Legal

Privacy Policy

Effective Date: 18 April 2026
Last Updated: 18 April 2026

This Privacy Policy explains how Black Stag Kft, operating under the brand Adrian's Selection ("Adrian's Selection," "we," "us," or "our"), collects, uses, stores, shares, and otherwise processes personal data in connection with the Adrian's Selection services platform, including related websites, subdomains, dashboards, authentication flows, sourcing request forms, certificates, communications, and associated services (collectively, the "Services").

This Privacy Policy is intended to provide transparent information about our data processing practices in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR) where applicable.

1. Data Controller

The controller responsible for the processing of your personal data under this Privacy Policy is:

Black Stag Kft
Brand / Trading Name: Adrian's Selection
Registered Office: 8636 Balatonszemes, Kinizsi utca 13., Hungary
Tax Number: 32550717-2-14
Email: privacy@adriansselection.com

If we designate a specific privacy contact for the Services, that contact information may also be published on the Services.

2. Scope of This Privacy Policy

This Privacy Policy applies to personal data processed in connection with:

  • your access to and use of the Services,
  • account creation and account management,
  • authentication requests,
  • private sourcing requests,
  • service purchases and activations,
  • certificate generation and certificate access,
  • communications and support interactions,
  • payment-related workflows,
  • store credit and customer account linkage,
  • legal, fraud prevention, operational, and security processes related to the Services.

This Privacy Policy does not necessarily govern personal data processed exclusively under the separate Adrian's Selection online store checkout, store order fulfillment, or independent third party platform policies, which may be subject to additional privacy notices.

3. Categories of Personal Data We Process

Depending on how you use the Services, we may process the following categories of personal data.

3.1 Account and Identity Data

  • full name,
  • email address,
  • phone number,
  • country,
  • login credentials or authentication data,
  • account identifiers,
  • linked store or customer account identifiers,
  • profile details you provide.

3.2 Request and Service Data

  • authentication request details,
  • item category, brand, model, source, seller, and related descriptions,
  • sourcing request details,
  • requested product specifications,
  • budget range,
  • timing preferences,
  • status history,
  • request notes,
  • internal request references,
  • support history,
  • service selections,
  • activation choices,
  • certificate references,
  • result status,
  • store credit status.

3.3 Submitted Materials and User Content

  • photographs of products,
  • images of packaging,
  • serial numbers,
  • labels,
  • tags,
  • receipts,
  • authenticity cards,
  • certificates,
  • uploaded screenshots,
  • text notes,
  • documents and materials you submit in connection with a request.

These materials may include personal data where, for example, names, addresses, receipt details, account identifiers, or other personal information appear in uploaded content.

3.4 Transaction and Payment Data

  • payment status,
  • transaction references,
  • billing details,
  • currency,
  • product or activation purchased,
  • chargeback or refund status,
  • payment processor metadata,
  • invoice-related data.

We do not intentionally store full payment card numbers unless this is expressly handled by us through a compliant process. In most cases, payments are processed by a third party payment provider.

3.5 Communication Data

  • email correspondence,
  • support messages,
  • account notifications,
  • dashboard communications,
  • request follow-up details,
  • internal records of user support interactions.

3.6 Technical and Usage Data

  • IP address,
  • browser type,
  • device type,
  • operating system,
  • time zone,
  • referring URLs,
  • log data,
  • service interaction data,
  • navigation patterns,
  • authentication events,
  • security and fraud signals,
  • approximate location inferred from technical data.

3.7 Storefront and Linkage Data

Where relevant to store credit or account matching, we may process:

  • Shopify or storefront customer identifiers,
  • linked customer email,
  • store credit amount,
  • credit issuance status,
  • redemption status,
  • related service request identifiers,
  • customer matching or verification records.

3.8 Legal and Compliance Data

  • records relevant to complaints,
  • misuse flags,
  • fraud review indicators,
  • legal correspondence,
  • audit records,
  • enforcement-related metadata,
  • records necessary to establish, exercise, or defend legal claims.

4. Sources of Personal Data

We collect personal data from the following sources:

  • directly from you,
  • from your account activity,
  • from forms and request submissions,
  • from materials you upload,
  • from payment processors and transaction providers,
  • from authentication or identity providers,
  • from storefront systems or linked customer records,
  • from technical systems, cookies, server logs, and analytics tools,
  • from support communications,
  • from publicly available sources where reasonably necessary for sourcing, fraud prevention, compliance, or service verification.

