Privacy Policy
This page explains in simple terms what personal data is used for the operation of the Resin Novel eshop.
Data controller
The data controller for the Resin Novel eshop is ΚΟΚΚΑΛΑΣ ΑΘΑΝΑΣΙΟΣ ΤΟΥ ΔΗΜΗΤΡΙΟΥ.
Contact email: info@resinnovel.gr. Telephone: 698 589 0915. VAT: 154249914. GEMI: 1938081300000. info@resinnovel.gr · Contact page
Information provided by customers
The Contact form collects name, email, message and optional phone number.
Checkout collects full name, email, phone, city, address, ZIP/postal code, order products, quantities, total, payment method and optional notes.
If a customer writes personalization instructions in an order note or message, those instructions are used to produce and support that specific order. The current checkout does not include a file-upload field.
Technical data
The eshop uses browser local storage for cart, wishlist and recently viewed products.
When Supabase Auth is enabled, account data may include email, password managed by the authentication service, Google sign-in where selected by the customer, user ID and session cookies.
When Google reCAPTCHA is enabled, the verification token, form action and, where available, IP address are sent to Google for spam and abuse checks.
Google Analytics loads only when a Measurement ID is configured. No consent mechanism for non-essential analytics cookies was found in the current implementation.
Purposes
Information is used to answer messages, process and fulfil orders, send bank-transfer instructions, send order-status updates, provide support, handle returns, refunds and disputes.
Information is also used for accounting, tax and other legal obligations, transaction security, and prevention of spam, fraud or abuse.
No active newsletter or marketing opt-in system was found. Customers are not added to a newsletter through contact or order forms.
Legal bases
Pre-purchase communication and order processing are based on pre-contractual steps and performance of the order.
Keeping invoice, accounting or tax records is based on legal obligation.
Answering requests, providing customer support, protecting the eshop and preventing spam or abuse are based on legitimate interests where necessary and proportionate.
Consent is not used as a general processing basis. No newsletter opt-in or cookie banner was found in the current implementation.
Contact form
The Contact form asks for name, email and message, while phone is optional. The details are sent by email to the eshop team through the configured SMTP service.
The form uses a honeypot field and may use Google reCAPTCHA to limit unwanted or automated messages. Customers should avoid sending sensitive information that is not needed for their request.
Orders and checkout
Checkout supports bank transfer. The eshop stores the order, customer and delivery details, products, value, notes, order number and order status.
The eshop sends a confirmation email to the customer and an order email to the admin address. When an order is marked as shipped, courier and tracking number may be stored and sent in a status update.
The current implementation does not collect or store complete payment-card details.
Customer account
When account functionality is enabled, customers may create or use an account through Supabase Auth with email and password or Google sign-in. The account is used for sign-in, profile email display and order-history access for orders linked to the user.
Providers and recipients
Personal data may be processed by the website hosting infrastructure, the Supabase database and authentication service, the configured SMTP email service and, when enabled, Google reCAPTCHA.
When Google Analytics is configured, technical and aggregate usage data may be submitted to the analytics service. To deliver an order, necessary delivery details may be used with the shipping service handling that order.
Information may also be provided to competent authorities where required by law. The Sanity integration found in the codebase is used for catalogue content, and no customer personal-data processing through it was identified.
Retention
Contact messages are kept for as long as needed to answer, support and follow up the request.
Order, transaction, return, support and accounting or tax records are kept for as long as needed to fulfil the order, support the customer, establish or defend rights and meet legal obligations.
No fixed retention periods were found in the implementation. Retention is based on the purpose, the nature of the request and legal obligations.
Customer rights
Customers may, under the GDPR conditions, request access, correction, deletion, restriction of processing, portability where applicable, objection to processing based on legitimate interests and withdrawal of consent where processing relies on consent.
Privacy requests can be sent to info@resinnovel.gr. Rights are subject to legal conditions and exceptions, such as obligations to keep accounting, tax or order records. info@resinnovel.gr
Supervisory authority
The competent supervisory authority in Greece is the Hellenic Data Protection Authority, in Greek Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα. Customers have the right to lodge a complaint with the authority under the GDPR. www.dpa.gr
Security
Reasonable technical and organisational measures are used to protect information handled for messages, accounts and orders. No online transmission or storage method can be guaranteed as absolutely secure.
Cookies and similar technologies
The eshop uses localStorage for cart, wishlist and recently viewed products so core shopping features work in the browser.
When customer accounts are enabled, Supabase Auth uses session cookies to sign in and maintain the session.
Google reCAPTCHA and Google Analytics are configurable third-party services. If enabled, they may use cookies or similar technologies for security or usage measurement. No consent mechanism for non-essential analytics cookies was found.
Third-party links
The website may include normal external links to social networks such as Facebook, Instagram and TikTok. When customers follow those links, the privacy policies of the relevant platform apply.
International transfers
The current implementation does not confirm specific processing countries or international transfers for the configured providers. If processing outside the EEA is confirmed, this policy should be updated with the provider, country and relevant safeguards.
Children
The eshop is intended for commercial customer transactions and does not include age verification. People who need parent or guardian consent should use the eshop with appropriate support.
Policy changes
This Privacy Policy may be updated when processing practices, eshop services or legal requirements change.
