We respect your privacy and are committed to protecting your personal data. This policy explains how PELLERIA collects, uses, and safeguards your information.
🇪🇺 GDPR Compliant
🇺🇸 CCPA Compliant
Last updated: June 2026
Who we are: PELLERIA is a Moroccan luxury leather goods brand. Our website is pelleria.com. We ship to Europe and the United States. When we say “PELLERIA”, “we”, “us”, or “our” in this policy, we mean the company operating pelleria.com.
01GDPR · CCPA
Data Controller / Business Identity
The data controller responsible for your personal information is:
| Detail | Information |
|---|---|
| Company name | PELLERIA |
| Business address | casablanca, Morocco |
| privacy@pelleria.com | |
| Website | pelleria.com |
| Markets served | European Union, United Kingdom, United States, and worldwide |
For EU/UK customers, PELLERIA acts as the data controller as defined under the General Data Protection Regulation (GDPR) and UK GDPR. For California residents, PELLERIA acts as the business under the California Consumer Privacy Act (CCPA/CPRA).
02GDPR · CCPA
Data We Collect
We collect only the data necessary to provide our services. Here is a complete overview:
A. Data You Provide Directly
| Data Type | Examples | Why We Collect It |
|---|---|---|
| Identity data | First name, last name | To process your order and personalize communication |
| Contact data | Email address, phone number | Order confirmations, shipping updates, customer support |
| Delivery data | Shipping address, country | To fulfill and ship your order |
| Payment data | Card type, last 4 digits, billing address | To process payments (full card data handled by Stripe/PayPal — not stored by us) |
| Account data | Username, password (hashed), order history | To manage your customer account |
| Communication data | Messages, emails, support requests | To respond to inquiries and improve service |
| Marketing preferences | Newsletter opt-in/opt-out | To send marketing communications only with your consent |
B. Data Collected Automatically
| Data Type | Examples | Why We Collect It |
|---|---|---|
| Technical data | IP address, browser type, device type, OS | Security, fraud prevention, site functionality |
| Usage data | Pages visited, time on site, click patterns | Analytics to improve user experience |
| Cookie data | Session cookies, preference cookies, analytics cookies | See Section 6 (Cookies) |
| Transaction data | Purchase history, returns, abandoned cart | Order management and personalization |
C. Data We Do NOT Collect
- Full payment card numbers (processed directly by Stripe/PayPal)
- Sensitive personal data (health, religion, political views, biometrics)
- Government ID numbers
- Data from children under 16 years of age
03GDPR · CCPA
How We Use Your Data
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Process and fulfill your order | Identity, contact, delivery, payment | Contract performance |
| Send order confirmation and shipping updates | Email, order details | Contract performance |
| Process returns and refunds | Identity, payment, order history | Contract performance |
| Respond to customer support requests | Contact, communication data | Legitimate interest / Contract |
| Send marketing emails and newsletters | Email, preferences | Consent (opt-in only) |
| Retargeted advertising (Meta Pixel, TikTok Pixel) | IP, cookie, browsing behavior | Consent |
| Improve website and user experience | Usage data, analytics | Legitimate interest |
| Fraud prevention and security | Technical data, transaction data | Legitimate interest / Legal obligation |
| Legal and regulatory compliance | All relevant data | Legal obligation |
| Business analytics and reporting | Aggregated, anonymized data | Legitimate interest |
We will never: sell your personal data to third parties, use your data for profiling without consent, or send you marketing emails without your explicit opt-in.
04GDPR
Legal Basis for Processing (GDPR)
Under GDPR Article 6, we process your personal data on the following lawful bases:
🇪🇺 GDPR — Article 6 Legal Bases
6(1)(b) — Contract: Processing necessary to fulfill your order, manage your account, and provide customer service.
6(1)(a) — Consent: Marketing emails, cookies, retargeting ads. You may withdraw consent at any time without affecting prior processing.
6(1)(f) — Legitimate Interests: Fraud prevention, site analytics, service improvement. We always balance this against your rights and freedoms.
6(1)(c) — Legal Obligation: Tax records, accounting, compliance with applicable law.
