Your cart is empty

Continue shopping

For those who leave a trace.

Privacy policy

Last updated: 16 August 2026

1. Controller

The controller responsible for processing personal data through the Vallorne online store and related services is:

Vallorne ECOM OÜ
Paul-Gossen-Straße 99
91052 Erlangen
Germany

Estonian registry code: [insert Estonian registry code]
VAT identification number: [insert VAT identification number]

Represented by:

Amir Sultani, Member of the Management Board

Privacy enquiries: privacy@vallorne.com
General enquiries: store@vallorne.com
Customer service: help@vallorne.com
Telephone: +49 1522 9264462

In this Privacy Policy, “Vallorne”, “we”, “us” and “our” refer to Vallorne ECOM OÜ.

This Privacy Policy applies to our online store, customer accounts, communications, marketing activities, affiliate programme and any related Vallorne services that link to it.

The sections concerning particular providers apply only where the corresponding service, sales channel or technology is enabled or used.

2. General principles

We process personal data only where a lawful basis exists. Depending on the circumstances, processing is based on:

  • Article 6(1)(a) GDPR — your consent;

  • Article 6(1)(b) GDPR — taking steps at your request or performing a contract with you;

  • Article 6(1)(c) GDPR — compliance with a legal obligation;

  • Article 6(1)(f) GDPR — our or a third party’s legitimate interests, provided that your interests and fundamental rights do not override those interests.

Where we process special categories of personal data, such as health information included in a report about an adverse reaction to a fragrance, we rely on an applicable legal basis under Article 9 GDPR.

3. Information we collect

Depending on how you interact with us, we may process the following categories of information:

  • Name, billing address, delivery address and country;

  • Email address and telephone number;

  • Customer-account credentials and account identifiers;

  • Products viewed, searched for, added to a basket, purchased or returned;

  • Order numbers, transaction details, discount codes and payment status;

  • Selected payment method;

  • Delivery instructions, tracking numbers and shipment status;

  • Communications with customer service;

  • Newsletter and SMS subscription status, consent records and preferences;

  • Affiliate applications, referral identifiers and commission information;

  • Reviews, ratings and other content you submit;

  • IP address, browser, device, operating system and approximate location;

  • Cookie identifiers, advertising identifiers and referral information;

  • Website interactions, such as page views, clicks, searches and checkout events;

  • Fraud-prevention and security information;

  • Information necessary to comply with tax, accounting, commercial and regulatory requirements.

We do not normally receive complete card numbers, online-banking credentials or other full payment credentials. These are generally collected directly by the selected payment provider.

4. Hosting and operation through Shopify

Our store is operated through Shopify. Shopify provides the ecommerce platform, hosting, checkout, customer accounts, order administration and related technical infrastructure.

For these purposes, Shopify may process:

  • Contact and account information;

  • Billing and delivery addresses;

  • Shopping-basket and order information;

  • Payment and transaction information;

  • Device, browser, IP-address and cookie information;

  • Searches, product views and other store activity;

  • Privacy choices and consent preferences.

The processing required to operate the store and fulfil orders is based primarily on Article 6(1)(b) GDPR. Security, fraud prevention and reliable operation are based on Article 6(1)(f) GDPR. Legal recordkeeping is based on Article 6(1)(c) GDPR.

For merchants in the EEA, Shopify services are generally provided through Shopify International Limited, Ireland. Shopify may use affiliated companies and subprocessors in other countries.

Shopify normally acts as our processor when handling customer information on our instructions. If Shopify Network Intelligence or certain Enhanced Services are enabled, Shopify may process particular information as an independent controller for the purposes described in its terms and privacy notices.

Further information is available in the Shopify Consumer Privacy Policy and through Shopify’s privacy controls.

5. Orders and performance of contracts

When you place an order, we process the information necessary to:

  • Confirm and administer the order;

  • Verify availability;

  • Process payment;

  • Prepare and dispatch the products;

  • Provide delivery and tracking information;

  • Handle returns, refunds, complaints and warranty rights;

  • Communicate with you about the order;

  • Prevent misuse, payment fraud and unauthorised transactions.

