Privacy policy
Operated by Web Window OÜ, Tallinn, Estonia. Last updated: September 21, 2026.
1. Data controller
The controller of your personal data is Web Window OÜ, a private limited company registered in Estonia (registry code 17163769), Maakri tn 19/1, Kesklinna linnaosa, 10145 Tallinn, Harju maakond, Estonia (the “Operator”, “we”). We operate the Rolly store at rollyme.com.
For any privacy question or request, contact us at support@rollyme.com.
2. Scope
This policy covers personal data processed when you browse rollyme.com, place an order, or contact us, wherever you are in the world. We apply the EU General Data Protection Regulation (GDPR) as our baseline standard for all customers, not only those in the EU.
3. Data we collect
Order data: your name, email address, phone number, billing and shipping address, order items, payment status and order history. You enter payment and address details on Stripe’s hosted checkout. We receive the details needed to prepare, invoice and deliver your order; your full card number stays with Stripe.
Contact details you give us for artwork: any of email, Instagram, Telegram or WhatsApp that you type into the product page or cart, so we can send your proof on whichever one you actually read. You choose which, and none of them is required to browse.
Messages you send us: the contact and business-quote forms collect your name, email, company name (optional), and message. If you reach out on WhatsApp or Telegram, we see the profile details and messages you choose to share there.
Artwork you submit: logos, design layouts and files you upload for engraving, together with the proof revisions we prepare and your approval or change requests.
Newsletter signup: when you choose to subscribe, we store your email, the consent wording, signup source and time, and any welcome discount and redemption record. The signup is optional. Each newsletter email includes an unsubscribe link. Using it stops newsletter updates while keeping order, proof and delivery emails available.
Saved carts: when you provide an email and cart recovery is enabled, the site can send your cart contents and contact details to our server before checkout. This lets us recover an unfinished cart and, when enabled, send a cart reminder. A cart reminder includes an opt-out link.
Technical data: our hosting provider uses request information, including your IP address and browser, for site delivery, approximate location, security and reliability. Approximate country helps set the initial currency and delivery destination.
Order and cart context: when you place an order, or leave items in your cart after giving us an email address, we record the approximate country and city, the device type, the browser and the operating system that the request came from. We use it to support you when something goes wrong with an order, to investigate fraudulent or disputed payments, and to understand which devices the store needs to work well on. It is derived from your IP address and your browser's own user-agent string, not from any tracking script, and it is never used for advertising or sold to anyone. Approximate location is exactly that: a VPN or a company network will show where the connection left, not where you are.
4. Payment details and customer accounts
We do not see or store your full card number. Stripe handles payment details. There are no customer account passwords to create. We do not use advertising trackers.
5. Purposes and legal bases
Performance of a contract (GDPR Art. 6(1)(b)): processing your order, preparing and approving proofs, producing and shipping your items, sending order confirmations and tracking emails, and answering your support requests.
Legal obligation (Art. 6(1)(c)): keeping invoices and transaction records required by Estonian accounting and tax law.
Legitimate interests (Art. 6(1)(f)): preventing fraud and abuse, securing the site, keeping records needed to handle support and defect claims, and helping with incomplete orders. Optional analytics is governed by the current choices described in our cookie policy.
Consent (Art. 6(1)(a)): optional newsletter signups and consent-based analytics and recordings. Newsletter consent is separate from your artwork contact details. You can withdraw consent without affecting earlier processing; see the cookie policy and the contact details below.
6. Who receives your data
We use service providers to run the store: Stripe for payments and checkout; our hosted store database for orders, contacts, subscriptions and saved carts; Resend for email; Vercel for website hosting and performance measurement; Cloudflare for DNS and artwork storage; Google for analytics; and Omniva or other delivery partners for shipping. The carrier receives the name, address and contact details needed to deliver your parcel. If you choose a messaging app for support, that provider also handles the messages.
When Google Analytics is enabled, its script uses advanced consent mode. Before analytics cookies are allowed, Google can still receive measurements without those cookies, including request information such as the page and browser details. Rejecting analytics cookies is not a promise that no request reaches Google. Advertising storage and personalization are disabled in our configuration.
We disclose data to public authorities only where the law requires it. We never sell or rent your personal data to anyone.
7. International transfers
Service providers may process data outside the EU/EEA. The applicable provider agreements and transfer safeguards govern that processing. Contact support@rollyme.com for information about the providers and safeguards used for your data.
Artwork and proof files are kept in private storage. They are available to the people and services handling your order through controlled access, rather than a public file listing.
8. How long we keep data
Invoices and supporting transaction records are kept for seven years from the end of the relevant financial year. We also keep order, contact, proof and payment-reference records in our own store database to fulfil orders and handle support and claims. Stripe keeps its payment records under its own retention rules.
Other correspondence, artwork, saved carts and subscription records are kept while needed for their stated purpose or a related legal requirement. Contact us to request deletion or to ask about a particular record. We may retain the minimum information needed to honour an email opt-out or meet an accounting obligation.
9. Your rights (GDPR)
You may ask us at any time to access, correct, export or erase your personal data, to restrict or object to its processing, and to withdraw any consent you have given (without affecting processing before withdrawal). Email support@rollyme.com and we will respond within one month.
You also have the right to lodge a complaint with a supervisory authority, in Estonia, the Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee), or the authority in your own EU country.
10. Customers in the United States
We do not sell or share personal information as those terms are defined in US state privacy laws (such as the CCPA/CPRA), and we do not use it for cross-context behavioral advertising. US customers may exercise the same access, correction and deletion rights described above by emailing support@rollyme.com.
11. Cookies and site storage
We use browser storage for your cart, contact details, design draft and preferences. Optional analytics follows the consent rules and providers described in the cookie policy. The Cookie settings button on the cookie policy page lets you review or change that choice without deleting your cart. See rollyme.com/legal/cookies for details.
12. Changes and contact
We may update this policy as the store or the law changes; the current version is always published on this page with its “last updated” date. Material changes will be highlighted here.
Questions about this policy or your data: support@rollyme.com, or by post to Web Window OÜ, Maakri tn 19/1, Kesklinna linnaosa, 10145 Tallinn, Harju maakond, Estonia.