DONT CARE SO MUCH AND DONT TRY AS HARD

Privacy Policy

Last Updated: November 18, 2025

1. Introduction

This Privacy Policy explains how OWNOVR (“we”, “our”, or “us”) collects, uses, shares, and protects your personal data when you use our website ownovr.com and purchase our vintage clothing products.

We are committed to protecting your privacy and complying with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and Czech Act No. 110/2019 Coll. on Personal Data Processing.

Data Controller:

  • Business Name: Ilya Makarov
  • Legal Form: Foreign Natural Person (Zahraniční fyzická osoba)
  • Registered Address: Puklicova 930/43, České Budějovice 3, 370 04 České Budějovice, Czech Republic
  • Company ID (IČO): 22534628
  • Tax Authority: Finanční úřad v Českých Budějovicích
  • Email: privacy@ownovr.com
  • Website: https://ownovr.com
  • Date of Establishment: January 29, 2025

2. Personal Data We Collect

We collect and process the following categories of personal data:

2.1 Information You Provide Directly

Account Registration:

  • Full name
  • Email address
  • Password (encrypted)
  • Phone number

Purchase Information:

  • Billing address
  • Shipping address
  • Payment details (processed securely by our payment processor)
  • Order history
  • Product preferences

Communication Data:

  • Customer service inquiries
  • Newsletter subscriptions
  • Product reviews and ratings
  • Survey responses

2.2 Information Collected Automatically

Technical Data:

  • IP address
  • Browser type and version
  • Device type and operating system
  • Time zone settings
  • Location data (country/city level)
  • Cookie identifiers

Usage Data:

  • Pages visited on our website
  • Products viewed
  • Search queries
  • Time spent on pages
  • Referring/exit pages
  • Clickstream data

2.3 Information from Third Parties

  • Payment verification data from payment processors
  • Delivery confirmation from shipping providers
  • Social media profile information (if you connect your social media account)

3. Legal Basis and Purpose of Processing

We process your personal data based on the following legal grounds under GDPR Article 6:

3.1 Contract Performance (Article 6(1)(b))

Purpose: To fulfill our contractual obligations when you place an order

  • Processing and fulfilling your orders
  • Delivering products to your address
  • Managing payments and refunds
  • Providing customer service
  • Handling returns and exchanges

What happens if you don’t provide this data: We cannot process or deliver your order without necessary information such as shipping address and payment details.

3.2 Legal Obligation (Article 6(1)(c))

Purpose: To comply with legal requirements

  • Maintaining accounting records (7 years retention as required by Czech law)
  • VAT and tax reporting
  • Handling consumer complaints as required by Czech Civil Code
  • Responding to lawful requests from authorities

3.3 Legitimate Interests (Article 6(1)(f))

Purpose: To operate and improve our business

  • Fraud prevention and security
  • Website analytics and performance optimization
  • Product recommendations based on browsing history
  • Internal business intelligence and market research
  • Protecting our legal rights

Our legitimate interest: Ensuring secure transactions, improving customer experience, and operating a sustainable business. These interests are balanced against your privacy rights, and you can object to this processing at any time.

3.4 Consent (Article 6(1)(a))

Purpose: Optional marketing and enhanced features

  • Sending marketing emails and newsletters
  • Personalized advertising
  • Non-essential cookies for analytics and marketing
  • Social media integration

Your right to withdraw: You can withdraw your consent at any time by clicking the unsubscribe link in emails, adjusting cookie preferences, or contacting us at privacy@ownovr.com.

