Privacy policy
Last updated: 2 September 2026
Varusteleka Oy processes personal data in running its online store, its retail store and its customer service. This notice explains what data we process, for what purposes and on what legal basis, how long we keep it, and what rights you have. It is written to meet the requirements of the EU General Data Protection Regulation (2016/679).
If you want to limit how your data is used, you can do so in the cookie settings at the bottom of the page and by contacting info@varusteleka.com.
Contents
-
General
-
Controller and contact details
-
What data we process and where it comes from
-
What we use the data for, and on what basis
-
How we protect your data
-
How long we keep your data
-
Who we disclose data to
-
Do we transfer data outside the EU and EEA
-
Cookies and other tracking
-
Profiling and customer segmentation
-
Your rights
-
How you can influence the use of your data
-
Rights of California residents
-
Changes to this notice
1. General
In this notice, "customer" means a natural person who uses our services: browses or orders from our online store at varusteleka.com, visits our retail store in Konala, or contacts our customer service.
Scope of this notice. This notice covers the online store, the retail store and customer service.
The data we process falls into three groups:
-
data you give us yourself (for example when placing an order)
-
data generated by your use of the service (for example order history and browsing data)
-
data derived through analytics (for example product recommendations)
We process only the data each purpose requires. What you do in our service affects what data we process about you.
2. Controller and contact details
The controller is:
Varusteleka Oy Business ID 2082907-8 Hankasuontie 11 A, 00390 Helsinki, Finland
Questions and requests concerning privacy and the processing of personal data: info@varusteleka.com
Our online store runs on the Shopify platform. Shopify processes personal data on our behalf in order to provide the service, and in part for its own purposes in accordance with its own privacy policy. To the extent Shopify processes data for its own purposes, it is responsible for that processing and for related requests under its own privacy policy.
3. What data we process and where it comes from
When you create a customer account
Name, email address and phone number. If you sign in using a third-party authentication service, we also process the email address and token used for that sign-in.
When you place an order
Delivery and billing address, chosen delivery method, chosen payment method and the payment transaction identifier, the products ordered with their prices, the order date, and communication relating to the order. We do not store payment card numbers in our own systems; the payment transaction is handled by the payment service provider.
For orders delivered outside the EEA we also process the information required for customs clearance.
Invoice and instalment payment methods
If you choose invoice or instalment payment, the provider of that payment method may request your personal identity code in order to run a credit check. The check is performed by the payment service provider, which acts as an independent controller for that part under its own privacy notice. You will see that notice when selecting the payment method.
We do not store personal identity codes in our customer database.
Data you give us for marketing
If you subscribe to our newsletter, we process your email address and language choice. If you subscribe to SMS marketing, we process your phone number for that purpose.
A phone number given for marketing is not the same as one given when placing an order: the order number is used to handle the delivery, and we do not send marketing to it without separate permission. Email and SMS marketing consents are separate. Subscribing to one does not subscribe you to the other, and you can cancel one without affecting the other.
Data generated by use of the service
Browsing and usage data from the online store, shopping cart events, device identifiers and IP address, and data collected via cookies. Your cookie settings govern the collection of this data.
Other contexts
Customer service communication (email and chat), product reviews, wishlist items, back-in-stock notification requests, loyalty programme events, and survey responses when you take part in a survey.
Special categories of personal data
We do not collect or process special categories of personal data, such as data concerning health, beliefs or trade union membership.
Sources of data
The primary source is you. Some data is generated by your use of the service, and some is derived through analytics. We may also receive data from the invoice and instalment payment provider in connection with processing that payment method.
4. What we use the data for, and on what basis
We process data to perform a contract, to comply with legal obligations, on the basis of your consent, or on the basis of our legitimate interest. The basis varies by purpose, and the tables below state it purpose by purpose.
