Privacy Policy

Last update: 01.11. 2024

 

ONE TEA TREE is an online store www.oneteatree.co (hereinafter — the «Website»), together with the services, that is operated by individual entrepreneur Holovko Yelyzaveta, registered at 17h Koltsova Boulevard, apt. 87, Kyiv, 03194, Ukraine, taxpayer identification number 3619910166, date and the number of the records in Unified State Register as of June 07, 2023, 2 010 350 0000 00325417 (hereinafter — «ONE TEA TREE», «We», «Our»).

In the course of Our activities on Goods offer/sales on the Website, for the arrangement of the Goods delivery to the customers, and for other connected and related purposes, We collect, store, disclose, and/or otherwise process the Personal Data of Our Users.

Our Users’ and Visitors’ privacy and security are of primary importance to Us! We undertake to protect the data You provide to Us. This Privacy Policy explains how ONE TEA TREE processes Personal Data and has been collected using Our Website.

 

1. GENERAL INFORMATION

 

1.1. This Policy applies to the following individuals:

  • 1.1.1. any individual who places Order(s) of Goods available on Our Website or otherwise uses Our Website, for instance — create an account (for this Policy, We define the term «User», «You», «Your», or «Data Subject»);
  • 1.1.2. any individual who visits Our Website, including Users (for this Privacy Policy, We define the term «Visitor», «You», «Your», or «Data Subject»);
  • 1.1.3. any individual who initiates communication with Us (sends requests, leaves feedback, sends claims, etc.) via communication channels available on the Website, other channels except via the Website, or via any other means of communication (for this Privacy Policy, We define the term «Visitor», «You», «Your», or «Data Subject»).

1.2. This Privacy Policy applies only to Our Website.

1.3. Please be attentive when visiting or using Our Website! Our Website may contain links to other websites. Once You link to another website, this Privacy Policy no longer applies. We are not responsible for the content or privacy policies of other websites.

1.4. We assume that all Visitors and Users have read this Privacy Policy carefully, understand its content, and agree to the terms and conditions outlined herein. If You do not agree to this Privacy Policy, You must refrain from using Our Website.

1.5. Amendment of the Privacy Policy. We may from time to time amend and update Our Privacy Policy, so please review it frequently. We reserve the right to change and update this Privacy Policy at any time and without prior notice.

  • 1.5.1. All amendments and updates to this Privacy Policy are effective from the moment they are posted on the Website. Your continued access to and/or use of the Website constitutes Your consent to the new revision of this Privacy Policy and its application to all information collected before and after its effective date.
  • 1.5.2. If there are any amendments to this Privacy Policy that We believe are material/substantial, We will use Our reasonable efforts to notify You in advance through Your contact information provided to Us or by posting a notice on Our Website. However, We don’t undertake and hereby disclaim any obligation in relation to such notification.

 

2. TERMS AND DEFINITIONS

 

2.1. The following terms shall have the following meaning:

  • 2.1.1. «Cookies» — small text files placed on Your device, such as Your computer, smartphone, or tablet, by Your browser when You visit a website. They allow You to be recognized as the same Visitor/User and store information collected on one web page until it is needed for use on another.
  • 2.1.2. «Data Controller» — an individual or legal entity who (either alone or jointly or in common with other persons) determines the purposes and means of how and which Personal Data are (or are to be) processed.
  • 2.1.3. «Personal Data» — information that can be used to directly or indirectly identify individuals and has been collected through Our Website or the use thereof.

2.2. Any terms and definitions not expressly defined herein shall carry the meanings ascribed to them in ONE TEA TREE Terms of Use and Public Offer.

 

3. DATA CONTROLLER

 

3.1. ONE TEA TREE is the Data Controller which defines the purposes and means of processing of the Personal Data that are collected and used within the scope of this Privacy Policy.

3.2. Collection channels. Users’ and Visitors’ Personal Data may be collected through the following channels (including, but not limited to):

  • 3.2.1. ONE TEA TREE Website: when visiting the Website, when filling out the contact form on the Website by the User or Visitor, when creating an account by the User (including through accounts within the third-party services available on the Website, for example, Facebook/Google/X and/or others), when creating and placing an Order/Orders for Goods, during other use of the Website according to its functionality.
  • 3.2.2. Websites and services, operated by third parties using embedded Cookies, pixels, or other tracking technologies.

