Privacy policy

 

This Privacy Policy governs the collection, storage, use, processing, and sharing of personal data that POKE STUDIO d.o.o. collects from you when you use the website https://www.bespokehome.eu (hereinafter referred to as the "website") or make a purchase on it. A "user" is any legal or natural person who uses or visits the aforementioned website. The personal data controller is POKE STUDIO d.o.o., located at Vilharjeva cesta 42, 1000 Ljubljana, company ID 8124850000.

In addition to this Privacy Policy, please also familiarize yourself with the General Terms of Use of the website, which govern access and conditions of use of the website.

1. Personal Data We Collect
A personal data is any information that identifies you as a specific or identifiable individual.
If you visit our website without registration for better functionality, user experience, and security, we automatically collect certain information about your device, including data about your web browser, IP address, time zone, and some cookies installed on your device. Additionally, as you browse the website, we collect information about individual web pages or products you view, websites or search terms that referred you to our website, and how you interact with the website. We refer to this automatically-collected information as "Device Information".

Device Information is collected using the following technologies:

"Cookies" are data files placed on your device or computer and often include an anonymous unique identifier. For more information about cookies, and how to disable them, visit http://www.allaboutcookies.org.
"Log files" track actions occurring on the website and collect data including your IP address, browser type, Internet service provider, referring/exit pages, and date/time stamps.
"Web beacons," "tags," and "pixels" are electronic files used to record information about how you browse the site.