4. How We Use Your Personal Data

We use your personal data for the following purposes:

Essential Operations:

  • Process and deliver your orders
  • Manage your account
  • Process payments and prevent fraud
  • Provide customer support
  • Send transactional emails (order confirmations, shipping updates)

Business Improvements:

  • Analyze website usage to improve functionality
  • Understand customer preferences
  • Develop new products and services
  • Conduct market research

Marketing (with your consent):

  • Send promotional emails about new products and special offers
  • Display personalized advertisements
  • Recommend products based on your browsing history

Legal Compliance:

  • Fulfill tax and accounting obligations
  • Comply with consumer protection laws
  • Respond to legal requests and prevent illegal activities

5. Cookies and Tracking Technologies

We use cookies and similar technologies to enhance your browsing experience. Under the ePrivacy Directive and GDPR, we require your explicit consent before placing non-essential cookies.

5.1 Types of Cookies We Use

Strictly Necessary Cookies (No consent required)

  • Session management
  • Shopping cart functionality
  • Security and fraud prevention
  • Load balancing

Functional Cookies (Consent required)

  • Remember your preferences
  • Language selection
  • Currency selection

Analytics Cookies (Consent required)

  • Google Analytics (anonymized IP)
  • Website usage statistics
  • Performance monitoring

Marketing Cookies (Consent required)

  • Facebook Pixel
  • Google Ads
  • Retargeting and personalized advertising

5.2 Managing Cookies

You can manage your cookie preferences at any time through our cookie consent banner or by clicking [Cookie Settings] at the bottom of our website. You can also configure your browser to refuse all cookies, but this may limit website functionality.

Browser Cookie Settings:

  • Chrome: Settings > Privacy and Security > Cookies
  • Firefox: Settings > Privacy & Security > Cookies
  • Safari: Preferences > Privacy > Cookies
  • Edge: Settings > Privacy > Cookies

5.3 Cookie Duration

  • Session cookies: Deleted when you close your browser
  • Persistent cookies: Remain for the duration specified (typically up to 13 months).

You can view detailed information about specific cookies we use in our [Cookie Policy].

6. Sharing Your Personal Data

We share your personal data only when necessary and with appropriate safeguards:

6.1 Service Providers (Data Processors)

We work with trusted third-party service providers who process data on our behalf:

Payment Processing:

  • Stripe / PayPal (payment gateway)
  • Purpose: Secure payment processing
  • Location: EU/EEA with appropriate safeguards
  • Data shared: Payment card details, transaction amount, billing address

Shipping and Delivery:

  • Packeta, Czech Post
  • Purpose: Product delivery
  • Location: Czech Republic / EU
  • Data shared: Name, shipping address, phone number, order details

Email Services:

  • Mailchimp / SendGrid
  • Purpose: Transactional and marketing emails
  • Location: EU/US with Standard Contractual Clauses
  • Data shared: Email address, name, order history

Website Hosting:

  • zomro.com
  • Purpose: Website infrastructure
  • Location: EU
  • Data shared: All website data

Analytics:

  • Google Analytics (anonymized)
  • Purpose: Website usage analysis
  • Location: US with Standard Contractual Clauses
  • Data shared: Anonymized browsing data

Customer Support:

  • Zendesk / Intercom
  • Purpose: Customer service management
  • Location: EU/US with appropriate safeguards
  • Data shared: Contact information, order details, communication history

All data processors are bound by Data Processing Agreements (DPAs) that ensure GDPR compliance.

6.2 Legal Requirements

We may disclose your personal data if required by law or in response to:

  • Court orders or legal processes
  • Requests from law enforcement or regulatory authorities
  • Protection of our legal rights or safety of others
  • Investigation of fraud or illegal activities

6.3 Business Transfers

In the event of a merger, acquisition, or sale of our business, your personal data may be transferred to the new owner. We will notify you via email and website notice before such transfer occurs.

6.4 No Sale of Personal Data

We do not sell, rent, or trade your personal data to third parties for their marketing purposes.

7. International Data Transfers

Some of our service providers are located outside the European Economic Area (EEA). When we transfer your data internationally, we ensure appropriate safeguards are in place:

7.1 Transfer Mechanisms

Standard Contractual Clauses (SCCs): For transfers to countries without adequacy decisions (e.g., United States), we use European Commission-approved Standard Contractual Clauses as approved in Commission Implementing Decision (EU) 2021/914.

