This text is a placeholder. It has not yet been reviewed by a lawyer or a fiduciary and must not be considered binding until it has been approved.
Privacy Policy
Last updated: September 2026
This policy explains which personal data we process when operating the online shop "Nayla Shop" (nayla-shop.web.app), why we do so and what rights you have. It is governed by the revised Swiss Federal Act on Data Protection (revFADP) and the Data Protection Ordinance (DPO). It describes how the shop actually works technically and will be updated whenever that changes.
1. Controller
i2bit
Aarauerstrasse 132, 4600 Olten, Switzerland
Email: info@i2bit.de
[TODO: Enter the contact person (name) for data protection requests. We are not required to appoint a data protection adviser.]
For questions about data protection, access requests and anything else concerning your data, please contact the email address above.
2. Principles and legal basis
We process personal data only to the extent necessary to run the shop, handle your orders and comply with legal obligations (principles of proportionality and purpose limitation, Art. 6 FADP). Where the law requires a justification, we rely on:
- the performance of a contract with you (customer account, order, delivery, payment, support);
- legal obligations, in particular age verification for the sale of tobacco and nicotine products and the retention of business records;
- your consent, where we ask for it (e.g. newsletter, starting age verification, any future statistics cookies);
- our overriding interest in a secure operation free of abuse (protection against spam and attacks, troubleshooting).
3. What data we process
Without a customer account you can browse the shop, fill your cart, use the contact form and subscribe to the newsletter. A customer account is required to place orders. Depending on how you use the shop, we process:
- Customer account: email address, password (stored exclusively as a cryptographic hash, never in plain text), date of birth, optional display name, time of registration.
- Addresses: name, street, postcode, city, country, optional phone number and a label you choose.
- Orders: order number, items ordered and quantities, amounts, any discount code, payment method and payment reference, a copy of the delivery address, your age confirmation and your acceptance of the Terms and Conditions with timestamp, order status.
- Age verification: status (pending, approved, rejected), method used, the reference number of the check at the verification provider and the timestamps. Details in section 5.
- Loyalty points: points balance and every credit or redemption linked to the respective order.
- Referral programme: your personal referral code, the link between the referring and the referred account, the triggering order and the reward code issued.
- Wishlist and product reviews: saved products; for reviews the star rating, title and text. Approved reviews are publicly visible in the shop – without your email address.
- Contact form: name, email address, message, the page you wrote from, and our reply.
- Newsletter: email address, chosen language and time of subscription.
- Technical data: for the contact form and newsletter sign-up we store your IP address briefly (at most 2 days) as a key for rate limiting against spam. In addition, our hosting providers keep standard server logs (IP address, time, requested address, browser identifier).
4. Purposes of processing
- providing the shop and your customer account;
- handling orders, payments, deliveries and returns;
- legally required age verification for tobacco and nicotine products;
- communication: order and status notifications, replies to enquiries, newsletter (only if subscribed);
- loyalty points and referral programme;
- security, abuse prevention and troubleshooting;
- compliance with statutory retention and disclosure obligations.
5. Age verification with Persona (ID document and selfie check)
Because we sell products that may only be sold to persons aged 18 or over, you must prove your age once before your first order of such products. For this we use the identity verification service Persona (Persona Identities, Inc., San Francisco, USA). This involves sensitive personal data within the meaning of Art. 5 lit. c FADP (ID document data and biometric data). Please read this section carefully.
How the check works: when you start it in your customer account, an embedded Persona window opens directly in your browser. There you photograph an official identity document (e.g. ID card, passport or driving licence) and – depending on the step – a selfie. These images and the information extracted from them (name, date of birth, document number, document type, biometric features for face comparison) are transmitted from your browser directly to Persona and evaluated there. They do not reach our servers.
What we receive and store: only the result of the check (approved, rejected, expired), the reference number of the check at Persona and the timestamps. We neither store nor view ID document images or selfies. The check is linked to your customer account only via an internal account ID. If the check is successful, the time of the age confirmation is recorded in your profile.
Access: only Persona has access to the data processed at Persona. On our side, only persons with administrator rights can see the status of your check, but never your ID document data.
Consent and voluntariness: by starting the check you expressly consent to this processing. The check is voluntary; without it, however, you cannot buy age-restricted products in the shop. To limit abuse and costs, at most three new checks are possible per 24 hours.
Transfer to the USA: Persona is based in the USA. The transfer is based on the provider's certification under the Swiss-U.S. Data Privacy Framework or on the standard contractual clauses recognised by the Swiss Federal Data Protection and Information Commissioner (Art. 16 FADP). Further details on processing by Persona can be found in Persona's privacy policy (withpersona.com).
[TODO: Conclude a data processing agreement (DPA) with Persona, document the basis for the transfer (DPF certification or standard contractual clauses) and configure a short retention period with automatic deletion for ID images and selfies in the Persona dashboard. Enter the configured period here: "Persona deletes ID images and selfies … days after the check is completed."]
6. Payment processing
- Prepayment (bank transfer): you transfer the amount to our bank account. We receive the details usual for a transfer (name of the account holder, amount, payment reference).
- Card and TWINT via PostFinance Checkout (PostFinance AG, Bern, Switzerland): for payment we redirect you to the PostFinance payment page. For this we transmit the order number, the amount, the list of items (names and quantities), your email address and the shop language. You enter your card or TWINT details exclusively at PostFinance; we never receive full card data, only the payment status and a transaction reference. PostFinance processes the data in Switzerland under its own privacy policy.
