Privacy Policy
Last updated: 22.03.2026
This Privacy Policy explains how CRNO Holdings OÜ, an Estonian private limited company, registry code 17514619, registered address Estonia, Harju maakond, Tallinn, Kesklinna linnaosa, Narva mnt 5, 10117, operating the website plushins.com and the brand Plushins (“Plushins”, “we”, “us”, “our”), collects, uses, stores, and protects your personal data.
This Privacy Policy applies when you visit our website, place an order, place a preorder, contact us, subscribe to marketing, or otherwise interact with our services.
For the purposes of the EU General Data Protection Regulation GDPR, CRNO Holdings OÜ is the data controller of your personal data.
Contact email: info@plushins.com
1. Personal Data We Collect
We may collect the following personal data.
1.1 Order and customer information
When you place an order or preorder, we may collect:
- first and last name;
- billing address;
- shipping address;
- email address;
- phone number;
- order details;
- product size, quantity, and purchase history;
- payment status;
- delivery and tracking information.
1.2 Payment information
Payments are processed by third-party payment providers.
We do not store your full card number on our website.
Payment providers may process payment details such as card information, billing information, fraud-check data, transaction information, and refund information.
1.3 Website and device information
When you visit our website, we may collect:
- IP address;
- browser type;
- device type;
- operating system;
- pages viewed;
- time spent on the website;
- referring website or source;
- cookies and similar tracking data.
1.4 Communication data
If you contact us by email, form, social media, or customer support, we may collect the information you provide, including your name, email address, order number, message content, and attachments.
1.5 Marketing data
If you subscribe to emails, SMS, or other marketing updates, we may process your contact details, marketing preferences, consent status, and interaction with our messages.
2. Why We Process Your Data
We process personal data for the following purposes.
2.1 To process and fulfill orders
We use your data to:
- confirm your order or preorder;
- process payment;
- reserve your product;
- arrange production, packing, and delivery;
- send order confirmations and shipping updates;
- provide customer support;
- handle returns, refunds, complaints, and order issues.
2.2 To operate the website
We use data to keep our website secure, functional, and user-friendly.
2.3 To provide customer support
We use your contact and order information to answer questions, solve problems, and provide help with your order.
2.4 To send marketing messages
If you consent or where legally allowed, we may send you emails or messages about Plushins products, offers, launches, preorder updates, promotions, and other brand-related updates.
You can unsubscribe at any time.
2.5 To improve our business
We may use analytics and customer interaction data to understand how visitors use our website, improve our products, improve website performance, measure marketing results, and develop our services.
2.6 To comply with legal obligations
We may process and store certain data for accounting, tax, fraud prevention, consumer protection, legal claims, and compliance with Estonian and EU laws.
3. Legal Basis for Processing
We process personal data under the following GDPR legal bases.
3.1 Performance of a contract
We process your data when it is necessary to fulfill your order, preorder, delivery, return, refund, or customer support request.
3.2 Legal obligation
We process certain data to comply with accounting, tax, consumer protection, and other legal obligations.
3.3 Consent
We use consent where required, for example for marketing emails, SMS marketing, and non-essential cookies.
You may withdraw your consent at any time.
3.4 Legitimate interests
We may process data for legitimate business interests, such as fraud prevention, website security, customer service, business analytics, service improvement, and protecting our legal rights.
4. Cookies and Tracking Technologies
Our website uses cookies and similar technologies.
Cookies may be used for:
- website functionality;
- cart and checkout operation;
- security;
- analytics;
- advertising and retargeting;
- remembering preferences;
- improving website performance.
Some cookies are necessary for the website to work. Other cookies, such as analytics and advertising cookies, may require your consent depending on your location.
You can manage or disable cookies in your browser settings. Disabling cookies may affect website functionality.
5. Sharing Personal Data with Third Parties
We only share personal data where necessary for our business, legal compliance, or with your consent.
We may share data with the following categories of third parties.
5.1 E-commerce platform providers
We may share data with website, checkout, hosting, and store-management service providers, including Shopify or similar providers.
5.2 Payment providers
We may share data with payment providers for payment processing, fraud checks, refunds, chargebacks, and transaction handling.
5.3 Delivery, logistics, and fulfillment partners
We may share data with warehouses, suppliers, shipping carriers, customs brokers, and third-party logistics providers to fulfill your order or preorder.
5.4 Marketing and analytics providers
We may share data with email marketing providers, advertising platforms, analytics tools, retargeting services, and customer communication tools.
5.5 Professional service providers
We may share data with accountants, legal advisors, IT service providers, compliance advisors, and business consultants.
5.6 Public authorities
We may disclose data to tax authorities, courts, regulators, law enforcement, or other authorities if required by law.
We do not sell your personal data.
6. International Data Transfers
Because Plushins may work with service providers, payment processors, platforms, warehouses, shipping partners, suppliers, and fulfillment partners located outside Estonia and outside the European Economic Area, your personal data may be transferred internationally.
Where required, we use appropriate safeguards, such as:
- European Commission adequacy decisions;
- standard contractual clauses;
- contractual data protection obligations;
- technical and organizational security measures.
7. Data Retention
We keep personal data only for as long as necessary for the purposes described in this Privacy Policy.
Typical retention periods:
- order and invoice data are stored as required by accounting and tax laws;
- customer support messages are stored as long as needed to resolve issues and protect legal rights;
- marketing data is stored until you unsubscribe or withdraw consent;
- analytics and cookie data are stored according to the settings of the relevant tools.
When data is no longer needed, we delete it or anonymize it.
8. Data Security
We use reasonable technical and organizational measures to protect personal data from unauthorized access, loss, misuse, alteration, or disclosure.
These measures may include:
- restricted access to customer data;
- secure payment processing through third-party providers;
- password and account protection;
- website security tools;
- encrypted connections where available;
- limiting data access to people and service providers who need it.
No online service is completely secure, but we take reasonable steps to protect your data.
9. Your Rights Under GDPR
Depending on your location and applicable law, you may have the following rights:
- right to access your personal data;
- right to correct inaccurate data;
- right to delete your data;
- right to restrict processing;
- right to object to processing;
- right to data portability;
- right to withdraw consent at any time;
- right to object to direct marketing;
- right to lodge a complaint with a data protection authority.
To exercise your rights, contact us at:
We may need to verify your identity before processing your request.
10. Marketing Communications
If you subscribe to our marketing, we may send you promotional emails, product updates, preorder updates, launch offers, and other Plushins-related messages.
You can unsubscribe at any time by clicking the unsubscribe link in our emails or contacting us at:
We will not send you marketing messages where consent is required unless you have given consent.
11. Children’s Privacy
Our website is not intended for children under the age of 16.
We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will take appropriate steps to delete it.
12. Preorders
If you place a preorder, we process your personal data to reserve your product, process payment, communicate production or shipping updates, and fulfill the order once the product is ready.
If a preorder is cancelled or refunded, we may still retain certain transaction data where required for accounting, tax, fraud prevention, consumer protection, or legal compliance.
13. Complaints
If you believe your personal data rights have been violated, please contact us first at:
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time.
The latest version will always be available on our website. The “Last updated” date at the top shows when the policy was last changed.