Skip to main content
Last updated 1 September 2026

Privacy Policy

How SPROXT FIELD LTD collects, uses and protects personal data under the EU GDPR and CCPA.

Operator: SPROXT FIELD LTD, company number HE 486059, Republic of Cyprus.

1. Controller

The data controller is SPROXT FIELD LTD, Republic of Cyprus. Privacy requests: privacy@sproxtshop.com.

2. Data we collect

CategoryExamplesPurpose / legal basis
Order dataEmail address, name and billing address (from the payment page), items, prices, order number, timestampsPerform the contract; legal obligation (tax and accounting records)
Payment dataPayment reference, card scheme, last four digits, authorisation result, decline reason, country of the cardPerform the contract; fraud prevention (legitimate interest)
Cardholder dataNot collected. Full card numbers, expiry dates and security codes are entered only on Stripe's PCI DSS certified page and never stored by us.
Account accessEmail address, sign-in link timestamps, session cookieProvide order history and receipts (contract)
Support dataMessages, attachments, order referencesAnswer your request (contract / legitimate interest)
Technical dataIP address, device and browser details, pages visited, errors; analytics only with consentSecurity and service integrity (legitimate interest); analytics (consent)

3. Who we share data with and why

  • Stripe (payment processing, fraud screening, 3-D Secure) — receives your card and billing details directly.
  • Email delivery provider — sends receipts, sign-in links and support replies.
  • Hosting and database providers — store order records under contract.
  • Professional advisers and authorities — where required by law, for tax records or to respond to a lawful request or chargeback.

We never sell personal data. Customer card data is not sold, shared or disclosed to third parties by Sproxt Shop.

4. How we protect data

TLS encryption on every page, encrypted storage, access limited to staff with a role-based permission, audit logs of administrative actions, and a payment integration in which card data never touches our systems.

5. Retention

Order and receipt records are kept for at least 120 days for your access and for 6 years for tax and accounting law. Support messages are kept for 2 years. Technical logs are kept for up to 12 months.

6. Your rights

You can access, correct, delete, restrict or port your personal data and object to processing based on legitimate interests. To exercise a right, email privacy@sproxtshop.com or use the contact form (topic: Privacy request). We answer within one month. You may complain to the Commissioner for Personal Data Protection of the Republic of Cyprus (dataprotection.gov.cy) or to the supervisory authority in the country where you live. California residents have the rights to know, delete, correct and opt out of sale/sharing; we do not sell or share personal information.

7. International transfers

Our providers may process data outside the EEA (for example Stripe in the United States) under adequacy decisions or standard contractual clauses.

8. Cookies

See the Cookie Policy. Optional cookies are only set after you accept them in the cookie banner, which you can reopen from the footer.