PRIVACY & DATA PROTECTION

Venroys 隐私政策

This policy explains in clear language what data Venroys processes, why it is needed, and the choices and rights available to you.

Last updated: August 10, 2026Effective August 10, 2026Venroys OÜ · 17427636 · EE102991020
In short

Venroys OÜ is established in Estonia and is subject to the GDPR. Depending on the service, Venroys, an independent seller and a service provider may each have a separate role.

No raw card data

Card and payment details are processed securely by Stripe. Venroys does not store full card numbers or CVC codes.

Seller storefronts

A seller is responsible for its products, customer service and its own legal obligations. Venroys operates the technical infrastructure.

Choice and control

You can exercise privacy rights, stop marketing and manage non-essential cookies.

01

1. 谁负责处理?

Venroys OÜ(爱沙尼亚私人有限公司)
注册日期:2026年2月2日(爱沙尼亚)
注册码:17427636
地址: Tornimäe tn 5, 10145 塔林, 爱沙尼亚
网站: venroys.com
管理委员会:Constantino Aemilius Darshan Changoe
主要业务(EMTAK):47711 - 专卖店服装零售
电子邮件: info@venroys.com
如有任何隐私问题、请求或投诉,请通过上述邮箱地址联系我们。如有需要,我们将任命数据保护官 (DPO),其联系方式将在此处公布。

Founders: Constantino Aemilius Darshan Changoe and Muhammet Fatih Koçyigit

02

2. 我们处理的个人数据

根据您使用 Venroys 的方式(购物、创建帐户、联系我们或在平台上销售商品),我们可能会处理以下几类个人数据:

类别示例
身份识别和联系数据姓名、账单/收货地址、电子邮件地址、电话号码、账户 ID
支付和账单数据支付提供商令牌、交易 ID、发票详情、付款详情(适用于卖家)
订单和履行数据订购商品、数量、运输方式、配送状态、退货/退款信息
账户和登录数据用户名/邮箱、哈希密码、账户偏好设置、登录时间戳
沟通和同意数据支持消息、新闻简报订阅状态、Cookie 同意选项
技术和设备数据IP 地址、浏览器类型、设备信息、会话日志、安全事件
使用情况和行为数据页面浏览量、搜索查询量、点击量、滚动行为、浏览产品数
Seller and verification dataBusiness details, representatives, date of birth, tax details, verification status and Stripe Connect account references
Storefront and content dataBrand name, domain, website content, product media, theme settings and published pages
Derived risk and trust signalsDelivery outcomes, refund and chargeback rates, policy status, suspicious activity and marketplace progress

我们不会故意收集特殊类别的个人数据(例如健康数据)。除非绝对必要,否则请勿在订单备注、支持信息或其他自由文本字段中包含敏感的个人信息。

03

3. 目的和法律依据

目的法律依据(GDPR)细节
账户创建和身份验证合同的履行(第6(1)(b)条)创建您的帐户,让您安全登录,并保持您的帐户可用。
订单处理、付款和配送合同的履行(第6(1)(b)条)处理购买事宜、确认订单、安排发货以及管理退货或退款。
客户支持和服务沟通合法利益(第6条第1款第(f)项)回答问题、调查问题、提高支持质量。
市场营销传播和促销优惠同意(第6(1)(a)条)仅在法律要求且您选择加入后才会发送。您可以随时取消订阅或撤回同意。
安全性、欺诈预防和平台完整性合法利益(第6条第1款第f项)和法律义务(第6条第1款第c项)检测滥用行为、保护账户安全、防止欺诈、履行安全相关义务。
法律、税务和会计合规法律义务(第6(1)(c)条)为了满足簿记、税务、报告和其他法定要求。
Seller verification and payoutsContract, legal obligation and legitimate interestsTo onboard sellers, verify identity and business details, enable payouts and limit financial fraud.
Marketplace trust and policy administrationLegitimate interests and contractTo monitor seller performance, review marketplace applications and protect customers and the platform.
04

4. Platform, seller and storefront roles

  • Venroys is a controller for Venroys accounts, platform security, marketplace administration, platform fees, tax records and operation of our services.
  • For an independent seller storefront, the seller may be a separate controller for customer relationships, product information, fulfillment, returns and support. The seller's identity should be available in the relevant storefront or order information.
  • Where Venroys handles data only on a seller's instructions, we act as a processor under the applicable agreement. For certain services, including payments and legally required identity checks, Stripe may act as an independent controller.
05

5. Sources of personal data

  • Directly from you through registration, checkout, support, uploads or settings.
  • From sellers when they manage an order, return or customer request.
  • From payment, fulfillment, shipping, verification and fraud-prevention providers.
  • Automatically from devices, logs, cookies and security signals, depending on your choices.
06

4. Cookie 和类似技术

我们使用 Cookie 和类似技术来运营网站、记住您的偏好、提升网站性能并衡量网站使用情况。在法律要求的情况下,我们会就非必要的 Cookie 征求您的同意。更多信息,请参阅我们的Cookie 政策
07

5. 与第三方共享

我们仅在必要时共享个人数据,例如与以下机构共享:

