Privacy Policy

Last updated: October 16, 2025

At Baby&Oak, we place great importance on protecting and maintaining the confidentiality of our customers’ and visitors’ personal data. We are committed to respecting your privacy and ensuring the security of your personal information (hereinafter referred to as “Personal Data” or “PD”), in accordance with applicable laws, including the General Data Protection Regulation (GDPR).

This Privacy Policy aims to inform you transparently about the types of data we collect, the reasons we use them, and the measures we take to protect them.

What data do we collect?

We collect only the information necessary to manage our services and maintain our relationship with you. This includes:

1. Account creation and billing information
– Name, surname, postal address, phone number, email address.
– Login credentials and encrypted passwords.
– Payment information (e.g., cardholder name, credit card number, expiration date).

2. Transaction-related information
– Purchase history, preferences, delivery data.

3. Website browsing information
– Cookie identifiers, visited pages, user actions, and geolocation data. These are collected through tools such as Google Analytics.

How do we collect your data?

Your personal data is collected through the following actions:

• When you create a customer account on our website.
• When you place an order.
• When you subscribe to our newsletter.
• When you interact with our website (navigation, clicks, etc.).

This information is collected only with your prior consent and is used to process your orders, send communications, and improve our services.

Why do we use your data?

Your personal data is used for specific and legitimate purposes, including:

• Processing your orders, payments, and deliveries.
• Sending updates about Baby&Oak (newsletters, events, offers).
• Enhancing your user experience on our website.
• Preventing fraud and ensuring transaction security.
• Handling your requests or inquiries.

We ensure that your data is used only for purposes consistent with our commercial relationship or to comply with legal obligations.

Who do we share your data with?

Your personal information is strictly confidential. Access is limited to Baby&Oak staff, as well as service providers and partners involved in fulfilling your orders (e.g., carriers, payment services such as Stripe or PayPal).

• All partners are contractually bound to protect your data and use it only for the intended services.
• We do not sell or share your personal data with third parties unrelated to our services.

Are your data transferred abroad?

Your personal data are primarily stored and processed within the European Economic Area (EEA). If we transfer your data to partners or entities outside the EEA, we ensure that they provide an adequate level of protection in accordance with European law.

Use of cookies and social plugins

We use cookies to enhance your browsing experience, analyze site traffic, and personalize our communications. Cookies help us remember your preferences or track browsing habits for statistical purposes.

You may refuse or delete cookies through your browser settings. However, doing so may limit certain site features.

We also use social media plugins (e.g., Facebook, Instagram, WhatsApp) to enable content sharing. If you are logged into these platforms while browsing our site, they may collect data about your activity. To prevent this, please log out of your social accounts before visiting our site.

Newsletters and marketing communications

If you have provided consent, you may receive our newsletters and personalized promotional offers. You may unsubscribe at any time by clicking the link in our emails or by contacting us via the contact form.

How long do we retain your data?

We retain your personal data only for as long as necessary to manage our services and comply with legal requirements.

• Customer data are retained for the duration of the commercial relationship, plus 3 years for marketing purposes.
• Prospect data are retained for up to 180 days after the last interaction.

Your rights

You have the following rights regarding your personal data:

Access: You may request access to your personal data.
Rectification: You may request updates or corrections to your information.
Erasure: You may request deletion of your data, subject to legal obligations.
Withdrawal of consent: You may withdraw your consent to data use at any time (e.g., unsubscribe from newsletters).

To exercise these rights, please contact us via the contact form or by email at contact@babyandoak.com, attaching a valid form of identification. We will process your request within one month.