Privacy policy
Last updated: May 5, 2026
This Privacy Policy explains how Matchy LTD, registered in Bulgaria under company number 208750422, with registered address at Tvardishki Prohod 19, Sofia, Bulgaria (“Matchy”, “we”, “us”, or “our”), collects, uses, stores, shares, and protects your personal data when you visit or make a purchase through matchy.bg.
For the purposes of the General Data Protection Regulation, Matchy LTD is the data controller of your personal data.
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, you can contact us at:
Email: matchy@gmail.com
Address: Tvardishki Prohod 19, Sofia, Bulgaria
1. Personal Data We Collect
We may collect the following types of personal data:
Order and contact information
When you place an order, we may collect:
- full name;
- email address;
- phone number;
- delivery address;
- billing address, if different;
- order details;
- payment method;
- delivery preferences;
- communication related to your order.
Payment information
We offer payment by:
- cash on delivery;
- debit or credit card.
Card payments are processed by third-party payment providers. We do not directly store full card numbers or full payment card details.
Delivery information
To deliver your order, we may process and share relevant delivery data, including:
- name;
- phone number;
- delivery address;
- order reference;
- cash on delivery amount, where applicable;
- delivery status.
Technical and usage data
When you visit our website, we may collect:
- Internet Protocol address;
- browser type;
- device information;
- pages visited;
- time spent on the website;
- products viewed;
- cart activity;
- checkout activity;
- cookie and tracking preferences.
Customer communication
If you contact us, we may process the information you provide, including your name, email, phone number, message content, and any order-related details.
Reviews and testimonials
If you leave a product review, we may process and display the information you submit, such as your name, review text, rating, and any other content you choose to provide.
We do not intentionally collect health data, allergy information, pregnancy information, caffeine sensitivity information, or other special category personal data.
2. How We Collect Personal Data
We collect personal data:
- directly from you when you place an order, contact us, or submit a review;
- automatically through cookies and similar technologies when you use our website;
- through Shopify, which powers our online store;
- from delivery, payment, and technical service providers where necessary for order fulfillment, payment confirmation, delivery, fraud prevention, or customer support.
3. Why We Use Your Personal Data
We use your personal data for the following purposes:
To process and deliver your orders
We use your personal data to confirm, process, package, ship, deliver, return, exchange, or refund your orders.
Legal basis: performance of a contract.
To process payments
We use your payment-related information to process your selected payment method, including cash on delivery or card payment.
Legal basis: performance of a contract and legitimate interest in secure payment processing.
To arrange delivery
We share necessary personal data with courier companies such as Econt, Speedy, or other delivery partners in order to deliver your order, process cash on delivery payments, manage returns, and resolve delivery issues.
Legal basis: performance of a contract.
To provide customer support
We use your information to respond to questions, complaints, delivery issues, product issues, refund requests, and other support requests.
Legal basis: performance of a contract and legitimate interest.
To send order-related messages
We may send you non-marketing messages, including order confirmations, delivery updates, payment updates, return information, and customer service replies.
Legal basis: performance of a contract.
To send abandoned checkout reminders
If you begin checkout but do not complete your purchase, we may use the contact details and cart information you provided to remind you about your unfinished order, where permitted by law and, where required, based on your consent.
Legal basis: legitimate interest or consent, depending on the applicable setup and communication channel.
To send marketing communications
In the future, we may send newsletters, promotional emails, offers, product updates, or other marketing communications if you have subscribed or where otherwise permitted by law.
We may also use SMS, Viber, WhatsApp, Messenger, or similar communication channels in the future, but only where we have the required legal basis, including consent where necessary.
You may unsubscribe or withdraw your consent at any time.
Legal basis: consent or legitimate interest where permitted by law.
To use advertising and analytics technologies
We use Meta Pixel and similar technologies to measure advertising performance, understand customer interactions, and show relevant advertising on platforms such as Facebook and Instagram.
We do not currently use Google Analytics or TikTok Pixel.
Non-essential cookies and advertising technologies are used only where required consent has been obtained.
Legal basis: consent, where required by law.
To improve our website and services
We may use technical and usage data to improve website performance, product presentation, checkout experience, customer service, and business operations.
Legal basis: legitimate interest or consent, depending on the technology used.
To comply with legal obligations
We may process and retain personal data where required for accounting, tax, invoicing, consumer protection, legal claims, regulatory requests, or other legal obligations.
Legal basis: legal obligation.
To protect our business and prevent fraud
We may use data to prevent fraud, abuse, unauthorized access, payment issues, chargebacks, security incidents, and misuse of our website.
Legal basis: legitimate interest.
4. Shopify
Our online store is hosted and powered by Shopify. Shopify provides the ecommerce platform that allows us to sell our products and process orders.
When you visit or purchase from our store, your personal data may be processed by Shopify, including data related to browsing, checkout, payment, order processing, fraud prevention, and store functionality.
Shopify may process personal data in countries outside the European Economic Area. Where required, Shopify relies on appropriate legal transfer mechanisms, such as Standard Contractual Clauses.
You can read more about Shopify’s privacy practices here:
https://www.shopify.com/legal/privacy
5. Payments
We offer debit and credit card payments through third-party payment providers. These providers process payment information securely and may collect information necessary to authorize, confirm, and protect the payment.
We do not directly store full card numbers or full card security codes.
If you select cash on delivery, the courier may process the order amount, delivery details, payment confirmation, and transfer-related information necessary to complete the cash on delivery process.
6. Delivery Partners
We use courier and logistics partners, including Econt and Speedy, to deliver orders in Bulgaria and Romania.
