Privacy policy
PRIVACY POLICY
Are you concerned about how your personal data is handled in this online store? Then you’ve come to the right place!
Below you can read how we at UPURU handle personal data, as well as get information about your rights as a registered user with us. We hope you find what you're looking for here. Of course, you are also welcome to contact us if you have any questions about how we process your information. We are committed to safety and transparency in this area and take your inquiries seriously!
Data Controller:
-
Name: UPURU
-
Sole Proprietorship: Upuru Karlsen
-
Email: upurunorge@gmail.com
WHY DO WE PROCESS PERSONAL DATA?
We collect and process personal data to offer visitors to our website the services and products they request. We also aim to provide better and more relevant content to each customer and build good, long-term relationships with our existing customers.
WHEN DO WE PROCESS PERSONAL DATA?
Below is a list of when and how we process personal data in different situations. Note that all processing is based on consent, with the exception of data collected at the time of purchase, where certain information must be provided to complete the transaction. In such cases, the legal basis is contract performance.
Newsletter:
-
Where: Store newsletter
-
Data stored: Email address
-
Purpose: To send newsletters
-
Retention: Until you unsubscribe or request deletion
-
Legal basis: Consent
-
Security: Data is stored on a secured server. Contact us for more information.
Purchases:
-
Where: Store checkout
-
Data stored: First name, last name, phone number, email, street address, postal code, city, product name, quantity, chosen shipping options, selected payment method (e.g. Vipps), and price. National ID numbers are collected and processed only by the payment provider.
-
Purpose: To complete your purchase and delivery, issue invoices where applicable, and for bookkeeping. Contact information may also be used to reach you regarding your purchase.
-
Retention: Data is retained in accordance with the Norwegian Accounting Act, typically for 10 years. If a warranty is involved, data is kept as long as the warranty is valid, but never less than 10 years.
-
Legal basis: Contract and legal obligation.
-
Security: Data is stored on a secured server.
-
Third-party processors: Vipps, Shopify, PayPal
Contact Form / Customer Inquiries:
-
Where: Website contact form
-
Data stored: First name, last name, phone number, email, and message
-
Purpose: To respond to your inquiry and keep history for follow-ups
-
Retention: As long as necessary to respond
-
Legal basis: Consent
-
Security: Data is stored on a secured server
Customer Account:
-
Where: "My Account / Create Account"
-
Data stored: First name, last name, address, phone number, email, and password
-
Purpose: To allow account management and access to order history
-
Retention: Until deletion is requested
-
Legal basis: Consent
-
Security: Stored securely
Cookies:
We use cookies to improve the user experience. The use of cookies is based on your consent through your browser settings and continued use of our site.
🔗 Please see our [cookie policy] for full details.*
WHAT IS OUR LEGAL BASIS FOR PROCESSING?
Most processing is based on your consent, except for when you make a purchase, in which case processing is necessary for fulfilling a contract and complying with legal bookkeeping obligations.
We confirm that Norwegian law offers sufficient protection of personal data.
YOUR RIGHTS
-
Access: You have the right to access your personal data.
-
Correction: You can request correction of inaccurate or incomplete data.
-
Deletion: You can request deletion unless legal grounds prevent immediate removal.
-
Restriction: You may request limited use of your data in certain circumstances.
-
Portability: If processing is automated and based on consent, you may transfer your data to another provider.
-
Withdraw Consent: You can withdraw consent at any time for any processing based on consent.
-
Lodge a Complaint: You may contact us or the Norwegian Data Protection Authority (Datatilsynet) if you believe your rights have been violated.
DATA SHARING WITH META (FACEBOOK AND INSTAGRAM)
We collect certain data to enhance marketing and user experience. With Shopify’s maximum data sharing enabled, we share data with Meta to support ad targeting, campaign optimization, and performance analytics.
What we share:
-
Personal Data: Name, email address, phone number
-
Usage Data: Visit history, product views, cart actions, purchases
-
Device & Browser Info: IP address, device type, OS, browser
-
Ad Interaction: Clicks, likes, comments, shares
How Meta uses the data:
To tailor ads, create custom audiences, and improve algorithms. This helps us show more relevant content based on your activity.
Legal basis: Consent under GDPR.
International Transfers: Data may be processed outside the EEA (e.g., USA) under Standard Contractual Clauses or equivalent safeguards.
Your Choices:
You can manage data use via Facebook and Instagram settings, or contact us directly to access or delete your data. Withdrawal of consent is available via our website or by contacting us.
Questions?
Contact us at [upurunorge@gmail.com].
You also have the right to contact Datatilsynet, the Norwegian Data Protection Authority, if you disagree with our practices.