This privacy policy describes how Dotty. (data controller) collects, uses, and protects your personal data in accordance with the General Data Protection Regulation (GDPR).
Dotty. is the data controller for the processing of personal data described in this privacy policy. Contact us at hei@dotty.no for privacy questions.
We process your personal data based on the following legal grounds:
We share your data with the following third parties who process data on our behalf:
| Service | Purpose | Location |
|---|---|---|
| Stripe | Payment processing | EU/USA (EU-US DPF) |
| Supabase | Database and authentication | EU (Frankfurt) |
| Resend | Email services | USA (EU-US DPF) |
| Vercel | Web hosting | EU/Global CDN |
| Shipping companies | Delivery of goods | Norway |
All data processors have signed a Data Processing Agreement (DPA) with us.
We retain your personal data as long as necessary for the purpose for which it was collected:
| Data type | Retention period |
|---|---|
| Order data | 7 years (legal accounting requirement) |
| Newsletter | Until you unsubscribe |
| Contact messages | 2 years |
| Shopping cart | 15 minutes (temporary) |
All payment information is handled securely by our payment partners (Stripe and Vipps). We never store card information or other sensitive payment data on our servers. Stripe is PCI DSS certified.
We use double opt-in for newsletter subscriptions. You must confirm your subscription via email before receiving newsletters. You can unsubscribe at any time via the unsubscribe link in emails or on the "My Data" page.
We only use essential cookies:
| Name | Purpose | Duration |
|---|---|---|
| Authentication | Keep you logged in | Session |
| Shopping cart | Store shopping cart | Permanent |
| Consent | Remember your cookie choice | Permanent |
We do not use any tracking, analytics, or marketing cookies.
Under GDPR, you have the following rights:
Use the "My Data" page to exercise your rights, or contact us at hei@dotty.no.
If you believe we are not handling your personal data correctly, you have the right to complain to the supervisory authority:
Datatilsynet (Norwegian DPA)
Postboks 458 Sentrum, 0105 Oslo
We take data security seriously. All data is transferred via HTTPS, stored encrypted, and we use row-level security (RLS) to protect your data.
We may update this privacy policy as needed. For significant changes, we will notify you via email or the website.
Last updated: January 2026
Manage your data →