PRIVACY & DATA PROTECTION

Venroysプライバシーポリシー

This policy explains in clear language what data Venroys processes, why it is needed, and the choices and rights available to you.

Last updated: August 10, 2026Effective August 10, 2026Venroys OÜ · 17427636 · EE102991020
In short

Venroys OÜ is established in Estonia and is subject to the GDPR. Depending on the service, Venroys, an independent seller and a service provider may each have a separate role.

No raw card data

Card and payment details are processed securely by Stripe. Venroys does not store full card numbers or CVC codes.

Seller storefronts

A seller is responsible for its products, customer service and its own legal obligations. Venroys operates the technical infrastructure.

Choice and control

You can exercise privacy rights, stop marketing and manage non-essential cookies.

01

1. 処理の責任者は誰ですか?

Venroys OÜ(エストニアの有限会社)
登録日: 2026年2月2日 (エストニア)
登録コード: 17427636
住所: Tornimäe tn 5、10145 タリン、エストニア
ウェブサイト: venroys.com
経営委員会:コンスタンチノ・アエミリウス・ダルシャン・チャンゴエ
主な活動(EMTAK):47711 - 専門店における衣料品の小売
メールアドレス: info@venroys.com
プライバシーに関するご質問、ご要望、苦情につきましては、上記のメールアドレスまでご連絡ください。必要に応じてデータ保護責任者(DPO)を任命する場合、その連絡先をここに掲載いたします。

Founders: Constantino Aemilius Darshan Changoe and Muhammet Fatih Koçyigit

02

2. 当社が処理する個人データ

Venroys の使用方法(ショッピング、アカウントの作成、当社への連絡、またはプラットフォームでの販売)に応じて、当社は以下のカテゴリーの個人データを処理する場合があります。

カテゴリ
識別情報と連絡先データ氏名、請求先/配送先住所、メールアドレス、電話番号、アカウントID
支払いおよび請求データ決済プロバイダートークン、取引ID、請求書の詳細、支払いの詳細(販売者向け)
注文と履行データ注文商品、数量、配送方法、配送状況、返品・返金情報
アカウントとログインデータユーザー名/メールアドレス、ハッシュ化されたパスワード、アカウント設定、ログインタイムスタンプ
コミュニケーションと同意データサポートメッセージ、ニュースレターのオプトインステータス、Cookieの同意の選択
技術データとデバイスデータIPアドレス、ブラウザの種類、デバイス情報、セッションログ、セキュリティイベント
使用状況と行動データ閲覧したページ、検索クエリ、クリック数、スクロール行動、閲覧した商品
Seller and verification dataBusiness details, representatives, date of birth, tax details, verification status and Stripe Connect account references
Storefront and content dataBrand name, domain, website content, product media, theme settings and published pages
Derived risk and trust signalsDelivery outcomes, refund and chargeback rates, policy status, suspicious activity and marketplace progress

当社は、特別なカテゴリーの個人データ(例えば、健康データ)を意図的に収集することはありません。注文メモ、サポートメッセージ、その他の自由記述欄には、必要不可欠な場合を除き、機密性の高い個人情報を入力しないでください。

03

3. 目的と法的根拠

目的法的根拠(GDPR)詳細
アカウントの作成と認証契約の履行(第6条(1)(b))アカウントを作成し、安全にログインできるようにし、アカウントを利用できるようにしておきます。
注文処理、支払い、配送契約の履行(第6条(1)(b))購入の処理、注文の確認、発送の手配、返品または返金の管理を行います。
顧客サポートとサービスコミュニケーション正当な利益(第6条(1)(f))質問に答え、問題を調査し、サポート品質を向上させるため。
マーケティングコミュニケーションとプロモーションオファー同意(第6条(1)(a))法律で義務付けられている場合、およびお客様が同意した後のみ。いつでも登録を解除したり、同意を取り消したりできます。
セキュリティ、不正防止、プラットフォームの整合性正当な利益(第6条(1)(f))と法的義務(第6条(1)(c))不正使用を検出し、アカウントを保護し、詐欺を防止し、セキュリティ関連の義務を遵守するため。
法務、税務、会計コンプライアンス法的義務(第6条(1)(c))簿記、税金、報告、およびその他の法定要件を満たすため。
Seller verification and payoutsContract, legal obligation and legitimate interestsTo onboard sellers, verify identity and business details, enable payouts and limit financial fraud.
Marketplace trust and policy administrationLegitimate interests and contractTo monitor seller performance, review marketplace applications and protect customers and the platform.
04

4. Platform, seller and storefront roles

  • Venroys is a controller for Venroys accounts, platform security, marketplace administration, platform fees, tax records and operation of our services.
  • For an independent seller storefront, the seller may be a separate controller for customer relationships, product information, fulfillment, returns and support. The seller's identity should be available in the relevant storefront or order information.
  • Where Venroys handles data only on a seller's instructions, we act as a processor under the applicable agreement. For certain services, including payments and legally required identity checks, Stripe may act as an independent controller.
05

5. Sources of personal data

  • Directly from you through registration, checkout, support, uploads or settings.
  • From sellers when they manage an order, return or customer request.
  • From payment, fulfillment, shipping, verification and fraud-prevention providers.
  • Automatically from devices, logs, cookies and security signals, depending on your choices.
06

4. クッキーおよび類似のテクノロジー

当社は、ウェブサイトの運営、お客様の嗜好の記憶、パフォーマンスの向上、利用状況の測定のために、Cookieおよび類似の技術を使用しています。法律で義務付けられている場合、必須ではないCookieの使用については同意をお願いしています。詳しくは、 Cookieポリシーをご覧ください。
07

