Privacy Policy
Last updated: 12 September 2026
Drafted Lab SRL respects the privacy rights of its users and is committed to protecting personal data in accordance with Regulation (EU) 2016/679 (GDPR) and applicable national legislation.
1. Data controller
Drafted Lab SRL
Reg. no.: J2026043976003 · Tax ID (CUI): 55189641
Strada Drumul Gura Gârliței nr. 26, sc. C, et. 4, ap. 406, Sector 3, Bucharest, Romania
Email: office@drafted-lab.com
2. What data we collect
Data you provide directly:
- When creating an account: name, email address, password (protected by hashing by the authentication provider)
- When placing an order: delivery address (street, locality/sector, county, country, postcode) or the easybox you selected, phone, and, if different, a billing address (name or company name, plus VAT ID for B2B invoices)
- When ordering as a guest (no account): we process your email, name, phone and delivery/billing addresses solely to fulfil the order. If you later create an account with the same email, the orders are linked automatically
- When subscribing to the newsletter: your email and, as proof of consent, the moment (date and time), IP address, user agent, source (footer/checkout) and policy version - kept in a consent registry, per Art. 7(1) GDPR
- When you request a return: order identification and information needed to resolve your request. No explanation is required for withdrawal. Photos may help assess defects; avoid including people or unrelated personal details. Photos are stored privately and accessible only to authorised staff and the requester through authenticated access
- When you write a review: the rating, the text and, optionally, photos. The review and its photos are public on the product page
- When contacting us or using the custom-order form: your message and the contact details provided
Data collected automatically:
- IP address - used at request time for security: sign-in attempt limiting and the anti-bot check. Within our application it is retained, among other places, in the newsletter consent record and the admin action audit log. It is not stored in our traffic statistics.
- Traffic measurement, on our own server, without cookies: for each page view we keep the path (never anything after the question mark), the two-letter country code from Cloudflare, the referring domain only, a coarse browser and device category, and the campaign label from the link. The visitor is pseudonymised with SHA-256 over a secret key that rotates every 24 hours, so yesterday's codes cannot be linked to today's. The pseudonym is deleted after 48 hours, raw rows normally after 7 days (up to 21 days if aggregation is delayed), and beyond that only daily totals remain, with no identifier at all. These internal statistics are separate from Google tools and advertising pixels that start after consent. See the Cookie Policy.
- Anti-bot check (Cloudflare Turnstile) - on sign-in, registration, newsletter sign-up, the custom-order form, gift-card purchase and checkout. Cloudflare receives your IP address and browser signals in order to decide whether the request comes from a human. We get no identifier about you back.
- Newsletter opens and clicks - campaign emails contain an invisible 1x1 pixel image and links that pass through a redirect of ours. That is how we see, per recipient, whether the message was opened and which link was clicked. This applies only to marketing emails, never to order or account messages. You can stop this processing entirely by unsubscribing, with a single click from any email we send.
- Admin audit log - what each member of our team changed in the admin panel (an order, a product, a return), together with the IP address they acted from. It does not record visitor browsing on the site.
OpenAI Ads: only after marketing consent, the OpenAI pixel measures visits, product views, cart additions, checkout starts and completed orders (RON value and a deduplication identifier). It may store attribution identifiers in first-party cookies, including __oppref. OpenAI may match events using contact details hashed in the browser. Events opt out of future user-level personalization. Withdrawing consent stops the pixel. OpenAI privacy policy.
3. Purposes and legal basis for processing
Contract performance (processing and delivering orders)Art. 6(1)(b) GDPR - necessity of contract
Invoicing and accounting obligationsArt. 6(1)(c) GDPR - legal obligation
Authentication and account securityArt. 6(1)(f) GDPR - legitimate interest
Anti-bot and anti-fraud protection (Cloudflare Turnstile, request rate limiting)Art. 6(1)(f) GDPR - legitimate interest
Traffic measurement on our own server (aggregate, pseudonymised, no cookies, no profiling)Art. 6(1)(f) GDPR - legitimate interest
Admin action audit logArt. 6(1)(f) GDPR - legitimate interest
Stock alerts (if subscribed)Art. 6(1)(a) GDPR - consent
Newsletter and marketing communications (if subscribed)Art. 6(1)(a) GDPR - consent
Measuring newsletter opens and clicks, per recipientArt. 6(1)(a) GDPR - consent (the same one as the subscription, withdrawn by unsubscribing)
Campaign attribution via the dl_attr cookieArt. 6(1)(a) GDPR - consent
Google Analytics and Google Ads, Meta, TikTok and OpenAI tools (statistics and advertising measurement)Art. 6(1)(a) GDPR - consent, withdrawable at any time via "Cookie settings"
Review managementArt. 6(1)(f) GDPR - legitimate interest
4. Data retention periods
- Accounting and supporting records: the general period is 5 years starting on 1 July of the year following the financial year in which they were prepared (Art. 25 of Law 82/1991). Other order data is retained as needed for contract performance, guarantees and legal claims; longer retention requires a specific obligation or ongoing dispute
- Account data: for the lifetime of the account. On an erasure request it is deleted or anonymised immediately, not after a waiting period (see section 6)
- Cart saved on the server: 60 days from the last change
- Automated email send log: 365 days
- Internal admin notifications: 90 days once read, 180 days in any case
- Back-in-stock alert requests: 180 days
- Admin audit log: kept as a record of who changed what, but the IP address in it is deleted after 365 days
- Traffic telemetry: the pseudonym is deleted after 48 hours, raw rows normally after 7 days (up to 21 days if aggregation is delayed); only daily totals with no identifiers remain
- Newsletter consent proof: for as long as you are subscribed and afterwards, as proof of consent (Art. 7(1) GDPR); deleted on an erasure request
- Per-recipient campaign statistics (sent, opened, clicked, unsubscribed): for as long as we keep the campaign; deleted on an erasure request
- Newsletter subscriptions: until unsubscription
5. Who we share data with
We do not sell or rent your data. We share it only with partners necessary to provide services:
- Supabase - database and authentication. Our project runs in the
eu-central-1 region (Frankfurt, Germany), so the data is hosted in the European Union. The provider is a US company, so support access from outside the EEA remains possible and is covered by EU Standard Contractual Clauses. - Stripe - card payment processing. Card details never reach our servers: they are entered directly into a form hosted by Stripe. The group has entities in both the EU and the US, and transfers outside the EEA are made under EU Standard Contractual Clauses.
