Last updated: 10/07/2026
This Privacy Policy explains how bearlee (“bearlee,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal data when you visit our website, create an account, or make a purchase (collectively, the “Services”).
We are a small, EU-based business selling apparel online to customers worldwide. This policy is designed to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR, and to reflect good-practice standards recognized in other jurisdictions, including the U.S. California Consumer Privacy Act (CCPA/CPRA).
Who we are (data controller)
For the purposes of GDPR, bearlee is the “data controller” of the personal data described in this policy.
Supervisory authority: If you are in the EU/EEA, you have the right to lodge a complaint with the data protection authority of Greece, or your own country’s supervisory authority.
What personal data we collect
a) Data you give us directly
- Name, email address, billing and shipping address, phone number (order and account data)
- Payment information — note: we do not store full card details ourselves; payment is processed by our payment gateway (see Section 6)
- Order history and purchase preferences
- Any information you submit via contact forms, customer support requests, or newsletter sign-up
- If product reviews are enabled: your name, email address, and the content of your review
b) Data collected automatically
- IP address, browser type and user-agent string, device type, operating system
- Pages visited, time spent on site, referring/exit pages, clickstream data
- Cookies and similar tracking technologies (see Section 5)
c) Data from third parties
- Delivery status updates from shipping carriers
- Aggregated or event data from advertising platforms (e.g., ad interactions) when you arrive at our site via an ad
- An anonymized hash of your email address may be shared with the Gravatar service (operated by Automattic) if you leave a comment or review, to check whether you have a Gravatar profile picture
We do not knowingly collect any special category data (e.g., health, religion, sexual orientation) and ask that you not submit such information to us.
How we use your data
We use personal data for the following purposes and legal bases (GDPR Art. 6):
| Purpose | Legal basis |
|---|---|
| Processing and fulfilling orders, payments, returns | Performance of a contract |
| Customer service and order-related communication | Performance of a contract / legitimate interest |
| Account creation and management | Performance of a contract |
| Marketing emails (newsletters, offers, product drops) | Consent |
| Site analytics and performance monitoring (Google Analytics) | Consent |
| Advertising and retargeting (Meta/Instagram Pixel) | Consent |
| Spam and fraud prevention (e.g., comment/review spam filtering) | Legitimate interest |
| Compliance with legal/tax/accounting obligations | Legal obligation |
Where we rely on consent (marketing emails, analytics, advertising cookies), you may withdraw that consent at any time — see Section 8.
Marketing emails
If you sign up for our newsletter, we will send you occasional emails about new drops, offers, and brand news. We do not send marketing emails without your opt-in consent. Every marketing email includes an unsubscribe link, and you can opt out at any time without affecting your ability to place orders.
We currently use — or plan to use — a third-party email marketing platform to manage this. That provider acts as a data processor on our behalf.
Cookies and tracking technologies
We use cookies and similar technologies for:
- Essential/functional cookies — required for the store to work: cart and session cookies, and (if you have an account) login cookies. Login cookies typically last 2 days (14 days if “Remember Me” is selected); these do not require consent as they are strictly necessary.
- Comment/review cookies — if you leave a product review while logged out, you may be offered the option to save your name, email, and website in a cookie for convenience on future visits. These last around one year and are optional.
- Analytics cookies — Google Analytics, used to understand site traffic and usage patterns.
- Advertising cookies — Meta/Instagram Pixel, used to measure ad performance and show relevant ads on Meta platforms.
Analytics and advertising cookies are non-essential and, for EU/UK visitors, will only be activated after you provide consent via our cookie banner. You can change your preferences at any time [via the cookie settings link in the site footer].
Who we share data with
We share personal data with the following categories of third-party processors, strictly to operate the Services:
- Hostinger — website hosting and infrastructure
- WooCommerce (Automattic / WooCommerce.com) — e-commerce plugin infrastructure and any official WooCommerce extensions in use
- WooCommerce Payemnts — payment processing
- Automattic (Akismet) — if enabled, automated spam detection for comments/reviews
- Automattic (Gravatar) — if comments/reviews are enabled, avatar lookup by email hash
- Google LLC — Google Analytics (website analytics)
- Meta Platforms, Inc. — Meta/Instagram Pixel (advertising and retargeting)
- Shipping carriers and fulfillment partners — order delivery
- Professional advisors (accountants, lawyers) where necessary
- Law enforcement or regulators, where required by law
If you request a password reset, your IP address will be included in the reset email for security purposes.
We do not sell personal data for money. Under U.S. state laws (e.g., CCPA/CPRA), the use of advertising cookies like the Meta Pixel may be interpreted broadly as a “share” of personal data for cross-context behavioral advertising. See Section 9 for California-specific rights and opt-outs.
We require all processors to handle personal data under written data processing agreements consistent with GDPR Article 28.
International data transfers
Because we sell worldwide and use providers such as Google, Meta, and Automattic (all U.S.-based), personal data may be transferred outside the EU/EEA. Where this happens, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses (SCCs) or an equivalent adequacy mechanism, as implemented by our processors.
Your rights
If you are in the EU/UK, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion (“right to be forgotten”)
- Restrict or object to processing
- Data portability
- Withdraw consent at any time (without affecting prior lawful processing)
- Lodge a complaint with your local data protection authority
To exercise any of these rights, contact us at [privacy email]. We will respond within one month as required by GDPR. If you have a registered account, you can also use WordPress/WooCommerce’s built-in tools to request an export or erasure of your personal data directly.
If you are in California, see Section 9 below.
All other visitors: we apply the same rights described above to all users of our site, regardless of location, as a matter of good practice.
California privacy rights (CCPA/CPRA)
Depending on our size and data volume, California’s privacy law (CCPA/CPRA) may apply to us. As a matter of good practice, California residents have the right to:
- Know what personal information we collect, use, and disclose
- Request deletion of personal information
- Correct inaccurate personal information
- Opt out of the “sale” or “sharing” of personal information (which may include advertising cookies like the Meta Pixel)
- Non-discrimination for exercising these rights
To opt out of data sharing for advertising purposes, use the cookie preference link in the footer / contact us at privacy email.
Data retention
We retain personal data only as long as necessary for the purposes described in this policy:
- Order and transaction data: retained for the period required by tax and accounting law (typically 6–10 years depending on jurisdiction)
- Account data: retained while your account is active, plus a reasonable period after. You can view, edit, or delete most of your personal information from your account at any time (except your username)
- Comments/reviews: if enabled, retained indefinitely so we can recognize approved return commenters and reduce moderation queue friction
- Marketing data: retained until you unsubscribe or withdraw consent
- Analytics data: retained per Google Analytics’ default retention settings, or a shorter period we configure
Children’s privacy
Our Services are not directed at children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
Security
We use reasonable technical and organizational measures to protect personal data. Payment card data is handled directly by our payment gateway (e.g., Stripe/PayPal), which is responsible for PCI-DSS compliance; we do not store full card numbers on our own servers. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top reflects the most recent revision. Material changes will be communicated via the website or email where appropriate.
Contact us
For any privacy questions or to exercise your rights:
Email: co*****@*****ee.shop
