We respect your privacy and are committed to protecting your personal data. This policy explains how PELLERIA collects, uses, and safeguards your information.

🇪🇺 GDPR Compliant

🇺🇸 CCPA Compliant

Last updated: June 2026

Who we are: PELLERIA is a Moroccan luxury leather goods brand. Our website is pelleria.com. We ship to Europe and the United States. When we say “PELLERIA”, “we”, “us”, or “our” in this policy, we mean the company operating pelleria.com.

01GDPR · CCPA

Data Controller / Business Identity

The data controller responsible for your personal information is:

DetailInformation
Company namePELLERIA
Business addresscasablanca, Morocco
Emailprivacy@pelleria.com
Websitepelleria.com
Markets servedEuropean Union, United Kingdom, United States, and worldwide

For EU/UK customers, PELLERIA acts as the data controller as defined under the General Data Protection Regulation (GDPR) and UK GDPR. For California residents, PELLERIA acts as the business under the California Consumer Privacy Act (CCPA/CPRA).

02GDPR · CCPA

Data We Collect

We collect only the data necessary to provide our services. Here is a complete overview:

A. Data You Provide Directly

Data TypeExamplesWhy We Collect It
Identity dataFirst name, last nameTo process your order and personalize communication
Contact dataEmail address, phone numberOrder confirmations, shipping updates, customer support
Delivery dataShipping address, countryTo fulfill and ship your order
Payment dataCard type, last 4 digits, billing addressTo process payments (full card data handled by Stripe/PayPal — not stored by us)
Account dataUsername, password (hashed), order historyTo manage your customer account
Communication dataMessages, emails, support requestsTo respond to inquiries and improve service
Marketing preferencesNewsletter opt-in/opt-outTo send marketing communications only with your consent

B. Data Collected Automatically

Data TypeExamplesWhy We Collect It
Technical dataIP address, browser type, device type, OSSecurity, fraud prevention, site functionality
Usage dataPages visited, time on site, click patternsAnalytics to improve user experience
Cookie dataSession cookies, preference cookies, analytics cookiesSee Section 6 (Cookies)
Transaction dataPurchase history, returns, abandoned cartOrder management and personalization

C. Data We Do NOT Collect

  • Full payment card numbers (processed directly by Stripe/PayPal)
  • Sensitive personal data (health, religion, political views, biometrics)
  • Government ID numbers
  • Data from children under 16 years of age

03GDPR · CCPA

How We Use Your Data

PurposeData UsedLegal Basis
Process and fulfill your orderIdentity, contact, delivery, paymentContract performance
Send order confirmation and shipping updatesEmail, order detailsContract performance
Process returns and refundsIdentity, payment, order historyContract performance
Respond to customer support requestsContact, communication dataLegitimate interest / Contract
Send marketing emails and newslettersEmail, preferencesConsent (opt-in only)
Retargeted advertising (Meta Pixel, TikTok Pixel)IP, cookie, browsing behaviorConsent
Improve website and user experienceUsage data, analyticsLegitimate interest
Fraud prevention and securityTechnical data, transaction dataLegitimate interest / Legal obligation
Legal and regulatory complianceAll relevant dataLegal obligation
Business analytics and reportingAggregated, anonymized dataLegitimate interest

We will never: sell your personal data to third parties, use your data for profiling without consent, or send you marketing emails without your explicit opt-in.

04GDPR

Legal Basis for Processing (GDPR)

Under GDPR Article 6, we process your personal data on the following lawful bases:

🇪🇺 GDPR — Article 6 Legal Bases

6(1)(b) — Contract: Processing necessary to fulfill your order, manage your account, and provide customer service.

6(1)(a) — Consent: Marketing emails, cookies, retargeting ads. You may withdraw consent at any time without affecting prior processing.

6(1)(f) — Legitimate Interests: Fraud prevention, site analytics, service improvement. We always balance this against your rights and freedoms.

6(1)(c) — Legal Obligation: Tax records, accounting, compliance with applicable law.

