Last updated: 10 September 2025
DownTownSounds (“we,” “our,” “us”) respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share information when you use our website and services.
1. Information We Collect
We collect the following categories of personal data when you purchase products from our online shop:
- Name and surname
- Email address
- Billing and shipping address
- Payment details (processed securely by our payment providers)
Name and email address (when a user submits a contact form).
2. How We Collect Information
Personal data is provided directly by you when you:
- Place an order through our Woocommerce shop
- Submit payment and shipping details at checkout
- When you voluntarily provide information through our contact form.
We do not use tracking or analytics scripts.
3. Purpose of Processing
We use your personal data for the following purposes:
- To process and fulfill your order
- To arrange production and shipping via our service partners
- To provide customer support and communicate about your order
- To respond to inquiries and provide customer support.
We do not use your personal data for profiling, advertising, or analytics.
4. Sharing of Information
We share your data only with third parties necessary to provide our services:
- Gelato – Our print-on-demand partner responsible for production, order fulfillment, and shipping.
- PayPal – Our payment provider, which securely processes payment transactions. When you choose PayPal at checkout, certain information required to process the payment will be transferred directly to PayPal in accordance with their privacy policy.
- Payment processors – where applicable, to securely process transactions.
- Brevo – Our email service provider, which securely relays contact form submissions to us.
We also provide optional embedded content from Mixcloud and Soundcloud. These services may collect information if you consent to loading their iframes. No data is shared until you provide explicit consent.
5. Cookies
We use cookies strictly for the functioning of the website (e.g., enabling the shop and user sessions). These cookies do not store personal information and are not used for tracking or analytics.
6. Data Security
We take appropriate technical and organizational measures to protect your data, including:
- SSL encryption across the website
- Hosting on secure infrastructure (Hetzner Cloud)
- Protection via Cloudflare services, including Turnstile for form and download security
- Limited access to data on a need-to-know basis
7. Legal Basis for Processing (GDPR)
We process personal data under the following legal grounds:
- Contractual necessity – to fulfill and deliver your order
- Consent – for optional embedded third-party content (Mixcloud, Soundcloud)
- Legal obligation – where required for accounting or tax purposes
- Consent – when you voluntarily provide personal information via the contact form.
- Legitimate interest – to respond to user inquiries.
8. Your Rights
As a data subject under the GDPR, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate or incomplete data
- Request deletion of your data where legally applicable
- Withdraw consent at any time (for optional services such as embedded content)
- Request restriction or object to processing under certain conditions
- Receive a copy of your data in a portable format
To exercise your rights, please contact us (see Section 10).
9. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, including legal, accounting, or reporting obligations.
Contact form submissions are retained only as long as necessary to handle the inquiry, unless legal obligations require otherwise.
10. Contact
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, you may contact us via our website contact form.
11. Updates to this Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Updates will be posted on this page with a revised “Last updated” date.