- Sameday Courier (Romania) - order delivery. It receives your name, phone and delivery address or the easybox you selected, plus your email address (that is where the easybox pickup code is sent).
- Microsoft (Microsoft 365 / Graph) - sending transactional emails and the newsletter.
- Oblio (Romania) - issuing and archiving fiscal invoices.
- Cloudflare - CDN, security, the Turnstile anti-bot check and Cloudflare R2, where we store images: product photos, review photos (public) and the photos you upload with a return request (in a private bucket, with no public access).
- Hosting provider (VPS, EU) - server infrastructure.
- Meta Platforms Ireland Ltd and TikTok Technology Limited (Ireland) - only if you pressed "Accept all" in the cookie banner. Their ad-measurement pixels receive: standard shop events (page viewed, product viewed, add to cart, order placed with its value) together with their own cookie identifiers; the content of the pages you visit and your interactions with them (clicks, time spent, page performance), for ad-quality measurement; and, in hashed form (pseudonymised, not anonymous data), the contact details you type into the site's forms - email, phone, name, address - to match orders to your account on that platform ("Advanced Matching"). The platforms never receive this data in clear text. The legal basis is your consent, Art. 6(1)(a) GDPR, which you can withdraw at any time via "Cookie settings" (in the footer of every page). For the collection and transmission of data through the Meta pixel we act as joint controllers with Meta, per the Fashion ID case law; for their subsequent processing each platform is an independent controller under its own policy. Both companies may transfer data outside the EEA (including to the US), under the EU-US Data Privacy Framework or Standard Contractual Clauses.
Google and OpenAI: Google Ireland Limited (Analytics and Ads; Google privacy policy) and OpenAI Ireland Limited for EEA services (OpenAI privacy policy) receive the measurement data described above only after consent to optional tools. Depending on the service and settings, providers may process identifiers, technical signals, visited pages and purchase events. A hashed email remains personal data. Placing an order does not constitute advertising consent.
Other recipients and safeguards: strictly necessary data may be shared with accountants, legal advisers, authorities or courts for legal obligations and legal claims. For provider access outside the EEA we use the mechanism applicable to the service: an adequacy decision, including DPF only for certified entities and covered transfers, or standard contractual clauses and supplementary safeguards where needed. You may request information and a copy of relevant safeguards through our contact address, with confidential information protected.
Required data and requests: mandatory checkout data is needed for the contract or invoicing; without it we cannot process the order. Marketing is optional. We may request only proportionate evidence needed to verify a requester’s identity. You can object to direct marketing unconditionally. You may request human review of an automated security or payment-eligibility restriction by contacting us.
6. Your rights (GDPR)
Under the GDPR, you have the following rights:
- Right of access - to request a copy of the data we hold about you
- Right to rectification - to correct inaccurate data
- Right to erasure - to request deletion of your data (subject to legal obligations)
- Right to restrict processing — under Art. 18 GDPR
- Right to data portability - to receive your data in a structured format
- Right to object - to processing based on legitimate interest
- Right to withdraw consent - at any time, without affecting the lawfulness of prior processing
Account holders can download their data and delete their account directly from Account → Profile. If you ordered as a guest, send your request to office@drafted-lab.com. We respond to any request within one month of receipt; for complex requests we may extend by two further months, explaining the reasons within the first month (Art. 12(3) GDPR). You can unsubscribe from the newsletter at any time with a single click from any email we send.
Account deletion and statutory exceptions. The deletion feature removes or anonymises operational account data. We retain records required by law and data strictly needed to establish, exercise or defend legal claims, with restricted access and no reuse for marketing. Erasure does not cancel contracts, guarantees or accounting obligations. Backups are removed through their retention cycle; deletion from every copy is not instantaneous.
You also have the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP): www.dataprotection.ro
7. Data security
We implement appropriate technical and organisational measures to protect data: TLS encryption in transit, encryption at rest, restricted access, mandatory two-factor authentication for our team, audit logging and periodic security reviews. Sensitive documents (courier labels, return photos) are kept in a separate bucket with no public access and are served only through an authenticated endpoint.
8. International transfers
The data sits mainly in the European Union: the database is hosted in Frankfurt, the application server is in the EU, and invoicing and delivery are handled by Romanian providers. Some providers are, however, US companies (Cloudflare, Supabase, Stripe), so access from outside the European Economic Area cannot be ruled out. Those transfers are made on the basis of Standard Contractual Clauses approved by the European Commission or other adequate transfer mechanisms.
9. Cookies
For details about the cookies we use and about cookieless traffic measurement, please see our Cookie Policy.
10. Changes to this policy
We publish changes with their update date and highlight material changes on the site or through an appropriate channel before the new processing begins. Corrections and legally required changes may apply immediately. We do not extend consent retrospectively: new purposes requiring consent need a separate choice.