Privatumo strategija

Last updated: January 7, 2026

Cake Box Store operates this store and website, including all related information, content, features, tools, products and services, in order to provide you, the customer, with a curated shopping experience (the “Services”). Cake Box Store is powered by Shopify, which enables us to provide the Services to you.

This Privacy Policy describes how we collect, use, and disclose your personal information when you visit, use, or make a purchase or other transaction using the Services, or otherwise communicate with us. If there is a conflict between our Terms of Service and this Privacy Policy, this Privacy Policy controls with respect to the collection, processing, and disclosure of your personal information.

Please read this Privacy Policy carefully. By using and accessing any of the Services, you acknowledge that you have read this Privacy Policy and understand the collection, use, and disclosure of your information as described in this Privacy Policy.

1. Personal Information We Collect or Process

When we use the term “personal information,” we are referring to information that identifies or can reasonably be linked to you or another person. Personal information does not include information that is collected anonymously or that has been de-identified so that it cannot identify or be reasonably linked to you.

We may collect or process the following categories of personal information depending on how you interact with the Services, where you live, and as permitted or required by applicable law:

  • Contact details including your name, billing address, phone number, and email address

  • Financial information including payment card information and payment confirmations (payments are processed securely by Shopify and payment providers; we do not store full card numbers)

  • Transaction information including products you view, add to your cart, and purchase, as well as your purchase history

  • Communications with us including the information you include when you contact customer support

  • Device information including information about your device, browser, network connection, IP address, and other unique identifiers

    Usage information including information regarding your interaction with the Services, such as how and when you navigate the website

    We do not intentionally collect or request sensitive personal data (such as health data or biometric data).

2. Personal Information Sources

We may collect personal information from the following sources:

  • Directly from you, including when you purchase a product, contact us, or otherwise provide your personal information

  • Automatically through the Services, including from your device when you visit our website and through cookies and similar technologies

  • From our service providers, including Shopify and payment providers, when they process your personal information on our behalf to provide the Services

3. How We Use Your Personal Information

Depending on how you interact with us or which of the Services you use, we may use personal information for the following purposes:

Provide, Improve, and Operate the Services

We use your personal information to provide you with the Services, including to process payments, complete transactions, deliver digital products (PDF recipes), send order confirmations and transactional emails, provide customer support, prevent fraud, and maintain our store operations.

Security and Fraud Prevention

We use your personal information to detect, investigate, or take action regarding possible fraudulent, illegal, unsafe, or malicious activity, protect the security of our website and business, and protect users and the public.

Communicating with You

We use your personal information to respond to inquiries and provide support related to orders, refunds, or technical issues.

Legal Reasons

We use personal information to comply with applicable law, respond to lawful requests, enforce our policies, and protect our legal rights.

We do not send newsletters or promotional marketing emails unless you explicitly request to receive them.

4. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA) or the United Kingdom, we process your personal data under the following legal bases:

  • Contract (Article 6(1)(b)): We process your personal information to fulfill your purchase, process payments, deliver digital products (PDF downloads), send transactional emails, and provide customer support.

  • Legitimate Interests (Article 6(1)(f)): We process your personal information to prevent fraud, secure our Services, improve store performance, and protect our legal rights, where these interests are not overridden by your rights and freedoms.

  • Legal Obligation (Article 6(1)(c)): We process certain information to comply with legal and tax obligations, including accounting requirements.

  • Consent (Article 6(1)(a)): We rely on consent where required for non-essential cookies or similar technologies. You may withdraw consent at any time through cookie settings.

5. Digital Products

If you purchase a digital product, we use your personal information (such as your email address and transaction details) to:

  • deliver the product to you (e.g., via download link or email confirmation),

  • provide access to your purchase, and

  • offer customer support

6. How We Disclose Personal Information

In certain circumstances, we may disclose your personal information to third parties for legitimate purposes subject to this Privacy Policy. These circumstances may include:

  • With Shopify and other service providers who enable the Services (such as payment processing, hosting, analytics, and customer support tools).

  • With third parties when required by law, such as to respond to lawful requests, enforce policies, or protect rights and safety.

  • In connection with a business transaction, such as a merger or business transfer, in compliance with applicable law.

We do not sell your personal information.

7. Relationship with Shopify

The Services are hosted by Shopify, which collects and processes personal information about your access to and use of the Services to provide and improve the Services.

Information you submit to the Services may be transmitted to and shared with Shopify and with third-party service providers that may be located in countries other than where you reside. To learn more about how Shopify uses your personal information, you can visit the Shopify Consumer Privacy Policy.

8. Cookies and Similar Technologies

We use cookies and similar technologies to operate our website and improve user experience. Some cookies are required for the website to function, while others may be used for analytics or functionality.

Where required by applicable law (including in the EU), we will ask for your consent before placing non-essential cookies on your device. You may manage cookie preferences using the cookie banner and settings.

9. Children’s Data

The Services are not intended for use by children, and we do not knowingly collect personal information from children under the age of majority in your jurisdiction. If you believe a child has provided personal information, please contact us so we can delete it.

10. Security and Retention of Your Information

We take reasonable steps to protect your personal information, but no security measures are perfect.

Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.

  • Order and transaction records (including invoices and payment confirmations) are typically retained for up to 10 years, as required by tax and accounting laws in Luxembourg.

  • Customer support communications are retained for up to 3 years, unless needed longer to resolve disputes or enforce agreements.

  • Website analytics and technical logs are retained for a limited period depending on the tools used and for security purposes.

You may request deletion of personal information where applicable, subject to legal retention requirements.

11. Your Rights and Choices (EEA / GDPR)

If you are located in the EEA or the United Kingdom, you have the following rights, subject to exceptions and limitations under applicable law:

  • Right of access to your personal information

  • Right to rectification of inaccurate personal information

  • Right to deletion (“right to be forgotten”)

  • Right to restrict processing

  • Right to data portability

  • Right to object to processing based on legitimate interests

  • Right to withdraw consent at any time where we rely on consent

  • Right to lodge a complaint with your local data protection authority

To exercise these rights, please contact us using the details below.

12. International Transfers

We may transfer, store, and process your personal information outside the country you live in. If we transfer personal information out of the EEA or the United Kingdom, we rely on recognized transfer mechanisms such as the European Commission’s Standard Contractual Clauses, unless the destination country has been deemed to provide an adequate level of protection.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our practices or for operational, legal, or regulatory reasons. We will post the updated Privacy Policy on this website and update the “Last updated” date.

14. Contact

If you have any questions about this Privacy Policy or our privacy practices, or if you would like to exercise your rights, please contact us:

Cake Box Store
Name: Gabriele Vaskyte 
Country: Luxembourg
Email: vaskyte.gabriele@gmail.com

For the purposes of applicable data protection laws, we are the data controller of your personal information.