Home » Privacy Policy
Privacy Policy
Contents
- Who we are
- Scope
- How we collect data
- Personal data we process
- Purposes and legal bases
- Cookies and similar technologies
- How we share data
- International transfers
- Retention
- Your rights
- Marketing choices
- Children
- Security
- Automated decision-making
- Changes to this policy
- Contact
- Annex A: Key processors
- Annex B: Definitions
Who we are
Controller: Vintage Visual OÜ, trading as “Vintage Visual” Registered address: Vahi, Purila küla, Raplamaa, ESTONIA 79661 Email: info@vintagevisual.euScope
This policy covers personal data processed through our websites, and related customer support, sales, and marketing. It does not apply to third-party services we do not control.How we collect data
- Directly from you: account registration, checkout, support, forms, email, phone.
- Automatically: via cookies, pixels, SDKs, and logs when you use our sites.
- From third parties: payment providers, logistics partners, analytics and advertising partners, anti-fraud tools, and social platforms where you interact with us.
Personal data we process
- Identity and contact: name, email, phone, billing and shipping address, company, VAT.
- Account: login, roles, preferences, communication choices.
- Order and warranty: products, serial numbers, delivery details, invoices, returns.
- Payment: payment method, status, and limited details. We do not store full card numbers.
- Usage and device: IP address, identifiers, device/app info, pages viewed, actions, error logs.
- Marketing and communications: newsletter status, consent records, campaign interactions.
- Support: messages, attachments, repair and service notes.
Purposes and legal bases
We process personal data only when a legal basis applies. Where we rely on legitimate interests, we perform and document a balancing test.Purpose | Examples | Data | Legal basis |
---|---|---|---|
Operate sites | Load pages, keep sessions, remember settings | Usage, device, necessary cookies | Legitimate interests; necessary for service |
Create and manage accounts | Registration, authentication, preferences | Identity, contact, account | Contract or steps prior to contract |
Process orders and deliver products | Cart, checkout, payments, shipping, returns, warranty | Identity, contact, order, payment | Contract; legal obligation for tax/accounting |
Customer support | Answer requests, troubleshooting, repairs | Identity, contact, support | Contract; legitimate interests |
Security and fraud prevention | Detect abuse, protect accounts, rate-limit | Usage, device, logs | Legitimate interests; legal obligation where applicable |
Analytics and improvement | Measure usage, fix bugs, plan capacity | Usage, device, analytics cookies/SDKs | Consent for non-essential cookies/SDKs; limited aggregated metrics under legitimate interests where permitted |
Marketing | Newsletters, product updates, offers | Identity, contact, marketing interactions | Consent (withdraw anytime) |
Abandoned cart reminders | Single reminder limited to pending order | Identity, contact, cart contents | Legitimate interests with easy opt-out; if broader promotions are included, we rely on consent |
B2B outreach | Distribution and sales emails to business contacts | Work contact details | Legitimate interests with opt-out |
Legal compliance | Tax, accounting, regulatory requests | Order, payment, identity | Legal obligation |
Business operations | Mergers, acquisitions, audits | Relevant data as needed | Legitimate interests |
Cookies and similar technologies
We use cookies, pixels, and SDKs.- Strictly necessary: cart, checkout, security. Always on.
- Functional: preferences.
- Analytics: performance and usage. Requires consent.
- Advertising/remarketing: ads and measurement. Requires consent.
How we share data
- Service providers: hosting, payments, logistics, email delivery, customer support, analytics, advertising, anti-fraud, IT security. Bound by contracts and confidentiality.
- Business partners: distributors and resellers to fulfill purchases or warranty.
- Authorities: when required by law.
- Business transfers: if we are involved in a merger, sale, or reorganization, data may transfer under this policy.
