Privacy Policy
This Privacy Policy explains how Black Stag Kft, operating under the brand Adrian's Selection ("Adrian's Selection," "we," "us," or "our"), collects, uses, stores, shares, and otherwise processes personal data in connection with the Adrian's Selection services platform, including related websites, subdomains, dashboards, authentication flows, sourcing request forms, certificates, communications, and associated services (collectively, the "Services").
This Privacy Policy is intended to provide transparent information about our data processing practices in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR) where applicable.
1. Data Controller
The controller responsible for the processing of your personal data under this Privacy Policy is:
If we designate a specific privacy contact for the Services, that contact information may also be published on the Services.
2. Scope of This Privacy Policy
This Privacy Policy applies to personal data processed in connection with:
- your access to and use of the Services,
- account creation and account management,
- authentication requests,
- private sourcing requests,
- service purchases and activations,
- certificate generation and certificate access,
- communications and support interactions,
- payment-related workflows,
- store credit and customer account linkage,
- legal, fraud prevention, operational, and security processes related to the Services.
This Privacy Policy does not necessarily govern personal data processed exclusively under the separate Adrian's Selection online store checkout, store order fulfillment, or independent third party platform policies, which may be subject to additional privacy notices.
3. Categories of Personal Data We Process
Depending on how you use the Services, we may process the following categories of personal data.
3.1 Account and Identity Data
- full name,
- email address,
- phone number,
- country,
- login credentials or authentication data,
- account identifiers,
- linked store or customer account identifiers,
- profile details you provide.
3.2 Request and Service Data
- authentication request details,
- item category, brand, model, source, seller, and related descriptions,
- sourcing request details,
- requested product specifications,
- budget range,
- timing preferences,
- status history,
- request notes,
- internal request references,
- support history,
- service selections,
- activation choices,
- certificate references,
- result status,
- store credit status.
3.3 Submitted Materials and User Content
- photographs of products,
- images of packaging,
- serial numbers,
- labels,
- tags,
- receipts,
- authenticity cards,
- certificates,
- uploaded screenshots,
- text notes,
- documents and materials you submit in connection with a request.
These materials may include personal data where, for example, names, addresses, receipt details, account identifiers, or other personal information appear in uploaded content.
3.4 Transaction and Payment Data
- payment status,
- transaction references,
- billing details,
- currency,
- product or activation purchased,
- chargeback or refund status,
- payment processor metadata,
- invoice-related data.
We do not intentionally store full payment card numbers unless this is expressly handled by us through a compliant process. In most cases, payments are processed by a third party payment provider.
3.5 Communication Data
- email correspondence,
- support messages,
- account notifications,
- dashboard communications,
- request follow-up details,
- internal records of user support interactions.
3.6 Technical and Usage Data
- IP address,
- browser type,
- device type,
- operating system,
- time zone,
- referring URLs,
- log data,
- service interaction data,
- navigation patterns,
- authentication events,
- security and fraud signals,
- approximate location inferred from technical data.
3.7 Storefront and Linkage Data
Where relevant to store credit or account matching, we may process:
- Shopify or storefront customer identifiers,
- linked customer email,
- store credit amount,
- credit issuance status,
- redemption status,
- related service request identifiers,
- customer matching or verification records.
3.8 Legal and Compliance Data
- records relevant to complaints,
- misuse flags,
- fraud review indicators,
- legal correspondence,
- audit records,
- enforcement-related metadata,
- records necessary to establish, exercise, or defend legal claims.
4. Sources of Personal Data
We collect personal data from the following sources:
- directly from you,
- from your account activity,
- from forms and request submissions,
- from materials you upload,
- from payment processors and transaction providers,
- from authentication or identity providers,
- from storefront systems or linked customer records,
- from technical systems, cookies, server logs, and analytics tools,
- from support communications,
- from publicly available sources where reasonably necessary for sourcing, fraud prevention, compliance, or service verification.
5. Purposes of Processing and Legal Bases
Depending on the context, we rely on one or more of the following legal bases:
- performance of a contract,
- taking steps at your request before entering into a contract,
- compliance with legal obligations,
- our legitimate interests, provided those interests are not overridden by your rights and freedoms,
- consent, where consent is required or specifically requested.
5.1 To Provide and Manage the Services
We process personal data to create accounts, authenticate users, manage dashboards, operate workflows, deliver results, issue certificates, handle sourcing requests, and provide the Services generally.
