Privacy Policy
1. Overview and Data Controller
This Privacy Policy sets out how meshwallcaddy processes and protects personal data collected through the website www.meshwallcaddy.com.
For the purposes of the General Data Protection Regulation (GDPR) and applicable European data protection laws, the data controller responsible for your personal information is meshwallcaddy (contact email: mesh@meshwallcaddy.com).
2. Personal Data Collected
We collect and process personal data necessary for providing our products, processing orders, and fulfilling our contractual commitments. This includes:
Identity and Contact Data: Name, billing address, shipping address, and email address.
Transaction Data: Details of products ordered, purchasing history, and order fulfillment records.
Technical and Usage Data: IP address, browser type, device identifier, and page interaction metrics collected via cookies or technical logs.
3. Legal Basis for Processing
We process personal data in accordance with the provisions of Article 6(1) of the GDPR under the following legal bases:
Contractual Necessity (Art. 6(1)(b) GDPR): To accept, process, ship, and deliver your orders, and to provide customer support regarding purchases.
Legal Obligation (Art. 6(1)(c) GDPR): To comply with statutory accounting, tax, and commercial record-keeping obligations under applicable European law.
Legitimate Interests (Art. 6(1)(f) GDPR): To secure our website operations, prevent fraudulent activities, and optimize user experience.
4. Payment Processing and Third-Party Data Transfer
To process online payments securely, we integrate payment processing services provided by Stripe Payments Europe, Ltd. (1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland).
When an order is placed, transaction-related data (such as order total, currency, name, and billing details) is transmitted to Stripe for authorization and payment clearance. Stripe acts as an independent data controller for payment processing activities. We do not store or process complete credit card details or payment credentials on our own servers. Transfers of personal data to Stripe adhere to applicable European data protection frameworks.
5. Data Retention Period
Personal data is stored only for as long as required to fulfill the purposes for which it was collected or to comply with statutory retention limits under applicable commercial and tax law:
Order and Transaction Records: Retained for up to 10 years to comply with statutory legal and tax retention requirements.
General Inquiries and Communications: Retained for the duration necessary to resolve the inquiry, and purged thereafter unless needed for legal defense.
Technical Logs: Retained for up to 30 days for system security and administrative monitoring, unless required for operational security investigations.
Upon expiration of the relevant retention periods, personal data is permanently erased or anonymized.
6. Security Measures
We implement standard technical and organizational measures designed to protect personal data against unauthorized access, loss, alteration, or disclosure. Data transmissions on our website are encrypted using Industry-standard Transport Layer Security (TLS) technology. While continuous technical protocols are maintained, no transmission over the Internet or electronic storage system can be guaranteed completely immune from all prospective vulnerabilities.
7. Rights of Data Subjects
Under the General Data Protection Regulation (GDPR), individuals residing in the European Economic Area possess the following rights regarding their personal data:
Right of Access (Art. 15 GDPR): Request information regarding personal data held by us.
Right to Rectification (Art. 16 GDPR): Request correction of inaccurate or incomplete personal data.
Right to Erasure (Art. 17 GDPR): Request deletion of personal data where legal grounds permit.
Right to Restriction of Processing (Art. 18 GDPR): Request limitation of data processing activities.
Right to Data Portability (Art. 20 GDPR): Request transfer of personal data in a structured, commonly used format.
* Right to Object (Art. 21 GDPR): Object to processing based on legitimate interests.
To exercise any of these rights, please contact us at mesh@meshwallcaddy.com. You also maintain the right to lodge a complaint with a competent supervisory authority within the European Union.
8. Cookies
Our website utilizes necessary technical cookies required for proper site functionality and shopping cart persistence. Non-essential operational or analytical cookies are deployed strictly where applicable user preferences allow. Users can adjust cookie preferences through their web browser settings.
9. Contact Details
For questions regarding this Privacy Policy or the processing of personal data, please contact:
meshwallcaddy
Website: www.meshwallcaddy.com
Email: mesh@meshwallcaddy.com