 

4. PRINCIPLES OF DATA PROCESSING

 

4.1. We adhere to the following principles of data processing in relation to the Personal Data:

  • 4.1.1. principle of «purposeful limitation» — We process Personal Data fairly and transparently, solely for the achievement of specific, clear, and legitimate purposes, and We do not process them in a manner inconsistent with such data processing purposes;
  • 4.1.2. principle of «data minimization» — We collect Personal Data only to the extent necessary to achieve the defined purposes. We do not store Personal Data if it is no longer needed, or if the purposes for which the Personal Data was collected have been achieved, or if they are not necessary for other legitimate purposes anymore;
  • 4.1.3. principle of «limited use» — We use Personal Data for any other purpose only with the consent of the Data Subject, or without such consent if the competent authority expressly permits it or it is stipulated by legislation;
  • 4.1.4. principle of «data quality» — We always keep Personal Data up-to-date and complete to achieve the ultimate purpose of data processing more effectively;
  • 4.1.5. principle of «security and integrity» — We process Personal Data in a way that ensures adequate security of Personal Data, in particular their protection against unauthorized or unlawful processing and accidental loss, destruction, or corruption, using appropriate technical and organizational measures;
  • 4.1.6. principle of «individual participation» — We inform Users and Visitors about Personal Data collection, where appropriate or required. Users and Visitors have the right to access their Personal Data and request the correction of inaccurate or misleading data and the deletion of Personal Data.

 

5. PERSONAL DATA THAT WE COLLECT AND PROCESS

 

5.1. In order to fulfill Our obligations to enable You to create an account on the Website, We have the right to ask You to provide Us with the following Personal Data, including (but not limited to):

  • 5.1.1. Username;
  • 5.1.2. First and Last Name;
  • 5.1.3. Email address;
  • 5.1.4. User password (can be stored in an encrypted form, using a hashing algorithm that is not available for retrieval, or other similar methods of encryption, anonymization, and security).

5.2. In order to fulfill Our obligations to provide You with the option to Order Goods, to deliver or return Goods, as well as to identify and solve issues with delivery and related matters, We have the right to ask You to provide Us with the following Personal Data, including (but not limited to):

  • 5.2.1. First and Last Name;
  • 5.2.2. Email address;
  • 5.2.3. Phone number;
  • 5.2.4. The postal address for the delivery of the Goods and/or the details of the Carrier’s branch for the delivery of the Goods.

5.3. In order to fulfill Our obligations to provide You with the option to subscribe to the newsletter of advertising, marketing, and similar materials and their further receipt from Us, We have the right to ask You to provide Us with the following Personal Data, including (but not limited to):

  • 5.3.1. Email address.

5.4. For marketing purposes – to attract new customers and to determine the preferences of our Users, we plan to use the analytical tools of the Google Analytics and Meta Pixel systems. During their use, we collect and store the following Personal Data regarding Users:

  • 5.4.1. The browser in where User’s actions were registered;
  • 5.4.2. Continent, subcontinent, region, country, city where User’s actions were registered;
  • 5.4.3. Brand, type, model, operating system, its version and platform of the device used by the User;
  • 5.4.4. Language of the site;
  • 5.4.5. IP address;
  • 5.4.6. Pixel ID and Facebook Cookie;
  • 5.4.7. Information regarding buttons, pressed by the User and their names, the names of the corresponding sections of the Website.

5.5. We may also collect, process, and store other personally identifiable information that You provide to Us in emails or other communications from You. WE ASK YOU TO CAREFULLY REVIEW AND CHECK THE CONTENT AND SCOPE OF THE INFORMATION PROVIDED VIA SUCH COMMUNICATIONS.

5.6. When accessing the Website, We may also receive:

  • 5.6.1. GeoIP — the current location of the User, a method of determining the geographic location of a computer terminal by determining the IP address of this terminal. The User can disable/set these Cookies through the authorization system used on their mobile or computer devices, including but not limited to іOS, Android, web browsers, etc.

