Privacy policy

This privacy policy applies to the website www.wildspiritapparel.com.

Processing of Personal Data
We process your personal data on this website as follows (for additional processing activities, please refer to the further sections of this privacy policy):

Log Files When Visiting the Website
When you use our website, our hosting provider logs so-called log file data for each server request. This includes the name of the requested website, the previously visited page (referrer URL), product and version information of the browser and operating system used, requesting provider, date and time of access, search engines used, country of access, amount of data transferred, names of downloaded files, and IP address.

The legal basis for this processing is Article 6(1)(f) GDPR. Our legitimate interest in storing log file data lies in ensuring system security, including the investigation of misuse. Log file data is deleted or anonymized after a maximum of 30 days unless it is required for a longer period due to a security-relevant incident (e.g., for investigation or evidence purposes).

Contacting Us
When you contact us, we process personal data such as your name, address, email address, phone number, etc., that we need to respond to your inquiry.

The legal basis for processing your personal data in connection with inquiries is Article 6(1)(b) GDPR, provided your inquiry is aimed at entering into a contract. Otherwise, it is Article 6(1)(f) GDPR, with our legitimate interest being to respond to inquiries.

We retain your personal data as long as necessary to process your inquiry and/or to comply with statutory retention periods.

Registration/Orders
When you register or place an order, we process personal data such as name, address, email address, phone number, date of birth, chosen username, payment details, etc., necessary to perform the contractual relationship with you or to carry out pre-contractual measures at your request.

We retain the personal data collected during registration or ordering as long as necessary to fulfill the contractual relationship (including provision of a customer account, if applicable), carry out pre-contractual measures, fulfill warranty, guarantee, or similar obligations, and/or comply with statutory retention periods.

The legal basis for processing personal data in this context is Article 6(1)(b) GDPR (performance of a contract).

Providing this personal data is not legally or contractually required but is necessary for concluding a contract where the relevant information is mandatory in our registration/order process.

Newsletter
If you subscribe to our newsletter, we process data collected during registration, such as your email address, title, etc., for the purpose of sending you the newsletter.

If processing is based on your consent, the legal basis is Article 6(1)(a) GDPR (consent). Otherwise, it is based on Article 6(1)(f) GDPR (legitimate interests), where our legitimate interests lie in the purposes stated above.

We retain the personal data needed for the newsletter as long as required for this purpose or until you withdraw your consent to receive the newsletter. Any legitimate further retention for other purposes (e.g., customer communication) remains unaffected.

Cookies
Cookies are small text files stored on the user’s device that enable analysis of website usage.

Cookies can make using the website more convenient, enable certain features, or analyze visitor flows.

Where cookies process personal data, processing occurs under Article 6(1)(b) GDPR (performance of a contract), Article 6(1)(a) GDPR (consent), or Article 6(1)(f) GDPR (legitimate interests), with our legitimate interests being the efficient and user-friendly operation of our website.

Cookies may be temporary (session cookies, deleted after closing your browser) or persistent (to recognize returning users). Unless otherwise specified, assume cookies may remain for up to two years. You can revoke consent or object to processing by deleting cookies in your browser settings or configuring your browser to accept cookies only with your consent.

For advertising cookies, you can also block/manage them via:
www.aboutads.info/choices/
www.youronlinechoices.com/uk/your-ad-choices/
www.networkadvertising.org/managing/opt_out.asp

If you refuse cookies, certain features of the site may not function properly.

Google Analytics
This website uses Google Analytics, a web analytics service by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google may transfer your data to servers worldwide, relying on the EU-U.S. Data Privacy Framework or the EU Standard Contractual Clauses. For details: https://policies.google.com/privacy/frameworks
Google’s privacy policy: https://policies.google.com/privacy

If based on consent, the legal basis is Article 6(1)(a) GDPR. Otherwise, it is based on Article 6(1)(f) GDPR (legitimate interests), with our legitimate interests lying in the purposes above.

You can prevent Google Analytics from collecting and processing data about your use of the website by installing the browser plugin available at: https://tools.google.com/dlpage/gaoptout?hl=en

Data Subject Rights
Under Articles 15–20 GDPR, you have the right to:
Access your personal data (right of access)
Rectify or erase inaccurate personal data (right to rectification/right to erasure)
Restrict processing under certain conditions (right to restriction of processing)
Receive your data and transfer it to another controller (right to data portability)
You also have the right to withdraw consent at any time (see below) and the right to object to processing based on legitimate interests (see below).
Additionally, you have the right to lodge a complaint with the competent supervisory authority.

Withdrawal of Consent
You can withdraw your consent to the processing of your personal data at any time, e.g., by emailing us at the above address. The lawfulness of processing before withdrawal remains unaffected.

Right to Object
Where processing is based on Article 6(1)(f) GDPR (legitimate interests), you have the right under Article 21 GDPR to object to the processing of your personal data.

Data Sharing
Unless otherwise stated above, we share your personal data with the following recipients/categories of recipients:

Printify: https://www.printify.com/

We also operate our online store using Shopify’s software and servers, which process data worldwide, including in Canada and the U.S. Shopify’s privacy policy (including details on international data transfers) is available at: https://www.shopify.com/legal/privacy

Controller
The controller for processing your personal data is:
Khaos Designs OG
Ragnitzstraße 198b, 8047 Graz, Austria
Email: hello@wildspiritapparel.com

Data Protection Officer
If you have any questions or concerns regarding our privacy practices, you may contact our data protection officer at the email address above.

If you’d like, I can also format this nicely as a ready-to-publish document or help draft a shorter version for your website footer. Let me know!