05GDPR · CCPA
Data Sharing & Third Parties
We do not sell your personal data. We share your data only with the following categories of trusted service providers, under strict contractual data processing agreements:
| Recipient Category | Service Provider (Examples) | Data Shared | Purpose |
|---|---|---|---|
| Payment processors | Stripe, PayPal | Payment data, email | Secure payment processing |
| Shipping carriers | DHL, FedEx, La Poste, USPS | Name, address, phone | Order delivery |
| E-commerce platform | Hostinger, WooCommerce | Order data, account data | Store operations |
| Email marketing | Mailchimp, Klaviyo | Email, name, preferences | Newsletter (consent-based only) |
| Analytics | Google Analytics 4 | Anonymized usage data | Website improvement |
| Advertising platforms | Meta (Facebook/Instagram), TikTok, google | IP, cookie, pixel data | Retargeted ads (consent only) |
| Customer support | WhatsApp Business | Name, message content | Customer inquiries |
| Legal / compliance | Accountants, lawyers, regulators | Relevant data | Legal obligation |
All third-party processors are contractually required to process your data only on our instructions and in accordance with GDPR/CCPA requirements.
Legal Disclosure
We may disclose your personal data to law enforcement, regulatory authorities, or courts when required by law, court order, or to protect the rights, property, or safety of PELLERIA, our customers, or others.
06ePrivacy · GDPR
Cookies & Tracking Technologies
We use cookies and similar technologies on pelleria.com. You will be shown a cookie consent banner on your first visit where you can accept or reject non-essential cookies.
| Category | Cookie Name (Examples) | Purpose | Consent Required? |
|---|---|---|---|
| Strictly Necessary | session_id, cart, csrf_token | Shopping cart, login, security | No — essential |
| Preferences | currency, language, region | Remember your settings | No — functional |
| Analytics | _ga, _gid (Google Analytics) | Anonymous site usage statistics | Yes — opt-in |
| Marketing | _fbp (Meta Pixel), _ttp (TikTok) | Retargeted advertising | Yes — opt-in |
Managing Your Cookies
- Cookie banner: Use the consent manager on our site to change your preferences at any time
- Browser settings: Block or delete cookies via your browser settings (this may affect site functionality)
- Google Analytics opt-out: tools.google.com/dlpage/gaoptout
- Meta ad preferences: facebook.com/ads/preferences
07GDPR — Art. 5(1)(e)
Data Retention
We retain your personal data only for as long as necessary for the purposes outlined in this policy or as required by law.
| Data Type | Retention Period | Reason |
|---|---|---|
| Order and transaction data | 7 years | Tax and accounting legal requirement |
| Customer account data | Duration of account + 3 years after last activity | Customer service, repurchase history |
| Marketing preferences | Until you unsubscribe | Consent-based |
| Support communications | 3 years | Reference and dispute resolution |
| Analytics data | 26 months (Google Analytics default) | Site improvement |
| Cookies (marketing) | Up to 90 days | Advertising performance |
| Fraud prevention data | Up to 5 years | Security and legal obligation |
When your data is no longer needed, we will securely delete or anonymize it.
08GDPR — Chapter V
International Data Transfers
PELLERIA is based in Morocco. When we process data for EU/UK customers, we transfer personal data outside the European Economic Area (EEA). We ensure these transfers comply with GDPR by using:
- Standard Contractual Clauses (SCCs) — approved by the European Commission for transfers to third countries
- Adequacy decisions — where the destination country has been recognized as providing adequate data protection
- Binding Corporate Rules — for transfers to our own group companies
🇪🇺 EU–Morocco Data Transfers
Morocco has enacted Law 09-08 on personal data protection, broadly aligned with European standards. All transfers from EU to PELLERIA are further protected by Standard Contractual Clauses pursuant to GDPR Article 46(2)(c).
Our main third-party processors (Stripe, Meta, Google) are located in the United States and operate under their own GDPR-compliant transfer mechanisms, including SCCs and EU-U.S. Data Privacy Framework certification where applicable.
09GDPR — Articles 15–22
Your Rights — EU / UK Residents (GDPR)
If you are located in the European Union or United Kingdom, you have the following rights under GDPR:
👁️Right of Access (Art. 15)
Request a copy of all personal data we hold about you.
✏️Right to Rectification (Art. 16)
Correct inaccurate or incomplete personal data.
🗑️Right to Erasure (Art. 17)
Request deletion of your data (“right to be forgotten”), subject to legal retention requirements.
⏸️Right to Restriction (Art. 18)
Request that we limit processing of your data in certain circumstances.
