Privacy policy
What we know about you, and what we do not.
What you buy here says something private about you, so the honest thing is to collect as little as possible and say exactly what happens to it. We run no analytics, no advertising pixels, no profiling and no cross-site tracking of any kind. This policy explains the rest.
1. Who is responsible
The data controller for personal data collected through onyxbunny.com is:
- Controller
- Vakaris Pupkus, trading as Onyx Bunny
- Registration number
- [OWNER TO CONFIRM — individual activity certificate number; not yet registered]
- Registered address
- Bajorų 1, Verdulių kaimas, LT-77155 Šiauliai, Lithuania
- Privacy contact
- [email protected]
We are not required to appoint a Data Protection Officer, and we have not. Privacy requests go to the address above and are handled by the owner.
Our lead supervisory authority is the State Data Protection Inspectorate of Lithuania (Valstybinė duomenų apsaugos inspekcija, vdai.lrv.lt). You may also complain to the authority in your own country.
2. What we collect, why, and on what legal basis
| Data | Why | Legal basis (GDPR Art. 6) | Kept for |
|---|---|---|---|
| Name, delivery address, email, phone if you give it | To take, price, fulfil and deliver your order, and to contact you about it | 6(1)(b) — performance of a contract | Duration of the order, then retained only as accounting records require |
| Order contents, totals, VAT, country | To fulfil the order and to meet tax and accounting obligations | 6(1)(b) and 6(1)(c) — legal obligation | 10 years from the end of the financial year, as Lithuanian accounting law requires |
| Correspondence you send us | To answer you, and to keep a record of complaints and returns | 6(1)(b), and 6(1)(f) — our legitimate interest in defending claims | 3 years from the last message, or longer if it relates to a live dispute |
| Confirmation that you accepted the hygiene-seal notice and the terms | Evidence of pre-contract information, required by consumer law | 6(1)(c) | With the order record |
| Payment status and processor reference | To reconcile payments and process refunds | 6(1)(b) and 6(1)(c) | With the order record |
| Email address, if you ask for product or safety notices | To send them | 6(1)(a) — consent, withdrawable at any time | Until you unsubscribe |
We never collect card numbers, expiry dates or security codes. Card details are entered only on the payment provider's own hosted page. They never reach this site, are never logged, and we never see them.
We do not ask for, and do not want, any information about your health, sexuality or relationships. Your order contents are of course revealing, so we treat every order record as confidential, restrict access to the owner and the fulfilment partner, and never use it for anything except fulfilling and supporting that order.
3. What stays in your browser and never reaches us
Several things are stored in your own browser's local storage and are never transmitted to us:
- Your 18+ confirmation.
- Your basket contents, currency and language preference.
- Whether you dismissed the storage notice.
- Recently viewed products.
- If you create an optional account: your saved address, wishlist and order history, stored encrypted in your browser.
These are strictly necessary for the functions you asked for, so under Article 5(3) of the ePrivacy Directive they do not require consent, and we therefore do not show a consent banner. We use no cookies for analytics, advertising, profiling or fingerprinting, and no third-party scripts run on this site at all.
Account security. Passwords are never stored anywhere. Sign-in verification uses a PBKDF2-SHA-256 hash with 210,000 iterations and a unique random salt. A separate password-derived key encrypts your local account data with AES-GCM using a fresh initialisation vector for every write. The decryption key lives in session storage, so a copy of your local storage alone does not reveal the contents. Signing out removes that key. We cannot recover your password, and clearing your browser data deletes the account record permanently.
5. Transfers outside the EEA
Fulfilling your order requires sending your name and delivery address to our fulfilment partner in China, and to the carrier. China has no EU adequacy decision, so this transfer is made under Article 49(1)(b) GDPR — it is necessary for the performance of the contract you entered with us — and is supported by standard contractual clauses with the partner. Only the data needed to address and post the parcel is sent: your name, address, phone where the carrier requires it, and the items. Your email address, payment information and order history are not sent.
If you are not willing for your address to be transferred for this purpose, we cannot fulfil an order, because there is no other way to get the parcel to you. Please do not order.
6. Your rights
Under the GDPR you may:
- Access the personal data we hold about you, and get a copy.
- Rectify anything inaccurate — an address typo, for example.
- Erase your data, where we are not required to keep it. Accounting records must be kept for 10 years, so an order record cannot be deleted on request within that period; everything outside it can.
- Restrict or object to processing based on our legitimate interests.
- Port your data to another controller in a machine-readable format.
- Withdraw consent at any time where consent is the basis, without affecting what was done before.
- Complain to a supervisory authority — see section 1.
Email [email protected]. We respond within one month, and we will tell you if we need the two-month extension the GDPR allows for complex requests. There is no charge. We may ask you to confirm the email address the order was placed with, so we do not disclose someone's purchase history to the wrong person.
There is no automated decision-making and no profiling on this site.
7. Security
The site is served over HTTPS only, with HSTS, a strict content security policy that permits no third-party scripts, clickjacking protection, a same-origin opener policy, restrictive browser permissions and strict referrer handling. Order records are stored on Cloudflare infrastructure, access is limited to the owner, and API credentials are held as platform secrets and never in the codebase.
If a breach occurs that is likely to risk your rights and freedoms, we will notify the supervisory authority within 72 hours and tell you directly without undue delay.
8. Children
This site is for adults aged 18 and over. We do not knowingly collect data from anyone under 18. If you believe a minor has given us personal data, email us and we will delete it.
9. Changes to this policy
If we change this policy we update the version and date at the top. If a change materially affects how we use data you have already given us, we will email you before it takes effect.