← Back to the site

Privacy policy

Privacy Policy

Version 4 · Published 2026-07-31

Personal data, legal bases, recipients, retention and rights.

Effective 31 July 2026. Controller: Buono Confetto on GrowpacaOS Sweets. Contact admin@growpaca.io; seller details shown at checkout also apply. We process account/contact data, addresses, order and payment-status metadata, cart, favourites, support, authentication/security events, consent evidence and device data. Optional analytics and marketing require consent. GDPR Art. 6 bases are contract for accounts and orders, legal obligation for tax/accounting/consumer duties, legitimate interests for security and fraud prevention, and consent for optional analytics/marketing. Consent may be withdrawn. Recipients are authorised staff and necessary hosting, email, payment, delivery, support and consented analytics processors. EEA transfers require adequacy or safeguards such as EU Standard Contractual Clauses. Data is retained only for configured purpose-specific or statutory periods, then deleted or anonymised by tenant-scoped controls. Rights include access, correction, deletion, restriction, portability, objection and withdrawal via the account privacy centre or email. Identity verification may be required; complaints may be made to the competent EEA authority. We use access controls, tenant isolation, encryption in transit, audit evidence and minimisation. The store is not directed to children below the applicable digital-consent age. No solely automated decision has significant legal effect unless separately disclosed. Material changes create a new version and may require re-acceptance.