05GDPR · CCPA

Data Sharing & Third Parties

We do not sell your personal data. We share your data only with the following categories of trusted service providers, under strict contractual data processing agreements:

Recipient CategoryService Provider (Examples)Data SharedPurpose
Payment processorsStripe, PayPalPayment data, emailSecure payment processing
Shipping carriersDHL, FedEx, La Poste, USPSName, address, phoneOrder delivery
E-commerce platformHostinger, WooCommerceOrder data, account dataStore operations
Email marketingMailchimp, KlaviyoEmail, name, preferencesNewsletter (consent-based only)
AnalyticsGoogle Analytics 4Anonymized usage dataWebsite improvement
Advertising platformsMeta (Facebook/Instagram), TikTok, googleIP, cookie, pixel dataRetargeted ads (consent only)
Customer supportWhatsApp BusinessName, message contentCustomer inquiries
Legal / complianceAccountants, lawyers, regulatorsRelevant dataLegal obligation

All third-party processors are contractually required to process your data only on our instructions and in accordance with GDPR/CCPA requirements.

Legal Disclosure

We may disclose your personal data to law enforcement, regulatory authorities, or courts when required by law, court order, or to protect the rights, property, or safety of PELLERIA, our customers, or others.

06ePrivacy · GDPR

Cookies & Tracking Technologies

We use cookies and similar technologies on pelleria.com. You will be shown a cookie consent banner on your first visit where you can accept or reject non-essential cookies.

CategoryCookie Name (Examples)PurposeConsent Required?
Strictly Necessarysession_id, cart, csrf_tokenShopping cart, login, securityNo — essential
Preferencescurrency, language, regionRemember your settingsNo — functional
Analytics_ga, _gid (Google Analytics)Anonymous site usage statisticsYes — opt-in
Marketing_fbp (Meta Pixel), _ttp (TikTok)Retargeted advertisingYes — opt-in

Managing Your Cookies

  • Cookie banner: Use the consent manager on our site to change your preferences at any time
  • Browser settings: Block or delete cookies via your browser settings (this may affect site functionality)
  • Google Analytics opt-out: tools.google.com/dlpage/gaoptout
  • Meta ad preferences: facebook.com/ads/preferences

07GDPR — Art. 5(1)(e)

Data Retention

We retain your personal data only for as long as necessary for the purposes outlined in this policy or as required by law.

Data TypeRetention PeriodReason
Order and transaction data7 yearsTax and accounting legal requirement
Customer account dataDuration of account + 3 years after last activityCustomer service, repurchase history
Marketing preferencesUntil you unsubscribeConsent-based
Support communications3 yearsReference and dispute resolution
Analytics data26 months (Google Analytics default)Site improvement
Cookies (marketing)Up to 90 daysAdvertising performance
Fraud prevention dataUp to 5 yearsSecurity and legal obligation

When your data is no longer needed, we will securely delete or anonymize it.

08GDPR — Chapter V

International Data Transfers

PELLERIA is based in Morocco. When we process data for EU/UK customers, we transfer personal data outside the European Economic Area (EEA). We ensure these transfers comply with GDPR by using:

  • Standard Contractual Clauses (SCCs) — approved by the European Commission for transfers to third countries
  • Adequacy decisions — where the destination country has been recognized as providing adequate data protection
  • Binding Corporate Rules — for transfers to our own group companies

🇪🇺 EU–Morocco Data Transfers

Morocco has enacted Law 09-08 on personal data protection, broadly aligned with European standards. All transfers from EU to PELLERIA are further protected by Standard Contractual Clauses pursuant to GDPR Article 46(2)(c).

Our main third-party processors (Stripe, Meta, Google) are located in the United States and operate under their own GDPR-compliant transfer mechanisms, including SCCs and EU-U.S. Data Privacy Framework certification where applicable.

09GDPR — Articles 15–22

Your Rights — EU / UK Residents (GDPR)

If you are located in the European Union or United Kingdom, you have the following rights under GDPR:

👁️Right of Access (Art. 15)

Request a copy of all personal data we hold about you.

✏️Right to Rectification (Art. 16)

Correct inaccurate or incomplete personal data.

🗑️Right to Erasure (Art. 17)

Request deletion of your data (“right to be forgotten”), subject to legal retention requirements.

