Squishiii

Privacy Policy

Last updated: 26 August 2026

This Privacy Policy explains how Forenzo OÜ (registry code 17583268), registered at Vilja tee 1, Savikoti küla, Viljandi vald, Viljandi maakond, 71103, Estonia, trading as Squishiii ("we", "us", "our"), collects, uses, and protects your personal data when you use https://squishiii.com (the "Service"). We are the data controller for the personal data described in this policy.

1. Information We Collect

Account information. If you create an account, we process your email address and password (your password is hashed by our authentication provider, Supabase, and is never stored or visible to us in plain text). Your account profile may also include a username, an optional full name, and the date your account was created.

Saved addresses. If you save a shipping address to your account, it may include a label, full name, address line 1/2, city, postal code, and country. You can delete a saved address at any time from your account settings.

Order information. When you place an order, we process your email address, order status, subtotal, currency, a snapshot of the shipping address used for that order, a reference ID from our payment processor (Stripe), your account ID where applicable, and the products, quantities, and prices in the order.

Newsletter. If you subscribe to our newsletter, we collect your email address for that purpose only.

Technical and usage information. Like most websites, some basic technical information (such as IP address and request information) passes through our hosting infrastructure as part of normal web traffic. See Sections 5 and 8 below for how this is used and shared.

2. How We Use Your Information

  • To create and manage your account, including login and order history.
  • To process, fulfil, and provide customer service for your orders.
  • To send order confirmations, shipping updates, and other transactional messages.
  • To send newsletter updates, if you've subscribed.
  • To maintain the security of the Service and prevent abuse.
  • To meet our legal and accounting obligations.
  • Where you've given consent, to measure and improve our advertising (see Section 6).

3. Legal Bases for Processing

Where GDPR applies, we rely on the following legal bases, depending on the specific processing activity:

  • Performance of a contract — for account creation, order processing and fulfilment, and customer service.
  • Legal obligation — for retaining order and accounting records as required by law.
  • Consent — for the newsletter, and for non-essential advertising cookies/pixels (Meta Pixel and TikTok Pixel).
  • Legitimate interests — for maintaining the security of the Service and preventing abuse (for example, limited use of IP addresses to prevent brute-force attempts on certain endpoints), where this does not override your rights and interests.

4. Service Providers We Use

We share personal data with the following service providers, each only to the extent necessary for them to perform their function on our behalf:

  • Supabase — provides our account authentication and database, including storage of profile, address, order, and newsletter subscriber data. Our Supabase project is configured to store and process this data in the EU (Ireland).
  • Stripe — processes payments. Checkout is hosted entirely by Stripe; your card number, expiry date, and CVC are entered directly with Stripe and never reach our servers. We send Stripe your email address and, where applicable, an internal customer reference, in order to create the checkout session. Stripe acts as our processor for payment services, and may also act as an independent controller for its own purposes, such as fraud prevention and compliance.
  • Resend — sends our transactional emails (such as order confirmations, shipping updates, and password resets) and newsletter emails. Resend receives the recipient's email address and the content necessary to send each email.
  • Vercel — hosts the Service. As with any hosted website, technical request information (such as IP address and request headers) passes through Vercel's infrastructure as part of normal operation. We also use Vercel Analytics, a cookie-free, privacy-oriented analytics tool that does not use persistent individual tracking identifiers, for basic traffic statistics.
  • Upstash — provides short-lived rate limiting to protect certain parts of the Service (such as login, checkout, and newsletter signup) against abuse and brute-force attempts. Only IP addresses are processed for this purpose, and only for a short time (a few minutes to at most one hour) before being automatically discarded.
  • Meta (Facebook/Instagram) and TikTok — used for advertising measurement, only after you've given consent. See Section 6.

5. Cookies and Local Storage

Essential (always on). We use browser local storage — which is not the same as a cookie, though it serves a similar purpose — to keep items in your shopping cart, remember your cookie preference, and remember if you've dismissed certain on-site notices. We also use necessary cookies for signed-in sessions and for admin authentication, using secure, HttpOnly cookies. None of this is used for advertising, and none of it requires consent, as it is necessary for the Service to function and to keep it secure.

Non-essential (requires your consent). The Meta Pixel and TikTok Pixel are only loaded, and only begin sending events, after you've actively accepted non-essential cookies via the banner shown on your first visit. These may process page views and shopping events (such as adding an item to your cart, starting checkout, or completing a purchase), including product information, order value, and currency. Meta and TikTok may also independently collect technical information such as your IP address and browser information, and may set their own advertising cookies, as part of how their tools work.

You can review or change your choice at any time using Cookie Settings in the site footer, without needing to clear your browser data. If you withdraw consent, the Meta Pixel and TikTok Pixel stop sending further events going forward.

6. International Data Transfers

Some of our service providers process personal data outside the European Economic Area (EEA), including in the United States. This currently applies to Stripe, Resend, Vercel, Upstash, Meta, and TikTok. Where this occurs, appropriate safeguards apply, such as the European Commission's Standard Contractual Clauses, adequacy mechanisms, or other legally recognised transfer safeguards, depending on the provider and the specific processing involved.

7. Data Retention

We retain personal data only for as long as necessary for the purposes described in this policy, or as required by law. In general:

  • Account, profile, and saved address data is retained while your account is active.
  • Order and accounting information is retained for as long as necessary to fulfil our legal and accounting obligations, and otherwise only for as long as necessary for the purposes described above.
  • Newsletter subscriber data is retained while you remain subscribed, unless a longer retention period is required for legitimate legal or documentation purposes.

You can delete your account at any time from your account settings. This removes your authentication account, profile, and saved addresses. Order records are not deleted when you delete your account, because we may be legally required to retain order and accounting records — instead, the order's association with your account is removed, while the order record itself is retained.

8. Security

We use reasonable technical and organisational measures to protect your personal data, including access controls, secure authentication, encrypted connections, and appropriate infrastructure safeguards. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Children

The Service is not directed at children, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will take appropriate steps to address it.

10. Your Rights

Depending on your location and the specific processing activity, you may have the following rights under the GDPR:

  • the right of access to your personal data;
  • the right to rectification of inaccurate data;
  • the right to erasure of your data, where applicable;
  • the right to restriction of processing, where applicable;
  • the right to object to certain processing, where applicable;
  • the right to data portability, where applicable;
  • the right to withdraw your consent at any time, where processing is based on consent (this does not affect the lawfulness of processing before withdrawal); and
  • the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), or your local supervisory authority.

Not every right applies to every type of processing described in this policy. To exercise any of these rights, or with any privacy questions, contact us at hello@squishiii.com.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make a material change, we will update the "Last updated" date at the top of this page.

12. Contact

For any privacy questions or to exercise your rights, contact us at hello@squishiii.com.