Strictly Required Cookies
Name Description Category Provider Duration
_orig_referrer This cookie is generally provided by Shopify and is used to track landing pages. Strictly Required Cookies Shopify 2 weeks
_landing_page This cookie is generally provided by Shopify and is used to track landing pages. Strictly Required Cookies Shopify 2 weeks
_ab This cookie is generally provided by Shopify and is used in connection with access to the admin view of an online store platform. Strictly Required Cookies Shopify 2 weeks
_secure_session_id This cookie is generally provided by Shopify and is used to track a user's session through the multi-step checkout process and keep their order, payment and shipping details connected. Strictly Required Cookies Shopify 1 day
cart This cookie is generally provided by Shopify and is used in connection with a shopping cart. Strictly Required Cookies Shopify 2 weeks
cart_sig This cookie is generally provided by Shopify and is used in connection with checkout. It is used to verify the integrity of the cart and to ensure performance of some cart operations. Strictly Required Cookies Shopify 2 weeks
cart_ts This cookie is generally provided by Shopify and is used in connection with checkout. Strictly Required Cookies Shopify 2 weeks
cart_ver This cookie is generally provided by Shopify and is used in connection with the shopping cart. Strictly Required Cookies Shopify 2 weeks
cart_currency This cookie is generally provided by Shopify and it is set after a checkout is completed to ensure that new carts are in the same currency as the last checkout. Strictly Required Cookies Shopify 2 weeks
checkout_token This cookie is generally provided by Shopify and is used in connection with a checkout service. Strictly Required Cookies Shopify 1 year
storefront_digest This cookie is generally provided by Shopify and it stores a digest of the storefront password, allowing merchants to preview their storefront while it's password protected. Strictly Required Cookies Shopify 2 years
cookieconsent_status This cookie is associated with the app Consentmo GDPR Compliance and is used for storing the customer's consent. Strictly Required Cookies GDPR/CCPA + Cookie management 1 year
cookieconsent_preferences_disabled This cookie is associated with the app Consentmo GDPR Compliance and is used for storing the customer's consent. Strictly Required Cookies GDPR/CCPA + Cookie management 1 day
_shopify_m This cookie is generally provided by Shopify and is used for managing customer privacy settings. Strictly Required Cookies Shopify 1 year
_shopify_tm This cookie is generally provided by Shopify and is used for managing customer privacy settings. Strictly Required Cookies Shopify 30 minutes
_shopify_tw This cookie is generally provided by Shopify and is used for managing customer privacy settings. Strictly Required Cookies Shopify 2 weeks
_tracking_consent This cookie is generally provided by Shopify and is used to store a user's preferences if a merchant has set up privacy rules in the visitor's region. Strictly Required Cookies Shopify 1 year
tracked_start_checkout This cookie is generally provided by Shopify and is used in connection with checkout. Strictly Required Cookies Shopify 1 year
Analytics and Statistics
Name Description Category Provider Duration
_s This cookie is associated with Shopify's analytics suite. Analytics and Statistics 30 minutes
_shopify_fs This cookie is associated with Shopify's analytics suite. Analytics and Statistics Shopify 30 minutes
_shopify_s This cookie is associated with Shopify's analytics suite. Analytics and Statistics Shopify 30 minutes
_shopify_sa_t This cookie is associated with Shopify's analytics suite concerning marketing and referrals. Analytics and Statistics Shopify 30 minutes
_shopify_sa_p This cookie is associated with Shopify's analytics suite concerning marketing and referrals. Analytics and Statistics Shopify 30 minutes
_shopify_y This cookie is associated with Shopify's analytics suite. Analytics and Statistics Shopify 1 year
_y This cookie is associated with Shopify's analytics suite. Analytics and Statistics 1 year
_ga This cookie name is associated with Google Universal Analytics Analytics and Statistics Google Analytics 2 years
_gat This cookie name is associated with Google Universal Analytics. Analytics and Statistics Google Analytics 1 minute
_s This cookie is associated with Shopify's analytics suite. Analytics and Statistics 30 minutes
Marketing and Retargeting
Name Description Category Provider Duration
IDE This domain is owned by Doubleclick (Google). The main business activity is: Doubleclick is Googles real time bidding advertising exchange Marketing and Retargeting Google DoubleClick 2 years
GPS This cookie is associated with YouTube which collects user data through videos embedded in websites, which is aggregated with profile data from other Google services in order to display targeted advertising to web visitors across a broad range of their own and other websites. Marketing and Retargeting Youtube 1 session
PREF This cookie, which may be set by Google or Doubleclick, may be used by advertising partners to build a profile of interests to show relevant ads on other sites. Marketing and Retargeting Youtube 8 months
BizoID This is a Microsoft MSN 1st party cookie to enable user-based content. Marketing and Retargeting LinkedIn 1 month
_fbp Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers. Marketing and Retargeting Meta Platforms, Inc. 3 months
__adroll This cookie is associated with AdRoll Marketing and Retargeting Adroll Group 1 year
__adroll_v4 This cookie is associated with AdRoll Marketing and Retargeting Adroll Group 1 year
__adroll_fpc This cookie is associated with AdRoll Marketing and Retargeting Adroll Group 1 year
__ar_v4 This cookie is associated with AdRoll Marketing and Retargeting Adroll Group 1 year
Functional Cookies
Name Description Category Provider Duration
_gid This cookie name is associated with Google Universal Analytics. Functional Cookies Google Analytics 1 day

In case of registration (or making a purchase as a "guest"), when you make a purchase or attempt to make a purchase through the website, or when you submit various inquiries, we collect additional specific data including:

Identity information: name and surname, email address, and a password, which is encrypted and known only to the user (remains hidden even from the data controller).
Contact information: billing address, shipping address, telephone number.
Financial information: payment details including credit card numbers and PayPal account information.
Purchase and payment details: we retain all data regarding your orders and payments, including details about transactions and returns.
All these details are referred to as "Order Information".

When we talk about “Personal Data” in this policy, we are referring both to Device Information and Order Information.

2. Purpose and Basis for Processing Personal Data
POKE studio d.o.o. collects and processes your personal data based on individual consent and legitimate interest. All personal data provided by you will be treated confidentially and used solely for the purpose for which they were transmitted and collected.
Order Information we collect is generally used to fulfill any orders placed through the website (including processing your payment details, arranging for shipping, and providing you with invoices and/or order confirmations). Additionally, we use this Order Information to:

Comply with legal obligations (maintaining financial and business records)
Communicate with you
Screen our orders for potential risk or fraud
In line with preferences you have shared with us, provide you with information or advertising relating to our products or services.
Device Information that we collect helps us to screen for potential risk and fraud (particularly, your IP address) and generally to improve and optimize our website (for example, by generating analytics about how our customers browse and interact with the site, and to assess the success of our marketing and advertising campaigns).

