Contact information
This policy applies to customers located in the European Economic Area (EEA), United Kingdom, and Switzerland. It supplements our standard Privacy Policy and explains your rights under the General Data Protection Regulation (GDPR).
Who We Are (Data Controller)
Zebess is the data controller responsible for your personal information.
Contact Email: support@zebess.com
Website: www.zebess.com
What Personal Data We Collect
We collect the following data when you visit our store or place an order:
- Full name and contact details (email, phone number)
- Billing and shipping address
- Payment information (processed by secure third-party providers — we never store full card details)
- IP address and browsing behavior (via cookies)
- Order history and purchase records
- Any communication you send us (emails, support tickets)
Legal Basis for Processing Your Data
Under GDPR, we are required to have a lawful basis for processing your data. We rely on the following:
- Contract Performance — We need your data to process and fulfill your order
- Legal Obligation — We may be required to retain certain data for tax or legal compliance
- Legitimate Interests — To improve our store, prevent fraud, and ensure security
- Consent — For marketing emails and non-essential cookies (you can withdraw consent at any time)
How We Use Your Data
- To process, fulfill, and ship your orders
- To communicate order updates and respond to inquiries
- To send marketing emails (only with your explicit consent)
- To comply with legal and tax obligations
- To improve our website and customer experience
How Long We Keep Your Data
We only keep your data for as long as necessary:
- Order and transaction records: 7 years (legal/tax requirements)
- Marketing consent records: Until you unsubscribe or withdraw consent
- Customer service communications: 2 years after resolution
Who We Share Your Data With
We do not sell your data. We only share it with trusted third parties who help us operate our business, including:
- Shipping carriers (to deliver your orders)
- Payment processors (to handle transactions securely)
- Email marketing platforms (only if you opted in)
- Analytics tools (with anonymized or aggregated data where possible)
All third-party providers we use are GDPR-compliant and bound by data processing agreements.
International Data Transfers
As a US-based store selling to European customers, your data may be transferred to and processed in the United States. We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, to protect your data during any international transfer.
Cookies and Tracking
We use the following types of cookies:
- Essential cookies — Required for the website to function (no consent needed)
- Analytics cookies — Help us understand how visitors use our site (consent required)
- Marketing cookies — Used for targeted advertising (consent required)
You will be presented with a cookie consent banner when you first visit our site. You can manage or withdraw your cookie preferences at any time through our cookie settings.
Your Rights Under GDPR
As a European customer, you have the following rights:
- Right to Access — Request a copy of the personal data we hold about you
- Right to Rectification — Ask us to correct inaccurate or incomplete data
- Right to Erasure ("Right to be Forgotten") — Request deletion of your personal data
- Right to Restrict Processing — Ask us to limit how we use your data
- Right to Data Portability — Receive your data in a structured, machine-readable format
- Right to Object — Object to processing based on legitimate interests or for direct marketing
- Right to Withdraw Consent — Withdraw consent for marketing or non-essential cookies at any time
To exercise any of these rights, contact us at support@zebess.com. We will respond within 30 days.
Right to Lodge a Complaint
If you believe we are not handling your data in compliance with GDPR, you have the right to lodge a complaint with your local data protection authority. A full list of EU supervisory authorities can be found at: www.edpb.europa.eu
Changes to This Policy
We may update this GDPR Privacy Policy from time to time. Any changes will be posted on this page with an updated date. We recommend checking back periodically.
Contact Us
For any privacy-related questions or to exercise your rights:
Email: support@zebess.com
Website: www.zebess.com