[01] Legal

Privacy Policy

SSCS SERVICES LTD ("SOXIE365", "we", "us") is the controller of the personal data described below. This policy explains what we collect, why, how long we keep it, and the rights you can exercise — under the EU GDPR, the UK GDPR, and US state privacy laws such as the CCPA/CPRA.

Last updated: 21 August 2026

1. Who we are

Controller: SSCS SERVICES LTD, Amathountos 59, Kypriopoulos Court B, 4532, Agios Tychonas, Limassol, Cyprus. Company number HE 393290. VAT 1039329OU.

Privacy contact: info@soxie365.com. We have not appointed a Data Protection Officer, as we are not required to.

2. What we collect

  • Order data: name, email address, billing and shipping address, chosen variant, order reference, amount paid, and delivery status.
  • Payment data: processed directly by Stripe. We never receive or store your full card number, CVC, or bank credentials — only the last four digits, card brand and payment outcome.
  • Communications: messages you send us by email and our replies.
  • Analytics data (consent-based): pages viewed, approximate location at country/city level, device and browser type, and referring source, collected via Google Analytics 4 only after you accept analytics cookies.
  • Technical logs: IP address, timestamps and error diagnostics generated by our hosting provider for security and troubleshooting.

We do not knowingly collect data from children under 16, and we do not collect special category data or sell personal data.

3. Why we use it and our legal basis

  • To fulfil your order — payment, shipping, order confirmation and service emails. Legal basis: performance of a contract (GDPR Art. 6(1)(b)).
  • To meet tax, VAT, customs and accounting obligations. Legal basis: legal obligation (Art. 6(1)(c)).
  • To secure the site and prevent fraud or chargeback abuse. Legal basis: legitimate interests (Art. 6(1)(f)).
  • To measure how the site is used via analytics cookies. Legal basis: consent (Art. 6(1)(a)), withdrawable at any time.

We do not use your data for automated decision-making that produces legal effects, and we do not run profiling-based advertising.

4. Who we share it with

We share data only with processors that help us run the store:

  • Stripe — payment processing, fraud prevention and payment receipts.
  • Lovable Cloud / Supabase — application hosting, database and email delivery.
  • Google Analytics — website analytics, only with your consent.
  • Shipping and customs partners — name, address and phone number needed to deliver and clear your parcel.

We may also disclose data where required by law, or as part of a merger or acquisition. We never sell or rent your personal data, and we do not share it for cross-context behavioural advertising.

5. International transfers

Some providers process data outside the EEA/UK, including in the United States. Those transfers rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and — where applicable — the provider's certification under the EU–US Data Privacy Framework, together with appropriate technical safeguards such as encryption in transit.

6. How long we keep it

  • Order, invoice and tax records: 7 years, as required by accounting law.
  • Support emails: 24 months from the last message.
  • Analytics data: 14 months, then deleted or aggregated.
  • Server and security logs: up to 12 months.

7. Your rights

If you are in the EEA or UK you may request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interests. Where processing is based on consent, you can withdraw it at any time without affecting prior processing.

If you are a California, Colorado, Connecticut, Virginia, Texas or other US state resident, you may request to know, delete, or correct your personal information, opt out of any sale or sharing (we do neither), and are entitled to non-discrimination for exercising those rights. Authorised agents may submit requests on your behalf with proof of authorisation.

To exercise any right, email info@soxie365.com. We respond within 30 days (45 days for US state requests, extendable once where permitted). You also have the right to lodge a complaint with your local data protection authority.

8. Security

Traffic is encrypted with TLS, payments are handled entirely inside Stripe's PCI-DSS certified environment, and access to order data is limited to the people who need it to fulfil your order. No system is perfectly secure, but we notify affected users and the relevant authority without undue delay if a breach is likely to create a risk to you.

9. Changes

We update this policy when our processing changes. The version date at the top always reflects the current version, and material changes are announced on this page.