PRIVACY AND COOKIE POLICY

Our customers' security is really important to us and we're committed to ensuring we keep our customers safe. We take the privacy of your personal data very seriously and we are committed to protecting personal data we process against loss, supporting your privacy rights and, at all times, complying with laws and regulations on data protection This Privacy Policy describes how nokayadesign.com (the “Site” or “we”) collects, uses, and discloses your Personal Information when you visit or make a purchase from the Site.

After reviewing this policy, if you have additional questions, want more information about our privacy practices, or would like to make a complaint, please contact us by e-mail at tatyana.nosovskaya@nokayadesign.com or by mail using the details provided below:

NOKAYA LTD - 85 Great Portland Street, London, England, W1W 7LT

 We are committed to protecting your personal information and to being transparent about the information we hold about you. Using personal information allows us to develop a better understanding of our customers, and in turn to provide them with only that information they elect to receive.

The purpose of this policy is to give you a clear explanation about how we collect and process your personal information through your use of our website, including any data you may provide to us in-store.

We will use the information that we collect about you in accordance with:

  • The Data Protection Act 1998
  • The Privacy and Electronic Communications (EC Directive) Regulations 2003
  • The EU General Data Protection Regulation (Regulation EU 2016/679), (‘GDPR’) which becomes effective from 25 May 2018

When you visit the Site, we collect certain information about your device, your interaction with the Site, and information necessary to process your purchases. We may also collect additional information if you contact us for customer support. In this Privacy Policy, we refer to any information about an identifiable individual (including the information below) as “Personal Information”.

This privacy notice provides a summary of when we collect your personal data and what we do with it. It applies to data we collect by e-mail or phone, when you use our website, through social media and when you sign up for our newsletter, when you create an account or participate in our promotions.

 

INFO ON THE DATA WE MIGHT COLLECT

Personal information means any information about an individual from which that person can be identified. It does not include data where the identity has been removed, i.e. anonymous data. We may collect, use, store and transfer different kinds of personal information about you which we have grouped together as follows:

  • Identity Data includes first name, last name, username or similar identifier such as marital status, title, date of birth and gender.
  • Contact Data includes billing address, delivery address, email address and telephone numbers.
  • Financial Data includes bank account and payment card details.
  • Transaction Data includes details about payments to and from you and other details of products you have purchased from us.
  • Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access our Site.
  • Profile Data includes your username and password, purchases or orders made by you, your interests, preferences, feedback and survey responses.
  • Usage Data includes information about how you use our website, products and services.
  • Marketing and Communications Data includes your preferences in receiving marketing information from us and our third parties and your communication preferences. This also includes us making a note of conversations we have had with you in person and/or communications you have sent to Nokaya. This helps us to manage our relationship with you and ensures you only receive communications from us that are relevant and timely.

We also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data may be derived from your personal information but is not considered personal data in law as this data does not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific website feature or purchasing a specific product. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy policy.

We do not collect any “sensitive” data or Special Categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data). Nor do we collect any information about criminal convictions and offenses.

We use the data you share with us in a number of ways:

Information you give us - when you purchase goods from our website or in-store, or sign up to receive further information published by Nokaya. We will also keep a record of your purchases with us.

Automated technologies or interactions – as you interact with our website, we may automatically collect Technical Data about your equipment, browsing actions and patterns by using cookies and other similar technologies.

Information from third parties - analytics providers such as Google, but not limited to it, advertising networks such as Meta (Facebook, Instagram, Messenger), search information providers such as Google AdWords, but not limited to it.

The main aim of collecting such data from you is to fulfill any order that you have placed with Nokaya via Site, social media, messengers, phone calls or email communications. This is necessary in order to perform our contract with you. That is also necessary to provide help in creation and management of your Nokaya account, respond to your questions or requests, and is essential in order to perform our contract with you and/or necessary for our legitimate interests.

We aim to communicate with you in ways that you find relevant, timely, respectful, and never excessive. To do this, we use data that we have stored about you, such as your purchasing history, as well as any contact preferences you may have told us about.

We use our legitimate organization interest as the legal basis for communications by email and we will give you an opportunity to opt out of receiving electronic communications during your first purchase with us. If you do not opt out, we will provide you with an option to unsubscribe in every email that we send you subsequently. Alternatively, you can use the contact details at the end of this policy or update your contact preferences in your online account with us.

As part of our service to you, we may contact you by email or telephone to provide essential information related to your purchases.

SHARING DATA

We may share your personal data with third party service providers who help us to operate our website and fulfil your orders and deliver our products to you – e.g. credit reference agencies, couriers, IT support, our website host etc.

Your information may be transferred by Nokaya to countries within the EEA for processing, storage, administration or any other use stated in this notice. The purposes and processing associated with any such transfer will comply with all applicable data protection regulations, and we will take all steps necessary to ensure that your data is treated securely and in accordance with this privacy notice.

 

AUTOMATIC DECISION MAKING

If you are a resident of the EEA, you have the right to object to processing based solely on automated decision-making (which includes profiling), when that decision-making has a legal effect on you or otherwise significantly affects you.

We do not engage in fully automated decision-making that has a legal or otherwise significant effect using customer data.

Our processor Shopify uses limited automated decision-making to prevent fraud that does not have a legal or otherwise significant effect on you.

Services that include elements of automated decision-making include:

Temporary blacklist of IP addresses associated with repeated failed transactions. This blacklist persists for a small number of hours.

Temporary blacklist of credit cards associated with blacklisted IP addresses. This blacklist persists for a small number of days.

