Privacy Protocol
Data Controller: Colceriu Ana-Maria-Stefana P.F.A.
Trading as: Victorian Shadows
01. Data Acquisition (GDPR)
We process personal data under the legal basis of "Contractual Necessity" to fulfill your orders, and "Legitimate Interest" for fraud prevention. This includes your name, email, shipping address, and order history. If you choose to create a secure account in the future, your authentication credentials will also be securely stored. Data is processed only for the duration required by Romanian fiscal law (up to 10 years for invoice records).
02. Payment Processing
Victorian Shadows does not extract, process, or store raw credit card numbers. All financial transactions and portal authentications are handled securely off-site by Stripe. We only receive confirmation tokens, fraud risk signals, and necessary fulfillment data via encrypted webhooks.
03. Third-Party Infrastructure
We utilize Stripe for financial routing and Supabase for cloud database infrastructure. By utilizing this site, you acknowledge that your data may be processed outside the European Economic Area (EEA). This transfer is legally protected by Standard Contractual Clauses (SCCs) and enterprise-grade encryption.
04. Cookie Protocol
Our architecture deploys strictly necessary functional cookies for session handling, cart preservation, and Stripe checkout security. We do not deploy third-party advertising trackers, marketing pixels, or sell your data to external brokers.
05. Developer Limitation of Liability
The original software developers and technical architects of this platform act strictly as third-party builders. They are not Data Controllers or Data Processors under GDPR. They have no ongoing access to production databases, customer information, or order data, and hold zero legal liability for the operational data privacy compliance of Victorian Shadows.
06. Your Statutory Rights
Under the General Data Protection Regulation (GDPR), you possess the right to access, rectify, export, or permanently erase your personal data. To exercise these rights, or to lodge a formal complaint with the ANSPDCP (Romania), please contact our studio via the official channels provided in our contact portal.
07. Technical Provider Disclosure
The technical infrastructure provider acts only as a builder. All business policies, data handling practices, and legal compliance are dictated by the Site Owner. By operating this site, the Owner accepts full responsibility for the privacy of user data and the operational conduct of the platform.