Privacy policy
Last updated 18 September 2026
This policy explains what personal data we process when you visit mojaluc.si, design a gift with a name, place an order, or sign up for the newsletter and the Birthday Club — why we need it, who else sees it, how long we keep it and what you can ask of us.
It describes what the shop actually does, not what shops do in general. Where processing depends on your consent, it says so. We process personal data in accordance with the General Data Protection Regulation (GDPR) and the Slovenian Personal Data Protection Act (ZVOP-2).
Data controller
Miha Vidakovič s.p.
Huje 5 4000 Kranj Slovenija
For any question about privacy, or to exercise your rights, write to us at info@mojaluc.si.
1. In short
- For an order we need your email, your name and a delivery address; a phone number is optional.
- We never see your payment card details — payment is handled entirely by Stripe.
- The name you enter for personalisation is often a child’s. We use it only for the preview and to make the gift.
- If you upload a photo for the jigsaw puzzle, only the cropped part reaches us and only in black and white; photos with no order behind them are deleted after 90 days.
- Analytics and session recordings load only if you accept them, and the Meta advertising pixel only if you also accept advertising. In recordings all text and everything you type is masked.
- We send the newsletter, birthday reminders and the reminder about an unfinished purchase only if you ask for them; every newsletter carries an unsubscribe link.
- We do not sell data, and we do not pass it to anyone for their own marketing.
- You can ask to see, correct or delete your data at any time.
2. Visiting the site
Every visit automatically records technical data: IP address, time of the request, page address and browser details. The site is hosted by Cloudflare, which keeps these logs for 7 days; our own server’s logs are rotated automatically and kept for no longer than five weeks.
We use this data only to run the site, keep it secure and fix faults, not to find out who you are. The legal basis is our legitimate interest in a working, secure site (Article 6(1)(f) GDPR).
If you arrive through a link in an ad or an email, we remember its campaign tags (utm_source, utm_medium, utm_campaign, utm_term, utm_content) while the tab is open and store them with your order if you place one. That tells us which campaign led to a purchase. The tags contain no personal data and are not sent to anyone.
3. Personalisation and the 3D preview
When you type a name or other text for personalisation, we build a 3D preview of the gift from it. To do that, the text with the chosen size and colour is sent to our server, which builds and stores the model. The name is often a child’s, so we treat it as personal data even when it is not yours.
A preview nobody opens for 30 days and that is not part of an order is deleted automatically. When you place an order, the text is stored with the order and turned into a production file, which we process on our own equipment in our workshop. Files tied to an order are kept for 24 months — long enough to make the gift again if it arrives damaged or gets lost — and then deleted.
The photo puzzle asks you to upload a photo. You crop it in your browser, so only the cropped part reaches us, and it arrives already in black and white — the colour original stays on your device. We build the preview and, later, the print file from that crop. The data a camera writes into a photo (the device, and where it was taken) is removed.
A photo that is not part of an order is deleted 90 days after it is uploaded. If you place an order with it, it is kept with the order for 24 months so the gift can be made again if it has to be; an erasure request deletes it along with everything else.
The legal basis is performance of the contract, or steps taken at your request before entering into it (Article 6(1)(b) GDPR). On an erasure request we remove the text from the order, from the previews and from the production files.
4. Placing an order
At checkout you enter the data we need to carry out your order:
- your email address — for the order confirmation, the purchase receipt and updates on the order;
- your name and delivery address (street, postcode, town, country) — for the parcel;
- your phone number, if you give one — so the courier can call you;
- the contents of your basket, including the personalisation text, any discount code and the “Skip the queue” choice;
- the language you order in — so we write to you in the same language.
The legal basis is performance of the contract (Article 6(1)(b) GDPR). We also have to keep order records under accounting and tax law (Article 6(1)(c) GDPR).
Orders are stored in a database on a server in the European Union (Hetzner Online GmbH, Finland). If we cannot carry out an order for technical reasons — for example because an item sold out while you were paying — we cancel it, refund the full amount and tell you by email.
5. Payment
Payment takes place on the payment page of Stripe (Stripe Payments Europe, Ltd., Ireland). You enter your card or other payment details directly with Stripe; they never reach our servers and we cannot see them.
We send Stripe your email address, your delivery address, the list of items with the personalisation description (visible on the payment page and on Stripe’s receipt), the amounts and the order number. From Stripe we receive only confirmation of whether the payment succeeded and what we need to issue a refund.
Stripe also processes payment data as an independent controller — to prevent fraud and meet its own legal obligations — under its privacy policy at stripe.com/privacy.