3. Users of Personal Data
POKE studio d.o.o. will not share your personal data with unauthorized third parties without your consent. In addition to us, your personal data may also be used by our trusted partners necessary for order fulfillment, in compliance with the applicable Personal Data Protection Law and the European Regulation on Data Protection. We share your personal data with:
Delivery services that require data for transporting and delivering the order;
Suppliers needing data for preparing shipments with your delivery address and order content;
Suppliers and authorized service providers, if claims are managed through us;
Payment processors;
With your consent, we occasionally share your data through cookies with advertising and social networks.
For our online store operations, we use Shopify - you can read more about how Shopify uses your Personal Data here: https://www.shopify.com/legal/privacy. We also use Google Analytics to help us understand how our customers use the site - you can read more about how Google uses your personal information here: https://www.google.com/intl/en/policies/privacy/. You can opt-out of Google Analytics here: https://tools.google.com/dlpage/gaoptout.

We may also share your Personal Data to comply with applicable laws and regulations, to respond to a subpoena, search warrant or other lawful requests for information we receive, or to otherwise protect our rights.

Your data will never be shared with unauthorized third parties.

As described above, we use your Personal Data to provide you with targeted advertisements or marketing communications we believe may be of interest to you. For more information on how targeted advertising works, you can visit the educational page of the Network Advertising Initiative ("NAI") at http://www.networkadvertising.org/understanding-online-advertising/how-does-it-work.

You can opt out of targeted advertising by using the following links:

FACEBOOK: https://www.facebook.com/settings/?tab=ads
GOOGLE: https://www.google.com/settings/ads/anonymous
Additionally, you can opt out of some of these services by visiting the Digital Advertising Alliance’s opt-out portal at: http://optout.aboutads.info/.

Please note that we do not alter our site’s data collection and use practices when we see a Do Not Track signal from your browser.

4. Rights of the Individual Regarding Data Processing
Under the provisions of the General EU Data Protection Regulation, as an individual, you have the following rights:

  • Right to withdraw consent: If you have consented to the processing of your personal data, you have the right to withdraw that consent at any time. The withdrawal of consent can be done with a written statement sent to the controller via one of the contacts listed on the website. The withdrawal has no negative consequences or penalties for the individual. However, it is possible that the controller may no longer be able to offer certain or all of its services to the individual if they involve services that cannot be provided without personal data.
  • Right of access to personal data: As an individual, you have the right from the controller of personal data to obtain confirmation whether personal data concerning you is being processed and, where that is the case, access to the personal data and certain information (about the purposes of processing, the categories of personal data, the users, the retention periods or criteria for determining the periods, the existence of the right to rectification or erasure of data, the right to restriction of processing and to object to processing, the right to lodge a complaint with a supervisory authority, the source of the data if not collected from you, the existence of automated decision-making, including profiling, the reasons for it, and the significance and consequences of such processing for you, and other information in accordance with Article 15 of the General EU Data Protection Regulation).
  • Right to rectification of personal data: As an individual, you have the right to have the provider rectify inaccurate personal data concerning you without undue delay. As an individual, taking into account the purposes of the processing, you have the right to have incomplete data completed, including by means of providing a supplementary statement.
    Right to erasure of personal data: As an individual, you have the right to have the provider erase personal data concerning you without undue delay, and the provider is obligated to erase the data without undue delay where one of the following grounds applies:
    • the data is no longer necessary for the purposes for which they were collected or otherwise processed;
    • if you withdraw consent and there is no other legal ground for processing;
    • if you object to the processing and there are no overriding legitimate grounds for the processing;
    • the data has been unlawfully processed;
    • the data has to be erased for compliance with a legal obligation in Union or Member State law to which the provider is subject;
    • the data has been collected in relation to the offer of information society services.

However, as an individual, you do not have the right to erasure in certain cases described in the third paragraph of Article 17 of the General EU Data Protection Regulation.