Adequacy Decisions: We may transfer data to countries recognized by the European Commission as providing adequate data protection (e.g., UK, Switzerland, Japan).

EU-US Data Privacy Framework: For US-based service providers certified under the EU-US Data Privacy Framework, we rely on this framework for lawful data transfers.

7.2 Your Rights

You have the right to obtain information about the safeguards we use for international transfers by contacting privacy@ownovr.com.

8. Data Retention

We retain your personal data only as long as necessary for the purposes outlined in this Privacy Policy:

Account Data:

  • Active accounts: Until you request deletion
  • Inactive accounts: 3 years after last login, then deleted

Order Data:

  • Transactional records: 7 years (Czech accounting law requirement)
  • Order history in your account: Until account deletion
  • Payment details: Not stored (handled by payment processor)

Marketing Data:

  • Newsletter subscribers: Until you unsubscribe
  • Marketing cookies: As specified in cookie settings (typically up to 13 months).

Communication Data:

  • Customer service inquiries: 3 years
  • Product reviews: Until you request deletion or account closure

Legal Claims:

  • Data necessary for legal claims: Until the expiration of applicable limitation periods

Anonymized Data: We may retain anonymized data (that cannot identify you) indefinitely for statistical and analytical purposes.

After the retention period expires, we securely delete or anonymize your personal data.

9. Your Rights Under GDPR

As a data subject in the EU, you have the following rights:

9.1 Right of Access (Article 15)

You can request a copy of the personal data we hold about you. We will provide this free of charge in a commonly used electronic format within one month.

How to exercise: Email privacy@ownovr.com with subject “Data Access Request”

9.2 Right to Rectification (Article 16)

You can request correction of inaccurate or incomplete personal data.

How to exercise: Log into your account and update your information, or contact us at privacy@ownovr.com

9.3 Right to Erasure / “Right to be Forgotten” (Article 17)

You can request deletion of your personal data when:

  • The data is no longer necessary for its original purpose
  • You withdraw consent (where consent was the legal basis)
  • You object to processing based on legitimate interests
  • The data was unlawfully processed
  • Legal obligations require erasure

Limitations: We may retain data if required by law (e.g., accounting records) or for establishing legal claims.

How to exercise: Email privacy@ownovr.com with subject “Data Deletion Request”

9.4 Right to Restriction of Processing (Article 18)

You can request that we limit how we use your data when:

  • You contest the accuracy of the data
  • The processing is unlawful but you don’t want erasure
  • We no longer need the data, but you need it for legal claims
  • You have objected to processing pending verification

How to exercise: Email privacy@ownovr.com with subject “Restriction Request”

9.5 Right to Data Portability (Article 20)

You can receive your personal data in a structured, commonly used, machine-readable format (e.g., CSV, JSON) and transmit it to another controller.

Applies to: Data processed based on consent or contract performance, and processed by automated means.

How to exercise: Email privacy@ownovr.com with subject “Data Portability Request”

9.6 Right to Object (Article 21)

You can object to processing based on legitimate interests or for direct marketing purposes.

Direct marketing: You can opt out at any time by clicking unsubscribe in emails or adjusting account settings.

Legitimate interests: We will stop processing unless we demonstrate compelling legitimate grounds that override your interests.

How to exercise: Email privacy@ownovr.com with subject “Objection to Processing”

9.7 Rights Related to Automated Decision-Making (Article 22)

You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects or similarly significant effects.

Our practices: We do not engage in fully automated decision-making that significantly affects you. Product recommendations are based on automated algorithms, but these do not produce legal effects.

9.8 Right to Withdraw Consent

Where processing is based on consent, you can withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

How to exercise:

  • Marketing emails: Click unsubscribe link
  • Cookies: Adjust cookie preferences
  • Account settings: Update preferences in your account
  • Email: privacy@ownovr.com

9.9 Response Timeline

We will respond to your requests within one month. In complex cases, we may extend this by two additional months, and we will inform you of the delay.