6. Emails about your order
We send the following messages to the email address on the order as part of carrying it out:
- an order confirmation with a “Purchase receipt” attached as a PDF;
- a notice when we dispatch the parcel;
- a notice if the order is cancelled or refunded;
- one message about 7 days after delivery asking you to review the gift — not sent if you have unsubscribed from our messages;
- one reminder about 24 hours after an order that was not paid — only if you explicitly choose it at checkout. It lists the items and has a link that puts them back in your basket; it is not sent if you complete the purchase or place a new order in the meantime, and it is never repeated.
Messages are sent through Resend (Resend, Inc., USA), which receives the email address and the content of the message with its attachment. So that we can show what we sent, we keep a record of each message: recipient, type, subject, time and delivery status — not the content.
The legal basis for order notices is performance of the contract; for the review request it is our legitimate interest in learning how the gift was received (Article 6(1)(f) GDPR); and for the reminder about an unfinished purchase it is your consent, recorded with the order (Article 6(1)(a) GDPR). You can object to review requests at any time.
7. Delivery and packing
For delivery we hand the parcel to a courier. When we ship with GLS, we give it the name, address, phone number (if you gave one), email address for delivery notifications, order number and a short description of the contents, for the label and the delivery. GLS uses this data to deliver the parcel and to tell you about it.
We may also post a parcel with another carrier; in that case the label shows the recipient’s name and address.
For packing we print the purchase receipt, which shows the name, address, email address and the order contents. It is printed on our own printer in the workshop and nobody else receives it. The legal basis is performance of the contract (Article 6(1)(b) GDPR).
8. Customer account
An account is optional — you can buy without one. If you create one, we store your name, email address and your password in hashed form, which cannot be turned back into the password. Each sign-in creates a session that stores your IP address and browser details; a session lasts 30 days.
The account shows your orders and your Birthday Club details. The legal basis is performance of the contract for the account (Article 6(1)(b) GDPR). On request we delete the account together with all its sessions.
9. Newsletter
You can sign up in the pop-up on the site, at checkout, or when joining the Birthday Club. We store your email address, where and when the sign-up was made, and the discount code you receive on signing up, which is tied to your email address. We send news, offers and promotions from the shop.
The legal basis is your consent (Article 6(1)(a) GDPR). Every message has a one-click unsubscribe link, and unsubscribing takes effect immediately — including for any reminder already scheduled. After you unsubscribe, the address stays on a suppression list so that we do not write to you again; on request we delete it entirely.
10. Birthday Club
You can register one or more children in the Birthday Club. For each we store a name and the day and month of the birthday — nothing else. We do not collect or store the year of birth, so we hold no date of birth and the child’s age cannot be derived from what we keep. The name is needed so the reminder can say which child it is about.
About three weeks before the birthday we send you a reminder with a discount code. We use the data solely for that reminder and keep it until you withdraw consent (Article 6(1)(a) GDPR). The form is submitted by a parent or guardian, who confirms this when signing up.
Every message carries a link where you can add, correct or remove a child at any time — removing one stops their reminder. Unsubscribing from the newsletter deletes all of it, and so does a deletion request.
11. Back-in-stock alerts
If an item is out of stock, you can leave your email address so we can tell you when it is available again. We store the address and the item and send one notification. The legal basis is your request, that is your consent (Article 6(1)(a) GDPR); we delete the record on request.
12. Product reviews
Once your order has been dispatched, you can review the gift through a link in an email. We store the rating, the title and text of the review, the name it should be published under, the language and the email address from the order — the email address is never published. Every review is checked before it is published. A published review on the product page shows the name you gave, the rating, the text, the date and any reply from us. The legal basis is your consent by submitting the review (Article 6(1)(a) GDPR); we remove a review on request.
13. When you write to us
When you email us, we use your email address and the content of your message to reply and resolve the matter. We keep messages for as long as needed to resolve it and to deal with any claims arising from it. The legal basis is performance of the contract where it concerns an order, and otherwise our legitimate interest in answering questions (Article 6(1)(b) and (f) GDPR).
14. Cookies and browser storage
The shop stores a little data in your browser — in cookies and in local storage (localStorage, sessionStorage). Essential items are stored without consent because the shop does not work without them; everything else only once you accept it in the cookie banner.
