Privacy policy

Last Updated: 19th of August, 2026

1. Introduction

Paysafe LLC (“ we ” or “ us ”) respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you visit ceyla.co or purchase our products/services. It also explains your rights under various privacy laws. Paysafe LLC (8 The Green, Ste B, Dover, Delaware 19901, United States) is the “data controller” for purposes of EU and UK data protection law, and the business (covered entity) for U.S. privacy law purposes. By using our website, you consent to the practices described in this Policy. If you do not agree with this Policy, please do not use our services. We may update this Policy occasionally (see section 9 on changes).

2. Personal Data We Collect

We collect information that identifies, relates to, or could reasonably be linked with you (“Personal Data”). We collect this information in several ways:

• Information You Provide Directly: When you place an order or register an account, you provide information such as your name, billing and shipping address, email address, phone number (optional), payment details (payment card number, which is processed by our payment processor – we do not store full card numbers), and any preferences or special requests. If you contact us (e.g., via email), we will collect the information contained in your correspondence. If you create an account, we may collect additional information such as your account login credentials and any profile information you choose to provide.
• Information Collected Automatically: When you browse our site, we use cookies and similar technologies to automatically collect certain data about your device and usage of our site. This may include your IP address, browser type, operating system, referring URLs, pages viewed, and dates/times of access. In addition to essential cookies that are necessary for the website to function (for example, session cookies that keep track of your cart contents), we and our partners use analytics and advertising technologies — including the Meta (Facebook) pixel — to measure how the site is used and how our advertising performs. Where required by law (for example, for visitors from the EU/UK), non-essential cookies and trackers are only activated with your consent, which you can give or withdraw through the cookie preferences on our site.
• Information from Third Parties: If you use a third -party login (if we enable “Login with Google” or similar in future) or if you engage with us on social media, those services might send us certain information about you (according to their privacy settings and policies). For example, if you click an Instagram or Facebook ad for our product, those platforms may inform us of aggregate data like how many people clicked (but not personal identities unless you’ve given permission). Currently, we do not actively obtain personal data from third -party marketers or data brokers.

We do not intentionally collect sensitive personal data (such as race, ethnic origin, health information, or biometrics) or data about children. Our website and services are not directed to children under 13, and we do not knowingly collect personal information from children under 13 (or under 16 in the EU without parental consent). If you believe a child has provided us with personal data, please contact us so we can delete it.

3. How We Use Your Personal Data

We use the collected personal data for the following purposes:

• To Fulfill Orders and Provide Services: We process your name, address, payment info, etc., to process transactions, ship your orders, and to communicate with you about your orders (e.g., order confirmations, shipping notifications). This is primarily to perform our contract with you or to take steps at your request before entering a contract (Article 6(1)(b) GDPR).
• Customer Service: If you contact us with a question, feedback, or need support, we will use your contact information and any information you give us to respond and resolve issues. We may also use your email to send important service or account- related announcements (for example, if there’s a recall or a major update about a product you purchased, or changes to our terms). Service communications of this nature are considered necessary for the use of our service.
• Marketing Communications (Opt-in): With your consent, we may use your email address to send you our newsletter, promotions, or updates about new products or services. We will only send you marketing emails if you have affirmatively subscribed (opted in) to such communications. You can unsubscribe at any time by clicking the “ unsubscribe ” link in any marketing email or by contacting us. We do not spam and we do not sell your information to third -party advertisers. Our marketing practices comply with laws like CAN-SPAM (in the U.S.) and, where applicable, GDPR/UK GDPR consent requirements for electronic marketing.
• Account Management: If you create an account, we use your data to authenticate you when you log in, to show you your order history, and to help you manage your details.
• Improving Our Services: We may use usage data (mostly aggregated or anonymized) to analyze how our site is used, in order to improve the user experience, fix technical issues, and tailor our offerings. For example, we might look at aggregated data to see which product pages are most visited or identify confusion in the checkout process. When feasible, we use non- identifiable data for analytics. If we ever introduce more analytic tools, we will update this policy and, if required, obtain consent.
• Legal Compliance and Protection: We may process personal data as necessary to comply with our legal obligations (e.g., record-keeping for tax, customs, or accounting purposes; responding to lawful requests by public authorities). We also may process data to protect our rights, privacy, safety, or property, and/or that of you or others – for example, to detect and prevent fraud, security or technical issues, or if necessary to establish or defend legal claims.