Online store and orders
|
Purpose |
Data categories |
Legal basis |
|
Creating and maintaining a customer account |
Name, email, phone number, account settings |
Contract |
|
Sign-in and authentication |
Account data, sign-in events |
Contract |
|
Processing and delivering orders |
Contact, delivery, payment and order data |
Contract; legal obligation as regards accounting |
|
Order and delivery confirmations and other order-related communication |
Email, phone number, order data |
Contract |
|
Returns, exchanges and cancellations |
Contact, order and return data |
Contract |
|
Warranty and repair cases |
Contact, order and product data |
Contract; legitimate interest as regards product liability |
|
Wishlist and back-in-stock notifications |
Email, selected products |
Contract |
|
Product reviews |
Nickname, review content |
Consent |
|
Credit check for invoice and instalment payment |
Data is passed to the payment provider, which acts as an independent controller for that part |
Contract (payment method chosen by you) |
|
Customs clearance and export |
Recipient details, data required for customs |
Legal obligation |
|
Retail store sales and pickups |
Contact data, purchase transaction |
Contract |
Customer service
|
Purpose |
Data categories |
Legal basis |
|
Customer service by email and chat |
Contact data, message content, order data |
Legitimate interest (managing the customer relationship) |
|
Product safety notices and recalls |
Email, order data |
Legal obligation (General Product Safety Regulation (EU) 2023/988) |
|
Handling data subject requests |
Contact data, content of the request |
Legal obligation |
Marketing
|
Purpose |
Data categories |
Legal basis |
|
Newsletter (Finnish, English, German, Polish) |
Email, language choice, marketing permissions |
Consent |
|
SMS marketing |
Phone number, order data, marketing permissions |
Consent (separate from email consent) |
|
Personalising content and product recommendations |
Browsing and purchase data, derived interest data |
Consent |
|
Targeting advertising on other sites |
Browsing data, device identifiers |
Consent |
|
Loyalty programme |
Customer identifier, points, purchase history |
Contract (programme terms) |
Analytics and service development
|
Purpose |
Data categories |
Legal basis |
|
Website usage analytics |
Browsing and usage data, device identifiers |
Consent |
|
Customer segmentation and profiling |
Purchase history, interest data, browsing data |
Legitimate interest; consent as regards browsing data |
|
Business reporting and range development |
Pseudonymised order and sales data |
Legitimate interest |
|
Customer satisfaction and feedback surveys |
Email, responses |
Legitimate interest; responding is voluntary |
Security and prevention of misuse
|
Purpose |
Data categories |
Legal basis |
|
Website protection and bot mitigation |
IP address, request logs |
Legitimate interest |
|
Preventing misuse and fraud |
Order, payment and delivery data |
Legitimate interest; partly legal obligation |
|
Accounting and archiving of orders |
Order and payment data |
Legal obligation (Finnish Accounting Act 1336/1997) |
Where the basis is legitimate interest, we have weighed our interest against your rights and freedoms. You have the right to object to such processing (section 11).
5. How we protect your data
We only use service providers with whom we have concluded a data processing agreement. Where the location of a service can be configured, we have selected the EU region.
Our practical safeguards:
-
Multi-factor authentication on all administrative systems
-
Role-based access control, meaning each employee sees only the data their job requires
-
Pseudonymisation in analytics: direct identifiers are not transferred to our analytics and reporting environment; identifiers are replaced
-
Encrypted connections when data is transferred
-
Staff training and confidentiality obligations
-
Partner administrative access is limited on the same principles and bound by contract
-
A security incident process, under which we assess incidents and, where required, notify the supervisory authority and data subjects
6. How long we keep your data
We keep data for as long as it is needed for the purpose it was collected for, or as long as the law requires. If the same data is used for several purposes, the retention period is determined by the longest one.
Two rules govern the rest:
A customer account is removed after five years of inactivity. If an account is not signed in to for five years, we consider the customer relationship ended, and the account and the personal data linked to it are deleted or anonymised automatically.
Order data is kept for ten years. Product liability and warranty cases can arise after a long delay. If the customer account has been deleted or anonymised before that, the order remains in our systems without the data that would link it to you.
