Effective date: 01.10.2025
Last updated: 01.10.2025
Toolify SIA (“we”, “our”, “the company”) operates the website toolify.lv (“the Website”). We respect your privacy and are committed to protecting your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR), applicable Latvian legislation, and industry best practices.
This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you use our Website, make purchases with us, or interact with our services.
1. Data Controller
The controller responsible for your personal data is:
Toolify SIA
Druvas iela 10A, Ogre, Ogres nov., LV-5001, Latvia
Email: toolify.website@gmail.com
Phone: +371 26 329 111
2. What Data We Collect
We collect the following categories of personal data:
-
- Registration and profile data:
Name, email address, username, password, shipping/billing address, and contact phone number. - Order and transaction data:
Payment method, order history, billing information, and delivery details. We do not store sensitive card data (it is processed by PayPal, WooPayments, and Stripe).
We may store non-sensitive metadata (e.g., payment method, last 4 digits, date). - Customer support data:
Emails you send us, including any information provided therein. Phone calls are not recorded. - Website functionality data:
IP address, device/browser information, and cookies necessary for website operation. - Reviews and ratings:
Feedback or comments you leave about products.
- Registration and profile data:
We do not collect sensitive categories of personal data (such as health information, race, religion, or political opinions).
3. How We Use Your Data
We use your personal data only for the following purposes:
-
-
To process and deliver your orders.
-
To manage user accounts and provide profile functionality.
-
To ensure delivery and payment processing.
-
To comply with tax, accounting, and consumer protection requirements in the EU and Latvia.
-
To maintain website functionality (functional cookies).
-
To respond to customer support requests.
-
To maintain website security and perform backups.
-
Legal bases for processing:
Contract performance, legal obligations, and legitimate interests (such as fraud prevention and security).
4. Data Sharing with Third Parties
We share your personal data only with trusted partners necessary for our operations:
-
- Payment processors: PayPal, WooPayments, Stripe.
- Delivery / logistics: ILIOR SIA (warehouse).
- Hosting and security: Hostinger, Wordfence Security, UpdraftPlus Backup.
- Public authorities: Only when required by law.
We do not sell or rent your data to third parties, nor do we share it with advertising or analytics service providers.
5. Data Transfer to Other Countries
We do not intentionally transfer your data outside the European Union (EU) or the European Economic Area (EEA).
If third-party service providers (such as payment processors) transfer data outside the EU, they are required to ensure GDPR-compliant safeguards (e.g., Standard Contractual Clauses).
6. Data Retention
-
-
Order Data: Retained for 5–10 years, as required by Latvian tax and accounting law.
-
User Accounts: Retained as long as the account is active. Upon account closure, data is deleted or anonymized within 30–90 days unless required by law.
-
Payment Metadata: Retained in accordance with order data retention.
-
Backups: Created via UpdraftPlus and retained for security and disaster recovery purposes; deleted according to internal rotation schedules.
-
7. Cookies
We use cookies strictly necessary for the operation of our Website. These may include:
-
-
Essential Cookies: Required for core site functions (checkout, login, cart).
-
Functional Cookies: Remember user settings such as language (via Polylang).
-
Security Cookies: Used by Wordfence and Hostinger to maintain security.
-
We do not use analytics, advertising, or third-party tracking cookies.
Our Website uses a cookie consent banner (Complianz) that allows you to review and manage your cookie preferences.
8. Your Rights
Under the GDPR, you have the following rights:
-
-
Right of Access – Request a copy of your data.
-
Right to Rectification – Correct inaccurate or incomplete data.
-
Right to Erasure – Request deletion of your data, subject to legal obligations.
-
Right to Restriction – Limit processing of your data.
-
Right to Data Portability – Request transfer of your data to another provider.
-
Right to Object – Object to certain processing (e.g., direct marketing).
-
Right to Withdraw Consent – Withdraw consent where we rely on it.
-
You can exercise these rights by:
-
Managing data via your profile account page.
-
Contacting us at: toolify.website@gmail.com or by phone: +371 26 329 111.
If you are not satisfied, you may lodge a complaint with the Latvian Data State Inspectorate (Datu valsts inspekcija).
9. Security
We take appropriate technical and organizational measures to protect your personal data, including:
-
-
SSL/TLS encryption of Website traffic.
-
Wordfence Security for malware/firewall protection.
-
Hostinger server security and monitoring.
-
UpdraftPlus encrypted backups.
-
Access controls and secure password policies.
-
10. Minors
Our services are not directed at children under 16 years of age. We do not knowingly collect data from minors.
11. Policy Updates
We may update this Privacy Policy from time to time. Changes will be posted on this page, and by continuing to use our Website after updates, you agree to the revised policy.
12. Governing Law
This Privacy Policy is governed by Latvian law and EU data protection law (GDPR).
