Privacy policy
Last updated: July 18, 2026
This Privacy Policy explains how we process personal data when you use the One by One Design e-shop, purchase goods or services, subscribe to the newsletter, communicate with customer support and use related e-shop functions.
The controller of personal data is JK Foto Studio s.r.o., with registered seat at Priemyselná 10, 918 38 Trnava, Slovak Republic, Company ID: 44101511, Tax ID: 2022597225, VAT ID: SK2022597225, registered in the Commercial Register of the District Court Trnava, section Sro, file no. 21830/T.
Contact for personal data protection questions and exercising data subject rights: jana@onebyone.sk, phone: +421 905 326 618, postal address: JK Foto Studio s.r.o., Priemyselná 10, 918 38 Trnava, Slovak Republic.
The e-shop operates on the Shopify platform. Shopify provides us with the technical infrastructure of the e-shop, checkout, customer accounts, security tools and related services. Information about how Shopify processes personal data of users and customers is also available in Shopify's policies: Shopify Consumer Privacy Policy and at the Shopify Privacy Portal.
Personal data we process
We process mainly the following categories of personal data, depending on how you communicate with us and which services you use:
- Identification and contact details: first name, surname, e-mail, phone number, billing address, delivery address and details stated in the customer account.
- Order and transaction data: ordered products or services, variants, prices, discounts, gift vouchers, gift wrapping or dedication, delivery method, payment method, order status, returns, complaints and related communication.
- Payment data: information needed to process and confirm payment. We do not process full payment card numbers directly; they are processed by the relevant payment service provider or Shopify.
- Communication: content of e-mails, messages, forms, questions, feedback, reviews or other communication you send to us.
- Newsletter and marketing preferences: e-mail address, information about subscribing to or unsubscribing from the newsletter, and possibly data about delivery and opening of marketing communication if we use such functionality.
- Technical and analytics data: IP address, device and browser identifiers, data about use of the e-shop, viewed pages, interactions with products, cart or checkout, cookies and similar technologies.
Sources of personal data
We obtain personal data mainly directly from you when you create an order, account, fill in a form, subscribe to the newsletter or contact us. Some data is generated automatically when using the e-shop, such as technical data, device data and cookies. We may receive some data from our service providers, especially Shopify, payment gateways, carriers, technical tools, marketing tools or fraud prevention tools.
Purposes and legal bases of processing
| Purpose of processing | Legal basis |
|---|---|
| Processing the order, conclusion and performance of a purchase contract or service contract, delivery of goods, payment, customer account and related communication. | Performance of a contract or pre-contractual measures under Article 6(1)(b) GDPR. |
| Issuing and retaining accounting and tax documents, fulfilling statutory information obligations, keeping records of consumer rights. | Compliance with a legal obligation under Article 6(1)(c) GDPR. |
| Handling contract withdrawal, returns, complaints, customer requests or complaints. | Performance of a contract, compliance with a legal obligation and legitimate interest under Article 6(1)(b), (c) and (f) GDPR. |
| Direct communication with the customer, answers to questions, technical support and protection of the rights of the merchant or customer. | Performance of a contract or legitimate interest under Article 6(1)(b) and (f) GDPR. |
| Securing the e-shop, fraud prevention, handling security incidents, protection of the payment and purchasing process. | Legitimate interest under Article 6(1)(f) GDPR, or compliance with a legal obligation. |
| Sending newsletters and marketing e-mails if you subscribe to them. | Consent under Article 6(1)(a) GDPR, or legitimate interest when communicating with customers to the extent permitted by legal regulations. |
| Traffic analytics, e-shop performance measurement and user-experience improvement through Shopify Analytics, Google Analytics and Microsoft Clarity. Before analytics consent, Clarity operates without optional identifiers. | Consent under Article 6(1)(a) GDPR for identifier-based measurement; legitimate interest under Article 6(1)(f) GDPR for necessary technical diagnostics without optional identifiers. |
| Marketing cookies, advertising pixels, campaign measurement, remarketing and audience creation through Google Merchant Center, GLAMI, Meta Pixel for Facebook and Instagram, and Pinterest Tag. | Consent under Article 6(1)(a) GDPR and rules for storing or reading information from terminal equipment. |
Who we share personal data with
We provide personal data only to the extent necessary for the stated purposes. Recipients or processors may include in particular:
- Shopify and companies in the Shopify group, which provide operation of the e-shop, checkout, customer accounts, security and analytics functions,
- payment service providers and digital wallets available at checkout, such as payment cards, Apple Pay or Google Pay, if you use them for payment,
- carriers, pickup points and logistics partners according to the selected delivery method,
- technical suppliers of the e-shop, hosting, development, security and service tools, including applications used for specific e-shop functions such as gift wrapping or customer forms,
- e-mail communication and newsletter tools, if we use them,
- analytics and marketing partners Shopify, Google, Microsoft Clarity, GLAMI, Meta Platforms Ireland Limited, Pinterest Europe Ltd. and Pinterest, Inc., within the scope of the relevant consent or necessary technical diagnostics without optional identifiers,
- accounting, tax, legal and other professional advisers,
- public authorities, courts, supervisory authorities or other persons if required by law or necessary to protect our rights.