Legal basis: performance of a contract; pre-contractual steps at your request.
5.2 To Review Authentication Requests
We process item details, uploaded images, submitted documents, and related data to evaluate authentication requests, request additional materials, generate outcomes, and issue certificates or reports where applicable.
Legal basis: performance of a contract; legitimate interests in operating, quality-controlling, and defending our independent assessment services.
5.3 To Review and Handle Private Sourcing Requests
We process request data, preferences, contact information, and supporting materials to assess sourcing eligibility, manage activations, conduct sourcing work, and communicate sourcing updates.
Legal basis: performance of a contract; pre-contractual steps at your request; legitimate interests in operating and improving our sourcing services.
5.4 To Process Payments and Issue Invoices
We process transaction-related data to confirm payments, prevent fraud, manage disputes, administer payment-linked service activation, and maintain billing and accounting records.
Payments are processed through Stripe. Invoices and billing documentation are prepared through Billingo.
Legal basis: performance of a contract; compliance with legal obligations; legitimate interests in fraud prevention, accounting, invoicing, and business operations.
5.5 To Link Service Accounts to Storefront Customer Accounts and Administer Store Credit
Where applicable, we process customer identity and account linkage data to connect the Services account with the relevant Adrian's Selection store customer record, issue or prepare store credit, maintain customer continuity across the services platform and the store, and manage redemption status or related technical support.
This may involve processing through Shopify or Shopify-related systems where certain Services, benefits, or account-linking functions depend on store integration.
Legal basis: performance of a contract; legitimate interests in administering service benefits, preventing duplicate or erroneous issuance, and maintaining accurate customer records.
5.6 To Communicate with You
We process your contact details and communication records to send confirmations, updates, support replies, activation notices, security alerts, and service-related messages.
Legal basis: performance of a contract; legitimate interests in customer support, service continuity, and account security.
5.7 To Maintain Security, Prevent Fraud, and Enforce Our Terms
We process personal data to detect suspicious activity, prevent abuse, manage chargebacks, investigate misuse, enforce our legal terms, and protect the Services, our users, and our business.
Legal basis: legitimate interests in security, fraud prevention, and legal risk management; compliance with legal obligations where applicable.
5.8 To Comply with Legal, Regulatory, Tax, and Accounting Requirements
We process personal data where necessary to comply with legal obligations, maintain records, respond to lawful requests, or establish, exercise, or defend legal claims.
Legal basis: compliance with legal obligations; legitimate interests in legal defense and governance.
5.9 To Improve and Analyze the Services
We may process usage and technical data to understand how users interact with the Services, improve reliability, optimize workflows, and maintain performance.
This may include the use of Google Analytics for traffic analysis and service performance insights.
Legal basis: legitimate interests in analytics, service optimization, and operational improvement; consent where required by law for non-essential tracking technologies.
5.10 Advertising Measurement and Remarketing
We may use Meta Pixel for advertising measurement, campaign attribution, audience analytics, and remarketing, subject to applicable consent requirements.
Legal basis: consent where required by law; legitimate interests where permitted by applicable law.
5.11 Marketing and Optional Updates
If you subscribe to newsletters, launch notices, or optional marketing communications, we may process your contact details for those purposes.
Legal basis: consent where required by law; in limited cases, legitimate interests where permitted by applicable law.
6. Main Service Providers and Third Party Tools
We use the following named service providers or tools in connection with the Services:
- Lovable.dev for application development, implementation, workflow building, or related product infrastructure,
- Supabase for backend functions, database services, storage, authentication-related features, and related technical infrastructure,
- Stripe for payment processing, transaction management, and payment-related fraud and dispute handling,
- Google Analytics for traffic analytics, usage measurement, and service performance insights,
- Meta Pixel for advertising analytics, campaign measurement, audience creation, and remarketing, subject to applicable consent requirements,
- Shopify for customer account linkage, store integration, store credit related workflows, and continuity between the Services platform and the Adrian's Selection store,
- Billingo for invoice issuance, billing administration, and related accounting documentation.
Depending on the context, these providers may act as our processor, independent controller, or both in relation to different processing activities.