 

COOKIES

A cookie is a small amount of information that’s downloaded to your computer or device when you visit our Site. We use a number of different cookies, including functional, performance, advertising, and social media or content cookies. Cookies make your browsing experience better by allowing the website to remember your actions and preferences (such as login and region selection). This means you don’t have to re-enter this information each time you return to the site or browse from one page to another. Cookies also provide information on how people use the website, for instance whether it’s their first time visiting or if they are a frequent visitor.

We use the following cookies to optimize your experience on our Site and to provide our services.

Cookies Necessary for the Functioning of the Store

Name

Function

Duration

_ab

Used in connection with access to admin.

2y

_secure_session_id

Used in connection with navigation through a storefront.

24h

_shopify_country

Used in connection with checkout.

session

_shopify_m

Used for managing customer privacy settings.

1y

_shopify_tm

Used for managing customer privacy settings.

30min

_shopify_tw

Used for managing customer privacy settings.

2w

_storefront_u

Used to facilitate updating customer account information.

1min

_tracking_consent

Tracking preferences.

1y

c

Used in connection with checkout.

1y

cart

Used in connection with shopping cart.

2w

cart_currency

Used in connection with shopping cart.

2w

cart_sig

Used in connection with checkout.

2w

cart_ts

Used in connection with checkout.

2w

cart_ver

Used in connection with shopping cart.

2w

checkout

Used in connection with checkout.

4w

checkout_token

Used in connection with checkout.

1y

dynamic_checkout_shown_on_cart

Used in connection with checkout.

30min

hide_shopify_pay_for_checkout

Used in connection with checkout.

session

keep_alive

Used in connection with buyer localization.

2w

master_device_id

Used in connection with merchant login.

2y

previous_step

Used in connection with checkout.

1y

remember_me

Used in connection with checkout.

1y

secure_customer_sig

Used in connection with customer login.

20y

shopify_pay

Used in connection with checkout.

1y

shopify_pay_redirect

Used in connection with checkout.

30 minutes, 3w or 1y depending on value

storefront_digest

Used in connection with customer login.

2y

tracked_start_checkout

Used in connection with checkout.

1y

checkout_one_experiment

Used in connection with checkout.

session

 

Reporting and Analytics

Name

Function

Duration

_landing_page

Track landing pages.

2w

_orig_referrer

Track landing pages.

2w

_s

Shopify analytics.

30min

_shopify_d

Shopify analytics.

session

_shopify_s

Shopify analytics.

30min

_shopify_sa_p

Shopify analytics relating to marketing & referrals.

30min

_shopify_sa_t

Shopify analytics relating to marketing & referrals.

30min

_shopify_y

Shopify analytics.

1y

_y

Shopify analytics.

1y

_shopify_evids

Shopify analytics.

session

_shopify_ga

Shopify and Google Analytics.

session

The length of time that a cookie remains on your computer or mobile device depends on whether it is a “persistent” or “session” cookie. Session cookies last until you stop browsing and persistent cookies last until they expire or are deleted. Most of the cookies we use are persistent and will expire between 30 minutes and two years from the date they are downloaded to your device.

You can control and manage cookies in various ways. Please keep in mind that removing or blocking cookies can negatively impact your user experience and parts of our website may no longer be fully accessible.

Most browsers automatically accept cookies, but you can choose whether or not to accept cookies through your browser controls, often found in your browser’s “Tools” or “Preferences” menu. For more information on how to modify your browser settings or how to block, manage or filter cookies can be found in your browser’s help file or through such sites as: www.allaboutcookies.org.

Additionally, please note that blocking cookies may not completely prevent how we share information with third parties such as our advertising partners. To exercise your rights or opt-out of certain uses of your information by these parties, please follow the instructions in the “Behavioural Advertising” section above.

Please note that because there is no consistent industry understanding of how to respond to “Do Not Track” signals, we do not alter our data collection and usage practices when we detect such a signal from your browser.

 

DATA RETENTION

We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

When you place an order through the Site, we will retain your Personal Information for our records unless and until you ask us to erase this information. For more information on your right of erasure, please see the ‘Your rights’ section below.

 

YOUR RIGHTS

Under certain circumstances, you have rights under data protection laws in relation to your personal information:

  1. Request access to your personal information:

You have a right to request a copy of the personal information that we hold about you. Please contact via Contact us link on our Site to exercise this right, or any of the rights listed below. You will receive a response within five working days.

  1. Request correction of your personal information:

You have the right to request that we correct the personal information we hold about you, although we may need to verify the accuracy of the new information you provide to us.

  1. Request erasure of your personal information:

You have the right to request that we delete or remove personal information where there is no good reason for us continuing to process it. Please note that we may not always be able to comply with your request for erasure if there are specific legal reasons - which will be notified to you at the time of your request.

  1. Object to processing of your personal information:

You have the right to object to the processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.

  1. Request restriction of processing your personal information:

You have the right to request that we suspend the processing of your personal data in the following scenarios: if you want us to establish the data’s accuracy; where our use of the data is unlawful but you do not want us to erase it; where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.

  1. Request transfer of your personal information:

You have the right to request that the personal information we hold about you is transferred to you or to a third party. We will provide to you, or a third party you have chosen, your personal information in a structured, commonly used, machine-readable format. Please note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.

  1. Right to withdraw consent:

In circumstances where we are relying on your consent to process your personal data, you have the right to withdraw your consent at any time. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.

 

CHANGES

We may update this Privacy Policy from time to time in order to reflect, for example, changes to our practices or for other operational, legal, or regulatory reasons.

 

COMPLAINTS

As noted above, if you would like to make a complaint, please contact us by e-mail or by mail using the details provided under “Contact” above.

If you are not satisfied with our response to your complaint, you have the right to lodge your complaint with the relevant data protection authority. You can contact your local data protection authority, or our supervisory authority.

Last updated: August 2022