International transfers
If data is transferred outside the EEA/UK, we use legal safeguards such as European Commission Standard Contractual Clauses, the UK Addendum, or adequacy decisions, and apply supplementary measures where needed.Retention
We keep data only as long as needed for the stated purposes or legal duties, then delete or anonymize it.Data category | Typical retention |
---|---|
Account data | For the life of the account and up to 24 months after last activity, unless you request deletion |
Orders, invoices, warranty | Warranty term and statutory tax/accounting periods |
Customer support records | Up to 36 months after case closure, unless needed for legal claims |
Marketing consent records | While subscribed and 24 months after withdrawal to demonstrate compliance |
Analytics data | Configured in the analytics tool, typically 14–26 months, or sooner if consent is withdrawn |
Security logs | 12 months, longer if needed to investigate incidents |
Your rights
Subject to law, you can:- Access your data
- Correct inaccurate data
- Erase data
- Restrict processing
- Object to processing based on legitimate interests or to direct marketing
- Withdraw consent at any time
- Port your data
- Lodge a complaint with a supervisory authority
Marketing choices
- Email marketing: sent only with consent. Unsubscribe using the link in each email or by contacting us.
- Abandoned cart: we may send a single reminder limited to your pending order under legitimate interests. Each message includes an opt-out. If we include broader promotions, we rely on consent.
- B2B messages: you can object at any time.
Children
Our services are not directed to children under 16. We do not knowingly collect their data. If you believe a child provided data, contact us to delete it.Security
We apply technical and organizational measures including encryption in transit, access controls, least-privilege, secure development practices, backups, and vendor due diligence. No system is perfectly secure.Automated decision-making
We do not use automated decision-making that produces legal or similarly significant effects without human review.Changes to this policy
We will update this policy when needed.Contact
Data controller: Vintage Visual OÜ Email: support@vintagevisual.eu Postal address: Tatari 64-301, Tallinn 10134, Estonia You can also complain to your local supervisory authority. If our main establishment is in Estonia, the authority is the Estonian Data Protection Inspectorate.Annex A: Key processors
We use processors to deliver services. They process data only under our instructions and are bound by contracts and confidentiality.- Cloud hosting and CDN: infrastructure and content delivery. Region: EU with global CDN. Safeguard: SCCs or adequacy.
- Payment processor: payments and fraud prevention. Region: EU/US. Safeguard: SCCs.
- Email delivery and marketing: transactional email and newsletters. Region: EU/US. Safeguard: SCCs.
- Analytics platform: site analytics. Region: EU/US. Safeguard: SCCs.
- Logistics and repair partners: shipping, returns, and service. Region: EU.
Annex B: Definitions
Personal data is any information about an identified or identifiable person. Processing is any operation on personal data. Other terms follow Article 4 GDPR.Our privacy commitment (last updated 23.02.2024)
How do we collect data about you?
We collect personal information when you purchase a product; subscribe to our newsletter; receive customer or technical support or via website cookies.
Vintage Visual collects your personal data in one of two possible ways:
- directly from you in cases where Vintage Visual is providing a service to you directly by website or App;
What information we collect about you and how do we use it?
Types of Information We Collect
Personal information means information that can be used to identify and contact you. You do not need to submit personal information to access the Service generally. However, you may be required to submit personal information to access certain aspects of the Service or when you purchase a product in online store.
The types of personal data we may collect from you include your name, email address, billing address, phone number, and credit card type, or other payment information. We may also collect non-personal information such as your mobile device type, when you accessed the Service, and from what location you access the Service.
Third-party privacy policies
Through the Service, you may be able to access technology, software and services owned and controlled by third parties (“ Third-Party Features ”) by clicking on a third-party logo or URL displayed via the Service.
Third-Party Features may collect information about you when you communicate with them. Such use of Third-Party Features and submission of information through Third-Party Features will be subject to applicable third party’s terms of use, terms of service, and privacy policy. In this case, our Privacy Policy and Terms of Use no longer apply. You agree to approach only the relevant third party and not Vintage Visual to enforce your rights in relation to your personal information.
How do we use your personal information?
The personal information you provide to us will allow us to communicate with you and provide the Service to you. This includes package delivery; processing orders; handling your customer service questions or issues; alerting you of new products, services, features, or enhancements to the Service; verifying your identity; requesting feedback, and distributing newsletters.
We may also use your email address as part of the Service in sending you messages about the Service and other general announcements. We keep track of your interactions with us, including but not limited to your activity within the Service. If it is not stated in this Privacy Policy or if we do not have your consent, we will not share your personal information with any person or entity other than entities acting on our behalf, and relevant third parties such as those needed to collect and maintain our servers and perform technology and related services.
