Privacy policy
Privacy and Cookie Policy — www.raydanperfumes.shop
Version CO-2026-10-06-03. Last updated: 6 October 2026. This notice applies from publication and does not retrospectively authorise processing.
1. Controller and contact
The seller of goods purchased through www.raydanperfumes.shop is Commercium Omaniae, UAB, a Lithuanian private limited company, company code 304031448 (the “Seller”, “we”, “us” or “our”). VAT number: LT100012229211. Registered office: Antanavos g. 9-17, LT-46273 Kaunas, Lithuania. Email: info@raydanperfumes.shop; telephone: +370 698 39257. The Seller operates this online shop and resells goods purchased from suppliers. Product trademarks belong to their respective owners; references to a brand do not make its owner or manufacturer a party to the retail sales contract.
Commercium Omaniae, UAB is the controller where it determines the purposes and means of the processing described here. Contact info@raydanperfumes.shop or the registered office for privacy enquiries and rights requests. Shopify, payment providers and carriers may act as independent controllers for their own services; their applicable privacy notices explain that processing.
2. Information, sources and purposes
We process information relevant to your interaction with the shop: name and contact details; billing and delivery addresses and nominated recipients; order items, prices, payment status and transaction references; account information where an account is used; correspondence, return and complaint information; and necessary delivery records, including tracking, recipient signatures and collection or delivery instructions. A payment provider processes payment credentials under its own arrangements; do not send card numbers or security codes to our support email.
Information comes from you, people placing or receiving an order on your behalf, Shopify, payment providers, carriers and authorities where relevant. Technical information may include IP address, device or browser information, security logs and consent settings. Optional analytics, advertising identifiers and email-interaction information are processed only where the feature is used and the necessary legal basis and consent requirements are satisfied.
Provide only information needed for the enquiry. In particular, avoid sending unnecessary identity documents, passwords or medical information. If you name another recipient, give accurate details, have a lawful basis to provide them, and inform the person about the delivery and this notice. This does not transfer our own controller responsibilities to you.
3. Legal bases
- Contract and pre-contractual steps — GDPR Article 6(1)(b): handling your order, payment, delivery, customer account where requested, withdrawal and contractual support.
- Legal obligations — Article 6(1)(c): accounting and tax records, statutory consumer procedures, regulatory cooperation and other applicable legal duties.
- Legitimate interests — Article 6(1)(f): proportionate security, fraud prevention, service administration and establishing, exercising or defending legal claims, after assessing necessity and balancing your rights. For a nominated third-party recipient who is not a contracting party, necessary delivery-contact processing is assessed on this basis or another applicable basis, rather than treating that person as our contractual customer.
- Consent — Article 6(1)(a): electronic marketing, optional tracking and other processing where consent is required. Sales-terms acceptance is not marketing or tracking consent.
Providing information necessary to perform an order or meet legal requirements is needed for that transaction. Optional marketing and tracking choices are voluntary; refusal does not prevent an ordinary purchase. Consent may be withdrawn at any time without affecting the lawfulness of earlier consent-based processing.
4. Marketing and cookies
Marketing messages require consent where applicable law requires it. Any existing-customer exception is used only if all legal conditions are met, including the required opportunity to object when details are collected and in every message. Unsubscribe using the message link or contact us. Transactional order, delivery and complaint messages are separate from promotional marketing.
Strictly necessary cookies support requested functions such as the cart, checkout, authentication, security and recording privacy choices. Consent is required before non-essential analytics or advertising cookies and comparable technologies are activated where the law requires it. You must be able to reject optional categories and withdraw consent as easily as you gave it. Browser settings are an additional control, not a substitute for the legally required choice mechanism. A privacy-policy statement does not constitute consent.
The information in the shop's consent controls must identify the optional purposes and providers actually used and the applicable cookie lifetimes or criteria. Shopify's cookie information is available at shopify.com/legal/cookies. It does not by itself describe every additional integration. If you cannot access a privacy control, contact us at info@raydanperfumes.shop. Valid browser opt-out preference signals, including Global Privacy Control, will be honoured where applicable law requires this; no claim is made that every browser signal or feature is supported in every jurisdiction.