Online store and orders
|
Purpose |
Retention period |
|
Customer account |
For the duration of the customer relationship. The account is deleted or anonymised automatically if it is not signed in to for five years |
|
Order and delivery data |
10 years from processing of the order |
|
Accounting records |
6 years from the end of the financial year in which the order was processed |
|
Order-related communication (confirmations, delivery notices) |
12 months from sending |
|
Wishlist and back-in-stock notifications |
Until you remove them or the customer account is deleted |
|
Published product reviews |
Not deleted automatically. We remove a review at your request |
Customer service
|
Purpose |
Retention period |
|
Customer service communication and chat conversations |
5 years from the last contact |
Marketing
|
Purpose |
Retention period |
|
Newsletter subscriber data |
For as long as the consent is valid |
|
SMS marketing subscriber data |
For as long as the consent is valid |
|
Record of marketing opt-out (email and SMS) |
Under the five-year inactivity rule, so that the opt-out stays in force. The opt-out record has to be kept, because without it we cannot make sure we do not message you again. We delete it earlier if you request deletion of all your data |
|
Marketing profile and segments |
In line with the customer account retention period |
|
Loyalty programme events |
In line with the customer account retention period |
Analytics and security
|
Purpose |
Retention period |
|
Web analytics |
14 months |
|
Analytics and reporting environment |
Five full calendar years on a rolling basis, pseudonymised |
|
Data collected via cookies |
Per cookie. Exact durations are listed in the cookie settings |
|
Technical logging and bot mitigation |
Short-term |
7. Who we disclose data to
We disclose data only to the extent necessary to provide the service or where the law requires it. Our partners may use the data only for the agreed purpose.
Categories of recipients:
-
The online store platform on which the store runs
-
Our online store development partner, which has administrative access to the store in order to carry out development work
-
Marketing partners with limited access to the online store and the customer messaging platform in order to carry out marketing
-
Payment intermediaries and payment method providers, depending on the payment method you choose
-
Invoice and instalment payment providers, which perform the credit check and act as independent controllers for that part
-
Logistics partners and carriers for delivering orders
-
The customer service platform provider
-
Email marketing and customer messaging providers
-
An SMS service provider for sending marketing and service messages
-
The loyalty programme provider
-
Analytics and advertising partners, to the extent you have given cookie consent. The disclosure relies on cookies and similar identifiers
-
Cloud and analytics partners that maintain our reporting environment
-
Financial administration and debt collection partners
-
Authorities, where the law requires or permits it. We will also inform you of a data request where we are legally permitted to do so
If Varusteleka is sold or the business is otherwise reorganised, personal data may transfer to the new owner.
8. Do we transfer data outside the EU and EEA
Yes, in part. Some of the service providers we use are based in the United States or the United Kingdom, and their maintenance and support may take place from outside the EEA. Where the location of a service can be configured, we have selected the EU region, but that does not remove all transfers.
When data is transferred outside the EEA, the transfer relies on one of the following:
-
United Kingdom: the European Commission's adequacy decisions, renewed on 19 December 2025 and valid until 27 December 2031. An adequacy decision means no separate safeguard is required for the transfer.
-
United States: the EU-U.S. Data Privacy Framework where the provider is certified under it, or the standard contractual clauses approved by the European Commission together with any additional safeguards required.
-
Other countries: an adequacy decision by the Commission concerning the destination country, or standard contractual clauses with additional safeguards.
9. Cookies and other tracking
We use cookies and similar technologies, including browser local storage and server-side tracking. Cookies are small files used to recognise a browser and keep the service working.
We use a consent tool to manage cookies. Cookies other than strictly necessary ones are blocked until you accept them. You can change or withdraw your consent at any time in the cookie settings at the bottom of the page.
Cookies fall into four categories:
-
Necessary cookies enable basic site functions such as the shopping cart, sign-in and secure payment. These cannot be switched off, because the service does not work without them
-
Preferences cookies remember your choices, such as language and currency
-
Statistics cookies tell us how the site is used so that we can improve it
-
Marketing cookies enable the targeting of advertising and the measurement of it
This notice describes the purposes, legal bases and retention periods. The technical details of cookies, such as names, providers and durations, are available in the cookie settings and in the cookie declaration, which updates automatically.
10. Profiling and customer segmentation
We use profiling and customer segmentation so that we can recommend products that interest you and target our messaging sensibly. Here is what that means in practice.
What profiling and segmentation are
Profiling means the automated analysis of your data, producing an estimate of which products and content are likely to interest you.
Segmentation means grouping customers by shared characteristics or purchasing behaviour. The same customer can belong to several groups.
Profiling and segmentation do not lead to automated decision-making that would have legal effects concerning you or similarly significantly affect you. Nobody is denied service or given a different price on the basis of profiling.
