Privacy and Cookies Policy
1. Introduction
Thurje Handmade, operated by Mikaela Maçka PF (NIPT: M01808005D), is committed to protecting your personal data and respecting your privacy. This Privacy and Cookies Policy explains what data we collect, why we collect it, how we use it, and what rights you have in relation to your data when you visit http://www.thurjehandmade.com or place an order with us.
This policy applies to all personal data collected through the Website, including data submitted via contact forms, checkout, newsletter subscription, and data collected automatically through cookies and similar tracking technologies.
2. Data Controller
Name: Mikaela Maçka
Trading as: Thurje Handmade
NIPT: M01808005D
Address: Baba Meleq, Old Bazaar, 7001 Korça, Albania
Email: contact@thurjehandmade.com
3. Personal Data We Collect
3.1 Data You Provide Directly
We collect the following categories of personal data when you interact with our Website:
Contact form
First and last name
Company name (optional, for professional customers)
Email address
Message content
Newsletter subscription
Email address
Placing an order
– First and last name
– Delivery address (street, city, postal code, country)
– Email address
– Phone number (for delivery purposes)
– Payment information (processed securely by PayPal — we do not store card details)
3.2 Data Collected Automatically
When you visit our Website, certain technical data is collected automatically through cookies and analytics tools, including:
– IP address
– Browser type and version
– Pages visited and time spent on each page
– Referring URL
– Device type and operating system
4. Legal Basis for Processing
We process your personal data on the following legal bases under GDPR Article 6:
– Contract performance (Art. 6(1)(b)): to process and fulfil your orders, manage returns, and communicate about your purchases.
– Legitimate interests (Art. 6(1)(f)): to improve our Website, prevent fraud, and manage customer enquiries.
– Consent (Art. 6(1)(a)): for newsletter subscriptions and non-essential cookies (e.g. Google Analytics, Meta Pixel). You may withdraw consent at any time.
– Legal obligation (Art. 6(1)(c)): to comply with applicable tax, accounting and commercial law obligations.
5. How We Use Your Data
– Processing and fulfilling your orders
– Communicating with you about your order or enquiry
– Sharing your shipping details with our delivery partners (DHL, Albanian Post)
– Improving the Website through analytics
– Sending marketing communications (only with your consent)
– Complying with legal and fiscal obligations
6. Sharing Your Data with Third Parties
We do not sell, rent or trade your personal data. We may share data with the following categories of trusted third parties strictly for the purposes described above:
– Shipping carriers — DHL and Albanian Post: receive your name, phone number and delivery address to deliver your order.
– Payment processors — PayPal (WooCommerce PayPal Payments, PayPal Inc., USA): processes payment transactions securely. We do not receive or store your full card details. See paypal.com/privacy. Bank transfers are processed directly between you and our bank; no third party is involved.
– Website hosting — WordPress.com (Automattic Inc., USA): hosts our Website. Data may be processed in the United States under Standard Contractual Clauses.
– Cookie consent management — Complianz (van Ommen IT, Netherlands): manages your cookie consent preferences and stores a record of consent. Data processed in accordance with Complianz’s privacy policy at complianz.io.
– Email marketing — MailPoet (Automattic Inc., USA): used to manage newsletter subscriptions and send marketing emails to subscribers who have given their consent. Data stored and processed by Automattic.
– Spam filtering — Akismet (Automattic Inc., USA): analyses data submitted through our contact forms to detect and filter spam. Content of submitted messages and metadata (IP address, browser user agent) may be sent to Akismet for processing.
– SEO and search indexing — Rank Math SEO (MyThemeShop LLC): processes Website metadata to improve search engine visibility. No personal data of visitors is transmitted to Rank Math servers in standard configuration.
– Google Listings & Ads (Google LLC, USA) — used to list our products on Google Shopping and manage advertising campaigns. Data may be processed by Google in connection with ad delivery and conversion measurement.
– Analytics — Google Analytics (Google LLC, USA): collects anonymised browsing data. IP anonymisation is enabled. Data processed under Google’s data processing terms.
– Advertising — Meta Pixel (Meta Platforms Inc., USA/Ireland): used to measure advertising performance and serve personalised ads. Data processed by Meta Platforms Ireland Ltd.
