Privacy Policy

1) Introduction and Controller Contact Details

1.1 Thank you for visiting our website and for your interest. Below we explain how your personal data is handled when using our website. “Personal data” means any data that can be used to identify you personally.

1.2 The controller responsible for data processing on this website, in accordance with the UK GDPR, is:

VELAROA LTD
71–75 Shelton Street
Covent Garden
London, WC2H 9JQ
United Kingdom
Email: service.premfit@gmail.com

1.3 This website uses SSL or TLS encryption for security and to protect the transmission of personal data. You can recognize an encrypted connection by the “https://” prefix in your browser's address bar and the lock icon.


2) Data Collection When Visiting Our Website

When using our website for informational purposes only (i.e., not registering or submitting information), we only collect the data your browser transmits to our server ("server log files"). These include:

  • visited pages

  • date and time of access

  • amount of data transferred

  • referring source/URL

  • browser used

  • operating system used

  • IP address (possibly in anonymized form)

The data is processed under Article 6(1)(f) UK GDPR based on our legitimate interest in ensuring stability and functionality. Data is not shared or used otherwise.


3) Hosting & Content Delivery Network

Our website is hosted by:

Shopify International Limited
Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland

Data may also be shared with affiliated entities:

  • Shopify Inc., 150 Elgin Street, Ottawa, ON K2P 1L4, Canada

  • Shopify Data Processing (USA) Inc.

  • Shopify Payments (USA) Inc.

We have a Data Processing Agreement (DPA) with Shopify, including Standard Contractual Clauses to ensure UK GDPR-compliant processing.


4) Cookies

Our website uses cookies to enable key features and improve your experience. These include session cookies (deleted after your visit) and persistent cookies (stored on your device).

If cookies process personal data, processing is based on:

  • Art. 6(1)(b) UK GDPR (contract performance)

  • Art. 6(1)(a) UK GDPR (consent)

  • Art. 6(1)(f) UK GDPR (legitimate interests)

You can configure your browser to notify you of cookies, allow them case-by-case, disable them, or auto-delete on exit.


5) Contacting Us

When you contact us (e.g., via email or contact form), personal data is collected based on the form used. This data is used solely for handling your inquiry under Art. 6(1)(b) or (f) UK GDPR.


6) Newsletter Subscription

If you subscribe to our newsletter, we use your email to send you promotional content. Emails are sent via:

Klaviyo
225 Franklin St, Boston, MA 02110, USA

We use a double opt-in process. You may unsubscribe at any time via the link in the email. Processing is based on your consent (Art. 6(1)(a) UK GDPR).
Klaviyo uses Standard Contractual Clauses for GDPR compliance.


7) Data Processing for Order Fulfilment

To process your order, we share data with payment providers as needed:

  • PayPal (Europe) S.à r.l. et Cie, S.C.A.

  • Shopify Payments via Stripe Payments Europe Ltd.

Processing is based on Art. 6(1)(b) UK GDPR. Creditworthiness checks may be based on Art. 6(1)(f) UK GDPR.


8) Analytics & Marketing Tools

Facebook Pixel
We use Meta (Facebook) Pixel with advanced matching to measure conversions and build audiences. Processing only occurs with your consent under Art. 6(1)(a) UK GDPR.

TikTok Pixel
Used for ad personalization and tracking. Processing also based on Art. 6(1)(a) UK GDPR with prior consent.


9) Your Rights

You have the right to:

  • Access (Art. 15 UK GDPR)

  • Rectification (Art. 16)

  • Erasure (Art. 17)

  • Restriction of processing (Art. 18)

  • Data portability (Art. 20)

  • Withdraw consent (Art. 7(3))

  • Lodge a complaint with a supervisory authority (Art. 77)


10) Right to Object

If your data is processed under Art. 6(1)(f) UK GDPR, you have the right to object at any time for reasons arising from your particular situation.
You may also object at any time to processing for direct marketing purposes.


11) Data Retention

Data is stored according to statutory retention periods and deleted afterward unless required for contract performance.
Data processed based on consent is stored until consent is withdrawn.


12) Final Note

This Privacy Policy is compliant with the UK GDPR and Data Protection Act. Updates may occur due to legal or operational changes. The current version is always available on our website.