What it is based on
The legal basis is legitimate interest: we want to understand our customer base so that we can recommend more relevant products and develop our range. To the extent profiling relies on browsing data or cookies, it also requires your cookie consent. If you do not give cookie consent, this data is neither collected nor used.
Receiving marketing communication always requires separate consent. You can receive our newsletter without profiling, in which case the content is not targeted to you.
What data is used
|
Data category |
Example |
|
Purchase history |
Products purchased, product categories, delivery and payment method |
|
Basic customer data |
Length of the customer relationship, country and language choice |
|
Interests |
Product category interests derived from purchase history |
|
Browsing data* |
Products and product listings viewed |
|
Marketing communication data** |
Opens and clicks |
|
Product reviews and survey responses |
Reviews and answers you have given |
* Requires cookie consent. ** Requires marketing consent.
We do not acquire data for profiling from third-party registers or other external sources. Nor do we disclose individual-level profile or segment data onwards.
How you can control it
You have the right to object to profiling and segmentation at any time (Article 21 of the GDPR). After you object, your data is no longer used for these purposes. You can continue to use the service normally, but content and recommendations will not be targeted to you.
You can separately prevent the collection of browsing data in the cookie settings.
11. Your rights
If you live in the EU or EEA, you have the following rights. They are not conditional, although in some situations the law limits how far we can act on them, and we will always tell you if something cannot be done.
-
Right of access. You can find out whether we process your data, and obtain a copy of the data we process.
-
Right to rectification. We correct inaccurate data and complete incomplete data.
-
Right to erasure. We delete your data when there is no longer a basis for processing it. We cannot delete data we are legally required to keep (for example accounting records) or that we need in order to handle a legal claim.
-
Right to object to processing based on legitimate interest, where you have grounds relating to your particular situation. You can object to direct marketing at any time and without giving a reason.
-
Right to restriction of processing in the situations set out in Article 18 of the GDPR.
-
Right to data portability in a machine-readable format, to the extent processing is based on consent or on a contract.
-
Right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before it.
How to exercise your rights
Send your request to info@varusteleka.com. Describe the request in enough detail for us to identify you and locate the right data. We may need to verify your identity before acting on the request.
We respond within one month. If the request is exceptionally broad, we may extend that period, and we will tell you if we do.
Exercising your rights is free of charge, and we will not treat you differently for exercising them.
Right to lodge a complaint
If you believe we are processing your data unlawfully, you can lodge a complaint with a supervisory authority. In Finland this is the Office of the Data Protection Ombudsman (tietosuoja.fi). We would also appreciate hearing about it directly, so that we can fix the mistake.
12. How you can influence the use of your data
-
Cookie settings at the bottom of the page: change or withdraw your cookie consent at any time
-
The unsubscribe link at the end of every marketing email
-
Stopping SMS marketing by replying STOP or the equivalent keyword given in the message. This stops text messages only, not email
-
Email info@varusteleka.com: access, correction, deletion, objection to profiling and other requests
Even if you withdraw your marketing permissions, we will still send messages relating to your orders, such as order confirmations and delivery notices. These are part of fulfilling the order and are not marketing.
13. Rights of California residents
This section applies only to residents of the State of California and supplements the other sections of this notice.
Under California privacy law (CCPA/CPRA) you have the right to:
-
know what personal information is collected about you, what it is used for and who it is disclosed to
-
have your information deleted
-
have inaccurate information corrected
-
opt out of the "sale" or "sharing" of your personal information for targeted advertising
-
not be discriminated against for exercising these rights
Sharing for targeted advertising. When you accept marketing cookies, your browsing data is shared with advertising partners for the purpose of targeted advertising. Under the definitions in California law this counts as "sharing" personal information. You can opt out by switching marketing cookies off in the cookie settings at the bottom of the page.
We do not sell personal information for monetary consideration. We do not knowingly sell or share the personal information of persons under 16 years of age.
Requests: info@varusteleka.com. You may authorise an agent to make a request on your behalf, in which case we will ask for proof of the authorisation.
14. Changes to this notice
We update this notice when our services, our practices or the law change. We publish the updated notice on this page and change the update date. We notify registered customers separately of significant changes.
Contact
Privacy questions and requests: info@varusteleka.com Other matters: our customer service, info@varusteleka.com