5.7. We may collect, record, and analyze information about the Visitors. If Our Website is accessed solely for information, i.e., when You do not provide Us with any information, We collect only Personal Data that Your browser has transmitted to Our server. If You wish to visit Our Website, We collect and store the following data (after this — the «Usage Data»), which is necessary for technical purposes to enable Us to display Our Website to You and to ensure sufficient stability and security of access (therefore, the legal basis for this is the legitimate interest of ONE TEA TREE):

  • 5.7.1. IP address;
  • 5.7.2. Date and time of request;
  • 5.7.3. Difference in time zones for Greenwich (GMT);
  • 5.7.4. Content of the request (exact access to the web page);
  • 5.7.5. Access status / HTTP status code;
  • 5.7.6. Scope of transferred data in each case;
  • 5.7.7. Website for forming a request;
  • 5.7.8. Browser;
  • 5.7.9. OS and OS interface;
  • 5.7.10. Browser language and version.

5.8. We use this Usage Data in the aggregate to evaluate the popularity of web pages on Our Website and the effectiveness of Our content delivered to You. In combination with other information We know about You from previous visits, this data may be used to identify You personally. The information collected in this way is stored for up to 36 (thirty-six) months.

5.9. Purposes of processing. We can use the Personal Data collected from You for various purposes (in addition to those specified in other provisions of this Privacy Policy) primarily related to providing access to the Website and placing Order/Orders for Goods on this Website, and information regarding Website and Our Goods, including (but not limited to) (i) satisfying Your request regarding the Website and Our Goods for the purpose of formalizing contractual relations, (ii) processing Your requests, (iii) providing a greater and better experience with the Website, (iv) processing Order/Orders or other transactions and issuing invoices, (v) comply with Our legal obligations under applicable laws, regulations, court orders, or other legal processes, and (vi) for any other purposes, which We determine at Our sole discretion to be necessary or required to ensure the safety of Our Users, personnel, third parties, the public and/or Our activities, or to comply with any applicable law, and (vii) for other purposes as permitted by law.

 

6. LEGAL (LAWFUL) BASIS FOR DATA PROCESSING

 

6.1. The legal basis (ground) for the processing of the Personal Data of Our Visitors/Users is their consent to the processing of their Personal Data which can be given, in particular (but not exclusively), by the User pressing the button «I agree to this Privacy Policy and give consent to the Personal Data processing» (or with another similar wording as may be available). We use such Personal Data in ways You would reasonably expect and that have minimal impact on Your privacy.

6.2. The legal basis (ground) for the processing of Personal Data for marketing purposes is also the consent obtained from You, which can be given, in particular (but not exclusively), by the Visitor/User pressing the button «I wish to receive marketing material» (or with another similar wording as may be available). We use such Personal Data in ways You would reasonably expect and that have minimal impact on Your privacy.

6.3. The legal basis (ground) for Usage Data processing is Our legitimate interest. It is necessary for the efficient and effective management, the conduct of Our activities, and the provision of quality services to the Visitor and User, including Website support, development, and improvement, and to identify who may be interested in such, and for other related purposes.

6.4. You can contact Us by sending Us a request to Our email hi@oneteatree.co. Please specify Your name, phone number (messenger), as well as the content of Your request. We only use the Personal Data collected to contact You while You are waiting for Our response to Your request, and We may also record Your request and Our response to improve the efficiency of the organization and operation of Our support service. We store information that can be used to identify You personally related to Your request, such as Your name and phone number (messenger) (if You have provided Us with such data) so that We can contact You and provide quality service. If You do not want Us to collect Your Personal Data, do not use Our contact form and do not give Your consent. However, regardless of whether You use Our contact form or not, certain Cookies are always active on Our Website and may be placed without Your consent, which is described more specifically below.

6.5. Wherever possible, We seek to obtain Your explicit consent to the processing of Your Personal Data, for example, by asking You to consent to the use of Cookies. At the same time, Your consent applies to all actions related to the processing of Your Personal Data, which are carried out with the same purpose(s). If the processing has several purposes, Your consent is deemed to be given for all of these purposes.