5. 第三者との共有

当社は、必要な場合にのみ個人データを共有します。たとえば、次のような場合です。

  • 支払い、払い戻し、および関連する取引チェックを処理する支払いサービスプロバイダー。
  • 注文を配送し、返品を処理する配送および物流パートナー。
  • プラットフォームをサポートするホスティング、インフラストラクチャ、電子メール、および技術サービス プロバイダー。
  • 分析およびマーケティング パートナー (許可されている場合、および必要な場合はお客様の同意を得た場合のみ)。
  • 法的に情報を開示する必要がある公的機関、規制当局、または法執行機関。

第三者が当社に代わってデータを処理する場合、当社は必要に応じてデータ処理契約を使用し、合意された目的にのみ個人データを処理するよう指示します。

08

8. Key service providers

ServiceRole and dataMore information
StripePayments, direct charges, seller verification, fraud prevention and payouts. Stripe receives data directly through secure payment and onboarding components.Stripe Privacy
PrintfulOptional product, fulfillment, shipping, tracking and return services. Name, address, contact and order data may be shared for fulfillment.Printful Privacy
Hosting and databaseCloud hosting, secure storage, backups, network delivery and operational logging.Contractually restricted providers
Email and communicationsTransactional messages, verification, order updates, support and consented marketing.Necessary contact and message data only

Specific vendors and subprocessors may change as our infrastructure changes. We assess providers before they process personal data.

09

9. International transfers

Some providers or their subprocessors are located outside the European Economic Area. Where the GDPR requires it, we rely on an adequacy decision, European Commission Standard Contractual Clauses or another valid safeguard. We assess supplementary organizational and technical measures where appropriate.

European Commission Standard Contractual Clauses
10

6. データの保持

データカテゴリ保存期間
請求書と取引記録At least 7 years under applicable Estonian accounting and tax rules, calculated from the legally prescribed starting date
顧客アカウントデータアカウントの有効期間中、および非アクティブまたは閉鎖後の一定期間
マーケティングの好みと同意の記録同意が撤回されるか、同意を証明する必要がなくなるまで
セキュリティ、ログ、分析データセキュリティと分析の目的に適した限られた期間
Seller KYC and payout recordsWhile needed for the payment relationship and afterward as required for financial, anti-fraud and legal obligations; Stripe also applies its own retention periods
Order and fulfillment recordsAs needed for delivery, returns, disputes, warranties and applicable accounting and tax periods

After the applicable period, we delete or anonymize data unless it remains necessary for a legal claim, investigation, dispute or other legal obligation.

11

7. セキュリティ

当社は、個人データを保護するために、次のような適切な技術的および組織的措置を実施します。

  • 転送中の暗号化(HTTPS / TLS)
  • パスワードハッシュと安全な認証制御
  • アクセス制御とロールベースの権限
  • 監視、バックアップ、セキュリティメンテナンスのプロセス

No system is entirely risk-free. Protect your account with a unique password and two-factor authentication where available.

12

8. お客様の権利

お住まいの地域および適用法に応じて、お客様には以下の権利がある場合があります。

  • 当社が保有するお客様の個人データへのアクセスをリクエストします。
  • 不正確または不完全な個人データの修正を要求します。
  • 該当する場合、個人データの削除をリクエストします。
  • 処理の制限を要求したり、特定の処理活動に異議を申し立てたりします。
  • 同意に基づいて処理が行われる場合、いつでも同意を撤回できます。
  • Receive your data in a portable format where the right to data portability applies.
  • You may also complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or the supervisory authority where you usually live.

Send requests to info@venroys.com. We may request additional information to verify your identity. We normally respond within one month; the GDPR permits a reasoned extension for complex requests.

13

13. Fraud, trust and automated signals

Venroys uses security, fraud and performance indicators such as delivery outcomes, refunds, chargebacks, account age, policy incidents and verification status. These signals support risk management and marketplace review. Marketplace access is not automatically guaranteed by a score. Decisions with a material effect may be reviewed by a person, and you may contact us to request an explanation or review.

14

14. Security incidents

We investigate suspected personal-data breaches, limit their effects and notify the competent authority and affected people where legally required. Report suspected security issues to info@venroys.com without sending passwords or complete payment details.

15

15. Seller responsibilities

Sellers receiving personal data through Venroys must use it lawfully, securely and only for permitted business purposes. They may not use customer data for unsolicited marketing, sell it or disclose it outside necessary order and support processes. Sellers must provide their own privacy information where required and respond to data-subject requests for which they are responsible.

16

9. 未成年者

Venroysは、適用法でデータ処理への同意が求められる年齢(例えば、一部の法域では16歳)未満のお子様を対象としていません。当社は、必要な同意を得ずにお子様から個人データを故意に収集することはありません。

17

11. 本プライバシーポリシーの変更

当社は、本プライバシーポリシーを随時更新することがあります。ページ上部の「最終更新日」は、このページの最終更新日を示しています。重要な変更を行う場合は、必要に応じてウェブサイト、メール、またはアカウント通知を通じてお知らせする場合があります。

18

12. 連絡先

本プライバシーポリシーまたは当社のデータ慣行についてご質問、ご懸念、ご要望がございましたら、下記までご連絡ください。
ヴェンロイスOÜ
トルニマエ tn 5
10145 タリン
エストニア
登録コード: 17427636
経営委員会:コンスタンチノ・アエミリウス・ダルシャン・チャンゴエ
メールアドレス: info@venroys.com
ウェブサイト: venroys.com

Founders: Constantino Aemilius Darshan Changoe and Muhammet Fatih Koçyigit

info@venroys.com