1. This policy is governed under the General Data Protection Regulation (GDPR).
2. What Personal Data We Collect
When you use our site, we may collect the following personal data:
- Identity and contact information: Name, email address, billing/shipping address.
- Order information: Products ordered, payment status.
- Technical data: IP address, browser type, device information.
- Payment details: Processed securely via Stripe or PayPal (we do not store card numbers)
3. How We Use Your Data
We process your data to:
Purpose:
- Process and ship your order
- Communicate about your order
- Prevent fraud
- Improve our store
- Fulfill legal obligations (e.g. taxes)
We do not use your data for unsolicited marketing.
4. Cookies
We use cookies to ensure basic functionality (like cart storage), analyze traffic, and prevent fraud. Analytics do not collect personally identifiable data without your consent.
We use strictly necessary cookies and analytics cookies. You will be presented with a cookie consent banner upon arrival to choose your preferences.
You can manage cookies anytime via your browser settings or by clicking [Cookie Settings].
5. Payment Providers: Stripe and PayPal
We use Stripe and PayPal to process payments. When you make a purchase:
- Your payment data is processed directly by these providers.
- We do not store your full card details or PayPal credentials.
- Data may be transferred outside the EEA (e.g., to the U.S.) under Standard Contractual Clauses (SCCs) to ensure legal protection.
Please review:
6. Sharing of Data
We only share your data with:
- Payment processors: Stripe and PayPal
- Shipping carriers to fulfill orders
- Legal authorities, if required
We do not sell or rent your personal data to third parties.
7. International Transfers
Where necessary, personal data may be transferred outside the European Economic Area (EEA). All transfers are secured using approved mechanisms such as SCCs or handled by providers with adequate data protection levels.
8. How Long We Keep Your Data
Data Type + Retention Period
- Order records – 7 years (for accounting/tax laws)
- Account data (if created)- Until deleted
- Cookie data – Based on your consent (max 13 months)
9. Your Rights Under GDPR
You can:
- Request access to your data
- Correct inaccuracies
- Request deletion
- Withdraw consent (where applicable) Object to processing
- Request data portability
To exercise your rights, email us at info@geeksteel.com
You also have the right to lodge a complaint with your local Data Protection Authority (DPA).
10. Security Measures
We use SSL encryption, secure payment gateways to protect your data against unauthorized access or loss
11. Changes to This Policy
We may update this policy. When we do, we will revise the “Effective Date” and notify you on our website.