Tikkaro · Legal
Privacy Policy
We treat your personal data the way we'd want ours treated — with the minimum collection necessary, strict access control, and full compliance with the EU General Data Protection Regulation (GDPR).
Last updated: May 2026
1. Who we are
Tikkaro is operated as an independent collector platform. The data controller for the purposes of GDPR is Tikkaro, contactable at privacy@tikkaro.store.
2. Data we collect
- Account & order data: name, email, shipping address, phone (optional), order history.
- Payment data: processed by our PCI-DSS compliant payment providers — we never store full card numbers.
- Technical data: IP address, browser type, device, pages visited (for security and analytics).
- Marketing preferences: only if you opt in to our newsletter.
3. Cookies
We use strictly necessary cookies (cart, session) and, with your consent, analytics cookies (aggregated traffic measurement). You can withdraw consent at any time via your browser settings.
4. Analytics
We use privacy-friendly analytics to understand how visitors discover and use the site. Analytics data is aggregated and never sold to third parties.
5. Payment processing
Card payments are tokenised and processed by our payment provider. We receive only the minimum information required to identify the transaction and prevent fraud.
6. Email marketing
We only send marketing emails to subscribers who explicitly opt in. Every email includes a one-click unsubscribe link.
7. Sharing & transfers
We share data only with carriers (for shipping) and processors (payments, analytics, email) bound by GDPR-compliant data processing agreements. We never sell your personal data.
8. Retention
Order data is retained for the period required by tax and accounting law (typically 7–10 years). Marketing data is retained until you unsubscribe.
9. Your rights under GDPR
- Right of access — request a copy of your data.
- Right to rectification — correct inaccurate data.
- Right to erasure — request deletion (subject to legal retention).
- Right to restrict or object to processing.
- Right to data portability.
- Right to lodge a complaint with your supervisory authority.
10. Contact
Privacy requests: privacy@tikkaro.store. We respond within 30 days.