Privacy policy

Caffeiny runs this shop and website, including all related information, content, features, tools, products, and services, to give you a personalised shopping experience (the “Services”). Caffeiny is built on Shopify, which enables us to provide the Services to you. This Privacy Policy explains how we collect, use, or share personal data when you visit or use the website, make a purchase or other transaction through the Services, or otherwise communicate with us. If there is any conflict between our Terms and Conditions and this Privacy Policy, this Privacy Policy takes priority when it comes to collecting, processing, and sharing your personal data.

Please read this Privacy Policy carefully. By accessing or using any of the Services, you confirm that you have read this Privacy Policy and agree to the collection, use, and sharing of your information as described here.

What personal data do we collect or process?

When we use the term “personal data,” we mean information that identifies you (or another person) or can reasonably be linked to you. Personal data does not include information that is collected anonymously or has been anonymised so that it can’t be linked back to you. Depending on how you interact with the Services, where you live, and what applicable law allows or requires, we may collect or process the following categories of personal data, including any inferences drawn from them:

  • Contact details such as your name, postal address, billing address, delivery address, phone number, and email address.

  • Financial details such as credit or debit card and bank account numbers, payment card information, account information, transaction details, payment method, payment confirmation, and other payment-related details.

  • Account information such as your username, password, security questions, preferences, and settings.

  • Transaction information including items you view, add to your basket, wishlist, or purchase, return, exchange, or cancel, as well as your order history.

  • Your communications with us including any information you provide when you contact us, for example by sending a customer support request.

  • Device information including details about your device, browser, or network connection, your IP address, and other unique identifiers.

  • Usage information including how you interact with the Services, including when and how you browse or use them.

Sources of personal data

We may collect personal data from the following sources:

  • Directly from you. For example when you create an account, access or use the Services, contact us, or otherwise provide your personal data.

  • Automatically through the Services. For example from your device when you use our products or Services or visit our website, including through cookies and similar technologies.

  • From our service providers. For example when we hire providers to enable certain technologies, and they collect or process personal data on our behalf.

  • From partners and other third parties.

How do we use your personal data?

Depending on how you interact with us or which Services you use, we may use personal data for the following purposes:

  • Providing, tailoring, and improving the Services. We use your personal data to deliver the Services to you. This includes fulfilling our contract with you, processing payments, completing orders, saving your preferences and items you’re interested in, sending account-related messages, creating and managing your account, arranging shipping, making returns and exchanges easier, letting you leave reviews, and personalising your shopping experience, for example by recommending products based on what you’ve bought. We may also use your data to better customise and improve the Services overall.

  • Marketing and advertising. We use your personal data for marketing and promotional purposes, for example to send marketing messages by email, SMS, or post, and to show you online ads for products or Services on our site or others. This can include ads based on items you’ve previously bought or added to your basket, and other activity connected to the Services.

  • Security and fraud prevention. We use your personal data to verify your account, provide a secure checkout and shopping experience, detect, investigate, or act on potentially fraudulent, illegal, unsafe, or malicious activity, protect public safety, and keep our Services secure. If you register an account, you’re responsible for keeping your login details safe. We strongly recommend that you don’t share your username, password, or other access details with anyone.

  • Communicating with you. We use your personal data to provide customer support and effective service, respond to your requests quickly, and maintain our relationship with you.

  • Legal reasons. We use your personal data to comply with applicable laws or respond to lawful requests, including from law enforcement or regulators, to take part in civil investigations or legal disputes, and to investigate or enforce potential breaches of our terms or policies.

How do we share personal data?

In certain situations, we may share your personal data with third parties for legitimate purposes under this Privacy Policy. This may include:

  • With Shopify and its partners. These are providers and other third parties who perform Services for us, such as IT management, payment processing, analytics, customer support, cloud storage, fulfilment, and shipping.

  • With business and marketing partners. These partners help deliver marketing services and show you ads. For example, we use Shopify to support personalised advertising with third-party services based on your online activity across different merchants and websites. Our business and marketing partners use your data under their own privacy policies. Depending on where you live, you may have the right to tell us not to share information about you for targeted ads or marketing based on your activity across different merchants and sites.

  • When you ask us to or give consent. For example, when it’s needed to deliver products to you, or when you use social media widgets or login integrations.

  • Within our corporate group. We may share personal data with our affiliates or other companies in our group.

  • As part of business transactions or legal obligations. For example in connection with a merger, insolvency, or similar event; to comply with legal duties (including subpoenas, search warrants, and similar requests); to enforce our terms or policies; or to protect or defend the Services, our rights, and the rights of our users or others.

Relationship with Shopify

The Services are hosted by Shopify. Shopify collects and processes personal data about your access to and use of the Services to provide and improve them. Data you submit through the Services is shared with Shopify and with third parties who may be located in countries other than your country of residence, so they can provide and improve the Services for you.

To protect, grow, and improve our business, we also use certain enhanced Shopify features that draw on data from your interactions with our shop, other merchants, and Shopify. To deliver these advanced features, Shopify may use personal data collected from your interactions with our shop, other merchants, and Shopify. In these situations, Shopify is responsible for processing your personal data, including handling requests to exercise your rights regarding Shopify’s use of your personal data for these purposes. More details about how Shopify uses personal data and your rights can be found in Shopify’s Consumer Privacy Policy. Depending on where you live, you may be able to exercise certain rights regarding your personal data via Shopify’s Privacy Portal.