Legal Bases for Processing (EU/UK visitors): We only process your personal data when we have a legal basis to do so under GDPR/UK GDPR. The bases we rely on are:

• Performance of a Contract: for data used to fulfill orders, process payments, and provide you with products/services you requested.
• Consent: for marketing emails or certain cookies (where applicable) – we will ask for your consent before processing your data for these purposes.
• Legitimate Interests: for uses necessary for our legitimate interests (or those of a third party) provided those interests are not overridden by your data protection rights. For instance, our legitimate interests include improving our site’s functionality, preventing fraud, securing our IT systems, and understanding our customer base. If we rely on legitimate interest, we will ensure our interest is balanced against your privacy.
• Legal Obligation: when processing is required to comply with a law, such as retaining transaction records for tax audits or providing information to law enforcement if properly requested.

4. Cookies and Similar Technologies

Cookies: Cookies are small text files placed on your device when you visit a website. We use a minimal number of cookies on ceyla.co. These include:

• Essential Cookies: These are necessary for core functionality, such as keeping items in your shopping cart, maintaining your session login, or remembering your cookie preferences. Without these, the site may not function correctly. They do not require consent.
• Analytics and Advertising Cookies: We use a small number of third-party technologies to understand site performance and measure our advertising, including the Meta (Facebook) pixel, which helps us measure the effectiveness of our ads and reach people who may be interested in our products. These technologies may collect information about your device and your interactions with our site and our ads. For visitors in regions where consent is required (such as the EU/UK), these technologies are only activated after you consent via our cookie banner, and you can withdraw that consent at any time. You can also limit tracking through your browser settings and, for Meta specifically, through your Facebook ad preferences.

Opt-Out Preference Signals: Where required by applicable law, we honor opt-out preference signals such as Global Privacy Control (GPC). Legacy “Do Not Track” browser signals have no settled industry standard; if that evolves, we will re-evaluate our approach.

For completeness, if you navigate to external links (such as our Instagram or YouTube pages), those third -party sites might set their own cookies. Our Privacy Policy does not cover external sites – please refer to those sites ’ policies.

Cookie Choices: Our cookie consent mechanism for EU/UK visitors covers all non-essential cookies, and customers always have the option to refuse them. If we add further analytics or advertising technologies in the future, they will be brought under the same consent mechanism before activation.

5. How We Share Your Personal Data

We value your privacy. We do not sell your personal information for money. However, our use of advertising tools such as the Meta pixel may be considered “sharing” of personal information for cross-context behavioral advertising as defined under the CCPA/CPRA; California residents can opt out of such sharing at any time (see Section 8). However, we do share certain data with third parties in the following contexts, as necessary to run our business or comply with law:

• Service Providers: We use trusted third -party companies to perform functions on our behalf. For example:
o Payment Processors: to securely handle credit card transactions (e.g., Stripe, PayPal). Your payment info is transmitted directly to them; we receive confirmation of payment and limited info (like last 4 digits of card, card type). These processors are PCI-DSS compliant and are contractually prohibited from using your data for anything other than processing our transactions.
o Shipping Partners: to deliver your orders, we share your name and shipping address (and phone or email as needed for delivery updates) with postal services or courier companies (e.g., USPS, DHL, FedEx or local delivery partners). They use this data only for shipping and delivery communications.
o Cloud Storage and IT Providers: Our store is hosted on Shopify Inc., our e-commerce platform, and data may also be stored with other IT providers. These providers store data on our behalf (such as account info and order history) and are bound by confidentiality and security obligations.
o Email Service: We may use an email service (like an SMTP relay or marketing email platform) to send communications. If you subscribed to our newsletter, your name and email might be stored in that platform to facilitate mailings. We ensure any such platform complies with applicable privacy laws (for example, some providers offer EU- hosted data storage).
o Advertising and Analytics Partners: We share certain information (such as device identifiers, IP address, and pages viewed or actions taken on our site) with advertising platforms — currently Meta Platforms, Inc. — via the Meta pixel, to measure and improve our advertising.

All our service providers are chosen for their strong data protection practices. We have data processing agreements as needed (especially for EU personal data) to ensure they protect your information according to our standards and applicable law.

• Affiliates and Corporate Transactions: If Paysafe LLC ever is involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, receivership, sale of company assets, or transition of service to another provider, your information may be transferred as part of that transaction. We would ensure the new holder of your personal data continues to be bound by terms that are at least as protective as those in this Policy, and we would notify you of the change either via the website or email.
• Legal Compliance and Protection: We may disclose personal data to courts, law enforcement, regulatory authorities, or other competent bodies when we believe disclosure is necessary to comply with a legal obligation or request (such as a court order or subpoena), or to protect our rights or the rights of others. Examples include fraud prevention or investigating any potential violation of law or our Terms. We will carefully review each request to ensure it has valid legal basis before disclosing information.
• With Your Consent: In cases where you have provided consent for us to share your info, we will do so in accordance with that consent. For instance, if we were to run a co- branded promotion and you consent to share your details with the third party running the promotion, we would share as consented. (This is merely an example; we currently have no such program).