The main legal basis is Article 6(1)(b) GDPR. Processing required by accounting, commercial, tax, sanctions or other laws is based on Article 6(1)(c) GDPR. Fraud prevention and the establishment or defence of legal claims are based on Article 6(1)(f) GDPR.

Information marked as mandatory during checkout is required to complete the order. Without it, we may be unable to enter into or perform the contract.

6. Customer accounts and order tracking

If you create or use a customer account, we process your login information, contact details, addresses, order history, saved preferences and account activity.

This enables you to manage your information, view previous orders and follow their status. Processing is based on Article 6(1)(b) GDPR.

Security logs and information used to protect the account against unauthorised access are processed under Article 6(1)(f) GDPR.

7. Payment providers

Available payment methods may vary according to country, order value, device, eligibility and the settings of the respective provider.

When you choose a payment method, the information necessary to process and verify the transaction is transmitted to the relevant provider. This may include:

  • Name and contact information;

  • Billing and delivery addresses;

  • Order value, currency and product information;

  • Transaction and customer identifiers;

  • IP address and device information;

  • Information required for fraud, identity, sanctions or credit checks.

Payment providers may process this information as independent controllers under their own privacy notices.

7.1 Shopify Payments

When Shopify Payments is selected, Shopify and its payment, acquiring, banking and card-network partners process transaction and fraud-prevention information.

The processing necessary to complete the payment is based on Article 6(1)(b) GDPR. Compliance, fraud prevention and transaction security may also be based on Article 6(1)(c) and Article 6(1)(f) GDPR.

7.2 PayPal

When PayPal is selected, information is transmitted to the applicable PayPal company. For customers in the EEA, services are generally provided by PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg.

PayPal may conduct identity, sanctions, fraud, money-laundering, risk and creditworthiness checks. It may use automated decision-making where permitted by law.

Further information is available in the PayPal Privacy Statement.

7.3 Klarna

When a Klarna payment method is selected, information required to process the payment and determine eligibility is transmitted to Klarna Bank AB (publ), Sweden.

Klarna may independently conduct identity, fraud, affordability and creditworthiness assessments. Depending on the payment method, this may include obtaining information from credit-reference agencies and using automated assessment procedures.

Further information is available in Klarna’s Privacy Notice.

7.4 Riverty

When a Riverty invoice or deferred-payment method is selected, relevant customer, address, order and transaction information is transmitted to Riverty GmbH, Gütersloher Straße 123, 33415 Verl, Germany.

Riverty may independently perform identity, address, fraud and creditworthiness checks. For German customers, this can include obtaining information from credit-reference agencies such as SCHUFA or other agencies identified in Riverty’s current privacy notice.

Riverty may also administer invoices, reminders, payments, claims and debt collection.

Further information is available in Riverty’s Privacy Policy.

7.5 Decisions made by payment providers

Vallorne does not itself calculate your credit score and does not normally receive the complete information used by Klarna, Riverty, PayPal or their credit-reference agencies.

A payment provider may independently decline or restrict a particular payment method. If this happens, you may be able to select another payment method or contact the provider directly.

8. PayPal tracking synchronisation through PalTrack

Where PalTrack is enabled, we use it to transmit delivery and tracking information for PayPal transactions to PayPal.

The information may include:

  • Shopify order identifier;

  • PayPal transaction identifier;

  • Carrier and tracking number;

  • Fulfilment and shipment status;

  • Order information necessary to match the shipment to the payment.

This processing helps provide accurate shipment information, administer transactions and protect Vallorne against payment disputes. It is based on Article 6(1)(b) and Article 6(1)(f) GDPR.

PalTrack is provided by PartnersWire LLC, 1309 Coffeen Avenue, Suite 1200, Sheridan, Wyoming 82801, United States. Its current privacy information is linked from the PalTrack Shopify App Store listing.

9. Delivery through DHL

We provide DHL with the information required to deliver and track your order. Depending on the shipment, this may include:

  • Recipient name;

  • Delivery address;

  • Email address or telephone number;

  • Order and parcel reference;

  • Delivery instructions;

  • Tracking and shipment status.

