Privacy policy
Privacy Policy
Data Controller
Name: PALMA Trading Kft.
Registered seat: Back Bernat u. 1, 6728 Szeged, Hungary
Mailing address, complaint management: Back Bernat u. 1, 6728 Szeged, Hungary
E-mail: info@palmachocolate.com
Phone number: +36 20 555 2020, +36 70 424 1400
Website: http://www.palmachocolate.com
Hosting service provider
Name: DotRoll Kft.
Mailing address: 1148 Budapest, Fogarasi út 3-5
E-mail: support@dotroll.com
Phone number: (06 1) 432 3232
Description of the data processing activities carried out in the course of the operation of the webshop
This document contains all relevant data processing information regarding the operation of the webshop in accordance with General Data Protection Regulation (2016/679) of the European Union (hereinafter: Regulation or GDPR) and Act CXII of 2011 (hereinafter: Privacy Act).
Information on the use of cookies
What is a cookie?
Upon visiting the website, the Data Controller uses cookies. A cookie is an information package consisting of letters and numbers sent to your browser by our website with the purpose of saving certain settings, facilitate the use of our website and help us collect relevant, statistical information of our visitors.
Some cookies do not contain personal information and are not suitable for identifying individual users, but some cookies contain a unique identifier, that is, a secret number sequence generated randomly, which will be stored by your device and therefore will ensure your identification. The operational duration of each cookie is included in the relevant description.
Legal background and legal grounds of cookies:
The legal basis of processing is your consent pursuant to Article 6(1)(a) of the Regulation.
Main characteristics of the cookies used by the website:
Strictly necessary cookies:
If you do not accept the use of cookies, certain functions will not be available to you.
Cookies strictly necessary for operation: These cookies are essential for the use of the website and enable the use of the basic functions of the site. In the lack of these cookies several functions of the website will not be available to you. The lifetime of these cookies is limited exclusively to the duration of the session.
Session cookies: These cookies store the location of the user, the language of the browser, and the currency of the payment. Their lifetime lasts until the browser is closed or 2 hours at maximum.
Age-restricted content cookies: These cookies record the fact of the approval to age-restricted content and that the person concerned is over 18 years old, their lifetime lasts until the browser is closed.
Recommended product cookies: It records the list of products intended to be recommended, at the “Recommend to a friend” function. Their lifetime is 60 days.
Mobile version, design cookies: It detects the device used by the visitor and switches to full view on mobile. Their lifetime is 365 days.
Cookie acceptance cookies: Upon arrival to the site, you accept the statement on the storage of cookies in the appropriate window. Their lifetime is 365 days.
_ab Used in connection with access to admin. Duration: 2 year.
_customer_account_shop_sessions Used in combination with the _secure_account_session_id cookie to track a user's session for new customer accounts. Duration: 30 days.
_secure_session_id Used to track a user's session through the multi-step checkout process and keep their order, payment and shipping details connected. Duration: 24 hour.
_shopify_country For shops where pricing currency/country set from GeoIP, that cookie stores the country we've detected. This cookie helps avoid doing GeoIP lookups after the first request. Duration: session.
_shopify_m Used for managing customer privacy settings. Duration: 1 year.
_shopify_tm Used for managing customer privacy settings. Duration: 30 sec.
_shopify_tw Used for managing customer privacy settings. Duration: 2 week.
_storefront_u Used to facilitate updating customer account information. Duration: 1 min.
_tracking_consent Used to store a user's preferences if a merchant has set up privacy rules in the visitor's region. Duration: 1 year.
_cmp_a Used for managing customer privacy settings. Duration: 1 day.
c Used in connection with checkout. Duration: 1 year.
cart Used in connection with shopping cart. Duration: 2 week.
cart_currency Set after a checkout is completed to ensure that new carts are in the same currency as the last checkout. Duration: 2 week.
cart_sig A hash of the contents of a cart. This is used to verify the integrity of the cart and to ensure performance of some cart operations. Duration: 2 week.
cart_ts Used in connection with checkout. Duration: 2 week.
cart_ver Used in connection with shopping cart. Duration: 2 week.
checkout Used in connection with checkout. Duration: 4 week.
checkout_token Used in connection with checkout. Duration: 1 year.
customer_account_locale Used in connection with new customer accounts Duration: 1 year.
dynamic_checkout_shown_on_cart Used in connection with checkout. Duration: 30 sec.
hide_shopify_pay_for_checkout Used in connection with checkout. Duration: session.
keep_alive Used in connection with buyer localization. Duration: 2 week.
master_device_id Used in connection with merchant login. Duration: 2 year.
previous_step Used in connection with checkout. Duration: 1 year.
discount_code Used in connection with checkout. Duration: session.
remember_me Used in connection with checkout. Duration: 1 year.
secure_customer_sig Used to identify a user after they sign into a shop as a customer so they do not need to log in again. Duration: 1 year.
shopify_pay Used in connection with checkout. Duration: 1 year.
shopify_pay_redirect Used in connection with checkout. Duration: 1 hour, 3w or 1y depending on value.
