Privacy policy

Privacy Policy

Last updated: 20 August 2026

This Privacy Policy explains how Haritkumar Shantilal Kaklotar (trading as ZomaModa) ("ZomaModa", "we", "us", "our") collects, uses, shares, and protects personal data when you visit zomamoda.com, place an order, or contact us.

It is written to satisfy the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679), the UK GDPR and Data Protection Act 2018, the German BDSG and TDDDG, and the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), together with comparable US state privacy laws.

We keep this in plain language wherever we can. If anything is unclear, email support@zomamoda.com and a person will answer.


1. Who We Are — Data Controller

The controller responsible for processing your personal data is:

Haritkumar Shantilal Kaklotar, trading as ZomaModa Steinrader Weg 69 23558 Lübeck Germany

Email: support@zomamoda.com Contact form: https://zomamoda.com/pages/contact Represented by: Haritkumar Shantilal Kaklotar

Data Protection Officer: We have not appointed a Data Protection Officer, as we are not required to do so under Art. 37 GDPR or § 38 BDSG. All data protection enquiries are handled directly by the controller named above.


2. What Personal Data We Collect

2.1 Data you give us

Category Examples When
Identity & contact Name, email address, phone number Checkout, account creation, contact form, newsletter
Delivery Shipping address, billing address, country Checkout
Order Items, sizes, quantities, order number, order history Checkout
Payment Payment method type, tokenised card reference, transaction ID, billing postcode Checkout
Communications Emails, support messages, photos you send with a defect claim When you contact us
Marketing preferences Newsletter opt-in, consent records Sign-up
User content Product reviews, social tags you submit to us When submitted

We never see or store your full card number. Payment card data is captured directly by our payment processors under their own PCI-DSS-compliant systems.

2.2 Data collected automatically

  • Device & connection data: IP address, browser type and version, operating system, device type, screen resolution, language, referring URL.
  • Usage data: pages viewed, time on page, products viewed, items added to cart, checkout steps completed, search terms used on-site.
  • Cookies and similar technologies: see Section 7.

2.3 Data from third parties

  • Order, fulfillment, and delivery status data from Printful and carriers.
  • Fraud-risk signals and payment confirmation from payment providers.
  • Aggregated audience and campaign data from advertising and analytics platforms, where you have consented.

We do not knowingly collect data from children under 16. If you believe a child has provided us data, contact us and we will delete it.

Special category data: we do not seek or intentionally process special categories of personal data (Art. 9 GDPR), and we ask that you do not send us any.


Purpose Data used Legal basis (GDPR Art. 6)
Processing and fulfilling your order; producing and shipping your item Identity, contact, delivery, order, payment Art. 6(1)(b) — performance of a contract
Customer service, defect claims, returns, and refunds Identity, contact, order, communications, photos Art. 6(1)(b) — contract; Art. 6(1)(f) — legitimate interests
Sending transactional emails (confirmation, shipping, delivery) Identity, contact, order Art. 6(1)(b) — contract
Keeping tax, accounting, and commercial records Identity, order, payment, invoices Art. 6(1)(c) — legal obligation (e.g. § 147 AO, § 257 HGB)
Fraud prevention, chargeback defence, and site security Device, order, payment, usage Art. 6(1)(f) — legitimate interest in protecting our business
Website analytics and performance measurement Device, usage, cookies Art. 6(1)(a) — consent (where required)
Marketing emails and newsletters Contact, marketing preferences Art. 6(1)(a) — consent; withdrawable at any time
Advertising, retargeting, and conversion measurement Device, usage, cookies, hashed contact data Art. 6(1)(a) — consent
Post-purchase emails to existing customers about similar products Contact, order Art. 6(1)(f) / § 7(3) UWG — soft opt-in, with an unsubscribe link in every message
Defending or bringing legal claims Any relevant data Art. 6(1)(f) — legitimate interest

Where we rely on legitimate interests, we have carried out a balancing test and concluded our interest does not override your rights and freedoms. You may object at any time — see Section 9.

Providing your data is not a statutory requirement, but it is necessary to conclude a contract. Without delivery and payment data we cannot fulfill an order.


4. Who We Share Your Data With

We share personal data only where necessary, and only with processors bound by written data processing agreements under Art. 28 GDPR.

