BYDAZED
Privacy Policy
How BYDAZED handles your personal information and cookies.
Last updated: September 4, 2026
BYDAZED ("we," "us," or "our") operates bydazed.com (the "Store"). This Privacy Policy explains how we collect, use, and protect your personal information when you visit or make a purchase from the Store.
/ 1. Information We Collect
1.1 Information You Provide
When you place an order or create an account, we collect:
- Contact information: name, email address, shipping address
- Payment information: processed securely through Stripe (we do not store your full credit card details)
- Order information: products purchased, order history
1.2 Information Automatically Collected
First-Party Analytics (Cookie-Free)
We collect aggregated, privacy-first analytics to understand how visitors use our Store. This system:
- Does not use cookies or similar tracking technologies
- Does not store IP addresses or other personally identifiable information
- Does not share data with third-party analytics services (no Google Analytics, Meta Pixel, or similar trackers)
- Collects only: anonymized page views, product views, add-to-cart events, and completed checkouts
- Uses daily visitor identifiers (cryptographic hashes that reset every 24 hours) to deduplicate page views — these cannot be used to track you across sessions or identify you
Data Retention for Analytics
Raw event data is automatically aggregated into daily summaries and deleted after 90 days. Aggregated daily summaries are retained for 24 months for business planning, then permanently deleted.
Technical Information
When you visit the Store, your browser automatically provides:
- Browser type and version
- Device type (desktop, mobile, tablet)
- Referring website (if you clicked a link to reach us)
This information is used solely to ensure the Store functions correctly on different devices and browsers.
/ 2. How We Use Your Information
We use the information we collect to:
- Fulfill your orders: process payments, arrange shipping, send order confirmations
- Communicate with you: respond to inquiries, send transactional emails (order updates, shipping notifications)
- Improve our Store: understand which products are popular, identify technical issues, optimize the shopping experience
- Comply with legal obligations: tax reporting, fraud prevention
We do not:
- Sell, rent, or share your personal information with third parties for their marketing purposes
- Use your data for advertising or profiling beyond what is necessary to operate the Store
- Track you across other websites
/ 3. Who We Share Information With
We share your information only with trusted service providers necessary to operate the Store:
- Stripe (payment processing) — handles all payment transactions securely. Stripe Privacy Policy
- Gelato (print-on-demand fulfillment) — receives your shipping address and order details to produce and ship your items. Gelato Privacy Policy
- Website hosting provider — hosts the Store infrastructure
These providers are contractually required to protect your data and may only use it to provide services to us.
Legal Requirements
We may disclose your information if required by law, court order, or government regulation, or to protect our rights, property, or safety.
/ 4. Cookies and Tracking
Session Cookies (Essential)
We use a single, essential session cookie to keep you logged in while you browse the Store. This cookie is necessary for the Store to function and cannot be disabled. It is automatically deleted when you close your browser.
No Marketing or Tracking Cookies
We do not use cookies for advertising, cross-site tracking, or behavioral profiling. We do not integrate Google Analytics, Meta Pixel, TikTok Pixel, or any similar third-party tracking scripts.
Your Browser Settings
You can configure your browser to refuse all cookies, but this will prevent you from using certain features of the Store (such as adding items to your cart or completing checkout).
/ 5. Data Security
We take the security of your personal information seriously:
- Payment data is encrypted and processed by Stripe using industry-standard PCI-DSS compliance — we never see or store your full credit card number
- Website traffic is encrypted using HTTPS (TLS/SSL)
- Access controls restrict who can view customer data internally (admin accounts only)
However, no method of transmission over the internet is 100% secure. While we implement reasonable safeguards, we cannot guarantee absolute security.
/ 6. Your Rights (GDPR / Norwegian Privacy Law)
If you are located in the European Economic Area (EEA) or Norway, you have the following rights under GDPR and Norwegian privacy law:
- Access: Request a copy of the personal data we hold about you
- Rectification: Correct inaccurate or incomplete information
- Erasure ("right to be forgotten"): Request deletion of your data (subject to legal retention requirements)
- Restriction: Limit how we use your data in certain circumstances
- Portability: Receive your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interests
- Withdraw consent: If processing is based on your consent, you may withdraw it at any time
To exercise any of these rights, contact us at: [email protected]
We will respond within 30 days of receiving your request.
Data Retention
We retain your personal information for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required by law (e.g., tax and accounting records are retained for 5 years as required by Norwegian law).
/ 7. International Data Transfers
Your information may be transferred to and processed in countries outside Norway/the EEA, including the United States (where our payment processor Stripe is located).
We ensure that such transfers comply with GDPR requirements through:
- Standard Contractual Clauses (SCCs) with service providers
- Providers' Privacy Shield or equivalent certifications
- Adequate safeguards to protect your data in accordance with EEA standards
/ 8. Children's Privacy
The Store is not intended for individuals under the age of 16. We do not knowingly collect personal information from children. If we learn that we have collected information from a child under 16, we will delete it promptly.
/ 9. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The "Last updated" date at the top will indicate when changes were made.
If we make material changes, we will notify you by email (if you have an account) or by posting a notice on the Store before the changes take effect.
/ 10. Contact Us
If you have questions about this Privacy Policy or how we handle your data, contact us:
BYDAZED
Hovslagervegen
Lillehammer, Norway
Lillehammer, Norway
/ Summary
What we collect: Name, email, shipping address, order details, payment info (via Stripe), anonymized analytics (no cookies, no IP storage)
Why: To fulfill orders, improve the Store, comply with legal obligations
Who we share with: Stripe (payments), Gelato (fulfillment), hosting provider — no third-party marketers
Your rights: Access, correction, deletion, data portability (GDPR)
Analytics retention: Raw data deleted after 90 days, aggregated summaries after 24 months
No tracking: No advertising cookies, no cross-site tracking, no Google Analytics or Meta Pixel
Why: To fulfill orders, improve the Store, comply with legal obligations
Who we share with: Stripe (payments), Gelato (fulfillment), hosting provider — no third-party marketers
Your rights: Access, correction, deletion, data portability (GDPR)
Analytics retention: Raw data deleted after 90 days, aggregated summaries after 24 months
No tracking: No advertising cookies, no cross-site tracking, no Google Analytics or Meta Pixel