Essential, without consent:
- cart (local storage) — your basket, including personalisation text, so it is still there when you come back; kept until you empty it or clear your browser data;
- analytics_consent, marketing_consent and consent_version (local storage) — your choice in the cookie banner and which version of the question it answers;
- newsletter_prompt (local storage) — so the newsletter pop-up is not shown again once you close it or sign up;
- utm (session storage) — campaign tags, while the tab is open;
- checkoutEmail and Birthday Club form drafts (session storage) — so you need not type your email again after buying and an unfinished entry is not lost; deleted when you close the tab or submit the form;
- the customer account session cookie (store.…) — only if you sign in; valid for 30 days;
- cart_restore (cookie) — only when you open the link in the unfinished-purchase reminder: it holds the order reference for at most an hour so we can refill your basket, and is deleted once used.
With analytics consent: the Google Analytics cookies _ga and _ga_… (by default up to two years), the PostHog cookie and local storage entry ph_…_posthog (by default one year), and ab_visitor (local storage) — a random identifier that keeps showing you the same version of a page while we test two versions.
With advertising consent: the Meta cookies _fbp and _fbc (by default 90 days) and meta_purchases_sent (local storage) — the numbers of recent orders already reported to Meta, so the same purchase is not reported twice.
You can change your choice at any time through “Cookie settings” in the footer. When you withdraw consent, we delete those tools’ cookies and stored data from your browser and reload the page, so the tools no longer load. You can also delete or block cookies in your browser settings.
15. Analytics: Google Analytics and PostHog
If you choose “Analytics only” or “Accept all” in the cookie banner, two analytics tools are loaded. We use them to learn which pages are read, where a purchase gets stuck and which version of a page works better. Without that consent neither of them loads. The legal basis is your consent (Article 6(1)(a) GDPR).
Google Analytics 4 (Google Ireland Ltd.) receives data about the visit: the page address, the page you came from, your device and browser type, an approximate location Google derives from your IP address, and events in the shop — viewing a product, adding to cart, starting checkout and buying, with the product and the amount. For personalisation we send it only the length of the name you typed, never the name itself.
PostHog (PostHog, Inc., servers in the USA) receives the same kinds of visit and event data, clicks on the page, and your IP address, from which it derives an approximate location. We do not send it the text of the elements you click on.
Session recordings (PostHog):
- PostHog records how you move through the site — mouse movements and clicks, scrolling, moving between pages and the layout of each page. A recording shows us where a visit gets stuck.
- ALL text on the page and everything you type into any field is masked in a recording. A name for personalisation, your email, your delivery address and all other content appear as asterisks, whichever page they are on.
- The 3D preview of a product, which shows the name you entered, is not recorded, and neither is the content of drawing surfaces (canvas).
- We do not record the content of network requests (such as basket or order data), their headers, or messages in the browser console.
- Payment takes place on Stripe’s page, outside our shop, so no recording captures it.
- Recordings are kept for 30 days and then deleted automatically. PostHog keeps other analytics data for one year, and Google Analytics for at most 14 months.
These settings are written into the shop’s code rather than the tools’ settings, so a change in a provider’s dashboard cannot widen them. From the page addresses PostHog receives, we remove the tokens that open an order page or the Birthday Club editor. We do not link your name, email or address to analytics data, and we do not tell anyone who you are.
16. Advertising: the Meta Pixel
If you choose “Accept all” in the banner, the Meta Pixel (Meta Platforms Ireland Ltd.) is loaded as well. We use it to measure which visits and purchases come from our Facebook and Instagram ads, and Meta also uses this data to show ads.
Meta receives data about the visit — the page address, your IP address, browser details and its own cookies — and, when you view a product, add it to your cart, start checkout or buy, the product, the amount and, for a purchase, the order number. The pixel does not read form fields, so we never send it your name, email address, postal address or a name you enter for personalisation.
For collecting this data and passing it to Meta, Moja Luč and Meta are joint controllers (Article 26 GDPR); Meta carries out any further processing as an independent controller under its own privacy policy. The legal basis is your consent (Article 6(1)(a) GDPR). Without it the pixel is not loaded, and declining does not affect your purchase.
17. Who else receives data
We pass data only to those who need it for a purpose described above:
- Stripe Payments Europe, Ltd. (Ireland) — payments;
- Resend, Inc. (USA) — sending email;
- Cloudflare, Inc. (USA) — hosting the site and storing images, previews, production files and encrypted database backups;
- Hetzner Online GmbH (Germany) — the database server, located in Finland;
- GLS — parcel delivery;
- Google Ireland Ltd. (Ireland) — analytics, only with your consent;
- PostHog, Inc. (USA) — analytics and session recordings, only with your consent;
- Meta Platforms Ireland Ltd. (Ireland) — ad measurement, only with advertising consent.