  • 支付服务提供商负责处理付款、退款和相关交易检查。
  • 负责配送订单和处理退货的运输和物流合作伙伴。
  • 为平台提供支持的托管、基础设施、电子邮件和技术服务提供商。
  • 分析和营销合作伙伴(仅在允许的情况下,并在需要时征得您的同意)。
  • 在法律要求我们披露信息的情况下,我们会向公共机构、监管机构或执法部门披露信息。

当第三方代表我们处理数据时,我们会根据需要使用数据处理协议,并指示他们仅出于约定的目的处理个人数据。

08

8. Key service providers

ServiceRole and dataMore information
StripePayments, direct charges, seller verification, fraud prevention and payouts. Stripe receives data directly through secure payment and onboarding components.Stripe Privacy
PrintfulOptional product, fulfillment, shipping, tracking and return services. Name, address, contact and order data may be shared for fulfillment.Printful Privacy
Hosting and databaseCloud hosting, secure storage, backups, network delivery and operational logging.Contractually restricted providers
Email and communicationsTransactional messages, verification, order updates, support and consented marketing.Necessary contact and message data only

Specific vendors and subprocessors may change as our infrastructure changes. We assess providers before they process personal data.

09

9. International transfers

Some providers or their subprocessors are located outside the European Economic Area. Where the GDPR requires it, we rely on an adequacy decision, European Commission Standard Contractual Clauses or another valid safeguard. We assess supplementary organizational and technical measures where appropriate.

European Commission Standard Contractual Clauses
10

6. 数据保留

数据类别保留期限
发票和交易记录At least 7 years under applicable Estonian accounting and tax rules, calculated from the legally prescribed starting date
客户账户数据在账户有效期内以及账户长期不活跃或关闭后的有限时间内有效。
营销偏好和同意记录直至撤回同意或不再需要证明同意为止
安全、日志和分析数据为安全和分析目的,在一段有限的时间内
Seller KYC and payout recordsWhile needed for the payment relationship and afterward as required for financial, anti-fraud and legal obligations; Stripe also applies its own retention periods
Order and fulfillment recordsAs needed for delivery, returns, disputes, warranties and applicable accounting and tax periods

After the applicable period, we delete or anonymize data unless it remains necessary for a legal claim, investigation, dispute or other legal obligation.

11

7. 安全性

我们采取适当的技术和组织措施来保护个人数据,包括:

  • 传输过程中加密(HTTPS / TLS)
  • 密码哈希和安全身份验证控制
  • 访问控制和基于角色的权限
  • 监控、备份和安全维护流程

No system is entirely risk-free. Protect your account with a unique password and two-factor authentication where available.

12

8. 你的权利

根据您所在地区和适用法律,您可能享有以下权利:

  • 请求查阅我们持有的关于您的个人数据。
  • 请求更正不准确或不完整的个人数据。
  • 如适用,请请求删除您的个人数据。
  • 请求限制处理或反对某些处理活动。
  • 如果数据处理是基于您的同意,您可以随时撤回您的同意。
  • Receive your data in a portable format where the right to data portability applies.
  • You may also complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or the supervisory authority where you usually live.

Send requests to info@venroys.com. We may request additional information to verify your identity. We normally respond within one month; the GDPR permits a reasoned extension for complex requests.

13

13. Fraud, trust and automated signals

Venroys uses security, fraud and performance indicators such as delivery outcomes, refunds, chargebacks, account age, policy incidents and verification status. These signals support risk management and marketplace review. Marketplace access is not automatically guaranteed by a score. Decisions with a material effect may be reviewed by a person, and you may contact us to request an explanation or review.

14

14. Security incidents

We investigate suspected personal-data breaches, limit their effects and notify the competent authority and affected people where legally required. Report suspected security issues to info@venroys.com without sending passwords or complete payment details.

15

15. Seller responsibilities

Sellers receiving personal data through Venroys must use it lawfully, securely and only for permitted business purposes. They may not use customer data for unsolicited marketing, sell it or disclose it outside necessary order and support processes. Sellers must provide their own privacy information where required and respond to data-subject requests for which they are responsible.

16

9. 未成年人

Venroys 不面向未达到适用法律规定可自行同意数据处理的年龄(例如,某些司法管辖区规定为 16 岁)的儿童。我们不会在未获得必要同意的情况下故意收集儿童的个人数据。

17

11. 本隐私政策的变更

我们可能会不时更新本隐私政策。页面顶部的“最后更新”日期显示了本页面上次更改的时间。如果我们做出重大变更,我们会酌情通过网站、电子邮件或帐户通知告知您。

18

12. 联系方式

如果您对本隐私政策或我们的数据处理方式有任何疑问、疑虑或要求,请通过以下方式联系我们:
Venroys OÜ
Tornimäe tn 5
10145 塔林
爱沙尼亚
注册码:17427636
管理委员会:Constantino Aemilius Darshan Changoe
电子邮件: info@venroys.com
网站: venroys.com

Founders: Constantino Aemilius Darshan Changoe and Muhammet Fatih Koçyigit

info@venroys.com