Privacy policy

PRIVACY POLICY

Last updated: 21 July 2026

This Privacy Policy describes how NATALIIA BONDARENKO, conducting business under the name NATALIIA BONDARENKO, with its registered business address at Kolejowa 9/78, 01-217 Warszawa, Poland, registered in the Central Register and Information on Economic Activity of the Republic of Poland (CEIDG), Tax Identification Number (NIP): 5273210265, REGON: 544268106, hereinafter referred to as “we”, “us”, “our” or the “Controller”, collects, uses, stores and shares personal information when you visit, use our services, make a purchase from aroundjewellery.com or otherwise communicate with us.

For the purposes of the General Data Protection Regulation (EU) 2016/679 (“GDPR”), we are the controller of your personal data.

Please read this Privacy Policy carefully. By using our website, you acknowledge that you have read and understood how we process personal data as described below.

1. CONTACT DETAILS

The data controller is:

Business name: NATALIIA BONDARENKO
Owner: NATALIIA BONDARENKO
Registered address: Kolejowa 9/78, 01-217 Warszawa, Poland

NIP: 5273210265
REGON: 544268106
Email: natalie@aroundjewellery.com
Telephone: +48451145739
Website: https://aroundjewellery.com/

You may contact us regarding this Privacy Policy or the processing of your personal data by emailing natalie@aroundjewellery.com.

2. PERSONAL DATA WE COLLECT

Depending on how you interact with our website and services, we may collect the following categories of personal data.

2.1 Information you provide directly

We may collect information that you provide when you:

  • place or attempt to place an order;

  • create or manage a customer account;

  • subscribe to our newsletter;

  • contact us by email, contact form, social media or another communication channel;

  • submit a return, complaint, warranty request or other customer service request;

  • participate in a promotion, survey, contest or similar activity;

  • post a product review or other content.

This information may include:

  • first and last name;

  • billing and delivery address;

  • email address;

  • telephone number;

  • company name, NIP or VAT number, if applicable;

  • account login details;

  • order and transaction information;

  • product preferences;

  • correspondence and customer service history;

  • information included in returns, complaints or warranty requests;

  • any other information you voluntarily provide to us.

Please do not provide sensitive personal data, such as health information, biometric data, information about racial or ethnic origin, political opinions, religious beliefs or sexual orientation, unless it is strictly necessary and we have expressly requested it.

2.2 Payment information

When you make a purchase, payment information is processed by the payment service provider selected during checkout.

Depending on the payment method, this may include:

  • payment card details;

  • bank account or payment account information;

  • payment status;

  • transaction identification number;

  • information required for fraud prevention and payment verification.

We generally do not receive or store complete payment card numbers. Such information is processed directly by our authorised payment service providers.

Our current payment providers may include:

  • Shopify Payments;

  • PayPal 

  • Banks and card payment networks involved in processing the transaction.

Each payment provider may process personal data as an independent controller or as a processor, in accordance with its own privacy policy.

2.3 Information collected automatically

When you visit or use our website, certain information may be collected automatically through cookies, pixels, server logs and similar technologies.

This information may include:

  • IP address;

  • browser type and version;

  • device type and operating system;

  • device identifiers;

  • language and regional settings;

  • time zone;

  • pages viewed;

  • products viewed or added to the cart;

  • referring website or source;

  • date, time and duration of visits;

  • interactions with our website and advertisements;

  • checkout and purchase activity;

  • approximate location based on the IP address;

  • cookie identifiers and consent preferences.

For more information, please see Section 10, “Cookies and Similar Technologies”.

2.4 Information received from third parties

We may receive personal data from third parties, including:

  • Shopify and companies within the Shopify group;

  • payment service providers;

  • delivery and logistics companies;

  • analytics and advertising providers;

  • social media platforms;

  • fraud prevention and security providers;

  • customer support, email marketing and review applications;

  • business partners or service providers acting on our behalf.

The type of information received depends on the service concerned and your interaction with that third party.

3. PURPOSES AND LEGAL BASES FOR PROCESSING

We process personal data only where we have a lawful basis under the GDPR.

