Privacy policy

Privacy Policy
Last updated: 20 August 2025

Controller. MADAME ARTWITCH is the trading name of Yulia Kireeva (also written as “Julia Kireeva” in public materials), who acts as the data controller (“we”, “us”, “our”).
This Privacy Policy explains how we collect, use, disclose, and protect personal information when you visit our website, use our services, or make a purchase.

1) Scope & relationship with Shopify
Our store is hosted on Shopify. For most processing related to your interactions with our store (orders, checkout, payments, shipping), we act as the data controller and Shopify acts as our processor under Shopify’s Data Processing Addendum. Shopify may also process some data for its own platform purposes (e.g., security, platform improvement); for those purposes Shopify is a separate controller and you can exercise rights via the Shopify Privacy Portal: https://privacy.shopify.com/en.

2) Personal data we collect or receive
We collect the following categories of personal data depending on how you use the Services, which features you choose, your cookie preferences, and our integrations with service providers:
Contact details (name, billing/shipping address, email, phone) — when you place an order, create an account or contact us.
Order & transaction data (items purchased/returned, order notes, totals) — when you make a purchase/return.
Payment data (payment method, confirmation; full card data is processed by our payment providers and is not stored by us).
Account data (if you register): username, password, preferences.
Communications (messages to customer support, reviews) — when you contact us or post a review.
Device & usage data (e.g., IP address, browser/device info, pages viewed): essential logs always; analytics/advertising data only with your consent in the EEA/UK.
Cookies/online identifiers: necessary cookies for core functionality; analytics/ads cookies only if you consent (EEA/UK).
Sources: directly from you; automatically via our site/app; from service providers (e.g., payment, shipping/fulfilment, email/CRM); and, where lawful and applicable, from marketing/advertising partners you interact with (subject to consent where required).

3) Purposes & legal bases (EEA/UK)
Contract: process orders and payments, ship goods, manage returns, provide account features, customer support.
Legal obligations: tax, accounting, fraud monitoring, lawful requests.
Legitimate interests: securing our services, preventing abuse/fraud, keeping records, limited direct marketing to existing customers (where permitted), improving our site and offerings. You can object where we rely on legitimate interests.
Consent: email/SMS marketing; non-essential cookies/analytics/ads cookies in EEA/UK; certain promotions. You may withdraw consent at any time.

4) Cookies & similar technologies
We use necessary cookies for site functionality and, with your prior consent in the EEA/UK, analytics and advertising cookies. You can accept or reject non-essential cookies and change choices any time via our cookie banner or Cookie Settings link. See our separate Cookie Policy for details (types, purposes, lifetimes, partners).

5) Marketing & advertising
With your consent (or as permitted by law), we send promotional emails/SMS and show interest-based ads using cookies or similar technologies. You can unsubscribe via each message and adjust ads preferences in Cookie Settings. Where applicable (e.g., certain US states), we honor the Global Privacy Control (GPC) opt-out signal for sale/sharing of personal information. Other browser “Do Not Track” signals are not recognized at this time.

6) Disclosure of personal data
We share data only as needed for the purposes above with: Platform & hosting (Shopify); payments (e.g., Shopify Payments/Stripe/PayPal); fulfilment & logistics (printers, warehouses, carriers); IT & support (email, CRM, analytics, cloud); marketing/ads partners (only with consent in EEA/UK); professional advisers & authorities; and in corporate transactions (e.g., merger).

7) International data transfers
Your data may be transferred outside your country (e.g., to Canada/USA) via Shopify and other providers. Where required, we use Standard Contractual Clauses (SCCs) or equivalent safeguards and assess recipients’ laws and practices.

8) Retention
We keep data only as long as necessary for the purposes collected and to meet legal obligations. For example, order and invoicing records are generally retained up to 6 years under Spanish commercial record-keeping rules, unless a longer period applies (e.g., for tax or legal claims). Marketing data is kept until you unsubscribe or withdraw consent; account data is kept while your account is active and then for a limited period for legal/operational reasons.

9) Your rights (EEA/UK and similar jurisdictions)
Subject to limits in law, you may have the right to access, rectify, erase, restrict or object to processing, data portability, and the right to withdraw consent at any time (this does not affect processing prior to withdrawal). We respond within one month and may request reasonable proof of identity.
You also have the right to lodge a complaint with your local authority. In Spain: Agencia Española de Protección de Datos (AEPD) — https://www.aepd.es/.
For data Shopify controls independently (see Section 1), use the Shopify Privacy Portal: https://privacy.shopify.com/en.

10) Children’s data
Our services are not directed to children. In Spain, if you are under 14, parental/guardian consent is required for processing based on consent. We do not knowingly collect personal information from children below the applicable minimum age. If you believe a child provided data, please contact us to delete it.

11) Security
We implement reasonable technical and organizational safeguards appropriate to the risks. However, no system is completely secure. Please avoid sending sensitive information via unencrypted channels.

12) Changes
We may update this Policy to reflect changes to our practices or legal requirements. We will post the updated version with a new “Last updated” date.

13) Contact
MADAME ARTWITCH (Yulia Kireeva) — madameartwitch@gmail.com