Privacy Policy

Privacy Policy

1. CONTROLLER INFORMATION AND DATA COLLECTION

1.1 Controller Information

We are glad you are visiting our website and thank you for your interest in our products.

This Privacy Policy explains how we collect, use, and protect your personal data when you use our website or purchase our products.

Data Controller:

Store name: UpGoods Company name: UpGoods Email address: info@up-goods.shop

The data controller is responsible for determining the purposes and means of processing personal data in accordance with applicable data protection laws, including but not limited to:

the GDPR — where applicable, the UK GDPR — where applicable, the Privacy Act 1988 (Australia), PIPEDA (Canada), and other applicable data protection laws.

1.2 Secure Data Transmission

For security reasons and to protect the transmission of personal data and other confidential content (such as orders or inquiries), this website uses SSL/TLS encryption.

An encrypted connection can be recognized by:

the "https://" prefix, the padlock symbol in your browser's address bar.

2. DATA COLLECTED WHEN VISITING OUR WEBSITE

2.1 Server Log Files

When you visit our website purely for informational purposes, without registering an account or providing any other information, we automatically collect the data your browser transmits to our server ("server log files").

This technical data is necessary for the correct display of the website and includes:

the website visited, the date and time of access, the amount of data transferred (in bytes), the referring URL (the source from which you accessed the site), the browser type and version, the operating system used, the IP address (anonymized where possible).

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in improving the stability and functionality of the website).

This data is not shared with third parties or used for any other purpose.

We reserve the right to review server log files if there are specific indications of unlawful use of the website.

3. COOKIES AND TRACKING TECHNOLOGIES

3.1 What Are Cookies?

Cookies are small text files stored on your device when you visit our website.

They help us provide a more functional and user-friendly website.

3.2 Types of Cookies Used

Necessary cookies

Required for the basic functioning of the website, e.g.:

shopping cart functionality, core store features.

Functional cookies

Allow us to remember your preferences and settings.

Performance cookies

Help us analyze how the website is used, e.g.:

Google Analytics.

Marketing cookies

Track how the website is used in order to display more relevant advertisements, e.g.:

Facebook Pixel, Google Ads.

3.3 Cookie Retention Period

Session cookies

Deleted when you close your browser.

Persistent cookies

Remain stored on your device for a set period (depending on the specific cookie).

Legal basis:

Necessary cookies: Art. 6(1)(b) GDPR (performance of a contract).

Other cookies: Art. 6(1)(a) GDPR (consent) or Art. 6(1)(f) GDPR (legitimate interest).

3.4 Managing Cookies

You can configure your browser to:

notify you when cookies are set, accept or reject cookies individually, block all cookies.

Please note that disabling cookies may limit the functionality of the website.

You can also withdraw your cookie consent at any time via:

our cookie banner, your browser settings.

4. PERSONAL DATA WE COLLECT

4.1 Information You Provide to Us

When creating an account, placing an order, or contacting us, we may collect:

Account and order data: full name, email address, billing address, delivery address, phone number (optional), payment information (processed by payment providers), order history, product preferences.

Contact details: full name, email address, phone number (if provided), message content.

4.2 Information Collected Automatically

We may automatically collect:

IP address, browser type and version, device type and operating system, pages visited and time spent on the site, referral source, click patterns and user interactions.

5. HOW WE USE YOUR DATA

We collect and process your personal data for the following purposes:

5.1 Order Fulfilment

Legal basis: Art. 6(1)(b) GDPR — performance of a contract

We use your data to:

process and fulfil orders, manage payments and billing, arrange shipping and delivery, send order confirmations and shipping notifications, handle returns and refunds, provide customer support.

5.2 Account Management

Legal basis: Art. 6(1)(b) GDPR

We use your data to:

create and maintain your customer account, remember your preferences, provide a personalized shopping experience.

5.3 Communication

Legal basis: Art. 6(1)(b) or (f) GDPR

We use your data to:

respond to inquiries and support requests, send messages related to order fulfilment (e.g. order updates, shipping information), handle complaints and disputes.

5.4 Marketing

Legal basis: Art. 6(1)(a) GDPR — consent

We may use your data to:

send newsletters and promotional messages (only with your consent), display personalized advertisements, send review reminders, inform you about new products and special offers.

You can withdraw your marketing consent at any time by:

clicking the "unsubscribe" link in our emails, contacting us at:

info@up-goods.shop

5.5 Legal Obligations

Legal basis: Art. 6(1)(c) GDPR

We use data to:

comply with tax and accounting requirements, respond to legal requests, prevent fraud and abuse, enforce our Terms and Conditions.

5.6 Website Improvement

Legal basis: Art. 6(1)(f) GDPR — legitimate interest

We use data to:

analyze website usage and performance, improve the user experience, test and develop new features, conduct research and analysis.

6. WHO WE SHARE YOUR DATA WITH

We only share your personal data with trusted third parties that are necessary for running our business.

