Privacy Policy
Glowest Trade OÜ · glowest.eu · Effective date: 1 April 2026
This Privacy Policy explains how Glowest Trade OÜ (“Glowest”, “we”, “us”, or “our”) collects, uses, and protects your personal data when you visit glowest.eu (the “Site”) or purchase our products. We are committed to handling your data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Estonian law.
1. Who we are
| Data controller:
Glowest Trade OÜ Lammi 8, Tallinn, Estonia Email: hello@glowest.eu |
As the data controller, Glowest Trade OÜ determines the purposes and means of processing your personal data. We are registered in Estonia and subject to EU data protection law.
2. Data we collect
2.1 Data you provide directly
- Order information: Name, billing and shipping address, email address, phone number, and payment details (payment card data is processed directly by our payment provider and never stored by us)
- Account information: Email address and password if you create an account
- Communication: Messages sent via contact forms, email, or customer support
- Marketing preferences: Email address and consent records when you subscribe to our newsletter
2.2 Data collected automatically
- Usage data: IP address, browser type and version, operating system, pages viewed, referral URLs, and time spent on the Site
- Device data: Device type, screen resolution, language settings
- Cookies and similar technologies: See Section 5 for full details
- Transaction data: Purchase history, order value, and product preferences
2.3 Data from third parties
- Payment processors who confirm transaction status
- Analytics providers who share aggregated usage insights
- Advertising platforms (Meta, Google) who may share ad interaction data where you have consented to personalised advertising
3. How and why we use your data
| Purpose | Data used | Legal basis |
| Process and fulfil orders | Name, address, contact details, order data | Contract performance |
| Handle payments | Order total, payment status | Contract performance |
| Provide customer support | Name, email, order history, communications | Contract performance / Legitimate interest |
| Send order confirmations and shipping updates | Email address, order data | Contract performance |
| Send marketing emails and newsletters | Email address, purchase history | Consent |
| Personalise ads on Meta and Google | Email address, browsing and purchase data | Consent |
| Improve the Site and product offering | Usage data, analytics | Legitimate interest |
| Prevent fraud and ensure security | IP address, order data, device data | Legitimate interest / Legal obligation |
| Comply with legal and tax obligations | Name, address, invoice data | Legal obligation |
| Manage returns and complaints | Order data, communications | Legal obligation / Contract performance |
4. Legal basis for processing
We rely on the following legal bases under Article 6 GDPR:
- Contract: Processing necessary to perform the sales contract with you (order fulfilment, shipping, customer service)
- Legal obligation: Processing required to comply with Estonian and EU law (accounting records, consumer rights, tax)
- Legitimate interest: Processing for our reasonable business interests (fraud prevention, Site improvement, B2B direct marketing) where these interests are not overridden by your rights
- Consent: Processing where you have given us clear, specific consent (marketing emails, analytics cookies, personalised advertising). You may withdraw consent at any time without affecting the lawfulness of prior processing.
5. Cookies and tracking
We use cookies and similar tracking technologies on glowest.eu. When you first visit the Site, a cookie consent banner will ask for your preferences. You may accept all cookies, customise your choices, or reject non-essential cookies.
5.1 Types of cookies we use
| Category | Purpose | Basis |
| Strictly necessary | Shopping cart, session management, security | No consent required |
| Functional | Remembering your preferences (language, currency) | Consent |
| Analytics | Measuring Site performance (Google Analytics) | Consent |
| Marketing | Ad targeting and retargeting (Meta Pixel, Google Ads) | Consent |
You can change or withdraw your cookie preferences at any time by clicking the “Cookie settings” link in the Site footer or adjusting your browser settings. Note that disabling certain cookies may affect Site functionality.
6. Sharing your data
We do not sell your personal data. We share data only where necessary with trusted service providers acting as data processors on our behalf:
- Payment processors: To securely handle payment transactions
- Logistics and shipping providers: To deliver your orders
- Email marketing platforms: To send order communications and newsletters
- Analytics providers (e.g. Google Analytics): To help us understand Site usage
- Advertising platforms (Meta Platforms, Google LLC): To serve and measure advertising where you have consented
- Hosting and infrastructure providers: To operate and maintain the Site
- Accounting and legal advisors: Where required to meet our legal obligations
All processors are bound by data processing agreements and may only use your data according to our instructions. We may also disclose your data to competent authorities where required by law.
7. International transfers
Some of our service providers are based outside the European Economic Area (EEA), including in the United States. Where data is transferred outside the EEA, we ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Transfers to countries with an EU adequacy decision
You may request a copy of the relevant transfer safeguards by contacting us at the details in Section 13.
8. How long we keep your data
| Data type | Retention period |
| Order and invoice records | 7 years (Estonian Accounting Act requirement) |
| Customer account data | Duration of account + 2 years after last activity |
| Marketing consent and email data | Until you unsubscribe, then deleted within 30 days |
| Customer support communications | 3 years from resolution |
| Website analytics data | 26 months (anonymised after 14 months where possible) |
| Fraud prevention logs | 12 months |
After the applicable retention period, data is securely deleted or anonymised.
9. Your rights
Under the GDPR, you have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Rectification: Ask us to correct inaccurate or incomplete data
- Erasure (“right to be forgotten”): Request deletion of your data where there is no overriding legal basis for us to keep it
- Restriction: Ask us to limit processing of your data in certain circumstances
- Data portability: Receive your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interests or for direct marketing purposes
- Withdraw consent: Withdraw any consent you have given at any time (this does not affect processing already carried out)
- Automated decision-making: Not be subject to decisions based solely on automated processing that significantly affect you
| To exercise any of these rights, email us at hello@glowest.eu.
We will respond within 30 days. We may ask you to verify your identity before processing your request. Your request is free of charge. |
If you are unsatisfied with how we handle your data or your rights request, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (aki.ee) or your local supervisory authority within the EU.
10. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or disclosure. These include TLS/HTTPS encryption for data in transit, access controls, and working only with PCI-DSS-compliant payment processors.
No method of transmission over the internet is completely secure. If you suspect any security incident related to your data, please contact us immediately at hello@glowest.eu.
11. Children
Our Site and products are intended for adults. We do not knowingly collect personal data from individuals under the age of 16. If you believe a child has provided us with their personal data, please contact us and we will delete it promptly.
12. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The current version is always available at glowest.eu/privacy. If we make material changes, we will notify you by email or by placing a notice on the Site. The date at the top of this page indicates when the policy was last revised.
13. Contact us
| Glowest Trade OÜ
Lammi 8, Tallinn, Estonia Email: hello@glowest.eu Website: glowest.eu |