Version of 12 August 2026

This policy explains what data we collect about you, why, who we share it with, and how long we keep it. We’ve tried to describe what actually happens rather than rewrite someone else’s template.

It is written to comply with the Law of Ukraine “On Personal Data Protection” No. 2297-VI and with the EU General Data Protection Regulation (Regulation (EU) 2016/679, GDPR) — the latter applies because we deliver orders to European Union countries.

Who processes your data

The data controller is:

Andrii Mihachov, private entrepreneur registered in Ukraine
Taxpayer registration number 2898010290
Data protection enquiries: legal@babywood.shop, telephone +380 (63) 180-38-79
The controller’s location and full details are in the “Company details” section of the Contacts page.

What data we collect

When you place an order: name and surname, telephone number, email address, delivery address, contents and total of the order.

When you write via the contact form: name, email address, telephone number, company name (if you provide one) and the text of your message.

Automatically, as you use the site: IP address, browser and device type, screen size, pages you opened, data from cookies (see the separate section), and how you behave on a page: clicks, scrolling, the order in which you moved through the site, and — in the shop — viewing a product, adding it to the basket, starting checkout and completing a paid order. This is collected by two analytics services, Google Analytics and PostHog — see “Who we share data with” and “Cookies” below.

Session recording has been on since 12 August 2026. The analytics keeps a replay of your path through the site: the sequence of pages, cursor movement, clicks and scrolling, the content of the pages you saw, and technical messages from your browser. Recordings are kept for 30 days, after which they are deleted automatically.

What the analytics does not collect: the text you type into fields. Your name, phone number, address and order note are masked in your browser, before anything is sent — they never reach a recording.

One exception is worth naming plainly: on the order confirmation page your name, phone number and address appear as ordinary text rather than in input fields — there they do end up in the recording.

What we don’t collect: your payment card details. You enter them on the payment provider’s secure page — they never reach us and we don’t store them.

Why, and on what legal basis

PurposeLegal basis
To place and fulfil your order and deliver the itemPerformance of a contract to which you are party — Art. 11(1)(3) of Law 2297-VI, Art. 6(1)(b) GDPR
Accounting and tax recordsCompliance with a legal obligation — Art. 11(1)(5), Art. 6(1)(c) GDPR
To answer your enquirySteps prior to entering into a contract — Art. 11(1)(3), Art. 6(1)(b) GDPR
To operate and secure the siteLegitimate interests — Art. 11(1)(6), Art. 6(1)(f) GDPR
To see how the site is used and fix what gets in the wayLegitimate interests — Art. 11(1)(6), Art. 6(1)(f) GDPR
To send news and offersYour consent — Art. 11(1)(1), Art. 6(1)(a) GDPR

No separate consent is needed or requested for placing an order. The basis here is the contract itself: without your name, phone number and address the item cannot be delivered. Consent is needed only for what goes beyond fulfilling the order — chiefly the newsletter — and you can withdraw it at any time.

Who we share data with

We share your data with processors acting on our instructions. The first three are needed for the order to happen at all; the last two show us what the site looks like from a visitor’s side.

WayForPay — payment service. When you pay by card, your name and surname, email, telephone, address, city, postcode, country, and the contents and total of your order are transmitted. This is needed to process the payment.

Nova Poshta, Ukrposhta, Meest Express — carriers. Name, telephone and delivery address are transmitted. This is needed to get the parcel to you.

Hostinger — the hosting provider whose servers run the site and relay our outgoing email. It has technical access to data stored on the site.

Google Ireland Limited — the Google Analytics 4 service. It receives de-identified data about how the site is used: pages viewed, referral source, device and browser type, approximate location at country and city level, and shop events — viewing a product, adding it to the basket, starting checkout and completing a paid order together with its total and contents. Your name, phone number, email and delivery address are not passed to the service: an order is identified by its number alone. Google’s advertising features (Google Signals) are switched off.

PostHog, Inc. — a product analytics service. The project is hosted in the EU Cloud region, so the data is stored within the European Union. It receives the same signals: page views, clicks and element labels, shop events, and session recordings — with the contents of input fields masked. No separate profiles are created for anonymous visitors.

We do not sell your data and do not pass it on for third-party advertising or marketing.