  • Right to restriction of processing: As an individual, you have the right to obtain from the provider restriction of processing where one of the following applies:
    • if you contest the accuracy of the data for a period enabling the provider to verify the accuracy of the data;
    • the processing is unlawful and you oppose the erasure of the data and request the restriction of their use instead;
    • the provider no longer needs the data for the purposes of the processing, but they are required by you for the establishment, exercise or defense of legal claims;
    • you have objected to processing pending the verification whether the legitimate grounds of the provider override your reasons.
  • Right to data portability: As an individual, you have the right to receive the personal data concerning you, which you have provided to a controller, in a structured, commonly used and machine-readable format, and you have the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided, where:
    • the processing is based on consent or on a contract, and
    • the processing is carried out by automated means.


As an individual, you have the right to have the personal data transmitted directly from one controller to another, where technically feasible.

  • Right to object to processing: As an individual, on grounds relating to your particular situation, you have the right to object at any time to processing of personal data concerning you which is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the provider (point (e) of Article 6(1) of the General EU Data Protection Regulation) or is necessary for the purposes of the legitimate interests pursued by the provider or a third party (point (f) of Article 6(1) of the General EU Data Protection Regulation), including profiling based on those provisions. The provider shall no longer process the personal data unless the provider demonstrates compelling legitimate grounds for the processing which override your interests, rights and freedoms, or for the establishment, exercise or defense of legal claims.


Where personal data are processed for direct marketing purposes, the individual has the right to object at any time to processing of personal data concerning him or her for such marketing, which includes profiling to the extent that it is related to such direct marketing. Where the individual objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.

Where data are processed for scientific or historical research purposes or statistical purposes, the individual has the right, on grounds relating to his or her particular situation, to object to processing of personal data concerning him or her, unless the processing is necessary for the performance of a task carried out for reasons of public interest.

  • Right to lodge a complaint with a supervisory authority: As an individual to whom the personal data relate, you have the right to lodge a complaint with a supervisory authority, particularly in the Member State of your habitual residence, place of work or place of the alleged infringement if you consider that the processing of personal data relating to you infringes the General EU Data Protection Regulation. The supervisory authority with which the complaint has been lodged shall inform the complainant of the progress and the outcome of the complaint, including the possibility of a judicial remedy pursuant to Article 78 of the General EU Data Protection Regulation. As an individual, you have the right to lodge a complaint with the following address: Republic of Slovenia, Information Commissioner, Dunajska cesta 22, 1000 Ljubljana, telephone: 01 230 97 30, email: gp.ip@ip-rs.si.

Without prejudice to any other administrative or judicial remedy, as an individual, you have the right to an effective judicial remedy against a legally binding decision of a supervisory authority concerning you, as well as in the case where the supervisory authority does not handle a complaint or does not inform you within three months on the status of the complaint or decision on the complaint. The courts of the Member State where the supervisory authority is located shall have jurisdiction over proceedings against the supervisory authority.
Individuals can address all requests concerning the exercise of rights relating to personal data to the controller in writing, via one of the contacts listed on the website. For the purposes of reliable identification in exercising rights related to personal data, the controller may request additional information, and the action can be refused only if the controller proves that it cannot reliably identify the individual. The controller must respond to the individual’s request to exercise their rights concerning personal data without undue delay and at the latest within one month of receiving the request.

Please note that we process your data to fulfill contracts we might have with you (for example, if you place an order through the website), or otherwise to pursue our legitimate business interests listed above.

5. Data Retention Period
We will store and process your personal data to the extent necessary to fulfill the purposes of processing and as long as necessary to complete the ordered or agreed activities, and then within the limitations periods for obligations that may arise from the processing of these personal data, especially when the processing of personal data is necessary within the framework of the conclusion or execution of a contract.
Data obtained based on consent are kept permanently until the consent is revoked by the individual or a request for termination of processing is made.

In cases where the retention period for personal data is prescribed by law, data are kept in accordance with the statutory mandate.

6. Changes
We may update this privacy policy from time to time, for example, due to changes in our practices or for other operational, legal, or regulatory reasons.

7. Contact
For more information about our privacy practices, if you have questions, or if you would like to make a complaint, please contact us by email at support@bespokehome.eu or by mail using the details provided below:

POKE STUDIO d.o.o.
Vilharjeva cesta 42,
1000 Ljubljana,
Slovenia