Privacy Notice
Privacy Notice
This privacy notice sets out how we use and protect the personal data you provide to us when you visit this website, purchase goods and services from us, subscribe to our newsletter, respond to our online ads, or otherwise interact with us or our products and services.
Reflect Studio BV residing at Beyoğlu/İstanbul (“we”, “us”, “our”) is the controller for the purposes of the General Data Protection Regulation (the “GDPR”). You can contact us via our post address or via email on hello@reflectstudio.com.
What data do we collect?
The personal data we collect from you are not only information that we actively collect while you interact with our services but also information that you voluntarily provide to us in various contexts (such as by signing up to our website, placing an order, or sending an email to us). Therefore, it is not possible to define an exclusive list of all potential types of personal data that we may collect from you. However, we provide below the typical types of personal data we collect from each data subject group. Note that you may belong to more than one data subject groups. For instance, if you signed up to our website and placed an order, your personal data listed next to “Website member (authenticated user)” and “Customer” will be processed.
Data Subject Group
Personal Data Categories
Website visitor
Information about how our website was used such as the pages visited, the date, time, and duration of the visit, search terms entered, and other interaction with the website and its content
Technical information related to the visit such as online identifiers (including IP address and cookie data) and information about the devices used (including unique device IDs, network connection type, browser type, language, operation system)
Non-precise location information (inferred from technical data such as the IP address or language setting of the device)
Information about reviews of our goods and your questions about the same submitted through our website, including name, email address, and review or question details
Website member
(i.e., if you signed up and logged in to our website)
Identity and contact information such as name and email address as well as login credentials
Newsletter subscriber
Email address
Information about how you interacted with our emails such as whether you opened our email, the links you clicked, and how you use our website after clicking a link
Customer
(i.e., visitors or members who placed an order on our website)
Telephone number, delivery address, invoice address, and further contact information as required
Order, invoice, and payment details (except we never store your credit card information)
Shopping history including open and completed transactions
Persons who respond to our internet ads
(including those who respond to Facebook Lead Ads)
Email address and information about the context and details of the interaction with the ad
Persons who contact us
Identity and contact details as well as the content of communication
How do we collect your data?
You directly provide us with most of the data we collect but we also use automated processes to collect some information about you.
We collect and process your data when:
You visit our website, in which case we use cookies and similar technologies (more on this below);
You fill in the forms on our website such as newsletter sign up form, website sign up form, review forms for goods, forms for questions about our goods, and contact forms,
You sign up to and read our newsletters,
You respond to our ads online including Facebook Lead Ads, in which case we may receive the data from our advertising partners such as Facebook,
You contact us in any other manner.
Cookies and Similar Technologies
Cookies are small text files that are placed on your computer by websites that you visit. They are widely used to make websites work, or work more efficiently, as well as to provide information to the owners of the site. The table below explains the cookies we use and why we use them.
Cookie / Technology
Name
Purpose
Cookie preference
CookieControl
This cookie is used to remember your choices about cookies on our website. Where you have previously indicated a preference, your preference will be stored in this cookie.
WWF Market
currency
This cookie is used to store your currency preference.
Secure_customer_sig
This cookie is set by websites built on Shopify platform and is used in connection with member login processes.
_orig_referrer
cart_currency
cart_sig
cart
cart_ts
cart_ver
These cookies are used in association with the shopping cart feature of our website. They provide a secure and smooth checkout and payment function for your purchasing experience.
PHPSESSID
This cookie is native to PHP applications and is used to store and identify a users’ unique session ID for the purpose of managing user session on the website. It is a session cookie and is deleted when all the browser windows are closed.
Google Analytics
_ga
_gat
_gid
These cookies are used to collect information about how visitors use our website. We use the information to compile reports and to help us improve the website. The cookies collect information including the number of visitors to the website, where visitors have come to the website from, and the pages they visited. Read Google’s overview of privacy and safeguarding data. To opt out of being tracked by Google Analytics across all websites, visit this page.
Snapchat
sc_at
_scid
The cookie is set by Snapchat and is used for advertising purposes. It shows relevant ads to you by tracking your behavior on Snapchat and serves and stores your Snapchat Pixel unique ID.
Shopify
_landing_page
_y
_s
_shopify_y
_shopify_s
_shopify_sa_t
_shopify_sa_p
‘_landing_page’ cookie is set by websites built on Shopify platform and is used to track landing pages. Others are associated with Shopify’s analytics suite to track how the website is being used you.
