Privacy Policy
Privacy Policy
Last updated: January 2026
Your privacy matters to us. This policy explains what personal data we collect, why we collect it, how we use it, and what rights you have. We've tried to keep it clear and jargon-free.
Who We Are
PouchSpot is operated by:
Munken OÜ
Registration number: 17304112
Ahtri tn 12, Kesklinna linnaosa
Tallinn, Harju maakond, 15551
Estonia
VAT number: EE102891052
Email: contact@pouchspot.com
For the purposes of data protection law, Munken OÜ is the data controller responsible for your personal data.
What Data We Collect
Information you provide directly
- Account information: Name, email address, password (encrypted)
- Order information: Billing address, shipping address, phone number
- Payment information: Payment method details (processed securely by our payment providers — we do not store full card numbers)
- Communications: Messages you send us via email or contact forms
- Preferences: Product preferences, quiz responses, subscription settings
- Age verification: Confirmation that you are 18 years or older
Information collected automatically
- Device information: IP address, browser type, operating system, device type
- Usage information: Pages visited, time spent on site, links clicked, products viewed
- Location information: Country and region (derived from IP address)
- Cookies and similar technologies: See our Cookies section below
Information from third parties
- Payment providers: Transaction confirmation and fraud prevention data
- Shipping carriers: Delivery status and confirmation
- Analytics services: Aggregated website usage data
Why We Collect Your Data
We only collect data when we have a valid legal basis under GDPR. Here's what we use and why:
| Purpose | Data used | Legal basis |
|---|---|---|
| Processing your orders | Name, address, email, payment details | Contract performance |
| Delivering your products | Name, shipping address, phone | Contract performance |
| Managing your account | Email, password, preferences | Contract performance |
| Managing subscriptions | Payment details, product preferences, delivery schedule | Contract performance |
| Sending order updates | Email, phone | Contract performance |
| Age verification | Date of birth or age confirmation | Legal obligation |
| Responding to enquiries | Name, email, message content | Legitimate interest |
| Sending marketing emails | Email, name, purchase history | Consent |
| Improving our website | Usage data, device info | Legitimate interest |
| Preventing fraud | IP address, payment data, order patterns | Legitimate interest |
| Legal compliance | Transaction records, communications | Legal obligation |
Who We Share Your Data With
We never sell your personal data. We only share it with trusted partners who help us run our business:
Service providers
- Payment processors: To process your payments securely (e.g., Stripe, PayPal, Klarna)
- Shipping carriers: To deliver your orders (e.g., DHL)
- Email service providers: To send transactional and marketing emails
- Hosting providers: To host our website and store data securely
- Analytics providers: To understand how our website is used
- Customer support tools: To manage and respond to your enquiries
Legal requirements
We may disclose your data if required by law, regulation, legal process, or government request. We may also disclose data to protect our rights, privacy, safety, or property.
Business transfers
If we sell, merge, or transfer our business, your data may be transferred to the new owner. We will notify you before your data becomes subject to a different privacy policy.
International Transfers
We are based in Estonia (EU). Your data is primarily stored and processed within the European Economic Area (EEA).
Some of our service providers may process data outside the EEA. When this happens, we ensure appropriate safeguards are in place, such as:
- EU Standard Contractual Clauses
- Adequacy decisions by the European Commission
- Other approved transfer mechanisms under GDPR
How Long We Keep Your Data
We retain your data only as long as necessary for the purposes described in this policy:
| Data type | Retention period |
|---|---|
| Account information | Until you delete your account, plus 30 days |
| Order history | 7 years (for tax and legal compliance) |
| Payment records | 7 years (for tax and legal compliance) |
| Marketing preferences | Until you unsubscribe or withdraw consent |
| Customer support messages | 3 years from last contact |
| Website analytics | 26 months (aggregated and anonymised) |
Cookies
We use cookies and similar technologies to make our website work, remember your preferences, and understand how you use our site.
Essential cookies
Required for the website to function. They enable core features like shopping cart, checkout, and account access. You cannot opt out of these.
Analytics cookies
Help us understand how visitors use our website. We use this data to improve our site and your experience. These are only set with your consent.
Marketing cookies
Used to deliver relevant advertisements and track campaign performance. These are only set with your consent.
Managing cookies
When you first visit our website, you'll see a cookie banner where you can accept or decline non-essential cookies. You can change your preferences at any time through our cookie settings or your browser settings.
Your Rights
Under GDPR, you have the following rights regarding your personal data:
Right to access
You can request a copy of the personal data we hold about you.
Right to rectification
You can ask us to correct inaccurate or incomplete data.
Right to erasure
You can ask us to delete your personal data in certain circumstances (e.g., if it's no longer needed for its original purpose).
Right to restrict processing
You can ask us to limit how we use your data in certain circumstances.
Right to data portability
You can request your data in a structured, machine-readable format to transfer to another service.
Right to object
You can object to processing based on legitimate interests, including profiling and direct marketing.
Right to withdraw consent
Where we process data based on your consent, you can withdraw that consent at any time.
How to exercise your rights
To exercise any of these rights, contact us at contact@pouchspot.com. We will respond within 30 days. We may ask you to verify your identity before processing your request.
Right to complain
If you're not satisfied with how we handle your data, you have the right to lodge a complaint with a supervisory authority. In Estonia, this is the Data Protection Inspectorate (Andmekaitse Inspektsioon):
Website: www.aki.ee
Email: info@aki.ee
Data Security
We take the security of your data seriously and implement appropriate technical and organisational measures to protect it, including:
- SSL/TLS encryption for all data transmitted to and from our website
- Encrypted storage of sensitive data
- Access controls limiting who can access your data
- Regular security assessments and updates
- Secure payment processing through PCI-compliant providers
No system is 100% secure. If you believe your data has been compromised, please contact us immediately.
Marketing Communications
We will only send you marketing emails if you have opted in. You can unsubscribe at any time by:
- Clicking "Unsubscribe" at the bottom of any marketing email
- Updating your preferences in your account settings
- Contacting us at contact@pouchspot.com
Even if you unsubscribe from marketing, we will still send you transactional emails related to your orders and account (e.g., order confirmations, shipping updates, subscription reminders).
Children's Privacy
Our website and products are intended for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe we have collected data from a minor, please contact us immediately and we will delete it.
Third-Party Links
Our website may contain links to third-party websites. We are not responsible for the privacy practices of those websites. We encourage you to read their privacy policies before providing any personal data.
Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. For significant changes, we may notify you by email.
We encourage you to review this policy periodically to stay informed about how we protect your data.
Contact Us
If you have any questions about this Privacy Policy or how we handle your data, please contact us:
Munken OÜ
Ahtri tn 12, Kesklinna linnaosa
Tallinn, Harju maakond, 15551
Estonia
Email: contact@pouchspot.com
We aim to respond to all enquiries within 7 business days.