Privacy policy
Last updated: 2026-08-15
Personal details are not required
You do not need to write or submit personal details to browse the catalogue or use the storefront in general. Viewing products is not conditioned on registration or a profile.
Personal data is processed only when you choose to register, sign in, place an order, or contact support — not merely for browsing. Cookie consent is about optional technical storage, not a requirement to fill in personal forms.
Payments — handled by payment providers
Bank and payment card details are handled by the respective payment provider(s). We do not enter or store full card numbers, CVV, or card secrets in our shop systems or databases.
At checkout, you pay through the payment provider’s secure flow. We only receive non-sensitive outcomes such as payment status (paid or failed) and a provider reference (for example a payment-intent or transaction id). We do not keep cards on file for reuse in this store.
This store (relishbg) processes personal data needed to provide the online shop: account details, orders, delivery, and support. The service is operated with infrastructure and tooling from Csitea.
We do not sell your personal data. Session authentication uses a strictly necessary HttpOnly cookie. Language preference may be stored in a first-party cookie or local storage so the site can open in your language.
For questions about your data, contact the shop operator via the contact details published on the site. You may request access or deletion where applicable under applicable law.
Who is responsible
This notice is for customers of this online shop. Personal data is processed to run the storefront, your account, orders, delivery and support. The seller named on the contact page handles orders, deliveries and returns. The platform operator named on the data-protection page is the data controller for the site.
The platform operator (data controller) is Csitea Oy Ab.
What we process
Depending on what you choose to do, this may include: name and email; sign-in identifiers (including a Google or Facebook user id if you use those buttons); delivery address; order history and payment status (not full card numbers); language preference; support messages; and feedback you send while signed in. Browsing the catalogue does not require a profile.
Why we process it
We process personal data to perform a contract with you (registration, checkout, delivery), to meet legal duties (invoices, tax and consumer-law records), with your consent where the law requires it (optional cookies; some social-login permissions), and for limited legitimate interests such as keeping the shop secure and preventing abuse. You can withdraw cookie consent at any time via Cookie settings in the footer.
Who else receives data
Payment providers receive what they need to take payment. Delivery partners receive what they need to deliver an order. Hosting and shop tooling are provided by the platform operator. We do not sell your personal data and we do not use it to build advertising profiles for third parties.
How long we keep it
We keep account and order data for as long as needed to provide the shop and to meet legal record-keeping duties (for example invoices). Sign-in session cookies last for the signed-in session. When data is no longer needed and no law requires us to keep it, we delete or anonymise it.
Your rights
Under the GDPR you may request access, correction, erasure, restriction or portability of your personal data, and you may object to certain processing. How to make a request, how we verify identity, and how to complain to a supervisory authority are explained on the data-protection page.
Google and Facebook sign-in
If you choose to continue with Google or Facebook, that provider authenticates you and may share a verified email and a provider user id so we can create or link your shop account. We do not post to your social profile. Disconnecting Facebook is described on the Facebook data-deletion page linked from that provider.