Criteo
uid
This cookie is used to measure the number and behavior of the visitors to the website anonymously. The data includes the number of visits, average duration of the visit on the website, pages visited, etc. for the purpose of better understanding user preferences for targeted advertisements.
Klaviyo
__kla_id
KL_FORMS_MODAL
We use Klaviyo to track our visitors when they click through a Klaviyo email to your website and when they subscribe (opt in) to one of our forms. This allows us to follow the actions of visitors and customers in our sales funnel.
Google Ads / Doubleclick
test_cookie
We use Google AdWords remarketing service to advertise on third party websites to previous visitors to our site. This could be in the form of an advertisement on the Google search results page or a site in the Google Display Network. Google use these cookies to serve ads based on your past visits to our website.
Facebook
_fbp
fr
Our website utilizes the Facebook Pixel and other ads services of Facebook. These tools allow us to follow the actions of users after they are redirected to a provider’s website by clicking on a Facebook advertisement. We are thus able to record the efficacy of Facebook advertisements for statistical and market research purposes. Using this data also allows us to improve our advertising for a better experience to the users and also retarget you with further advertising on Facebook. They also allow Facebook to deliver advertisement when users are on Facebook or a digital platform powered by Facebook advertising after visiting this website as well as to track the behavior of the users across the web on sites that have Facebook pixel or Facebook social plugin.
The collected data are saved and processed by Facebook. Facebook is able to connect the data with your Facebook account and use the data for their own advertising purposes in accordance with Facebook’s Data Policy found here.
You can change your cookie preferences at any time by clicking on the ‘C’ icon. You can then adjust the available sliders to ‘On’ or ‘Off’, then clicking ‘Save and close’. You may need to refresh your page for your settings to take effect.
Alternatively, most web browsers allow some control of most cookies through the browser settings. To find out more about cookies visit www.aboutcookies.org and to access mechanisms for exercising your preferences visit www.aboutads.info/choices, www.youronlinechoices.eu/, and www.networkadvertising.org/managing/opt_out.asp.
Why do we process your data and what are the lawful bases?
We collect your data for the following purposes and pursuant to the legal bases indicated next to them:
Subject
Purposes
Legal Basis
Service maintenance
To administer, operate, and maintain our website, newsletter, and our services in general, to understand, diagnose, troubleshoot, and fix issues with our services
Legitimate interests in running our business (6(1)(f) of the GDPR)
Sign up processes
To allow you to sign up to our website and our newsletters
Performance of a contract (6(1)(b) of the GDPR)
Order fulfilment
To facilitate and process product and service orders placed on the website, to carry out financial, accountancy, and operational processes in relation to your purchases, to fulfill the requirements of your order, to collect payment from you
Performance of a contract (6(1)(b) of the GDPR) insofar as the purpose relates to the execution of a contract agreed with you or the provision of a service requested by you. Otherwise, the legal basis is legitimate interests (6(1)(f) of the GDPR).
Customer support
To respond to your requests, to provide customer support on pre-sale and/or post-sale queries and issues, to help you solve any issues you may have with our services, to update you about changes to our terms of service or privacy notice, or to contact you to know how your experience with us was
Performance of a contract (6(1)(b) of the GDPR) and legitimate interests in retaining you as a customer (6(1)(f) of the GDPR)
Cyber security
To ensure information security of our services and prevent any malicious use of our website and services
Legitimate interests in ensuring the security of our services (6(1)(f) of the GDPR)
Service analysis and improvement
To perform analytics and conduct customer research, to evaluate and develop new features and improvements to our website and newsletter by analyzing your interaction with our website and newsletter
Legitimate interests in running our business and improving our website and your experience (6(1)(f) of the GDPR)
Marketing and advertisement
To carry out our marketing and advertisement campaigns, to tailor our products and services, content on our website and newsletter, and advertisements by analyzing your preferences, interests, and needs and by carrying out retargeting, targeting, and profiling campaigns, to send you marketing communications on our products and services
If data processing for these above purposes occurs with your consent, the legal basis is your consent (6(1)(a) of the GDPR). This data processing otherwise occurs pursuant our legitimate interests in marketing our services (6(1)(f) of the GDPR).
