Privacy policy

 

Privacy Policy

 


Effective date: 17 June 2025


 

1. Who We Are

 


Rashrash OÜ, a private limited company incorporated in Estonia (registry no. 17258263) with its registered office at Lõõtsa tn 5, Lasnamäe district, Tallinn 11415, Harju County, Estonia, operates the website orabella.style and any associated mobile or web applications (together, the “Service”).

In this policy “we”, “us” or “our” means Rashrash OÜ; “you” refers to any visitor, customer or user of the Service.


 

2. Scope

 


This Privacy Policy explains how we collect, use, disclose and safeguard your personal information when you visit or purchase from the Service or otherwise interact with us. It does not cover processing by third parties that we do not control.


 

3. Personal Information We Collect

 


We collect the following categories of personal information:

 

  1. Contact identifiers – name, postal address, e-mail address, telephone number.

    • Collected directly from you. • Processed because it is necessary to perform a contract with you or because we have a legitimate interest.

  2. Account credentials – username, password, social-login ID.

    • Collected directly from you. • Processed to perform a contract with you.

  3. Commercial data – products viewed, items in cart, order history, payment token (handled by our PCI-compliant payment provider).

    • Collected from you and automatically. • Processed to perform a contract or for our legitimate interests.

  4. Device and internet activity – IP address, advertising identifier, browser type, pages viewed, timestamps, click-stream data, non-precise location.

    • Collected automatically via cookies, pixels and SDKs. • Processed on the basis of your consent or our legitimate interests.

  5. Profile and marketing data – preferences, survey responses, reviews, social-media handle.

    • Collected from you or social platforms. • Processed on the basis of your consent or our legitimate interests.

  6. Sensitive data – precise geolocation or multi-factor authentication codes (only if you opt in).

    • Collected directly from you. • Processed on the basis of your explicit consent.

 


We also create inferences about your likely interests from the information above. We do not knowingly collect data from children under 13 in the United States or under 16 in the EEA/UK.


 

Cookies and Similar Technologies

 


We employ first- and third-party cookies, pixels and SDKs for essential site functions, analytics, personalisation and targeted advertising. For details, see Section 9 and our separate Cookie Policy.


 

4. How We Use Personal Information

 


We process personal information to:

 

  1. Provide and improve the Service (fulfil orders, manage accounts, deliver customer support, debug, develop new features).

  2. Process transactions and prevent fraud, money-laundering or charge-backs.

  3. Communicate with you about orders, updates, security alerts and promotional offers (you may opt out at any time).

  4. Personalise advertising on our sites, on third-party sites and on social platforms where permitted by law.

  5. Conduct research and aggregate analytics to understand and improve our business.

  6. Comply with legal obligations and protect the rights, safety or property of you, us or others.

 


 

5. How We Disclose Personal Information

 


We do not “sell” personal information in the conventional sense. We disclose it only to:

 

  • Service providers and contractors (payment processors, fulfilment partners, hosting companies, analytics and marketing agencies) bound by confidentiality obligations.

  • Advertising partners for cross-context behavioural ads where you have not opted out.

  • Affiliates and business transferees if we reorganise, merge or sell our business.

  • Law-enforcement or regulators when required or permitted by law.

  • The public or other users if you post reviews or other user-generated content.

  • Any other party with your direction or explicit consent.

 


Certain disclosures may constitute “sharing” or “targeted advertising” under some U.S. state laws—see Section 9 for your opt-out rights.


 

6. International Data Transfers

 


We are headquartered in Estonia and use service providers worldwide. When your personal information is transferred outside your jurisdiction we rely on:

 

  • Adequacy decisions issued by the European Commission or UK Government.

  • Standard Contractual Clauses or other recognised safeguards.

  • Your explicit consent, where required.

 


 

7. Security

 


We employ organisational, technical and physical safeguards—such as TLS encryption, access controls and regular penetration testing—designed to protect personal information. No online service is 100 % secure, and we therefore cannot guarantee absolute security.


 

8. Retention

 


We keep personal information only as long as necessary for the purposes described in this policy, or as required by law, to resolve disputes and enforce our agreements. When data is no longer required, we delete or anonymise it.


 

9. Your Privacy Choices and Rights

 


 

Global Choices (available to all users)

 

 

  • Marketing e-mails – click “Unsubscribe” in any message.

  • SMS / WhatsApp – reply “STOP” to the message.

  • Push notifications – disable them in your device settings.

  • Browser cookies – adjust your browser preferences or use recognised opt-out signals such as Global Privacy Control.

  • Targeted advertising – use the “Your Privacy Choices” or “Do Not Sell or Share” link on our site, or industry tools such as DAA or NAI to opt out.

 


 

Region-Specific Rights

 

 

  • EEA/UK (GDPR & UK GDPR) – You may request access, rectification, erasure, restriction, portability or objection to processing, and may withdraw consent at any time. Send your request to the e-mail address below. We will respond within one month. You may lodge a complaint with your supervisory authority.

  • California (CPRA) – You have rights to know, correct, delete, opt out of sale/share and limit the use of sensitive information. Exercise these rights using the footer link on our site or by e-mail. We respond within 45 days. You may appeal to the California Attorney General.

  • Other U.S. states (Colorado, Connecticut, Virginia, etc.) – You may access, correct, delete or request portability of your data and opt out of targeted ads. Use the same methods described above. We respond within 45 days and provide an internal appeal process followed by state Attorney-General review if needed.

  • UAE and KSA (PDPL) – You may request access, rectification, erasure, objection to processing or data portability by contacting us. We will respond within a reasonable time. You may escalate to the relevant Data Office if unsatisfied.

 


We will not discriminate against you for exercising any of these rights.


 

10. Children

 


The Service is not directed to children under 13 in the United States or under 16 in the EEA/UK, and we do not knowingly collect personal information from such individuals. If you believe we have inadvertently collected data from a child, please contact us so we can delete it.


 

11. Do Not Track

 


Our sites do not respond to browser “Do Not Track” signals. However, where legally required, we honour recognised opt-out preference signals such as Global Privacy Control.


 

12. Changes to This Policy

 


We may update this Privacy Policy from time to time. Any material changes will be posted on this page with an updated “Effective date”. Where required by law, we will notify you by e-mail or through the Service before the changes take effect.


 

13. Contact Us

 


If you have questions, wish to exercise your rights, or require this policy in an alternative format, please contact:

 

  • E-mail: support@orabella.style

  • Postal: Privacy Team, Rashrash OÜ, Lõõtsa tn 5, Lasnamäe district, Tallinn 11415, Harju County, Estonia

  • Data-Protection Officer: Shaker (support@orabella.style)