YOUR DATA
Privacy Policy
How Yavqo Store collects, uses, shares, and protects personal data.
Last updated: 30 August 2026The controller’s verified legal name, full postal address, and public privacy email must be added to the Legal Notice before live sales begin.
1. Controller
The data controller is the business operating Yavqo Store, identified in the Legal Notice. That business decides why and how personal data is processed through this Store.
2. Data we process
- Account data, such as your user ID, email address, authentication records, and profile avatar URL.
- Order data, such as products, quantities, prices, order status, timestamps, customer email, and any creator code applied to the order.
- Creator-program data, such as creator name, contact email, assigned code, attributed orders, commission amounts, and settlement status.
- Checkout and delivery data, such as billing and shipping addresses and transaction identifiers.
- Bag data, such as products and quantities saved to your signed-in cart.
- Technical and security data, such as IP address, browser information, request logs, and essential session identifiers generated by our hosting, authentication, and payment providers.
- Messages or requests you send to us.
3. Why we process data and our legal bases
- To create and operate your account, maintain your bag, take payment, deliver orders, handle returns, and provide support: performance of a contract or steps requested before a contract (GDPR Article 6(1)(b)).
- To administer creator codes, attribute verified purchases, calculate commission balances, prevent duplicate attribution, and settle approved earnings: performance of the creator arrangement and our legitimate interests in operating and auditing the creator program (Articles 6(1)(b) and 6(1)(f), as applicable).
- To keep invoices and transaction records, respond to lawful requests, and meet tax, accounting, product-safety, and consumer-law duties: compliance with legal obligations (Article 6(1)(c)).
- To prevent fraud, secure the Store, troubleshoot failures, and improve reliability: our legitimate interests in operating a safe and effective store (Article 6(1)(f)).
- Where we specifically ask for optional consent, we rely on that consent (Article 6(1)(a)); you may withdraw it at any time for future processing.
4. Service providers and recipients
We disclose only the data reasonably required for a service. Recipients may include Supabase for authentication, database, and storage services; Stripe and participating payment providers for checkout, payment processing, and fraud prevention; Resend for transactional order-confirmation email delivery; our site-hosting and security providers; delivery providers when goods are shipped; and professional advisers or public authorities where legally required.
Stripe may also process transaction data for its own regulatory, security, and fraud-prevention purposes. Its privacy information is available from Stripe’s Privacy Center. Resend receives the customer email address and the order and delivery details needed to generate and deliver the requested confirmation message.
5. International transfers
Some providers may process data outside the European Economic Area. Where required, transfers are protected by an adequacy decision, approved standard contractual clauses, or another lawful safeguard. Provider privacy documentation contains further details about the locations and safeguards used.
6. Retention
We keep personal data only as long as needed for the purposes described above. Account and bag data are generally kept while the account remains active. Order, payment, tax, and accounting records may be retained for the statutory retention period. Security logs are retained only for a proportionate period. Data may be kept longer where required to establish, exercise, or defend legal claims.
7. Cookies and local storage
The Store uses essential browser storage and similar technologies to maintain authentication, security, bag functionality, and a creator code that you choose to apply. These are necessary to provide features you request. We do not currently use advertising or behavioral-marketing cookies. If optional analytics or marketing tools are introduced, this policy and any required consent controls must be updated first.
8. Your rights
- Access your personal data and obtain a copy.
- Correct inaccurate or incomplete data.
- Request erasure where the legal conditions are met.
- Restrict processing in certain circumstances.
- Receive portable data for eligible processing.
- Object to processing based on legitimate interests and to direct marketing at any time.
- Withdraw consent at any time where processing relies on consent.
- Lodge a complaint with the competent data protection authority.
9. Security and automated decisions
We use access controls, encrypted connections, row-level database rules, and limited credentials designed to protect customer information. No internet service can guarantee absolute security.
Yavqo does not make decisions that produce legal or similarly significant effects based solely on automated processing. Stripe and payment partners may conduct automated fraud checks under their own legal responsibilities.
10. Changes and contact
We may update this policy when our services or legal obligations change. The date above shows the latest revision. To exercise privacy rights or ask a question, use the verified contact details that will appear in the Legal Notice.
Official consumer resources
For independent information, visit the EU guidance on returns, EU guidance on legal guarantees, and the German provider-information rules.
