Privacy
Privacy Policy
How we handle data relating to orders, payments, delivery, security, cookies, analytics and marketing.
1. Who applies this policy and when
This policy applies when using the SturmPak website, placing an order, contacting the seller or selecting settings for cookies, analytics and marketing. Information about the data controller is provided on this page.
2. What data do we process?
To process your order, we require your name, email address, telephone number, delivery address and country, the selected product, variant, quantity, accessories, delivery and payment method, total amount, payment and order status, correspondence and parcel tracking information.
To ensure the website functions properly and remains secure, we may process your IP address, browser and device information, session identifiers, consent preferences, anti-abuse signals and administrative security logs. The seller does not itself collect or store any payment card details.
When you create a customer account, we process your verified email address, name, optional phone number, securely hashed password, account and consent timestamps, login and security logs, and the history of orders linked to the same email address.
3. Objectives and legal basis
Order, payment and delivery data are processed for the purpose of concluding and fulfilling the purchase contract and taking action at the buyer’s request. Accounting and consumer rights data are processed in order to comply with legal obligations.
Security and fraud prevention data is processed on the basis of a legitimate interest in protecting customers, the website and administrative systems. Non-essential analytics and marketing are used only with the relevant consent.
4. MakeCommerce and payment details
Instant payments are processed by Maksekeskus AS, the operator of the MakeCommerce platform, registration number 12268475, Liivalaia 45, Tallinn 10145, Estonia. The necessary order, payer and technical data are transferred to them to process and confirm the payment.
The payment service provider processes data in accordance with its legal obligations and privacy policy. The seller receives the transaction identifier, amount, currency and payment status, but not all card details.
5. Other recipients and service providers
Data may be transferred, where necessary, to providers of hosting and infrastructure, databases, email, anti-fraud, delivery, accounting, technical support, consent management and authorised analytics or advertising measurement service providers.
The recipient’s name, address, telephone number, email address and other information necessary for delivery are provided to the carrier. Each recipient receives only the data required for their specific role.
6. Cookies and tracking technologies
Essential browser cookies are used for privacy preferences, language settings, the ordering process and security. Optional integrations with Google Tag, Plausible and Meta Pixel are only activated once they have been configured and consent has been obtained for the relevant category.
You can change or withdraw your consent via the website’s privacy settings. Further information is available in the Cookie Policy.
7. Shelf life
Order and accounting data are retained for as long as is necessary to fulfil the contract and to comply with the obligations set out in legislation regarding accounting, taxation, guarantees, consumer complaints and disputes.
Security logs and technical data are retained for a limited period, as required to detect misuse and investigate incidents. Data is deleted or anonymised when it is no longer required, unless retention is required by law.
Account data is retained while the account is active. When an account is deleted, its profile, login sessions, and active verification or recovery tokens are removed or anonymised, while order and accounting records are retained for the period required by law.
8. International data transfer
Where a service provider processes data outside the European Economic Area, a legitimate transfer mechanism applies, such as a European Commission adequacy decision or standard contractual clauses, and, where necessary, additional safeguards.
9. Your rights
Depending on the applicable legal basis, you may request access to your data, have it rectified, erased, have its processing restricted, have it transferred, object to its processing, or withdraw your consent. Withdrawal of consent does not affect the lawfulness of processing carried out prior to such withdrawal.
Please submit your request via the email address provided on this page. To protect your data, you may be asked to verify your identity. You may also lodge a complaint with the State Data Protection Inspectorate or your country’s supervisory authority.
10. Children’s privacy
This website is not intended for children to enter into purchase agreements independently. If it is determined that a child’s data has been provided without a valid legal basis or the consent of a legal representative, it will be deleted, except where retention is required by law.
11. Safety, changes and contact details
Appropriate technical and organisational measures are in place: encrypted communication, restricted administrative access, session and access control, verification of the authenticity of payment notifications, restricted database access and security logs.
This policy may be updated in response to changes to our services, legal requirements or data processing practices. The effective date is stated on this page; any queries may be sent to the data controller by email.
Data controller
- Name
- UAB Milisec
- Company code
- 304971926
- VAT registration number
- LT100012176610
- Address
- M. K. Čiurlionio g. 82A-49, LT-03100, Vilnius, Lietuva
- team@sturmpak.com
- Phone
- +370 686 66240
- Valid from
- 2026-08-04
- Document version
- 2026-08-04