6.1 Contact Details of Main Service Providers and Related Third Parties
For transparency purposes, the main service providers and related third parties used in connection with the Services may be identified as follows:
Lovable.dev
- Provider: Lovable Labs AB
- Contact email: dpo@lovable.dev
- Privacy contact email: privacy@lovable.dev
- Address: Box 190, 101 23 Stockholm, Sweden
- Privacy information: https://lovable.dev/privacy
Supabase
- Provider: Supabase, Inc.
- Privacy contact email: privacy@supabase.io
- Contact page: https://supabase.com/contact-us
- Privacy information: https://supabase.com/privacy
Stripe
- Provider: Stripe Payments Europe, Ltd. / Stripe Technology Europe, Limited, as applicable
- Privacy contact email: privacy@stripe.com
- Address: 1 Wilton Park, Wilton Place, Dublin 2, D02 FX04, Ireland
- Contact page: https://stripe.com/contact
- Privacy information: https://stripe.com/privacy
Google Analytics
- Provider: Google Ireland Limited
- Address: Gordon House, 4 Barrow St, Grand Canal Dock, Dublin 4, D04 V4X7, Ireland
- Privacy Help Center: https://support.google.com/policies/answer/9581826
- Privacy information: https://policies.google.com/privacy
Meta Pixel
- Provider: Meta Platforms Ireland Ltd.
- Address: ATTN: Privacy Operations, Merrion Road, Dublin 4, D04 X2K5, Ireland
- Privacy information: https://www.facebook.com/privacy/policy/
Shopify
- Provider for EEA-related processing where applicable: Shopify International Ltd.
- Address: Attn: Data Protection Officer, c/o Intertrust Ireland, 2nd Floor 1-2 Victoria Buildings, Haddington Road, Dublin 4, D04 XN32, Ireland
- Privacy portal: https://privacy.shopify.com/
- Privacy information: https://www.shopify.com/legal/privacy
Billingo
- Provider: Billingo Technologies Zártkörűen Működő Részvénytársaság
- Address: 1133 Budapest, Árbóc utca 6. I. emelet, Hungary
- Email: hello@billingo.hu
- Website: https://www.billingo.hu/
- Privacy information: https://www.billingo.hu/adatkezelesi-tajekoztato
The providers, entities, roles, and contact details listed above may change from time to time. Where appropriate, we may update this Privacy Policy to reflect material changes.
7. Special Categories of Data and Sensitive Information
The Services are not intended to require special category personal data.
You should not submit sensitive personal data unless strictly necessary and legally permitted. This includes, by way of example, data revealing health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, biometric identifiers used for unique identification, or similar highly sensitive information.
If you voluntarily include such information in uploaded materials or communications, we may process it only to the extent necessary to handle your request, comply with law, protect legal claims, or delete or suppress it where appropriate.
8. Automated Decision-Making
We do not intend to make decisions producing legal effects or similarly significant effects based solely on automated processing unless expressly disclosed otherwise.
Our authentication and sourcing services are intended to involve human review, expert handling, and operational judgment, even where automated tools may assist with workflow, quality checks, fraud screening, or system management.
10. International Transfers
Some recipients of personal data may be located outside the European Economic Area.
Where personal data is transferred outside the EEA, we will seek to ensure that the transfer is covered by an appropriate legal mechanism, such as:
- a country benefiting from an adequacy decision,
- Standard Contractual Clauses,
- another lawful transfer mechanism recognized under applicable data protection law,
- derogations where legally available and appropriate in limited cases.
You may contact us for more information about the safeguards used for specific transfers, subject to confidentiality and legal limits.
11. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Services, maintain business records, comply with legal obligations, resolve disputes, and enforce agreements.
Retention periods may vary depending on the type of data and the purpose of processing. For example:
- account records may be retained while your account remains active and for a reasonable period afterward,
- authentication request files, certificates, and review records may be retained for audit, quality control, legal defense, and misuse prevention purposes,
- sourcing request files may be retained to manage follow-up, disputes, and operational records,
- transaction and billing records may be retained for tax, accounting, and legal compliance periods,
- technical logs may be retained for security, diagnostics, and fraud prevention for limited periods or longer where reasonably necessary,
- communications may be retained for support continuity, dispute handling, and legal defense.
Where data is no longer required, we may delete it, anonymize it, or securely archive it in accordance with applicable law and operational need.
12. Security
We take reasonable technical and organizational measures designed to protect personal data against unauthorized access, accidental loss, misuse, alteration, unlawful disclosure, and other unlawful or unauthorized processing.