6.1 Service Providers

Shopify Inc. (e-commerce platform)

We use Shopify for:

hosting and managing the website, processing orders, integrating payment systems.

Location: Canada (Adequate level of protection under the GDPR)

Privacy policy: https://www.shopify.com/legal/privacy

Payment Processors

We may use the following payment providers:

PayPal (Europe) S.à r.l. et Cie, S.C.A.

Luxembourg

Stripe, Inc.

USA — using Standard Contractual Clauses

Payment Card Processors

(e.g. processing in compliance with the PCI DSS standard)

Purpose: Secure payment processing.

Shipping Companies

We use international courier services such as:

FedEx, UPS, DHL, local postal services.

Purpose: Delivering products to the specified address.

Data shared:

full name, address, phone number, shipment tracking information.

Email Service Providers

Purpose:

sending order-related messages, sending marketing communications.

Data shared:

email address, full name, order information.

6.2 Marketing and Analytics

Google LLC (USA)

We may use:

Google Analytics (website traffic analysis), Google Ads (online advertising).

Legal basis: Consent — Art. 6(1)(a) GDPR.

Privacy policy: https://policies.google.com/privacy

Meta Platforms (Facebook/Instagram)

We may use:

Facebook Pixel (conversion tracking), Instagram integration.

Legal basis: Consent — Art. 6(1)(a) GDPR.

Privacy policy: https://www.facebook.com/privacy/policy

6.3 Legal Requirements

We may disclose your data to:

law enforcement authorities, where required by law, courts and regulatory authorities, legal and accounting advisors, fraud prevention services.

6.4 Business Transfers

In the event of a:

merger, acquisition, sale of part or all of our assets,

your data may be transferred to the new owner.

You will be notified of any such change.

7. INTERNATIONAL DATA TRANSFERS

Because we operate internationally and use service providers located in various countries, your data may be transferred outside the European Economic Area (EEA).

7.1 Safeguards Ensuring an Adequate Level of Protection

We apply appropriate safeguards, including:

Standard Contractual Clauses (SCCs)

Used when transferring data to countries without an adequacy decision.

Adequacy Decisions

This applies, among others, to:

Canada (PIPEDA), Switzerland, New Zealand,

as recognized by the European Union.

Data Privacy Framework and Other Transfer Mechanisms

Used for service providers based in the USA, where applicable.

7.2 Your Rights

You can request a copy of the safeguards used for international data transfers by contacting us at:

info@up-goods.shop

8. DATA RETENTION PERIOD

We only retain your personal data for as long as necessary for the purposes described in this policy or as required by law.

8.1 Retention Periods

Order data:

7 years

(tax and accounting requirements)

Account data:

Until account deletion + 30 days

Marketing data:

Until consent is withdrawn + 30 days

Contact inquiries:

3 years after the matter is resolved

Website analytics data:

14–26 months (depending on Google Analytics settings)

Cookie data:

In accordance with cookie settings (period depends on the type of cookie)

8.2 Data Deletion

After the retention periods have expired, your data is securely deleted or anonymized, unless:

you have consented to further use, we are legally required to retain it, the data is needed to establish or defend legal claims.

9. YOUR RIGHTS UNDER DATA PROTECTION LAW

Your rights may vary depending on where you live.

The rights applicable in various jurisdictions are set out below.

9.1 Customers in the EU/EEA (Rights under the GDPR)

You have the right to:

Right of access (Art. 15 GDPR)

Request a copy of your personal data.

Right to rectification (Art. 16 GDPR)

Correct inaccurate data.

Right to erasure (Art. 17 GDPR)

Request deletion of your data ("right to be forgotten").

Right to restriction of processing (Art. 18 GDPR)

Restrict how your data is used.

Right to data portability (Art. 20 GDPR)

Receive your data in a structured format.

Right to object (Art. 21 GDPR)

Object to processing based on legitimate interest.

Right to withdraw consent (Art. 7(3) GDPR)

Withdraw consent at any time.

Right to lodge a complaint (Art. 77 GDPR)

File a complaint with the competent supervisory authority.

9.2 Customers in the United Kingdom (UK GDPR and Data Protection Act 2018)

Customers in the United Kingdom have the same rights as customers in the European Union, under the UK GDPR.

These rights are enforced by:

Information Commissioner's Office (ICO)

Website: https://ico.org.uk

9.3 Customers in Canada (PIPEDA)

Customers in Canada have the right to:

access their personal data, correct inaccurate information, withdraw consent to data processing, file a complaint with the Privacy Commissioner of Canada.

Website: https://www.priv.gc.ca

9.4 Customers in Australia (Privacy Act 1988)

Customers in Australia have the right to:

access their personal data (Australian Privacy Principle 12), correct inaccurate data (APP 13), file a complaint with the Office of the Australian Information Commissioner (OAIC).

