Operated by Web Window OÜ, Tallinn, Estonia. Last updated: July 17, 2026.
The controller of your personal data is Web Window OÜ, a private limited company registered in Estonia (registry code 17163769), Maakri tn 19/1, Kesklinna linnaosa, 10145 Tallinn, Harju maakond, Estonia (the “Operator”, “we”). We operate the LogoRolly store at logorolly.com.
For any privacy question or request, contact us at support@logorolly.com.
This policy covers personal data processed when you browse logorolly.com, place an order, or contact us, wherever you are in the world. We apply the EU General Data Protection Regulation (GDPR) as our baseline standard for all customers, not only those in the EU.
Order data: your name, email address, billing and shipping address, and the contents of your order. Address and payment details are entered on Stripe's secure hosted checkout page, not on our site.
Messages you send us: the contact and business-quote forms collect your name, email, company name (optional), and message. If you reach out on WhatsApp or Telegram, we see the profile details and messages you choose to share there.
Artwork you submit: logos and designs you provide for engraving, together with the proof files we prepare from them.
Technical data: our hosting provider derives your approximate country from your IP address so we can show the right currency and shipping options, and keeps standard, short-lived server logs (IP address, browser type, pages requested) for security and reliability.
We never see or store your card number, payment is handled entirely by Stripe. We have no user accounts and no passwords. We run no advertising trackers and keep no marketing mailing lists: the only emails we send are about your order or your enquiry.
Performance of a contract (GDPR Art. 6(1)(b)): processing your order, preparing and approving proofs, producing and shipping your items, sending order confirmations and tracking emails, and answering your support requests.
Legal obligation (Art. 6(1)(c)): keeping invoices and transaction records required by Estonian accounting and tax law.
Legitimate interests (Art. 6(1)(f)): preventing fraud and abuse, securing the site, keeping records needed to handle warranty or defect claims, and, for visitors outside the EEA, the UK and Switzerland, measuring how the store is used with Google Analytics. We weighed that against your interests: the measurement is not used for advertising or profiling, and you can stop it with Global Privacy Control or your browser's cookie settings.
Consent (Art. 6(1)(a)): Google Analytics cookies for visitors in the EEA, the UK and Switzerland, which are set only after you choose “Accept” in the cookie banner. Decline and no analytics cookie is written, see the Cookie policy.
We share personal data only with the service providers needed to run the store: Stripe (payment processing and tax calculation), Resend (transactional email delivery), Vercel (website hosting, plus cookieless traffic and performance measurement), Cloudflare (DNS, and storage of your artwork and proof files), Google (Google Analytics), and Omniva or the relevant carrier (delivery, they receive your name, address and phone/email needed for shipment). Each processes data under its own privacy terms and our instructions.
To be precise about Google: its analytics script loads on every visit, so it receives your shortened IP address and the page you are on from the first page view, wherever you are. What your consent controls, in the EEA, the UK and Switzerland, is whether it may also store a cookie and recognise you on a later visit. Until you accept there, the measurement cannot be linked back to you.
We disclose data to public authorities only where the law requires it. We never sell or rent your personal data to anyone.
Your data is processed primarily within the EU/EEA. Where a provider (such as Stripe, Resend, Vercel or Google) processes data in the United States, the transfer is protected by the EU-U.S. Data Privacy Framework or the European Commission's Standard Contractual Clauses.
The artwork and proof files you send us are stored with Cloudflare in buckets restricted to the European Union, so those files are held inside the EU and are not transferred out.
Invoices and transaction records are kept for seven years as required by Estonian accounting law. Order correspondence and proof files are kept for as long as needed to support your order and any warranty claims. We do not maintain a long-term customer database of our own, order and payment records live with Stripe under its retention rules.
You may ask us at any time to access, correct, export or erase your personal data, to restrict or object to its processing, and to withdraw any consent you have given (without affecting processing before withdrawal). Email support@logorolly.com and we will respond within one month.
You also have the right to lodge a complaint with a supervisory authority, in Estonia, the Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee), or the authority in your own EU country.
We do not sell or share personal information as those terms are defined in US state privacy laws (such as the CCPA/CPRA), and we do not use it for cross-context behavioral advertising. US customers may exercise the same access, correction and deletion rights described above by emailing support@logorolly.com.
We use a small set of first-party, functional cookies and browser storage (cart, currency, theme, consent choice), plus Google Analytics cookies, which ask your permission first in the EEA, the UK and Switzerland. No advertising trackers anywhere. Details are in our Cookie policy at logorolly.com/legal/cookies.
We may update this policy as the store or the law changes; the current version is always published on this page with its “last updated” date. Material changes will be highlighted here.
Questions about this policy or your data: support@logorolly.com, or by post to Web Window OÜ, Maakri tn 19/1, Kesklinna linnaosa, 10145 Tallinn, Harju maakond, Estonia.