📦Right to Portability (Art. 20)
Receive your data in a structured, machine-readable format to transfer to another provider.
🚫Right to Object (Art. 21)
Object to processing based on legitimate interests, including for direct marketing purposes.
🤖Automated Decision-Making (Art. 22)
Not to be subject to solely automated decisions that produce significant legal effects.
↩️Right to Withdraw Consent
Withdraw consent at any time for processing based on consent (e.g., marketing emails).
How to Exercise Your Rights
Submit a request to privacy@pelleria.com with the subject line “GDPR Rights Request”. We will respond within 30 days. We may ask you to verify your identity before processing the request.
Right to Lodge a Complaint
If you are unsatisfied with how we handle your data, you have the right to lodge a complaint with your national supervisory authority:
- France: CNIL — cnil.fr
- Germany: BfDI — bfdi.bund.de
- UK: ICO — ico.org.uk
- Italy: Garante — garanteprivacy.it
- Spain: AEPD — aepd.es
10CCPA / CPRA
Your Rights — California Residents (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) grant you the following rights:
🇺🇸 CCPA / CPRA — Your Rights
Right to Know: You may request details about the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and third parties we share it with.
Right to Delete: You may request that we delete personal information we have collected from you, subject to certain exceptions (e.g., legal obligations).
Right to Correct: You may request correction of inaccurate personal information.
Right to Opt-Out of Sale/Sharing: PELLERIA does not sell personal information. We do not share personal information for cross-context behavioral advertising without your consent.
Right to Limit Use of Sensitive Personal Information: We do not collect sensitive personal information as defined under CPRA.
Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights. We will not deny goods, charge different prices, or provide a lower level of service.
Categories of Personal Information Collected (CCPA)
| CCPA Category | Collected? | Examples |
|---|---|---|
| Identifiers | Yes | Name, email, IP address |
| Commercial information | Yes | Purchase history, products browsed |
| Internet / network activity | Yes | Browsing behavior on our site |
| Geolocation data | Limited | Country/region from IP (not precise location) |
| Inferences | No | We do not build consumer profiles |
| Sensitive personal information | No | Not collected |
| Financial information | Limited | Last 4 digits of card (via Stripe) |
How to Submit a CCPA Request
Email privacy@pelleria.com with subject line “CCPA Privacy Request”. We will verify your identity and respond within 45 days (extendable by 45 days with notice).
Authorized Agent
You may designate an authorized agent to submit requests on your behalf. The agent must provide written authorization signed by you, and we may still verify your identity directly.
Shine the Light (California Civil Code § 1798.83)
California residents may request information about personal information disclosed to third parties for their direct marketing purposes during the prior calendar year. Contact us at privacy@pelleria.com.
Other U.S. State Privacy Laws
Residents of Colorado (CPA), Virginia (VCDPA), Connecticut (CTDPA), and other states with comprehensive privacy laws may also have similar rights. We honor these rights — please contact us at privacy@pelleria.com.
11COPPA · GDPR
Children’s Privacy
PELLERIA does not knowingly collect personal data from children under the age of 16 (or under 13 in the United States under COPPA). Our website and services are not directed to minors.
If you believe we have inadvertently collected data from a child, please contact us immediately at privacy@pelleria.com and we will delete it promptly.
12GDPR — Art. 32
Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, destruction, or alteration, including:
- SSL/TLS encryption on all pages of pelleria.com (HTTPS)
- PCI-DSS compliant payment processing via Stripe — we never store full card numbers
- Hashed passwords — account passwords are never stored in plain text
- Access controls — only authorized personnel can access customer data
- Regular security reviews of our infrastructure and third-party processors
Data Breach Notification: In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours (as required by GDPR Article 33) and will inform affected individuals without undue delay.
13GDPR · CCPA
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Update the “Last updated” date at the top of this page
- Send an email notification to registered customers for significant changes
- Display a notice on our website
We encourage you to review this page periodically. Your continued use of our website after any changes constitutes your acceptance of the updated policy.
14. Contact & Privacy Requests
For any questions about this Privacy Policy, to exercise your rights, or to submit a data request, please contact our privacy team. We respond within 30 days (EU) or 45 days (US).
Email: privacy@pelleria.com
Subject Line: GDPR Request — or — CCPA Request
Response Time: Within 30 days (EU) / 45 days (US)