Legal
Privacy Policy
1. Scope
This Privacy Policy explains how SideCarve collects, uses, stores, and shares personal data when you use our website, place an order, or contact us.
2. Data Controller
For GDPR purposes, SideCarve is the data controller of personal data processed through this website. For privacy requests, contact us at business@sidecarve.com.
3. Data We Collect
We may process identity and contact data (name, email, shipping address), transaction data (order details, payment status), customization data (text and design preferences), and technical data (IP address, browser type, and usage logs).
4. Lawful Bases (GDPR Art. 6)
We process personal data based on contract performance (order fulfillment), legal obligations (tax and accounting), legitimate interests (service improvement and fraud prevention), and consent where required (marketing cookies or newsletter).
5. How We Use Data
We use data to process orders, provide customer support, generate product previews, improve website performance, prevent abuse, and comply with legal obligations.
6. Sharing and Processors
We share data only with trusted service providers that support payment processing, hosting, analytics, and logistics. These providers process data under contractual safeguards and only for instructed purposes.
7. International Transfers
If personal data is transferred outside the EEA/UK, we use lawful transfer mechanisms such as adequacy decisions or standard contractual clauses.
8. Data Retention
We keep personal data only as long as necessary for the original purpose, legal compliance, or dispute resolution. Retention periods are reviewed regularly.
9. Your Rights
Under GDPR, you may request access, rectification, erasure, restriction, portability, or objection to processing. You may also withdraw consent at any time where processing is consent-based.
10. Cookies and Tracking
We use essential cookies for website operation and may use optional analytics cookies where allowed. You can control cookie preferences through browser settings.
11. Security
We implement technical and organizational safeguards to protect personal data against unauthorized access, alteration, disclosure, or loss.
12. Complaints
If you believe your data rights were violated, please contact us first. You also have the right to lodge a complaint with your local data protection authority.
13. Policy Updates
We may update this policy from time to time. Material changes will be published on this page with a revised effective date.