Providers that process data on our behalf may use it only on our instructions and for the purpose we gave it to them for. We disclose data to public authorities where the law requires it. We do not sell data.
18. Transfers outside the European Union
Some providers (Resend, PostHog, Cloudflare and affiliates of Stripe, Google and Meta) also process data in the USA. Such transfers rely on the European Commission’s adequacy decision for the EU-U.S. Data Privacy Framework where the provider participates in it, and otherwise on the standard contractual clauses adopted by the European Commission (Article 46 GDPR).
19. How long we keep data
- Order records: 10 years after the end of the year in which the order was placed, as tax and accounting law requires; after that we delete or anonymise them. The same applies to records of messages sent about an order.
- Personalisation previews: 30 days after last viewed, unless part of an order. Production files: 24 months.
- Uploaded photos: 90 days after upload if no order holds them; otherwise 24 months, the same as production files.
- Customer account: until you ask us to delete it. Sign-in sessions: 30 days.
- Newsletter and Birthday Club: until you withdraw consent; an address on the suppression list until you ask us to delete it.
- Back-in-stock alerts and reviews: until you ask us to delete them.
- Technical logs: 7 days at Cloudflare, at most five weeks on our server.
- Encrypted database backups: 30 days.
- Session recordings: 30 days; analytics data in PostHog: one year; in Google Analytics: at most 14 months.
- Email you send us: as long as needed to resolve the matter and deal with any claims arising from it.
20. Your rights
You have these rights over your personal data:
- access — we tell you what data about you we process and give it to you in a machine-readable file;
- rectification — we correct inaccurate data and complete incomplete data;
- erasure (the “right to be forgotten”) — we delete your data, except what the law requires us to keep (see the next section);
- restriction — for a while we only store your data and do not use it, for example while we check whether it is accurate;
- portability — you receive the data you provided in a structured, machine-readable format;
- objection — you may object to processing based on legitimate interest, and to direct marketing at any time without giving a reason;
- withdrawing consent — you may withdraw consent at any time, as easily as you give it: for cookies through “Cookie settings” in the footer, for email through the unsubscribe link in every message. Withdrawal does not affect the lawfulness of processing before it.
Send your request to info@mojaluc.si. We reply without undue delay and within one month at the latest; for complex requests this can be extended by up to two further months, and we will tell you if it is. Exercising your rights is free of charge.
So that we do not hand your data to someone else, we may check that the request really comes from the owner of the email address or order — usually by replying to the email address on the order.
21. What we cannot delete
On an erasure request we delete your account, your newsletter sign-up together with your Birthday Club details, back-in-stock alerts and reviews. From orders we remove the email address, name, address, notes, campaign tags and personalisation text, and we delete the previews and production files.
What remains is the order record with the country and postcode needed to evidence the VAT treatment, together with the amounts and dates — accounting law requires this and Article 17(3)(b) GDPR permits it. The shipping label, if one was issued, a record that a discount code was used, and the subjects of messages sent, without the email address, also remain. Data in encrypted backups disappears when those backups expire after 30 days.
Data Stripe holds as an independent controller is deleted by Stripe under its own obligations. We do not link analytics data to your name or email address, so it cannot be looked up by them; session recordings are deleted after 30 days.
22. Children
The shop is intended for adults. Data about children — a name for personalisation and Birthday Club details — is given to us by a parent, guardian or other adult customer. We do not collect data directly from children and do not send them messages. People under 15 should not use the shop on their own.
23. Security
The site works only over an encrypted connection (HTTPS). Only people who need data for their work have access to it. Account passwords are stored hashed, never in readable form, and access keys to external services are stored encrypted. Database backups are encrypted. Payment card details never reach us.
24. Automated decision-making
We make no decisions based solely on automated processing that have legal or similarly significant effects on you (Article 22 GDPR). The only automatic step is cancelling an order and refunding it in full when an item sells out while you are paying.
25. Complaints to the supervisory authority
If you believe we process data unlawfully, you may lodge a complaint with the Information Commissioner of the Republic of Slovenia (Dunajska cesta 22, 1000 Ljubljana, gp.ip@ip-rs.si, www.ip-rs.si) or with the supervisory authority in the country where you live or work. You are of course welcome to write to us first at info@mojaluc.si so we can try to resolve it together.
26. Changes to this policy
We change this policy when we change how we process data or when the law requires it. The current version is always published on this page, with the date of the last change at the top. If a change affects processing based on consent, we ask for your consent again.