Legal
Privacy Policy.
Last updated: April 2026 (newsletter section added)
Who we are
Pikeline ("we", "us", "our") is the data controller responsible for this website. We are located in Luxembourg at: 49, rue des Champs, L-7521 Mersch. Contact: contact@pikeline.shop.
This privacy policy explains how we collect, use, and protect your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Luxembourg law of 1 August 2018.
Data we collect and why
When you place an order, Shopify collects the following data on our behalf:
- Name and surname:To identify you and address your order
- Delivery address:To ship your order
- Email address:To send your order confirmation and shipping updates
- Payment information:Processed securely by Shopify Payments — we never see your card details
- Phone number (optional):For delivery coordination if provided
- IP address and browser data:For fraud prevention and security
Legal basis for processing
We process your personal data under the following legal bases:
- Contract performance (Art. 6(1)(b) GDPR): Processing your order, shipping, and after-sales.
- Legal obligation (Art. 6(1)(c) GDPR): Accounting and tax records as required by Luxembourg law.
- Legitimate interest (Art. 6(1)(f) GDPR): Fraud prevention and security.
How long we keep your data
Order data (name, address, order history) is kept for 10 years as required by Luxembourg accounting law.
If you request deletion before that period, we will anonymise your personal identifiers while retaining the minimum data required for our legal obligations.
Third parties
We share your data only with service providers who process it on our behalf:
- Shopify Inc. (Canada/USA): Order management, payment processing, and checkout. Shopify is certified PCI-DSS Level 1. Data may be transferred outside the EEA under Standard Contractual Clauses.
- Vercel Inc. (USA): Website hosting. Data may be transferred outside the EEA under Standard Contractual Clauses.
- Klaviyo, Inc. (USA, EU region: Dublin, Ireland): Email marketing platform. Stores newsletter subscribers, sends welcome / abandoned-cart / post-purchase emails, and tracks engagement (opens, clicks). Data is stored in Klaviyo's EU data center; transfer to the USA may occur under Standard Contractual Clauses (DPA: klaviyo.com/legal/data-processing-agreement) and the EU-US Data Privacy Framework. Klaviyo is also subject to its own subprocessors listed at klaviyo.com/legal/subprocessors.
- Shipping carriers: Your name and delivery address are shared with the carrier to deliver your order.
We do not sell your personal data to any third party.
Newsletter and marketing emails
If you subscribe to our newsletter (via the form on our website or by ticking the marketing-consent box at checkout), we process the following data:
- Email address: To send you marketing emails (new drops, restocks, occasional brand stories) and the three automated flows (welcome series, abandoned cart, post-purchase follow-up).
- Consent timestamp + IP: Logged by Klaviyo at signup for GDPR audit purposes.
- Engagement data (optional): Email opens and clicks, used to send more relevant content. You can disable this in your Klaviyo profile preferences.
Legal basis: Your explicit consent (Art. 6(1)(a) GDPR), given when you tick the consent checkbox. Subscription is confirmed via double opt-in — you receive a confirmation email and become a subscriber only after you click the link inside.
Withdrawal: Every email contains a one-click unsubscribe link. You can also email us at contact@pikeline.shop to be removed.
Retention: We keep subscriber data until you unsubscribe, and for up to 12 months after unsubscribing for suppression-list purposes (so we don't accidentally re-add you).
Cookies
This website uses only functional cookies necessary for the shopping cart to work. No analytics, tracking, or advertising cookies are set without your consent.
- Cart session cookie: Stores your cart contents locally so items are not lost between pages. Essential — no consent required.
- Shopify checkout cookies: Set by Shopify on their domain when you proceed to checkout. Subject to Shopify's own privacy policy.
Your rights under GDPR
You have the right to:
- Access a copy of your personal data (Art. 15)
- Correct inaccurate data (Art. 16)
- Request deletion ("right to be forgotten") (Art. 17)
- Restrict processing (Art. 18)
- Data portability (Art. 20)
- Object to processing based on legitimate interest (Art. 21)
- Withdraw consent at any time (where processing is based on consent)
To exercise your rights, contact us at: contact@pikeline.shop
You also have the right to lodge a complaint with the Commission Nationale pour la Protection des Données (CNPD) in Luxembourg: cnpd.public.lu
This policy may be updated from time to time. Material changes will be communicated via email or a notice on the website.