Privacy policy

Privacy Policy

Last updated: November 19, 2025

1. Introduction

This Privacy Policy explains how The Bulb Bag, owned and operated by ANDVISIBLE S.R.L., collects and processes personal data when you use our services, visit our website, or place an order. This Policy is written in accordance with Regulation (EU) 2016/679 (GDPR) and Law 190/2018 of Romania.

By accessing our website or purchasing a product, you acknowledge that you have read this Privacy Policy. If you do not agree, you should stop using the website and services.

2. Data Controller Information

Company: ANDVISIBLE S.R.L.
Registered address: Strada Cugir, Nr. 38, Sector 3, București, Romania
Trade Registration Number: J40/10339009
Unique Registration Code (VAT): 51284071
Email: thebulbbag@gmail.com
Website: www.thebulbbag.com

3. Personal Data We Collect

Personal data means any information that can identify an individual directly or indirectly. We collect the minimum required data to operate our business:

3.1. When placing an order

  • Full name
  • Billing and delivery address
  • Phone number
  • Email address
  • Payment confirmation details (we do not store full card numbers)

3.2. When subscribing to newsletters

  • Email address

3.3. When contacting us

  • Email address and details you voluntarily provide

3.4. Automatically via cookies and site usage

Device information (browser, IP address, approximate location, session behavior). For more information, refer to our Cookie Policy.

4. Legal Basis of Processing

We process personal data under GDPR using the following legal bases:

Purpose Legal Basis
Order processing, payment, delivery, returns Contract execution (Art. 6(1)(b))
Customer support Legitimate interest (Art. 6(1)(f))
Marketing newsletters Consent (Art. 6(1)(a))
Fraud prevention and security Legitimate interest (Art. 6(1)(f))
Legal and tax compliance Legal obligation (Art. 6(1)(c))

5. Third-Party Providers

We share data only with trusted third parties who assist our business operations and act under GDPR contracts as data processors:

  • Shopify (Website hosting and platform)
  • Payment processors: Shopify Payments, Netopia, Klarna (where available), PayPal
  • Shipping/courier services: Fan Courier, DHL, UPS, or similar providers
  • Newsletter service: Shopify Email

These providers process data strictly to deliver our services (payments, hosting, delivery, emails). We do not sell personal data.

6. Relationship With Shopify

Our store is hosted by Shopify, which may process limited data (e.g., IP, device information, purchase metadata) as an independent data controller for purposes such as platform security, analytics, fraud prevention, and product improvement.

For how Shopify handles this data, visit:
Shopify Privacy Policy

7. International Data Transfers

Some service providers (e.g., Shopify, PayPal) may store data on servers outside the European Economic Area (EEA). In such cases, transfers are legally protected by Standard Contractual Clauses (SCCs) or other GDPR-approved safeguards.

8. Data Retention

  • Order & invoicing data: up to 10 years (Romanian fiscal law)
  • Newsletter data: until consent is withdrawn
  • Customer support messages: only as long as necessary

9. Your GDPR Rights

You have the following rights under GDPR:

  • Access your data
  • Rectify incorrect data
  • Erase data (“Right to be forgotten”)
  • Restrict processing
  • Data portability
  • Withdraw consent (marketing)
  • Object to processing based on legitimate interest
  • Lodge a complaint with ANSPDCP (Romania’s authority)

To exercise your rights, contact:
Email: thebulbbag@gmail.com

10. Children’s Data

We do not knowingly collect personal data from individuals under the age of 16. If you believe a minor has provided data, contact us to request deletion.

11. Data Security

We apply security measures such as HTTPS encryption and restricted internal access. However, no system is 100% secure, and we cannot guarantee absolute protection against cyber attacks.

12. Third-Party Links

Our website may include links to external websites. We are not responsible for their content or privacy practices. We recommend reviewing their policies separately.

13. Changes to This Policy

We may update this Policy due to legal or operational changes. Updates will appear on this page with a new “Last updated” date.

14. Contact

If you have questions or requests regarding personal data, contact:
Email: thebulbbag@gmail.com
Data Controller: ANDVISIBLE S.R.L., București, Romania