Amethyst Cat customer care

Privacy policy

How we process personal data, use cookies and respect your data protection rights.

Effective date: 11 August 2026

This Privacy Policy explains how Kivikauppa Ametistikissa, trading online as Amethyst Cat (“Amethyst Cat”, “we”, “us” or “our”), collects, uses, discloses and protects personal data when you visit amethystcat.eu, communicate with us, create an account or make a purchase (together, the “Services”).

We process personal data in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), applicable Finnish data protection law and other laws that apply to our Services.

1. Data controller and contact details

The controller responsible for the processing described in this Privacy Policy is:

Kivikauppa Ametistikissa
Trading name: Amethyst Cat
Finnish Business ID: 3607143-3
Address: Kaukolantie 21, 23800 Laitila, Finland
Email: info@ametistikissa.fi

We have not appointed a data protection officer because our current processing activities do not require one. Privacy and data-subject requests may be sent to the email address above.

2. Personal data we collect

Depending on how you use the Services, we may process the following categories of personal data:

  • Identity and contact information: name, billing and delivery address, email address and, if provided, telephone number.
  • Order and transaction information: products ordered, order value, discounts, delivery method, order status, returns, refunds, complaints and correspondence relating to an order.
  • Payment information: payment method, payment status, transaction reference and limited payment-related details received from payment providers. We do not normally receive or store complete payment-card numbers, online-banking credentials or authentication codes.
  • Account information: login and account details, saved addresses, order history and account preferences if you create or use a customer account.
  • Communications: messages, support requests, withdrawal notices, return requests, reviews and other information you choose to provide.
  • Marketing information: newsletter subscription status, consent records, marketing preferences and interactions with our marketing communications.
  • Device and technical information: IP address, browser and device type, operating system, language, approximate location derived from IP address, cookie identifiers, session data and security logs.
  • Usage information: pages viewed, links and buttons selected, searches, referring pages, shopping-cart activity and interactions with the Site, where permitted by your cookie choices.
  • Fraud and security information: risk signals, suspected misuse, authentication events and information necessary to protect customers, transactions and the Services.

Please do not send us special-category personal data, such as health information, unless it is strictly necessary and we have specifically requested it.

3. How we obtain personal data

We obtain personal data:

  • directly from you when you place an order, create an account, contact us, submit a form, write a review or subscribe to marketing;
  • automatically from your device and use of the Site through essential technologies and, where allowed, consent-based cookies, pixels and analytics tools;
  • from service providers involved in your transaction, such as Shopify, payment providers, fraud-prevention providers and delivery carriers; and
  • from advertising or analytics partners only where the relevant processing is permitted and any required consent has been obtained.

4. Why we process personal data and our legal bases

Purpose Typical data Legal basis under the GDPR
Processing and delivering orders, taking payment, providing order updates, handling returns and issuing refunds Identity, contact, order, transaction and payment information Performance of a contract or steps taken at your request before entering into a contract (Article 6(1)(b))
Customer service, complaints, product enquiries and withdrawal requests Contact details, communications and order information Performance of a contract (Article 6(1)(b)); compliance with legal obligations (Article 6(1)(c)); and our legitimate interest in serving customers and resolving disputes (Article 6(1)(f))
Bookkeeping, taxation, product-safety obligations, consumer-law compliance and responding to lawful authority requests Order, transaction, identity and communication records Compliance with legal obligations (Article 6(1)(c))
Operating customer accounts and saving requested account preferences Account, contact and order information Performance of a contract (Article 6(1)(b)) and our legitimate interest in providing requested account functionality (Article 6(1)(f))
Protecting the Site, preventing fraud, securing transactions and establishing, exercising or defending legal claims Technical, device, transaction, risk and security information Our legitimate interests in security, fraud prevention and legal protection (Article 6(1)(f)); and, where applicable, compliance with legal obligations (Article 6(1)(c))
Sending newsletters and other electronic direct marketing Contact details, consent and marketing preferences Your consent where required (Article 6(1)(a)); in limited cases, our legitimate interest in marketing similar products to existing customers where permitted by law (Article 6(1)(f)). You may opt out at any time.
Non-essential analytics, personalisation and advertising technologies Device, cookie and usage information Your consent (Article 6(1)(a)), where required. Withdrawing consent does not affect processing that occurred before withdrawal.
Essential website functions, checkout, shopping cart, localisation and consent-preference storage Device, session, cart and preference information Performance of a contract (Article 6(1)(b)) and our legitimate interest in providing a secure and functioning online store (Article 6(1)(f))
Improving products, customer service and Site performance using aggregated or appropriately limited information Order, support and usage information Our legitimate interest in improving the Services (Article 6(1)(f)); consent where improvement relies on non-essential tracking (Article 6(1)(a))

Where we rely on legitimate interests, we consider whether the processing is necessary and whether your rights and interests override ours. You may ask for further information about this assessment by contacting us.

