Privacy policy
Effective date: [01.12.2025]
This Privacy & Cookie Policy explains how Rebelicious SIA (“Rebelicious”, “we”, “us”, “our”) collects, uses, shares and protects your personal data when you visit our Shopify store at rebelicious.eu, purchase our products, book our services or interact with us in other ways. It also explains your rights under the EU General Data Protection Regulation (GDPR) and related laws.
Rebelicious SIA is the controller of your personal data processed in connection with this store. Shopify acts as our e-commerce service provider and data processor for customer data.
1. What data we collect
Depending on how you interact with us, we may collect the following categories of data:
1.1 Identity and contact data
-
name and surname
-
billing and shipping address
-
email address
-
phone number
-
account username (if you create an account)
1.2 Order and transaction data
-
products purchased, order history and payment status
-
chosen shipping method and tracking details
-
invoice details, including VAT information where relevant
1.3 Payment data
-
limited payment information (for example card type, last four digits, transaction IDs) processed through Shopify’s payment gateway and third-party providers such as Stripe or PayPal
-
we do not store full card numbers or CVV codes on our servers
1.4 Technical and usage data
-
IP address, device identifiers, browser type and version
-
operating system, time zone setting and approximate location
-
pages viewed, links clicked, time spent on pages
-
referring URLs and campaign parameters
1.5 Marketing and communication data
-
newsletter subscription status
-
preferences for marketing emails or SMS (where applicable)
-
records of your communications with us, including email and contact forms
1.6 Workshop, event and professional account data
-
details you provide when booking courses, workshops or pro accounts (such as business name, school, studio, role or professional ID where relevant)
2. How we obtain your data
We collect personal data from:
-
information you provide directly (checkout, account creation, contact forms, newsletter signup, workshop registration)
-
data generated automatically when you browse our site (through cookies and similar technologies)
-
data from payment processors and delivery partners in relation to your transactions
-
data from marketing tools and Shopify apps you consent to or interact with
3. Legal bases for processing
Under GDPR, we rely on the following legal bases:
-
performance of a contract: to process your orders, payments, deliveries and customer service requests
-
legitimate interests: to improve our store and services, prevent fraud and manage our business, provided these interests are not overridden by your rights
-
consent: for sending marketing communications you opt in to, and for non-essential cookies or tracking technologies where required by law
-
legal obligation: to comply with accounting, tax and consumer-protection rules, and to respond to lawful requests from authorities
4. How we use your data
We use personal data to:
-
create and manage your customer account
-
process and deliver your orders, including shipping and returns
-
process payments via Shopify and our payment providers
-
provide customer care and respond to enquiries
-
send transactional communications such as order confirmations, shipping updates and account notices
-
manage professional, wholesale and workshop or event bookings
-
personalize your experience on the Site, for example by remembering your cart
-
send marketing communications where permitted, and measure the performance of campaigns
-
detect and prevent fraud, misuse or security incidents
-
comply with legal obligations including invoicing, VAT and reporting
5. Sharing your data
We share your personal data only when necessary and with appropriate safeguards, for example with:
-
Shopify, as our store platform and hosting provider
-
payment providers such as Stripe, PayPal or banks, to process payments and prevent fraud
-
shipping and logistics partners, to deliver your orders and handle returns
-
marketing and analytics providers, including email services, analytics tools and Shopify apps, where you have consented to their use or where permitted by law
-
professional advisers, such as accountants, legal advisers and auditors
-
authorities, where required by law or to protect our legal rights
We do not sell your personal data.
6. International data transfers
Because Shopify and some of our service providers operate globally, your personal data may be transferred outside the European Economic Area. When this happens, we rely on appropriate safeguards, such as adequacy decisions and standard contractual clauses between data exporters and data importers.
7. Data retention
We keep your personal data only for as long as necessary for the purposes described above, including to:
-
fulfil orders and provide customer service
-
comply with accounting and tax retention periods under applicable law
-
resolve disputes and enforce our agreements
Typical retention periods are:
-
order and invoicing data: generally up to 10 years, depending on local legal requirements
-
marketing data: until you unsubscribe or object, plus a short period to implement your request
-
account data: for the life of your account and a reasonable period after closure
8. Your rights under GDPR
Subject to legal limitations, you have the right to:
-
access your personal data and obtain a copy
-
rectify inaccurate or incomplete data
-
erase your data (“right to be forgotten”) in certain circumstances
-
restrict processing in certain circumstances
-
object to processing based on our legitimate interests, including profiling
-
object at any time to direct marketing
-
receive your data in a structured, commonly used machine-readable format and transmit it to another controller (data portability)
-
withdraw consent at any time where processing is based on consent, without affecting prior lawful processing
To exercise these rights, contact us at hello@rebelicious.eu. We may need to verify your identity before processing your request.
You also have the right to lodge a complaint with your local data protection authority. Our lead supervisory authority in Latvia is the national Data State Inspectorate (Datu valsts inspekcija).
9. Cookies and similar technologies
9.1 What are cookies
Cookies are small text files placed on your device when you visit a website. They can remember your actions and preferences over time.
9.2 Types of cookies we use
-
strictly necessary cookies: required for the Site and checkout to function, such as cart, login and session cookies
-
preference cookies: remember your choices, such as language or region
-
analytics cookies: help us understand how visitors use our Site so we can improve it
-
marketing cookies: used to deliver more relevant ads and measure marketing performance, where enabled
9.3 Cookie consent and control
When you first visit our Shopify store from certain regions, including the European Economic Area, you may see a cookie banner. Through it, you can accept or reject non-essential cookies in line with Shopify’s customer privacy tools. You can also change your browser settings to block or delete cookies.
Please note that blocking some cookies may affect the functionality of the Site and checkout.
10. Children’s privacy
Our Site is not intended for children under 16, and we do not knowingly collect personal data from children under 16. If you believe a child has provided personal data to us, please contact hello@rebelicious.eu so we can remove it.
11. Security
We take appropriate technical and organizational measures to protect personal data against unauthorized access, loss, misuse, alteration or destruction, including:
-
using secure encrypted connections (HTTPS)
-
limiting access to personal data to staff and service providers who need it
-
regularly reviewing our security measures and Store Policies
However, no system is completely secure, and we cannot guarantee absolute security of information transmitted over the internet.
12. Changes to this Privacy & Cookie Policy
We may update this Policy from time to time, for example if we implement new features, use new apps on Shopify or if legal requirements change. The latest version will always be available on our Site, with the “Effective date” updated accordingly.
13. Contact
For questions about this Privacy & Cookie Policy or how we process your data, please contact:
Rebelicious SIA
Email: hello@rebelicious.eu