3.1 Processing and fulfilling orders

We process your identification, contact, delivery, payment and order information in order to:

  • accept and process your order;

  • confirm your purchase;

  • receive and verify payment;

  • prepare and deliver products;

  • provide order updates;

  • manage returns, complaints and warranty requests;

  • issue invoices and other transaction documents;

  • provide customer service relating to your order.

Legal basis: processing is necessary for the performance of a contract or to take steps at your request before entering into a contract, pursuant to Article 6(1)(b) GDPR.

3.2 Compliance with legal obligations

We process and retain certain transaction, accounting, tax, invoice and complaint information in order to comply with obligations under Polish and European Union law.

Legal basis: processing is necessary to comply with a legal obligation, pursuant to Article 6(1)(c) GDPR.

3.3 Customer service and communication

We process your contact details and correspondence in order to:

  • respond to questions;

  • resolve problems;

  • provide product and order information;

  • manage complaints, returns and other requests;

  • maintain records of our communication.

Where the communication concerns an existing or potential order, the legal basis is Article 6(1)(b) GDPR.

In other cases, the legal basis is our legitimate interest in communicating with customers, providing effective support and protecting our business, pursuant to Article 6(1)(f) GDPR.

3.4 Customer accounts

Where customer accounts are available, we process account and order information to create and maintain your account, provide access to your order history and facilitate future purchases.

Legal basis: performance of a contract under Article 6(1)(b) GDPR.

3.5 Direct marketing and newsletters

Where you have subscribed to our newsletter or otherwise provided valid consent, we may use your email address and, where applicable, your name and preferences to send:

  • product updates;

  • offers and promotions;

  • information about new collections;

  • brand news;

  • invitations and other marketing communications.

Legal basis: your consent under Article 6(1)(a) GDPR and, where applicable, relevant electronic communications and marketing laws.

You may withdraw your consent at any time by:

  • clicking the unsubscribe link in any marketing email; or

  • contacting us at natalie@aroundjewellery.com.

Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

3.6 Analytics and website improvement

Subject to your cookie choices, we may process device, usage and interaction data to:

  • understand how visitors use our website;

  • measure website traffic and performance;

  • identify technical problems;

  • improve website functionality;

  • analyse the effectiveness of our content and campaigns;

  • develop and improve our products and services.

For non-essential analytics technologies, the legal basis is normally your consent under Article 6(1)(a) GDPR.

Where strictly necessary data is processed for security, basic statistics or service operation, the legal basis may be our legitimate interest under Article 6(1)(f) GDPR.

3.7 Personalised advertising

Subject to your consent, we and our advertising partners may use cookies, pixels and similar technologies to:

  • measure advertising performance;

  • create audiences;

  • display advertisements based on your activity or interests;

  • limit how often advertisements are displayed;

  • attribute purchases or other actions to advertising campaigns.

Legal basis: your consent under Article 6(1)(a) GDPR.

You may withdraw or change your consent through our cookie settings at any time.

3.8 Fraud prevention and website security

We may process account, payment, transaction, device and technical information to:

  • verify transactions;

  • detect and prevent fraud;

  • prevent misuse of our website;

  • protect customer accounts;

  • maintain network and information security;

  • establish, exercise or defend legal claims.

Legal basis: our legitimate interests in protecting our customers, website and business, pursuant to Article 6(1)(f) GDPR, and where applicable compliance with legal obligations under Article 6(1)(c) GDPR.

3.9 Establishing or defending legal claims

We may process and retain relevant information where necessary to establish, exercise or defend legal claims, resolve disputes, enforce our agreements or cooperate with competent authorities.

Legal basis: our legitimate interests under Article 6(1)(f) GDPR or compliance with a legal obligation under Article 6(1)(c) GDPR.

4. WHETHER PROVIDING PERSONAL DATA IS REQUIRED

Providing personal data is voluntary, but certain information is necessary to:

  • conclude and perform a purchase contract;

  • process payment;

  • deliver your order;

  • issue an invoice;

  • respond to a complaint, return or warranty request;

  • comply with applicable legal requirements.

