Privacy Policy
Last updated 16 April 2026
This Privacy Policy describes how Posa ("we", "us", "our") collects, uses and protects the personal data of visitors to byposa.com ("the Site") and customers who purchase through it. We take privacy seriously and comply with the EU General Data Protection Regulation (GDPR) and applicable national data-protection laws.
Who we are
The data controller for personal data collected through the Site is Posa. You can contact us at email@byposa.com.
What we collect
We collect the minimum personal data needed to operate the Site and fulfil orders:
- Order data — name, shipping address, billing address, email, phone number, items purchased, order total. Collected when you place an order.
- Payment data — handled by our payment processors (Shopify Payments, PayPal, Apple Pay, Shop Pay). We do not see or store full card numbers.
- Communication data — if you email us or submit the contact form, we store the message and your reply address.
- Technical data — IP address, device type, browser, timestamps, pages visited. Collected via cookies and analytics (see below).
- Marketing data — if you consent, we store your email for newsletters and offers; you can unsubscribe at any time.
Why we collect it (legal basis)
- Contract — to process your order, ship the product, handle returns, and provide customer support.
- Legal obligation — to comply with tax, accounting, and consumer-protection rules.
- Legitimate interest — to secure the Site against fraud and abuse, to understand how visitors use the Site, and to improve the product.
- Consent — for marketing emails and non-essential cookies. You can withdraw consent at any time.
Who we share it with
We use these processors to run the store. Each has its own privacy terms and handles data on our instructions:
- Shopify Inc. — platform, hosting, checkout, order management (privacy policy).
- Payment processors (Shopify Payments, PayPal, Apple Pay, Shop Pay) — processing card transactions.
- Shipping carriers — to deliver your order. They receive your name, address and phone number.
- Email providers — for transactional email (order confirmation, shipping updates) and, with consent, marketing.
- Analytics providers — aggregated traffic data. Where possible we use IP-anonymising or privacy-forward configurations.
We do not sell personal data.
International transfers
Some processors (notably Shopify and payment providers) may transfer personal data outside the European Economic Area. When this happens we rely on the European Commission's Standard Contractual Clauses or equivalent safeguards to protect your data.
How long we keep it
- Order and invoice data — 10 years (required by tax and accounting law in most EU countries).
- Customer account data — while your account is active, or until you ask us to delete it.
- Marketing data — until you unsubscribe or ask us to remove you.
- Contact-form messages — up to 2 years, then deleted.
- Analytics data — retained in aggregated form per the analytics provider's policy.
Cookies
We use cookies that are strictly necessary to operate the Site (e.g. cart state, fraud prevention). These are set automatically. With your consent, we also use analytics and marketing cookies to understand visits and measure campaigns. You can manage cookie preferences through the consent banner or in your browser settings.
Your rights
Under GDPR you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Request deletion of your data (subject to retention obligations).
- Restrict or object to processing.
- Data portability — receive a copy in a machine-readable format.
- Withdraw consent at any time (for consent-based processing).
- Lodge a complaint with your national supervisory authority.
To exercise these rights, email email@byposa.com. We will respond within 30 days.
Security
We use industry-standard measures — TLS encryption for all Site traffic, access controls on admin tools, and vetted processors — to protect personal data. No system is fully secure; if we ever detect a breach that risks your rights, we will notify you and the relevant authority as the law requires.
Children
The Site is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has given us data, contact us and we will delete it.
Changes to this policy
We may update this policy to reflect changes in law or our operations. The "Last updated" date at the top shows when it last changed. Significant changes will be announced on the Site or by email where appropriate.
Contact
For any question about this policy or your personal data: email@byposa.com.