5. Purposes of Processing and Legal Bases

Depending on the context, we rely on one or more of the following legal bases:

  • performance of a contract,
  • taking steps at your request before entering into a contract,
  • compliance with legal obligations,
  • our legitimate interests, provided those interests are not overridden by your rights and freedoms,
  • consent, where consent is required or specifically requested.

5.1 To Provide and Manage the Services

We process personal data to create accounts, authenticate users, manage dashboards, operate workflows, deliver results, issue certificates, handle sourcing requests, and provide the Services generally.

Legal basis: performance of a contract; pre-contractual steps at your request.

5.2 To Review Authentication Requests

We process item details, uploaded images, submitted documents, and related data to evaluate authentication requests, request additional materials, generate outcomes, and issue certificates or reports where applicable.

Legal basis: performance of a contract; legitimate interests in operating, quality-controlling, and defending our independent assessment services.

5.3 To Review and Handle Private Sourcing Requests

We process request data, preferences, contact information, and supporting materials to assess sourcing eligibility, manage activations, conduct sourcing work, and communicate sourcing updates.

Legal basis: performance of a contract; pre-contractual steps at your request; legitimate interests in operating and improving our sourcing services.

5.4 To Process Payments and Issue Invoices

We process transaction-related data to confirm payments, prevent fraud, manage disputes, administer payment-linked service activation, and maintain billing and accounting records.

Payments are processed through Stripe. Invoices and billing documentation are prepared through Billingo.

Legal basis: performance of a contract; compliance with legal obligations; legitimate interests in fraud prevention, accounting, invoicing, and business operations.

5.5 To Link Service Accounts to Storefront Customer Accounts and Administer Store Credit

Where applicable, we process customer identity and account linkage data to connect the Services account with the relevant Adrian's Selection store customer record, issue or prepare store credit, maintain customer continuity across the services platform and the store, and manage redemption status or related technical support.

This may involve processing through Shopify or Shopify-related systems where certain Services, benefits, or account-linking functions depend on store integration.

Legal basis: performance of a contract; legitimate interests in administering service benefits, preventing duplicate or erroneous issuance, and maintaining accurate customer records.

5.6 To Communicate with You

We process your contact details and communication records to send confirmations, updates, support replies, activation notices, security alerts, and service-related messages.

Legal basis: performance of a contract; legitimate interests in customer support, service continuity, and account security.

5.7 To Maintain Security, Prevent Fraud, and Enforce Our Terms

We process personal data to detect suspicious activity, prevent abuse, manage chargebacks, investigate misuse, enforce our legal terms, and protect the Services, our users, and our business.

Legal basis: legitimate interests in security, fraud prevention, and legal risk management; compliance with legal obligations where applicable.

5.8 To Comply with Legal, Regulatory, Tax, and Accounting Requirements

We process personal data where necessary to comply with legal obligations, maintain records, respond to lawful requests, or establish, exercise, or defend legal claims.

Legal basis: compliance with legal obligations; legitimate interests in legal defense and governance.

5.9 To Improve and Analyze the Services

We may process usage and technical data to understand how users interact with the Services, improve reliability, optimize workflows, and maintain performance.

This may include the use of Google Analytics for traffic analysis and service performance insights.

Legal basis: legitimate interests in analytics, service optimization, and operational improvement; consent where required by law for non-essential tracking technologies.

5.10 Advertising Measurement and Remarketing

We may use Meta Pixel for advertising measurement, campaign attribution, audience analytics, and remarketing, subject to applicable consent requirements.

Legal basis: consent where required by law; legitimate interests where permitted by applicable law.

5.11 Marketing and Optional Updates

If you subscribe to newsletters, launch notices, or optional marketing communications, we may process your contact details for those purposes.

Legal basis: consent where required by law; in limited cases, legitimate interests where permitted by applicable law.

6. Main Service Providers and Third Party Tools

We use the following named service providers or tools in connection with the Services:

  • Lovable.dev for application development, implementation, workflow building, or related product infrastructure,
  • Supabase for backend functions, database services, storage, authentication-related features, and related technical infrastructure,
  • Stripe for payment processing, transaction management, and payment-related fraud and dispute handling,
  • Google Analytics for traffic analytics, usage measurement, and service performance insights,
  • Meta Pixel for advertising analytics, campaign measurement, audience creation, and remarketing, subject to applicable consent requirements,
  • Shopify for customer account linkage, store integration, store credit related workflows, and continuity between the Services platform and the Adrian's Selection store,
  • Billingo for invoice issuance, billing administration, and related accounting documentation.

Depending on the context, these providers may act as our processor, independent controller, or both in relation to different processing activities.

