PRIVACY & DATA PROTECTION

Venroys Privacy Policy

This policy explains in clear language what data Venroys processes, why it is needed, and the choices and rights available to you.

Last updated: August 10, 2026Effective August 10, 2026Venroys OÜ · 17427636 · EE102991020
In short

Venroys OÜ is established in Estonia and is subject to the GDPR. Depending on the service, Venroys, an independent seller and a service provider may each have a separate role.

No raw card data

Card and payment details are processed securely by Stripe. Venroys does not store full card numbers or CVC codes.

Seller storefronts

A seller is responsible for its products, customer service and its own legal obligations. Venroys operates the technical infrastructure.

Choice and control

You can exercise privacy rights, stop marketing and manage non-essential cookies.

01

1. Who is responsible for processing?

Venroys OÜ (Estonian private limited company)
Registered on: 2 February 2026 (Estonia)
Registry code: 17427636
Address: Tornimäe tn 5, 10145 Tallinn, Estonia
Website: venroys.com
Management board: Constantino Aemilius Darshan Changoe
Main activity (EMTAK): 47711 - Retail sale of clothing in specialised stores
Email: info@venroys.com
For privacy questions, requests, or complaints, please contact us at the email address above. If we appoint a Data Protection Officer (DPO) where required, the contact details will be published here.

Founders: Constantino Aemilius Darshan Changoe and Muhammet Fatih Koçyigit

02

2. Personal Data We Process

Depending on how you use Venroys (shopping, creating an account, contacting us, or selling on the platform), we may process the following categories of personal data:

CategoryExamples
Identification and Contact DataName, billing/shipping address, email address, phone number, account ID
Payment and Billing DataPayment provider token, transaction ID, invoice details, payout details (for sellers)
Order and Fulfillment DataOrdered items, quantities, shipping method, delivery status, return/refund information
Account and Login DataUsername/email, hashed password, account preferences, login timestamps
Communication and Consent DataSupport messages, newsletter opt-in status, cookie consent choices
Technical and Device DataIP address, browser type, device information, session logs, security events
Usage and Behavioral DataPages viewed, search queries, clicks, scroll behavior, products viewed
Seller and verification dataBusiness details, representatives, date of birth, tax details, verification status and Stripe Connect account references
Storefront and content dataBrand name, domain, website content, product media, theme settings and published pages
Derived risk and trust signalsDelivery outcomes, refund and chargeback rates, policy status, suspicious activity and marketplace progress

We do not intentionally collect special categories of personal data (for example, health data). Please do not include sensitive personal information in order notes, support messages, or other free-text fields unless it is strictly necessary.

03

3. Purposes and Legal Bases

PurposeLegal Basis (GDPR)Details
Account creation and authenticationPerformance of a contract (Art. 6(1)(b))To create your account, let you log in securely, and keep your account available.
Order processing, payment, and deliveryPerformance of a contract (Art. 6(1)(b))To process purchases, confirm orders, arrange shipping, and manage returns or refunds.
Customer support and service communicationLegitimate interests (Art. 6(1)(f))To answer questions, investigate issues, and improve support quality.
Marketing communications and promotional offersConsent (Art. 6(1)(a))Only where required by law and after you opt in. You can unsubscribe or withdraw consent at any time.
Security, fraud prevention, and platform integrityLegitimate interests (Art. 6(1)(f)) and legal obligations (Art. 6(1)(c))To detect abuse, secure accounts, prevent fraud, and comply with security-related obligations.
Legal, tax, and accounting complianceLegal obligation (Art. 6(1)(c))To meet bookkeeping, tax, reporting, and other statutory requirements.
Seller verification and payoutsContract, legal obligation and legitimate interestsTo onboard sellers, verify identity and business details, enable payouts and limit financial fraud.
Marketplace trust and policy administrationLegitimate interests and contractTo monitor seller performance, review marketplace applications and protect customers and the platform.
04

4. Platform, seller and storefront roles

  • Venroys is a controller for Venroys accounts, platform security, marketplace administration, platform fees, tax records and operation of our services.
  • For an independent seller storefront, the seller may be a separate controller for customer relationships, product information, fulfillment, returns and support. The seller's identity should be available in the relevant storefront or order information.
  • Where Venroys handles data only on a seller's instructions, we act as a processor under the applicable agreement. For certain services, including payments and legally required identity checks, Stripe may act as an independent controller.
05

5. Sources of personal data

  • Directly from you through registration, checkout, support, uploads or settings.
  • From sellers when they manage an order, return or customer request.
  • From payment, fulfillment, shipping, verification and fraud-prevention providers.
  • Automatically from devices, logs, cookies and security signals, depending on your choices.
06

4. Cookies and Similar Technologies

We use cookies and similar technologies to operate the website, remember your preferences, improve performance, and measure usage. We request consent for non-essential cookies where required by law. For more information, see our Cookie Policy.
07

5. Sharing With Third Parties

We share personal data only when necessary, for example with:

  • Payment service providers to process payments, refunds, and related transaction checks.
  • Shipping and logistics partners to deliver orders and handle returns.
  • Hosting, infrastructure, email, and technical service providers that support the platform.
  • Analytics and marketing partners (only where permitted and, where required, with your consent).
  • Public authorities, regulators, or law enforcement where we are legally required to disclose information.

