Privacy policy
Draft for legal review
This policy explains how Kulla (demo) handles your personal data.
1. Who is responsible
The seller named at the foot of every page is responsible for your personal data (the data controller). For any privacy question, write to our support email address.
2. What we collect
Your email address, name and country, your order details, and the type and last four digits of your card. We don’t store full card numbers. We also record technical data such as your IP address to prevent fraud.
3. Why we use it
To deliver your code, send your receipt, prevent fraud and meet legal duties. We email offers only if you opt in.
4. Who we share it with
Our bank’s card gateway, to process your payment; our email provider, to send your code and receipts; and the hosting providers that run the store. We don’t sell your data.
5. How long we keep it
Order and payment records for as long as accounting and tax law requires. Account data until you delete your account. Fraud prevention records only as long as that purpose needs them.
6. Cookies
We use only essential cookies: they keep your cart, your sign-in and access to your guest orders. They are httpOnly, so scripts on the page can’t read them, and they expire after 7 days at most. We don’t use analytics, advertising or tracking cookies, so we don’t show a cookie banner.
7. Your rights
You can ask to see, correct, export or delete your data, and object to its use. Email our support team to make a request. You can also complain to the data protection authority in your country.
8. Changes
We update this policy when the way we handle data changes. The date at the top shows the current version.
Questions? Email agon@gjirafa.com.