All third-party processors are contractually bound to process your data only on our instructions and in compliance with applicable data protection law.
7. International Data Transfers
Several of our third-party providers are based outside the European Economic Area (EEA), including Automattic Inc. (WordPress.com, MailPoet, Akismet), Google LLC, Meta Platforms Inc., and PayPal Inc. — all based in the USA. When your data is transferred outside the EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission or equivalent mechanisms.
8. Data Retention
We retain your personal data only for as long as necessary for the purposes set out in this Policy:
– Order and transaction data: retained for 5 years to comply with Albanian tax and accounting obligations.
– Contact form enquiries: retained for 1 year from the date of last correspondence.
– Newsletter subscribers: retained until you unsubscribe.
– Website analytics data: retained for 26 months (Google Analytics default).
– Cookie consent records: retained for 1 year.
9. Your Rights Under GDPR
If you are based in the EU/EEA, or otherwise protected by GDPR-equivalent legislation, you have the following rights:
– Right of access: to obtain a copy of the personal data we hold about you.
– Right to rectification: to request correction of inaccurate or incomplete data.
– Right to erasure: to request deletion of your data, subject to legal retention requirements.
– Right to restriction: to request that we limit processing in certain circumstances.
– Right to data portability: to receive your data in a structured, machine-readable format.
– Right to object: to object to processing based on legitimate interests or for direct marketing.
– Right to withdraw consent: at any time, without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us at contact@thurjehandmade.com. We will respond within 30 days. You also have the right to lodge a complaint with the Albanian Information and Data Protection Commissioner (IDP) at http://www.idp.al, or with the supervisory authority of your EU member state.
10. Cookie Policy
10.1 What Are Cookies?
Cookies are small text files stored on your device when you visit a website. They are widely used to make websites work more efficiently and to provide information to the website owner.
10.2 Cookies We Use
We use the following categories of cookies on this Website:
Strictly Necessary Cookies
These cookies are essential for the Website to function and cannot be disabled. They include:
– Session and authentication cookies (WordPress/WooCommerce)
– Shopping cart cookies
– cmplz_* cookies (Complianz) — store your cookie consent preferences (expire after 1 year)
Analytics Cookies
We use Google Analytics (with IP anonymisation enabled) to understand how visitors interact with our Website. These cookies are only set with your consent.
– _ga — used to distinguish users (expires after 2 years)
– _gid — used to distinguish users (expires after 24 hours)
– _gat — used to throttle request rate (expires after 1 minute)
Marketing and Tracking Cookies
We use the Meta Pixel (Facebook) to measure the effectiveness of our advertising and to build custom audiences. These cookies are only set with your consent.
_fbp — Meta Pixel cookie (expires after 90 days)
Functional Cookies
These cookies remember your preferences to personalise your experience (e.g. language, currency). Set with your consent.
10.3 Managing Cookies
When you first visit the Website, you will be shown a cookie consent banner managed by Complianz allowing you to accept or reject non-essential cookies by category. Your preferences are stored for 1 year. You can change your preferences at any time by clearing your browser cookies and revisiting the Website.
You can also manage or disable cookies directly through your browser settings. Please note that disabling certain cookies may affect the functionality of the Website. For more information, visit http://www.allaboutcookies.org.
To opt out of Google Analytics across all websites, you can install the Google Analytics Opt-out Browser Add-on available at tools.google.com/dlpage/gaoptout.
11. Security
We implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Our Website uses SSL/HTTPS encryption for all data transmissions. Payment data is handled exclusively by PayPal and is subject to PCI-DSS security standards.
12. Children’s Privacy
Our Website and services are not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us at contact@thurjehandmade.com and we will delete it promptly.
13. Changes to This Policy
We may update this Privacy and Cookies Policy from time to time. Any changes will be published on this page with an updated revision date. For significant changes, we will notify you by email or a prominent notice on the Website.
14. Contact Us
For any questions, requests, or complaints regarding this Policy or the way we handle your data, please contact:
Email: contact@thurjehandmade.com
Post: Thurje Handmade, Baba Meleq, Old Bazaar, 7001 Korça, Albania