Privacy Policy
Effective date: 1 May 2026 · Last updated: 16 May 2026
Who we are
SILKILINEN is an online retailer of silk and linen intimates, operated from Donegal, Ireland. We are the data controller for the personal information collected through this website (silkilinen.com).
Contact: hello@silkilinen.com
What data we collect
When you place an order we collect:
- Full name and billing address
- Shipping address
- Email address
- Phone number
- Payment information (processed directly by Stripe — we never see your card details)
When you browse the site we may collect:
- Anonymised usage data via cookies (pages visited, session duration)
- Device and browser type
- IP address (for fraud prevention)
How we use your data
- To process and fulfil your order
- To send order confirmation and shipping notifications by email
- To handle returns, refunds, and customer service queries
- To comply with legal obligations (tax records, consumer rights)
- To prevent fraud
Our legal basis for processing is contract performance (Article 6(1)(b) GDPR) for order-related data, and legitimate interests (Article 6(1)(f) GDPR) for fraud prevention and site analytics.
Third parties we share data with
- Stripe — payment processing (PCI-DSS compliant). Stripe Privacy Policy
- Railway — backend server hosting
- Vercel — frontend hosting and CDN
- MongoDB Atlas — encrypted cloud database for order records
- Cloudinary — product image storage and delivery
- Resend — transactional email delivery (order confirmations)
We do not sell your personal data to any third party.
Cookies
We use minimal cookies — essential cart storage only. Your cart contents are stored in your browser's local storage so items persist between visits. No server-side session cookie is created for shop visitors.
We do not currently use analytics or advertising cookies. When we introduce optional cookies in the future, you will be asked for consent before any are placed.
How long we keep your data
- Order records are retained for 7 years as required by Irish Revenue for tax purposes.
- Email correspondence is retained for 2 years.
- Analytics data is anonymised and retained for 12 months.
Your rights under GDPR
You have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — ask us to correct inaccurate data
- Erasure — ask us to delete your data (subject to legal retention obligations)
- Portability — receive your data in a structured, machine-readable format
- Restriction — ask us to limit processing in certain circumstances
- Objection — object to processing based on legitimate interests
To exercise any of these rights, email us at hello@silkilinen.com. We will respond within 30 days. If you are unsatisfied with our response, you may lodge a complaint with the Data Protection Commission of Ireland.
Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email if you have placed an order with us. The effective date at the top of this page will always reflect the most recent update.