The processing is based on Article 6(1)(b) GDPR. Where additional delivery notifications are optional, they are provided only where requested or otherwise lawfully enabled.

The relevant recipient may be DHL Paket GmbH, Deutsche Post AG, or another DHL Group company responsible for the selected delivery service.

10. Customer service and communications

When you contact us by email, telephone, a contact form, social media or another channel, we process the information you provide in order to respond.

Depending on the request, this may include your:

  • Name and contact details;

  • Order number;

  • Customer-account information;

  • Message and attachments;

  • Return, refund or complaint information;

  • Previous communications with us.

Requests connected with an order are processed under Article 6(1)(b) GDPR. General enquiries and the efficient administration of customer service are processed under Article 6(1)(f) GDPR. Legal complaints and recordkeeping may be processed under Article 6(1)(c) or Article 6(1)(f) GDPR.

11. Email infrastructure, GoDaddy and Microsoft Outlook

We use GoDaddy for our domain and email-hosting infrastructure and Microsoft Outlook for the management of business communications.

When you email Vallorne, your email address, message, attachments and technical transmission information may therefore be processed by the applicable GoDaddy and Microsoft companies and their subprocessors.

The legal basis depends on the communication and may be Article 6(1)(b), Article 6(1)(c) or Article 6(1)(f) GDPR.

Further information is available in the GoDaddy Privacy Notice and the Microsoft Privacy Statement.

12. Email and SMS marketing through Klaviyo

Where enabled, we use Klaviyo to manage:

  • Email newsletters;

  • SMS marketing;

  • Subscription forms and opt-ins;

  • Welcome and post-purchase sequences;

  • Basket and checkout reminders;

  • Product-release and back-in-stock notifications;

  • Customer segmentation;

  • Campaign performance;

  • Consent and unsubscribe records.

The information processed may include your name, email address, telephone number, country, subscription status, consent date, order history, product interests, campaign interactions and website activity.

Marketing emails and SMS messages are sent on the basis of your consent under Article 6(1)(a) GDPR and the applicable requirements of Section 7 UWG. Where required, we use a confirmation or double-opt-in procedure.

You may withdraw your consent at any time by:

  • Using the unsubscribe link in an email;

  • Following the opt-out instructions in an SMS;

  • Contacting privacy@vallorne.com.

Withdrawal does not affect processing carried out before the withdrawal.

Transactional messages concerning an order, payment, delivery, return or account are not marketing messages and may be sent where necessary to perform our contract with you.

Klaviyo may process names, email addresses, telephone numbers, IP addresses, cookie identifiers, consent records and campaign interactions on our behalf. Further information is available in the Klaviyo Privacy Notice.

13. Shopify Forms

We may use Shopify Forms to collect newsletter registrations, SMS registrations, product-release notifications or other customer requests.

The form will state the relevant purpose. Marketing registrations are processed on the basis of consent under Article 6(1)(a) GDPR. Information required to respond to another request may be processed under Article 6(1)(b) or Article 6(1)(f) GDPR.

Information collected through Shopify Forms may be stored in Shopify and synchronised with Klaviyo where the corresponding marketing integration is enabled.

14. Affiliate programme and UpPromote

We use UpPromote to administer our affiliate and creator programme.

14.1 Affiliate applicants and participants

If you apply to or participate in the programme, we may process:

  • Name and contact information;

  • Social-media profiles and audience information;

  • Affiliate account details;

  • Referral links and discount codes;

  • Referred orders and commission amounts;

  • Payment and tax information;

  • Communications and programme performance.

This processing is based on Article 6(1)(b) GDPR and, where applicable, Article 6(1)(c) and Article 6(1)(f) GDPR.

14.2 Affiliate attribution

When a visitor follows an affiliate link or uses an affiliate code, UpPromote may process referral parameters, cookie identifiers, IP/device information, order identifiers, products and order values to attribute the purchase to an affiliate.

Where affiliate attribution requires storing or accessing information on a device, it occurs only with the legally required consent. The legal bases are Section 25(1) TDDDG and Article 6(1)(a) GDPR.

