Privacy & Data Handling Policy
Last updated: 22 June 2026
This policy explains how VakaSport CRM (“we”, “us”), operated from Lithuania (European Union) and reachable at crm.vakasport.lt, collects, processes, stores, uses, shares and disposes of personal data. We act as a data controller for the order and customer data managed in our system and comply with the EU General Data Protection Regulation (GDPR).
1. What data we process
Our CRM consolidates e-commerce orders from connected sales channels. For each order we may process:
- Buyer and recipient name;
- Shipping/delivery address;
- Contact details (email address, phone number) where provided by the channel;
- Order details — purchased items, quantities, prices, taxes and order identifiers;
- Invoicing details required to issue lawful VAT invoices.
We do not collect payment card numbers; payments are handled by the marketplaces and their payment processors.
2. Why we process it (purposes & legal basis)
- Order fulfilment — picking, packing and shipping orders, and generating carrier shipping labels (legitimate interest / performance of a contract).
- Invoicing and accounting — issuing VAT invoices and meeting bookkeeping obligations (legal obligation).
- Customer service — handling delivery questions, returns and refunds (legitimate interest).
- Inventory and catalogue management — keeping stock and listings accurate across channels.
3. Amazon Selling Partner information
Where we are connected to Amazon via the Selling Partner API (SP-API), we retrieve order information for our own seller account solely to fulfil and account for those orders. This may include the buyer/recipient name and shipping address. Amazon data is:
- Collected only via authorised SP-API calls, restricted to the data elements our approved roles permit and accessed using short-lived Restricted Data Tokens;
- Processed only for order fulfilment, shipping and invoicing — never for advertising, resale, or transfer to unauthorised third parties;
- Stored encrypted within the EU, with access limited to authorised personnel (see Section 6);
- Shared only with carriers and tax/accounting recipients strictly as needed to deliver and invoice the order (see Section 4);
- Disposed of securely once retention obligations end (see Section 5).
Our use of Amazon information complies with the Amazon Acceptable Use Policy and Data Protection Policy.
4. Who we share data with
We share the minimum data necessary with:
- Carriers (e.g. LP Express / UNISEND, DPD, Smartpost) — recipient name and address to deliver parcels;
- Accounting and tax authorities — invoice data as required by law;
- Infrastructure providers hosting our encrypted servers within the EU, acting as processors under contract.
We never sell personal data or share it for third-party marketing.
5. Retention & disposal
We keep personal order data only as long as needed to fulfil the order and to meet legal obligations. Invoice and accounting records are retained for the statutory period required by Lithuanian/EU tax law. When data is no longer required it is securely deleted or anonymised from active systems and from backups on their normal rotation.
6. How we protect data
- Encryption in transit — all access is over HTTPS/TLS;
- Encryption at rest — databases and backups are stored on encrypted volumes;
- Access control — role-based, need-to-know access with individual named accounts and key-based server access; databases are not exposed to the public internet;
- Network protection — services run in isolated networks behind a firewalled reverse proxy;
- Logging & monitoring — access and application logs are retained and reviewed for suspicious activity;
- Backups — encrypted, off-host backups with tested restore procedures;
- Change management — code changes are reviewed and tested before release.
7. Your rights
Subject to applicable law, you may request access to, rectification of, or erasure of your personal data, as well as restriction of or objection to processing, and data portability. To exercise these rights, contact us using the details below. You also have the right to lodge a complaint with the Lithuanian State Data Protection Inspectorate (VDAI).
8. International transfers
Personal data is stored and processed within the European Union. Where data is received from Amazon marketplaces outside the EU strictly to fulfil an order, it is handled under appropriate safeguards and only for the purposes described above.
9. Data breach & incident contact
We maintain an incident response process to contain, investigate and remediate any unauthorised access or data leak, and to notify Amazon, affected individuals and regulators where required. Security incidents can be reported to our Incident Management Point of Contact:
- Incident contact (IMPOC): wimass@gmail.com
10. Contact us
For any privacy question or data-subject request, contact: wimass@gmail.com.
11. Changes to this policy
We may update this policy as our practices or legal requirements change. The “last updated” date above reflects the latest revision.