Privacy policy

What we know about you, and what we do not.

What you buy here says something private about you, so the honest thing is to collect as little as possible and say exactly what happens to it. We run no analytics, no advertising pixels, no profiling and no cross-site tracking of any kind. This policy explains the rest.

Version 2 · last updated 20 September 2026

1. Who is responsible

The data controller for personal data collected through onyxbunny.com is:

We are not required to appoint a Data Protection Officer, and we have not. Privacy requests go to the address above and are handled by the owner.

Our lead supervisory authority is the State Data Protection Inspectorate of Lithuania (Valstybinė duomenų apsaugos inspekcija, vdai.lrv.lt). You may also complain to the authority in your own country.

2. What we collect, why, and on what legal basis

DataWhyLegal basis (GDPR Art. 6)Kept for
Name, delivery address, email, phone if you give it To take, price, fulfil and deliver your order, and to contact you about it 6(1)(b) — performance of a contract Duration of the order, then retained only as accounting records require
Order contents, totals, VAT, country To fulfil the order and to meet tax and accounting obligations 6(1)(b) and 6(1)(c) — legal obligation 10 years from the end of the financial year, as Lithuanian accounting law requires
Correspondence you send us To answer you, and to keep a record of complaints and returns 6(1)(b), and 6(1)(f) — our legitimate interest in defending claims 3 years from the last message, or longer if it relates to a live dispute
Confirmation that you accepted the hygiene-seal notice and the terms Evidence of pre-contract information, required by consumer law 6(1)(c) With the order record
Payment status and processor reference To reconcile payments and process refunds 6(1)(b) and 6(1)(c) With the order record
Email address, if you ask for product or safety notices To send them 6(1)(a) — consent, withdrawable at any time Until you unsubscribe

We never collect card numbers, expiry dates or security codes. Card details are entered only on the payment provider's own hosted page. They never reach this site, are never logged, and we never see them.

We do not ask for, and do not want, any information about your health, sexuality or relationships. Your order contents are of course revealing, so we treat every order record as confidential, restrict access to the owner and the fulfilment partner, and never use it for anything except fulfilling and supporting that order.

3. What stays in your browser and never reaches us

Several things are stored in your own browser's local storage and are never transmitted to us:

These are strictly necessary for the functions you asked for, so under Article 5(3) of the ePrivacy Directive they do not require consent, and we therefore do not show a consent banner. We use no cookies for analytics, advertising, profiling or fingerprinting, and no third-party scripts run on this site at all.

Account security. Passwords are never stored anywhere. Sign-in verification uses a PBKDF2-SHA-256 hash with 210,000 iterations and a unique random salt. A separate password-derived key encrypts your local account data with AES-GCM using a fresh initialisation vector for every write. The decryption key lives in session storage, so a copy of your local storage alone does not reveal the contents. Signing out removes that key. We cannot recover your password, and clearing your browser data deletes the account record permanently.

4. Who else sees your data

Only the parties below, only the data each one needs, and only for the purpose stated. None of them may use it for their own purposes.

RecipientWhat they receiveWhere
Cloudflare — website and order storageOrder records, site request logsEU/global network. Data processing agreement and standard contractual clauses in place.
Resend — transactional emailYour email address, name and order details, to send the confirmation and trackingEU/US. [OWNER TO CONFIRM — DPA signed]
Fulfilment partnerYour name, delivery address and the items to packChina. See transfers below. [OWNER TO CONFIRM — written data processing agreement in place before first order]
CarrierYour name, delivery address, phone if required for delivery, and the customs declarationDestination country
Payment processorYour payment details, which you enter directly with them; we receive only a status and a referenceStripe Payments Europe, Ltd. (Ireland), with onward transfers within the Stripe group. Card details are entered on Stripe's own hosted page and never reach this site.
Accountant, and authorities where legally requiredTransaction recordsLithuania

We do not sell personal data. We do not share it with advertisers, data brokers or social platforms. We have no advertising relationships at all.

5. Transfers outside the EEA

Fulfilling your order requires sending your name and delivery address to our fulfilment partner in China, and to the carrier. China has no EU adequacy decision, so this transfer is made under Article 49(1)(b) GDPR — it is necessary for the performance of the contract you entered with us — and is supported by standard contractual clauses with the partner. Only the data needed to address and post the parcel is sent: your name, address, phone where the carrier requires it, and the items. Your email address, payment information and order history are not sent.

If you are not willing for your address to be transferred for this purpose, we cannot fulfil an order, because there is no other way to get the parcel to you. Please do not order.

6. Your rights

Under the GDPR you may:

Email [email protected]. We respond within one month, and we will tell you if we need the two-month extension the GDPR allows for complex requests. There is no charge. We may ask you to confirm the email address the order was placed with, so we do not disclose someone's purchase history to the wrong person.

There is no automated decision-making and no profiling on this site.

7. Security

The site is served over HTTPS only, with HSTS, a strict content security policy that permits no third-party scripts, clickjacking protection, a same-origin opener policy, restrictive browser permissions and strict referrer handling. Order records are stored on Cloudflare infrastructure, access is limited to the owner, and API credentials are held as platform secrets and never in the codebase.

If a breach occurs that is likely to risk your rights and freedoms, we will notify the supervisory authority within 72 hours and tell you directly without undue delay.

8. Children

This site is for adults aged 18 and over. We do not knowingly collect data from anyone under 18. If you believe a minor has given us personal data, email us and we will delete it.

9. Changes to this policy

If we change this policy we update the version and date at the top. If a change materially affects how we use data you have already given us, we will email you before it takes effect.