Privacy Policy
Last updated: July 31, 2026
This Privacy Policy explains how Ingrida Grigalytė, conducting individual activity under Lithuanian business certificate No. NH412887-1 and trading as INGRIÐ LOVE (“INGRIÐ LOVE”, “we”, “us” or “our”), collects, uses, discloses and retains personal data when you visit ingrid.love, use our store, Shopify checkout or Customer Accounts, purchase goods, submit a rental or Exclusive Services request, or otherwise communicate with us.
We are the controller of the personal data processed for our own business purposes unless this Policy or another provider’s privacy notice explains that the provider acts as a separate controller.
Personal data we process
Depending on how you interact with us, we may process:
- Identity and contact data, including your name, email address, telephone number, billing and delivery address, and preferred contact language.
- Order and transaction data, including products viewed, selected or purchased, cart activity, order value, payment status, delivery method, pickup details, returns, cancellations, refunds, complaints, legal-guarantee claims and dated garment-condition records, including photographs where created for dispatch or return quality control.
- Payment-related data. Payments are processed through Shopify Payments and the payment methods offered at checkout. We receive payment status and transaction information but do not receive or store your complete payment-card number.
- Customer Account data, including authentication and session information, your profile, saved addresses and order history.
- Rental and Exclusive Services request data, including your name, email address, language, selected product, event date or requested time window, enquiry details and request reference.
- Communications, including customer-service messages, fitting arrangements, return requests, complaints and other correspondence.
- Technical and usage data, including IP address, device, browser, network connection, cookies, session identifiers, security events, consent preferences and information about how you use the Services.
- Information from service providers, including Shopify, payment and fraud-prevention providers, delivery providers and email providers where needed to operate the Services.
Please do not send payment-card details, health information or other unnecessary sensitive information through free-text forms or ordinary email.
How we collect personal data
We collect personal data:
- directly from you when you place an order, create or use an account, submit a request, arrange a fitting or pickup, contact us, or exercise a legal right;
- automatically from your device when you use the website, subject to applicable consent requirements; and
- from Shopify and other providers involved in payments, fraud prevention, delivery, email communication and operation of the Services.
Why we process personal data
We process personal data for the following purposes and legal bases:
- Providing the website and store: to operate the storefront, cart, checkout, Customer Accounts, customer support and essential security. We rely on performance of a contract, steps requested before a contract, legal obligations and our legitimate interests in operating and protecting the Services.
- Orders and payments: to accept payment, confirm, fulfil and deliver orders, arrange studio pickup, and manage cancellations, returns, refunds, complaints and legal guarantees. We rely on our contract with you and our legal obligations.
- Rental and Exclusive Services enquiries: to receive, assess and respond to a request and arrange further communication or a fitting. We rely on steps taken at your request before a possible contract. Submitting a request does not itself create a booking, confirm availability, form a rental agreement or commission Exclusive Services work.
- Security and fraud prevention: to authenticate sessions, protect accounts and payments, prevent misuse, investigate suspicious activity and maintain service reliability. We rely on legal obligations and our legitimate interests in protecting customers and the business.
- Legal and business records: to keep accounting, tax, consumer-law, complaint and transaction records and to establish, exercise or defend legal claims. We rely on legal obligations and legitimate interests.
- Consent-based processing: where required, we rely on your consent for non-essential cookies, analytics, personalisation or marketing technologies. You can withdraw consent at any time without affecting processing that occurred lawfully before withdrawal.
At the date of this Policy, INGRIÐ LOVE does not use Google Tag Manager or Google Analytics 4. If you submit the newsletter form, we use your email address and consent to add you to our Resend audience and send INGRIÐ LOVE news and offers. Subscription is single opt-in: the address is added when you select Subscribe, without a separate confirmation email. Every marketing message will provide a clear way to unsubscribe, and withdrawal of consent does not affect processing carried out lawfully before withdrawal.
Cookies, local storage and privacy choices
The Services use essential cookies and similar storage required for security, sessions, shopping carts, checkout, Customer Accounts and consent preferences. These technologies are necessary to provide features you request.
Guest wishlist selections are stored locally in your browser unless you use them to create a Shopify cart or order. You can remove this local information by clearing your wishlist or browser storage.
Where applicable law requires consent, non-essential cookies and similar technologies are not used for analytics, personalisation or advertising purposes until you provide that consent. You can review or change your choices through the cookie preferences control displayed on the Services. You may also contact us if you need assistance with a privacy choice.
Shopify and Shopify Network Intelligence
The Services are powered and hosted by Shopify. Shopify processes personal data when you visit the store, use Customer Accounts, make a purchase or otherwise interact with Shopify-powered services. Data submitted through the Services is transmitted to Shopify and relevant providers so that Shopify can provide checkout, accounts, payments-related services, orders, security, analytics and other commerce functionality.
Shopify Network Intelligence is enabled for this store. Shopify may securely use information from your interactions with our store together with information from your interactions with Shopify and other Shopify merchants to provide Enhanced Services. These services can include improved products and personalisation, store performance, fraud and security protection, and advertising-related services.