We do not share your information with third parties for their own direct marketing purposes unless you have given permission.

6. International Data Transfers

We are a United States-based company. The personal data we collect from you will be stored and processed primarily in Delaware and possibly on servers located in other countries (for example, if our web hosting or email servers are located in the United States or the EU). If you are located in the European Economic Area (EEA), United Kingdom, or another region with data protection laws, please note that your personal data may be transferred to jurisdictions (such as the United States) that may not have the same level of data protection as your home country.

When we transfer personal data out of the EEA/UK, we will take steps to ensure appropriate safeguards are in place to protect your information in accordance with GDPR Chapter V requirements. These may include:

• Adequacy Decisions: The United States is covered by an EU adequacy decision only for organisations certified under the EU-U.S. Data Privacy Framework, and we are not currently certified, so we rely on other mechanisms as described below. (We note that Delaware state law may offer its own privacy protections, but U.S. state law is not recognized as adequate by the EU at this time.)
• Standard Contractual Clauses: We have standard data protection clauses (Standard Contractual Clauses, SCCs) in place with our service providers as required, obligating them to protect EU personal data in line with EU standards.
• Your Consent or Other Derogations: In certain cases, we may rely on your explicit consent for cross- border transfer (for instance, if you initiate a transaction that inherently requires your data be sent to a non-EU country), or another permitted derogation under Article 49 GDPR (such as transfer necessary for the performance of a contract with you, e.g., an international shipping label).

You can contact us for more information on the safeguards we implement for international transfers.

7. Data Retention

We retain personal data for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. In general:

• Order and Transaction Data: We keep records of purchases, correspondence, and basic account information for at least the minimum period required by applicable law. For example, in the United States and many jurisdictions, financial records must be kept for 7 years for tax and accounting purposes. Similarly, if you make a purchase, we retain details of that transaction to provide customer service and honor our 30-Day Money Back Guarantee, returns, and any statutory rights you have under EU/UK consumer law.
• Account Information: If you create an account, we retain your account data until you request deletion or after a period of inactivity. If you request account deletion, we will delete your personal information associated with the account (except data we are required to keep for legal reasons, which we will retain securely and limit access to).
• Marketing: If you have consented to receive marketing emails, we retain your contact info for that purpose until you unsubscribe or withdraw consent. Upon unsubscribe, we may keep your email on a suppression list to ensure we honor your opt -out going forward.
• Web Logs: Our server logs and security logs (which may include IP addresses) are generally retained for a short period (e.g. 90 days) unless reviewed for a specific investigation into suspicious activity, in which case relevant data might be kept until the issue is resolved.

When we no longer have a legitimate need to process your personal data, we will securely delete or anonymize it. If deletion or anonymization is not possible (for example, because your personal data is stored in backups), then we will securely store it and isolate it from further processing until deletion is possible.

8. Your Rights and Choices

You may lodge a complaint with your local Data Protection Authority (“DPA”), such as the CNIL (France), Garante (Italy), ICO (UK), or the supervisory authority of the EU Member State where you reside.

Depending on your jurisdiction, you have certain legal rights with respect to your personal data. We are committed to honoring these rights. These may include:

For EU/EEA and UK Individuals (GDPR/DPA 2018):

• Right to Access: You have the right to request a copy of personal data we hold about you, and information about how we process it.
• Right to Rectification: You can ask us to correct inaccuracies in your personal data or complete data that is incomplete. You can also update some of your information by logging into your account, if you have one.
• Right to Erasure: You can request that we delete your personal data under certain circumstances (for example, if it’s no longer necessary for us to retain it, or if you withdraw consent and no other legal basis applies). We will honor valid requests to the extent required by law. Note that certain data cannot be deleted if we have a legal obligation to keep it (e.g. transaction history for financial reporting) or other overriding legitimate interest.
• Right to Restrict Processing: You have the right to ask us to suspend the processing of some of your data (e.g., if you contest the accuracy of the data or have objected to processing pending verification).
• Right to Data Portability: Where processing is based on your consent or a contract with you and carried out by automated means, you have the right to request a common electronic format of the data you provided to us, so you can transfer it to another provider if desired.
• Right to Object: You may object to our processing of your personal data where we rely on legitimate interests as our legal basis, and your situation has particular grounds that you believe override our interests. You also have an unconditional right to object to our processing of your personal data for direct marketing purposes – if you object, we will stop processing for marketing.
• Right not to be subject to Automated Decisions: We do not engage in automated decision-making (including profiling) that produces legal or similarly significant effects on you. If we ever do, you would have the right to human intervention and to contest the decision.

