Privacy
Draft for legal review. Last edited 2 September 2026. This is a template written for an EU online pet supplies shop. It has not been reviewed by a lawyer, and the details in [square brackets] still have to be filled in. It must be reviewed by the client’s legal counsel before the shop takes an order.
This notice explains what we do with personal data under the General Data Protection Regulation. It is written in plain language on purpose: a privacy notice nobody can read is not transparency.
Where the shop stands today: there is no customer database yet and no orders have been taken. Nothing described below is happening at the moment beyond the cookies listed on the cookies page. This notice describes the shop as it will operate once ordering opens, so that it exists before the data does rather than after.
Who is responsible
The controller of your personal data is [registered legal name of the trading entity], [registered office address]. For anything in this notice, write to [privacy contact email].
Data protection officer: [DPO name and contact, or a statement that no DPO is required].
What we collect and why
We collect what an order actually needs and not more. Each purpose below names the legal basis we rely on under Article 6 of the GDPR.
Fulfilling your order
Your name, delivery and billing address, email address, telephone number where a carrier needs one, and the contents and value of the order. Legal basis: performance of a contract with you (Article 6(1)(b)). Without it we cannot ship anything, so this is not optional.
Taking payment
Payment is handled by our payment provider, [payment provider name]. We receive confirmation that a payment succeeded, the amount and a reference. We never see or store your full card number. Legal basis: performance of a contract, and legal obligation for the transaction records we must keep.
Invoicing, VAT and accounting
Invoices and the records behind them. Legal basis: legal obligation (Article 6(1)(c)) — tax law requires us to keep them, which is why we cannot delete an invoice on request even if you close your account.
Your account
Your email address, your name, a securely hashed password and any delivery address you choose to save. Legal basis: performance of a contract. You can order without an account.
Customer service
The messages you send us and our replies, tied to your order where relevant. Legal basis: performance of a contract, or our legitimate interest (Article 6(1)(f)) in answering people who write to us when there is no order involved.
Security and fraud prevention
Server logs containing IP address, timestamp, the page requested and browser identification; and the signals used to spot card fraud. Legal basis: legitimate interest in keeping the shop running and not being defrauded. We weighed that against your interests and kept the retention short for exactly that reason.
Email newsletter and analytics
Only if you opt in. Legal basis: consent (Article 6(1)(a)), which you can withdraw at any time — unsubscribe in any email, or change your choices on the cookies page. Withdrawing consent does not affect what we did lawfully before you withdrew it.
How long we keep it
- Order records and invoices
- [statutory retention period, e.g. 7 or 10 years] from the end of the financial year, because tax law requires it.
- Account data
- Until you delete the account, then 30 days in backups before it goes for good.
- Customer service correspondence
- [retention period, e.g. 24 months] after the matter is closed.
- Server and security logs
- [retention period, e.g. 90 days].
- Newsletter subscription
- Until you unsubscribe, plus a record of the unsubscribe so we do not mail you again by mistake.
Who else sees it
Only the companies that make an order happen, each under a written processing agreement and each only with the data they need:
- Payment provider: [name]
- Delivery carriers: [names]
- Hosting and infrastructure: [names]
- Email delivery: [name]
- Accountant and, where we must, tax and customs authorities
We do not sell personal data and we do not share it for anyone else’s marketing.
Data leaving the EEA
We keep processing inside the European Economic Area wherever we can. Where a provider processes data outside it, we rely on an adequacy decision or on the European Commission’s standard contractual clauses together with any extra safeguards the transfer needs. Ask at [privacy contact email] and we will tell you which applies to which provider.
Your rights
You can ask us to:
- Show you the personal data we hold about you, and a copy of it.
- Correct anything wrong or incomplete.
- Delete it, where we have no overriding obligation to keep it — invoices being the usual exception.
- Restrict what we do with it while a dispute is sorted out.
- Send it on — the data you gave us, in a machine-readable file, to you or to another provider.
- Stop processing based on legitimate interests, by objecting; and stop direct marketing, which we act on with no questions asked.
- Withdraw consent you previously gave, at any time.
Write to [privacy contact email]. We answer within one month. If a request is unusually complex we may take two months more, and we will tell you inside the first month if that happens. There is no charge.
If you are not satisfied you can complain to a supervisory authority — in our case [name and website of the lead supervisory authority], or the authority in the EU country where you live.
Automated decisions and profiling
We do not make decisions about you by automated means alone that produce legal or similarly significant effects. Fraud checks may flag an order, but a person looks before anything is refused.
Children
This shop is for adults. We do not knowingly collect data from children under 16. If you believe a child has given us data, tell us and we will delete it.
Changes
When this notice changes materially we will say so on this page and, if the change affects how we use data you already gave us, tell you directly. Last edited 2 September 2026.