For some of this processing, Shopify acts as a separate controller and is responsible for responding to the privacy choices and rights it provides directly. Learn more in the Shopify Consumer Privacy Policy. You can exercise available Shopify-specific choices through the Shopify Privacy Portal.
Who receives personal data
We disclose personal data only where reasonably necessary for the purposes described in this Policy, including to:
- Shopify and its relevant providers for Hydrogen and Oxygen infrastructure, checkout, Customer Accounts, orders, consent management, commerce analytics, security, payments-related services and Enhanced Services;
- Shopify Payments and payment providers available through Shopify checkout;
- delivery and pickup providers selected to transport, track or securely hand over your order;
- Resend to send a server-generated rental or Exclusive Services request notification to our monitored mailbox and to store newsletter contacts, consent-related subscription data and suppression status for marketing messages;
- Hostinger Email to receive and manage messages sent to hello@ingrid.love;
- professional advisers, insurers, auditors and service providers where reasonably necessary for advice, compliance, security or legal claims;
- courts, regulators, law-enforcement bodies or other public authorities where disclosure is legally required or permitted; and
- a purchaser or successor if the business or relevant assets are transferred, subject to applicable confidentiality and data-protection requirements.
We do not disclose personal data for an unrelated third party’s own purposes unless you direct us to do so, validly consent, or the disclosure is required or permitted by law.
International transfers
Shopify, Resend and some other providers or subprocessors may process personal data outside Lithuania or the European Economic Area. Where required, such transfers rely on an applicable adequacy decision, Standard Contractual Clauses or another safeguard permitted by data-protection law.
Resend may dispatch our request-notification emails through its Ireland region, but Resend states that account data, including email metadata, logs and API records, is stored in the United States. Selecting an Ireland sending region therefore does not mean that all Resend data remains exclusively within the European Union.
You may contact us if you would like further information about the safeguards relevant to a transfer of your personal data.
How long we retain personal data
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy:
- Non-converted rental and Exclusive Services requests: ordinarily for 12 months after the last substantive communication with you.
- Orders and accounting records: ordinarily for five calendar years after the end of the year in which the relevant document was issued or received, unless a longer period is legally required.
- Complaints, guarantees, disputes and legal claims: for as long as the matter remains active and afterward for any applicable limitation or mandatory retention period.
- Customer Account data: for as long as needed to provide the account and afterward only as needed for orders, legal obligations, security, disputes and deletion handling.
- Guest wishlist data: locally in your browser until you remove it or clear the relevant browser storage.
- Newsletter contacts: while you remain subscribed, followed by the minimum suppression information needed to honour an unsubscribe and demonstrate compliance.
- Garment-condition records: ordinarily for 90 days after delivery or completion of a return, or longer where reasonably necessary for an active complaint, chargeback, dispute, guarantee claim or legal claim.
- Resend email data: sent-email data may be retained by Resend for up to 30 days under its current standard retention configuration.
Deletion from an active system might not remove information immediately from protected backups, security records or mandatory archives. Access remains restricted until the information is overwritten or the applicable retention period ends.
Your data-protection rights
Subject to the conditions and exceptions in applicable data-protection law, you may ask us to:
- provide access to your personal data and a copy of it;
- correct inaccurate or incomplete personal data;
- delete personal data;
- restrict processing;
- provide portable data where applicable;
- stop processing based on legitimate interests; or
- withdraw consent where processing relies on consent. Withdrawal does not affect the lawfulness of earlier processing.
We may need to verify your identity before completing a request. Some data cannot be deleted where retention is required by law or necessary for an active dispute or legal claim.
To exercise your rights, email hello@ingrid.love.
You also have the right to lodge a complaint with the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, VDAI) or another competent supervisory authority. Information and complaint forms are available on the VDAI website.
Automated processing
We do not use solely automated decision-making that produces legal or similarly significant effects when assessing rental or Exclusive Services requests. Shopify and payment or fraud-prevention providers may use automated systems to secure accounts, assess transactions or prevent fraud, as described in their respective privacy notices.
Children
The Services are not directed to children, and we do not knowingly collect personal data from children without an applicable lawful basis or required authorisation. A parent or guardian who believes that a child has provided us with personal data may contact us to request appropriate action.
Security
We use reasonable organisational and technical measures designed to protect personal data. However, no method of transmission or electronic storage is completely secure. Please use Shopify checkout or the designated forms rather than ordinary email to provide payment information or other sensitive data.
Changes to this Policy
We may update this Policy to reflect changes in law, providers, features or our processing practices. We will update the “Last updated” date and provide additional notice where required.
Contact
The controller responsible for this Policy is:
Ingrida Grigalytė
Conducting individual activity under Lithuanian business certificate No.
NH412887-1
Trading as INGRIÐ LOVE
P. Vileišio g. 18-1
LT-10306 Vilnius
Lithuania
Email: hello@ingrid.love
Telephone: +370 631 55979