Privacy Policy
Last updated: 2026-05-24
This privacy policy explains how Northern Lighthouse Holding.ltd ("we", "us") collects, uses and protects your personal data when you visit and shop in our online store. We process your data in accordance with the General Data Protection Regulation (GDPR).
1. Data Controller
The controller responsible for processing your data is:
Northern Lighthouse Holding.ltd
2. What Data We Collect
- Contact and delivery details: name, delivery address, billing address, email address and phone number.
- Order data: the products you buy, order number, order history and your communication with us.
- Payment data: payments are handled by our payment providers (Stripe and, for crypto payments, NOWPayments). We do not store full card numbers.
- Newsletter: your email address if you choose to subscribe.
- Technical information: IP address, device and browser information, and cookies.
3. Purpose & Legal Basis
- Fulfilling your purchase and delivering your order – legal basis: performance of a contract.
- Customer service and handling returns/complaints – legal basis: performance of a contract and legitimate interest.
- Accounting and legal obligations – legal basis: legal obligation.
- Newsletters and marketing – legal basis: consent, which you may withdraw at any time.
- Improving and securing the store – legal basis: legitimate interest.
4. Recipients & Third Parties
- Payment providers (Stripe, NOWPayments) to process payments.
- Suppliers and shipping carriers to deliver your products.
- Our email/newsletter service provider for sending messages.
- Authorities where we are legally required to disclose data.
If any recipient processes data outside the EU/EEA, we ensure the transfer is protected by appropriate safeguards under the GDPR.
5. Data Retention
We keep your data only as long as necessary for the purposes above. Order data is retained as required by accounting law. Newsletter data is kept until you unsubscribe.
6. Your Rights
- request access to the data we hold about you,
- request correction of inaccurate data,
- request erasure ("the right to be forgotten"),
- request restriction of processing,
- object to processing based on legitimate interest,
- request data portability,
- withdraw any consent you have given.
You also have the right to lodge a complaint with your data protection supervisory authority (in Sweden, IMY). To exercise your rights, contact us at [contact email].
7. Cookies
We use cookies so the store works, to remember your cart and preferences, and where applicable for analytics. Essential cookies are required for the site to function. Other cookies are used only with your consent.
8. Contact
For questions about this privacy policy, contact us by clicking here.