Legal / Privacy
Privacy policy.
What we collect when you sign in or place an order, why we need it, who else touches it, and how to get it back or get rid of it. Written to be read, not to be survived.
Who we are
This website is operated by [Registered company name, e.g. „Skull & Roses” SRL], trading as Skull & Roses ([IDNO - 13-digit state registration number]), of [Street address], Chișinău, [postal code], Moldova. We are the controller of the personal data described here, which means we decide what is collected and why.
For anything in this policy - a question, a correction, or a request to delete what we hold - write to [email protected]. A person reads that inbox.
We process personal data under Law No. 133/2011 of the Republic of Moldova on the protection of personal data, and under the EU General Data Protection Regulation where it applies to you as a visitor or customer in the European Economic Area.
What we collect
We collect what an order and an account need, and nothing beyond it. There is no analytics account, no advertising pixel, and no third-party tracker on this site.
When you sign in
Signing in uses either a one-time code sent to your email address, or your Google account. In the first case we hold your email address and the sign-in session it created. In the second, Google confirms your identity to us and passes on your name, email address and profile picture; we never receive your Google password.
When you place an order request
The checkout collects your first and last name, email address, phone number if you give one, and the delivery address you want the order sent to. We store that alongside the items you selected, a short order reference, and the status of the order, so both of us can refer to the same record afterwards.
Details you ask us to remember
If you place an order while signed in, we save those contact and delivery details to your account so the next checkout arrives filled in. You can change or clear them at any time from your account, or ask us to.
Your selection
The products you add before ordering are kept in your own browser. Once you are signed in, that selection is also stored against your account, so it follows you from your phone to your laptop.
Keeping sign-in usable
We count how many sign-in codes have been requested for an email address in the past hour, and how many have been requested across the site. Without that counter, anyone could use our sign-in form to send mail to strangers in our name.
We never collect or store card numbers, bank details, or any payment credentials. No payment is taken on this website - see how an order works.
Why we use it, and on what basis
Every piece of data above is used for one of the following purposes, each with the legal ground that permits it.
- To handle your order - confirming items, price and delivery, and getting the parcel to the right address. Basis: performance of a contract with you, and steps taken at your request before it.
- To give you an account - proving it is you, keeping you signed in, and showing you your own orders. Basis: performance of a contract.
- To send transactional email - sign-in codes and order confirmations. These are not marketing and cannot be unsubscribed from without closing the account. Basis: performance of a contract.
- To protect the site - rate-limiting sign-in codes so our sending address is not used to spam other people. Basis: our legitimate interest in a service that is not abused.
- To meet obligations we cannot opt out of - accounting and tax records for sales that complete. Basis: compliance with a legal obligation.
We do not profile you, we do not make automated decisions that significantly affect you, and we do not sell personal data to anyone for any purpose.
Who else handles it
We use a small number of service providers to run the site. They process data on our instructions only, and none of them are permitted to use it for their own purposes.
- Convex - the database and authentication system holding accounts, orders and saved details.
- Vercel - hosting and delivery of the website itself.
- Resend - delivery of sign-in codes and order email.
- Google - only if you choose to sign in with a Google account, and only to confirm that the account is yours.
- Cloudflare - routing mail sent to our brand address to the inbox we read.
If you continue an order with us on Instagram, that conversation happens on Meta’s platform and under Meta’s privacy terms as well as ours. Nothing obliges you to use it - email reaches us just as well.
These providers operate servers outside Moldova, including in the European Union and the United States, so your data is transferred internationally. Those transfers rely on the providers’ standard contractual clauses and equivalent safeguards. Beyond this list, we disclose personal data only where the law requires it of us, or to establish or defend a legal claim.
How long we keep it
- Account and sign-in data - for as long as your account exists. Ask us to close it and it goes.
- Orders - for as long as we may need them for accounting and tax purposes, which in Moldova generally means several years from the end of the financial year. Order records are kept even if the account is closed, for that reason alone.
- Saved checkout details - until you change them, clear them, or close your account.
- Your selection - until you empty it or close your account. In your browser, until you clear your browser storage.
- Sign-in code counters - a rolling window measured in hours, then overwritten.
Your rights
Over the data we hold about you, you have the right to:
- ask what we hold and get a copy of it;
- have anything inaccurate corrected;
- have it deleted, where we have no continuing obligation to keep it;
- ask us to restrict what we do with it while a question is open;
- receive what you gave us in a portable, machine-readable form;
- object to processing we base on our own legitimate interest; and
- withdraw consent, wherever we relied on it, without affecting what was done beforehand.
Write to [email protected] and we will respond within one month. We do not charge for this.
If you think we have handled your data wrongly, we would rather hear it from you first - but you can complain to the National Centre for Personal Data Protection of the Republic of Moldova, or, if you are in the European Economic Area, to the supervisory authority where you live.
How it is protected
The site is served over an encrypted connection, and data is encrypted in transit and at rest by our providers. Signing in never involves a password we could lose: it is a single-use code sent to an inbox you already control, or your Google account. Failed code attempts are limited, and the number of codes that can be requested for an address is capped.
Access to customer records is limited to the people who need it to fulfil orders. No system is beyond compromise, and we will not pretend otherwise - if a breach ever affects your rights, we will tell you and the supervisory authority as the law requires.
Children
This site sells coffee and clothing to adults and is not directed at children. We do not knowingly create accounts for, or collect data from, anyone under 16. If you believe a child has given us personal data, write to us and we will remove it.
Changes to this policy
When the site changes what it collects, this page changes with it, and the date at the top changes too. If a change materially affects your rights, we will do more than update this page quietly - we will tell account holders by email.
Something unclear?
Ask us straight.
Anything in this document can be explained in plain language, and any request about your data is answered by a person. Write to [email protected] or start in the help pages.