If you do not provide the required information, we may be unable to process your order, deliver products or provide the requested service.

Providing data for newsletters, personalised advertising and non-essential analytics is optional and based on your consent.

5. HOW WE SHARE PERSONAL DATA

We may share personal data only where necessary and in accordance with applicable law.

Recipients may include:

5.1 Shopify

Our online store is hosted on Shopify. Shopify provides the e-commerce platform that enables us to offer and sell our products.

Shopify may process information relating to:

  • website visitors;

  • customers and customer accounts;

  • orders and checkout;

  • payments;

  • fraud prevention;

  • website performance;

  • customer privacy preferences;

  • support and platform security.

Shopify may process personal data on our behalf as a processor and, for certain activities, as an independent controller.

More information about Shopify’s processing practices is available through Shopify’s privacy documentation and privacy portal.

5.2 Payment providers

We share the information necessary to process transactions with payment providers, banks, card networks and other financial institutions selected during checkout.

5.3 Delivery and logistics providers

We may share your name, delivery address, email address, telephone number and order details with:

  • courier companies;

  • postal operators;

  • fulfilment centres;

  • customs brokers;

  • shipping platforms;

  • other logistics providers.

Current providers may include:

  • DHL;

  • INPOST;

  • other courier, postal and logistics providers selected for the delivery of a particular order.

5.4 Professional service providers

We may share personal data with trusted professional advisers and service providers, such as:

  • accountants and bookkeeping providers;

  • tax advisers;

  • lawyers;

  • auditors;

  • IT and website support providers;

  • hosting and cloud service providers;

  • customer service providers;

  • email and communications providers;

  • product review providers;

  • fraud prevention providers;

  • analytics and advertising providers.

These recipients receive only the information necessary to perform their services and are required to protect personal data as provided by applicable law and contractual obligations.

5.5 Public authorities

We may disclose personal data to courts, law enforcement authorities, tax authorities, customs authorities, supervisory authorities or other public bodies where:

  • disclosure is required by law;

  • we receive a legally binding request;

  • disclosure is necessary to protect our rights or the rights of another person;

  • disclosure is necessary to establish, exercise or defend legal claims.

5.6 Business transfers

If our business is sold, merged, reorganised or transferred, personal data may be disclosed to professional advisers and prospective or actual buyers, provided that appropriate confidentiality and data protection measures are applied.

6. SHOPIFY APPLICATIONS AND OTHER SERVICE PROVIDERS

We may use third-party Shopify applications to operate and improve our store.

These may include applications for:

  • email marketing;

  • customer reviews;

  • product recommendations;

  • customer support or live chat;

  • loyalty programmes;

  • returns management;

  • invoicing;

  • analytics;

  • advertising;

  • social media integration;

  • delivery and order tracking;

  • fraud detection;

  • consent and cookie management.

7. INTERNATIONAL TRANSFERS OF PERSONAL DATA

Some of our service providers, including Shopify and certain technology, payment, analytics, marketing or support providers, may operate or use servers outside the European Economic Area (“EEA”).

As a result, personal data may be transferred to or accessed from countries outside the EEA.

Where personal data is transferred outside the EEA, we take steps to ensure that an appropriate transfer mechanism is used, where required, such as:

  • an adequacy decision adopted by the European Commission;

  • Standard Contractual Clauses approved by the European Commission;

  • another legally recognised safeguard under Chapter V of the GDPR.

You may contact us at natalie@aroundjewellery.com to request additional information about the safeguards applicable to a specific transfer.

8. DATA RETENTION

We retain personal data only for as long as necessary for the purposes described in this Privacy Policy and to comply with applicable legal, accounting, tax and regulatory requirements.

The applicable retention period depends on the type of information and purpose of processing.