Website: https://www.oaic.gov.au

9.5 Customers in New Zealand (Privacy Act 2020)

Customers in New Zealand have the right to:

access their personal data (Principle 6), correct inaccurate information (Principle 7), file a complaint with the Privacy Commissioner.

Website: https://www.privacy.org.nz

9.6 Customers in the United States (state-dependent rights)

California (CCPA/CPRA)

California residents have the right to:

know what personal data is collected, request deletion of personal data, opt out of the sale of personal data (we do not sell personal data), equal treatment and non-discrimination.

Other U.S. States

Similar rights may apply under local state laws, including in:

Virginia, Colorado, Connecticut, and other states.

10. DIRECT MARKETING

10.1 Email Newsletter

If you sign up for our newsletter, we will send you regular updates about:

products, offers, promotions.

Sign-up process: Double opt-in

You must confirm your subscription via email.

Legal basis:

Art. 6(1)(a) GDPR (user consent)

Data collected: email address, first name (optional), sign-up date, IP address.

Unsubscribing:

You can unsubscribe from the newsletter by:

clicking the unsubscribe link included in every email, contacting us by email:

info@up-goods.shop

10.2 Marketing to Existing Customers

If you have made a purchase in our store, we may send you marketing messages about similar products based on:

Art. 6(1)(f) GDPR (legitimate interest).

You can opt out of such messages at any time.

11. SOCIAL MEDIA PLUGINS AND INTEGRATIONS

11.1 Facebook

We use Facebook plugins with privacy-enhancing solutions.

Data is only transmitted when a user actively clicks on or interacts with the plugin.

Facebook privacy policy:

https://www.facebook.com/privacy/policy

11.2 Instagram

Instagram plugins are integrated using privacy-enhancing methods.

Data is only transmitted after user interaction.

Instagram privacy policy:

https://help.instagram.com/155833707900388

12. WEB ANALYTICS

12.1 Google Analytics

We use Google Analytics to:

analyze website traffic, study user behaviour, improve the performance of our website.

Your IP address is anonymized.

Legal basis:

Art. 6(1)(f) GDPR (legitimate interest)

or

Art. 6(1)(a) GDPR (user consent).

Opting out:

You can opt out of Google Analytics using the browser add-on:

https://tools.google.com/dlpage/gaoptout

13. ONLINE ADVERTISING

13.1 Google Ads and DoubleClick

We use Google Ads to display advertisements tailored to your interests.

Legal basis:

Art. 6(1)(a) GDPR (consent given via the cookie banner).

Opting out:

You can change your Google Ads settings here:

https://adssettings.google.com

13.2 Facebook Pixel

We use Facebook Pixel to:

track conversions, optimize advertising campaigns, analyze ad performance.

Legal basis:

Art. 6(1)(a) GDPR (user consent).

Opting out:

You can change your Facebook ad settings here:

https://www.facebook.com/ads/preferences

14. SECURITY MEASURES

We apply industry-standard security measures to protect your data, including:

SSL/TLS encryption during data transmission, secure, firewall-protected servers, payment processing compliant with the PCI DSS standard, access controls limiting employee access to data, regular security audits and vulnerability assessments, backup systems to prevent data loss.

15. DATA BREACH NOTIFICATION

In the event of a data breach that may pose a risk to your rights and freedoms, we are committed to:

notifying affected individuals within 72 hours (GDPR requirement), notifying the relevant supervisory authorities in accordance with applicable law, providing information about the breach and the remedial measures taken.

16. CHILDREN'S PRIVACY

Our website and services are not intended for individuals under the age of 18.

We do not knowingly collect personal data from children.

If you believe we have collected data from a minor, please contact us immediately:

info@up-goods.shop

17. CHANGES TO THIS PRIVACY POLICY

We may periodically update this Privacy Policy to reflect:

changes in our practices, legal changes, new regulatory requirements.

Updates will be posted on this page along with a revised "Last updated" date.

Your continued use of our website after changes have been made constitutes acceptance of the updated Privacy Policy.

18. CONTACT AND EXERCISING YOUR RIGHTS

To exercise your rights, or if you have questions about this Privacy Policy, please contact us:

Email: info@up-goods.shop

Business hours: Monday – Saturday 09:00 – 17:00 CET

We will respond to your request within:

30 days — GDPR / UK GDPR, 30 days — PIPEDA Canada, 30 days — Australian Privacy Act, 20 business days — New Zealand Privacy Act, 45 days — CCPA California.

19. SUPERVISORY AUTHORITIES

You have the right to lodge a complaint with the competent data protection authority in your jurisdiction:

European Union / EEA

The relevant local data protection authority.

United Kingdom

Information Commissioner's Office (ICO)

https://ico.org.uk

Canada

Privacy Commissioner of Canada

https://www.priv.gc.ca

Australia

Office of the Australian Information Commissioner (OAIC)

https://www.oaic.gov.au

New Zealand

Privacy Commissioner

https://www.privacy.org.nz

United States — California

California Attorney General

https://oag.ca.gov

Last updated: 8 July 2026