Compliance
To comply with legal obligations and law enforcement requests, including participation in investigations and proceedings, complying with information requests from third parties based on any statutory information rights they have against us, retention and storage of your personal data to comply with specific legal retention requirements
Legal obligation (6(1)(c) of the GDPR)
Legal proceedings
To establish, exercise, or defend legal claims
Legitimate interests in protecting our business (6(1)(f) of the GDPR)
In cases where processing is based on your consent, you can withdraw your consent at any time (e.g., by changing your cookie preferences for cookies, by clicking the unsubscribe link for our newsletters, or otherwise by contacting us.
To whom do we transfer your data?
We have set out the categories of recipients of your personal data and why we share your data with them below:
Categories of Recipients
Reason for sharing
Our group companies
Many of our systems and technologies are shared within our group, which allows us to offer you a more economical, secure, unified, and personalized service. Therefore, we share your personal data with our group companies to carry out our daily business operations and to enable us to maintain and provide our services to you.
Shipping companies
We work with external shipping companies to deliver orders. These shipping companies typically receive your name, delivery address, email address, and phone number.
Technical service providers
We work with technical service providers who operates the technical infrastructure that we need, assist in protecting and securing our systems and services, and provide technical services to us for the provision of our services to you.
Payment service providers
As we offer different payment options to our customers, we partner with payment service providers to ensure a smooth purchase experience for you. Naturally, some payment data can be transferred to these payment service providers to collect payment from you and confirm that the payment has been affected.
World Wide Fund for Nature (WWF)
With your consent, we may share your name and email address with WWF to allow WWF to contact you directly for campaigns, promotions, events, and similar occasions.
Advertising partners
We work with advertising partners to enable us to customize the advertising content you may receive on our website and their websites and applications. These partners help us deliver more relevant ads and promotional messages to you and include Google and Facebook (see above Cookies and Similar Technologies).
Authorities
We share your personal data when we in good faith believe it is necessary for us to do so to comply with a legal obligation under applicable law or respond to valid legal process.
We may share your personal data with our group companies and third parties located in countries other than your country. Your personal data, therefore, may be subject to privacy laws that are different from those in your country. Personal data collected within the European Union may, for example, be transferred to and processed by third parties located in a country outside of the European Union. In such instances, we ensure that the transfer of your personal data is carried out in accordance with applicable privacy laws and, in particular, that appropriate contractual, technical, and organizational measures are in place such as the Standard Contractual Clauses approved by the EU Commission.
How long do we keep your data?
We will store your personal data as long as is necessary for the purposes named in this privacy notice, especially for the fulfilment of our contractual and legal obligations. In general, we retain the data you provide to us for as long as you have your account with us and thereafter for such period as you may have questions or a claim in relation to our services, notwithstanding any superior retention period that we may be obliged to observe in accordance with legal requirements applicable to us.
The specific retention periods for personal data are documented in our regional data retention guidelines because how long we retain personal data may vary depending on the services we provide and our legal obligations under applicable national law. The following factors typically affect the retention period:
Necessity for the provision of our services. This includes executing the user agreement with you, maintaining, and improving the performance of our products, keeping our systems secure, and maintaining appropriate business and financial records. Most of our retention periods are determined based on this general rule.
Consent-based processing of personal data. If we process personal data based on consent, we store the data for as long as necessary in order to process it according to your consent.
Statutory, contractual, or other similar obligations. Retention obligations may arise, for example, from laws or official orders. It may also be necessary to store personal data regarding pending or future legal disputes. Personal data contained in contracts, notifications and business letters may be subject to statutory storage obligations depending on national law.
What are your data protection rights?
We would like to make sure you are fully aware of all your data protection rights. You are entitled to the following:
Right to access – You have the right to ask us for copies of your personal information.
Right to rectification – You have the right to ask us to rectify information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete.
Right to erasure – You have the right to ask us to erase your personal information in certain circumstances.
Right to restrict processing – You have the right to ask us to restrict the processing of your information in certain circumstances.
Right to object to processing – You have the right to object to processing if we are able to process your information because the process is in our legitimate interests.
Right to data portability – You can request that we transfer the data we have collected to another organization or directly to you, under certain conditions.
Inquiries, requests, and complaints
You can reach out to our privacy team for general questions on privacy and in order to exercise your data protection rights by sending an email to gdpr@wwfmarket.com.
This is without prejudice to your right to launch a claim with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or the data protection supervisory authority in the EU country in which you live or work where you think we have infringed data protection laws.
Changes to this notice
We keep our privacy notice under regular review and might introduce updates from time to time. This privacy notice was last updated on 29.09.2022.