Legal notice

Privacy Policy

Last updated: November 24, 2025

FrostBloom values your privacy and is committed to protecting your personal data. This privacy policy explains how we collect, use, store, and protect your personal data in accordance with the EU General Data Protection Regulation (GDPR).


1. Data Controller

FrostBloom

Email: contact@frostbloom.se

Website: frostbloom.se

Daniel Frostell is the data controller for the processing of your personal data.


2. What Personal Data Do We Collect?

We collect the following types of personal data:

When Ordering:

  • Name (first and last name)
  • Email address
  • Delivery address
  • Phone number
  • Payment information (handled by our payment provider)

When Visiting the Website:

  • IP address
  • Browser type and version
  • Pages visited and click behavior
  • Cookies and similar technologies (see cookies section)

When Contacting Customer Service:

  • Email correspondence
  • Messages via contact form
  • Complaints and support cases

3. Why Do We Collect Your Personal Data?

We process your personal data for the following purposes:

Fulfillment of Contract (Legal basis: Contract performance)

  • Process and deliver your order
  • Communicate about your order (order confirmation, tracking information)
  • Handle payments
  • Handle returns and complaints

Legal Obligation (Legal basis: Legal requirement)

  • Accounting and bookkeeping (according to accounting law)
  • Handle tax requirements
  • Fulfill consumer protection laws

Legitimate Interest (Legal basis: Legitimate interest)

  • Improve our website and user experience
  • Analyze purchasing behavior to improve product range
  • Prevent fraud and security threats
  • Marketing to existing customers

Consent (Legal basis: Consent)

  • Send newsletters and marketing (only if you have consented)
  • Use non-essential cookies

4. How Long Do We Store Your Personal Data?

We store your personal data only as long as necessary:

  • Order information: 7 years (according to accounting law)
  • Customer accounts: Until you request deletion or the account has been inactive for 3 years
  • Marketing lists: Until you unsubscribe
  • Web analytics and cookies: According to our cookie policy (see below)
  • Customer service correspondence: 3 years after last contact

5. Who Do We Share Your Personal Data With?

We only share your personal data with necessary third parties:

Fulfillment Partner:

Selfnamed (Latvia) - Handles order processing, packaging, and delivery. They process your personal data as a data processor according to our agreement.

Payment Providers:

Shopify Payments or other payment providers. Process payment information securely according to PCI-DSS standard.

Carriers:

Delivery companies that deliver your package. Only receive name, address, and phone number for delivery.

Technical Providers:

  • Shopify - E-commerce platform (servers in EU/EEA)
  • Google Analytics - Web analytics (anonymized data)
  • Email providers - To send order confirmations and communication

We never sell your personal data to third parties.


6. Transfer to Third Countries

Your personal data is primarily stored and processed within the EU/EEA. Some technical providers (e.g., Shopify, Google) may have servers outside the EU. In such cases, we ensure that:

  • Adequate level of protection exists through EU-approved mechanisms
  • Standard contractual clauses are used
  • The provider follows GDPR requirements

7. Your Rights Under GDPR

You have the following rights:

Right of Access (Data Extract)

You have the right to receive confirmation of whether we process your personal data and receive a copy of it.

Right to Rectification

You can request that incorrect or incomplete information be corrected.

Right to Erasure ("Right to be Forgotten")

You can request deletion of your personal data if:

  • It is no longer necessary
  • You withdraw your consent
  • You object to the processing
  • The data is processed unlawfully

NOTE: We may need to retain certain information to fulfill legal requirements (e.g., accounting).

Right to Restriction

You can request that we restrict processing under certain circumstances.

Right to Data Portability

You have the right to receive your personal data in a structured, machine-readable format.

Right to Object

You can object at any time to processing based on legitimate interest or for direct marketing.

Right to Withdraw Consent

If processing is based on consent, you can withdraw it at any time.

Exercise your rights: Contact us via contact@frostbloom.se. We respond within 30 days.


8. Cookies

We use cookies to improve your experience on our website.

Necessary Cookies

  • Required for the website to function
  • Shopping cart, login, security
  • Does not require consent

Functional Cookies

  • Improves user experience
  • Saves language choices and preferences

Analytical Cookies

  • Google Analytics (anonymized)
  • Helps us understand how visitors use the website

Marketing Cookies

  • Used for targeted advertising
  • Requires your consent

Manage cookies: You can change your cookie settings at any time via our cookie banner or in your browser settings.


9. Security

We take appropriate technical and organizational measures to protect your personal data:

  • SSL encryption for all data traffic
  • Secure servers at Shopify
  • Limited access to personal data
  • Regular security updates
  • Secure passwords and authentication

10. Children

Our website is not directed at children under 16 years. We do not knowingly collect personal data from children. If you are a parent and discover that your child has provided personal data to us, contact us and we will delete the information.


11. Changes to Privacy Policy

We may update this privacy policy when necessary. For significant changes, we will notify you via email or through a notice on the website.

The latest update is always shown at the top of the document.


12. Complaint to Supervisory Authority

If you believe we process your personal data in violation of GDPR, you have the right to lodge a complaint with:

Swedish Authority for Privacy Protection (IMY)

Box 8114
104 20 Stockholm
Phone: +46 8-657 61 00
Email: imy@imy.se
Website: www.imy.se


13. Contact Us

For questions about this privacy policy or how we process your personal data:

Email: contact@frostbloom.se

Website: frostbloom.se

We normally respond within 24 hours on weekdays.


FrostBloom - Your privacy is important to us