Privacy & Cookie Policy
All Things Rósa Last updated: Wednesday 26 August 2026
This Privacy and Cookie Policy explains how All Things Rósa ("we", "us", "our", "Rósa") collects, uses, shares and protects personal data when you visit www.allthingsrosa.ie (the "Site") or buy from us, and it explains your rights under the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Irish Data Protection Act 2018.
If you have any questions about this Policy or how we handle your data, contact us at hello@allthingsrosa.ie.
1. Who we are (data controller)
All Things Rósa is the data controller responsible for your personal data.
Trading name: All Things Rósa
Legal entity / registered business name: [insert — e.g. sole trader name, or company name and CRO number if registered]
Registered/business address: [insert address — required for GDPR and Irish consumer law compliance]
Contact email:hello@allthingsrosa.ie
Instagram: @all_things_rosa
Pick-up location: Dublin city (available for local collection where arranged)
If you register a company later, you must add the CRO number and registered office address here — Irish law requires this on a business website.
2. What personal data we collect
We collect personal data in the following ways:
a) Information you give us directly
Name
Email address
Postal/delivery address
Phone number (if provided for delivery)
Order details (items purchased, order value, order history)
Payment information — processed by our payment provider, not stored by us (see Section 5)
Any messages you send us via the Contact page, email, or Instagram DM
Newsletter sign-up details, if you subscribe to marketing emails [remove if you don't run a mailing list]
b) Information collected automatically
IP address
Browser type and device information
Pages viewed, time on Site, referral source
Cookie and similar tracking data (see Section 8, Cookie Policy)
c) Information from third parties
Payment confirmation and fraud-check data from our payment processor
Delivery status updates from our courier
We do not knowingly collect special category data (e.g. health, religious belief, biometric data) and ask that you do not send us such information.
3. Why we process your data and our legal basis
Purpose Legal basis (GDPR Art. 6) Processing and fulfilling your order, taking payment, arranging delivery/pick-up Performance of a contract Responding to enquiries and customer service Performance of a contract / legitimate interests Sending order confirmations, shipping updates, and service messages Performance of a contract Sending marketing emails or newsletters Consent (you can withdraw at any time) Improving the Site, analytics, fraud prevention, and security Legitimate interests Complying with tax, accounting, and consumer law obligations Legal obligation Handling returns, refunds, and warranty claims Legal obligation / performance of a contract
Where we rely on consent (e.g. marketing emails, non-essential cookies), you may withdraw consent at any time, free of charge, without affecting the lawfulness of processing carried out before withdrawal.
4. Sharing your data
We do not sell your personal data. We share it only with third parties who need it to run the Site and fulfil your order, including:
Website platform: the Site is built and hosted on Squarespace, which processes data on our behalf as our website host and e-commerce provider.
Payment processor: [insert — e.g. Squarespace Payments / Stripe / PayPal] processes your payment details directly; we do not store full card numbers.
Delivery/courier partners: [insert courier name(s)] receive your name, address and phone number to deliver your order.
Email/marketing platform: [insert, e.g. Squarespace Email Campaigns / Mailchimp — remove if not applicable], if you subscribe to updates.
Analytics providers: [insert, e.g. Google Analytics, Squarespace Analytics — remove/adjust as applicable].
Professional advisors and authorities: accountants, legal advisors, or Revenue/regulatory bodies where required by law.
Each of these providers is only permitted to use your data for the specific service they provide to us, subject to their own privacy and security obligations.
5. Payment information
Card and payment details are entered directly with our payment processor and are not stored on our own systems. Our payment processor is responsible for the security of that data and is itself subject to strict industry security standards (PCI DSS). Please refer to your payment provider's own privacy policy for details of how they handle your payment data.
6. International data transfers
Some of our service providers (such as Squarespace, hosted in the United States) may process your data outside the European Economic Area (EEA). Where this happens, we ensure appropriate safeguards are in place, such as the European Commission's Standard Contractual Clauses, or reliance on a provider's participation in a recognised adequacy framework (e.g. the EU–US Data Privacy Framework), to ensure your data receives an equivalent level of protection.
7. How long we keep your data
We keep personal data only as long as necessary for the purposes it was collected, including to satisfy legal, accounting, or reporting requirements. As a general guide:
Order and transaction records: kept for 6 years to meet Irish tax and accounting obligations.
Customer account/contact details: kept while you remain an active customer, and deleted or anonymised after a period of inactivity [insert period, e.g. 3 years].
Marketing consent records: kept until you unsubscribe or withdraw consent, plus a short period afterwards to record that withdrawal.
Cookie data: as set out in Section 9 below.
8. Your rights under GDPR
As a data subject, you have the right to:
Access the personal data we hold about you
Rectify inaccurate or incomplete data
Erase your data ("right to be forgotten"), subject to legal exceptions (e.g. we may need to retain order records for tax purposes)
Restrict processing in certain circumstances
Object to processing based on legitimate interests or for direct marketing
Data portability — receive your data in a structured, machine-readable format
Withdraw consent at any time, where processing is based on consent
Lodge a complaint with the Irish Data Protection Commission (DPC) if you believe we have not handled your data properly
To exercise any of these rights, email hello@allthingsrosa.ie. We will respond within one month, as required by GDPR.
Data Protection Commission (Ireland) 21 Fitzwilliam Square South, Dublin 2, D02 RD28 Website: www.dataprotection.ie
9. Cookie Policy
What are cookies?
Cookies are small text files placed on your device when you visit a website. They help the Site function properly, remember your preferences, and give us insight into how visitors use the Site.
Cookies we use
Category Purpose Can you disable? Strictly necessary Required for core functions such as the shopping cart, checkout, and account login. Set automatically by Squarespace. No — the Site won't function properly without these Performance/analytics Help us understand how visitors use the Site (e.g. pages visited, time spent) so we can improve it. [Adjust to confirm whether you use Squarespace Analytics, Google Analytics, etc.] Yes, via cookie banner/browser settings Functional Remember preferences such as currency or previously viewed items Yes Marketing/advertising [Only include if applicable — e.g. Instagram/Meta pixel, retargeting ads] Used to show you relevant ads on other platforms Yes
Managing cookies
You can control or delete cookies through your browser settings, and where we use a cookie consent banner, through the preferences it offers. Blocking some cookies may affect Site functionality, such as the shopping cart or checkout.
For more detail on the specific cookies set by our platform, see Squarespace's own cookie information, as our hosting provider sets certain cookies automatically as part of running the Site.
10. Children's privacy
The Site is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.
11. Security
We take reasonable technical and organisational measures to protect your personal data against unauthorised access, loss, or misuse, including relying on the security measures provided by our hosting and payment platforms. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
12. Changes to this Policy
We may update this Policy from time to time to reflect changes in our practices or legal requirements. The "Last updated" date at the top shows when it was last revised. We encourage you to review this page periodically.
13. Contact us
If you have questions, concerns, or wish to exercise your data protection rights, contact us at:
Email:hello@allthingsrosa.ieInstagram: @all_things_rosa
You also have the right to lodge a complaint with the Data Protection Commission at www.dataprotection.ie.