Privacy policy
Last updated: October 2, 2025
1. Who we are (Data Controller)
- Controller: Ikistore OÜ (Reg. nr 17331712)
- Trading as: Lastenurk.com
- Registered address: R. Tobiase 11-3, 10152 Tallinn, Estonia
- Correspondence/returns address: Kivila 34 (Moeateljee), 13918 Tallinn, Estonia
- Email: info@lastenurk.com
- Phone: +372 5393 3413
Ikistore OÜ operates this store and website, including all related information, content, features, tools, products and services (the “Services”). Lastenurk.com is powered by Shopify, which enables us to provide the Services to you. This Privacy Policy describes how we collect, use, disclose and protect your personal information when you visit, use, or make a purchase via the Services or otherwise communicate with us. If this Privacy Policy conflicts with our Terms of Service regarding personal information, this Privacy Policy controls.
By using the Services, you acknowledge that you have read and understand this Privacy Policy.2. Personal information we collect
“Personal information” means information that identifies or can reasonably be linked to you. It does not include anonymized or de‑identified data. Depending on how you interact with us and applicable law, we may collect the following categories:
- Contact details: name, billing and shipping address, phone number, email address.
- Account information: username, password, preferences, settings.
- Transaction information: items viewed, added to cart, wishlisted or purchased; returns, exchanges, cancellations; order identifiers; transaction and delivery details.
- Financial/payment information: payment method, payment confirmation, and other payment details (note: card/bank data entered for payment is processed in secure environments by our payment providers; we do not see full card or online‑bank credentials).
- Communications: content of messages you send us (e.g., customer support).
- Device and usage information: device, browser and network information; IP address; identifiers; logs; how and when you interact with the Services, including via cookies or similar technologies.
3. Sources of personal information
- Directly from you (e.g., account creation, checkout, communications).
- Automatically via the Services (including cookies and similar technologies).
- From our service providers (acting on our behalf).
- From partners or third parties, and where applicable from public registers.
4. How we use personal information (purposes and legal bases)
We process personal information for:
- Provide, operate, fulfill and improve the Services (perform our contract; Art. 6(1)(b) GDPR). This includes processing orders and payments, arranging shipping, handling returns/exchanges, account management, recommendations and service improvements.
- Security and fraud prevention (our legitimate interests and/or legal obligations; Art. 6(1)(f) and 6(1)(c)): authenticate accounts, detect and prevent fraud, protect public safety, secure our Services.
- Customer support and communications (contract/legitimate interests; Art. 6(1)(b),(f)).
- Marketing and advertising (consent/legitimate interests; Art. 6(1)(a),(f)): send newsletters and offers if you opt in; show on‑site or online ads. You can opt out at any time.
- Legal and compliance (legal obligations; Art. 6(1)(c)): bookkeeping, responding to lawful requests, enforcing our terms, and defending legal claims.
Where we rely on consent, you can withdraw it at any time; withdrawal does not affect prior lawful processing.
5. Relationship with Shopify (separate processing by Shopify)
Our store is hosted by Shopify. Shopify collects and processes personal information about your access to and use of the Services to provide and improve its platform. For certain enhanced features (including aggregated analytics and personalized advertising across different merchants using Shopify services), Shopify may act as an independent controller and is responsible for responding to requests about those activities. To learn how Shopify processes personal information and to exercise rights for Shopify‑controlled processing, see Shopify’s Consumer Privacy Policy and Privacy Portal.
6. Payments via Maksekeskus (MakeCommerce)
We use Maksekeskus AS as our payment intermediary and authorized processor for payments. When you pay using bank links, card payments, wallets (e.g., Apple Pay/Google Pay) or pay‑later options, payment processing occurs in the secure environment of the respective provider (e.g., your bank, Maksekeskus AS).
- Controller/processor roles: Ikistore OÜ is the data controller for purchases made through our store. For the purpose of performing payments, we transmit the personal data necessary for payment processing to our authorized processor Maksekeskus AS.