6.6. Visitors and Users can control the use of Cookies at a specific browser level. If You reject Cookies, You may still use Our Website, but Your ability to use certain features or sections of Our Website may be limited, as described more specifically below.

7. COOKIES

7.1. Cookies can be used to store Your passwords or other identification data, Website browsing settings, and Goods selected when placing Your Order/Orders on the Website, as well as for other purposes such as collecting statistics and marketing.

7.2. Cookies help You to use the Website more conveniently, and also help Us learn more about Your preferences and offer You personalized Goods. Cookies saved from Our Website are read every time You visit the Website again, and can provide certain conveniences, for example, You no longer need to re-enter passwords, select Goods that have already been moved to the cart, etc.

7.3. Most browsers automatically accept Cookies, but You can change these settings. You can find a more detailed description of how to do this on the Internet, on the website of the developer of Your browser, or via other official resources. Unfortunately, if You disable Cookies, certain functionality of web pages will (or may) not be available to You, including the possibility of placing an Order/Orders for Goods through Our Website.

7.4. Types of Cookies used by the Website:

  • 7.4.1. «Strictly necessary/Technical Cookies» are essential for the proper functioning of Our Website, and its main functions, and are used for technical purposes, such as saving the Goods You have selected, proceeding to their payment, etc. Such Cookies cannot be disabled, they are always active and will be placed without Your consent;
  • 7.4.2. «Functional Cookies» — allow Our Website to store Your login, language choice, location, etc., for more convenient use of the Website by You and personalization of Your experience on the Website;
  • 7.4.3. «Marketing Cookies» — help personalize Your preferences and offer only those Products that may interest You;
  • 7.4.4. «Session Cookies» — certain Cookie files can be sessional, they allow Us to synchronize the User’s interaction during the browser session (record information viewed on the Website, etc.). Session Cookies expire when the browser session ends, so they are not stored after it is closed.

 

8. COMPLIANCE WITH REGULATIONS

 

8.1. For Visitors and Users located in Ukraine, the collection, processing, and use of Personal Data is carried out in accordance with the Law of Ukraine «On Personal Data Protection» adopted on June 1, 2010 № 2297-VI (not official translation). You can find an official version of the Law here (available in Ukrainian only).

8.2. For Visitors and Users located in the European Economic Area («EEA»), privacy rights are granted, and all processing and transfer of Personal Data is carried out in accordance with the regulations and rules of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27th April 2016 «On the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data, known as the General Data Protection Regulation» («GDPR»). ONE TEA TREE processes the Personal Data of Visitors and Users as a Controller as defined in the GDPR.

8.3. For non-EU persons. Personal Data is treated in compliance with generally accepted international laws and applicable to You regulations, including, but not limited to:

  • 8.3.1. If You are located in California (the USA), collection and processing of Personal Data is performed in accordance with regulations and rules following the California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq. («CCPA»). For identification of requirements regarding Personal Data in other states, legislation/regulation provisions of those states are applicable.
  • 8.3.2. If You are located in Canada, collection and processing of Personal Data is performed in accordance with regulations and rules following Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5).
  • 8.3.3. If You are located in the United Kingdom, collection and processing of Personal Data is performed in accordance with regulations and rules following the Data Protection Act 2018 («DPA 2018»).
  • 8.3.4. If You are located in the United Arab Emirates, collection and processing of Personal Data is performed in accordance with regulations and rules following Federal Decree by Law No. (45) of 2021 Concerning the Protection of Personal Data.

8.4. We do not sell and in any other way transfer Your Personal Data to third parties.

8.5. If We decide to transfer the rights to the Website, We will inform You about this, so You can forbid Us from transferring Your Personal Data together with Our assets. If so, We will delete Your Personal Data from the databases prior to the assets transfer.

8.6. If You believe Our Privacy Policy does not comply with the laws of Your jurisdiction, We would like to receive Your feedback. Ultimately, however, it is Your choice whether or not You wish to use Our Website.

