Privacy policy
We only collect what it takes to embroider and deliver your order.
Last updated
On this page
The company details have not been filled in yet (SHOP_* in .env). This page shows placeholders.
Data controller
Crafty Creations, CVR no. 00000000, Adresse mangler, 0000 By, Denmark, is the data controller for the processing of your personal data on craftycrochet.dk. Questions about personal data can be sent to hej@example.dk.
What we process
When you order, we process: name, email, phone number (if provided), delivery address, details of your order and the photo you upload for your embroidery. Payment is handled by Stripe — we only receive a confirmation of payment and never the card details themselves.
When you visit the website we also process technical information (IP address, browser type and time) in server logs for security reasons, and — only if you accept — cookies that show which of our posts lead to visits and purchases.
Purposes and legal bases
Delivering your order, communicating about it and producing your embroidery: necessary to perform the contract with you (GDPR Article 6(1)(b)).
Bookkeeping and retention of order and payment records: a legal obligation under the Danish Bookkeeping Act (Article 6(1)(c)) — five years from the end of the financial year the purchase relates to.
Statistics and marketing measurement via cookies: your consent (Article 6(1)(a)), which you can withdraw at any time on the Cookie policy page.
Security, abuse prevention and troubleshooting (server logs, rate limiting): our legitimate interest in running a secure website (Article 6(1)(f)).
Your photo and artificial intelligence
The photo you upload is processed by an AI image service (Azure OpenAI from Microsoft) to turn it into an embroidery drawing. The preview on the product page is computed on our own servers; the photo is only sent to the AI service after you have paid. Under Microsoft’s Azure OpenAI terms your images are not used to train the models.
Processing may take place outside the EU/EEA. The transfer is based on Microsoft’s data processing terms (Data Protection Addendum) and the European Commission’s standard contractual clauses, which ensure a level of protection equivalent to that in the EU.
Only upload photos you have the right to use. If the photo shows other people, you are responsible for their agreeing to have it embroidered.
Recipients of your data
We only share data with suppliers that help us deliver your order, and only what is necessary: Stripe (payment), Microsoft Azure (AI processing of your photo, see above), the carrier (name, address and phone/email for delivery), our email provider (order confirmations and shipping notices) and our hosting provider. We never sell your data.
Retention
Uploaded photos and embroidery files are deleted 90 days after delivery. Order and payment records are kept for five years from the end of the financial year (Bookkeeping Act). Uploaded photos without a completed purchase are deleted after 7 days, and unpaid draft orders after 24 hours. Server logs are kept briefly for security reasons.
Your rights
You have the right to access the data we process about you, to have inaccurate data rectified, to have data erased, to have processing restricted, to data portability and to object to processing. Consent can always be withdrawn with effect for the future. Write to hej@example.dk — we reply within one month at the latest.
If you are unhappy with how we process your data, you can complain to the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark, datatilsynet.dk.