6.1 Contact Details of Main Service Providers and Related Third Parties

For transparency purposes, the main service providers and related third parties used in connection with the Services may be identified as follows:

Lovable.dev

  • Provider: Lovable Labs AB
  • Contact email: dpo@lovable.dev
  • Privacy contact email: privacy@lovable.dev
  • Address: Box 190, 101 23 Stockholm, Sweden
  • Privacy information: https://lovable.dev/privacy

Supabase

Stripe

  • Provider: Stripe Payments Europe, Ltd. / Stripe Technology Europe, Limited, as applicable
  • Privacy contact email: privacy@stripe.com
  • Address: 1 Wilton Park, Wilton Place, Dublin 2, D02 FX04, Ireland
  • Contact page: https://stripe.com/contact
  • Privacy information: https://stripe.com/privacy

Google Analytics

Meta Pixel

Shopify

Billingo

The providers, entities, roles, and contact details listed above may change from time to time. Where appropriate, we may update this Privacy Policy to reflect material changes.

7. Special Categories of Data and Sensitive Information

The Services are not intended to require special category personal data.

You should not submit sensitive personal data unless strictly necessary and legally permitted. This includes, by way of example, data revealing health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, biometric identifiers used for unique identification, or similar highly sensitive information.

If you voluntarily include such information in uploaded materials or communications, we may process it only to the extent necessary to handle your request, comply with law, protect legal claims, or delete or suppress it where appropriate.

8. Automated Decision-Making

We do not intend to make decisions producing legal effects or similarly significant effects based solely on automated processing unless expressly disclosed otherwise.

Our authentication and sourcing services are intended to involve human review, expert handling, and operational judgment, even where automated tools may assist with workflow, quality checks, fraud screening, or system management.

9. Sharing of Personal Data

We may share personal data where reasonably necessary for the purposes described in this Privacy Policy.

9.1 Service Providers and Processors

We may share personal data with our named service providers and other providers acting on our behalf where reasonably necessary to operate, secure, measure, improve, and support the Services.

This includes, as applicable:

  • Lovable.dev,
  • Supabase,
  • Stripe,
  • Google Analytics,
  • Meta Pixel,
  • Shopify,
  • Billingo,
  • hosting and infrastructure providers,
  • email and messaging providers,
  • security and fraud prevention providers,
  • storage providers,
  • support and operational tooling.

9.2 Professional Advisors and Affiliates

We may share personal data with lawyers, accountants, auditors, consultants, insurers, or related professional advisors where reasonably necessary.

9.3 Counterparties and Fulfillment-Related Parties

Where relevant to sourcing, we may share limited information with boutiques, sellers, logistics or procurement counterparties, or other third parties where necessary to evaluate a request or facilitate a potential transaction. We aim to limit data sharing to what is reasonably necessary.

9.4 Legal and Regulatory Disclosure

We may disclose personal data if required to do so by law, regulation, court order, supervisory authority request, or other lawful process, or where disclosure is necessary to protect rights, prevent fraud, address misuse, or establish, exercise, or defend legal claims.

9.5 Business Transfers

If all or part of our business is restructured, sold, merged, financed, or transferred, personal data may be disclosed to relevant parties subject to appropriate safeguards and confidentiality obligations.

10. International Transfers

Some recipients of personal data may be located outside the European Economic Area.

Where personal data is transferred outside the EEA, we will seek to ensure that the transfer is covered by an appropriate legal mechanism, such as:

  • a country benefiting from an adequacy decision,
  • Standard Contractual Clauses,
  • another lawful transfer mechanism recognized under applicable data protection law,
  • derogations where legally available and appropriate in limited cases.

You may contact us for more information about the safeguards used for specific transfers, subject to confidentiality and legal limits.

11. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Services, maintain business records, comply with legal obligations, resolve disputes, and enforce agreements.

Retention periods may vary depending on the type of data and the purpose of processing. For example:

  • account records may be retained while your account remains active and for a reasonable period afterward,
  • authentication request files, certificates, and review records may be retained for audit, quality control, legal defense, and misuse prevention purposes,
  • sourcing request files may be retained to manage follow-up, disputes, and operational records,
  • transaction and billing records may be retained for tax, accounting, and legal compliance periods,
  • technical logs may be retained for security, diagnostics, and fraud prevention for limited periods or longer where reasonably necessary,
  • communications may be retained for support continuity, dispute handling, and legal defense.

Where data is no longer required, we may delete it, anonymize it, or securely archive it in accordance with applicable law and operational need.

