Before launch: replace the bracketed business details below and review this policy against the plugins, payment providers, analytics and marketing tools you actually use.
1. Who we are
Nestory is operated by [LEGAL COMPANY NAME], registration number [REGISTRATION NUMBER], registered address [REGISTERED ADDRESS]. For privacy questions, contact [PRIVACY EMAIL].
2. Information we collect
Depending on how you use the website, we may process identification and contact details, billing and delivery information, order and transaction information, customer-service correspondence, account information, technical device and log data, cookie or similar identifier data, and marketing preferences.
3. Why we use your information
- To process orders, payments, deliveries, returns and refunds.
- To provide customer support and respond to enquiries.
- To operate customer accounts and maintain the security and reliability of the website.
- To meet accounting, tax, consumer-protection and other legal obligations.
- Where permitted, to measure and improve our website and marketing.
- To send marketing communications when you have consented or where another lawful basis applies.
4. Legal bases
We process personal data where it is necessary to perform a contract with you, comply with legal obligations, pursue legitimate interests that do not override your rights, or where you have given consent. The applicable basis depends on the purpose and the data involved.
5. Who receives your information
We may share data with service providers that help us operate the store, such as hosting providers, payment processors, fraud-prevention services, delivery carriers, fulfilment and dropshipping partners, email providers, customer-support tools, accountants and professional advisers. They receive only the information needed for their role and are expected to handle it appropriately.
Because some Nestory products may be fulfilled by third-party European partners, order details necessary to fulfil and deliver an order may be shared with the relevant supplier or logistics provider.
6. International transfers
If a service provider processes personal data outside the European Economic Area, we use an appropriate transfer mechanism where required, such as an adequacy decision or approved contractual safeguards.
7. How long we keep information
We keep personal data only as long as necessary for the purposes described above and for applicable legal, tax, accounting, warranty and dispute-resolution periods. Contact enquiries that do not relate to an order are deleted when they are no longer needed, subject to any legitimate record-keeping requirement.
8. Your rights
Subject to applicable data-protection law, you may have rights to access, correct, erase or restrict your personal data, object to certain processing, request data portability, and withdraw consent at any time where processing is based on consent. You may also lodge a complaint with the competent data-protection authority.
9. Cookies
We use strictly necessary technologies to operate the site and may use optional analytics or marketing technologies if enabled and permitted. A cookie banner or preference tool should describe optional cookies before they are set where required.
10. Contact form
Messages sent through our contact form are emailed to our administration address and stored in the protected WordPress administration area so our team can manage enquiries. The form records the information you submit and the time consent was recorded.
11. Changes to this policy
We may update this policy when our services, providers or legal obligations change. The current version will always be published on this page.