PERSONAL DATA PROCESSING

The personal data controller of the online store pit-stop.ee is OÜ Pit-Stop Rehvid (registration code 11676806) located at Punane tn 48, Tallinn 13619, Estonia, phone +372 6339 200 and e-mail epood@pit-stop.ee.< /p>

In order to make payments, we transfer the necessary personal data to the authorized processor Maksekeskus AS.

What personal data is processed

  • name, telephone number and e-mail address;
  • Bank account number;
  • cost of goods and services and data related to payments (purchase history);
  • customer support details.

For what purpose is personal data processed

Personal data is used to manage customer orders and deliver goods.

Purchase history data (purchase date, product, quantity, customer data) is used to compile an overview of purchased goods and services and to analyze customer preferences.

The bank account number is used to return payments to the customer. Personal data such as e-mail, phone number, customer name are processed in order to resolve issues related to the provision of goods and services (customer support).

The online store user's IP address or other network identifiers are processed for the provision of the online store as an information society service and for online usage statistics.

Legal basis

Personal data is processed for the purpose of fulfilling the contract concluded with the customer. Personal data is processed to fulfill a legal obligation (e.g. accounting and consumer dispute resolution).

Recipients to whom personal data is transferred

Personal data is transferred to the customer support of the online store to manage purchases and purchase history and solve customer problems.

If the online store's accounting is done by a service provider, personal data will be transferred to the service provider for accounting operations.

Personal data may be transferred to information technology service providers if this is necessary to ensure the functionality of the online store or data hosting.

Security and data access

Personal data is stored on Zone.ee servers, which are located on the territory of a member state of the European Union or countries that have joined the European Economic Area. Data may be transferred to countries whose level of data protection has been assessed as adequate by the European Commission and to US companies that are affiliated with the Privacy Shield framework.

Employees of the online store have access to personal data, who can access personal data in order to solve technical issues related to the use of the online store and to provide customer support services.

The online store implements appropriate physical, organizational and IT security measures to protect personal data from accidental or unlawful destruction, loss, alteration or unauthorized access and disclosure.

The transfer of personal data to authorized processors of the online store (e.g. transport service provider and data hosting) is carried out on the basis of contracts concluded with the online store and authorized processors. Authorized processors are obliged to ensure appropriate protection measures when processing personal data.

Introduction and correction of personal data

Personal data can be viewed and corrected in the user profile of the online store. If the purchase has been made without a user account, you can consult the personal data through customer support.

Withdraw consent

If the processing of personal data takes place on the basis of the customer's consent, the customer has the right to withdraw the consent by notifying the customer support by e-mail

Preservation

When closing the customer account of the online store, personal data is deleted, except if such data needs to be kept for accounting purposes or to resolve consumer disputes.

If a purchase is made in the online store without a customer account, the purchase history is stored for three years.

In case of disputes related to payments and consumer disputes, personal data will be stored until the claim is fulfilled or until the end of the limitation period.

Personal data necessary for accounting is stored for seven years.

Delete

To delete personal data, you must contact customer support by e-mail. The deletion request will be answered no later than within a month and the data deletion period will be specified.

Direct Marketing Notices

The e-mail address and phone number are used to send direct marketing messages if the customer has given their consent. If the customer does not wish to receive direct marketing messages, he must select the corresponding reference in the footer of the e-mail or contact customer support

Dispute Resolution

Disputes related to the processing of personal data are resolved through customer support (tel: +372 6339 200, e-mail: epood@pit-stop.ee). The supervisory authority is the Estonian Data Protection Inspectorate (info@aki.ee).