Privacy policy

Privacy Policy

1. Introduction and Scope

1.1. This Privacy Policy (hereinafter – the Policy) sets out how UAB “Groomica” (hereinafter – We, the Company or the Data Controller) collects, uses, stores, and processes personal data when customers (hereinafter – You, the Customer) use our online store www.groomica.eu and other related services.

1.2. The Policy applies in all cases when you visit our website, purchase products, communicate with us via email, phone, through social networks, or subscribe to our newsletters.

1.3. Personal data means any information that can directly or indirectly identify a natural person, such as: name, surname, email address, telephone number, IP address, order history.

1.4. In processing personal data, we comply with:

  • The General Data Protection Regulation (EU) 2016/679 (GDPR);
  • The Law on Legal Protection of Personal Data of the Republic of Lithuania;
  • The Civil Code of the Republic of Lithuania;
  • The Law on Electronic Commerce;
  • Other applicable legal acts.

1.5. If you do not agree with the provisions of this Policy, please do not use our services or website. Please note that some data (e.g., essential cookies, order data) are mandatory for the performance of the contract and cannot be deleted without terminating our business relationship.

2. Data Controller

2.1. The Data Controller responsible for processing your personal data is:

UAB “Groomica”
Company code: 307092132
VAT code: LT100017601817
Registered office: Pašventės k. 11, Ignalina district, Lithuania
Email: hello@groomica.eu
Website: www.groomica.eu

2.2. We have not appointed an official Data Protection Officer (DPO), but for any questions related to your personal data or this Policy, you may contact us at: hello@groomica.eu

2.3. When submitting a data protection request, please indicate your name, surname, contact details, and the nature of your request so that we can process it promptly and respond within the deadlines set by the GDPR.

3. Data We Collect

3.1. We collect the following categories of your personal data:

3.1.1. Customer account data

  • Name, surname
  • Email address
  • Password (encrypted, not visible to us)
  • Account creation and last login dates

3.1.2. Order data

  • Shopping cart information
  • Delivery address (street, city, postal code, country)
  • Phone number
  • Order history

3.1.3. Payment data (via Shopify Payments)

  • Payment method (card, Apple Pay, Google Pay, etc.)
  • Payment amount, currency
  • Payment status

Note: We do not store or see full card details – they are processed by Shopify Payments in accordance with the highest PCI DSS security standards.

3.1.4. Communication data (via Omnisend and email)

  • Subscription status
  • Email open statistics
  • Click-through data
  • Submitted inquiries, complaints, or feedback

3.1.5. Browsing and device data

  • IP address
  • Browser type and version
  • Device operating system
  • Browsing history on our website
  • Data collected through cookies and pixels

3.1.6. Social media data (Facebook, Instagram, TikTok, YouTube)

  • Information you provide when messaging or commenting on social networks
  • Interaction with our ads (clicks, views, conversions)
  • Advertising campaign performance data

4. Purposes and Legal Bases of Data Processing

4.1. We process your personal data only for clearly defined purposes and based on the legal grounds provided by the GDPR:

4.1.1. Contract performance

  • To accept, process, and deliver orders.
  • To provide customer service (handling inquiries, warranty, returns).
  • To administer payments.

Legal basis: GDPR Art. 6(1)(b) – performance of a contract.

4.1.2. Compliance with legal obligations

  • To issue invoices and maintain accounting records.
  • To retain data as required by law (e.g., 10 years for financial documents).

Legal basis: GDPR Art. 6(1)(c) – legal obligation.

4.1.3. Consent

  • To send newsletters, offers, and promotions (via Omnisend).
  • For marketing activities on Facebook, Instagram, TikTok, Google Ads.
  • For analytical and marketing cookies.

Legal basis: GDPR Art. 6(1)(a) – consent.

4.1.4. Legitimate interests

  • To improve our website, services, and customer experience.
  • For direct marketing to existing customers (where permitted by law).
  • To prevent misuse, fraud, or abuse.

Legal basis: GDPR Art. 6(1)(f) – legitimate interests.

5. Data Sharing with Third Parties

5.1. We do not sell or disclose your personal data to third parties except in the cases listed below, where this is necessary for service provision or compliance with legal obligations.

5.2. Service providers and partners

  • Shopify – e-commerce platform ensuring the operation of the store.
  • Shopify Payments – for payment processing and secure transactions.
  • DPD, FedEx, and other couriers – for order delivery.
  • Omnisend – for newsletters, SMS, and automated messages.
  • Google (Google Analytics, Google Ads) – for website analytics and advertising.
  • Meta (Facebook, Instagram) – for social media marketing and advertising campaigns.
  • TikTok – for advertising campaigns.
  • YouTube – for video content distribution and advertising.

5.3. All service providers process data only to the extent necessary for their functions and may not use it for their own purposes.

5.4. Legal requirements: We may disclose your data to government authorities or law enforcement agencies if required by law or official requests (e.g., courts, tax authorities).

5.5. Data transfers outside the European Union

Some of our partners (e.g., Shopify, Meta, Google) are located outside the EU (in Canada, the US). In such cases, we ensure that data is transferred only under appropriate safeguards, such as the European Commission’s Standard Contractual Clauses (SCC) or certification under the EU–US Data Privacy Framework.

6. Cookies and Tracking Technologies

6.1. Our website uses cookies and other tracking technologies (e.g., Facebook Pixel, Google Analytics) to improve website functionality, analyze visitor behavior, and deliver targeted advertising.