If a third party acts as an independent controller, it processes personal data according to its own privacy policy. This applies in particular to some payment services, delivery services, advertising platforms and social networks.
Shopify and international transfers
Because the e-shop is built on the Shopify platform, personal data may be transferred and processed outside the Slovak Republic or the European Economic Area. If personal data is transferred to third countries, we rely on appropriate safeguards under the GDPR, in particular the European Commission's standard contractual clauses, an adequacy decision or another lawful mechanism.
Depending on the e-shop settings and services, Shopify may also process data for operation, security, service improvement, fraud prevention, analytics or Shopify network functions. Details are available in the Shopify documents linked above.
Cookies and similar technologies
The e-shop uses cookies, pixels and similar technologies. Necessary and functional technologies provide the e-shop, cart, checkout, security, localization and payment options. Identifier-based analytics and marketing technologies are used only after the relevant consent has been granted. You can change or withdraw consent at any time through the consent settings on the website.
Before analytics consent is granted, Microsoft Clarity operates in cookieless mode: it sends technical request and page-interaction data without storing or reading Clarity identifiers. Identifier mode starts only after analytics consent. We carry out technical measurement without optional identifiers on the basis of our legitimate interest in a secure and functional e-shop; identifier-based analytics and marketing processing is based on consent under Article 6(1)(a) GDPR.
| Category and provider | Cookies or identifiers | Purpose and recipient | Duration and activation |
|---|---|---|---|
| Necessary and preference – Shopify / Shop |
_shopify_essential, localization, _shop_app_essential
|
Operation, security, country/language choice and Shop features. The recipient is Shopify and the Shopify group. | Up to 365 days; available without marketing or analytics consent. Shopify may also use other necessary cart, checkout, account and fraud-prevention cookies listed in its policy. |
| Functional / payment – Google Pay |
NID on .google.com
|
Displaying and operating the payment option and remembering Google service preferences. Google acts under its own policies. | Approximately 183 days; it may be stored when the Google Pay frame is displayed, before a consent choice. |
| Analytics and marketing – Shopify |
_shopify_s, _shopify_y, _shopify_analytics, _shopify_marketing
|
Session measurement, store performance and marketing attribution. The recipient is Shopify and the Shopify group. | 30 minutes; 365 days; 365 days; 365 days. Only after the relevant analytics or marketing consent. |
| Analytics and marketing – Google Analytics / Merchant Center |
_ga, _ga_MQ5T7X5HPL, _ga_97WPZ9J3XM
|
Traffic, behavior, conversion and product-campaign performance measurement. The recipient is Google. | Up to 400 days. Only after analytics or marketing consent. |
| Analytics – Microsoft Clarity |
_clck, _clsk, ANONCHK, MR, SM, MUID, SRM_B on our domain and the .clarity.ms and .bing.com domains |
Technical diagnostics and understanding website use. The recipient is Microsoft. Before consent and after withdrawal, Clarity may send requests without these identifiers. | 365 days; 1 day; 10 minutes; 7 days; session; 390 days; 390 days. Identifiers only after analytics consent. |
| Marketing – GLAMI |
gp_s, gp_e, glm_usr, glm_usr_tmp on our domain and .glami.sk
|
Measuring visits, product interactions and orders, campaign attribution and remarketing. The recipient is GLAMI. | On this e-shop, up to 400 days was measured for gp_s/gp_e and 365 days for glm_usr/glm_usr_tmp. Only after marketing consent. |
| Marketing – Meta Pixel for Facebook and Instagram |
_fbp, _fbc and fr; Meta may use related identifiers |
Measuring visits, cart, checkout and purchases, attribution, audience creation and ad personalization on Facebook and Instagram. The recipient is Meta Platforms Ireland Limited; enhanced matching may send permitted contact data to Meta in hashed form. | Up to 90 days under Meta's policy. Only after marketing consent. |
| Marketing – Pinterest Tag |
_pinterest_sess, _pinterest_ct, _pinterest_ct_rt, _epik, _derived_epik, _pin_unauth, _pinterest_ct_ua, _routing_id, _pin_aem
|
Measuring visits, cart, checkout and purchases, attribution, audience creation and ad personalization on Pinterest. The recipients are Pinterest Europe Ltd. and Pinterest, Inc.; _pin_aem may contain hashed data when automatic enhanced matching is used. |
Up to 1 year under Pinterest documentation. Only after marketing consent. |
After consent is withdrawn, we stop sending new optional analytics and marketing events. Some cookies already stored by a provider may remain in the browser until they expire or are manually deleted; the mere presence of a stored cookie after withdrawal does not mean that the e-shop continues to use it for new measurement.
