Privacy Policy

1. Data We Collect

Personal Information

When Collected Data Type Purpose
Checkout Name, address, phone Order fulfillment
Account Signup Email, password Profile management
Newsletter Email, preferences Marketing
Customer Service Chat transcripts Support history

Automated Collection

  • Cookies: Session tracking (see Cookie Policy)

  • Analytics: Page views, device type (Google Analytics)

  • Payment Security: Tokenized card data (processed by Stripe/PayPal)

2. How We Use Your Data

Core Operations

✓ Process orders & send tracking
✓ Prevent fraud (address verification)
✓ Comply with tax laws (VAT reporting)

With Consent

✓ Send promotions (opt-out anytime)
✓ Show personalized jewellery recommendations

Legal Basis

  • EU GDPR: Contract fulfillment (Article 6(1)(b))

  • Swiss FADP: Legitimate business interest

3. Data Sharing

Third Parties

Recipient Purpose Data Shared
DHL/FedEx Delivery Name, address
Payment Processors Transactions Card last 4 digits
Email Service Newsletters Email only

We never sell your data.

4. International Transfers

  • EU → Switzerland: Protected by adequacy decision

  • Other Countries: Standard Contractual Clauses (SCCs)

5. Your Rights

Under GDPR/FADP

🔹 Access: Request your data copy
🔹 Rectification: Update inaccurate info
🔹 Erasure: “Right to be forgotten”
🔹 Portability: Get your data in CSV

Request via: privacy@karitesbella.com

6. Security Measures Protection Protocols Encryption: TLS 1.3 for all data transfers Payments: PCI-DSS compliant processors Staff Training: Annual GDPR workshops

7. Policy Updates

We’ll notify you of material changes via:

  • Website banner (30 days notice)

  • Email (for account holders)

8. Contact

Data Protection Officer:
[DPO Name]
📧 dpo@karitesbella.com
📍 [Company Address]

EU Representative (if applicable):
[Name], [Address]