Before we use your personal information for a purpose that is substantially different than the purpose we collected it for or that you later authorized, we will provide you with the opportunity to opt-out. In such a case we will notify you about those activities and offer to opt-out via email.
We may use anonymized data about your orders and use of Services for Analytical purposes (the “ Analytical Data ”), for example, to measure the number of visits, average time spent, page views, and other statistics about users of the Service. We also may use this data to monitor the Service’s performance and to make the Service easier and more convenient to use.
Log information
Our servers automatically record information that your device sends whenever you use the Service. This information includes, among other things, your Internet Protocol (IP) address and device type, which aspects of the Service you use, and from where, and when, and how long you use them. We use this information to monitor and analyze how users use the Service, to provide customer service, and to maintain and improve the Service. We may also collect similar information from emails we may send to you: these help us to track which emails are opened and which links are clicked by recipients. This information allows for more accurate reporting and improvement of the Service. Logs may also be monitored for unauthorized activities.
Will we share your information with thrid parties?
Sharing Your Information
The personal information we have gathered about you will be shared only with authorized persons under the following circumstances:
- Service Providers. We share your personal information with service providers that we engage to process information on our and your behalf. Additionally, we may partner with other companies to process, analyze, and/or store data, including, but not limited to, Analytical Data. While providing services for us, these companies may access your personal information.
- Protection of Rights. We will share personal information if we have a good faith belief that (i) access, use, preservation or disclosure of such information is reasonably necessary to satisfy any applicable law, legal processes, such as a court order, or a request by law enforcement or governmental authorities; (ii) such action is appropriate to enforce our Terms of Use for the Service (where applicable), including any investigation of potential violations thereof; (iii) such action is necessary to detect, prevent, or otherwise deal with fraud, security or technical issues associated with the Service; or (iv) such action is appropriate to protect the rights, property or safety of Vintage Visual, its employees, users of the Service or others.
- Asset Transfers. If we become involved in a merger, acquisition, or other transaction involving the transfer of some or all of Vintage Visuals assets, the information collected from you could be included in the transferred assets. Should such an event occur, we will use reasonable means to notify you through email and/or a prominent notice displayed via the App.
Where we do share your information with third parties, we will require such third parties to comply with this Privacy Policy and maintain appropriate security to protect your information from unauthorized access or processing, unless we cannot do so (for example, where we are sharing information with regulatory authorities or courts). Where applicable, we will enter into written agreements with such third parties.
How can you control your information?
You may update or request rectification or deletion of your personal information stored by Vintage Visual by writing to us at info@vintagevisual.eu . We may request specific information from you to confirm your identity. In some circumstances we may charge a reasonable fee for access to your information.
If you no longer want to receive our newsletter, emails, or other announcements, you may unsubscribe by writing to us at info@vintagevisual.eu or following the “unsubscribe” link at the bottom of our emails. Please note that you cannot unsubscribe from certain correspondence from us, including messages relating directly to your account.
You agree that in the event any dispute or claim arises out of or relating to this Privacy Policy, you and Vintage Visual will attempt in good faith to negotiate a written resolution of the matter directly between the parties. You agree that if the matter remains unresolved for forty-five (45) days after notification (via certified mail or personal delivery) that a dispute exists, all parties shall join in mediation services in Tallinn, Estonia, with a mutually agreed mediator in an attempt to resolve the dispute. Should you file any arbitration claims, or any administrative or legal actions without first having attempted to resolve the matter by mediation, then you agree that you will not be entitled to recover attorneys’ fees, even if you would otherwise be entitled to them.
Data Protection Officer – Questions or Complaints
Vintage Visual Lighting has appointed a Data Protection Officer (“ DPO ”) to mediate any questions or complaints you may have and also to facilitate the usage of data subject rights under the GDPR. You can contact the DPO by writing to us at info@vintagevisual.eu .
You can direct any questions or complaints about the use or disclosure of your personal data to us at info@vintagevisual.eu. We will investigate and attempt to resolve any complaints or disputes regarding the use or disclosure of your personal data within
(30) days of receiving your complaint.
NOTIFICATION OF CHANGES
This Privacy Policy may change from time to time and we will post all changes here.