Privacy Policy
Privacy Policy
Last updated: 10 May 2026
This Privacy Policy explains how Livnorr (“we”, “us”, “our”) collects, uses, shares, and protects personal data when you visit livnorr.com, place an order, or otherwise interact with us. We are committed to handling your personal data lawfully, transparently, and in line with the EU General Data Protection Regulation (GDPR) and the Swedish Data Protection Act.
1. Data controller
The data controller responsible for your personal data is:
Livnorr (enskild firma)
Wibeliusgatan 4C, 151 32 Södertälje, Sweden
Email: contact@livnorr.com
EU VAT: SE011118041001
2. Personal data we collect
We only collect personal data that is necessary to operate the store, fulfil your orders, and improve your experience. The categories include:
- Contact and identity data: name, billing and shipping address, email, telephone number.
- Order data: products purchased, order value, payment method, order history.
- Payment data: handled by our payment processors. We do not store full card numbers.
- Account data: login credentials and saved addresses if you choose to create an account.
- Customer service data: messages, attachments, and other information you share when contacting us.
- Technical and usage data: IP address, browser, device, language, pages viewed, referring URL, cookies, and similar identifiers.
- Marketing data: your subscription preferences and engagement with our communications.
3. How we use your personal data and the legal basis
We process your personal data on the following legal bases under Article 6 GDPR:
- Performance of a contract – to process your order, take payment, ship products, manage returns, and provide customer service.
- Legal obligation – to comply with accounting, tax, consumer protection, and other applicable laws (for example, Bokföringslagen requires us to retain order records for seven years).
- Legitimate interests – to operate, secure, and improve the store, prevent fraud, and conduct limited analytics. We balance our interests against your rights.
- Consent – for non-essential cookies, marketing emails, and any optional features. You may withdraw consent at any time.
4. Who we share data with
We share personal data only with carefully selected service providers who help us run the store. Each acts as a processor under written agreement and may only use your data on our instructions.
- Shopify Inc. – e-commerce platform and hosting.
- Payment providers – including Shopify Payments, Klarna, and PayPal where enabled at checkout.
- Shipping carriers – such as PostNord, DHL, and equivalent regional partners, to deliver your order.
- Email and analytics providers – including Shopify Email and, where enabled, Google Analytics.
- Apps installed on the store – such as Vitals (reviews, on-site enhancements). We restrict each app to the data it needs.
- Authorities – if we are legally required to disclose information.
5. International transfers
Some of our service providers are located outside the European Economic Area (EEA), including the United States. When personal data is transferred outside the EEA, we rely on appropriate safeguards such as the EU Standard Contractual Clauses or the EU–US Data Privacy Framework, where applicable, to ensure your data receives an equivalent level of protection. Shopify Inc.’s data processing terms and applicable SCCs are available at shopify.com/legal/dpa.
6. How long we keep data
- Order and accounting records: seven years from the end of the financial year, as required by Swedish law.
- Customer accounts: until you delete the account or request erasure.
- Customer service correspondence: up to three years after the last contact.
- Marketing data: until you unsubscribe or withdraw consent.
- Cookie and analytics data: up to 24 months, depending on the cookie.
7. Cookies
We use cookies and similar technologies to operate the store, remember your preferences, secure checkout, and measure performance. Strictly necessary cookies do not require consent. All other cookies are set only after you give consent through our cookie banner. You can change your preferences at any time from the cookie settings link in the footer.
8. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request erasure of your data, subject to legal retention requirements.
- Restrict or object to certain processing.
- Receive your data in a portable format.
- Withdraw consent at any time, without affecting the lawfulness of prior processing.
- Lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at www.imy.se.
To exercise any of these rights, write to contact@livnorr.com. We will respond within one month.
9. Security
Our store runs on Shopify’s PCI-DSS certified infrastructure. Payment pages are encrypted in transit, and we apply organisational and technical measures to protect your data from unauthorised access, alteration, disclosure, and loss.
10. Children
Livnorr is intended for adult customers. We do not knowingly collect personal data from children under 16. If you believe a child has provided personal data, please contact us so we can remove it.
11. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of the page reflects the latest revision. Material changes will be communicated through the store or by email where appropriate.
12. Contact
For privacy questions, requests, or complaints, contact us at contact@livnorr.com.