§ Legal

Privacy Policy.

Short version: minimum data, no reselling, and you can delete your account any time.

Last updated 2026-07-24

1. Data controller

Remanis Adventures AB (org.nr 559101-0078), Fågelvägen 24 b, 141 40 Huddinge, Sweden, is the data controller for personal data processed via retrograsp.com. Contact: support@remanis.se.

2. What we collect & why

  • Order data — name, email, shipping/billing address, order contents. Legal basis: contract (Art. 6(1)(b) GDPR).
  • Payment data — handled by Shopify Payments / Stripe. We only see the last 4 digits and status.
  • Account data — email, hashed password, preferences, if you create an account. Legal basis: contract.
  • Support messages — the content of emails / chat you send us. Legal basis: legitimate interest in helping you.
  • Analytics & marketing — pseudonymous usage data, only with your consent. Legal basis: consent (Art. 6(1)(a) GDPR).
  • Uploaded files (Analog Press) — stored in a private encrypted bucket, deleted 30 days after your order ships.

3. How long we keep it

Order records are kept for 7 years to comply with Swedish accounting law (Bokföringslagen). Account data is kept until you delete your account. Marketing consent is kept until you withdraw it. Support tickets are kept for 2 years.

4. Who we share with (processors)

  • Shopify Inc. — store platform, checkout, payments
  • Stripe — payment processing
  • Cloudflare — hosting & CDN
  • Shipping carriers (PostNord, DHL, UPS, etc.) — delivery
  • Supabase — database & file storage (EU region)
  • Google (Analytics) & Meta (Ads) — only with your consent

Some processors are located outside the EU/EEA. Transfers are covered by Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.

5. Your rights

Under GDPR you have the right to access, rectify, erase, restrict, port and object to processing of your personal data, and to withdraw consent at any time. Contact support@remanis.se to exercise these rights.

You may also lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se.

6. Security

We use TLS in transit, encryption at rest, row-level security in our database, and least-privilege access. No system is 100% secure, but we take breach notification seriously (within 72h to IMY where required).

7. Cookies

See our Cookie Policy for details and to change your consent.