Legal Information

This Privacy Policy explains how Deus Labs AB (the legal entity behind the Gottofrotto brand) collects, uses, shares, and retains personal data when you visit gottofrotto.com or place an order. It is written to comply with the EU General Data Protection Regulation (GDPR), the Swedish Data Protection Act, and the Swedish Bookkeeping Act.

Privacy Policy

Last updated: 30 June 2026

Data Controller

The controller responsible for your personal data is Deus Labs AB (org.nr. 559537-2219, VAT SE559537221901), Stockholm, Sweden. Gottofrotto is a brand operated by Deus Labs AB and is not a separate legal entity.

Privacy contact: privacy@gottofrotto.com. We aim to acknowledge requests within 5 business days and respond substantively within one month, as required by Article 12 GDPR.

A Data Protection Officer is not required under Article 37 GDPR and has therefore not been appointed.

Information We Collect

Order data: name, email address, phone number, shipping address, and billing address. Collected when you place an order and stored in our order database.

Payment data:card data is collected and processed directly by Stripe via embedded Stripe Elements; we never see your full card number. We store only the last four digits, card brand, and Stripe's payment-intent identifier alongside your order.

Order history and cart data:items added, cart identifiers (stored in your browser's localStorage), and completed orders.

Technical data: IP address, browser user-agent, and request paths in standard server logs. Used for security, debugging, and fraud prevention.

Analytics events (optional): when enabled, an anonymised session identifier and aggregate navigation events. Tied to an email address only after you complete a purchase.

Legal Basis for Processing

Order processing and delivery — Article 6(1)(b) GDPR, performance of a contract.

Accounting and invoice records — Article 6(1)(c) GDPR, legal obligation under the Swedish Bookkeeping Act (Bokföringslagen, 7-year retention).

Fraud prevention via Stripe Radar — Article 6(1)(f) GDPR, legitimate interest in preventing payment fraud.

Server logs and security — Article 6(1)(f) GDPR, legitimate interest in keeping the service available and secure.

Optional analytics and non-essential cookies — Article 6(1)(a) GDPR, consent. You may withdraw consent at any time without affecting prior processing.

Processors We Use

We share personal data with the following processors, each under a Data Processing Agreement and only to the extent necessary to deliver the service:

Stripe Payments Europe Ltd (Ireland) — payment processing, fraud screening (Stripe Radar), 3-D Secure authentication, refunds.

Vercel Inc. (United States) — storefront hosting and edge delivery; Vercel Analytics and Speed Insights collect aggregated performance and visit counts.

Railway Corp. (United States; data stored in the EU-west region) — hosting for the order backend and the orders database.

Cloudflare Inc. (United States with EU processing) — DNS, content delivery, and the R2 object storage bucket (EU jurisdiction) that serves product images at cdn.gottofrotto.com.

Resend Inc. (United States) — transactional email delivery for order confirmations and service notifications.

PostHog Inc. (EU-hosted instance, where enabled) — product analytics, only when you have consented to non-essential cookies.

International Transfers

Some of our processors are based in the United States (Vercel, Railway, Resend, Cloudflare). Where personal data is transferred outside the EU/EEA, we rely on the European Commission's Standard Contractual Clauses (Commission Decision 2021/914) and, where applicable, on the EU–US Data Privacy Framework certification held by the recipient. Order data itself is stored in the EU (Railway eu-west region; Cloudflare R2 EU bucket).

Cookies and Tracking

We use the following categories of cookies and similar technologies:

Strictly necessary — your cart identifier (browser localStorage), session cookies set by Stripe to enable secure checkout, and Cloudflare cookies for security and load balancing. These cannot be switched off and do not require consent.

Analytics (consent-based) — Vercel Analytics and Speed Insights, and PostHog where enabled. Loaded only after you grant consent through the cookie banner.

Payment partner cookies — Stripe Link may set cookies if you choose to save card details with Stripe; this is governed by Stripe's Privacy Policy.

You can withdraw or change consent at any time by clearing cookies in your browser or by emailing privacy@gottofrotto.com.

Retention Periods

Order, invoice, and accounting records: 7 years from the end of the calendar year in which the transaction was completed, as required by the Swedish Bookkeeping Act (Bokföringslagen §7).

Server access logs: 30 days.

Analytics events: 12 months from collection.

Marketing consent records: until you withdraw consent, plus a short audit window.

After these periods, data is deleted or fully anonymised.

Your Rights Under GDPR

Under Articles 15–22 GDPR you have the right to:

• access the personal data we hold about you

• have inaccurate data rectified

• request erasure ("right to be forgotten"), subject to legal retention obligations

• restrict processing

• receive your data in a portable, machine-readable format

• object to processing based on legitimate interest

• withdraw consent at any time

To exercise any of these rights, email privacy@gottofrotto.com. We may ask you to verify your identity to protect against fraudulent requests. We will respond within one month.

Automated Decision-Making

Stripe Radar performs automated risk scoring on payment attempts to detect fraud and trigger 3-D Secure authentication where appropriate. This screening does not produce legal effects on you and is reviewable on request. Email privacy@gottofrotto.com if a transaction was declined and you would like a manual review.

Children's Data

Gottofrotto is not directed at children under 16 and we do not knowingly collect their personal data. If you believe a child has provided us with personal information, contact privacy@gottofrotto.com and we will delete it.

Security

All traffic to gottofrotto.com is encrypted in transit via TLS. Payment card data is handled exclusively by Stripe under PCI-DSS; our storefront qualifies as SAQ-A. Order data is stored in EU-region databases with access restricted to authorised personnel. No system is perfectly secure; if a breach affecting your personal data occurs, we will notify the Swedish supervisory authority (IMY) within 72 hours and, where required, notify you directly.

Right to Lodge a Complaint

If you believe we have processed your personal data in violation of GDPR, you have the right to lodge a complaint with the Swedish supervisory authority: Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, imy@imy.se, www.imy.se.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our processing activities, our processors, or the law. The "Last updated" date at the top of the page will change with every revision. Material changes will be highlighted on the storefront.

Contact

For privacy questions or to exercise your rights:

Email: privacy@gottofrotto.com

Registered address: Deus Labs AB, Stockholm, Sweden (org.nr. 559537-2219). A full street address is available on request via the privacy contact above.

This policy is written to comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679), the Swedish Data Protection Act (2018:218), the Swedish Bookkeeping Act, and the ePrivacy Directive as implemented in Sweden.

Gottofrotto logo