Third-party websites and links

The Services may include links to websites or online platforms run by third parties. If you follow links to sites that aren’t our affiliates or under our control, you should review their privacy and security policies and terms. We’re not responsible for the privacy or security of those sites, including the accuracy, completeness, or reliability of information on them.

Information you share in public or semi-public spaces, including on third-party social networks, may be visible to other users of the Services or those platforms, without limits on how they use it. Including these links doesn’t mean we endorse those platforms or their operators unless explicitly stated in the Services.

Children’s data

The Services aren’t intended for children, and we don’t knowingly collect personal data from children who are not legally adults in their country. If you’re a parent or guardian and believe your child has given us personal data, you can contact us using the details below to request deletion. As of the effective date of this Privacy Policy, we have no knowledge that we “share” or “sell” personal data of anyone under 16 (as those terms are defined by applicable law).

Security and retention of your data

No security measure is perfect, and we can’t promise “perfect security.” Information you send us may also be at risk while in transit. Please avoid using insecure channels when sharing sensitive or confidential information with us.

How long we keep your personal data depends on several factors, such as whether we need it to maintain your account, provide Services, comply with legal obligations, resolve disputes, or enforce other contracts and policies.

Your rights and choices

Depending on where you live, you may have some or all of the rights below regarding your personal data. These rights are not absolute, may apply only in certain situations, and we may refuse requests where legally permitted.

  • Right of access. You may have the right to request access to the personal data we hold about you.

  • Right to deletion. You may have the right to ask us to delete personal data we hold about you.

  • Right to correction. You may have the right to request correction of inaccurate personal data.

  • Right to data portability. You may have the right to receive a copy of your personal data and, in certain cases and with certain exceptions, to have it transferred to a third party.

  • Managing communication preferences. We may send you promotional emails. You can opt out at any time using the unsubscribe option in our emails. Even if you opt out, we may still send non-promotional messages, for example about your account or orders.

If you live in the UK or the European Economic Area, you may also have these rights (subject to local law limits and exceptions):

  • Right to object or restrict processing. You may have the right to ask us to stop or limit processing of your personal data for certain purposes.

  • Withdrawal of consent. If we rely on your consent to process your personal data, you can withdraw it. This won’t affect any processing that took place before you withdrew your consent.

You can exercise these rights where the Services provide relevant options, or by contacting us using the details below. More information about Shopify’s processing and your rights, including rights related to data Shopify processes, is available at https://privacy.shopify.com/en

.

You won’t be treated unfairly for exercising your rights. Where allowed or required by law, we may need to verify your identity before handling your request. You may appoint an authorised agent to act on your behalf. If so, we’ll ask for proof of authorisation and may require you to confirm your identity directly with us. We’ll respond as quickly as the law requires.

Complaints

If you have concerns about how we handle your personal data, please contact us using the details below. Depending on where you live, you may have the right to appeal our decision by contacting us, or to file a complaint with your local data protection authority. For the EEA, a list of supervisory authorities is available online.

International transfers

Your personal data may be transferred to, stored in, and processed in countries outside your country of residence.

If we transfer personal data outside the EEA or the UK, we rely on recognised transfer mechanisms such as the European Commission’s Standard Contractual Clauses or equivalent UK-approved contracts, unless the transfer is to a country that has been officially recognised as providing an adequate level of protection.

Changes to this Privacy Policy

We may update this Privacy Policy from time to time, for example to reflect changes in our practices or for operational, legal, or regulatory reasons. We’ll post the updated version on this website, update the “Last updated” date, and provide any notice required by law.

Contact

If you have questions about our privacy practices or this Privacy Policy, or if you’d like to exercise any of your rights, please contact us by phone, email at office@caffeiny.com or by post at:

Caffeiny
Talgasse 12/3
1150 Vienna
Austria

Under applicable data protection laws, we are the data controller for your personal data.

Cookie Policy

Last updated: 30 October 2025

1. Purpose of cookies

We use cookies and similar technologies to make sure our website works properly, improve your experience, and understand how the site is used.

2. Types of cookies

  • Essential cookies: Always on, and needed for core functions (for example the shopping basket).

  • Analytics cookies: Help us understand site usage and performance (for example via Google Analytics). These are only set after you give consent.

3. Consent

On your first visit, you’ll see a banner asking for cookie consent.

4. Third‑Party Services

We may use Webflow, Stripe, or analytics tools. These third parties may store cookies under their own policies.

5. Data Retention

Cookies are stored for a maximum of 24 months or the period specified in your browser settings.

6. Your Rights

You may withdraw consent or disable cookies via browser settings. 

  • Accept all enables all cookies

  • Decline all blocks non-essential cookies

You can change your choice at any time using the cookie banner or the link in the footer.

4. Third-party services

We may use services like Webflow, Stripe, or analytics tools. These third parties may set cookies under their own policies.

5. Data retention

Cookies are stored for up to 24 months, or for the period you specify in your browser settings.

6. Your rights

You can withdraw your consent or disable cookies at any time in your browser settings.