To exercise your EU/UK data rights, please contact us at contact@venatorcommerce.com with your request. We may need to verify your identity to ensure we do not disclose or delete data improperly. We will respond within one month (or up to three months for complex requests, in which case we will inform you of the need for extension). There is no fee for making a request, except in cases of excessive or unfounded requests where we are permitted by law to charge a reasonable fee or refuse.

You also have the right to lodge a complaint with a supervisory authority: If you are in the EU/EEA, you can contact your country’s Data Protection Authority; if in the UK, the Information Commissioner’s Office (ICO). We encourage you to contact us first so we can try to resolve your concerns directly.

For California Residents (CCPA/CPRA): If you are a California resident and the California Consumer Privacy Act (CCPA) applies to our processing of your data (note: CCPA generally applies to businesses with over $25 million in revenue or handling large volumes of Californians ’ data; while Paysafe LLC may not meet those thresholds yet, we still aim to honor basic requests):

• Right to Know: You can request that we disclose what personal information we collect, use, disclose, and sell (we note that we do not sell personal info). You may request the specific pieces of information or the categories of information.
• Right to Delete: You can request deletion of personal information we have collected from you, subject to certain exceptions (similar to the erasure right above).
• Right to Opt-Out of Sale/Sharing: We do not sell personal information for money, but our use of advertising pixels may constitute “sharing” for cross-context behavioral advertising under the CCPA/CPRA. You may opt out of such sharing at any time by emailing contact@venatorcommerce.com with “Do Not Share My Personal Information” in the subject, by refusing non-essential cookies in our cookie preferences, or via an opt-out preference signal (such as Global Privacy Control), which we honor where required by law.
• Right to Non- Discrimination: We will not discriminate against you for exercising any CCPA rights (meaning we won’t deny service, change pricing, or degrade service quality just because you made a data request).

To submit a California privacy request, you (or an authorized agent) may contact us at contact@venatorcommerce.com with “CCPA Request ” in the subject. We will need to verify your California residency and identity (which may involve providing additional data or signing a declaration). We aim to respond within the statutory 45 days, or inform you of an extension if needed.

For Other Regions: If you reside in a jurisdiction with specific privacy rights not listed above (e.g., Canada, Australia, Brazil’s LGPD, etc.), please know that we respect all users’ privacy and will endeavor to fulfill requests to access, correct, or delete personal data as applicable. Contact us and we will inform you of what we can do under applicable law.

Email Preferences: As noted, you can always unsubscribe from marketing emails via the link in the email. Transactional /service emails (like order confirmations, password resets) are necessary and you cannot opt out of those if you use our services, except by not using the service.

9. Data Security

We implement appropriate technical and organizational security measures to protect your personal data against unauthorized access, loss, alteration, or destruction. These measures include encryption of sensitive information (such as using HTTPS/TLS for all data transfer on our site), firewalls, access controls restricting personal data to trained staff who need it for their job, and regular security assessments of our systems. Payment information is handled by PCI- compliant processors. We also maintain procedures to handle any suspected data breach, including notifying you and authorities when required by law.

Please note that, despite our efforts, no internet or email transmission is ever fully secure or error free. You are also responsible for maintaining the confidentiality of your account password and for any access to or use of the site via your credentials. Notify us immediately if you believe your account has been compromised. We will never ask you for your password via email.

10. Third-Party Links

Our website might contain links to external websites or services that are not operated by us (for example, links to our official pages on Instagram, or references to third -party reviews or resources). This Privacy Policy only applies to our website and services. Once you leave our site or interact with a third -party integration, that third party’s privacy policy will apply. We are not responsible for the content or privacy practices of third -party sites. We encourage you to review the privacy policies of any external sites you visit.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational reasons. The “Last Updated ” date at the top of this Policy indicates when it was last revised. If we make material changes (for example, if we start collecting additional personal data or using data in a new way that you might not expect), we will provide a more prominent notice of the change, such as by posting an alert on our homepage or emailing users who are affected, where required by law. We encourage you to review this Policy periodically to stay informed about how we are protecting your information.

By continuing to use our website or services after any updates become effective, you acknowledge the revised Policy. If you do not agree to the changes, you should stop using the site and can request us to delete your personal data if applicable.

12. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please contact us:

• Email: contact@venatorcommerce.com (please indicate that it is a privacy-related inquiry).
• Postal Mail: Data Protection Officer (or Privacy Team), Paysafe LLC, 8 The Green, Ste B, Dover, Delaware 19901, United States.

We will do our best to address and resolve your inquiries. If you feel we have not adequately addressed your concerns, you also have the right to seek further recourse with the appropriate data protection authority or regulator in your jurisdiction.