5. Cookies and similar technologies

We use cookies and similar technologies for the following categories:

  • Strictly necessary: security, checkout, shopping cart, account login, localisation, network management and storage of privacy choices. These technologies are necessary for the Site to function and cannot generally be disabled through our consent tool.
  • Analytics: understanding how visitors use the Site and measuring Site performance, including through Shopify analytics and, where enabled, Google Analytics.
  • Functional: remembering choices and enabling optional features.
  • Advertising: measuring campaigns and, where enabled and consented to, supporting personalised or targeted advertising.

In the EEA, we request consent before placing or accessing non-essential cookies or similar technologies where consent is required. You may accept, reject or change your choices through the cookie-preference tool on the Site. Rejecting non-essential cookies does not prevent you from placing an order, although some optional features may work differently.

The lifetime of a cookie varies. Session cookies expire when the browser session ends; persistent cookies remain for the period stated in the cookie-preference tool or until deleted. You can also manage cookies through your browser, but blocking strictly necessary cookies may prevent the Site from functioning correctly.

6. Shopify and Shopify Network Intelligence

Our online store is hosted by Shopify. For core commerce services, Shopify generally processes customer personal data on our behalf as a processor. Shopify may also process certain information as an independent controller when providing services for which Shopify determines the purposes and means of processing.

Where Shopify Network Intelligence or another relevant enhanced Shopify service is enabled, Shopify may use certain interactions and transaction information to provide, develop and improve analytics, personalisation, advertising, fraud-prevention and related services across Shopify. Such processing is subject to Shopify’s own terms and Consumer Privacy Policy. Shopify privacy choices can also be managed through the Shopify Privacy Portal. Where required, Shopify’s non-essential uses are restricted by the consent choices made through our cookie banner or another tool integrated with Shopify’s Customer Privacy API.

7. Who receives personal data

We disclose personal data only where necessary for the purposes described above. Recipients may include:

  • Commerce and hosting: Shopify and its authorised service providers.
  • Payment and financing providers: depending on the method selected at checkout, Shopify Payments, Klarna, MobilePay, Paytrail, PayPal, Apple Pay, Google Pay, card networks, banks and fraud-prevention or authentication providers. Payment providers may act as independent controllers under their own privacy notices.
  • Delivery and logistics providers: postal, parcel, fulfilment and tracking providers that require recipient and order information to deliver the purchase.
  • Analytics and technology providers: Shopify analytics, Google Analytics and Google Tag Manager where enabled and permitted by your choices, together with providers that support Site security, hosting, consent management and technical maintenance.
  • Customer communication and reviews: tools used for customer service, email delivery, newsletters, forms, chat and product reviews, such as Shopify services and Judge.me where enabled.
  • Professional advisers and authorities: accountants, auditors, legal advisers, insurers, debt-recovery providers, courts, regulators, law-enforcement authorities and tax authorities where disclosure is necessary or legally required.
  • Business transactions: a prospective buyer, successor or adviser in connection with a merger, sale, restructuring or transfer of all or part of our business, subject to appropriate confidentiality and data-protection safeguards.

We do not sell personal data for money. Service providers may not use data processed on our behalf for their own unrelated purposes. Independent controllers process data under their own privacy notices and legal responsibilities.

8. International transfers

Some service providers, affiliated companies or technical systems may process personal data outside Finland or the European Economic Area (“EEA”), including in Canada or the United States.

Where personal data is transferred outside the EEA, we use or require an applicable lawful transfer mechanism, such as an adequacy decision, the European Commission’s Standard Contractual Clauses, approved Binding Corporate Rules or another mechanism permitted by data-protection law. Additional contractual, organisational or technical safeguards are used where required. Shopify describes its transfer safeguards in its Data Processing Addendum and Binding Corporate Rules.