Further information is available in the UpPromote Privacy Policy.

15. Analytics, advertising and social-media technologies

Subject to your consent, we may use analytics and advertising services to measure store performance, understand customer journeys, prevent advertising fraud and display relevant advertising.

Unless a technology is strictly necessary, it is not activated before the required consent has been obtained.

The legal bases are:

  • Section 25(1) TDDDG for storing or accessing information on your device;

  • Article 6(1)(a) GDPR for the subsequent processing of personal data.

You can withdraw or change your choices at any time through the Cookies link in the footer.

15.1 Google services

Where enabled, we may use services supplied by Google, including:

  • Google Analytics;

  • Google Ads and conversion measurement;

  • Google Merchant Center;

  • Google sales-channel integrations;

  • Google Consent Mode;

  • YouTube.

These services may process cookie identifiers, device and browser information, IP addresses, referrer information, page views, searches, product interactions, shopping-basket events, purchases and conversion information.

For advertising measurement and audience functions, Google may associate information with other data it holds, depending on your Google settings and the configuration of the service.

Google services in the EEA are generally provided through Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Further information is available in the Google Privacy Policy.

15.2 YouTube videos

Our website may contain YouTube videos. Where possible, videos are embedded using privacy-conscious settings.

Before an external YouTube video is loaded, consent may be requested. When it is loaded, Google can receive your IP address, device information, the page containing the video and information about your interaction with it. If you are logged into Google, Google may associate the interaction with your account.

15.3 Meta services

Where enabled, we use Meta business and advertising technologies such as:

  • Facebook and Instagram sales channels;

  • Meta Pixel;

  • Meta Conversions API;

  • Meta Ads;

  • Custom Audiences;

  • Conversion and campaign measurement.

Meta may receive cookie or device identifiers, IP addresses, browser information, website events, product views, basket events, checkout events, purchase information and, where lawfully configured, hashed contact information.

Meta can use this information for attribution, advertising measurement, fraud prevention, audience creation and personalisation according to its own privacy terms.

The relevant EEA company is generally Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.

Further information is available in the Meta Privacy Policy.

15.4 TikTok services

Where enabled, we may use:

  • TikTok sales and shop integrations;

  • TikTok Pixel;

  • TikTok Events API;

  • TikTok Ads;

  • Conversion measurement and audience functions.

TikTok may receive IP and device information, cookie or advertising identifiers, page and product interactions, basket and checkout events, purchase information and, where lawfully configured, hashed contact data.

For EEA users, relevant TikTok processing may involve TikTok Technology Limited, Ireland, and other TikTok group companies.

Further information is available in the TikTok Privacy Policy.

15.5 Social-media pages

If you visit or interact with Vallorne on Facebook, Instagram, YouTube, TikTok or another platform, the platform operator processes information under its own privacy policy.

We may receive comments, messages, public profile information and aggregated audience statistics. We use this information to respond to enquiries, operate our social presence and understand engagement. The applicable legal basis is Article 6(1)(a), Article 6(1)(b) or Article 6(1)(f) GDPR.

16. Product feeds, Channable and external marketplaces

Where enabled, we use Channable, operated by ProductImpulse B.V., Kromme Nieuwegracht 66, 3512 HL Utrecht, the Netherlands, to manage product feeds, advertising feeds and marketplace connections.

Channable may process product data and, where order integration is used, relevant order, customer, shipment and transaction information. Processing is based on Article 6(1)(b) and Article 6(1)(f) GDPR.

Further information is available in the Channable Privacy Policy.

16.1 Amazon, Douglas and Sephora

Our products may also be offered through external marketplaces or retail partners, including Amazon, Douglas and Sephora.

If you visit or place an order through an external platform, the relevant platform operator independently collects and processes information under its own privacy policy. This can include account, browsing, payment, order and marketing information.

The platform may provide Vallorne with information required to:

  • Accept and fulfil the order;

  • Deliver the products;

  • Administer returns and refunds;

  • Provide customer service;

  • Meet accounting and legal obligations.

