Development placeholder — final text under review by counsel before launch.
Privacy Policy
Your data, handled with care
Last updated: 26 May 2026
This policy explains what personal data we collect when you visit mrsmood.com or place an order, on what legal basis we process it, and the rights you have under the EU General Data Protection Regulation (GDPR).
1. Data controller
Mrs. Mood Studio [PLACEHOLDER: registered legal entity], [PLACEHOLDER: street, postal code, city, country]. Email: privacy@mrsmood.studio. We are the controller of personal data processed via this website within the meaning of Art. 4(7) GDPR.
2. Personal data we collect
Account & order data: name, billing and shipping address, email, phone (optional), order history. Payment data: handled by our payment service providers (PayPal, Stripe — added at M3); we never store full card numbers. Communication data: messages you send to our support inbox. Technical data: IP address (truncated), browser type, referrer, pages visited, locale preference cookie. Newsletter data (optional): email and language preference, only if you sign up.
3. Legal basis for processing
Order fulfilment and customer service: Art. 6(1)(b) GDPR (performance of a contract). Legal record-keeping (invoices, tax records): Art. 6(1)(c) GDPR (legal obligation, §147 AO — 10-year retention). Newsletter: Art. 6(1)(a) GDPR (consent), withdrawable any time. Fraud prevention and site security: Art. 6(1)(f) GDPR (legitimate interest).
4. Cookies and tracking
We use a small set of cookies described in detail in our Cookie Policy. We do not use Google Analytics, Meta Pixel, or any third-party advertising network. Analytics (if any) is first-party and aggregate; it does not identify individual visitors.
5. Sharing and third parties
We share data only with processors strictly needed to fulfil your order: payment service providers (PayPal, Stripe), shipping carriers (DHL, DPD, depending on destination), email infrastructure (Resend), and hosting (Vercel — EU region where available). Each is bound by a Data Processing Agreement (DPA) under Art. 28 GDPR. We do not sell, rent, or trade personal data.
6. International transfers
Where a processor stores data outside the EU/EEA (e.g. US-based providers), we rely on the EU-US Data Privacy Framework or Standard Contractual Clauses (SCCs) under Art. 46 GDPR. The list of processors and their data location is available on request.
7. Your rights
Under GDPR Articles 15-22 you have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data. To exercise any of these rights write to privacy@mrsmood.studio — we respond within one month. You also have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your residence ([PLACEHOLDER: list responsible Datenschutzbehörde once company seat is fixed]).
8. Retention and changes to this policy
Order data is kept for the statutory retention period (10 years for tax records in Germany; varies by jurisdiction). Account data is kept until you request deletion. Newsletter data is kept until you unsubscribe. We may update this policy when our processing changes — material changes will be communicated by email to active customers and announced on this page with the date above.
Questions: privacy@mrsmood.studio.