Overview
Shopvibes Media is committed to GDPR compliance and protecting the data rights of all users. This page explains your rights under GDPR, how we protect your data, and how to exercise those rights.
Questions? Email contact@shopvibesmedia.com with "GDPR Request" in the subject line.
Your Rights Under GDPR
If you're in the EU, UK, or anywhere your data is processed, you have the following rights:
| Right | What It Means | How to Request |
|---|---|---|
| Right of Access | Request all data we hold about you in machine-readable format | Email contact@shopvibesmedia.com |
| Right to Rectification | Correct inaccurate information we hold | Email contact@shopvibesmedia.com |
| Right to Erasure | Request deletion of your data (except legally required records) | Email contact@shopvibesmedia.com |
| Right to Data Portability | Request your data in a portable format | Email contact@shopvibesmedia.com |
| Right to Object | Object to processing for specific purposes (e.g., marketing) | Email contact@shopvibesmedia.com or click unsubscribe |
| Right to Withdraw Consent | Withdraw consent anytime if we rely on it | Email contact@shopvibesmedia.com or unsubscribe |
How to Exercise Your Data Rights
- Email contact@shopvibesmedia.com
- Include your full name and email address
- Specify which right you're exercising (access, delete, export, etc.)
- We will respond within 30 days (GDPR legal deadline)
Subject line example: "GDPR Request: Right to Access My Data"
Data Processing Agreements
We have executed Data Processing Agreements with our service providers:
Our Data Processors:
- Stripe — Payment processing (DPA executed; Standard Contractual Clauses included)
- GoHighLevel — Email and CRM platform (DPA executed; Standard Contractual Clauses included)
- Mailgun — Email delivery (DPA executed; Standard Contractual Clauses included)
- Google Analytics — Website analytics (DPA in place; IP anonymization enabled)
- Meta Pixel — Ad conversion tracking (Standard contractual terms apply)
All processors are GDPR-compliant and operate under contractual obligations to protect your data.
International Data Transfers
Shopvibes Media is a US-based company. If you're outside the US and provide us data:
- Your data may be transferred to and processed in the United States
- We use Standard Contractual Clauses to ensure protection equivalent to GDPR
- We require all US processors to implement supplementary security measures
- You retain all GDPR rights regardless of where your data is stored
Data Retention
We retain your data only as long as necessary:
| Data Type | Retention Period | Reason |
|---|---|---|
| Contact information | Until you request deletion | Service delivery |
| Payment records | 7 years | Tax requirement |
| Email engagement data | 26 months | Analytics |
| Cookies | Until cleared | Session management |
Upon deletion request: We remove your personal data within 30 days. Financial records are anonymized to retain only transaction data for tax purposes.
EU AI Act Disclosure
Shopvibes Media uses AI as part of every engagement. We comply with EU AI Act transparency obligations:
- We disclose which parts of our work use AI
- We specify which models are used
- We disclose where your data is processed
- Every AI-generated content piece is reviewed by a human editor before publication
Complaints
If you believe we've violated your GDPR rights, you have the right to lodge a complaint with your national data protection authority:
- EU: Your country's national data protection authority
- UK: Information Commissioner's Office (ICO) — ico.org.uk
- Other countries: Your local privacy regulator
Contact & Oversight
For any GDPR-related inquiries or data subject requests:
Shopvibes Media
Email: contact@shopvibesmedia.com
Subject: "GDPR Request: [Your Request Type]"
Response time: 30 days maximum