⏸️Right to Restriction (Art. 18)

Request that we limit processing of your data in certain circumstances.

📦Right to Portability (Art. 20)

Receive your data in a structured, machine-readable format to transfer to another provider.

🚫Right to Object (Art. 21)

Object to processing based on legitimate interests, including for direct marketing purposes.

🤖Automated Decision-Making (Art. 22)

Not to be subject to solely automated decisions that produce significant legal effects.

↩️Right to Withdraw Consent

Withdraw consent at any time for processing based on consent (e.g., marketing emails).

How to Exercise Your Rights

Submit a request to privacy@pelleria.com with the subject line “GDPR Rights Request”. We will respond within 30 days. We may ask you to verify your identity before processing the request.

Right to Lodge a Complaint

If you are unsatisfied with how we handle your data, you have the right to lodge a complaint with your national supervisory authority:

10CCPA / CPRA

Your Rights — California Residents (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) grant you the following rights:

🇺🇸 CCPA / CPRA — Your Rights

Right to Know: You may request details about the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and third parties we share it with.

Right to Delete: You may request that we delete personal information we have collected from you, subject to certain exceptions (e.g., legal obligations).

Right to Correct: You may request correction of inaccurate personal information.

Right to Opt-Out of Sale/Sharing: PELLERIA does not sell personal information. We do not share personal information for cross-context behavioral advertising without your consent.

Right to Limit Use of Sensitive Personal Information: We do not collect sensitive personal information as defined under CPRA.

Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights. We will not deny goods, charge different prices, or provide a lower level of service.

Categories of Personal Information Collected (CCPA)

CCPA CategoryCollected?Examples
IdentifiersYesName, email, IP address
Commercial informationYesPurchase history, products browsed
Internet / network activityYesBrowsing behavior on our site
Geolocation dataLimitedCountry/region from IP (not precise location)
InferencesNoWe do not build consumer profiles
Sensitive personal informationNoNot collected
Financial informationLimitedLast 4 digits of card (via Stripe)

How to Submit a CCPA Request

Email privacy@pelleria.com with subject line “CCPA Privacy Request”. We will verify your identity and respond within 45 days (extendable by 45 days with notice).

Authorized Agent

You may designate an authorized agent to submit requests on your behalf. The agent must provide written authorization signed by you, and we may still verify your identity directly.

Shine the Light (California Civil Code § 1798.83)

California residents may request information about personal information disclosed to third parties for their direct marketing purposes during the prior calendar year. Contact us at privacy@pelleria.com.

Other U.S. State Privacy Laws

Residents of Colorado (CPA), Virginia (VCDPA), Connecticut (CTDPA), and other states with comprehensive privacy laws may also have similar rights. We honor these rights — please contact us at privacy@pelleria.com.

11COPPA · GDPR

Children’s Privacy

PELLERIA does not knowingly collect personal data from children under the age of 16 (or under 13 in the United States under COPPA). Our website and services are not directed to minors.

If you believe we have inadvertently collected data from a child, please contact us immediately at privacy@pelleria.com and we will delete it promptly.

12GDPR — Art. 32

Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, destruction, or alteration, including:

  • SSL/TLS encryption on all pages of pelleria.com (HTTPS)
  • PCI-DSS compliant payment processing via Stripe — we never store full card numbers
  • Hashed passwords — account passwords are never stored in plain text
  • Access controls — only authorized personnel can access customer data
  • Regular security reviews of our infrastructure and third-party processors

Data Breach Notification: In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours (as required by GDPR Article 33) and will inform affected individuals without undue delay.

13GDPR · CCPA

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Update the “Last updated” date at the top of this page
  • Send an email notification to registered customers for significant changes
  • Display a notice on our website

We encourage you to review this page periodically. Your continued use of our website after any changes constitutes your acceptance of the updated policy.

14. Contact & Privacy Requests

For any questions about this Privacy Policy, to exercise your rights, or to submit a data request, please contact our privacy team. We respond within 30 days (EU) or 45 days (US).

Email: privacy@pelleria.com

Subject Line: GDPR Request — or — CCPA Request

Response Time: Within 30 days (EU) / 45 days (US)