Relevant privacy information is available from:

The exact marketplace operator and its role are identified in the terms and privacy notice shown when you use that marketplace.

17. Accounting through sevdesk

We use sevdesk for bookkeeping, invoicing and the fulfilment of commercial and tax obligations.

For these purposes, sevdesk may process:

  • Customer and supplier details;

  • Order and invoice information;

  • Payment status;

  • Refunds and credit notes;

  • Tax information;

  • Accounting records and supporting documentation.

Processing required for legal accounting and tax obligations is based on Article 6(1)(c) GDPR. Efficient financial administration and the establishment or defence of claims may also be based on Article 6(1)(f) GDPR.

Further information is available in sevdesk’s Privacy Information.

18. Reviews and customer content

If you submit a product review, we may process and publish:

  • Your chosen display name;

  • Rating;

  • Review title and text;

  • Product reference;

  • Submission date;

  • Information indicating whether the purchase was verified, where this can be established.

We may contact you concerning the review or moderate content that violates our rules or applicable law.

Processing is based on your request and consent under Article 6(1)(a) GDPR and our legitimate interest in presenting genuine customer experiences under Article 6(1)(f) GDPR.

A review will only be described as a “verified purchase” if we can reliably associate it with a relevant order.

19. Product safety and adverse-event reports

If you report an allergic reaction, health issue or other adverse event concerning a fragrance, the report may contain health information.

We process this information to:

  • Investigate the report;

  • Communicate with you;

  • Meet product-safety and cosmetovigilance obligations;

  • Notify the manufacturer or responsible authorities where required;

  • Establish, exercise or defend legal claims.

Depending on the circumstances, processing is based on Article 6(1)(c), Article 6(1)(f), Article 9(2)(f) or Article 9(2)(i) GDPR. Where consent is the appropriate basis, we will request it.

Relevant information may be shared with the product manufacturer:

TBrand GmbH / Parfümfabrik Deutschland
Oststraße 71
22844 Norderstedt
Germany

and with competent supervisory or public-health authorities where legally required.

20. Cookies and similar technologies

Our store uses cookies, local storage, pixels, tags and comparable technologies.

20.1 Strictly necessary technologies

Strictly necessary technologies support functions expressly requested by you, such as:

  • Maintaining a shopping basket;

  • Operating checkout;

  • Customer-account login;

  • Security and fraud prevention;

  • Remembering privacy choices;

  • Load balancing and reliable store operation.

Where access to your device is strictly necessary to provide a requested service, it is based on Section 25(2) TDDDG. Related personal-data processing is based on Article 6(1)(b) or Article 6(1)(f) GDPR.

20.2 Preferences, analytics and marketing

Technologies used for preferences, analytics, attribution or personalised advertising are activated only after the legally required consent.

The legal bases are Section 25(1) TDDDG and Article 6(1)(a) GDPR.

20.3 Consent record

We may store a necessary record of your privacy selection so that the banner does not reappear on every page. Our current store configuration may remember this selection for up to twelve months, unless you delete your browser data or change your choice earlier.

You may reopen the privacy controls at any time through the Cookies link in the website footer. Withdrawal does not affect processing that occurred before withdrawal.

You can also delete or block cookies through your browser. Blocking strictly necessary technologies may prevent certain store functions from working.

21. Security and fraud prevention

We process technical, transaction and account information to:

  • Protect accounts and checkout;

  • Detect fraudulent orders;

  • Prevent misuse and automated attacks;

  • Investigate security incidents;

  • Protect our customers, systems and legal rights.

This processing is based on Article 6(1)(f) GDPR and, where applicable, Article 6(1)(c) GDPR.

We use appropriate technical and organisational safeguards designed to protect information against accidental or unlawful loss, alteration, disclosure or access. However, no internet transmission or storage system can guarantee absolute security.

