1. Who is responsible
The legal operator trading as Second Language is the controller of personal data collected through this storefront. That means the operator decides why and how that information is used.
Second LanguageController: Ralfs Ozolins, sole trader
Bauwenberg 17, 1970 Wezembeek-Oppem, Belgium
Privacy contact: contact@wearsecondlanguage.com
You can use that address for any privacy question or request. You do not need special wording or a form.
2. What we collect
When you browse
Our hosting provider receives the technical information needed to send the site to your device and protect it, such as an IP address, request time, requested page, browser or device information, and security logs. Vercel Web Analytics also provides aggregated, cookie-free visit and interaction counts. We do not run advertising pixels or cross-site tracking on this storefront.
When you use the bag or size tools
The site can save your bag contents, bundle choices, selected sizes, theme and motion preferences, and whether the first-order code has been issued. This information is stored in local storage on your device. It does not contain your name, email, payment details, or delivery address, and the storefront does not send it to us merely because it is saved.
When you join the email list
We collect the email address you enter. The form sends it to a Google Form connected to the operator’s Google account. The first-order code is also saved locally in your browser so the bag can apply it.
When you place an order
Shopify’s checkout collects the information needed to take payment and fulfil the order. Depending on the order, that can include your name, email, telephone number, billing and delivery addresses, order contents, size choices, discount information, payment status, transaction identifiers, and messages about the order. Payment providers handle card or account details; Second Language does not receive your full card number.
When you contact us or return something
We receive the information in your message and anything you attach, such as an order number, photographs of a damaged item, delivery information, or the details needed to handle a return, complaint, access request, or refund.
3. Why we use it
We use personal data only where there is a legal reason to do so:
- To perform a contract: take payment, confirm and fulfil an order, provide delivery updates, handle returns, issue refunds, and answer order-related questions.
- With your consent: send the first-order code and an occasional email when a new design lands. You can withdraw that consent at any time.
- For legitimate interests: keep the site secure, prevent fraud, understand aggregate site use, fix faults, respond to non-order enquiries, and protect or establish legal claims. We balance those interests against your rights.
- To meet legal obligations: keep required transaction and accounting records, respond to lawful requests, and honour consumer, tax, and data-protection duties.
We do not sell personal data. We do not use it to build advertising profiles, run behavioural ads, or make decisions about you solely by automated means that have legal or similarly significant effects.
4. Cookies and local storage
The storefront itself sets no cookies. It uses local storage for functions you ask it to remember: your bag, bundle, sizes, display preferences, and first-order code. Local storage stays on your device until the site removes it or you clear it through your browser settings.
Local storage is not sent automatically with every web request as a cookie would be. When you proceed to Shopify checkout, the products, variants, quantities, and discount needed to create that checkout are included in the checkout link.
Shopify’s hosted checkout is a separate service and may use cookies or similar technology required for checkout, fraud prevention, payment, and security. Its notices and controls appear in that checkout environment.
6. Processing outside your country
Some providers operate internationally, so personal data may be processed outside your country and, in some cases, outside the European Economic Area. Where EU law requires a transfer safeguard, the relevant provider or controller must rely on a recognised mechanism such as an adequacy decision or approved contractual clauses, together with any necessary supplementary protection.
Contact us if you want more information about the safeguard used for a particular service or transfer.
7. How long we keep it
- Order, payment, invoice, and accounting records: 10 years where Belgian accounting or tax law requires that period. A legal retention duty can override an erasure request for that record.
- Email-list address: until you unsubscribe, withdraw consent, ask for deletion, or the list is closed. After an objection or unsubscribe request, we may keep the minimum suppression record needed to prevent an accidental re-subscription for as long as the marketing activity continues.
- Customer-service messages: 2 years after the matter is closed, unless a longer period is needed for an active dispute or a legal duty.
- Security and hosting logs: for the limited period set by the hosting provider and needed for security, troubleshooting, and abuse prevention.
- Local storage: on your device until you clear it or the site removes the relevant entry.
When information is no longer needed, it is deleted or anonymised unless the law requires it to be kept.
8. Your data rights
Depending on where you live and the circumstances, you may have the right to ask for access to your personal data, correct it, delete it, restrict its use, receive a portable copy, or object to processing based on legitimate interests. Where processing relies on consent, you can withdraw consent at any time without affecting earlier lawful use.
Email contact@wearsecondlanguage.com and say what you want us to do. We may ask for enough information to confirm your identity and find the relevant record. We normally respond within one month, subject to any lawful extension for a complex or numerous request.
You can unsubscribe from marketing using the link in an email or by writing to us. You can clear the storefront’s saved bag and preferences through your browser’s site-data settings.
You also have the right to complain to the data-protection authority where you live, work, or believe an infringement happened. We would still like the chance to fix the issue directly.
9. Security and children
We use appropriate technical and organisational measures for the nature of the information involved. The storefront is delivered over HTTPS, payment is handled in hosted checkout rather than by this site, access to service accounts should be restricted, and providers are chosen for the specific functions described above.
No online system is perfectly secure. If a personal-data breach creates a risk that requires notice, we will notify the relevant authority and affected people as required by law.
The shop is not directed at children, and we do not knowingly collect a child’s personal data for marketing. A parent or guardian can contact us if they believe a child has submitted information.
10. Changes and questions
We will update this policy if the shop’s data use, providers, or legal duties change. A material change will be made clear on the site where appropriate. The effective date at the top shows the current version.
Questions, objections, deletion requests, and everything else go to contact@wearsecondlanguage.com.