These measures may include, as appropriate:
- access controls,
- account authentication measures,
- role-based permissions,
- encryption in transit and, where appropriate, at rest,
- provider-level security controls,
- logging and monitoring,
- backup and recovery processes,
- fraud prevention and anomaly monitoring,
- internal operational restrictions.
However, no online service or electronic storage system can be guaranteed to be completely secure.
13. Your Rights
Depending on the circumstances and applicable law, you may have the right to:
- request confirmation that we process your personal data,
- access a copy of your personal data,
- request correction of inaccurate or incomplete personal data,
- request deletion of personal data,
- request restriction of processing,
- object to certain processing based on legitimate interests,
- request portability of certain data you provided to us,
- withdraw consent where processing is based on consent,
- lodge a complaint with a supervisory authority.
These rights are not absolute and may be limited where an exemption or legal basis applies, for example where data must be retained for legal obligations, legal defense, fraud prevention, or the rights of others.
To exercise your rights, contact us using the details in this Privacy Policy.
We may request information necessary to verify your identity before responding. Requests will be handled in accordance with applicable law.
14. Complaints and Supervisory Authority
If you believe that your personal data has been processed unlawfully, you have the right to lodge a complaint with a supervisory authority.
In Hungary, the competent supervisory authority is the National Authority for Data Protection and Freedom of Information (NAIH).
You may also have the right to lodge a complaint with the supervisory authority in the EU/EEA country of your habitual residence, place of work, or alleged infringement, where applicable.
16. Linked Storefront and Shopify-Related Processing
Where the Services interact with the Adrian's Selection online store or related commerce systems, personal data may be processed to:
- match a Services account with a store customer account,
- issue or prepare store credit,
- verify customer identity or email matching,
- track credit redemption status,
- support purchase-related account continuity,
- investigate credit misuse, duplication, or fraud.
Where store-related data is processed, additional data may be received from or shared with Shopify or supporting service providers, subject to appropriate legal and contractual arrangements.
Store purchases, checkout pages, and separate store functions may also be governed by separate privacy terms or platform notices.
17. Children's Data
The Services are not directed to children, and we do not knowingly collect personal data from children in connection with the Services.
If you believe a child has provided personal data to us unlawfully, please contact us so that we can take appropriate steps.
18. Data Accuracy and User Responsibility
You are responsible for ensuring that the personal data and materials you submit are accurate, lawful, and up to date, and that you have the right to provide them.
You should avoid submitting unnecessary personal data, especially in uploaded receipts, screenshots, or documents where unrelated information may appear.
Where possible, you may redact information not needed for the service, provided that doing so does not interfere with the service requested.
19. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect legal, regulatory, technical, operational, or service-related changes.
If we make material changes, we may provide notice through the Services, by email, through dashboard notice, or by updating the date at the top of this Privacy Policy.
Your continued use of the Services after the effective date of an updated Privacy Policy will be subject to the updated version, to the extent permitted by law.
20. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, please contact:
21. Additional Notice Regarding Authentication and Uploaded Materials
Because the Authentication Services depend on uploaded images and supporting documents, uploaded materials may contain incidental personal data such as names, receipt details, order references, addresses, or identifying metadata.
We process such data only insofar as reasonably necessary to:
- review the item,
- assess source and documentation,
- detect inconsistencies or fraud indicators,
- generate the requested result or certificate,
- maintain quality control and legal records.
Where feasible and appropriate, we may redact, suppress, or minimize unnecessary personal data in outputs.
22. Additional Notice Regarding Sourcing Requests
Where you submit a private sourcing request, the request may reveal your shopping preferences, target brands, sizes, style interests, budget range, event timing, country of delivery, or similar commercial preferences.
We process this information solely for the purpose of assessing, activating, managing, and attempting to fulfill the sourcing request, and for related communications, account management, and fraud prevention.
We do not interpret such preference data as sensitive category data unless it independently falls within a legally protected category.
23. Data Minimization and Processing Principles
We seek to process personal data lawfully, fairly, transparently, and only to the extent reasonably necessary for the purposes described in this Privacy Policy. We also aim to keep personal data accurate, secure, and retained no longer than reasonably necessary, taking into account legal, operational, and evidentiary requirements.
End of Privacy Policy