No raw card data
Card and payment details are processed securely by Stripe. Venroys does not store full card numbers or CVC codes.
This policy explains in clear language what data Venroys processes, why it is needed, and the choices and rights available to you.
Venroys OÜ is established in Estonia and is subject to the GDPR. Depending on the service, Venroys, an independent seller and a service provider may each have a separate role.
Card and payment details are processed securely by Stripe. Venroys does not store full card numbers or CVC codes.
A seller is responsible for its products, customer service and its own legal obligations. Venroys operates the technical infrastructure.
You can exercise privacy rights, stop marketing and manage non-essential cookies.
Founders: Constantino Aemilius Darshan Changoe and Muhammet Fatih Koçyigit
У залежнасці ад таго, як вы карыстаецеся Venroys (пакупкі, стварэнне ўліковага запісу, сувязь з намі або продаж на платформе), мы можам апрацоўваць наступныя катэгорыі персанальных дадзеных:
| Катэгорыя | Прыклады |
|---|---|
| Ідэнтыфікацыйныя і кантактныя дадзеныя | Імя, адрас для выстаўлення рахункаў/дастаўкі, адрас электроннай пошты, нумар тэлефона, ідэнтыфікатар уліковага запісу |
| Плацежныя і рахункавыя дадзеныя | Токен пастаўшчыка плацяжоў, ідэнтыфікатар транзакцыі, рэквізіты рахунку-фактуры, рэквізіты выплаты (для прадаўцоў) |
| Дадзеныя аб замове і выкананні | Замоўленыя тавары, колькасць, спосаб дастаўкі, статус дастаўкі, інфармацыя пра вяртанне/кампенсацыю грошай |
| Дадзеныя ўліковага запісу і ўваходу | Імя карыстальніка/электронная пошта, хэшаваны пароль, налады ўліковага запісу, меткі часу ўваходу |
| Дадзеныя аб сувязі і згодзе | Паведамленні падтрымкі, статус падпіскі на рассылку, варыянты згоды на выкарыстанне файлаў cookie |
| Тэхнічныя дадзеныя і дадзеныя прылады | IP-адрас, тып браўзера, інфармацыя пра прыладу, журналы сеансаў, падзеі бяспекі |
| Дадзеныя аб выкарыстанні і паводзінах | Прагледжаныя старонкі, пошукавыя запыты, клікі, паводзіны пракруткі, прагледжаныя тавары |
| Seller and verification data | Business details, representatives, date of birth, tax details, verification status and Stripe Connect account references |
| Storefront and content data | Brand name, domain, website content, product media, theme settings and published pages |
| Derived risk and trust signals | Delivery outcomes, refund and chargeback rates, policy status, suspicious activity and marketplace progress |
Мы наўмысна не збіраем спецыяльныя катэгорыі персанальных дадзеных (напрыклад, дадзеныя пра здароўе). Калі ласка, не ўключайце канфідэнцыйную асабістую інфармацыю ў нататкі да замовы, паведамленні падтрымкі або іншыя палі для свабоднага ўводу, калі ў гэтым няма абсалютнай неабходнасці.
| Мэта | Прававая аснова (GDPR) | Падрабязнасці |
|---|---|---|
| Стварэнне ўліковага запісу і аўтэнтыфікацыя | Выкананне дамовы (арт. 6(1)(b)) | Каб стварыць уліковы запіс, дазвольце бяспечна ўвайсці ў сістэму і падтрымлівайце доступ да яго. |
| Апрацоўка замовы, аплата і дастаўка | Выкананне дамовы (арт. 6(1)(b)) | Для апрацоўкі пакупак, пацвярджэння заказаў, арганізацыі дастаўкі і кіравання вяртаннем або кампенсацыяй грошай. |
| Падтрымка кліентаў і камунікацыя па абслугоўванні | Законныя інтарэсы (арт. 6(1)(f)) | Каб адказваць на пытанні, даследаваць праблемы і паляпшаць якасць падтрымкі. |
| Маркетынгавыя камунікацыі і рэкламныя прапановы | Згода (арт. 6(1)(а)) | Толькі там, дзе гэта патрабуецца законам, і пасля вашай згоды. Вы можаце адпісацца або адклікаць згоду ў любы час. |
| Бяспека, прадухіленне махлярства і цэласнасць платформы | Законныя інтарэсы (арт. 6(1)(f)) і юрыдычныя абавязацельствы (арт. 6(1)(c)) | Для выяўлення злоўжыванняў, абароны акаўнтаў, прадухілення махлярства і выканання абавязацельстваў, звязаных з бяспекай. |
| Выкананне юрыдычных, падатковых і бухгалтарскіх патрабаванняў | Юрыдычнае абавязацельства (арт. 6(1)(c)) | Для выканання бухгалтарскіх, падатковых, справаздачных і іншых заканадаўчых патрабаванняў. |
| Seller verification and payouts | Contract, legal obligation and legitimate interests | To onboard sellers, verify identity and business details, enable payouts and limit financial fraud. |
| Marketplace trust and policy administration | Legitimate interests and contract | To monitor seller performance, review marketplace applications and protect customers and the platform. |
| Service | Role and data | More information |
|---|---|---|
| Stripe | Payments, direct charges, seller verification, fraud prevention and payouts. Stripe receives data directly through secure payment and onboarding components. | Stripe Privacy |
| Printful | Optional product, fulfillment, shipping, tracking and return services. Name, address, contact and order data may be shared for fulfillment. | Printful Privacy |
| Hosting and database | Cloud hosting, secure storage, backups, network delivery and operational logging. | Contractually restricted providers |
| Email and communications | Transactional messages, verification, order updates, support and consented marketing. | Necessary contact and message data only |
Specific vendors and subprocessors may change as our infrastructure changes. We assess providers before they process personal data.
