Privacy

[NEEDS REAL CONTENT — LEGAL REVIEW REQUIRED] — This is a working draft, not legal advice and not a finished privacy notice. You are established in Sweden and selling to EU consumers, so GDPR applies in full. Have this reviewed by someone qualified, and fill in the bracketed identifiers, before you publish.

Who we are

Imaeris, [LEGAL COMPANY NAME], [REGISTERED ADDRESS], [ORGANISATION NUMBER]. For anything about your data, contact [PRIVACY EMAIL].

What we collect

When you order: your name, email, delivery and billing address, phone number if you give it, and what you bought. We do not see or store your full card details — your payment is handled by our payment provider.

When you browse: cookies and similar technologies that keep your cart working and help us understand how the site is used. You can control non-essential cookies through the banner.

Why we use it

To take payment, deliver your order, handle returns and answer your questions — that is performance of our contract with you. To meet accounting and tax obligations — that is a legal duty. To send marketing email — only if you asked us to, and you can stop at any time.

Who we share it with

Shopify, which runs this store. Our payment provider. Our shipping carriers. [LIST ANY EMAIL OR ANALYTICS TOOLS]. Each of them only gets what they need to do their job.

Where your data goes

Some of these providers operate outside the EU. Where that happens we rely on the safeguards in Chapter V of the GDPR. [CONFIRM THE SPECIFIC MECHANISM WITH YOUR ADVISER.]

How long we keep it

Order records for [X] years to satisfy Swedish accounting law. Marketing consent until you withdraw it.

Your rights

You can ask for a copy of your data, ask us to correct or delete it, object to how we use it, or ask us to move it elsewhere. Email [PRIVACY EMAIL]. If you are not happy with our answer you can complain to Integritetsskyddsmyndigheten (IMY), the Swedish data protection authority.