1. Data Controller
The data controller responsible for processing your personal data on this website is:
Judge My Cover, Vienna, Austria
Email: hello@judgemycover.com
2. Data We Collect
We collect the following categories of personal data:
- Order information: Name, email address, shipping address, and payment details (processed by Stripe — we never store your card number).
- Account data: Email, name, and profile picture if you create an account.
- Usage data: Pages visited, browser type, device information, and IP address (anonymized).
- Communication data: Any information you provide when contacting us or subscribing to our newsletter.
3. Purpose of Processing
We process your data for the following purposes:
- Fulfilling and shipping your orders (Art. 6(1)(b) GDPR — contract performance).
- Sending order confirmations and shipping notifications (Art. 6(1)(b) GDPR).
- Sending our newsletter, if you opted in (Art. 6(1)(a) GDPR — consent).
- Improving our website and services (Art. 6(1)(f) GDPR — legitimate interest).
- Complying with legal obligations, e.g. tax records (Art. 6(1)(c) GDPR).
4. Payment Processing
Payments are processed by Stripe, Inc. We never receive or store your full credit card details. Stripe's privacy policy can be found at stripe.com/privacy.
5. Cookies
We use the following cookies:
- Essential cookies: Session management and cart functionality. These are strictly necessary and do not require consent.
- Analytics cookies: Only set if you give consent via our cookie banner. Used to understand how visitors use our site.
6. Data Sharing
We share your data only with:
- Stripe — for payment processing.
- Shipping carriers — name and address for order delivery.
- Resend — for transactional emails (order confirmations, shipping updates).
- Vercel — website hosting and infrastructure.
7. Data Retention
Order data is retained for the duration required by tax law (typically 6–10 years). Account data is kept until you delete your account. Newsletter subscriptions are kept until you unsubscribe.
8. Your Rights
Under GDPR, you have the right to:
- Access your personal data (Art. 15 GDPR).
- Rectify inaccurate data (Art. 16 GDPR).
- Request deletion of your data (Art. 17 GDPR).
- Restrict processing (Art. 18 GDPR).
- Data portability (Art. 20 GDPR).
- Object to processing (Art. 21 GDPR).
- Withdraw consent at any time (Art. 7(3) GDPR).
9. Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority if you believe your data is being processed unlawfully.
10. Security
We use industry-standard encryption (TLS/SSL) for all data transmission. Payment data is handled exclusively by Stripe's PCI-DSS compliant infrastructure.