GDPR & Cookies

This website uses cookies to provide the website owner with information about how visitors navigate and use the site via Google Analytics.

About cookies

Since 1 July 2011, cookies and other technologies used to store or retrieve data may only be used with the visitor’s consent—this consent can be given in various ways, for example through the visitor’s web browser.

If you do not want your web browser to consent to cookies from vasterbottenssapa.se being stored on your computer, you can change this in your browser settings. Read more at www.minacookies.se.

Cookies are passive files that websites store on their visitors’ computers, among other things so that they can recognize those computers the next time they are visited. vasterbottenssapa.se also uses so-called session cookies to make the shopping cart work and to enable our visitors to place orders. These session cookies disappear when you, as a visitor to our website, close your web browser.

GDPR – How we handle your personal data

It is important to us at Soapa that you feel confident about how we handle your personal data. That is why we are transparent about how we collect, process, and share the information we store about you. We never sell your personal data to other companies.

Personal data is any information that can be used to identify an individual. Examples include basic information about you, such as your name and contact details. It may also include purchase history, bonus points, and similar information—but if you have shopped with us, you already know that we do not have customer accounts, logins, or bonus points. Every purchase is unique to us, and we do not save unnecessary or excessive information.

We ensure that the personal data you provide when making a purchase is protected. We ensure that its processing complies with applicable data protection regulations, internal guidelines, and procedures.

On this page, we describe how and why we process your personal data, as well as the rights you have.

  1. When making a purchase you provide your personal data so that we can send goods to you and charge you for them.
    We retain your information for as long as the Consumer Sales Act gives you the right to cancel a purchase or return a damaged or defective product, that is, 14 days. The information is stored in our online store, Shopify, among other things so that we can process a return and refund if necessary.
  2. Payment: Qliro We use Qliro as our digital checkout service provider. We have what is known as a DPA agreement with Qliro, under which they guarantee that your information is secure. You can also pay with Swish and Shopify Pay, and the same applies there.
  3. Delivery: PostNord, To deliver your package, your address and telephone number, or alternatively your email address for delivery notifications, are required. PostNord and its UNIWIN service may therefore need to process your information. We also have DPA agreements with these companies that guarantee the security of your information. You can find PostNord and PacksoftOnline’s GDPR policy and rules here.
    Qliro and Swish (Swedbank), as well as Shopify Pay, process payments and the information associated with them. Shopify is our e-commerce platform and therefore processes the information you enter at checkout.
  4. Newsletter – Our newsletter service processes email addresses and any other information you provide there. You can always unsubscribe from our newsletter via the link included in the email. The newsletter service is called Klaiyo. 
  5. Email – if you send us an email, it is stored for six months. We retain your email because customers often ask about a specific product or have another question that we or you would like to follow up on.
  6. Telephone – voice calls, call logs, SMS, and MMS messages are automatically deleted at the start of each month.
  7. Social media – The social media platforms we use are Facebook, Instagram, Twitter, and Pinterest. We have accepted and signed their terms and agreements. We follow their rules, and if you no longer wish to follow us, you can unfollow us through the respective social media platform.
  8. Paper – Customer order-picking lists and incoming paper letters containing personal data are destroyed quarterly.
  9. In-store – If you shop at our physical store, only receipts are stored in accordance with the Swedish Bookkeeping Act. If you request a receipt by email, the receipt and email address are also stored in accordance with the Swedish Bookkeeping Act. We use iZettle’s point-of-sale system. Payments via Swish are also handled in accordance with the Swedish Bookkeeping Act.
  10. Procedures 
    Personal data breaches are reported to the Swedish Authority for Privacy Protection within 72 hours; affected individuals are informed, and the incident is documented by the company and stored together with the accounting records that must be archived under the Swedish Bookkeeping Act.
    Requests for access: A written copy of the personal data is sent within one month.