5. Recipients and delivery or payment evidence
Necessary information is disclosed to Shopify as the shop platform, payment providers, carriers such as DHL where selected, fulfilment and technical service providers, and authorities where required. Professional advisers, insurers and payment-dispute handlers may receive proportionate information needed for a claim. Optional analytics and advertising providers receive information only under an appropriate legal basis and required consent. Access is limited to the relevant purpose; a dispute does not permit unrestricted disclosure.
Relevant claim evidence may include the accepted order details and policy version, payment verification, the nominated address and receiving instructions, customer communications, carrier tracking, recipient role, signature and other delivery records. We use this information to investigate, prevent fraud and defend legitimate claims, without overriding privacy rights or the legal burden of proof. Service-provider data-processing arrangements and controller-to-controller disclosures must comply with applicable law.
A lawful business reorganisation or transaction may require limited disclosure under confidentiality and an appropriate legal basis, with notice where required. Product brand owners are not automatically entitled to our customer data merely because we resell their goods.
6. International transfers
Shopify, payment or technical providers and an international delivery destination may involve processing outside the EEA. Transfers requiring GDPR safeguards must use an applicable adequacy decision or appropriate safeguards, such as approved standard contractual clauses with supplementary measures where necessary. A narrowly applicable statutory derogation for a requested international transaction may be used only when its legal conditions are met and only for the necessary information. Contact us for relevant transfer and safeguard information or a copy of the applicable safeguard, subject to protection of legitimate confidential information.
7. Retention and security
Retention is determined by the purpose and applicable legal requirements. Accounting and tax records are kept for their statutory periods. Order, delivery, consent and complaint evidence is kept for the necessary contractual, statutory guarantee and legal-claim periods; an active dispute or legal hold may require longer retention. Account information is retained while needed for the account and subsequently only for a lawful continuing purpose. Marketing information is retained while the relevant permission or lawful exception applies, with a minimal suppression record where needed to respect an opt-out. Optional tracking data follows the disclosed lifetime and purpose. Records no longer lawfully needed are deleted or effectively anonymised.
We must apply appropriate technical and organisational safeguards proportionate to the risks, restrict access and comply with applicable breach-notification duties. No statement about unavoidable security risk excludes statutory responsibility. Keep account credentials secure and report suspected misuse promptly; an account compromise does not automatically establish that the customer is liable for every resulting transaction.
8. Rights and requests
Where GDPR applies, you may request access and a copy, correction, erasure, restriction and portability under the applicable conditions. You may object to processing based on legitimate interests; continued processing requires the applicable legal justification. You may object to direct marketing at any time, including related profiling. You may withdraw consent and raise rights relating to qualifying solely automated decisions. If such a decision is used, required information and safeguards must be supplied; this policy does not itself authorise one.
Send requests to info@raydanperfumes.shop. We may seek proportionate verification where there is reasonable doubt about identity or an agent's authority. We respond without undue delay and normally within one month; a legally justified extension of up to two further months for complex or numerous requests will be explained within the first month. Ordinary requests are free. Any refusal or reasonable fee must meet the legal criteria and be explained. Erasure does not require deletion of records that must lawfully be retained; legal-claim retention is limited to information genuinely needed.
Where another applicable privacy law grants additional rights, including rights concerning defined sale, sharing or targeted advertising, you may exercise them through the available privacy controls or our email. Definitions, eligibility and applicable legal conditions govern those rights. Optional consent is not a blanket authorisation to sell personal information.
9. Complaints, children and changes
You may complain to the Lithuanian State Data Protection Inspectorate, vdai.lrv.lt, or another competent supervisory authority. Contacting us first is encouraged but is not a condition of a statutory complaint.
The shop is not directed at children. Purchases require the legal capacity described in the Terms of Sale. If you believe a child has provided information without an appropriate legal basis, contact us so it can be addressed.
Independent linked websites have their own privacy arrangements; merely linking does not authorise them to process our customer data or relieve us of our own obligations. We will publish updated notices and give additional notice or obtain new consent where required. Changes do not retrospectively create consent or remove accrued rights.