Privacy policy
In short. We process the data necessary to run the site, manage orders, process payment, delivery, invoicing, support and, only where the law permits, commercial communications and site-usage analysis. We do not sell personal data.
1. Who is the data controller
The controller of personal data is STARPAY TECH SRL, a Romanian company with its registered office at Str. Belizarie 22-24, Bl. 5/1, Sc. D, Et. 2, Ap. 52, Sector 1, Bucharest, postal code 013968, registered with the Trade Registry under no. J2015012489400, tax ID RO35116262, operator of the online store and the RIVELO brand.
For questions about this policy or to exercise your rights, you can contact us at contact@rivelo.ro or +40 720 123 551. The company has not currently appointed a data protection officer, as no legal obligation to do so applies. Requests are handled directly by the controller.
2. Scope
This policy applies to individuals who visit rivelo.ro, create an account, place an order, request a quote, communicate with RIVELO, request installation or service, subscribe to commercial communications, or interact with the site's analytics and marketing features.
The policy applies to both individual customers and to representatives, employees or contact persons of business customers. Data relating exclusively to a legal entity is not personal data, but the data of individuals acting on its behalf is protected under the law.
3. What data we may process
- Identification and contact data: first name, last name, shipping or billing address, email address, phone number.
- Order and contract data: products ordered, value, date, order status, returns, warranties, installation or service requests.
- Billing data: information required to issue the invoice, including, as applicable, name, tax ID, registered office, bank account or other tax information.
- Payment data: payment method, transaction status and confirmation. RIVELO does not store full card details; online payment is processed by NETOPIA Payments and the financial institutions involved.
- Account data: account identifier, order history, preferences and login information technically protected by the platform.
- Communication data: the content of messages, requests, complaints and conversations with support.
- Technical and usage data: IP address, online identifiers, device type, browser, operating system, pages visited, events and interactions with the site.
- Marketing and preference data: newsletter choices, cookie and ad-personalization preferences, and interactions with commercial messages.
- Data needed for fraud prevention and security: risk indicators, access attempts, technical logs and information provided by the platform or payment processor.
Please do not send us, through the standard forms, special categories of data such as health information, biometric data or other sensitive data, unless strictly necessary and expressly requested.
4. Where we obtain the data from
- Directly from you, when you use the site, create an account, place an order or contact us.
- Automatically, through the Shopify platform, cookies and similar technologies, depending on the preferences you express.
- From providers involved in fulfilling the order, such as the payment processor, couriers, invoicing providers or installation and service partners.
- From public sources or from the organization you represent, when the order is placed on behalf of a legal entity.
5. Purposes, legal bases and retention periods
| Purpose | Data used | Legal basis | Indicative retention |
|---|---|---|---|
| Taking and fulfilling orders | Identification, contact, order, payment, delivery | Performance of the contract; pre-contractual steps | For the duration of the contract and afterward per statutory limitation periods |
| Invoicing and financial-accounting records | Identification, billing, order and payment | Legal obligation | Per the mandatory periods under tax and accounting law |
| Delivery, installation, service and warranties | Contact, order, address, communications, technical documents | Performance of the contract; legal obligation; legitimate interest | For the duration of the service and afterward per warranty and limitation periods |
| Managing the customer account | Identification, authentication, history and preferences | Performance of the contract; legitimate interest | Until the account is deleted, then only data that must be retained by law |
| Responding to requests and complaints | Contact, communications and related documents | Performance of the contract; legitimate interest; legal obligation | Generally 3 years from resolution, or longer if there is a dispute |
| Security and fraud prevention | Technical data, logs, transactions and risk indicators | Legitimate interest; legal obligation, as applicable | As long as necessary for the purpose and the defense of rights |
| Newsletter and promotional communications | Email, phone, preferences and interactions | Consent; where permitted by law, legitimate interest | Until consent is withdrawn or you object |
| Analytics and online advertising | Technical data, identifiers and online behavior | Consent for non-essential technologies | Per cookie lifespan and provider settings |
| Defense of rights and compliance | Data relevant to complaints, audits or disputes | Legal obligation; legitimate interest | For the duration of the procedure and applicable statutory periods |
The periods above are indicative. Once the applicable period expires, data is deleted, anonymized or retained under restricted access where there is a legal obligation, a dispute, or the need to establish, exercise or defend a right.