shop_pay_accelerated Used in connection with checkout. Duration: 1 year.
source_name Used in combination with mobile apps to provide custom checkout behavior, when viewing a store from within a compatible mobile app. Duration: session.
storefront_digest Stores a digest of the storefront password, allowing merchants to preview their storefront while it's password protected. Duration: 2 year.
tracked_start_checkout Used in connection with checkout. Duration: 1 year.
checkout_session_lookup Used in connection with checkout. Duration: 3 week.
checkout_prefill Used in connection with checkout. Duration: 5 min.
checkout_queue_token Used in connection with checkout. Duration: 1 year.
checkout_queue_checkout_token Used in connection with checkout. Duration: 1 year.
checkout_worker_session Used in connection with checkout. Duration: 3 day.
checkout_session_token Used in connection with checkout. Duration: 3 week.
checkout_session_token_<> Used in connection with checkout. Duration: 3 week.
cookietest Used to ensure our systems are working correctly Duration: 1 min.
order Used in connection with order status page. Duration: 3 week.
identity-state Used in connection with customer authentication Duration: 24 hour.
identity-state-<> Used in connection with customer authentication Duration: 24 hour.
identity_customer_account_number Used in connection with customer authentication Duration: 12 week.
card_update_verification_id Used in connection with checkout. Duration: 20 min.
customer_account_new_login Used in connection with customer authentication Duration: 20 min.
customer_account_preview Used in connection with customer authentication Duration: 7 day.
customer_payment_method Used in connection with checkout. Duration: 1 hour.
customer_shop_pay_agreement Used in connection with checkout. Duration: 20 min.
pay_update_intent_id Used in connection with checkout. Duration: 20 min.
localization Used in connection with checkout. Duration: 2 week.
profile_preview_token Used in connection with checkout. Duration: 5 min.
login_with_shop_finalize Used in connection with customer authentication Duration: 5 min.
preview_theme Used in connection with the theme editor Duration: session.
shopify-editor-unconfirmed-settings Used in connection with the theme editor Duration: 16 hour.
wpm-test-cookie Used to ensure our systems are working correctly. Duration: session.
Statistic cookies:
Google Analytics cookies: Google Analytics is Google’s analytical tool that enables owners of websites and applications to get a more accurate picture of their visitors’ activities. The service may use cookies to collect information and make reports of statistical data on the use of the website without individually identifying visitors for Google. Google Analytics primarily uses „__ga” cookies. In addition to reporting statistical data regarding the use of the website, Google Analytics, along with the above-described ad cookies, can also be used to display more relevant ads in Google products (e.g., in Google Search) and across the web.
Cookies for improving user experience: These cookies collect information of the way the user uses the website, for example which pages does the user visit most frequently or what error messages do they receive from the website. These cookies do not collect information identifying the visitor, that is, they work with completely general, anonymous information. They use the data extracted from such information to improve the performance of the website. The lifetime of these cookies is limited exclusively to the duration of the session.
Referer cookies: They record the external websites from which the visitor arrived to the site. Their lifetime lasts until the browser is closed.
Last viewed product cookies: It records the product last viewed by the visitor. Their lifetime is 60 days.
Last viewed category cookies: It records the category last viewed. Their lifetime is 60 days.
Cart cookies: Records the products added to the cart. Their lifetime is 365 days.
_landing_page Track landing pages. Duration: 2 week.
_orig_referrer Track landing pages. Duration: 2 week.
Marketing cookies:
Google Adwords cookies When someone visits our website, the cookie identifier of the visitor will be added to the remarketing list. Google uses cookies – e.g., NID and SID cookies – in Google products, such as to personalize the ads displayed in Google search. Google uses these cookies for example to remember your earlier searches, interactions with the ads of certain advertisers or search results, or visits to the advertisers’ websites. AdWords conversion tracking uses cookies. To track sales and other conversions resulting from advertising, cookies are saved on the user’s computer when the user clicks on the ad. Some common methods to use cookies are: to select ads based on what is relevant for the given user, to improve reports on campaign performance, and to avoid displaying ads that the user has already seen.
Remarketing cookies: These cookies may appear to previous visitors or users when they browse other websites in the Google Display Network or search for terms related to its products or services.
Facebook pixel (Facebook cookies) Facebook pixel is a code which enables a report to be prepared on the website on conversions, target audiences to be compiled and the owner of the site to receive detailed analysis about the visitors’ use of the website. Facebook pixel enables personalized ads to be displayed for the visitors of the site on the platform of Facebook. You can read Facebook’s Privacy Policy here: https://www.facebook.com/privacy/explanation
_s Shopify analytics. Duration: 30 min.
_shopify_d Shopify analytics. Duration: session.
_shopify_fs Shopify analytics. Duration: 30 min.
_shopify_s Shopify analytics. Duration: 30 min.
_shopify_sa_p Shopify analytics relating to marketing and referrals. Duration: 30 min.
_shopify_sa_t Shopify analytics relating to marketing and referrals. Duration: 30 min.
_shopify_y Shopify analytics. Duration: 1 year.
