Privacy policy
Last updated: May 29, 2026
1. Data Controller
The data controller responsible for your personal information is:
eSCALERS AB Organisationsnummer: 559509-0225 Address: Severinsa väg 15, Glommen, 311 54, Sweden Email: hello@goodshades.com Website: goodshades.com
eSCALERS AB operates the GOOD SHADES online store and website, including all related information, content, features, tools, products and services (the “Services”). The Services are powered by Shopify.
This Privacy Policy describes how we collect, use, and disclose your personal information when you visit, use, or make a purchase through the Services or otherwise communicate with us. By using the Services, you acknowledge that you have read and understood this Privacy Policy.
2. Personal Information We Collect
We may collect the following categories of personal information depending on how you interact with the Services:
Information you provide directly
• Contact details: name, email address, phone number, billing address, shipping address.
• Payment information: credit/debit card details, Klarna account information, and other payment details. These are processed by our payment processors (Shopify Payments/Stripe and Klarna) and are not stored by us directly.
• Account information: username, password, preferences and settings (if you create an account).
• Communications: information you include when you contact our customer support or otherwise communicate with us.
• Marketing preferences: your newsletter subscription status and marketing consent.
Information collected automatically
• Device information: IP address, browser type, operating system, device identifiers.
• Usage information: pages visited, products viewed, items added to cart, time spent on pages, referring URLs.
• Cookie data: information collected through cookies and similar technologies. Please see our separate Cookie Policy for details.
• Transaction information: items viewed, purchased, returned or exchanged, order history.
Information from third parties
• From Shopify: information related to your use of the Shopify platform.
• From payment providers: transaction confirmation and fraud screening data.
3. Legal Basis for Processing (GDPR)
Under the EU General Data Protection Regulation (GDPR) and applicable Swedish data protection law, we process your personal information based on the following legal grounds:
|
Legal Basis |
Purpose |
Examples |
|
Performance of contract |
Processing necessary to fulfil our contractual obligations to you |
Processing your order, arranging shipping via PostNord, handling payments, managing returns and exchanges |
|
Consent |
Processing based on your explicit, freely given consent |
Sending marketing emails and newsletters via Shopify Email, placing non-essential cookies (analytics, marketing), showing personalised advertisements |
|
Legitimate interest |
Processing necessary for our legitimate business interests, balanced against your rights |
Fraud prevention, securing the Services, improving user experience, internal analytics and reporting |
|
Legal obligation |
Processing required to comply with applicable law |
Retaining financial records under Swedish bookkeeping law (bokföringslagen, 7 years), responding to lawful requests from authorities |
Where we rely on consent, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
4. How We Use Your Personal Information
Order fulfilment and service delivery
• Processing and fulfilling your orders, including payment processing, shipping via PostNord (through our Shipmondo integration), and delivery notifications.
• Managing your account, processing returns and exchanges, and providing customer support.
• Remembering your preferences, cart contents, and wishlist items.
Marketing and communications
• Sending marketing emails and newsletters about new GOOD SHADES collections, promotions, and offers via Shopify Email (only with your consent).
• Showing you relevant advertisements on the Services or third-party platforms (only with your consent for non-essential tracking).
• You can unsubscribe from marketing emails at any time using the unsubscribe link in each email or by contacting us.
Security and fraud prevention
• Authenticating your account and ensuring secure payment processing.
• Detecting, investigating and preventing fraudulent, illegal or malicious activity.
Improving our Services
• Analysing how customers use our store to improve product offerings, website functionality, and user experience.
• Internal reporting and business analytics.
Legal compliance
• Complying with applicable laws, regulations, and legal processes.
• Retaining financial and transaction records as required by Swedish law.
5. Third Parties and Data Processors
We share your personal information with the following categories of third parties, who act as data processors on our behalf or as independent data controllers where indicated:
|
Third Party |
Purpose |
Role |
Location |
|
Shopify Inc. |
E-commerce platform, hosting, payment processing |
Processor / Joint Controller (for enhanced features) |
Canada / USA / EU |
|
Klarna AB |
Payment services (“Pay Later”, instalments) |
Independent Controller |
Sweden / EU |
|
PostNord AB (via Shipmondo) |
Shipping, delivery, and tracking |
Processor |
Sweden / Denmark / EU |
|
Google LLC |
Analytics (GA4), advertising (if enabled) |
Processor (Analytics) / Controller (Ads) |
USA (with EU SCCs) |
|
Meta Platforms Inc. |
Advertising pixel and social media integration (if enabled) |
Joint Controller (Ads) |
USA (with EU SCCs) |
We may also disclose personal information in connection with a business transaction (such as a merger or acquisition), to comply with legal obligations, to enforce our terms of service, or to protect the rights and safety of our users and others.
We do not sell your personal information to third parties.
6. Relationship with Shopify
The Services are hosted by Shopify, which collects and processes personal information about your access to and use of the Services. Information you submit to the Services will be transmitted to and shared with Shopify, as well as third parties that may be located in countries other than where you reside, in order to provide and improve the Services.
