Privacy Policy

Last updated: 22.03.2026

This Privacy Policy explains how CRNO Holdings OÜ, an Estonian private limited company, registry code 17514619, registered address Estonia, Harju maakond, Tallinn, Kesklinna linnaosa, Narva mnt 5, 10117, operating the website plushins.com and the brand Plushins (“Plushins”, “we”, “us”, “our”), collects, uses, stores, and protects your personal data.

This Privacy Policy applies when you visit our website, place an order, place a preorder, contact us, subscribe to marketing, or otherwise interact with our services.

For the purposes of the EU General Data Protection Regulation GDPR, CRNO Holdings OÜ is the data controller of your personal data.

Contact email: info@plushins.com


1. Personal Data We Collect

We may collect the following personal data.

1.1 Order and customer information

When you place an order or preorder, we may collect:

  • first and last name;
  • billing address;
  • shipping address;
  • email address;
  • phone number;
  • order details;
  • product size, quantity, and purchase history;
  • payment status;
  • delivery and tracking information.

1.2 Payment information

Payments are processed by third-party payment providers.

We do not store your full card number on our website.

Payment providers may process payment details such as card information, billing information, fraud-check data, transaction information, and refund information.

1.3 Website and device information

When you visit our website, we may collect:

  • IP address;
  • browser type;
  • device type;
  • operating system;
  • pages viewed;
  • time spent on the website;
  • referring website or source;
  • cookies and similar tracking data.

1.4 Communication data

If you contact us by email, form, social media, or customer support, we may collect the information you provide, including your name, email address, order number, message content, and attachments.

1.5 Marketing data

If you subscribe to emails, SMS, or other marketing updates, we may process your contact details, marketing preferences, consent status, and interaction with our messages.


2. Why We Process Your Data

We process personal data for the following purposes.

2.1 To process and fulfill orders

We use your data to:

  • confirm your order or preorder;
  • process payment;
  • reserve your product;
  • arrange production, packing, and delivery;
  • send order confirmations and shipping updates;
  • provide customer support;
  • handle returns, refunds, complaints, and order issues.

2.2 To operate the website

We use data to keep our website secure, functional, and user-friendly.

2.3 To provide customer support

We use your contact and order information to answer questions, solve problems, and provide help with your order.

2.4 To send marketing messages

If you consent or where legally allowed, we may send you emails or messages about Plushins products, offers, launches, preorder updates, promotions, and other brand-related updates.

You can unsubscribe at any time.

2.5 To improve our business

We may use analytics and customer interaction data to understand how visitors use our website, improve our products, improve website performance, measure marketing results, and develop our services.

2.6 To comply with legal obligations

We may process and store certain data for accounting, tax, fraud prevention, consumer protection, legal claims, and compliance with Estonian and EU laws.


3. Legal Basis for Processing

We process personal data under the following GDPR legal bases.

3.1 Performance of a contract

We process your data when it is necessary to fulfill your order, preorder, delivery, return, refund, or customer support request.

3.2 Legal obligation

We process certain data to comply with accounting, tax, consumer protection, and other legal obligations.

3.3 Consent

We use consent where required, for example for marketing emails, SMS marketing, and non-essential cookies.

You may withdraw your consent at any time.

3.4 Legitimate interests

We may process data for legitimate business interests, such as fraud prevention, website security, customer service, business analytics, service improvement, and protecting our legal rights.


4. Cookies and Tracking Technologies

Our website uses cookies and similar technologies.

Cookies may be used for:

  • website functionality;
  • cart and checkout operation;
  • security;
  • analytics;
  • advertising and retargeting;
  • remembering preferences;
  • improving website performance.

Some cookies are necessary for the website to work. Other cookies, such as analytics and advertising cookies, may require your consent depending on your location.

You can manage or disable cookies in your browser settings. Disabling cookies may affect website functionality.


5. Sharing Personal Data with Third Parties

We only share personal data where necessary for our business, legal compliance, or with your consent.

We may share data with the following categories of third parties.

5.1 E-commerce platform providers

We may share data with website, checkout, hosting, and store-management service providers, including Shopify or similar providers.

5.2 Payment providers

We may share data with payment providers for payment processing, fraud checks, refunds, chargebacks, and transaction handling.

5.3 Delivery, logistics, and fulfillment partners

We may share data with warehouses, suppliers, shipping carriers, customs brokers, and third-party logistics providers to fulfill your order or preorder.

5.4 Marketing and analytics providers

We may share data with email marketing providers, advertising platforms, analytics tools, retargeting services, and customer communication tools.

5.5 Professional service providers

We may share data with accountants, legal advisors, IT service providers, compliance advisors, and business consultants.

5.6 Public authorities

We may disclose data to tax authorities, courts, regulators, law enforcement, or other authorities if required by law.

We do not sell your personal data.


6. International Data Transfers

Because Plushins may work with service providers, payment processors, platforms, warehouses, shipping partners, suppliers, and fulfillment partners located outside Estonia and outside the European Economic Area, your personal data may be transferred internationally.

Where required, we use appropriate safeguards, such as:

  • European Commission adequacy decisions;
  • standard contractual clauses;
  • contractual data protection obligations;
  • technical and organizational security measures.

7. Data Retention

We keep personal data only for as long as necessary for the purposes described in this Privacy Policy.

Typical retention periods:

  • order and invoice data are stored as required by accounting and tax laws;
  • customer support messages are stored as long as needed to resolve issues and protect legal rights;
  • marketing data is stored until you unsubscribe or withdraw consent;
  • analytics and cookie data are stored according to the settings of the relevant tools.

When data is no longer needed, we delete it or anonymize it.


8. Data Security

We use reasonable technical and organizational measures to protect personal data from unauthorized access, loss, misuse, alteration, or disclosure.

These measures may include:

  • restricted access to customer data;
  • secure payment processing through third-party providers;
  • password and account protection;
  • website security tools;
  • encrypted connections where available;
  • limiting data access to people and service providers who need it.

No online service is completely secure, but we take reasonable steps to protect your data.


9. Your Rights Under GDPR

Depending on your location and applicable law, you may have the following rights:

  • right to access your personal data;
  • right to correct inaccurate data;
  • right to delete your data;
  • right to restrict processing;
  • right to object to processing;
  • right to data portability;
  • right to withdraw consent at any time;
  • right to object to direct marketing;
  • right to lodge a complaint with a data protection authority.

To exercise your rights, contact us at:

info@plushins.com

We may need to verify your identity before processing your request.


10. Marketing Communications

If you subscribe to our marketing, we may send you promotional emails, product updates, preorder updates, launch offers, and other Plushins-related messages.

You can unsubscribe at any time by clicking the unsubscribe link in our emails or contacting us at:

info@plushins.com

We will not send you marketing messages where consent is required unless you have given consent.


11. Children’s Privacy

Our website is not intended for children under the age of 16.

We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will take appropriate steps to delete it.


12. Preorders

If you place a preorder, we process your personal data to reserve your product, process payment, communicate production or shipping updates, and fulfill the order once the product is ready.

If a preorder is cancelled or refunded, we may still retain certain transaction data where required for accounting, tax, fraud prevention, consumer protection, or legal compliance.


13. Complaints

If you believe your personal data rights have been violated, please contact us first at:

info@plushins.com


14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time.

The latest version will always be available on our website. The “Last updated” date at the top shows when the policy was last changed.