Privacy policy

Privacy Policy (GDPR)

This document explains how we process the personal data of customers in the online store Little Dressagerider, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation – "GDPR").

1. Who is the data controller?

The data controller is: Zuzana Novotna  Registered office: Jílovská 431/23, 142 00, Prague 4, Czech Republic Company ID (IČO): 10737448 E-mail: eshop@littledressagerider.com 

2. What personal data do we process and why?

We process personal data only to the necessary extent and for clearly defined purposes:

A. Order processing and fulfillment of the purchase contract

  • What data: First name, last name, delivery and billing address, e-mail address, phone number, and details about the purchased goods.

  • Why: To confirm, pack, and ship your order, and to inform you about the delivery status. Also for handling potential exchanges, returns, or complaints.

  • Legal basis: Processing is necessary for the performance of a contract (Art. 6(1)(b) GDPR).

B. Accounting and fulfillment of legal obligations

  • What data: Billing details (name, address, payment information).

  • Why: We must process and retain this data for accounting and tax compliance, as required by the laws of the Czech Republic.

  • Legal basis: Compliance with a legal obligation (Art. 6(1)(c) GDPR).

C. Customer support and communication

  • What data: E-mail, possibly phone number, and the content of our conversation.

  • Why: To answer your questions regarding products, sizes, or order status.

  • Legal basis: Our legitimate interest in providing quality customer care (Art. 6(1)(f) GDPR).

D. Direct marketing (Newsletters)

  • What data: E-mail address, possibly first name.

  • Why: If you make a purchase from us, we may send you e-mails with news or discounts regarding similar products, unless you opt out. In other cases, we will only send you the newsletter with your explicit consent.

  • Legal basis: Legitimate interest (for existing customers) or your consent. You can unsubscribe at any time by clicking the link in the footer of every e-mail.

3. Who do we share your data with? (Processors)

We do not sell your personal data to any third parties. However, to deliver your goods and run the e-shop, we share data to the necessary extent with our reliable partners:

  • E-commerce platform provider: Shopify Inc., which ensures the technical operation of our online store and data storage on secure servers.

  • Shipping companies: PPL CZ s.r.o. (or its contractual partners for deliveries within the EU), to whom we provide your name, address, e-mail, and phone number so they can deliver your package and inform you about the courier's arrival time.

  • Payment gateway providers: For secure payment processing (we do not see or store your full credit card details; they are processed directly by a certified payment gateway, e.g. Apple Pay / Google Pay).

4. How long do we keep your data?

  • Data necessary for processing orders and handling potential complaints are kept for the duration of the warranty period and subsequently for another 3 years in case of legal disputes.

  • We are legally obliged to keep accounting and tax documents (invoices) for 10 years.

  • E-mails for newsletter purposes are kept until you unsubscribe or withdraw your consent.

5. What are your rights?

Under the GDPR, you have full control over your personal data. You have the right to:

  1. Access your personal data: You can ask us what data we process about you.

  2. Rectification: If your data is inaccurate or outdated, you have the right to have it corrected.

  3. Erasure ("right to be forgotten"): You can request the deletion of your data if it is no longer needed for the purposes for which it was collected, provided there is no legal obligation preventing it (e.g., invoice archiving).

  4. Restriction of processing: In certain cases, you can ask us to temporarily suspend the processing of your data.

  5. Data portability: You have the right to receive your data in a machine-readable format to transfer it to another controller.

  6. Object: You can object to processing based on legitimate interest (e.g., against sending newsletters).

You can exercise these rights by sending an e-mail to eshop@littledressagerider.com.

If you believe we are not handling your data lawfully, you have the right to file a complaint with the supervisory authority, which in the Czech Republic is the Office for Personal Data Protection (ÚOOÚ), located at Pplk. Sochora 27, 170 00 Prague 7 (www.uoou.cz).

6. Cookies

Our e-shop uses cookies for its proper function. More detailed information about the cookies we use and the option to set your preferences can be found in the cookie management banner (Cookie Preferences) in the footer of this website.

This policy is effective as of 3.3.2026