We share only the information necessary for delivery and related services, such as:
- name;
- phone number;
- delivery address;
- order details necessary for delivery;
- cash on delivery amount, if applicable;
- delivery and return information.
Courier providers may also process your personal data as independent controllers according to their own privacy policies.
7. Cookies and Tracking Technologies
Our website uses cookies and similar technologies.
Cookies may be used to:
- keep the website functioning properly;
- remember your cart;
- support checkout;
- improve website performance;
- understand how visitors use the website;
- measure advertising performance;
- show relevant advertisements through Meta platforms.
Cookies may include:
Essential cookies
These are necessary for the website to function, including cart, checkout, security, and payment-related functions.
Analytics and performance cookies
These help us understand how visitors use the website and improve user experience.
Advertising cookies
These help us measure advertising campaigns and show relevant ads, including through Meta Pixel.
Where required by law, non-essential cookies are used only after you give consent. You may manage or withdraw cookie consent through the cookie settings available on our website, where such settings are provided.
You can also control cookies through your browser settings.
8. Marketing Communications
If you subscribe to marketing communications, we may use your email address to send offers, product updates, launches, promotions, and other marketing content.
In the future, we may use an email marketing platform, such as Shopify Email, Klaviyo, Omnisend, Mailchimp, or another similar provider.
We may also use SMS, Viber, WhatsApp, Messenger, or similar channels in the future, but only where legally permitted and where the required consent has been obtained.
You can unsubscribe from marketing emails by using the unsubscribe link in the email or by contacting us.
Even if you unsubscribe from marketing, we may still send transactional messages related to your orders, payments, deliveries, returns, or customer support.
9. Who We Share Personal Data With
We may share personal data with:
- Shopify, as our ecommerce platform provider;
- payment processors;
- courier providers, including Econt and Speedy;
- technical service providers;
- hosting and cloud service providers;
- advertising platforms, including Meta;
- customer support tools;
- accountants, auditors, legal advisors, and other professional advisors;
- public authorities, regulators, courts, or law enforcement where required by law;
- future email marketing or communication providers, where used.
We do not sell your personal data.
We only share personal data where necessary for the purposes described in this Privacy Policy, where required by law, or where you have given consent.
10. International Data Transfers
Some of our service providers, including Shopify, Meta, payment providers, or future marketing and technical providers, may process personal data outside Bulgaria, Romania, or the European Economic Area.
Where personal data is transferred outside the European Economic Area, we rely on appropriate safeguards, such as:
- European Commission adequacy decisions;
- Standard Contractual Clauses;
- contractual and technical safeguards required under applicable data protection law.
11. How Long We Keep Your Personal Data
We keep personal data only for as long as necessary for the purposes described in this Privacy Policy.
Typical retention periods include:
| Data type | Retention period |
|---|---|
| Order and delivery data | As long as necessary to process the order, handle delivery, returns, complaints, disputes, and legal obligations |
| Accounting and invoice data | For the period required by applicable accounting and tax law |
| Customer support messages | As long as necessary to resolve the request and protect our legal interests |
| Marketing data | Until you unsubscribe, withdraw consent, or the data is no longer needed |
| Cookie consent records | As long as necessary to manage and prove consent |
| Technical/security logs | As long as necessary for security, fraud prevention, and website operation |
We may retain certain data for longer where required by law or where necessary to establish, exercise, or defend legal claims.
12. Your Rights
Under applicable data protection law, including the General Data Protection Regulation, you may have the right to:
- access your personal data;
- request correction of inaccurate or incomplete data;
- request deletion of your personal data;
- request restriction of processing;
- object to processing based on legitimate interest;
- withdraw consent at any time where processing is based on consent;
- request data portability;
- object to direct marketing;
- lodge a complaint with a supervisory authority.
These rights are not absolute and may apply only in certain circumstances.
To exercise your rights, contact us at:
We may need to verify your identity before responding to your request.
13. Complaints
If you believe that we have processed your personal data unlawfully or have not respected your rights, please contact us first so we can try to resolve the issue.
You also have the right to lodge a complaint with the Bulgarian data protection authority:
Commission for Personal Data Protection
Комисия за защита на личните данни
Website: https://www.cpdp.bg
14. Security
We take reasonable technical and organizational measures to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure.
However, no website, online store, payment method, or electronic communication system is completely secure. You should not send sensitive or confidential information to us through insecure channels.
15. Children’s Privacy
Our website and products are not intended for children.
We do not knowingly collect personal data from children. If you believe that a child has provided us with personal data, please contact us and we will take appropriate steps to delete it where required by law.
16. Customer Accounts
At the moment, purchases are made through checkout and customer accounts are not required.
If we enable customer accounts in the future, we may process account-related information such as login details, order history, saved addresses, preferences, and account settings. This processing will be used to provide and manage customer account functionality.
17. Automated Decision-Making
We do not use automated decision-making that produces legal or similarly significant effects concerning you.
We may use limited profiling or segmentation for marketing, advertising measurement, product recommendations, abandoned checkout reminders, or website improvement, where permitted by law and, where required, based on your consent.
18. Providing Personal Data
Some personal data is necessary for us to process and deliver your order.
If you do not provide required order, payment, contact, or delivery information, we may be unable to process your purchase, deliver your products, handle returns, or provide customer support.
Marketing data is optional and you may withdraw consent at any time.
19. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our business, website, service providers, legal obligations, or data processing practices.
The updated version will be published on this page with a new “Last updated” date.
20. Contact Us
For questions, requests, or complaints related to this Privacy Policy or your personal data, contact:
Matchy LTD
Company number: 208750422
Address: Tvardishki Prohod 19, Sofia, Bulgaria
Email: matchy@gmail.com
Website: matchy.bg