Providers may also process data outside the European Economic Area. In that case, the relevant GDPR mechanisms are used, in particular an adequacy decision, the EU–U.S. Data Privacy Framework or standard contractual clauses. Details and current provider lists are available from Shopify, Google, Microsoft Clarity, GLAMI, Meta and Pinterest.
Newsletter and marketing communication
You can subscribe to the newsletter voluntarily. Newsletter subscription is not a condition of purchase. You can unsubscribe from the newsletter at any time using the link in the marketing e-mail or by contacting the merchant at jana@onebyone.sk. Unsubscribing from the newsletter does not affect the lawfulness of processing before consent was withdrawn and does not prevent us from sending necessary transactional communication related to an order.
How long we retain personal data
We retain personal data only for the period necessary for the purposes for which it was obtained, or for the period required by legal regulations. Typically:
- order-related data is retained for the period necessary to perform the contract, handle contractual rights, complaints, withdrawals and protect legal claims,
- accounting and tax documents are retained for the statutory period, generally 10 years,
- customer account data is retained for the duration of the account or while we need it for the above purposes,
- newsletter data is retained until unsubscribing from the newsletter, withdrawal of consent or termination of newsletter use,
- data from complaints, returns, customer complaints and legal claims is retained for the period necessary to handle them and subsequently protect rights,
- cookies and similar technologies are retained according to their purpose, type and the settings of the specific tool or browser.
Your rights
Subject to the conditions set out in the GDPR, you have in particular the following rights:
- the right of access to personal data,
- the right to rectification of inaccurate or incomplete data,
- the right to erasure of personal data,
- the right to restriction of processing,
- the right to object to processing based on legitimate interest, including objection to direct marketing,
- the right to data portability,
- the right to withdraw consent if processing is based on consent,
- the right to lodge a complaint or submit a proposal to start proceedings with a supervisory authority.
You may exercise your rights by e-mail at jana@onebyone.sk or by post to the controller's address. Before handling a request, we may reasonably verify your identity to protect your data against unauthorized disclosure.
The supervisory authority in the Slovak Republic is the Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava, website: https://dataprotection.gov.sk/.
Automated decision-making and profiling
When operating the e-shop, we do not carry out automated individual decision-making under Article 22 GDPR that would have legal effects or similarly significantly affect you. Some providers of payment, security or advertising services may use automated tools for fraud prevention, security evaluation, analytics or marketing profiling according to their own policies and applicable legal bases.
Children's data
The e-shop is not intended for persons under 16 years of age. We do not knowingly collect personal data of children without the required consent of a legal representative. If you believe that a child has provided us with personal data, contact us and we will review the situation.
Security
We take appropriate technical and organizational measures to protect personal data. However, no method of transmitting or storing data is absolutely secure. We recommend that you do not send us sensitive or confidential information through unsecured channels unless necessary.
Third-party links
The e-shop may contain links to websites or profiles of third parties, especially social networks, payment services, carriers or other services. The operators of those websites are responsible for processing personal data on them according to their own privacy policies.
Changes to this policy
We may update this policy, especially when legal regulations, Shopify settings, applications used, marketing tools or methods of personal data processing change. The current version is always available on this page.