6.2. Types of cookies we use:

  • Essential cookies – ensure proper website functionality (e.g., cart, checkout). These cannot be disabled.
  • Analytical cookies – help us understand how visitors use the site and improve its performance (e.g., Google Analytics).
  • Marketing cookies – used to display targeted advertising based on your browsing habits (e.g., Facebook Pixel, TikTok Pixel, Google Ads).
  • Functional cookies – allow us to remember your preferences (e.g., language, login).

6.3. Cookie management

  • When you first visit the site, you are presented with a cookie consent notice, where you can choose which cookies to allow.
  • You can change cookie settings in your browser at any time and delete already stored cookies.
  • Please note that disabling some cookies may affect website functionality or make certain features unavailable.

6.4. Third-party cookies
Our website may also use third-party cookies (e.g., YouTube embedded video viewing). In such cases, the relevant service providers are responsible for their functioning.

7. Automated Decision-Making and Profiling

7.1. We may use automated data analysis (profiling) in order to:

  • Show you personalized offers;
  • Adjust advertising based on your browsing history and purchasing habits;
  • Analyze customer behavior to better understand needs.

7.2. We use profiling tools such as Google Ads, Meta (Facebook/Instagram) Ads (Meta Pixel), TikTok Pixel, and Omnisend.

7.3. Automated decision-making does not produce legal effects or significantly affect you. It is used only for marketing and communication purposes to provide you with more relevant information.

7.4. You have the right to object to profiling. You can do this by disabling marketing cookies, unsubscribing from newsletters (by clicking “unsubscribe” in the email), or contacting us at hello@groomica.eu.

8. Data Retention Periods

8.1. We retain your personal data only as long as necessary to achieve the purposes set out in this Policy, but no longer than required by applicable laws.

8.2. Data retention by category:

  • Customer account data – stored while the account is active, and for 2 years after closure, unless longer retention is required by law.
  • Order and payment data – stored for 10 years from the date of financial document issuance (under Lithuanian law).
  • Communication data (inquiries, complaints, emails) – stored for 3 years from the last correspondence.
  • Marketing data (newsletter subscriptions, profiling) – stored until consent is withdrawn or for 5 years after the last interaction.
  • Cookie data – stored according to the cookie’s validity period (from end of session up to 2 years).

8.3. After the retention periods expire, personal data is securely deleted or anonymized so it can no longer be linked to an identifiable person.

8.4. If data is required for resolving legal disputes or defense, it may be retained longer until the relevant process is completed.

9. Data Security Measures

9.1. We implement appropriate technical and organizational measures to protect your personal data against unlawful or accidental destruction, alteration, disclosure, loss, or any other unlawful processing.

9.2. Technical measures:

  • Data encryption using SSL (HTTPS).
  • Server protection against hacking, antivirus protection.
  • Database backups.
  • Shopify Payments protection compliant with PCI DSS standards.

9.3. Organizational measures:

  • Access to data is granted only to employees who need it to perform their work duties.
  • Regular employee training on data protection.
  • Internal data protection policies and controls.

9.4. Despite our efforts, no system or transmission method over the internet is completely secure. Therefore, we cannot guarantee absolute security, but we ensure that all legally required measures are applied to minimize risk.

10. Your Rights

Under the GDPR, you have the following rights:

  • Right to information – to receive clear and transparent information about how your data is processed.
  • Right of access – to obtain a copy of your personal data processed by us.
  • Right to rectification – to request correction of inaccurate or incomplete data.
  • Right to erasure (“right to be forgotten”) – to request deletion of your data when it is no longer needed or when processing was based on consent you have withdrawn.
  • Right to restrict processing – to request limitation of data processing in certain cases.
  • Right to object – to object to data processing based on our legitimate interests or for direct marketing.
  • Right to data portability – to receive your data in a structured, commonly used format and transmit it to another provider.
  • Right to withdraw consent – where data processing is based on your consent (e.g., newsletters), you may withdraw it at any time.
  • Right to lodge a complaint – if you believe your rights have been violated, you may lodge a complaint with the State Data Protection Inspectorate (VDAI) or your national supervisory authority.

11. Complaints and Supervisory Authorities

11.1. If you believe that we are processing your personal data unlawfully or violating your rights, please contact us first at hello@groomica.eu. We undertake to review all complaints and respond within 30 calendar days.

11.2. If you are not satisfied with our response or believe that your rights and interests have been infringed, you may lodge a complaint with:

State Data Protection Inspectorate (VDAI)
Email: ada@ada.lt
Website: www.ada.lt

11.3. You also have the right to apply to your country’s supervisory authority (if you reside outside Lithuania) or lodge a complaint with a European supervisory authority.

11.4. This provision does not limit your right to seek other legal remedies, such as bringing a claim before a court.

12. Updates to the Privacy Policy

12.1. We reserve the right to update or amend this Privacy Policy at any time to reflect changes in legislation, our service conditions, or technological developments.

12.2. The updated version of the Privacy Policy will always be published on our website www.groomica.eu.

12.3. If the changes are significant (e.g., changes to processing purposes or legal bases), we will notify you in advance via email or by other appropriate means.

12.4. We recommend reviewing this Policy periodically to stay informed about how we process your personal data.

12.5. This Privacy Policy was last updated on: 21 September 2025.

Login

Forgot your password?

Don't have an account yet?
Create account