Generally:

  • order, invoice and accounting information is retained for the period required under Polish tax and accounting law;

  • information relating to contracts may be retained until the applicable limitation period for legal claims expires;

  • complaint, return and warranty information may be retained for the period necessary to process the request and defend against potential claims;

  • customer service correspondence may be retained for as long as necessary to resolve the matter and for the applicable limitation period;

  • customer account information is retained while the account remains active and for an appropriate period afterwards;

  • newsletter information is processed until you withdraw your consent, unsubscribe or the service is discontinued;

  • cookie and consent records are retained in accordance with the relevant cookie duration and consent management settings;

  • technical and security logs are retained for the period necessary to protect and secure our website.

After the applicable retention period, personal data will be deleted, anonymised or securely archived where continued storage is legally required.

9. YOUR RIGHTS UNDER THE GDPR

Subject to the conditions and limitations set out in applicable law, you have the following rights:

9.1 Right of access

You may request confirmation as to whether we process your personal data and obtain a copy of that data together with information about how it is processed.

9.2 Right to rectification

You may request correction of inaccurate personal data and completion of incomplete personal data.

9.3 Right to erasure

You may request deletion of your personal data in circumstances specified by the GDPR.

This right is not absolute. We may retain information where processing is necessary to comply with a legal obligation, establish or defend legal claims or for another lawful reason.

9.4 Right to restriction of processing

You may request that we restrict the processing of your personal data in circumstances specified by the GDPR.

9.5 Right to data portability

Where processing is based on consent or a contract and is carried out by automated means, you may request to receive personal data that you provided to us in a structured, commonly used and machine-readable format.

You may also request that we transmit this data directly to another controller where technically feasible.

9.6 Right to object

Where we process personal data on the basis of our legitimate interests, you may object to the processing on grounds relating to your particular situation.

We will stop processing the data unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms or the processing is required for legal claims.

You may object to the processing of personal data for direct marketing purposes at any time. If you object, we will no longer process your data for such marketing.

9.7 Right to withdraw consent

Where processing is based on consent, you may withdraw that consent at any time.

Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

9.8 Rights relating to automated decision-making

You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or similarly significantly affects you, except where permitted by law and subject to appropriate safeguards.

Shopify and our payment or fraud prevention providers may use automated tools, including fraud analysis and risk scoring, to identify potentially fraudulent or unauthorised transactions.

However, we do not currently make decisions producing legal or similarly significant effects concerning customers based solely on automated processing. Orders identified as potentially high-risk may be reviewed manually before they are accepted, fulfilled or cancelled.

If you have questions about a declined, cancelled or delayed transaction, please contact us at natalie@aroundjewellery.com.


9.9 Exercising your rights

To exercise any of your rights, contact us at:

natalie@aroundjewellery.com

Please specify:

  • your full name;

  • the email address associated with your order or account;

  • the right you wish to exercise;

  • any information reasonably necessary to identify the relevant data.

We may request additional information to verify your identity before responding. We will respond within the period required by applicable law.

Exercising your rights is generally free of charge. However, where a request is manifestly unfounded or excessive, particularly because it is repetitive, we may charge a reasonable fee or refuse to act on the request, as permitted by law.

10. COOKIES AND SIMILAR TECHNOLOGIES

Our website uses cookies, pixels, tags, local storage and similar technologies.

Cookies are small files stored on your device when you visit a website. They may be placed by us, Shopify or third-party service providers.

We may use the following categories of cookies:

10.1 Strictly necessary cookies

These cookies are necessary for the operation and security of the website. They may support:

  • shopping cart functions;

  • checkout;

  • customer login;

  • payment processing;

  • fraud prevention;

  • security;

  • network management;

  • storage of privacy and consent preferences.

Because these cookies are necessary to provide the website and services requested by you, they generally cannot be disabled through our cookie banner.

10.2 Functional cookies

These cookies allow the website to remember choices and provide enhanced functions, such as language, currency, location or customer preferences.

10.3 Analytics cookies

These cookies help us understand how visitors use the website and allow us to measure traffic, performance and interactions.

We may use:

  • SHOPIFY ANALYTICS;

  • GOOGLE ANALYTICS;

10.4 Advertising and targeting cookies

These cookies and pixels may be used to measure advertising performance, create audiences and show more relevant advertisements.