Where third parties process data on our behalf, we use data processing agreements where required and instruct them to process personal data only for the agreed purposes.

08

8. Key service providers

ServiceRole and dataMore information
StripePayments, direct charges, seller verification, fraud prevention and payouts. Stripe receives data directly through secure payment and onboarding components.Stripe Privacy
PrintfulOptional product, fulfillment, shipping, tracking and return services. Name, address, contact and order data may be shared for fulfillment.Printful Privacy
Hosting and databaseCloud hosting, secure storage, backups, network delivery and operational logging.Contractually restricted providers
Email and communicationsTransactional messages, verification, order updates, support and consented marketing.Necessary contact and message data only

Specific vendors and subprocessors may change as our infrastructure changes. We assess providers before they process personal data.

09

9. International transfers

Some providers or their subprocessors are located outside the European Economic Area. Where the GDPR requires it, we rely on an adequacy decision, European Commission Standard Contractual Clauses or another valid safeguard. We assess supplementary organizational and technical measures where appropriate.

European Commission Standard Contractual Clauses
10

6. Data Retention

Data CategoryRetention Period
Invoices and transaction recordsAt least 7 years under applicable Estonian accounting and tax rules, calculated from the legally prescribed starting date
Customer account dataFor the duration of the account and a limited period after inactivity or closure
Marketing preferences and consent recordsUntil consent is withdrawn or no longer needed to demonstrate consent
Security, log, and analytics dataFor a limited period appropriate to security and analytics purposes
Seller KYC and payout recordsWhile needed for the payment relationship and afterward as required for financial, anti-fraud and legal obligations; Stripe also applies its own retention periods
Order and fulfillment recordsAs needed for delivery, returns, disputes, warranties and applicable accounting and tax periods

After the applicable period, we delete or anonymize data unless it remains necessary for a legal claim, investigation, dispute or other legal obligation.

11

7. Security

We implement appropriate technical and organizational measures to protect personal data, including:

  • Encryption in transit (HTTPS / TLS)
  • Password hashing and secure authentication controls
  • Access controls and role-based permissions
  • Monitoring, backups, and security maintenance processes

No system is entirely risk-free. Protect your account with a unique password and two-factor authentication where available.

12

8. Your Rights

Depending on your location and applicable law, you may have the right to:

  • Request access to the personal data we hold about you.
  • Request correction of inaccurate or incomplete personal data.
  • Request deletion of your personal data, where applicable.
  • Request restriction of processing or object to certain processing activities.
  • Withdraw consent at any time where processing is based on consent.
  • Receive your data in a portable format where the right to data portability applies.
  • You may also complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or the supervisory authority where you usually live.

Send requests to info@venroys.com. We may request additional information to verify your identity. We normally respond within one month; the GDPR permits a reasoned extension for complex requests.

13

13. Fraud, trust and automated signals

Venroys uses security, fraud and performance indicators such as delivery outcomes, refunds, chargebacks, account age, policy incidents and verification status. These signals support risk management and marketplace review. Marketplace access is not automatically guaranteed by a score. Decisions with a material effect may be reviewed by a person, and you may contact us to request an explanation or review.

14

14. Security incidents

We investigate suspected personal-data breaches, limit their effects and notify the competent authority and affected people where legally required. Report suspected security issues to info@venroys.com without sending passwords or complete payment details.

15

15. Seller responsibilities

Sellers receiving personal data through Venroys must use it lawfully, securely and only for permitted business purposes. They may not use customer data for unsolicited marketing, sell it or disclose it outside necessary order and support processes. Sellers must provide their own privacy information where required and respond to data-subject requests for which they are responsible.

16

9. Minors

Venroys is not intended for children under the age required by applicable law to consent to data processing on their own (for example, 16 in some jurisdictions). We do not knowingly collect personal data from children without the required consent.

17

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top shows when this page was last changed. If we make material changes, we may notify you through the website, email, or account notifications where appropriate.

18

12. Contact

If you have questions, concerns, or requests about this Privacy Policy or our data practices, contact us at:
Venroys OÜ
Tornimäe tn 5
10145 Tallinn
Estonia
Registry code: 17427636
Management board: Constantino Aemilius Darshan Changoe
Email: info@venroys.com
Website: venroys.com

Founders: Constantino Aemilius Darshan Changoe and Muhammet Fatih Koçyigit

info@venroys.com