Draft for administrator review โ€” this text is not approved and must not be treated as final legal advice.

Privacy policy

Version 1 ยท DRAFT

Who is responsible

GirlsCodeToo is the Swiss NGO responsible for this store. Its formal legal name, postal address and privacy contact must be completed and verified by an administrator before this draft can be approved.

Questions about personal data or requests to exercise privacy rights may be sent through the contact channel published on girlscodetoo.ch until a dedicated store privacy address is configured.

Data, purposes and legal grounds

We process an email address, preferred language, passwordless sign-in challenges and session records to create and secure customer accounts. We process cart, delivery, order and payment references to perform a purchase, prevent misuse and provide support.

Newsletter participation is optional and independent from account creation and checkout. We record each grant or withdrawal with the policy version and source so that the choice can be demonstrated without making marketing a condition of service.

Store administrators sign in through Microsoft Entra. We process their organisation identity, group membership, sessions and audited actions to restrict administration to the dedicated store-admin group and protect the store.

Recipients and international processing

Stripe receives the data required to process payment and prevent fraud. Printify receives the order and delivery data required to produce and ship made-to-order items. Email and infrastructure providers receive only the information required for their services.

Product pages can include store-hosted images and direct video. YouTube or Vimeo receives device and network information only after the visitor explicitly chooses to load an embedded video; the preference is kept in a first-party cookie.

Providers may process data outside Switzerland or the European Union. Before approval, GirlsCodeToo must verify the relevant contracts, safeguards, provider locations and current subprocessor information.

Retention, deletion and rights

Account and operational data is kept only as long as needed for the stated purposes. Order, payment and accounting records may be retained for legally required periods even after an account deletion request; other profile data is deleted or pseudonymised when appropriate.

Depending on applicable law, people may request access, correction, deletion, restriction, portability or objection, and may complain to a competent supervisory authority. Identity may need to be verified before a request is completed.