 

9. THE RIGHTS OF USERS

 

9.1. Visitors and Users may review, correct, update, delete, and transmit their Personal Data. To correct Your Personal Data, Users can use the functionality available in their personal account on the Website. To сorrect data by Visitors, delete data, and for related issues, please send Us a request via email hi@oneteatree.co. We will acknowledge Your request within 96 (ninety six) hours and process it within terms stipulated by applicable laws.

9.2. Subject to possible restrictions under applicable national law of the Data Subject, You may have certain rights regarding the Personal Data that We collect from You, particularly:

  • 9.2.1. Right to object to the processing of Your Personal Data. Visitors and Users have the right to object to (reject from) Our processing of their Personal Data by contacting Us at hi@oneteatree.co or using the functionality of the Website. Once We receive an objection, We will no longer process Your Personal Data unless it is necessary to conduct Our activities or We demonstrate other legitimate grounds for Our processing that override Your interests, rights, and freedoms or for necessary legal proceedings.
  • 9.2.2. Right to access Your Personal Data. Visitors and Users have the right to find out whether We process their Personal Data, what categories of Personal Data We process about them, the purposes of the processing, the categories of third parties to whom We may disclose the Personal Data of Visitors and Users, the storage period of their Personal Data or the criteria for determining it by contacting Us at hi@oneteatree.co.
  • 9.2.3. Right to verification and correction. Visitors and Users have the right to verify their Personal Data’s accuracy and request its update or correction. Upon receipt of such a request, We have the right to verify the grounds for updating or correcting Personal Data and request additional information and documents from You that confirm such grounds. If there are sufficient grounds to update or correct Personal Data, We will use Our reasonable efforts to make the necessary changes as soon as possible.
  • 9.2.4. Right to restrict the processing of Your Personal Data. Visitors and Users have the right, under specific circumstances, to request that We restrict the processing of their Personal Data as required by applicable data protection laws, such as when Our processing is unlawful. In that case, We will not process Your Personal Data for any purpose other than to store it.
  • 9.2.5. Right to receive Your Personal Data and to transmit it to another Data Controller. Where Our processing is based on Your consent and is carried out by automated means, You have the right to receive Your Personal Data in a structured, commonly used, and machine-readable format and, where technically feasible, to transmit it to another Controller without any hindrance.
  • 9.2.6. Right to withdraw consent. If Our processing is based on Your consent, You may withdraw Your consent at any time by sending Us an email to hi@oneteatree.co with Your request for Personal Data to be deleted, and We will delete Your Personal Data within 96 (ninety six) hours.

9.3. You also have the right to file a complaint with a supervisory authority if You believe We are violating Your rights. But We ask You to contact Us first with a request to the email hi@oneteatree.co so that We can help You.

9.4. When We receive any request to access, edit, or delete personally identifiable information, We reserve the right to initially take reasonable steps to verify Your identity before granting You access or otherwise taking action. This is essential to protect Your Personal Data and procure privacy.

 

10. ADVERTISING OFFERS, INFORMATIONAL AND MARKETING MESSAGES

 

10.1. We may send marketing newsletters and information notifications to Users and Visitors through the provided email address. Where required by law, We ask for Your explicit consent to receive such messages. When We send You messages, We aim to include instructions on how to further opt out of receiving such messages. Still, if We do not include such instructions, You may contact Us at hi@oneteatree.co to unsubscribe from receiving such messages.

10.2. We may use Your Personal Data to form an idea of what We think You may need or be interested in. This is how We decide which Goods and offers may be relevant to You (We call this marketing).

10.3. You will receive marketing newsletters and information notifications and other news about Our Goods from Us if You have requested information or purchased Our Goods or if You have provided Us with Your Personal Data when You contacted Us and explicitly indicated that You wish to receive such newsletters/notifications or if You provided Us prior consent as it can be described in this Privacy Policy and represented on the Website.

10.4. We may send You the following messages to a targeted set of individuals from Our marketing database: news about Our online store and the Goods We offer; promotions and special offers on the Website; surveys about the experience of ordering through Our Website and the level of services provided by the online store; other information that We believe may be interesting or relevant to Our Users and Visitors.

 

11. INFORMATION STORING AND DELETION

 

11.1. Personal Data shall be processed and stored only for as long as is necessary for the purpose for which it was collected or for other legitimate purposes and for any other period permitted by applicable law.