7. Processors and other recipients
We pass personal data on only to service providers we need to run the shop and who are contractually bound by our instructions (processing on behalf, Art. 9 FADP), and to recipients necessary for performing the contract:
- Supabase, Inc. (USA) – database, login (email and password), server functions for checkout, contact form, newsletter, referral programme and age verification, file storage for product images, and real-time updates. Our data is stored in the Frankfurt region (EU); access by the provider from the USA is possible for support and operations.
- Google (Google LLC, USA / Google Ireland Ltd., Ireland) – Firebase Hosting delivers the website files through a global network. This generates server logs with IP address, time, requested address and browser identifier. We embed neither the Firebase SDK nor Google Analytics; no usage profiles are created.
- Persona Identities, Inc. (USA) – age verification, see section 5.
- PostFinance AG (Switzerland) – payment processing for card and TWINT, see section 6.
- Swiss Post (Die Schweizerische Post AG, Switzerland) – receives your name and delivery address to ship your order.
- Email delivery: we send order and status notifications through i2bit's business mailbox (SMTP), hosted by HostEurope. Emails about your account (registration confirmation, password reset) are sent by Supabase's login service through its own infrastructure.
- Google (Gemini API) – the articles in our blog are generated automatically with the AI service Gemini. We transmit only topic prompts, no customer or usage data. This service therefore does not process any of your personal data.
8. Transfer abroad
Our data is processed mainly in Switzerland and in the EU (Supabase, Frankfurt region). The Federal Council recognises an adequate level of data protection for the EU member states. Persona, Supabase, Inc. and Google are based in the USA; disclosure to the USA is made either to companies certified under the Swiss-U.S. Data Privacy Framework or on the basis of the standard contractual clauses recognised by the FDPIC (Art. 16 and 17 FADP).
[TODO: For each US provider (Supabase, Google, Persona), check whether a DPF certification exists or standard contractual clauses are included in the data processing agreement, and file the contracts.]
9. Cookies, local storage and fonts
We currently set no cookies of our own. The shop runs as a static website; a few technically necessary items are instead kept in your browser's local storage and only leave your browser when a feature needs to send them to our servers:
- Login session: the access tokens of your customer account (set by the Supabase login service) so that you stay logged in.
- Cart: the products and quantities you selected ("nayla-cart-v1").
- Age gate: the time at which you confirmed on entering the shop that you are of legal age ("nayla-age-verified-at"). This does not replace the age verification described in section 5.
- Your choice in the cookie notice ("nayla-cookie-consent") so that we do not ask you again on every visit.
These items remain stored until you delete them in your browser. They are required to run the shop and do not need consent.
Statistics: the cookie notice offers a "Statistics" option. Currently no analytics or tracking tool is integrated – your choice is merely saved and has no effect at present. Should we collect anonymous usage statistics in the future, we will only activate this with your consent and update this policy beforehand.
Third-party services: during age verification (embedded Persona window) and payment (PostFinance payment page), these providers may set cookies on their own domains. Their privacy policies apply.
Fonts: the fonts used (Plus Jakarta Sans, Playfair Display) are downloaded when the website is built and served from our own hosting. No connection to Google Fonts servers is made when you visit the shop.
10. Retention periods
- Orders, invoices and payment records: 10 years from the end of the financial year in which the order was placed (accounting and retention obligation under Art. 958f of the Swiss Code of Obligations).
- Customer account, addresses, wishlist, loyalty points and referral data: until you delete your account. When the account is deleted, this data is removed; orders are kept for the statutory period without a link to an account.
- Age verification result: for as long as your customer account exists, as proof that the age check was carried out. We never store ID images or selfies (retention at Persona: see section 5).
- Product reviews: until you withdraw them or delete your account.
- Contact enquiries: for as long as the enquiry is being handled and for a reasonable follow-up period. [TODO: Define a specific deletion period, e.g. 12 months after closure, and set up deletion.]
- Newsletter: until you unsubscribe.
- IP-based rate limiting (contact form, newsletter): at most 2 days.
- Hosting providers' server logs: according to their usual short periods.
11. Data security
All connections to the shop and to our service providers are encrypted with TLS (including HSTS). Passwords are stored exclusively as hashes. Access to the database is secured with row-level access rules so that you only see your own data; particularly sensitive fields are additionally protected. Administrative access is limited to a few role-based authorised persons. Public endpoints (contact form, newsletter, age verification) are protected against mass requests.
12. Your rights
Under the Data Protection Act you have in particular the following rights:
- Access (Art. 25 FADP): you can find out whether and which personal data we process about you.
- Rectification (Art. 32 FADP): you can have incorrect data corrected – addresses and profile details also directly in your customer account.
- Erasure: you can request the deletion of your data, unless a statutory retention obligation prevents this.
- Data portability (Art. 28 FADP): you can receive the data you have given us in a common electronic format.
- Objection and restriction: you can object to processing or request that it be restricted.
- Withdrawal of consent: you can withdraw consent you have given (e.g. newsletter) at any time with effect for the future.
Write to us at info@i2bit.de. We generally provide information free of charge and within 30 days. To protect your data, we may ask for proof of identity before processing a request.
Deleting your account and unsubscribing from the newsletter: you can currently arrange both by email to info@i2bit.de; we carry out the deletion or unsubscription promptly. [TODO: Build self-service functions for account deletion and newsletter unsubscription into the shop and adjust this paragraph afterwards.]
Right to complain: you can contact the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, at any time.
13. Changes to this policy
We update this privacy policy when the shop, our service providers or the legal situation change. The version published on this page applies; the date of the last update is shown above.