UK & European Privacy Policy
Last updated: 17 August 2026
This UK and European privacy addendum explains VUNRO’s lawful bases, international transfers, individual rights and complaint process. It supplements our Global Privacy Policy.
Controller
GLOBAL TRADING INNOVATIONS LIMITEDtrading as VUNRO
Unit B, 3/F., Kai Wan House
146 Tung Choi Street
Kowloon, Mongkok
Hong Kong
Privacy email: support@getvunro.com
Scope and personal data
This addendum applies where the UK GDPR, EU GDPR or closely related European data-protection law applies. The Global Privacy Policy describes the identity, contact, account, order, payment-confirmation, delivery, support, review, marketing-choice, device, cookie, approximate-location, fraud-prevention and privacy-request information we process, its sources and recipient categories.
We do not intentionally request special-category data. Please do not send health or similarly sensitive information unless it is genuinely necessary for your request.
Purposes and lawful bases
| Purpose | UK/EU lawful basis |
|---|---|
| Accounts, checkout, payment confirmation, fulfilment, delivery, returns and refunds | Taking requested pre-contract steps and performing our contract with you. |
| Order enquiries and customer support | Contract and our legitimate interest in providing effective support. |
| Fraud prevention, account security and protection of the store | Our legitimate interests in preventing fraud and maintaining security; legal obligation where applicable. |
| Tax, accounting, consumer-law, privacy-request and complaint records | Legal obligation; otherwise our legitimate interests in proper records and legal claims. |
| Essential store, account, checkout and security technology | Contract and legitimate interests; applicable cookie-law exemptions. |
| Optional analytics, personalisation and advertising technology | Consent where UK/EU cookie law requires it. Where consent is not required, our proportionate legitimate interests in measuring and improving the store. |
| BladeClub and other direct marketing | Consent, or the limited existing-customer exception where law permits. You can opt out at any time. |
| Legal claims, misuse prevention and regulatory cooperation | Legal obligation and our legitimate interests in protecting VUNRO, customers and legal rights. |
Where we rely on legitimate interests, we consider necessity, reasonable expectations and the impact on your rights. Information requested at checkout is needed to accept and fulfil an order; optional analytics and marketing choices are not required to purchase.
Recipients and international transfers
We disclose information only as reasonably necessary to Shopify; payment and fraud-prevention providers; fulfilment, delivery and returns providers; store, hosting, security and support providers; email, review, analytics, advertising and affiliate providers subject to your choices; professional advisers; and authorities where required by law.
VUNRO is established in Hong Kong. Shopify and other providers may process information in the United States, Canada, the UK, EEA and other countries. Where a destination lacks an applicable adequacy decision, we use or require an appropriate recognised safeguard where the law requires one, such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum or another approved mechanism, together with supplementary measures where appropriate. Shopify also uses approved Binding Corporate Rules and contractual safeguards for relevant transfers. Email us to request information about the safeguard relevant to your data.
Retention and security
We keep personal data only while needed for the stated purpose and applicable tax, accounting, consumer, fraud-prevention, dispute and compliance obligations. Order and transaction records are kept for the applicable statutory recordkeeping period; accounts while active and afterwards only for security, disputes or records; support, complaint and privacy-request records until resolved and for the period needed to demonstrate compliance; marketing data until opt-out, followed by a limited suppression record; and cookie or device data for the period stated in the preference tool or needed for security. We delete or anonymise data when no continuing lawful reason remains.
We use proportionate technical and organisational safeguards. No online system can be guaranteed completely secure.
Your UK and EEA rights
Subject to legal conditions and exceptions, you may ask for access, correction, deletion, restriction, portability, or to object to processing based on legitimate interests. You may stop direct marketing and withdraw consent at any time. Withdrawal does not affect processing before it.
We may verify identity. We normally respond within one month and will explain any lawful extension, refusal or fee. We do not make decisions based solely on automated processing that produce legal or similarly significant effects for customers.
Data-protection complaints
Email support@getvunro.com with the subject Data protection complaint. Where UK complaint-handling law applies, we will acknowledge the complaint within 30 days, investigate it and communicate the outcome without undue delay.
You may also complain to the UK Information Commissioner’s Office or, in the EEA, the authority where you live, work or believe an infringement occurred. The European Data Protection Board lists EEA authorities.
How these privacy request forms work
The form sends the email address, request type and legal regime to Avada, our privacy-request form provider. As part of the same deliberate submission, it also sends the same request to VUNRO's Cloudflare-hosted fallback for secure logging and Freshdesk case handling. This fallback send happens for every deliberate submission and is not conditional on Avada confirming or failing delivery. Cloudflare Turnstile processes security signals to protect the form from automated abuse; VUNRO does not use those signals for advertising.
Avada may separately create its own request record and send a confirmation or identity-verification message. The request is reviewed manually. Submitting it does not instantly export, correct or delete data, show request history, or complete a sale or sharing opt out.
Request record retention: Security HMAC rate records are kept for no more than 2 hours. Semantic deduplication and delivery metadata are kept for no more than 30 days. Encrypted actionable request data held by Cloudflare is erased promptly after confirmed delivery to Freshdesk or an audited manual handoff; unresolved requests remain encrypted until handled. A Freshdesk compliance case may be kept for up to 6 years after closure where needed for legal, regulatory, dispute or audit purposes, and is deleted sooner when no longer needed.
Submit a privacy request
These controls create a request with our privacy-service provider. We may ask for information reasonably necessary to verify identity for access, correction or deletion. You can also email support@getvunro.com.
Access or receive a copy
Ask whether we hold information about you and request a copy where applicable.
Correct information
Ask us to correct inaccurate or incomplete account information.
View existing requests
Ask to view privacy requests associated with your email address.
Delete information
Ask us to delete eligible information. Legal, security and transaction records may need to be retained.
Children
The store is intended for adults and is not directed to children. We do not knowingly collect a child’s personal data where parental authorisation is required. A parent or guardian may contact us to request deletion.
Contact and representatives
Controller
GLOBAL TRADING INNOVATIONS LIMITEDtrading as VUNRO
Unit B, 3/F., Kai Wan House
146 Tung Choi Street
Kowloon, Mongkok
Hong Kong
Privacy email: support@getvunro.com
VUNRO’s controller privacy channel is the corporate contact above. We do not publish an owner’s or employee’s personal details. If a separate UK or EEA representative is formally required and appointed, its corporate contact details will be added here.