11.2. We will store Your Personal Data for as long as You are Our User or Visitor. Suppose You are no longer a Visitor or User and You have ordered Goods on ONE TEA TREE Website. In that case, We will store Your Personal Data for the minimum period necessary to fulfill the purposes outlined in this Privacy Policy and applicable legal obligations, but no longer than 36 (thirty six) months, and regarding Personal Data contained in invoices and ONE TEA TREE accountant documents — no longer than 5 (five) years, or other maximum terms applied according to the laws. Personal Data which is collected and processed with Your consent will be stored until Your withdrawal of consent.

11.3. Information received through contact forms shall be deleted in a 3 (three) years. We will delete Your information if You have not contacted customer support at hi@oneteatree.co for more than 36 (thirty six) months in a row.

11.4. We will delete any Usage Data collected for technical purposes no later than 36 (thirty six) months after it has been collected.

11.5. Notwithstanding what was stated in the previous clauses 11.2, 11.3, or 11.4 of this Privacy Policy, We may store Personal Data longer in the cases and for the period permitted by the applicable laws, upon the legal grounds for such storage which prevail over Your interests, rights, and freedoms, including for the execution of Our obligations for the storage of accounting and financial reporting documents.

11.6. After the expiry of the storage period, We shall delete Personal Data. Therefore, the right to object to the processing, the right to access, the right to delete, the right to correction, the right to restrict the processing, and the right to receive and transmit Personal Data cannot be exercised after the expiry of that storage period.

11.7. We strive to implement the option of deleting the User’s personal account by Your own at any time. Currently, the User can delete its personal account at any time by sending a request to Our email hi@oneteatree.co. At the same time, Our Terms of Use and the Privacy Policy remain in force after the deletion of the User’s personal account, including provisions on the terms of storage of Personal Data.

 

12. INFORMATION SECURITY

 

12.1. We care about the security of Your Personal Data. We adhere to generally accepted industry standards to protect the data transmitted to Us, both during transmission, and after it is received. We take technical, physical, and organizational security measures to ensure that Your Personal Data is adequately protected. When We process Your Personal Data, We also ensure that Your Personal Data is protected against unauthorized access, loss, manipulation, falsification, destruction, or unauthorized disclosure.

12.2. However, You agree, that no 100% secure way to transmit data over the Internet or electronic storage exists. Therefore, We cannot guarantee its absolute security.

12.3. We never process any special categories of Personal Data and/or data on criminal offenses. In addition, We never conduct Personal Data profiling.

 

13. SERVICE PROVIDERS AND CONTRACTORS

 

13.1. We cooperate with third-party service providers who provide Us with services such as website development, hosting of Our Website, maintenance, emailing, marketing, technical support and collateral, information technology and cybersecurity services, customer support, and other services. These contractors may access the Personal Data or process it on Our behalf as part of their services to us. We may also provide access to Personal Data to Our employees, consultants, and other contractors, as well as partners (payment processors, analytics providers, etc.) as part of the services or work they perform for Us. We limit the information provided to such parties to that which is reasonably necessary to perform their functions.

13.2. Your Personal Data are stored on OVH Cloud servers. OVH Data Center location address: 59820 Gravelines, Nord-Pas-de-Calais-Picardie, France.

13.3. If Your Personal Data is transferred outside the EEA, We require such third parties to maintain appropriate security measures.

13.4. We demand from Our service providers, contractors, and partners to ensure compliance with the GDPR and other applicable laws as well as the privacy of Personal Data. All data transfers are carried out under the strictest information security rules.

13.5. For more information on cross-border information transfers to Our service providers, contractors, and partners outside the EEA, please contact Us using the details provided in the «Contact Us» section below.

 

14. CONTACT US

 

14.1. If You have any questions about the operation of Our Website or Your interaction with it, please contact Us at hi@oneteatree.co.

14.2. Notices related to this Privacy Policy may be sent to You by email to the email address You used when creating Your personal account or otherwise provided to Us. You expressly authorize Us to contact You via such email in the event that We (or Our affiliate) are required by law to notify You of a data security incident or data breach.

Cart