We may use:

  • META PIXEL;

  • GOOGLE ADS;

Non-essential cookies are used only after you provide consent where consent is required.

You can accept, reject or customise non-essential cookies through the cookie banner or cookie settings available on our website.

You may withdraw or change your consent at any time by clicking “Cookie preferences” in the footer of our website or by reopening the cookie settings panel.

You may also manage cookies through your browser settings. Blocking certain cookies may affect website functionality.

For more detailed information about the cookies used on our website, including their providers, purposes and duration, please see our Cookie Policy or the cookie settings panel.

11. EMAIL AND ELECTRONIC COMMUNICATIONS

We may send transactional messages necessary to process your order or provide requested services, including:

  • order confirmations;

  • payment confirmations;

  • shipping and delivery updates;

  • return and complaint communications;

  • account security messages;

  • important changes affecting your purchase or account.

These transactional communications are not marketing communications and may be sent where necessary to perform our contract with you or comply with legal obligations.

Marketing messages are sent only where we have an appropriate legal basis. You may unsubscribe from marketing emails at any time without affecting transactional communications.

12. SOCIAL MEDIA

Our website may contain links to or integrations with social media platforms, such as:

  • Instagram;

  • Facebook;

  • Pinterest.

When you interact with these platforms, the relevant platform may collect and process information in accordance with its own privacy policy.

Where we jointly determine certain purposes and means of processing with a social media provider, we may act as joint controllers for that limited processing. The provider remains responsible for its own processing activities.

We encourage you to review the privacy settings and privacy policies of each social media platform you use.

13. LINKS TO THIRD-PARTY WEBSITES

Our website may contain links to websites, applications or services operated by third parties.

We are not responsible for the privacy, security or content of third-party services. This Privacy Policy does not apply to personal data collected independently by third parties.

We recommend reviewing the privacy policy of any third-party website or service before providing personal information.

14. DATA SECURITY

We use appropriate technical and organisational measures designed to protect personal data against:

  • unauthorised access;

  • unlawful use or disclosure;

  • accidental loss;

  • destruction;

  • alteration;

  • damage.

These measures may include access controls, password protection, encrypted connections, service provider assessments, secure payment processing, backups and internal data protection procedures.

However, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security.

You are responsible for maintaining the confidentiality of your account credentials and should notify us promptly if you suspect unauthorised access to your account.

15. PERSONAL DATA OF CHILDREN

Our website and services are not directed to children under the age of 16, and we do not knowingly collect personal data directly from children below this age.

If you believe that a child has provided personal data to us without appropriate parental or guardian authorisation, please contact us at natalie@aroundjewellery.com. We will take appropriate steps to investigate and delete the information where required.

16. COMPLAINTS TO A SUPERVISORY AUTHORITY

If you believe that our processing of your personal data violates applicable data protection law, you have the right to lodge a complaint with a competent supervisory authority.

Because our business is established in Poland, you may contact:

President of the Personal Data Protection Office
Prezes Urzędu Ochrony Danych Osobowych (UODO)
ul. Stanisława Moniuszki 1A
00-014 Warsaw
Poland

You may also lodge a complaint with the data protection authority in the EU or EEA country where you habitually reside, work or where the alleged infringement occurred.

We encourage you to contact us first at natalie@aroundjewellery.com so that we have an opportunity to address your concerns.

17. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time to reflect:

  • changes to our practices;

  • new website functions or service providers;

  • changes to Shopify applications;

  • legal or regulatory requirements;

  • operational or business changes.

The current version will always be published on this page. The “Last updated” date at the top of the Privacy Policy indicates when the most recent changes were made.

Where required by law, we will provide additional notice or request renewed consent before materially changing how we process personal data.

18. CONTACT US

For questions, requests or complaints relating to privacy or personal data, please contact:

NATALIIA BONDARENKO

Kolejowa 9/78

01-217 Warszawa, Poland

NIP: 5273210265

REGON: 544268106

Email: natalie@aroundjewellery.com

Telephone: +48 451 145 739

Website: https://aroundjewellery.com