_y Shopify analytics. Duration: 1 year.
_shopify_ga Shopify and Google Analytics. Duration: session.
customer_auth_provider Shopify analytics. Duration: session.
customer_auth_session_created_at Shopify analytics. Duration: session.
unique_interaction_id Shopify analytics. Duration: 10 min.
You can find further information about deleting cookies at the following links:
- Internet Explorer: http://windows.microsoft.com/en-us/internet-explorer/delete-manage-cookies#ie=ie-11
- Firefox: https://support.mozilla.org/en-US/kb/cookies-information-websites-store-on-your-computer
- Mozilla: https://support.mozilla.org/hu/kb/weboldalak-altal-elhelyezett-sutik-torlese-szamito
- Safari: https://support.apple.com/guide/safari/manage-cookies-and-website-data-sfri11471/mac
- Chrome: https://support.google.com/chrome/answer/95647
- Edge: https://support.microsoft.com/hu-hu/help/4027947/microsoft-edge-delete-cookies
Google Consent Mode v2
The data controller has integrated the Google Consent Mode v2 version into its website. The data controller provides the consents and rejections of cookies based on the new version through its consent panel. Based on Google Consent Mode v2, Google allows to use besides the former two flags (analytics_storage, ad_storage) two additional flags:
- ad_user_data: Any user data that can be sent to Google for advertising purposes.
- ad_personalization: The user's data can be used for personalized advertising purposes, for example for remarketing purposes.
These two switches can be used to control whether the storage and reading of cookies for statistical or advertising purposes is permitted.
Data processed for the purpose of concluding and performing the contract
In order to conclude and performing the contract, several cases of data processing may occur. We hereby inform you that data processing related to complaint management and administration related to guarantee rights will only be carried if you exercise one of the said rights.
If you do not purchase via the webshop but arrive only as a visitor, then the provisions on data processing for marketing purposes may apply to you if you give consent to us for marketing purposes.
Data processing activities for the purpose of concluding and performing the contract in detail are:
Contact
If, for example, you contact us via email, contact form or by phone for inquiry on a product. Prior contact is not necessary, you can order from the webshop at any time in the lack of it.
Data processed
The data provided by you upon contacting us.
Period of the data processing
We only process the data until the end of the contact.
Legal basis for the data processing
Your voluntary consent given to the Data Controller by contacting us. [Data processing pursuant to Article 6(1)(a) of the Regulation]
Registration on the website
By storing the data provided upon registration, the Data Controller can provide more convenient service (e.g., the data subject will not have to provide their data each time they shop on the site). Registration is not a requirement for contracting
Data processed
During the data processing, the Data Controller processes your name, address, phone number, email address, the properties of the products purchased and the date of the purchase.
Period of the data processing
Until the withdrawal of your consent.
Legal basis for the data processing
Your voluntary consent given to the Data Controller by the registration. [Data processing pursuant to Article 6(1)(a) of the Regulation]
Processing the order
Data processing activities in the course of order management required for the purpose of performing the contract.
Data processed
During the data processing, the Data Controller processes your name, address, email address, the properties of the products purchased, the order number and the date of the purchase.
If you place an order in the webshop, the data processing and the provision of the data is inevitable for the performance of the contract.
Period of the data processing
We process the data for 5 years in accordance with the civil-law limitation period.
Legal basis for the data processing
The performance of the contract. [Data processing pursuant to Article 6(1)(b) of the Regulation]
Issuing the invoice
The data processing is carried out for the purpose of issuing an invoice in compliance with the law and fulfilling the obligation of retaining the accounting document. Pursuant to paragraphs (1)-(2) of section 169 of the Accounting Act, economic organisations must retain accounting documents directly and indirectly supporting the accounting records.
Data processed
Name, address, e-mail address, phone number.
Period of the data processing
Pursuant to paragraph (2) of section 169 of the Accounting Act, the issued invoices must be retained for 8 years of the issuing.
Legal basis for the data processing
Pursuant to paragraph (1) of section 159 of Act CXXVII of 2007 on value added tax, issuing an invoice is mandatory and, pursuant to paragraph (2) of section 169 of the Accounting Act, the issued invoices must be retained for 8 years. [Data processing pursuant to Article 6(1)(c) of the Regulation].
Data processing related to product delivery
The data processing is carried out for the purpose of delivering the ordered product.
Data processed
Name, address, e-mail address, phone number.
Period of the data processing
The data processing is carried out for the purpose of delivering the ordered product.
Legal basis for the data processing
The performance of the contract. [Data processing pursuant to Article 6(1)(b) of the Regulation]
Recipients and data processors for delivery of goods
Name of recipient: Express One Hungary Kft.
Registered seat of recipient: 1239 Budapest, Európa út 12., BILK Logisztikai Központ L1 épület
Phone number of recipient: +36 1 8 777 400
E-mail address of recipient: ugyfelszolgalat@expressone.hu
Website of recipient: https://expressone.hu/
The courier service participates in delivering the ordered product based on its contract concluded with the Data Controller. The courier service processes the data provided to it in accordance with the privacy policy available on its website.