Privacy Policy for GraphicRunway.com

Last updated: 4 June 2025

Who We Are

Our website address is: https://graphicrunway.com

GraphicRunway.com offers services in fashion and graphic design. We operate entirely online and comply with Swedish and EU data protection laws, including the General Data Protection Regulation (GDPR).

Contact for privacy concerns:
Email: [email protected]


What Personal Data We Collect and Why

We collect personal data to deliver services, respond to inquiries, process payments, and improve your user experience.

Types of data collected:

  • Name, email address, and phone number – to contact you and handle orders

  • Billing information – required for processing payments

  • Technical data – including IP address, browser type, and cookie data

  • Uploaded media – if applicable (see “Media” below)

Why we collect it:

  • To deliver services and fulfill contracts

  • To respond to inquiries and customer support requests

  • To comply with legal obligations (e.g., invoicing)

  • To improve and secure the website (legitimate interest)

  • With your consent, for optional services like newsletters


Comments

If you leave a comment on the site, we collect:

  • The data shown in the comment form

  • Your IP address and browser user agent (for spam detection)

  • An anonymized string from your email (may be sent to Gravatar)

Gravatar privacy policy: https://automattic.com/privacy/


Media

Avoid uploading images with embedded location data (EXIF GPS), as visitors can download and extract that data from the images on the site.


Contact Forms

When using our contact form, we collect:

  • Your name

  • Your email address

  • Your message

This data is stored for up to 6 months and used only to respond to your inquiry. It is not used for marketing unless you explicitly opt in.


Cookies

Cookies are used to:

  • Save preferences (e.g., name/email in comment forms)

  • Manage login sessions and cart contents

  • Collect analytics data

Cookie data may include non-personal information like browser type and screen resolution. You can manage cookies via your browser settings or through the cookie consent banner on our site.


Analytics

We use Google Analytics or similar services to understand how users interact with the site. This helps us improve the site experience.

These tools may collect:

  • IP address

  • Browser type

  • Pages visited

  • Time spent on the site

You can opt out of Google Analytics here: https://tools.google.com/dlpage/gaoptout

Google Privacy Policy: https://policies.google.com/privacy


Who We Share Your Data With

We share data only with trusted third parties necessary to operate the site and deliver services:

  • Payment processors (e.g., PayPal)

  • Email service providers (for optional newsletters)

  • Hosting providers (for storing site data securely)

  • Analytics services (e.g., Google Analytics)

All third parties must comply with GDPR or equivalent data protection frameworks.


How Long We Retain Your Data

  • Comments: retained indefinitely

  • Contact form entries: up to 6 months

  • Order/payment data: retained for up to 7 years for legal and accounting purposes

  • Analytics data: stored for up to 14 months

  • User accounts (if applicable): retained until deleted by the user


Your Rights Over Your Data

Under the GDPR, you have the right to:

  • Access the data we hold about you

  • Request correction or deletion of your data

  • Withdraw consent (where processing is based on consent)

  • Object to or restrict processing

  • Lodge a complaint with the Swedish authority: https://www.imy.se

To make a request, contact [email protected]


Where Your Data Is Sent

Some data may be processed outside the EU (e.g., U.S.-based services). We ensure such data transfers are safeguarded through:

  • Standard Contractual Clauses

  • Participation in the EU-U.S. Data Privacy Framework

  • Providers’ GDPR-compliance guarantees


How We Protect Your Data

We use:

  • SSL encryption

  • Secure hosting environments

  • Limited access by authorized personnel only

  • Up-to-date software and firewalls


Data Breach Procedures

In the event of a data breach, we will:

  1. Assess and contain the issue

  2. Notify affected users if there is a risk to their rights/freedoms

  3. Report to the Swedish Authority for Privacy Protection (IMY) within 72 hours, if required


Third-Party Data Sources

We may receive limited user data from integrated platforms (e.g., portfolio or social platforms) to offer services. This data is treated as strictly confidential and used only for service fulfillment.


Automated Decision Making

We do not use any automated decision-making or profiling features on GraphicRunway.com.


Industry Regulatory Disclosure

GraphicRunway.com is not subject to specific industry regulations beyond GDPR and standard Swedish digital commerce laws.


For any questions regarding this policy or your data rights, contact us at:
[email protected]