- Data shared for payments (depending on method): order number, amount, currency, payer’s name, email and/or phone, billing details, partial card/payment token information, and technical data (e.g., IP address, device/browser metadata necessary for fraud prevention).
- Security: We do not have access to your full bank credentials or full card numbers. Bank‑link payments complete in your bank’s secure environment; card payments and certain wallets complete in Maksekeskus AS’s secure environment.
7. Other disclosures and processors
We disclose personal information to third parties where necessary, proportionate and subject to appropriate safeguards:
- Service providers/authorized processors: platform hosting (Shopify), payments (Maksekeskus AS), logistics and couriers (e.g., Omniva, Smartpost, DPD, PostNord, Posti), IT and security providers, email and marketing tools, customer support tools, accountants/bookkeeping.
- Business and marketing partners: to provide marketing services and advertising (in accordance with your choices and applicable law).
- Affiliates/within our corporate group: for operations consistent with this Policy.
- Legal and corporate events: to comply with law, respond to lawful requests, enforce terms, protect rights/safety, or in connection with a merger, acquisition or similar transaction.
8. Direct marketing
We send newsletters and promotional offers only if you have expressly opted in (e.g., by entering your email and consenting to direct marketing). You may unsubscribe at any time using the link in our emails or by contacting us at info@lastenurk.com. We may still send non‑marketing service messages (e.g., order updates).
9. Cookies and similar technologies
We and our providers use cookies and similar technologies to run the store, remember your preferences, analyze traffic/performance, prevent fraud and personalize content/ads. You can manage cookies via your browser settings and, where available, our cookie banner/preferences. Some cookies are necessary for the store to function.10. Data retention
We keep personal information only as long as needed for the purposes outlined above or as required by law. Typical retention periods:
- Orders, invoices and accounting records: retained for the period required by law (e.g., up to 7 years under applicable accounting rules).
- Customer accounts and customer service communications: for the life of the account and up to 3 years after last activity or request closure (or longer if needed to establish, exercise or defend legal claims).
- Security/fraud logs: typically up to 12 months unless longer needed for investigations.
- Marketing data (with consent): until you withdraw consent or after 24 months of inactivity, whichever comes first.
We may retain data longer where necessary to comply with legal obligations or to resolve disputes.
11. International transfers
We may transfer, store and process personal information outside your country, including outside the European Economic Area (EEA) and the UK. Where we do so, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (or UK equivalents) unless the destination country benefits from an adequacy decision.
12. Your rights
Depending on where you live and subject to conditions/exceptions in law, you may have the right to:
- Access and obtain a copy of your personal information.
- Rectify inaccurate or incomplete personal information.
- Erase personal information (right to be forgotten).
- Restrict processing.
- Object to processing (including direct marketing).
- Data portability.
- Withdraw consent where processing is based on consent.
You can exercise your rights by emailing info@lastenurk.com. We may need to verify your identity. You may authorize an agent to act for you where permitted by law.
13. Complaints and supervisory authority
If you have concerns about our processing, please contact us at info@lastenurk.com. You also have the right to lodge a complaint with your local data protection authority. In Estonia, this is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).14. Children’s data
The Services are not intended for children, and we do not knowingly collect personal information from individuals who are under the age of majority in their jurisdiction. If you are a parent or guardian and believe a child has provided us personal information, please contact us to request deletion. We do not knowingly “sell” or “share” personal information of individuals under 16 (as those terms may be defined by applicable law).
15. Security
We implement appropriate organizational and technical measures to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. No security measure is perfect; transmissions over the internet may not be fully secure. Please avoid sending sensitive information via unsecure channels.
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time (for operational, legal or regulatory reasons). We will post the revised version here, update the “Last updated” date, and provide any additional notice required by law.
17. Contact us (privacy requests and controller details)
- Controller: Ikistore OÜ (Reg. nr 17331712)
- Registered address: R. Tobiase 11-3, 10152 Tallinn, Estonia
- Correspondence/returns address: Kivila 34 (Moeateljee), 13918 Tallinn, Estonia
- Email: info@lastenurk.com
- Phone: +372 5393 3413
- Website: https://lastenurk.com