Privacy Policy

Glowest Trade OÜ  ·  glowest.eu  ·  Effective date: 1 April 2026

This Privacy Policy explains how Glowest Trade OÜ (“Glowest”, “we”, “us”, or “our”) collects, uses, and protects your personal data when you visit glowest.eu (the “Site”) or purchase our products. We are committed to handling your data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Estonian law.

1. Who we are

Data controller:

Glowest Trade OÜ

Lammi 8, Tallinn, Estonia

Email: hello@glowest.eu

As the data controller, Glowest Trade OÜ determines the purposes and means of processing your personal data. We are registered in Estonia and subject to EU data protection law.

2. Data we collect

2.1 Data you provide directly

  • Order information: Name, billing and shipping address, email address, phone number, and payment details (payment card data is processed directly by our payment provider and never stored by us)
  • Account information: Email address and password if you create an account
  • Communication: Messages sent via contact forms, email, or customer support
  • Marketing preferences: Email address and consent records when you subscribe to our newsletter

2.2 Data collected automatically

  • Usage data: IP address, browser type and version, operating system, pages viewed, referral URLs, and time spent on the Site
  • Device data: Device type, screen resolution, language settings
  • Cookies and similar technologies: See Section 5 for full details
  • Transaction data: Purchase history, order value, and product preferences

2.3 Data from third parties

  • Payment processors who confirm transaction status
  • Analytics providers who share aggregated usage insights
  • Advertising platforms (Meta, Google) who may share ad interaction data where you have consented to personalised advertising

3. How and why we use your data

Purpose Data used Legal basis
Process and fulfil orders Name, address, contact details, order data Contract performance
Handle payments Order total, payment status Contract performance
Provide customer support Name, email, order history, communications Contract performance / Legitimate interest
Send order confirmations and shipping updates Email address, order data Contract performance
Send marketing emails and newsletters Email address, purchase history Consent
Personalise ads on Meta and Google Email address, browsing and purchase data Consent
Improve the Site and product offering Usage data, analytics Legitimate interest
Prevent fraud and ensure security IP address, order data, device data Legitimate interest / Legal obligation
Comply with legal and tax obligations Name, address, invoice data Legal obligation
Manage returns and complaints Order data, communications Legal obligation / Contract performance

4. Legal basis for processing

We rely on the following legal bases under Article 6 GDPR:

  • Contract: Processing necessary to perform the sales contract with you (order fulfilment, shipping, customer service)
  • Legal obligation: Processing required to comply with Estonian and EU law (accounting records, consumer rights, tax)
  • Legitimate interest: Processing for our reasonable business interests (fraud prevention, Site improvement, B2B direct marketing) where these interests are not overridden by your rights
  • Consent: Processing where you have given us clear, specific consent (marketing emails, analytics cookies, personalised advertising). You may withdraw consent at any time without affecting the lawfulness of prior processing.

5. Cookies and tracking

We use cookies and similar tracking technologies on glowest.eu. When you first visit the Site, a cookie consent banner will ask for your preferences. You may accept all cookies, customise your choices, or reject non-essential cookies.

5.1 Types of cookies we use

Category Purpose Basis
Strictly necessary Shopping cart, session management, security No consent required
Functional Remembering your preferences (language, currency) Consent
Analytics Measuring Site performance (Google Analytics) Consent
Marketing Ad targeting and retargeting (Meta Pixel, Google Ads) Consent

You can change or withdraw your cookie preferences at any time by clicking the “Cookie settings” link in the Site footer or adjusting your browser settings. Note that disabling certain cookies may affect Site functionality.

6. Sharing your data

We do not sell your personal data. We share data only where necessary with trusted service providers acting as data processors on our behalf:

  • Payment processors: To securely handle payment transactions
  • Logistics and shipping providers: To deliver your orders
  • Email marketing platforms: To send order communications and newsletters
  • Analytics providers (e.g. Google Analytics): To help us understand Site usage
  • Advertising platforms (Meta Platforms, Google LLC): To serve and measure advertising where you have consented
  • Hosting and infrastructure providers: To operate and maintain the Site
  • Accounting and legal advisors: Where required to meet our legal obligations

All processors are bound by data processing agreements and may only use your data according to our instructions. We may also disclose your data to competent authorities where required by law.

7. International transfers

Some of our service providers are based outside the European Economic Area (EEA), including in the United States. Where data is transferred outside the EEA, we ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Transfers to countries with an EU adequacy decision

You may request a copy of the relevant transfer safeguards by contacting us at the details in Section 13.

8. How long we keep your data

Data type Retention period
Order and invoice records 7 years (Estonian Accounting Act requirement)
Customer account data Duration of account + 2 years after last activity
Marketing consent and email data Until you unsubscribe, then deleted within 30 days
Customer support communications 3 years from resolution
Website analytics data 26 months (anonymised after 14 months where possible)
Fraud prevention logs 12 months

After the applicable retention period, data is securely deleted or anonymised.

9. Your rights

Under the GDPR, you have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Ask us to correct inaccurate or incomplete data
  • Erasure (“right to be forgotten”): Request deletion of your data where there is no overriding legal basis for us to keep it
  • Restriction: Ask us to limit processing of your data in certain circumstances
  • Data portability: Receive your data in a structured, machine-readable format
  • Objection: Object to processing based on legitimate interests or for direct marketing purposes
  • Withdraw consent: Withdraw any consent you have given at any time (this does not affect processing already carried out)
  • Automated decision-making: Not be subject to decisions based solely on automated processing that significantly affect you
To exercise any of these rights, email us at hello@glowest.eu.

We will respond within 30 days. We may ask you to verify your identity before processing

your request. Your request is free of charge.

If you are unsatisfied with how we handle your data or your rights request, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (aki.ee) or your local supervisory authority within the EU.

10. Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or disclosure. These include TLS/HTTPS encryption for data in transit, access controls, and working only with PCI-DSS-compliant payment processors.

No method of transmission over the internet is completely secure. If you suspect any security incident related to your data, please contact us immediately at hello@glowest.eu.

11. Children

Our Site and products are intended for adults. We do not knowingly collect personal data from individuals under the age of 16. If you believe a child has provided us with their personal data, please contact us and we will delete it promptly.

12. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The current version is always available at glowest.eu/privacy. If we make material changes, we will notify you by email or by placing a notice on the Site. The date at the top of this page indicates when the policy was last revised.

13. Contact us

Glowest Trade OÜ

Lammi 8, Tallinn, Estonia

Email: hello@glowest.eu

Website: glowest.eu