You may contact us for information about the transfer mechanism relevant to your personal data and, where available, a copy of the applicable safeguards. Commercially confidential information may be redacted.

9. How long we retain personal data

We retain personal data only for as long as necessary for the purpose for which it was collected and thereafter where required or permitted by law. Retention is determined using the following criteria:

  • order, invoice, payment and bookkeeping records are retained for the periods required by Finnish accounting, taxation and consumer-protection laws;
  • customer account information is retained while the account remains active and for a reasonable period after closure where necessary for unresolved orders, security, fraud prevention or legal obligations;
  • customer-service, complaint, return and warranty records are retained for as long as reasonably necessary to handle the matter and any related legal claims;
  • marketing contact information is used until consent is withdrawn, an objection is made or the information is no longer needed. We may retain minimal suppression information to honour an opt-out;
  • cookie and analytics information is retained according to the lifetimes shown in the cookie-preference tool and the relevant provider settings; and
  • security records are retained for a period proportionate to the risk and longer where necessary to investigate suspected fraud, misuse or a security incident.

When personal data is no longer required, it is deleted, anonymised or securely isolated until deletion is possible in accordance with backup cycles.

10. Security

We use appropriate technical and organisational safeguards designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures include access restrictions, secure Shopify-hosted commerce infrastructure, encrypted connections, authentication controls, service-provider agreements, backups and procedures for handling security incidents.

No method of transmission or storage is completely secure. If a personal-data breach creates a risk to individuals, we will notify the competent supervisory authority and affected individuals where required by law.

11. Your data-protection rights

Subject to the conditions and exceptions in applicable law, you may have the right to:

  • receive information about how your personal data is processed;
  • access and obtain a copy of your personal data;
  • correct inaccurate or incomplete personal data;
  • request deletion of personal data;
  • request restriction of processing;
  • receive personal data you provided in a structured, commonly used and machine-readable format and transmit it to another controller where the right to data portability applies;
  • object to processing based on legitimate interests, including profiling based on those interests;
  • object at any time to processing for direct marketing;
  • withdraw consent at any time, without affecting the lawfulness of processing before withdrawal; and
  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, except where permitted by law and accompanied by required safeguards.

To exercise a right, email info@ametistikissa.fi. Please describe your request and the email address or order information concerned. We may request information reasonably necessary to verify your identity and protect personal data from unauthorised disclosure. We will respond without undue delay and normally within one month. The period may be extended by up to two further months for complex or numerous requests, in which case we will inform you.

Rights are not absolute. For example, we may retain data where processing is required by law or necessary to establish, exercise or defend legal claims. If we refuse all or part of a request, we will explain the reason and available complaint options.

12. Complaints

Please contact us first so that we can try to resolve your concern. You also have the right to lodge a complaint with the supervisory authority in the EEA country where you live, work or believe an infringement occurred.

Our lead supervisory authority is:

Office of the Data Protection Ombudsman, Finland
Website: tietosuoja.fi/en/home

13. Automated decision-making

We do not make decisions based solely on automated processing that produce legal or similarly significant effects for you. Payment, financing and fraud-prevention providers may use automated systems to authenticate transactions, assess fraud risk or determine eligibility for their services. Those providers are responsible for explaining any independent automated decision-making under their own privacy notices. If a payment method is declined, you may select another available method or contact the relevant provider.

14. Children

The Services are intended for customers who can enter into a binding purchase contract. We do not knowingly collect personal data from children for behavioural advertising or knowingly allow a child to subscribe to marketing without any consent required by law. A parent or guardian who believes that a child has provided personal data to us may contact us to request appropriate action.

15. Third-party links

The Site may contain links to websites or services operated by third parties. Their privacy practices are governed by their own notices. We are not responsible for third-party sites that we do not control, and we encourage you to review their privacy information before providing personal data.

16. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes in our Services, providers, technology, legal requirements or processing practices. The updated version will be published on the Site with a revised effective date. Where a change materially affects your rights or how we use personal data, we will provide additional notice where required.

17. Contact us

Questions, privacy requests and complaints may be sent to:

Kivikauppa Ametistikissa / Amethyst Cat
Email: info@ametistikissa.fi
Address: Kaukolantie 21, 23800 Laitila, FINLAND