6. When providing data is mandatory
Data marked as required in the checkout process is necessary to enter into and perform the contract, issue the invoice, process payment and deliver the order. Refusing to provide it may make it impossible to process the order. Data requested solely for marketing or analytics is optional, and refusing it does not affect your ability to purchase products.
7. Who we may disclose data to
We share data only to the extent necessary and under appropriate contractual roles and obligations. Categories of recipients may include:
- Shopify International Limited and the Shopify entities or sub-processors that provide the e-commerce platform, hosting, security and store functionality.
- NETOPIA Payments, financial institutions and anti-fraud providers, for processing and securing payments.
- Couriers such as Sameday and Cargus, and other logistics partners activated by RIVELO.
- Invoicing and accounting providers, including Oblio, accountants, auditors and relevant public systems, such as ANAF/SPV and RO e-Invoice.
- Installation, service or technical support partners, when the service is requested and the data is necessary for scheduling and delivery.
- Email, communication, support, security, backup, hosting and IT maintenance providers.
- Analytics and advertising platforms, such as Google, Meta or TikTok, only if those tools are enabled and the necessary consent has been given.
- Public authorities, courts, bailiffs, legal advisors or other recipients where disclosure is required by law or necessary to defend a right.
We do not sell or rent personal data. The actual list of providers may change over time; any relevant change will be reflected in this policy or in the consent-management tools.
8. Shopify and roles regarding data protection
RIVELO uses the Shopify platform. For most operations related to running the store and processing customer data on our behalf, the applicable Shopify entity acts as a processor, under the data processing agreement included in Shopify's terms. For merchants in Europe, the main contracting entity is generally Shopify International Limited, Ireland.
For certain services aimed directly at consumers, such as Shop or Shop Pay, or for certain features of Shopify's own network, Shopify may act as an independent controller. In these cases, processing is also governed by Shopify's own disclosures provided directly to the user.
RIVELO has Shopify Network Intelligence enabled, through which customer data is used, together with other data from the Shopify platform, to improve products, target advertising and personalize, in accordance with Shopify's Additional Services Terms. No other merchant has access to RIVELO's data through this feature. If we enable other similar features or expanded services in the future, this policy will be updated accordingly.
9. International transfers
Some providers may process data outside the European Economic Area. Shopify states that for merchants in Europe certain data is stored at rest in Europe, but international transfers necessary to provide the services may still occur.
Transfers to Canada may rely on the adequacy decision applicable to eligible organizations. For other transfers, Shopify and other providers may use the standard contractual clauses approved by the European Commission, processing agreements, transfer impact assessments and additional security measures. Where a provider is a valid participant in an adequacy framework recognized by the European Union, the transfer may also rely on that mechanism.
You may request further information about the safeguards applicable to a specific transfer at contact@rivelo.ro, to the extent that disclosure does not affect the confidentiality, security or rights of other individuals.
10. Cookies, analytics and advertising
Strictly necessary cookies are used for the store, cart, login, security and checkout to function. Personalization, analytics and marketing cookies are enabled only under the conditions required by law and, where necessary, after consent is given through the preference tool available on the site.
RIVELO may enable tools such as Google Analytics, Google Ads, Meta Pixel or TikTok Pixel. These tools must not load before valid consent for the relevant category has been given. Users must be able to refuse as easily as they accept, and must be able to change their choices later.
If we enable custom or similar (lookalike) audiences on Meta or Google, we may send those platforms your email address or other identifiers in cryptographically anonymized (hashed) form, to allow matching with that platform's user accounts, only on the legal basis applicable to the marketing category. You may object to this specific processing at any time, either by withdrawing consent for the marketing category in the preference center or by sending a request to contact@rivelo.ro.
Details on cookie categories, providers, purposes and durations are set out in the Cookie Policy and in the preferences panel. In the event of any difference, the actual technical configuration and the up-to-date information in the panel must be corrected promptly to match this policy.