10. Right to Lodge a Complaint

If you believe we have not handled your personal data properly, you have the right to lodge a complaint with the relevant supervisory authority:

Czech Republic – Úřad pro ochranu osobních údajů (ÚOOÚ)

  • Address: Pplk. Sochora 27, 170 00 Prague 7, Czech Republic
  • Phone: +420 234 665 111
  • Email: posta@uoou.cz
  • Website: https://www.uoou.cz

European Data Protection Board:

  • Website: https://edpb.europa.eu

You also have the right to lodge a complaint in the EU member state where you reside, work, or where the alleged infringement occurred.

11. Data Security

We implement appropriate technical and organizational measures to protect your personal data:

11.1 Technical Measures

  • Encryption: SSL/TLS encryption for data in transit (HTTPS)
  • Secure Storage: Encrypted databases and secure servers
  • Access Controls: Multi-factor authentication for admin accounts
  • Regular Security Audits: Quarterly security assessments
  • Vulnerability Scanning: Automated security monitoring
  • Firewalls and Intrusion Detection: Network-level security

11.2 Organizational Measures

  • Access Limitation: Only authorized personnel can access personal data
  • Data Processing Agreements: With all third-party processors
  • Employee Training: Regular privacy and security training
  • Incident Response Plan: Procedures for data breach management
  • Privacy by Design: Privacy considerations in all new processes

11.3 Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms:

  • We will notify the supervisory authority within 72 hours
  • We will notify affected individuals without undue delay
  • We will provide information about the breach, its impact, and remedial measures

12. Children’s Privacy

Our website and services are not directed to children under 15 years of age. We do not knowingly collect personal data from children under 15.

If you are under 15, you may only use our website with the involvement and consent of a parent or guardian.

If we become aware that we have collected personal data from a child under 15 without parental consent, we will take steps to delete that information promptly.

Parents or guardians who believe we may have collected information from a child under 15 should contact us at privacy@ownovr.com.

13. Third-Party Links

Our website may contain links to third-party websites, social media platforms, or services not operated by us (e.g., Instagram, Facebook, payment providers).

We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any personal data.

External links are provided for your convenience and do not signify our endorsement of the linked website or its content.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or business operations.

Notification of Changes:

  • We will post the updated policy on this page
  • The “Last Updated” date at the top will be revised
  • For material changes, we will notify you via email or prominent website notice
  • Continued use of our services after changes constitutes acceptance

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data.

15. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:

Contact Information: Email: privacy@ownovr.com

Phone: +420 735 820 720

Address: Puklicova 930/43, České Budějovice 3, 370 04 České Budějovice, Czech Republic

Response Time: We aim to respond to all inquiries within 5 business days.

Mailing Address for Written Requests: Ilya Makarov – Data Protection Puklicova 930/43, České Budějovice 3 370 04 České Budějovice Czech Republic

16. Special Provisions for Czech Consumers

In accordance with Czech law (Act No. 89/2012 Coll., the Civil Code, and Act No. 634/1992 Coll., on Consumer Protection):

16.1 Information Obligations

We fulfill our obligation to inform you about:

  • The identity and contact details of the data controller (Section 1)
  • The purposes and legal basis of data processing (Section 3)
  • Your rights under GDPR (Section 9)
  • Data retention periods (Section 8)
  • Recipients of personal data (Section 6)

16.2 Compliance with Czech Data Protection Authority

We process personal data in compliance with the regulations enforced by the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů – ÚOOÚ).

16.3 Language

This Privacy Policy is provided in English. A Czech language version (Zásady ochrany osobních údajů) is available upon request at privacy@ownovr.com.


Effective Date: November 18, 2025
Last Reviewed: November 18, 2025

Select your currency
EUR Euro