We use certain Shopify enhanced features that incorporate data from your interactions with our store alongside data from other Shopify merchants. For these features, Shopify acts as a data controller and is responsible for responding to your rights requests related to that processing.
To learn more about how Shopify uses your personal information, visit the Shopify Consumer Privacy Policy at https://www.shopify.com/legal/privacy. You may exercise rights related to Shopify’s processing at https://privacy.shopify.com/en
7. Cookies and Tracking Technologies
We use cookies and similar technologies on our website. For detailed information about the cookies we use, their purposes, and how to manage your preferences, please refer to our separate Cookie Policy available on our website.
You can manage your cookie preferences at any time through the cookie consent banner on our website.
8. Data Retention
We retain your personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Specific retention periods are as follows:
|
Data Category |
Retention Period |
Legal Basis |
|
Order and financial records |
7 years from the end of the financial year |
Swedish bookkeeping law (bokföringslagen 7:2) |
|
Customer account data |
Until you delete your account or request deletion |
Contract / Consent |
|
Marketing consent records |
Until you withdraw consent (unsubscribe) |
Consent |
|
Customer support communications |
2 years after resolution |
Legitimate interest |
|
Cookie and analytics data |
As specified in our Cookie Policy |
Consent |
9. International Data Transfers
Your personal information may be transferred to, stored, and processed outside of Sweden and the European Economic Area (EEA), including in countries such as Canada and the United States where our service providers (including Shopify and Google) operate.
Where we transfer personal information outside the EEA or the United Kingdom, we rely on recognised transfer mechanisms, including the European Commission’s Standard Contractual Clauses (SCCs), adequacy decisions, or equivalent safeguards as required by applicable law.
10. Your Rights
Under the GDPR and applicable Swedish and Danish data protection law, you have the following rights regarding your personal information:
• Right of access: You may request confirmation of whether we process your personal information and, if so, access to that data along with information about the processing.
• Right to rectification: You may request correction of inaccurate personal information we hold about you.
• Right to erasure (“right to be forgotten”): You may request deletion of your personal information, subject to our legal retention obligations.
• Right to restriction: You may request that we restrict the processing of your personal information in certain circumstances.
• Right to data portability: You may request a copy of your personal information in a structured, commonly used, machine-readable format.
• Right to object: You may object to processing based on legitimate interests, including profiling, and to processing for direct marketing purposes.
• Right to withdraw consent: Where processing is based on your consent, you may withdraw consent at any time without affecting the lawfulness of prior processing.
• Right not to be subject to automated decision-making: You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects.
To exercise any of these rights, please contact us at hello@goodshades.com. We will respond within 30 days as required by GDPR. We may need to verify your identity before processing your request.
We will not discriminate against you for exercising any of these rights. You may also designate an authorised agent to make requests on your behalf.
11. Children’s Data
The Services are not intended for children under the age of 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at hello@goodshades.com so we can take steps to delete such information.
As of the date of this Privacy Policy, we do not have actual knowledge that we “sell” or “share” (as those terms are defined under applicable law) personal information of individuals under 16 years of age.
12. Third-Party Websites and Links
The Services may contain links to websites or platforms operated by third parties. We are not responsible for the privacy practices or content of those third-party sites. We encourage you to review the privacy policies of any third-party sites you visit.
Information you share on public or semi-public venues, including third-party social networking platforms, may be viewable by others.
13. Newsletter and Email Marketing
We use Shopify Email to send marketing communications, including newsletters about new collections, promotions, and exclusive offers from GOOD SHADES.
We only send marketing emails to customers who have given their explicit consent, either at checkout or through our newsletter sign-up form on the website. You can unsubscribe at any time by clicking the “unsubscribe” link at the bottom of any marketing email, or by contacting us at hello@goodshades.com
Even if you unsubscribe from marketing emails, we may still send you transactional emails related to your orders (e.g. order confirmations, shipping updates, refund notifications).
14. Security
We take reasonable technical and organisational measures to protect your personal information against unauthorised access, loss, alteration, or destruction. These measures include encryption of payment data, secure hosting through Shopify, and access controls for our staff.
However, no method of transmission over the internet or method of electronic storage is completely secure. We cannot guarantee absolute security of your personal information.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Services, or applicable law. We will post the revised Privacy Policy on our website and update the “Last updated” date at the top of this page. Where required by law, we will notify you of material changes.
16. Complaints and Supervisory Authorities
If you have any complaints about how we process your personal information, please contact us first at info@goodshades.com and we will do our best to resolve your concerns.
If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority:
• Sweden: Integritetsskyddsmyndigheten (IMY) www.imy.se
• Denmark: Datatilsynet www.datatilsynet.dk
• Other EU/EEA countries: Your local data protection authority. A full list is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en
17. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:
eSCALERS AB (trading as GOOD SHADES)
Organisationsnummer: 559509-0225
Email: hello@goodshades.com