PRIVACY POLICY
Last updated: May 2026
1. DATA CONTROLLER
EP Sportwear, based in Belgium, is the data controller for all personal data collected through this website. Contact: fitnessainemei@gmail.com
2. DATA WE COLLECT
- Account data: name, email address, password (hashed)
- Order data: shipping address, order history, payment status
- Payment data: processed exclusively by Stripe — we never store card details
- Usage data: pages visited, browser type, IP address (anonymised)
3. HOW WE USE YOUR DATA
- Processing and delivering your orders
- Managing your account and authentication
- Sending order confirmations and shipping notifications
- Improving our website and services
- Complying with legal obligations (Belgian and EU law)
4. LEGAL BASIS (GDPR)
We process your data based on: (a) contract performance — to fulfil your order; (b) legitimate interest — to improve our services; (c) legal obligation — accounting and tax records; (d) consent — for marketing communications.
5. THIRD PARTIES
- Stripe: payment processing. Stripe is PCI-DSS compliant. Stripe Privacy Policy
- Hosting provider: your data is stored on secure servers within the EU
6. DATA RETENTION
We retain your data for as long as your account is active or as required by law. Order data is kept for 7 years in accordance with Belgian accounting regulations. You may request deletion at any time.
7. YOUR RIGHTS
Under GDPR you have the right to: access your data · correct inaccuracies · request deletion · restrict or object to processing · data portability · withdraw consent at any time.
To exercise any right, contact us at fitnessainemei@gmail.com. You may also lodge a complaint with the Belgian Data Protection Authority (APD): dataprotectionauthority.be
8. COOKIES
We use strictly necessary cookies for authentication and cart functionality. We ask for your consent before using any analytics or preference cookies. You may withdraw consent at any time by clearing your browser cookies.