Privacy Policy
Privacy Policy
Last updated: May 1, 2026
This Privacy Policy explains how Hormoona Ltd OOD collects, uses, and protects your personal data when you visit hormoona.com (the “Site”), buy our products, or contact us. We aim to be plain-spoken and honest about what we do with your data.
1. Who we are (data controller)
The data controller responsible for your personal data is:
Hormoona Ltd OOD
57 Cherkovna St., office 15
Sofia 1505, Bulgaria
VAT: BG208463867
Email: admin@hormoona.com
2. What we collect
We collect the following categories of personal data:
- Identity and contact data — name, email address, phone number, billing address, shipping address.
- Order and transaction data — items purchased, order amount, subscription status, refund history. Payment card details are entered directly into our payment processors and we do not see or store full card numbers.
- Account data — login credentials and preferences if you create an account.
- Communications — messages you send us by email, contact form, or social media; reviews you submit; survey or quiz answers.
- Marketing preferences — your opt-in/opt-out status for email and SMS, language and currency preferences.
- Technical data — IP address, device type, browser, operating system, referring URL, pages visited, time on page, and approximate location derived from IP.
- Cookie and tracking data — see “Cookies and tracking” below.
3. How we collect it
- Directly from you when you place an order, create an account, take a quiz, sign up to email or SMS, contact support, or leave a review.
- Automatically through cookies and similar technologies when you browse the Site.
- From third parties — for example, our payment processors confirm payment status; ad platforms confirm whether a click converted; our shipping carriers confirm delivery status.
4. Why we use it (legal basis)
Under the EU General Data Protection Regulation (GDPR) and similar laws, every use of your data has a legal basis. Ours are:
- To perform our contract with you — processing orders, taking payment, shipping products, managing subscriptions, handling refunds and customer service. Legal basis: contract.
- To comply with legal obligations — keeping accounting and tax records, responding to law enforcement, meeting consumer-protection rules. Legal basis: legal obligation.
- To run and improve our business — preventing fraud, securing the Site, analysing how customers use the Site, and improving the product. Legal basis: legitimate interest.
- To send you marketing — newsletters, product launches, promotions, abandoned-cart reminders. Legal basis: consent (or, where permitted, legitimate interest in marketing similar products to existing customers, with an easy opt-out).
- For analytics and advertising cookies — measuring traffic, audiences, and ad performance. Legal basis: consent.
5. Who we share it with
We never sell your personal data. We share it only with service providers who help us run the Site and the business, and only to the extent they need it. Typical recipients include:
- Our ecommerce platform (Shopify) and any apps installed on the store.
- Payment processors (such as Shopify Payments, Stripe, PayPal) for taking payment.
- Subscription management providers.
- Shipping and fulfilment partners (3PLs, carriers).
- Email and SMS marketing platforms.
- Customer support and helpdesk tools.
- Analytics providers (such as Google Analytics, Microsoft Clarity, Meta Pixel, TikTok Pixel) — only after you accept analytics/marketing cookies.
- Review platforms (such as Judge.me).
- Professional advisors (lawyers, accountants, auditors) when needed.
- Authorities, regulators, or successors in interest where legally required (for example, in response to a subpoena, or in connection with a merger or sale).
6. International transfers
Some of our service providers are based outside the European Economic Area (notably in the United States). Where we transfer personal data outside the EEA, we rely on the European Commission’s Standard Contractual Clauses or another approved transfer mechanism, and we apply additional safeguards where appropriate.
7. How long we keep it
- Order and transaction data — for the length of our legal record-keeping obligations (typically up to 10 years for tax and accounting purposes).
- Account data — until you ask us to delete the account, plus any retention required for legal reasons.
- Marketing data — until you unsubscribe or withdraw consent, plus a short suppression record so we don’t accidentally email you again.
- Support emails — typically 3 years from the last interaction.
- Analytics and tracking data — see the cookie information for retention periods on each tool.
8. Your rights
Depending on your country, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Correction — ask us to fix data that is inaccurate or incomplete.
- Deletion — ask us to delete your data, subject to our legal record-keeping obligations.
- Restriction — ask us to limit how we use your data while a request is being resolved.
- Portability — receive a copy of your data in a structured, machine-readable format.
- Objection — object to processing based on our legitimate interests, including direct marketing.
- Withdraw consent — at any time, where we rely on consent (e.g. marketing emails, non-essential cookies). Withdrawing consent does not affect lawful processing that already happened.
- Lodge a complaint with your national data-protection authority. In Bulgaria, that is the Commission for Personal Data Protection (CPDP) — cpdp.bg/en.
To exercise any of these rights, email admin@hormoona.com. We will respond within one month.
9. Cookies and tracking
We use cookies and similar technologies to make the Site work, remember your preferences, measure performance, and (with your consent) show you relevant ads. The first time you visit the Site, you will see a cookie banner where you can accept all, reject all, or choose categories.
- Strictly necessary — required for the cart, checkout, login, and security. Always on.
- Functional — remember preferences such as language or currency.
- Analytics — anonymised traffic and behaviour analysis (e.g. Google Analytics, Microsoft Clarity).
- Marketing — measure and target ads (e.g. Meta Pixel, TikTok Pixel, Google Ads).
You can change your cookie choices at any time by clicking the “Cookie settings” link in the footer of the Site or by clearing cookies in your browser.
10. Marketing
- You can unsubscribe from marketing emails at any time using the “unsubscribe” link at the bottom of every email, or by emailing admin@hormoona.com.
- You can stop SMS marketing at any time by replying STOP to any message.
- Even after you unsubscribe from marketing, we will still send you transactional messages (order confirmations, shipping updates, refund notifications) because they are necessary to fulfil our contract with you.
11. Children
The Site is not directed to children under 18, and we do not knowingly collect personal data from anyone under 18. If you believe we have collected data from a minor, contact admin@hormoona.com and we will delete it.
12. Security
We use industry-standard technical and organisational measures to protect your data, including HTTPS encryption, access controls, and partnering with reputable processors. No system is perfectly secure, however, and we can’t guarantee that data transmitted over the internet is 100% safe. If you suspect a security incident, contact us immediately at admin@hormoona.com.
13. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of the page reflects the most recent version. If we make material changes, we will notify you by email or by a prominent notice on the Site before the change takes effect.
14. Contact us
For any questions about your personal data or this policy, please email admin@hormoona.com.
Hormoona Ltd OOD
57 Cherkovna St., office 15
Sofia 1505, Bulgaria
VAT: BG208463867
admin@hormoona.com