Privacy Policy
1. Data controller
The controller of the personal data processed through the site is CA CLASSIC STUDIO S.R.L., tax ID (CUI) 54184441, Trade Registry no. J2026015143008, registered office: Str. Viorii nr. 17, camera 3, ap. 2, sat Moșnița Veche, com. Moșnița Nouă, jud. Timiș, email: contact@claudiasimona.com, phone: +40 761 417 779.
2. Data processed
Account and order data: name, email address, phone number, shipping and billing addresses, order history.
Payment data: card payments are processed by Stripe Payments Europe, Ltd. Card details are entered directly with the payment processor and are not accessed or stored by CA CLASSIC STUDIO S.R.L..
Technical data: strictly necessary cookies (see the Cookie Policy).
Usage and marketing data, only on the basis of consent: the pages visited, interactions with products, the cart, checkout and a placed order, the identifiers held in the analytics and marketing cookies, and the technical details of the request — the IP address and user agent. The data transmitted to each recipient is set out in section 4.
3. Purposes and legal bases
Processing orders and delivering products — performance of a contract (Art. 6(1)(b) GDPR).
Invoicing and tax obligations — legal obligation (Art. 6(1)(c) GDPR).
Handling requests and complaints — legitimate interest (Art. 6(1)(f) GDPR).
Monitoring technical errors, to keep the site working correctly and securely — legitimate interest (Art. 6(1)(f) GDPR); this processing uses no cookies and does not depend on the cookie banner.
No newsletters or other direct commercial communications are sent. Should such communications be introduced, they will be sent only on the basis of the data subject's explicit consent (Art. 6(1)(a) GDPR), which may be withdrawn at any time.
Analysing how the site is used and improving the user experience — the data subject's consent (Art. 6(1)(a) GDPR), given through the “Analytics” category in the cookie banner.
Measuring, attributing and optimising Facebook and Instagram advertising, and creating retargeting audiences — the data subject's consent (Art. 6(1)(a) GDPR), given through the “Marketing” category in the cookie banner and withdrawable at any time.
4. Recipients of the data
To fulfil orders, data is transmitted to the following recipients: the payment processor Stripe Payments Europe, Ltd., the hosting providers Vercel Inc. and Railway Corp., the courier company chosen for delivery and, where applicable, the accounting service.
If the “Analytics” category is accepted, site usage data is transmitted to Google Ireland Limited (Google Analytics): the pages visited and the e-commerce interactions — including product list views, product selections, product views, cart changes, cart views, checkout steps and placed orders — with product identifiers, value and currency where applicable, together with the identifiers held in the GA4 cookies and the technical details of the request. Google processes this data on the controller's instructions. Transfers outside the EEA rely on the EU–US Data Privacy Framework and/or standard contractual clauses, as applicable.
Also on the basis of the “Analytics” category, Microsoft Ireland Operations Limited (Clarity) receives the pages viewed, the clicks, the scrolling and a reconstruction of the session as recordings and interaction maps. The text on the page, the fields filled in and the order details are masked before leaving the browser. Microsoft does not act as the controller's processor but as a controller in its own right: it also uses the data for its own purposes, as set out in the Microsoft Privacy Statement, and this processing is outside the controller's control. Transfers outside the EEA rely on the EU–US Data Privacy Framework and/or standard contractual clauses, as applicable.
If the “Marketing” category is accepted, data about browsing and orders is also transmitted to Meta Platforms Ireland Limited (Facebook, Instagram) from the browser, through the Meta Pixel. The event for a placed order is also sent directly from the server to Meta, through the Conversions API. The data transmitted comprises the pages visited, the products, the values and the currency belonging to each event, the _fbp identifier and, where it exists, _fbc, the IP address and the user agent. When an order is placed, the following are additionally transmitted, pseudonymised using SHA-256 before transmission: the email address, the phone number if provided, the first name, last name, city, postcode and country; these hashes remain personal data and are used by Meta to match an existing account. Depending on the specific purpose, Meta may act as a processor, a joint controller or an independent controller, under the Meta Business Tools Terms and the applicable supplements. Data is transferred outside the EEA under the EU–US Data Privacy Framework and/or standard contractual clauses, as applicable.
To detect and fix technical errors, error reports are transmitted to Functional Software, Inc. (Sentry), which processes them on the controller's instructions. A report contains the page on which the error occurred — with sensitive parameters removed before transmission —, the browser and operating system type, the application version and the technical details of the error. The IP address is not stored, and cookies and authentication headers are not transmitted. The data is hosted on Sentry's servers in the European Union; any transfer outside the EEA relies on the EU–US Data Privacy Framework and/or standard contractual clauses, as applicable.
Personal data is not sold or rented to third parties.
5. Data retention
Invoicing data is kept as required by tax law (10 years). Account data is kept while the account is active; its deletion may be requested at any time.
Analytics data is kept by the providers: 14 months in Google Analytics. In Microsoft Clarity, full recordings are kept for 30 days, while heatmaps, click data and flagged recordings are kept for 9 months; after 30 days Clarity may retain a reduced sample of recordings up to that same 9-month limit. Details of Microsoft's own processing are in the Microsoft Privacy Statement at https://privacy.microsoft.com/privacystatement.
The Meta cookies _fbp and _fbc last 90 days in the browser and are deleted if consent is withdrawn. Under the Meta Business Tools Terms, event data is kept by Meta for at most two years, and the contact information sent for matching is deleted once the matching process is complete. Further details are available in the Meta Privacy Policy at https://www.facebook.com/privacy/policy.
Error reports are kept in Sentry for 90 days and then deleted automatically.
6. Rights of the data subject
The data subject has the right of access, rectification, erasure, restriction of processing, data portability and objection, as well as the right to withdraw consent at any time.
Requests to exercise these rights may be sent by email to contact@claudiasimona.com. A complaint may also be lodged with the Romanian supervisory authority ANSPDCP (www.dataprotection.ro).