Skip to content

Calculated at checkout

Home
Legal

Privacy Policy

Last updated: August 2026

This policy explains what personal data we collect, the legal basis for each use, who processes it on our behalf, and the rights you can exercise over it.

1. Who is responsible

Amour LLC, a limited liability company registered in the United States and trading as amour store, is the controller for the personal data described in this policy. Where you are in the EU or EEA, that means the controller within the meaning of Article 4(7) of the General Data Protection Regulation (GDPR); we apply the same standard to every customer regardless of where they live. You can reach us at support@amourstore.store.

If you have a question about how your data is handled, our contact page reaches a person who can answer it.

2. What we collect, and why

When you place an order we collect your name, email address, delivery address and, where you provide one, a phone number. We use this to fulfil your order, keep you informed about it and meet our accounting obligations. The legal basis is performance of a contract (Art. 6(1)(b) GDPR) and, for retention of invoices, a legal obligation (Art. 6(1)(c) GDPR).

When you create an account we store your email address and password in hashed form so you can sign in and see your order history. The legal basis is performance of a contract (Art. 6(1)(b) GDPR).

If you sign in with TikTok, we receive your TikTok user ID and public profile information — display name, username and avatar. We store this to identify your account on return visits. The legal basis is performance of a contract (Art. 6(1)(b) GDPR). We never receive your TikTok password, and we cannot post on your behalf.

We keep limited technical data such as browser type and pages visited to keep the site working and secure. The legal basis is our legitimate interest in operating a functioning shop (Art. 6(1)(f) GDPR).

3. Payment data

Card details are collected and processed exclusively by our payment provider, Stripe Payments Europe Ltd. They are transmitted directly to Stripe and never reach our servers. We receive only a payment reference and its status.

4. Who processes data on our behalf

We use a small number of processors, each bound by a data processing agreement under Article 28 GDPR: Stripe for payments, Amazon Web Services for transactional email delivery, and our hosting provider for running the site. Each receives only the data it needs for that task.

Where a processor is located outside the European Economic Area, transfers are covered by the European Commission’s Standard Contractual Clauses.

5. Email

We send transactional email — order confirmations, shipping updates, password resets. These are part of fulfilling your order and are not marketing.

If an address bounces permanently, or someone marks our mail as spam, we record that and stop sending to it. That record exists to protect recipients from unwanted mail and to keep our sending reputation sound.

6. Cookies

We use cookies that are strictly necessary for the site to function — keeping your cart and your signed-in session. These do not require consent under Article 5(3) of the ePrivacy Directive.

We do not set advertising or cross-site tracking cookies.

7. How long we keep data

Order and invoice records are retained for the periods required by German commercial and tax law, which is generally six to ten years. Account data is kept while your account is open and deleted on request thereafter, except where a retention obligation applies.

8. Your rights

Under the GDPR you have the right to access your data (Art. 15), to have inaccurate data corrected (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18), to data portability (Art. 20), and to object to processing based on legitimate interests (Art. 21).

You can exercise any of these by contacting us. We answer within one month. Your account settings also let you export or delete your data directly.

You additionally have the right to lodge a complaint with a supervisory authority, in the member state of your residence, place of work or the place of the alleged infringement.

9. Security

The site is served exclusively over TLS. Passwords are stored using a slow hashing function and are never recoverable in plain text. Access tokens for connected accounts are encrypted at rest.

10. Changes to this policy

We update this policy when our processing changes. The current version always appears on this page with its date.