International transfers

The site runs on a Hostinger server located in France, where the order database is also stored. The content delivery network that serves pages to visitors uses nodes in Lithuania — that is a cache of static pages, not a place where your data is stored. PostHog data is stored within the European Union — the project is hosted in the EU Cloud region. Google Analytics is the exception: the processor is Google Ireland Limited, but Google’s infrastructure is global, so analytics data may be processed outside the EEA, including in the United States. The basis for that transfer is the standard contractual clauses within Google’s data processing terms.

Both countries are members of the European Union and therefore of the European Economic Area. Under Article 29(3) of Law 2297-VI, EEA states are recognised as providing an adequate level of data protection; no additional safeguards are required for such a transfer.

If you order delivery outside Ukraine, the data needed to prepare an international shipment is passed to the carrier and to the customs authorities of the destination country in accordance with their rules.

How long we keep data

WhatHow long
Order data (name, contacts, address, contents)3 years — the retention period for primary accounting documents under tax law
Copies of emails sent (order confirmations, notifications)14 days, then deleted automatically
Messages sent via the contact formFor as long as the correspondence continues, then within mail logs for 14 days
Newsletter dataUntil you withdraw consent
Server technical logsPer the hosting provider’s policy
Analytics visitor identifier (_ga)400 days (≈ 13 months) — after that you are a new visitor to the service
Analytics data in Google Analytics14 months — beyond that only de-identified aggregate reports remain
Session recordings30 days, then deleted automatically

Once the relationship ends and the statutory retention periods expire, the data is deleted (Article 15 of Law 2297-VI).

Cookies

Cookies are small files that a website stores in your browser.

What we use as of 7 August 2026:

Technical — the site does not work without them:

  • WooCommerce cookies — hold your basket contents and your session as you move around the site. Without them the basket would forget items on every page.
  • Caching cookies — speed up page loading.
  • Banner consent cookie — remembers that you’ve already dismissed the cookie notice.

Analytics — these show us how the site is used:

  • _ga, _ga_VPMKHNCXE1 — Google Analytics. The first tells visitors apart, the second holds the measurement session state; both live for 400 days. What exactly is collected is set out under “What data we collect”.
  • ph_phc_qxbDGoBhRxpkFU3od42sbuMittkkE4xv5NhzPteUU3z5_posthog — PostHog. Holds the visitor identifier and session state, and lives for 365 days. The service mirrors the same record in your browser’s local storage — it is cleared together with site data in your browser settings.
  • sbjs_* — WooCommerce’s built-in referral tracking: it remembers where you arrived from (search, social network, direct link) so that we can see it on the order.

There are no advertising cookies on this site. We do not use Google Tag Manager, Meta Pixel, retargeting or ad networks. We run two analytics services, Google Analytics and PostHog, and neither is tied to advertising: Google’s advertising features (Google Signals) are switched off and no data is passed to ad accounts.

An honest note about the banner. The cookie notice on the site informs you that cookies are used, but it is not a consent mechanism: it offers no choice and does not block cookies until you decide. The analytics in particular starts immediately, without waiting for your answer. We intend to fix this. For now we’re describing the situation as it actually is.

You can delete cookies or block them in your browser settings. Technical cookies will be disabled too, and the basket will stop working.

Your rights

You have the right to:

  • know what data we process about you, for what purpose, and with whom we share it;
  • access your data and obtain a copy;
  • rectify inaccurate or incomplete data;
  • erase your data where there is no lawful basis to keep it;
  • restrict processing or object to it;
  • receive your data in a portable format to transmit to another controller (Article 20 GDPR);
  • withdraw consent where processing is based on consent — for example, unsubscribe from the newsletter. Withdrawal does not affect the lawfulness of processing before it;
  • lodge a complaint with a supervisory authority.

To exercise any of these rights, write to legal@babywood.shop. We reply within thirty calendar days of receiving your request (Article 8(2) of Law 2297-VI).

We may ask for additional information to verify your identity — this protects you from someone else obtaining your data.

Where to complain

In Ukraine — to the Ukrainian Parliament Commissioner for Human Rights, who supervises compliance with personal data protection law, or to a court.

In the European Union — to the data protection supervisory authority of your country of residence.

How we protect data

The site runs over an encrypted HTTPS connection. Access to the site’s administration and to order data is limited to the people who need it for their work. We do not process payment card data at all — it passes through the payment service, bypassing our site.

No system is perfectly secure, and we won’t promise the impossible. If a breach occurs that puts your rights at risk, we will notify you and the supervisory authority.

Changes to this policy

We may update this policy — for instance if new services are introduced or the law changes. The current version is always on this page, with its date at the top.

If the changes are significant, we will notify you separately.