Política de privacidad
Privacy Policy
Last updated: April 2025
Elvara ("we", "us", "our") is committed to protecting your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Data Controller
Elvara operates www.elvarafit.com. Contact: elvarafit@gmail.com | For data requests: elvarafit@gmail.com
2. What Data We Collect
- Identity data: First name, last name, email address
- Transaction data: Purchase history, payment confirmation (payment card details are processed by Stripe/Shopify Payments and never stored by us)
- Technical data: IP address, browser type, device information, pages visited
- Marketing data: Email marketing preferences and communications history
3. How We Use Your Data
- To fulfil your order and deliver your digital product (legal basis: contract)
- To send order confirmations and customer service communications (legal basis: contract)
- To send marketing emails where you have consented (legal basis: consent — withdraw anytime)
- To improve our website via analytics (legal basis: legitimate interests)
4. Third Parties
We share data with: Shopify Inc. (e-commerce platform), Stripe (payment processing), Klaviyo (email marketing — only if you opt in), Google Analytics (website analytics, anonymised). We do not sell your data.
5. Cookies
We use essential cookies (required for checkout), analytics cookies (Google Analytics — opt-in via cookie banner), and marketing cookies (only with your consent).
6. Your Rights Under UK GDPR
You have the right to: access your data, rectification, erasure ("right to be forgotten"), data portability, object to processing, and withdraw consent at any time. Contact elvarafit@gmail.com to exercise any right. You may also lodge a complaint with the ICO (ico.org.uk).
7. Data Retention
Order data is retained for 7 years for legal and tax purposes. Marketing data is retained until you unsubscribe. Technical/analytics data is retained for 26 months.
8. Security
All data is transmitted over SSL/TLS encryption. Access to personal data is restricted to authorised personnel only.
9. Children
Our services are intended for users aged 18 and over. We do not knowingly collect data from children.
10. Changes to This Policy
We will notify you of material changes by email. The latest version is always available at www.elvarafit.com/policies/privacy-policy.