4.1 Core service providers

Recipient Role Data shared Location
Shopify Inc. / Shopify International Ltd. E-commerce platform, hosting, checkout, order management All order, account, and browsing data Canada / EU / USA
Printful Inc. / Printful Latvia SIA Print-on-demand production and fulfillment Name, shipping address, email, order contents USA / EU (Latvia)
Shipping carriers (DHL, Deutsche Post, DPD, Royal Mail, USPS, UPS, FedEx, and local partners) Delivery and tracking Name, shipping address, phone, email Varies by destination
Payment providers (Shopify Payments, Shop Pay, Apple Pay, Google Pay) Payment processing, fraud screening Payment and billing data, order value, device signals EU / USA
Shopify Email (Shopify Inc.) Transactional and marketing email Name, email, order history, engagement data Canada / EU / USA
Shopify Analytics (Shopify Inc.) Traffic and conversion measurement Device and usage data, cookie identifiers Canada / EU / USA
Advertising platforms (Meta Platforms, Google, Pinterest — only where a campaign is running and you have consented) Advertising and measurement Cookie identifiers, hashed email, event data EU / USA

4.2 Other disclosures

  • Legal obligation: where required by law, court order, or a valid request from a public authority.
  • Business transfer: if our business is sold, merged, or restructured, data may transfer to the acquirer, subject to this policy.
  • Your consent: any other sharing happens only if you ask us to.

We do not sell your personal data. See Section 10 for what this means specifically under US state law.


5. International Data Transfers

Some of our processors are located in, or access data from, countries outside the EEA and UK — principally the United States.

Where personal data is transferred outside the EEA/UK, we rely on one or more of:

  • Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914), and the UK International Data Transfer Addendum where relevant;
  • the EU–US Data Privacy Framework and its UK Extension, where the recipient is certified under it;
  • an adequacy decision of the European Commission (e.g. Canada for commercial organisations, United Kingdom);
  • supplementary technical and organisational measures such as encryption in transit and at rest, and data minimisation.

You may request a copy of the relevant safeguards by emailing support@zomamoda.com.


6. How Long We Keep Your Data

Data Retention period
Order, invoice, and transaction records 10 years from the end of the calendar year of the transaction (German commercial and tax law: § 147 AO, § 257 HGB; adjust to your jurisdiction)
Customer account data For as long as the account is active, then deleted 24 months after last activity
Customer service correspondence 3 years from the end of the year of the last message (statutory limitation period, § 195 BGB)
Defect-claim photos 2 years from claim resolution
Newsletter subscriber data Until you unsubscribe, plus consent records kept 3 years as proof of lawful processing
Analytics data Up to 14 months, or the shorter period configured in the tool
Cookie consent records 12 months, then re-requested
Server and security logs 30 days, unless needed to investigate an incident

Where deletion is not immediately possible because of a legal retention obligation, we restrict processing instead: the data is blocked from ordinary use and retained only to satisfy that obligation.


7. Cookies and Tracking Technologies

We use cookies and similar technologies (pixels, local storage, SDKs). On first visit you are shown a consent banner allowing granular choice.

Category Purpose Consent needed?
Strictly necessary Cart contents, checkout, session security, load balancing, fraud prevention, storing your cookie choices No — § 25(2) TDDDG
Functional / preference Language, currency, region, recently viewed items Yes
Analytics / performance Understanding traffic and improving the store Yes
Marketing / advertising Retargeting, conversion measurement, audience building Yes

Managing your choices: click "Cookie settings" in the site footer at any time to change or withdraw consent. You can also block or delete cookies in your browser settings, though strictly necessary cookies are required for checkout to work.

Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.


8. How We Protect Your Data

  • TLS/SSL encryption across the entire site, including checkout.
  • PCI-DSS-compliant payment processing; card data never touches our systems.
  • Access to customer data limited to those who need it, protected by strong authentication.
  • Vetted processors bound by contractual confidentiality and security obligations.
  • Regular review of access rights and of the third parties we work with.

No system is perfectly secure. In the event of a personal data breach likely to result in a high risk to your rights, we will notify the competent supervisory authority within 72 hours (Art. 33 GDPR) and inform you without undue delay where required (Art. 34 GDPR).