22. Recipients of personal data

Personal data may be disclosed to the following categories of recipients where necessary:

  • Shopify and ecommerce infrastructure providers;

  • Payment providers, banks, card networks and credit-reference agencies;

  • Shipping and logistics providers;

  • Email, SMS and communications providers;

  • Hosting, domain and IT-service providers;

  • Marketing, analytics and advertising providers;

  • Affiliate-management providers and participating affiliates where necessary;

  • Product-feed and marketplace integration providers;

  • External marketplaces and retail partners;

  • Accounting, tax and professional advisers;

  • Product manufacturers and product-safety specialists;

  • Insurers, auditors and legal advisers;

  • Authorities, courts and law-enforcement bodies where required;

  • A purchaser, investor or successor in connection with a lawful corporate transaction.

Providers receive only the information required for their respective task and are contractually or legally restricted where they act as processors.

23. International data transfers

Some providers or their subprocessors are located outside the EEA or may access information from other countries.

Where personal data is transferred to a country without an adequacy decision, the transfer is protected through an appropriate mechanism, such as:

  • European Commission standard contractual clauses;

  • The EU–US Data Privacy Framework where the recipient is validly certified;

  • Binding corporate rules;

  • Another safeguard permitted by Articles 44–49 GDPR.

Where appropriate, supplementary technical and organisational safeguards are applied.

International providers may be subject to foreign laws. These laws may permit public authorities to request access to information under conditions that differ from those in the EEA.

24. Retention

We retain personal data only for as long as required for the relevant purpose or by applicable law.

The following general criteria apply:

  • Order, invoice, payment and accounting information is retained for the statutory periods required by applicable commercial and tax law;

  • Customer-account information is retained while the account remains active and afterwards where required for orders, legal claims or statutory records;

  • Customer-service communications are generally retained until the request is resolved and for an appropriate limitation period afterwards;

  • Marketing subscriptions are retained until consent is withdrawn or the service is discontinued;

  • Consent and unsubscribe records may be retained for as long as necessary to demonstrate compliance;

  • Affiliate information is retained for the duration of the programme and applicable accounting or claim periods;

  • Technical security logs are retained only as long as reasonably necessary unless an incident requires a longer investigation;

  • Reviews may remain published until withdrawn or removed, subject to legal retention requirements;

  • Product-safety reports are retained for the period required by applicable product-safety and cosmetovigilance laws.

Where information is no longer required, it is deleted or anonymised, unless continued storage is legally permitted or required.

Independent providers may apply their own retention periods as described in their privacy notices.

25. Your rights

Subject to the legal requirements, you may have the right to:

  • Request access to your personal data under Article 15 GDPR;

  • Request rectification under Article 16 GDPR;

  • Request erasure under Article 17 GDPR;

  • Request restriction of processing under Article 18 GDPR;

  • Receive certain information in a portable format under Article 20 GDPR;

  • Object to processing based on legitimate interests under Article 21 GDPR;

  • Object at any time to processing for direct marketing;

  • Withdraw consent at any time under Article 7(3) GDPR;

  • Request information concerning relevant automated decision-making;

  • Lodge a complaint with a data-protection supervisory authority.

You may lodge a complaint with the authority responsible for your habitual residence, place of work or the location of an alleged infringement.

To exercise your rights, contact:

privacy@vallorne.com

We may request information necessary to verify your identity. This is intended to ensure that personal data is not disclosed to an unauthorised person.

26. Automated decision-making

Vallorne does not itself make decisions based solely on automated processing that produce legal or similarly significant effects concerning you.

Independent payment providers such as Klarna, Riverty and PayPal may use automated procedures for identity, fraud, risk, affordability or creditworthiness assessments. The relevant provider is responsible for that processing and explains it in its own privacy notice.

27. Children

Our store is not directed at children under 16, and we do not knowingly collect personal data from children for marketing purposes.

If you believe a child has provided us with information without the required authorisation, contact privacy@vallorne.com.

28. Changes to this Privacy Policy

We may update this Privacy Policy when:

  • Our services or providers change;

  • New sales or marketing channels are activated;

  • Legal requirements change;

  • We change how personal data is processed.

The current version will be published on our website with the applicable update date. Where a change materially affects your rights or an existing consent, we will provide an additional notice where required.

To keep up with our latest news, there's also the newsletter. Sign up here: