GDPR-Compliant Privacy Policy


At Everything But The Box, we are committed to protecting your personal data and respecting your privacy. This policy explains how we collect, use, and safeguard your information in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR).

📋 What Data We Collect
We may collect and process the following types of personal data:
Identity data: name, company name (if applicable).
Contact data: email address, phone number, shipping and billing address.
Transaction data: payment details, order history.
Technical data: IP address, browser type, device information.
Usage data: interactions with our website, preferences, and feedback.


⚙️ How and Why We Use Your Data
We process your data only when we have a legal basis to do so: | Purpose | Legal Basis | |--------|-------------| | To process and deliver your order | Contractual necessity | | To respond to inquiries or support requests | Legitimate interest | | To send updates or promotional offers (if opted-in) | Consent | | To improve our products and website | Legitimate interest | | To comply with legal obligations | Legal requirement |

⏳ Data Retention
We retain your personal data only as long as necessary:
For orders: up to 5 years to comply with accounting and warranty obligations.
For marketing (with consent): until you unsubscribe.
For inquiries: up to 1 year after resolution.


🔄 Sharing Your Data
We do not sell your data. We may share it with trusted third parties only when necessary:
Payment processors (e.g., Stripe, PayPal).
Shipping providers.
Email platforms (e.g., Mailchimp, for newsletters).
Web analytics tools (e.g., Google Analytics).

All partners are GDPR-compliant and process data securely under contractual agreements.

🌍 International Transfers
If your data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as:
Standard Contractual Clauses (SCCs).
Data processing agreements with service providers.


🍪 Cookies & Tracking
Our website uses cookies to enhance your experience. You can manage your cookie preferences at any time. For full details, please see our [Cookie Policy].

🧑 Your Rights Under GDPR
You have the right to:
Access your personal data.
Correct or update inaccurate data.
Request deletion (“right to be forgotten”).
Restrict or object to processing.
Withdraw consent at any time.
Lodge a complaint with the Commission for Personal Data Protection (CPDP) in Bulgaria.

To exercise your rights, contact us at:

📧 [info@ebtb.eu]

🔒 Data Security
We use encryption, secure servers, and access controls to protect your data. Only authorized personnel can access it, and we regularly review our security practices.


cookie Policy

This Cookie Policy explains how Everything But The Box uses cookies and similar technologies on our website. We believe in transparency and giving you control over your data.

🔍 What Are Cookies?
Cookies are small text files stored on your device when you visit a website. They help us remember your preferences, improve site performance, and deliver relevant content.

🧠 Why We Use Cookies
We use cookies to:
Ensure the website functions properly.
Analyze traffic and usage patterns.
Personalize your experience.
Offer relevant promotions (only with your consent).


🧩 Types of Cookies We Use
Type                                         Purpose                                                      Consent Required
Essential             Enable core site functions (e.g. shopping cart, login)      No
Performance       Help us understand how visitors use the site                  Yes
Functional          Remember your preferences and settings                       Yes
Marketing          Deliver personalized ads and track effectiveness             Yes


⚙️ Managing Your Preferences
When you first visit our site, you’ll see a cookie banner that lets you:
Accept all cookies.
Decline non-essential cookies.
Customize your preferences via a detailed settings menu.

You can change your preferences at any time by clicking the “Cookie Settings” link in the footer.

🔐 Third-Party Cookies
Some cookies are set by trusted third parties, such as:
Analytics providers (e.g. Google Analytics).
Advertising platforms (e.g. Meta, Google Ads).
Embedded content (e.g. YouTube, Instagram).

These providers may process your data outside the EU. We ensure appropriate safeguards are in place.

🧽 How to Clear Cookies
You can delete cookies manually through your browser settings. For instructions, visit:
Chrome
Firefox
Safari
Edge


📬 Contact Us
If you have questions about this Cookie Policy, reach out to:

📧 info@ebtb.eu