Privacy policy

Privacy Policy

Last updated: May 2026

1. Introduction and Data Controller

This Privacy Policy explains how Podium Trend Store collects, uses, stores, and protects your personal data when you visit our website or purchase from us. It complies with the General Data Protection Regulation (EU) 2016/679 (GDPR), the UK GDPR, and the EU ePrivacy Directive.

Data Controller: Podium Trend Store — Portugal Email: contact@podiumtrendstore.com Phone: +351 938 599 203

2. What Data We Collect

Data you provide directly: full name, delivery and billing address, email address, phone number, payment details (full card data is processed by our payment processor — not stored by us), and any correspondence sent to us.

Data collected automatically: IP address, browser type and version, operating system, pages visited, time spent on the site, date and time of access, cookie identifiers and device identifiers.

Data from third parties: limited data from payment processors, couriers, and Shopify relating to order fulfilment and tracking.

3. Legal Basis for Processing (GDPR Article 6)

Processing and fulfilling your order — performance of a contract. Sending order confirmation and shipping updates — performance of a contract. Legal obligations (tax records, accounting) — legal obligation. Marketing emails (opted-in only) — consent. Analysing website traffic — legitimate interests. Fraud prevention and security — legitimate interests.

Where we rely on legitimate interests, you may object at any time. Where we rely on consent, you may withdraw it at any time.

4. How We Use Your Data

  • Order fulfilment: processing payment, dispatching orders, sending shipping and delivery updates
  • Customer service: responding to enquiries, processing returns and refunds
  • Legal compliance: maintaining accounting and tax records as required by Portuguese and EU law
  • Marketing: if you have opted in, sending newsletters and promotional offers — you can unsubscribe at any time
  • Website improvement: analysing how visitors use our site
  • Fraud prevention: detecting and preventing fraudulent transactions

We do not use your personal data for automated decision-making or profiling that produces legal effects.

5. Data Sharing

We do not sell your personal data. We share it only where necessary:

  • Shopify Inc. — our website platform, acting as a data processor under a GDPR-compliant Data Processing Agreement
  • Payment processors (such as Stripe or Shopify Payments) — solely to authorise transactions
  • Couriers and logistics providers — your name, delivery address, and contact details for delivery purposes
  • Legal and regulatory authorities — where required by applicable law

Where personal data is transferred outside the EEA or UK, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs).

6. Cookies and Tracking Technologies

Strictly necessary cookies: essential for the website to function. Cannot be disabled. Functional cookies: remember your preferences such as language or currency. Analytics cookies: help us understand how visitors interact with our website (e.g. Google Analytics). Marketing cookies: used to deliver relevant advertisements — placed only with your explicit consent.

When you first visit our website, you will be shown a cookie consent banner where you may accept all cookies, reject non-essential cookies, or manage your preferences.

7. Data Retention

Order and transaction data: minimum 7 years (Portuguese and EU tax law). Customer account data: duration of account plus a reasonable period thereafter. Marketing data: until consent is withdrawn or you unsubscribe. Website analytics: typically within 14 months. Support correspondence: up to 3 years from close of enquiry.

8. Your Rights Under GDPR and UK GDPR

  • Right of Access: receive a copy of the data we hold about you
  • Right to Rectification: request correction of inaccurate data
  • Right to Erasure: request deletion of your data in certain circumstances
  • Right to Restriction: request that we restrict processing in certain situations
  • Right to Data Portability: receive your data in a machine-readable format
  • Right to Object: object to processing based on legitimate interests or direct marketing
  • Right to Withdraw Consent: withdraw consent at any time without affecting prior processing

To exercise any of these rights, contact us at contact@podiumtrendstore.com. We will respond within 30 calendar days.

9. Right to Lodge a Complaint

EU customers (Portugal): Comissão Nacional de Proteção de Dados (CNPD) — www.cnpd.pt

UK customers: Information Commissioner's Office (ICO) — www.ico.org.uk

10. Security

We implement appropriate technical and organisational measures to protect your personal data, including SSL/TLS encryption and access controls. We work only with processors who provide sufficient security guarantees.

11. Changes to This Policy

We may update this policy periodically. When we make material changes, we will update the "Last updated" date.

Contact: contact@podiumtrendstore.com | +351 938 599 203