6. Cookies
We use cookies to:
- Enable website functionality
- Remember login sessions
- Store user preferences
- Improve user experience
- Analyze website performance (if analytics tools are used)
You can disable cookies in your browser settings at any time.
Cookie retention periods:
- Login cookies: up to 2 weeks (if “Remember Me” is selected)
- Preferences cookies: up to 1 year
- Temporary cookies: deleted when browser is closed
7. Embedded Content
Pages on this website may include embedded content (videos, images, articles, etc.).
Embedded content behaves exactly as if you visited the external website directly. These third-party websites may:
- Collect data about you
- Use cookies
- Track your interaction with their content
8. Data Sharing
We do not sell your personal data.
We may share your data only with:
- Payment processors (for order processing)
- Shipping providers (for delivery purposes, if applicable)
- Hosting and IT service providers
- Spam detection services
- Legal or tax authorities if required by law
If you request a password reset, your IP address may be included in the reset email.
9. Data Retention
We retain your data only as long as necessary:
- Orders and invoices: as required by tax and accounting laws (typically up to 10 years)
- Customer accounts: until deletion request or inactivity
- Comments: retained indefinitely unless requested otherwise
- Technical logs: limited retention for security and diagnostics
10. Your Rights (GDPR)
You have the right to:
- Access your personal data
- Request correction of inaccurate data
- Request deletion of your personal data
- Request export of your data
- Object to data processing in certain cases
- Withdraw consent (where applicable)
You may request account deletion or data removal at any time by contacting:
Please note that we may retain certain data where required by law (e.g., accounting records).
11. Data Security
We apply reasonable technical and organizational measures to protect your personal data against:
- Unauthorized access
- Loss or misuse
- Alteration or disclosure
12. Where Your Data Is Sent
Visitor data may be processed by:
- Spam detection services
- Payment processors
- Hosting providers
Some of these services may be located outside the European Economic Area (EEA). In such cases, appropriate safeguards are applied in accordance with GDPR.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be published on this page with an updated date.