Privacy Policy
​
This Privacy Policy describes how personal information is collected, used, and shared when you visit or make a purchase from this website, in accordance with the EU General Data Protection Regulation (GDPR).
​
1. Who We Are
This website is operated by Sari Soininen, based in Finland.
For any questions or concerns, please contact: sari@sarisoininen.com.
​
2. What Personal Data We Collect
When you make a purchase or contact us, we collect:
-
Full name
-
Shipping address
-
Email address
-
Order details
-
Payment information (processed securely by third-party providers; we do not store full payment details)
We may also collect limited, aggregated technical data about site usage, such as general location based on country, browser type, and device category. This data is used only for statistical purposes and is not used to identify individual visitors.
​
3. Why We Collect This Data
We collect and process data to:
-
Fulfill and deliver orders
-
Communicate about purchases or delivery issues
-
Comply with legal obligations (e.g. accounting and tax requirements)
-
Understand how the website is used and improve its functionality
4. Legal Basis for Processing
Personal data is processed based on the following legal grounds under GDPR:
-
Contractual necessity (to fulfill orders)
-
Legal obligation (tax and accounting laws)
-
Legitimate interest (basic website functionality and aggregated analytics)
-
Consent, where required (e.g. for optional analytics cookies)
5. Data Sharing and Storage
Personal data is not sold or rented. Data is shared only with trusted service providers necessary to operate the website, including:
-
Wix (website hosting and infrastructure)
-
Payment service providers (such as PayPal or Stripe)
-
Shipping and delivery partners
These providers process data in accordance with applicable data protection laws.
6. Cookies and Analytics
This website uses essential cookies required for basic functionality, security, and purchases.
With user consent, analytics cookies may also be used to collect aggregated information about how the site is used (such as page views and country-level location). Analytics data is collected only after consent and is not used to identify individual visitors.
Users can manage cookie preferences through the cookie consent banner or browser settings.
7. Your Rights Under GDPR
You have the right to:
-
Access your personal data
-
Request correction or deletion
-
Object to or restrict processing
-
Withdraw consent where applicable
-
Lodge a complaint with your local data protection authority
To exercise these rights, contact: sari@sarisoininen.com
8. Data Retention
Personal data is retained only as long as necessary to fulfill orders and meet legal obligations.
Accounting and tax records may be retained for 6–10 years, as required by law.
9. Updates
This Privacy Policy may be updated from time to time.
The most current version will always be available on this page.
Last updated: 9.2.2026