Privacy Policy
Last updated: April 2026
1. Who we are
This website, lozak.store, is operated by MB Care by Yuliya (the Seller, we, us or our), which acts as the controller of your personal data.
Company code: 307398481
VAT number: LT100018867619
Email: info@lozak.store
2. Scope of this Policy
This Privacy Policy applies when you visit our Website, place an order, subscribe to our newsletter, contact us by email or through our contact form, or otherwise interact with us.
We process personal data in accordance with the General Data Protection Regulation (GDPR), applicable Lithuanian law and relevant guidance from supervisory authorities.
3. What personal data we collect
- Order data: name, surname, email address, phone number, billing address, shipping address, ordered products, order history and related order details.
- Payment data: payment method, payment status, transaction identifier and related payment information. We do not store full payment card details. Payments are processed by third-party payment providers such as Paysera and other available checkout partners.
- Customer support data: messages, enquiries, return requests, complaint details and any files or photos you send us (for example in relation to defective or incorrect items).
- Marketing data: newsletter subscription details, consent date, email engagement data and unsubscribe records.
- Technical and cookie data: IP address, browser type, device information, session identifiers, page views, approximate location data and cookie consent preferences. More information is available in our Cookie Policy.
4. Purposes of processing and legal basis
- Performance of a contract (GDPR Article 6(1)(b)): to process orders, manage payments, arrange shipping, handle returns, exchanges and customer support.
- Legal obligation (GDPR Article 6(1)(c)): to comply with accounting, tax and other mandatory legal requirements.
- Legitimate interests (GDPR Article 6(1)(f)): to prevent fraud, protect our business, improve our Website and services, analyse customer experience, and establish, exercise or defend legal claims.
- Consent (GDPR Article 6(1)(a)): for newsletters, promotional communications and non-essential cookies, analytics and advertising tools.
5. How long we keep your data
- Order and contract data: up to 10 years, or longer where required by law or necessary for legal claims and defence.
- Customer support data: up to 3 years from the last interaction, unless a longer retention period is necessary for legal reasons.
- Marketing data: until you withdraw consent or unsubscribe, or for up to 2 years from your last meaningful interaction, depending on the context.
- Cookie data: according to the lifespan of each cookie as described in our Cookie Policy.
6. Data recipients and processors
We share personal data only where necessary for the purposes described in this Policy.
- E-commerce platform: Shopify (including Shopify International Ltd. and/or Shopify Inc., where applicable).
- Payment providers: Paysera and other payment partners available at checkout.
- Shipping and logistics providers: carriers such as Omniva, LP Express, DPD, DHL, UPS and similar partners.
- IT and communications providers: hosting, email, customer service, security and related service providers.
- Accounting, legal and compliance providers: accountants, auditors, legal advisers and similar professional services.
- Public authorities: where disclosure is required by law or by a lawful request.
7. Transfers outside the EEA
Some of our service providers, such as Shopify or related technology providers, may process personal data outside the European Economic Area (EEA).
Where this happens, we ensure that appropriate safeguards are in place, such as the European Commission’s Standard Contractual Clauses (SCCs), adequacy decisions, or other lawful transfer mechanisms, together with appropriate security and confidentiality measures.
8. Your rights
Under the GDPR, you have the right to:
- access your personal data and receive information about how it is processed;
- rectify inaccurate or incomplete personal data;
- erase your personal data where applicable;
- restrict processing in certain circumstances;
- data portability where applicable;
- object to processing based on legitimate interests, including direct marketing;
- withdraw consent at any time where processing is based on consent.
To exercise your rights, please contact us at info@lozak.store.
We normally respond within 30 days. In complex cases, this period may be extended by up to a further 60 days, and we will inform you if that happens.
9. Complaints
If you believe that your personal data is being processed unlawfully, please contact us first at info@lozak.store.
You also have the right to lodge a complaint with the Lithuanian supervisory authority: State Data Protection Inspectorate (VDAI), https://vdai.lrv.lt.
10. Cookies and similar technologies
We use essential cookies necessary for the operation of the Website, and non-essential analytics and marketing cookies only where permitted by law and, where required, based on your consent.
Detailed information about cookie types, purposes, storage periods and third parties is available in our Cookie Policy. You can manage your preferences through our cookie banner, consent tool or your browser settings.
11. Marketing communications
- We send newsletters and promotional emails only where we have a valid legal basis, such as your consent or another lawful basis under applicable law.
- Every marketing email includes an unsubscribe link, and you can opt out at any time.
- Where permitted by law, we may send existing customers information about similar products that may be relevant to them, subject to their right to object at any time.
12. Children’s data
Our products are purchased by adults. We do not knowingly collect personal data directly from children under the age of 16.
If you believe that a child has provided personal data without appropriate parental or guardian consent, please contact us and we will take appropriate steps.
13. Security
We use appropriate technical and organisational measures to protect personal data, including access controls, secure systems, data minimisation and a need-to-know approach.
However, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security.
14. Third-party links
Our Website may contain links to third-party websites or services. We are not responsible for their content, security or privacy practices. We encourage you to read their privacy policies before providing personal data.
15. Changes to this Policy
We may update this Privacy Policy from time to time. Any changes become effective when published on the Website.
Where changes are significant, we may provide a clearer notice, for example on the Website or by email where appropriate.
16. Governing law
This Privacy Policy is governed by and interpreted in accordance with the laws of the Republic of Lithuania.
17. Privacy contact
If you have any questions, requests or concerns about this Privacy Policy or your personal data, please contact us at: info@lozak.store
Related pages: Cookie Policy · Terms & Conditions · Returns & Refund Policy · Shipping Policy · Contact