9. Your Rights — EU, EEA, UK, and Switzerland

You have the right to:

  • Access (Art. 15) — obtain confirmation of whether we process your data and receive a copy.
  • Rectification (Art. 16) — have inaccurate or incomplete data corrected.
  • Erasure (Art. 17) — have your data deleted, subject to our legal retention obligations.
  • Restriction (Art. 18) — have processing limited in defined circumstances.
  • Data portability (Art. 20) — receive data you provided in a structured, machine-readable format and have it transmitted to another controller.
  • Object (Art. 21) — object at any time to processing based on legitimate interests, including an absolute right to object to direct marketing, which we will always honour.
  • Withdraw consent (Art. 7(3)) — at any time, without affecting prior lawful processing.
  • Not be subject to automated decision-making (Art. 22) — we do not make decisions producing legal or similarly significant effects based solely on automated processing. Payment providers may run automated fraud checks; contact us if you believe a decision affected you.

How to exercise your rights

Email support@zomamoda.com with the subject line DATA REQUEST. We may ask for information to verify your identity — we will not use it for any other purpose. We respond within one month, extendable by two further months for complex requests, in which case we will tell you why. There is no charge unless a request is manifestly unfounded or excessive.

Right to complain

You may lodge a complaint with a supervisory authority, in particular in the EU/EEA member state of your residence, place of work, or the place of the alleged infringement.

  • Our competent supervisory authority: Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD), Holstenstraße 98, 24103 Kiel, Germany — https://www.datenschutzzentrum.de
  • United Kingdom: Information Commissioner's Office — ico.org.uk

We'd appreciate the chance to resolve it with you directly first.


10. Your Rights — California and Other US States

If you are a resident of California, or of a state with comparable privacy legislation (including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and Montana), you have the following rights.

Categories of personal information collected in the last 12 months

Identifiers (name, email, address, IP address); customer records (billing and shipping details, payment method type); commercial information (products purchased and considered); internet activity (browsing and interaction with our site); geolocation data (approximate, derived from IP); inferences drawn for advertising audiences.

Sources, purposes, and recipients are as described in Sections 2, 3, and 4.

Your rights

  • Right to know what personal information we collect, use, disclose, and share, including specific pieces.
  • Right to delete personal information we hold, subject to legal exceptions.
  • Right to correct inaccurate personal information.
  • Right to opt out of "sale" or "sharing" of personal information, and of targeted advertising.
  • Right to limit use of sensitive personal information — we do not collect sensitive personal information for the purposes requiring this right.
  • Right to non-discrimination — we will never deny service, charge different prices, or provide a lesser experience because you exercised a privacy right.

About "sale" and "sharing"

We do not sell personal information for money. However, our use of advertising and analytics cookies may constitute "sharing" for cross-context behavioural advertising under the CPRA and comparable laws.

To opt out: use the "Do Not Sell or Share My Personal Information" link in our site footer, adjust your choices via "Cookie settings", or email support@zomamoda.com with the subject CCPA OPT-OUT. We also honour Global Privacy Control (GPC) browser signals.

Submitting a request: email support@zomamoda.com with the subject US PRIVACY REQUEST. We confirm receipt within 10 business days and respond within 45 days, extendable by a further 45 days with notice. Authorised agents may submit requests on your behalf with written permission and proof of identity.


11. Marketing Communications

  • Newsletters are sent only with your explicit opt-in (double opt-in where required).
  • Every marketing email contains a one-click unsubscribe link, effective immediately.
  • Existing customers may receive occasional emails about similar products under the soft opt-in in § 7(3) UWG; you can object at any time at no cost beyond your standard transmission rates.
  • Transactional emails (order confirmation, shipping notification, defect claim updates) are not marketing and cannot be unsubscribed from while an order is active.

Our site links to external sites and social platforms. We are not responsible for their privacy practices. Where we operate social media profiles, the platform acts as a joint or independent controller for data it processes there — please review that platform's own policy.


13. Changes to This Policy

We update this policy when our processing, services, or the law changes. The "Last updated" date at the top always reflects the current version. Where changes are material — for example a new processing purpose — we will notify you by email or a prominent site notice before they take effect.


14. Contact

Haritkumar Shantilal Kaklotar, trading as ZomaModa Steinrader Weg 69, 23558 Lübeck, Germany Email: support@zomamoda.com

We answer privacy enquiries within 24 hours on business days, and formal requests within the statutory deadlines above.


Related: Terms of Service · Legal Notice / Impressum · Contact Us