11. Direct marketing
We send newsletters and promotional messages based on consent, except where the law allows communications about similar products or services to existing customers, always with a simple, free right to object.
You can unsubscribe via the link in each email or by sending a request to contact@rivelo.ro. Withdrawing consent does not affect the lawfulness of processing carried out beforehand and does not affect messages strictly necessary to fulfill your order, such as confirmations, invoices, delivery status or service communications.
12. Profiling and automated decisions
Data on interactions with the site may be used, with the necessary consent, for audience segmentation, campaign measurement and displaying relevant ads. These activities may constitute profiling within the meaning of the GDPR.
RIVELO does not, as a general practice, make decisions based solely on automated processing that produce legal effects on the user or similarly significantly affect them. Payment providers or the platform may use automated anti-fraud systems; an order flagged as risky may be checked further before acceptance. You may request human intervention and explanations when a relevant decision affects you.
13. Your rights
Under the GDPR, you are entitled, as applicable, to the following rights:
- The right to access your data and information about its processing.
- The right to rectification of inaccurate data and completion of incomplete data.
- The right to erasure, where there is no legal ground to continue retaining the data.
- The right to restriction of processing in the situations provided by law.
- The right to portability of the data you provided, where processing is automated and based on consent or contract.
- The right to object to processing based on legitimate interest and, at any time, to direct marketing.
- The right to withdraw consent at any time, without affecting prior processing.
- The right not to be subject to a decision based solely on automated processing, under the conditions provided by law.
- The right to lodge a complaint with ANSPDCP and the right to go to the competent courts.
14. How to exercise your rights
Send your request to contact@rivelo.ro, indicating clearly enough the right you are exercising and the information needed to identify your request. We may ask for reasonable additional information if there are doubts about the requester's identity, without collecting excessive data.
We generally respond within one month of receiving the request. This period may be extended by up to two further months for complex or numerous requests, in which case we will inform you within the first month. Exercising your rights is free of charge; for manifestly unfounded or excessive requests, the measures permitted under the GDPR may apply.
For complaints, you may contact the National Supervisory Authority for Personal Data Processing, B-dul G-ral. Gheorghe Magheru no. 28-30, Sector 1, postal code 010336, Bucharest, phone +40 31 805 9211, email anspdcp@dataprotection.ro, or through the official channels published on dataprotection.ro.
15. Data security
We apply technical and organizational measures appropriate to the risks, such as encrypted connections, access control, authentication, privilege limitation, updates, monitoring, backups and incident-response procedures. Key providers are selected taking into account their security measures and contractual obligations.
No transmission or storage can be guaranteed to be absolutely secure. If we identify a personal data breach, we assess the risk and notify the authority and affected individuals when required by law.
16. Children's data
The store is not intended for individuals under 16 and we do not knowingly seek to collect data from them for information-society services based on consent. Orders must be placed by individuals with legal capacity or with the involvement of a legal representative. If you believe a minor has provided us data without grounds, contact us for verification and appropriate measures.
17. Links and third-party services
The site may contain links to third-party services. When you leave rivelo.ro or use a service provided directly by a third party, that third party's policy may apply. RIVELO does not control the independent practices of other controllers, but selects the providers involved in its services with the reasonable care required by law.
18. Transfers in connection with a business transaction
In the event of a reorganization, merger, asset transfer or transfer of business, data may be disclosed to potential acquirers and transferred to the successor entity, under confidentiality conditions and in compliance with GDPR principles. Data subjects will be informed when the law requires separate notice.
19. Updates to this policy
We may update this policy to reflect legislative, technical, commercial changes or changes in the providers used. The current version is published on the site together with the date of the last update. For significant changes, we may display an additional notice or request new consent where the legal basis requires it.
20. Contact
STARPAY TECH SRL – RIVELO
Registered office: Str. Belizarie 22-24, Bl. 5/1, Sc. D, Et. 2, Ap. 52, Sector 1, Bucharest, postal code 013968, Romania
Email: contact@rivelo.ro
Phone: +40 720 123 551
This is an English translation provided for convenience. In case of any discrepancy, the Romanian-language version of this policy shall prevail.