Privacy Policy

1. Data Controller

Shiraz Essence

[Legal Entity Name]

[Physical Address, Switzerland]

UID: CHE-XXX.XXX.XXX

2. Data Collected

To provide you with our curated essence collections, we collect information directly from you. This includes your identity and contact details such as your name, email, physical address, and phone number, alongside payment information processed securely by our partners. Additionally, we store account credentials, your responses to our discovery quizzes, and your communication preferences for our newsletters.

In the background, we automatically gather technical data to improve your experience. This includes your IP address, browser and device information, your journey through our pages, and referral sources, primarily through the use of essential and analytical cookies.

We also receive selective information from trusted third parties. This is limited to payment confirmations from providers like Stripe, TWINT, and PostFinance, as well as delivery status updates from carriers such as Swiss Post.

3. Processing Purposes

Our processing of your data is strictly bound by legal necessity and your benefit. Primarily, we process data to fulfil our contractual obligations—this covers order fulfillment, payment processing, delivery logistics, customer service enquiries, and the management of your personal account.

We also act on our legitimate interests to provide a more meaningful experience. This includes the personalisation of our "Twin Quiz" results, product recommendations, and essential fraud prevention measures to ensure the security of our platform.

For activities beyond these essentials, we rely on your explicit consent. This applies to our marketing newsletters and analytical cookies used for website improvements. You remain in control and may withdraw this consent at any time. Finally, we process data where required by legal obligations, specifically for tax and accounting compliance under Swiss law.

4. Data Sharing & International Transfers

We respect your data integrity: We do not sell personal data. Information is shared only with vital partners:

International Transfers

Where service providers are outside CH/EEA: protected by adequacy decisions, Standard Contractual Clauses, or other safeguards per Art. 16 nDSG.

5. Retention Periods

We retain your information only as long as necessary for the purposes outlined. In accordance with Swiss commercial and tax law (Art. 958f CO), order-related documents are archived for a period of 10 years.

Data associated with your customer account is kept for the duration of your membership and is promptly deleted upon request. Regarding marketing and analytics, we keep your data until your consent is withdrawn or, in the case of anonymised analytics, for up to 26 months.

6. Your Rights

Under the Swiss FADP/nDSG and the GDPR, you hold significant rights over your personal data. You have the right to access the information we hold about you and request rectification if any details are inaccurate or incomplete. If you wish to close your journey with us, you may request the deletion of your data or the restriction of its processing.

Furthermore, you have the right to data portability, allowing you to receive your data in a structured format, and the right to object to processing based on our legitimate interests. Where we rely on your consent, you may withdraw it at any time.

To exercise any of these rights, or if you have any enquiries regarding your privacy, please contact us at privacy@shirazessence.ch. If you believe your data has been handled improperly, you have the right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) at www.edoeb.admin.ch.

7. Cookies

Essential cookies required for function. Analytics and marketing cookies require your explicit consent via our banner. Manage via 'Cookie Settings'.

8. Security

All transmissions are protected with SSL/TLS encryption. We perform regular security reviews and strictly control access to your data.

9. Minors

Our services are not intended for individuals under the age of 16. Any data discovered from minors will be promptly deleted.