No raw card data
Card and payment details are processed securely by Stripe. Venroys does not store full card numbers or CVC codes.
This policy explains in clear language what data Venroys processes, why it is needed, and the choices and rights available to you.
Venroys OÜ is established in Estonia and is subject to the GDPR. Depending on the service, Venroys, an independent seller and a service provider may each have a separate role.
Card and payment details are processed securely by Stripe. Venroys does not store full card numbers or CVC codes.
A seller is responsible for its products, customer service and its own legal obligations. Venroys operates the technical infrastructure.
You can exercise privacy rights, stop marketing and manage non-essential cookies.
Founders: Constantino Aemilius Darshan Changoe and Muhammet Fatih Koçyigit
Venroys の使用方法(ショッピング、アカウントの作成、当社への連絡、またはプラットフォームでの販売)に応じて、当社は以下のカテゴリーの個人データを処理する場合があります。
| カテゴリ | 例 |
|---|---|
| 識別情報と連絡先データ | 氏名、請求先/配送先住所、メールアドレス、電話番号、アカウントID |
| 支払いおよび請求データ | 決済プロバイダートークン、取引ID、請求書の詳細、支払いの詳細(販売者向け) |
| 注文と履行データ | 注文商品、数量、配送方法、配送状況、返品・返金情報 |
| アカウントとログインデータ | ユーザー名/メールアドレス、ハッシュ化されたパスワード、アカウント設定、ログインタイムスタンプ |
| コミュニケーションと同意データ | サポートメッセージ、ニュースレターのオプトインステータス、Cookieの同意の選択 |
| 技術データとデバイスデータ | IPアドレス、ブラウザの種類、デバイス情報、セッションログ、セキュリティイベント |
| 使用状況と行動データ | 閲覧したページ、検索クエリ、クリック数、スクロール行動、閲覧した商品 |
| Seller and verification data | Business details, representatives, date of birth, tax details, verification status and Stripe Connect account references |
| Storefront and content data | Brand name, domain, website content, product media, theme settings and published pages |
| Derived risk and trust signals | Delivery outcomes, refund and chargeback rates, policy status, suspicious activity and marketplace progress |
当社は、特別なカテゴリーの個人データ(例えば、健康データ)を意図的に収集することはありません。注文メモ、サポートメッセージ、その他の自由記述欄には、必要不可欠な場合を除き、機密性の高い個人情報を入力しないでください。
| 目的 | 法的根拠(GDPR) | 詳細 |
|---|---|---|
| アカウントの作成と認証 | 契約の履行(第6条(1)(b)) | アカウントを作成し、安全にログインできるようにし、アカウントを利用できるようにしておきます。 |
| 注文処理、支払い、配送 | 契約の履行(第6条(1)(b)) | 購入の処理、注文の確認、発送の手配、返品または返金の管理を行います。 |
| 顧客サポートとサービスコミュニケーション | 正当な利益(第6条(1)(f)) | 質問に答え、問題を調査し、サポート品質を向上させるため。 |
| マーケティングコミュニケーションとプロモーションオファー | 同意(第6条(1)(a)) | 法律で義務付けられている場合、およびお客様が同意した後のみ。いつでも登録を解除したり、同意を取り消したりできます。 |
| セキュリティ、不正防止、プラットフォームの整合性 | 正当な利益(第6条(1)(f))と法的義務(第6条(1)(c)) | 不正使用を検出し、アカウントを保護し、詐欺を防止し、セキュリティ関連の義務を遵守するため。 |
| 法務、税務、会計コンプライアンス | 法的義務(第6条(1)(c)) | 簿記、税金、報告、およびその他の法定要件を満たすため。 |
| Seller verification and payouts | Contract, legal obligation and legitimate interests | To onboard sellers, verify identity and business details, enable payouts and limit financial fraud. |
| Marketplace trust and policy administration | Legitimate interests and contract | To monitor seller performance, review marketplace applications and protect customers and the platform. |
| Service | Role and data | More information |
|---|---|---|
| Stripe | Payments, direct charges, seller verification, fraud prevention and payouts. Stripe receives data directly through secure payment and onboarding components. | Stripe Privacy |
| Printful | Optional product, fulfillment, shipping, tracking and return services. Name, address, contact and order data may be shared for fulfillment. | Printful Privacy |
| Hosting and database | Cloud hosting, secure storage, backups, network delivery and operational logging. | Contractually restricted providers |
| Email and communications | Transactional messages, verification, order updates, support and consented marketing. | Necessary contact and message data only |
Specific vendors and subprocessors may change as our infrastructure changes. We assess providers before they process personal data.
Some providers or their subprocessors are located outside the European Economic Area. Where the GDPR requires it, we rely on an adequacy decision, European Commission Standard Contractual Clauses or another valid safeguard. We assess supplementary organizational and technical measures where appropriate.
European Commission Standard Contractual Clauses ↗| データカテゴリ | 保存期間 |
|---|---|
| 請求書と取引記録 | At least 7 years under applicable Estonian accounting and tax rules, calculated from the legally prescribed starting date |
| 顧客アカウントデータ | アカウントの有効期間中、および非アクティブまたは閉鎖後の一定期間 |
| マーケティングの好みと同意の記録 | 同意が撤回されるか、同意を証明する必要がなくなるまで |
| セキュリティ、ログ、分析データ | セキュリティと分析の目的に適した限られた期間 |
| Seller KYC and payout records | While needed for the payment relationship and afterward as required for financial, anti-fraud and legal obligations; Stripe also applies its own retention periods |
| Order and fulfillment records | As needed for delivery, returns, disputes, warranties and applicable accounting and tax periods |
After the applicable period, we delete or anonymize data unless it remains necessary for a legal claim, investigation, dispute or other legal obligation.
当社は、個人データを保護するために、次のような適切な技術的および組織的措置を実施します。
No system is entirely risk-free. Protect your account with a unique password and two-factor authentication where available.
お住まいの地域および適用法に応じて、お客様には以下の権利がある場合があります。
Send requests to info@venroys.com. We may request additional information to verify your identity. We normally respond within one month; the GDPR permits a reasoned extension for complex requests.
Venroys uses security, fraud and performance indicators such as delivery outcomes, refunds, chargebacks, account age, policy incidents and verification status. These signals support risk management and marketplace review. Marketplace access is not automatically guaranteed by a score. Decisions with a material effect may be reviewed by a person, and you may contact us to request an explanation or review.
We investigate suspected personal-data breaches, limit their effects and notify the competent authority and affected people where legally required. Report suspected security issues to info@venroys.com without sending passwords or complete payment details.
Sellers receiving personal data through Venroys must use it lawfully, securely and only for permitted business purposes. They may not use customer data for unsolicited marketing, sell it or disclose it outside necessary order and support processes. Sellers must provide their own privacy information where required and respond to data-subject requests for which they are responsible.
Venroysは、適用法でデータ処理への同意が求められる年齢(例えば、一部の法域では16歳)未満のお子様を対象としていません。当社は、必要な同意を得ずにお子様から個人データを故意に収集することはありません。
当社は、本プライバシーポリシーを随時更新することがあります。ページ上部の「最終更新日」は、このページの最終更新日を示しています。重要な変更を行う場合は、必要に応じてウェブサイト、メール、またはアカウント通知を通じてお知らせする場合があります。
Founders: Constantino Aemilius Darshan Changoe and Muhammet Fatih Koçyigit
info@venroys.com