This Privacy Policy describes how plainvelvetribbon (referred to herein as “we”, “us”, or “our”) collects, uses, processes, and protects your personal data when you visit plainvelvetribbon.com (the “Site”) or make a purchase from us.
We operate in compliance with the Federal Laws of the United Arab Emirates, the General Data Protection Regulation (GDPR) for individuals within Europe, and applicable state privacy frameworks within the United States (including CCPA/CPRA where applicable).
1. Data Controller
For the purposes of applicable data protection legislation, the data controller responsible for your personal information is:
• Brand Name: plainvelvetribbon
• Registered Office: Office 402, Building A1, Digital Park, Silicon Oasis, Dubai, United Arab Emirates
• Commercial Registration Number: FZCO-84291
• Contact Email: solid@plainvelvetribbon.com
2. Information We Collect
We collect specific personal data necessary to fulfil your orders, secure our platform, and manage our commercial interaction with you. This includes:
• Identity and Contact Data: Your name, billing address, delivery address, email address, and telephone number.
• Transaction Data: Specifics regarding the single-colour ribbon products you have purchased from us.
• Technical and Usage Data: Internet protocol (IP) address, browser type, operating system, and device identifiers collected automatically when navigating our Site to ensure secure and optimal website performance.
3. Third-Party Payment Processing
To process financial transactions efficiently and securely, we utilise specialised third-party infrastructure.
• Payment Processor: All payment processing services on our Site are supplied and managed directly by Stripe.
• Data Handling by Processor: When you execute a transaction, your payment details (such as credit card numbers) are provided directly to Stripe. We do not store, access, or retain your full financial credentials within our systems.
• Processor Terms: Stripe processes your personal and financial information in accordance with their own strict corporate privacy frameworks and international financial regulations.
4. How We Use Your Data
We process your personal information under established legal bases, including:
• Performance of a Contract: To process, package, and fulfil your orders, and to communicate updates regarding your delivery.
• Legal Compliance: To maintain precise accounting registers and comply with statutory financial obligations in the United Arab Emirates, Europe, and the United States.
• Legitimate Interests: To detect, prevent, and mitigate fraudulent activity or security vulnerabilities on our Site.
5. Data Retention Period
We retain personal data only for as long as necessary to achieve the objectives outlined in this policy, or as mandated by international law.
• Order and Transaction Information: Data associated with your purchases is retained for a standard duration of seven (7) years following the date of the transaction. This duration is strictly required to comply with statutory taxation, accounting, and anti-financial crime obligations across our designated markets in Europe, the United States, and the United Arab Emirates.
• General Correspondence: Queries submitted via email or our message facility are retained for up to two (2) years from the date of final resolution to ensure consistent client communication.
6. Data Security
We employ appropriate administrative, operational, and physical measures designed to mitigate risks of unauthorized access, alteration, or disclosure of your personal data. Please note that while we maintain robust protocols to protect your information, no digital transmission over the internet or storage infrastructure can be characterized as entirely impenetrable.
7. Your Statutory Rights
Depending on your geographical location (including rights granted under the GDPR to European residents and statutory provisions within the United States), you possess specific rights regarding your personal data:
• The right to request access to the personal data we hold.
• The right to request the rectification of inaccurate or incomplete information.
• The right to request the erasure of your data, subject to our statutory retention requirements noted in Section 5.
• The right to withdraw consent at any time where we rely on your consent to process data.
To exercise any of these rights, please submit a formal written request to our dedicated email address: solid@plainvelvetribbon.com.