Some providers or their subprocessors are located outside the European Economic Area. Where the GDPR requires it, we rely on an adequacy decision, European Commission Standard Contractual Clauses or another valid safeguard. We assess supplementary organizational and technical measures where appropriate.
European Commission Standard Contractual Clauses ↗| Катэгорыя дадзеных | Тэрмін захоўвання |
|---|---|
| Рахункі-фактуры і запісы транзакцый | At least 7 years under applicable Estonian accounting and tax rules, calculated from the legally prescribed starting date |
| Дадзеныя ўліковага запісу кліента | На працягу ўсяго тэрміну дзеяння рахунку і абмежаваны перыяд пасля бяздзейнасці або закрыцця |
| Маркетынгавыя перавагі і запісы згоды | Пакуль згода не будзе адклікана або пакуль яна больш не будзе патрэбна для пацверджання згоды |
| Даныя бяспекі, журналы і аналітыка | На працягу абмежаванага перыяду, адпаведнага мэтам бяспекі і аналітыкі |
| Seller KYC and payout records | While needed for the payment relationship and afterward as required for financial, anti-fraud and legal obligations; Stripe also applies its own retention periods |
| Order and fulfillment records | As needed for delivery, returns, disputes, warranties and applicable accounting and tax periods |
After the applicable period, we delete or anonymize data unless it remains necessary for a legal claim, investigation, dispute or other legal obligation.
Мы ўкараняем адпаведныя тэхнічныя і арганізацыйныя меры для абароны персанальных дадзеных, у тым ліку:
No system is entirely risk-free. Protect your account with a unique password and two-factor authentication where available.
У залежнасці ад вашага месцазнаходжання і дзеючага заканадаўства, вы можаце мець права:
Send requests to info@venroys.com. We may request additional information to verify your identity. We normally respond within one month; the GDPR permits a reasoned extension for complex requests.
Venroys uses security, fraud and performance indicators such as delivery outcomes, refunds, chargebacks, account age, policy incidents and verification status. These signals support risk management and marketplace review. Marketplace access is not automatically guaranteed by a score. Decisions with a material effect may be reviewed by a person, and you may contact us to request an explanation or review.
We investigate suspected personal-data breaches, limit their effects and notify the competent authority and affected people where legally required. Report suspected security issues to info@venroys.com without sending passwords or complete payment details.
Sellers receiving personal data through Venroys must use it lawfully, securely and only for permitted business purposes. They may not use customer data for unsolicited marketing, sell it or disclose it outside necessary order and support processes. Sellers must provide their own privacy information where required and respond to data-subject requests for which they are responsible.
Venroys не прызначаны для дзяцей ва ўзросце, які не дасягнуў узросту, неабходнага дзеючым заканадаўствам для самастойнай згоды на апрацоўку дадзеных (напрыклад, 16 гадоў у некаторых юрысдыкцыях). Мы свядома не збіраем персанальныя дадзеныя дзяцей без неабходнай згоды.
Мы можам перыядычна абнаўляць гэтую Палітыку прыватнасці. Дата «Апошняе абнаўленне» ўверсе паказвае, калі гэтая старонка апошні раз змянялася. Калі мы ўнясем істотныя змены, мы можам паведаміць вам пра гэта праз вэб-сайт, электронную пошту або апавяшчэнні ўліковага запісу, калі гэта неабходна.
Founders: Constantino Aemilius Darshan Changoe and Muhammet Fatih Koçyigit
info@venroys.com