12. Security

We take reasonable technical and organizational measures designed to protect personal data against unauthorized access, accidental loss, misuse, alteration, unlawful disclosure, and other unlawful or unauthorized processing.

These measures may include, as appropriate:

  • access controls,
  • account authentication measures,
  • role-based permissions,
  • encryption in transit and, where appropriate, at rest,
  • provider-level security controls,
  • logging and monitoring,
  • backup and recovery processes,
  • fraud prevention and anomaly monitoring,
  • internal operational restrictions.

However, no online service or electronic storage system can be guaranteed to be completely secure.

13. Your Rights

Depending on the circumstances and applicable law, you may have the right to:

  • request confirmation that we process your personal data,
  • access a copy of your personal data,
  • request correction of inaccurate or incomplete personal data,
  • request deletion of personal data,
  • request restriction of processing,
  • object to certain processing based on legitimate interests,
  • request portability of certain data you provided to us,
  • withdraw consent where processing is based on consent,
  • lodge a complaint with a supervisory authority.

These rights are not absolute and may be limited where an exemption or legal basis applies, for example where data must be retained for legal obligations, legal defense, fraud prevention, or the rights of others.

To exercise your rights, contact us using the details in this Privacy Policy.

We may request information necessary to verify your identity before responding. Requests will be handled in accordance with applicable law.

14. Complaints and Supervisory Authority

If you believe that your personal data has been processed unlawfully, you have the right to lodge a complaint with a supervisory authority.

In Hungary, the competent supervisory authority is the National Authority for Data Protection and Freedom of Information (NAIH).

NAIH
Headquarters: 1055 Budapest, Falk Miksa utca 9-11
Postal Address: 1363 Budapest, Pf. 9.
Email: ugyfelszolgalat@naih.hu
Telephone: +36 (1) 391-1400

You may also have the right to lodge a complaint with the supervisory authority in the EU/EEA country of your habitual residence, place of work, or alleged infringement, where applicable.

15. Cookies and Similar Technologies

This section forms the cookie and similar technologies notice for the Services. No separate Cookie Policy is required unless we later decide to publish one for operational convenience.

We may use cookies, local storage, pixels, scripts, tags, SDKs, and similar technologies to operate the Services, maintain sessions, improve performance, understand usage, support security, measure the effectiveness of marketing activities, and support account continuity across relevant parts of the Adrian's Selection ecosystem.

15.1 What Cookies and Similar Technologies Are

Cookies are small text files placed on your device or browser when you visit a website or use a web-based service. Similar technologies may include pixels, tags, local storage objects, scripts, SDKs, and identifiers that perform comparable functions.

15.2 Categories of Technologies We May Use

(a) Strictly Necessary Technologies

These technologies are necessary for the operation, security, and core functionality of the Services. They may be used to:

  • enable login and account authentication,
  • maintain session integrity,
  • remember security or consent settings,
  • support fraud prevention and abuse detection,
  • route requests properly,
  • preserve core platform functionality,
  • support payment and account-related workflows where necessary.

Because these technologies are necessary for the provision of the Services, they may be used without consent where permitted by applicable law.

(b) Analytics and Performance Technologies

These technologies help us understand how users interact with the Services, measure traffic, identify technical issues, improve user experience, and optimize functionality.

For these purposes, we may use Google Analytics.

Analytics-related technologies may collect information such as:

  • pages visited,
  • navigation paths,
  • session duration,
  • approximate location inferred from IP,
  • device and browser information,
  • interaction events,
  • referring sources,
  • performance and usage signals.

Where consent is required by applicable law, analytics technologies will only be activated after the relevant consent has been given.

(c) Advertising, Measurement, and Remarketing Technologies

These technologies help us measure campaign performance, understand conversions, build audiences, and support remarketing or advertising analytics.

For these purposes, we may use Meta Pixel.

Advertising-related technologies may collect or infer information such as:

  • page visits,
  • conversion events,
  • campaign attribution data,
  • device or browser identifiers,
  • interactions relevant to audience creation or remarketing,
  • related event or traffic information.

Where consent is required by applicable law, advertising and remarketing technologies will only be activated after the relevant consent has been given.

15.3 Third Party Technologies Specifically Used

At the time of this Privacy Policy, the Services may use or integrate with the following relevant third party tools or technologies:

  • Google Analytics for traffic and usage analytics,
  • Meta Pixel for advertising measurement and remarketing,
  • Stripe where necessary for payment-related workflows,
  • Shopify where relevant for storefront linkage, account continuity, or store credit related workflows,
  • Supabase and related technical infrastructure for service functionality, authentication-related features, and backend operations.

