Privacy Policy

Vilma Candles ("we," "us," or "our") respects your privacy. This Privacy Policy explains how we collect, use, and safeguard your personal information when you visit vilmacandles.com (the "Site") or place an order with us.

Last updated: 4 June 2026

1. Information we collect

We collect only what is needed to operate the shop:

  • Personal information you give us directly — name, email, shipping and billing address, phone number, and any messages sent through the contact form or by email.
  • Order information generated when you make a purchase — order history, products purchased, and payment confirmation references.
  • Automated data collected through cookies — IP address, browser type, device, operating system, pages visited, and time spent on the Site (see Section 5).
  • Payment data — we do not store full card numbers. Payments are processed and stored directly by PayPal under their own security standards.

2. How we use your information

Your data helps us:

  • Process and fulfil your orders
  • Send order confirmations and shipping updates
  • Respond to your questions and provide customer support
  • Send marketing emails (only if you opt in — you can unsubscribe at any time)
  • Comply with our tax, accounting, and consumer-protection obligations
  • Understand how the Site is used and improve it

3. Who has access to your data

We do not sell or rent your data. We share it only with the service providers required to run the shop, each bound by GDPR-compliant data processing agreements:

  • Webflow — website hosting and CMS
  • PayPal — payment processing
  • Shipping carriers (Omniva, DPD, Latvijas Pasts, GLS, etc.) — order delivery
  • Google (Analytics 4, Tag Manager) — anonymised website usage data
  • Email infrastructure providers — transactional and (with your consent) marketing emails

We may also disclose data when required by Latvian or EU law, by a court order, or to investigate fraud.

4. How long we keep your data

  • Order and invoice records — 5 years (required by Latvian accounting law)
  • Customer service correspondence — up to 2 years after last contact
  • Marketing email subscribers — until you unsubscribe
  • Google Analytics data — 14 months

After these periods, your data is deleted or anonymised.

5. Cookies

The Site uses cookies for:

  • Essential functions — shopping cart, checkout, and basic site features. These cannot be disabled.
  • Analytics (Google Analytics 4) — only with your consent, used to understand traffic patterns and improve the Site.
  • Marketing — only with your consent, used to measure campaign effectiveness.

You can manage cookie preferences through your browser settings or the cookie banner shown on your first visit.

6. Your rights under GDPR

You have the right to:

  • Access — request a copy of the personal data we hold about you
  • Rectification — correct any inaccurate or incomplete data
  • Erasure — request deletion of your data, subject to legal retention requirements
  • Restriction — limit how we process your data
  • Portability — receive your data in a structured, machine-readable format
  • Objection — object to processing, including direct marketing
  • Withdraw consent — at any time, where processing is based on consent

To exercise any of these rights, write to info@vilmacandles.com. We will respond within 30 days.

If you believe we have not handled your data correctly, you may lodge a complaint with the Latvian Data Protection Authority — Datu valsts inspekcija, Elijas iela 17, Rīga, LV-1050, www.dvi.gov.lv.

7. International data transfers

Some service providers (such as Google and PayPal) may process data outside the European Economic Area. Such transfers take place under the European Commission's Standard Contractual Clauses or other approved safeguards under Article 46 GDPR.

8. Data security

The entire Site uses HTTPS encryption. Internal access to personal data is restricted, and all third-party processors are bound by signed data processing agreements. No system is fully immune from risk, but we work continuously to minimise it.

9. Children's privacy

The Site is not directed at children under 16, and we do not knowingly collect personal information from minors. If you believe a child has provided us with information, contact us and we will delete it.

10. Third-party links

The Site may link to external websites (for example, social media). We are not responsible for their privacy practices — please review their policies before sharing personal information.

11. Updates to this policy

We may update this Privacy Policy from time to time. Any material changes will be reflected by the "Last updated" date at the top of this page.

12. Contact

For any privacy-related question or request, email info@vilmacandles.com. We respond as quickly as possible.

By using the Site, you acknowledge you have read and agree to this Privacy Policy.