PRiVACY POLiCY
Last updated: January 14, 2026
Plain-language summary (for parents)
We only collect the information we need to run the shop, deliver orders, answer questions, and improve how the site works. That usually means contact details, order information, payment confirmation, and basic website usage data. We do not knowingly collect data about children, we do not sell personal data, and we use trusted service providers like Shopify, payment providers, and shipping companies to run the store. You stay in control of marketing and cookie preferences, and you can always contact us to access, correct, or delete your data.
This summary is for convenience only. The full Privacy Policy below is legally binding.
1. Introduction
BUMBiNOS operates this store and website, including all related information, content, features, tools, products and services, in order to provide you with a curated shopping experience (the “Services”). BUMBiNOS is operated by Paraply AB and powered by Shopify, which enables us to provide the Services to you.
This Privacy Policy explains how we collect, use, and disclose your personal information when you visit, use, or make a purchase or other transaction using the Services, or otherwise communicate with us.
If there is a conflict between our Terms & Conditions and this Privacy Policy, this Privacy Policy governs the collection, processing, and disclosure of personal information.
By using the Services, you acknowledge that you have read and understood this Privacy Policy.
2. Who is responsible for your personal information?
For the purposes of applicable data protection laws, including the GDPR, the data controller is:
Paraply AB (operating the brand BUMBiNOS)
Sockerbruket 9
414 51 Göteborg
Sweden
Email: info@bumbinos.com
Org. no.: 556892 - 2289
3. Personal information we collect or process
“Personal information” means information that identifies or can reasonably be linked to you. It does not include anonymous or de-identified data.
Depending on how you interact with the Services and as permitted by law, we may collect or process:
-
Contact details: name, billing address, shipping address, email address, phone number
-
Financial information: payment method, transaction details, payment confirmation (payment card details are handled by payment providers)
-
Account information: username, password, preferences and settings (if you create an account)
-
Transaction information: items viewed, added to cart, purchased, returned or exchanged, and order history
-
Communications: information you provide when contacting customer support
-
Device information: device type, browser, IP address, network information
-
Usage information: how and when you interact with the Services
4. Sources of personal information
We may collect personal information:
-
Directly from you, when you place an order, create an account, or contact us
-
Automatically, through your use of the Services and via cookies and similar technologies
-
From service providers that support the Services (for example payment, shipping, analytics, and security providers)
5. How we use your personal information and legal bases
5.1 Providing and improving the Services
We use personal information to process orders, handle payments, ship products, manage returns, provide customer support, manage accounts, and improve the Services.
Legal bases: performance of a contract (Art. 6(1)(b) GDPR); legitimate interests (Art. 6(1)(f) GDPR).
5.2 Marketing and communication
With your consent where required, we may send marketing communications and show relevant advertising based on your interaction with the Services.
Legal bases: consent (Art. 6(1)(a) GDPR); legitimate interests where permitted by law.
5.3 Security and fraud prevention
We use personal information to secure the Services, prevent fraud, and protect users and the business.
Legal bases: legitimate interests (Art. 6(1)(f) GDPR); legal obligation (Art. 6(1)(c) GDPR).
5.4 Legal and compliance purposes
We process personal information to comply with legal obligations and respond to lawful requests.
Legal bases: legal obligation (Art. 6(1)(c) GDPR).
6. How we disclose personal information
We may disclose personal information:
-
To Shopify and service providers that support the Services (IT, payments, analytics, customer support, hosting, fulfillment, and shipping)
-
To marketing partners, where you have consented where required
-
When you direct or consent to disclosure (for example for delivery or optional integrations)
-
In connection with a business transaction (such as a merger or asset sale)
-
To comply with legal obligations or protect our rights
We do not sell personal information.
7. Relationship with Shopify
The Services are hosted by Shopify. Shopify processes personal information to provide and improve the Services and may process data across different jurisdictions.
Some Shopify features use data from interactions with our store and other merchants. For such processing, Shopify acts as an independent controller.
More information:
8. Third-party websites and links
The Services may link to third-party websites or platforms. We are not responsible for their privacy practices. Information shared publicly on third-party platforms may be visible to others.
9. Children’s data
The Services are not intended for use by children. We do not knowingly collect personal information from children under the age of majority in their jurisdiction.
If you believe a child has provided personal information, please contact us to request deletion.
10. Cookies and similar technologies
We use cookies and similar technologies to operate the website and, where you consent, for analytics and marketing.
You can manage your preferences through the cookie banner and settings link in the website footer.
Necessary cookies are used based on legitimate interest. Analytics and marketing cookies are used only where consent is required and given.
11. Security and retention
No system is perfectly secure, and we cannot guarantee absolute security. Please avoid sending sensitive information via insecure channels.
We retain personal information only as long as necessary to provide the Services, comply with legal obligations, resolve disputes, and enforce agreements. Order and accounting data is retained in accordance with Swedish law.
12. Your rights and choices
Depending on where you live, you may have the right to:
-
Access your personal information
-
Request correction or deletion
-
Request data portability
-
Object to or restrict certain processing
-
Withdraw consent where processing is based on consent
You can opt out of marketing emails at any time via the unsubscribe link. Transactional and service emails may still be sent.
Targeted advertising
We do not provide a separate on-site opt-out link for targeted advertising. Preferences are managed through cookie settings.
If you use Global Privacy Control (GPC), and where required by law, we will treat it as an opt-out signal for the device and browser used.
More information: https://globalprivacycontrol.org/
13. Complaints
If you have concerns about our processing of personal information, please contact us.
You also have the right to lodge a complaint with a data protection authority. For the EEA, see:
https://edpb.europa.eu/about-edpb/about-edpb/members_en
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The latest version will always be published on the website with an updated date.
15. Contact
Questions or requests regarding privacy:
Paraply AB (BUMBiNOS)
Sockerbruket 9
414 51 Göteborg
Sweden
Org. no.: 556892-2289