Not every tool necessarily places browser-based cookies in every context, but each may be involved in technical processing connected to the Services.

15.4 Consent and User Choice

Where required by applicable law, non-essential cookies or similar technologies, including analytics, advertising, or remarketing technologies, will be used only after you have given the relevant consent.

Where we provide a consent banner, cookie preferences tool, or similar mechanism, you may be able to:

  • accept all,
  • reject non-essential technologies,
  • customize your preferences,
  • change your preferences later.

Please note that disabling certain technologies may affect some non-essential functionality, personalization, measurement, or convenience features of the Services.

15.5 Browser and Device Controls

You may also manage cookies through your browser or device settings. Depending on your browser, you may be able to block, delete, or restrict certain cookies. However, doing so may affect the operation of some parts of the Services.

15.6 Legal Basis

Strictly necessary technologies are processed on the basis of our legitimate interests in securely operating and delivering the Services, and where applicable because such processing is necessary to provide a service explicitly requested by the user.

Analytics, advertising, and remarketing technologies are processed on the basis of consent where consent is required by applicable law.

15.7 Retention of Cookie-Related Data

Cookie and similar technology data may be retained for different periods depending on whether the technology is session-based or persistent, the provider involved, the purpose of processing, and applicable legal or operational requirements.

15.8 Updates to This Section

We may update this Cookies and Similar Technologies section from time to time to reflect changes in the technologies we use, legal requirements, or operational practices.

16. Linked Storefront and Shopify-Related Processing

Where the Services interact with the Adrian's Selection online store or related commerce systems, personal data may be processed to:

  • match a Services account with a store customer account,
  • issue or prepare store credit,
  • verify customer identity or email matching,
  • track credit redemption status,
  • support purchase-related account continuity,
  • investigate credit misuse, duplication, or fraud.

Where store-related data is processed, additional data may be received from or shared with Shopify or supporting service providers, subject to appropriate legal and contractual arrangements.

Store purchases, checkout pages, and separate store functions may also be governed by separate privacy terms or platform notices.

17. Children's Data

The Services are not directed to children, and we do not knowingly collect personal data from children in connection with the Services.

If you believe a child has provided personal data to us unlawfully, please contact us so that we can take appropriate steps.

18. Data Accuracy and User Responsibility

You are responsible for ensuring that the personal data and materials you submit are accurate, lawful, and up to date, and that you have the right to provide them.

You should avoid submitting unnecessary personal data, especially in uploaded receipts, screenshots, or documents where unrelated information may appear.

Where possible, you may redact information not needed for the service, provided that doing so does not interfere with the service requested.

19. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect legal, regulatory, technical, operational, or service-related changes.

If we make material changes, we may provide notice through the Services, by email, through dashboard notice, or by updating the date at the top of this Privacy Policy.

Your continued use of the Services after the effective date of an updated Privacy Policy will be subject to the updated version, to the extent permitted by law.

20. Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, please contact:

Adrian's Selection / Black Stag Kft
Registered Office: 8636 Balatonszemes, Kinizsi utca 13., Hungary
Tax Number: 32550717-2-14
Email: privacy@adriansselection.com

21. Additional Notice Regarding Authentication and Uploaded Materials

Because the Authentication Services depend on uploaded images and supporting documents, uploaded materials may contain incidental personal data such as names, receipt details, order references, addresses, or identifying metadata.

We process such data only insofar as reasonably necessary to:

  • review the item,
  • assess source and documentation,
  • detect inconsistencies or fraud indicators,
  • generate the requested result or certificate,
  • maintain quality control and legal records.

Where feasible and appropriate, we may redact, suppress, or minimize unnecessary personal data in outputs.

22. Additional Notice Regarding Sourcing Requests

Where you submit a private sourcing request, the request may reveal your shopping preferences, target brands, sizes, style interests, budget range, event timing, country of delivery, or similar commercial preferences.

We process this information solely for the purpose of assessing, activating, managing, and attempting to fulfill the sourcing request, and for related communications, account management, and fraud prevention.

We do not interpret such preference data as sensitive category data unless it independently falls within a legally protected category.

23. Data Minimization and Processing Principles

We seek to process personal data lawfully, fairly, transparently, and only to the extent reasonably necessary for the purposes described in this Privacy Policy. We also aim to keep personal data accurate, secure, and retained no longer than reasonably necessary, taking into account legal, operational, and evidentiary requirements.

End of Privacy Policy