This notice explains how OG klubi Ltd, trading online as Supplenivo, uses personal data when you visit the site, create an account, place an order for delivery in Ireland, contact us or exercise a legal right.
Effective: 9 August 2026 · Last reviewed: 9 August 2026 · Version: 2026-08-09.4
1. Who is the controller?
The controller for Supplenivo customer and website data is OG klubi OÜ (trading as OG klubi Ltd; Estonian private limited company / osaühing; registry code 14843593; VAT number EE102216022), Tiigi tn 9, Sauga alevik, 85008, Pärnu maakond, Estonia. Email orders@supplenivo.eu or telephone +372 5562 2534. The company record can be checked in the Estonian e-Business Register.
2. Data we receive and where it comes from
- Identity and contact data: name, billing and delivery address, email address, telephone number and account display name.
- Order and contract data: products, quantities, prices, VAT, delivery charge, order status, delivery instructions, withdrawal, return, refund, complaint and product-safety records.
- Payment data: payment status, amount, currency, Stripe transaction reference and limited card details such as brand and last digits where Stripe returns them. Full card credentials are entered into Stripe’s payment service and are not stored in the Supplenivo WordPress database.
- Account and communications data: password hash, saved details, messages, evidence attached to a complaint, and public review name and content if you choose to submit a product review.
- Technical and security data: IP address, browser/device data, timestamps, requested pages, error and security logs, session/cart identifiers and consent choice.
- Optional analytics data: page, product and checkout interactions and pseudonymous device/browser identifiers, but only after analytics consent.
Most data comes directly from you or from your use of the site. Stripe returns payment results. Our European logistics partners return fulfilment status and a carrier tracking reference; UPS processes the parcel’s delivery events in its own carrier systems and may make them visible through its tracking service. Please do not send health information or identity documents unless we specifically need them to resolve a legal or product-safety issue.
3. Why we use data and our legal bases
- Contract and steps requested before a contract (GDPR Article 6(1)(b)): operate the cart and account, take payment, accept and fulfil an order, arrange delivery, send transactional messages, answer order questions and handle withdrawal, returns and refunds.
- Legal obligations (Article 6(1)(c)): invoices, tax and accounting records, consumer-rights compliance, payment records, product traceability, safety notices, recalls and responses to lawful authorities.
- Legitimate interests (Article 6(1)(f)): keep the site and accounts secure, prevent fraud and misuse, diagnose errors, establish or defend legal claims, preserve evidence of what was agreed, and improve operations using data that does not require optional tracking. We balance these interests against your rights and you may object.
- Consent (Article 6(1)(a)): optional Google Analytics and publication of a voluntary product review. You may withdraw consent without affecting earlier lawful processing.
We do not sell personal data. Supplenivo does not currently use customer data for a marketing-email list.
4. Who receives data?
We disclose only what is reasonably needed for the relevant service:
- Stripe: the applicable Stripe group entities process payment, refunds, authentication and fraud prevention. Stripe can act as our processor and as an independent controller for functions it determines under payment law. See Stripe’s privacy policy.
- European logistics / warehouse partners: receive the recipient’s name, delivery address, email, telephone number, ordered items and the identifiers needed to pick, pack and dispatch the parcel from European warehouses. They process that data as independent controllers or processors for fulfilment only.
- UPS: receives shipment contact and address data, parcel/tracking data and delivery events as the carrier and an independent controller. See the UPS privacy notice.
- Hetzner Online GmbH: hosts the production systems in Germany as an infrastructure processor. See Hetzner’s privacy information.
- Zone Media OÜ: provides the business email/domain infrastructure and acts as a processor for customer correspondence held there. See Zone’s privacy policy.
- Google Ireland Limited: receives analytics events only if a valid Google Analytics property is configured and you choose “Allow analytics”. Google Signals and advertising personalisation are disabled in our site configuration. See Google’s privacy policy and Analytics data safeguards.
- Professional advisers and authorities: accountants, legal advisers, banks, payment networks, insurers, regulators, courts, tax or law-enforcement authorities where needed for their work or required by law.
5. International transfers
Our main hosting and email systems are in the European Economic Area. Some logistics, payment and analytics providers operate internationally and may use group companies or service providers outside the EEA (including, where relevant, the United Kingdom under the European Commission’s adequacy decision while it remains in force). Depending on the destination they use an adequacy decision, European Commission standard contractual clauses or another lawful GDPR transfer safeguard. Their notices above give current details. You may ask us for information about the safeguard relevant to your data.
6. How long do we keep data?
- Orders, invoices and accounting evidence: seven years from the end of the financial year in which the transaction was recorded, as required by the Estonian Accounting Act; longer only where a live claim, investigation or other law requires it.
- Account profile: while the account remains open. If you ask us to close it, we delete profile data that is not needed for the accounting, safety, fraud or claims purposes above.
- Cart/session and technical records: temporary cart/session records expire under the shop’s session settings. Security, delivery and error logs are kept only while reasonably needed to investigate an event, protect the service or support a claim, then deleted or anonymised.
- Support, return and complaint records: until the matter is resolved and then for the period reasonably needed for follow-up and applicable legal claims.
- Consent choice: the first-party
supplenivo_consentrecord remains in your browser’s local storage until you clear it or a new consent version asks you again. - Analytics: Google Analytics is optional and currently disabled unless a valid measurement property is configured. When enabled with consent, user- and event-level Analytics data is retained under the property’s configured period, which for a standard GA4 property is no more than 14 months. Google’s setting does not remove data from standard aggregated reports; we keep our access to aggregate reports only while they remain useful for the stated improvement purpose.
7. Cookies and browser storage
Necessary WooCommerce cookies and server-side session identifiers keep your cart, checkout, login, security and market/VAT context working. The first-party supplenivo_country cookie stores a country you deliberately select for up to one year. These are used because the service you request cannot work reliably without them, not for advertising.
Google Analytics does not load before affirmative consent. If you allow it, Google may set _ga and related analytics cookies. Choosing “Necessary only” or later withdrawing analytics consent stops new analytics events and the site’s consent controller attempts to remove its common analytics cookies. You can reopen the choice through “Cookie settings” in the footer and can also clear site data in your browser.
8. Your rights
Subject to the conditions in the GDPR, you may ask for access, correction, deletion, restriction, portability, or object to legitimate-interest processing. You may withdraw consent at any time. These rights are not absolute; for example, we must preserve legally required invoices even after account closure. Send a request to orders@supplenivo.eu. We may ask for proportionate information to verify that the request concerns you and normally respond within one month.
You may complain to the Estonian Data Protection Inspectorate, the authority in the EU country where you live or work, or where the alleged infringement occurred. An Irish resident can contact the Data Protection Commission. We would appreciate the opportunity to address the issue first, but contacting us is not a condition of your right to complain.
9. Required data and automated checks
We need the checkout fields marked as required, a valid payment result and a deliverable address to enter into and perform an order. Without them we cannot accept or deliver it. Supplenivo does not make a decision with legal or similarly significant effects solely by its own automated profiling. Stripe and financial partners may run automated authentication or fraud checks under their own legal responsibilities; contact us if a payment outcome prevents an order and you want us to examine what we can.
10. Changes and contact
We will publish a newly dated version before a material new use of personal data starts. Changes do not retrospectively make an incompatible use lawful. Privacy questions and rights requests go to orders@supplenivo.eu or OG klubi Ltd at the registered address above.