Privacy Policy
Last updated: 29 July 2026
The short version: we collect your email if you join our waitlist, and your order details if you buy something. If you accept cookies we also measure which ads brought you here, and share those events with Meta. We don't sell your data to anyone, ever.
Who we are
This site is operated by Matej Novaković s.p., Bevško 13, 1420 Trbovlje, Slovenia. Registration no.: 9405992000. Tax no.: 15584534. Contact: brickstage.social@gmail.com.
We are the data controller for the personal data described below.
What we collect and why
- Email address — when you join the waitlist or newsletter. Legal basis: your consent. Used to tell you about launches, drops and offers.
- Order information — name, email, shipping address, and order contents when you buy. Legal basis: performance of a contract. Used to process and ship your order.
- Payment details — handled entirely by Stripe. We never see or store your card number.
- Basic technical data — e.g. IP address and browser type, collected by our host for security and to keep the site running. Legal basis: legitimate interest.
- Measurement data — if you accept cookies, we record which pages you visited, which link or ad brought you here, your device type, and your approximate location (country, region, city, worked out from your IP address, which we do not store). We also create a random identifier so we can tell one visit from another and see whether a visit led to an order. Legal basis: your consent. If you decline, we still count the visit but store no identifier, so it can never be linked back to you or to a purchase.
Who processes your data
We use a small number of trusted providers ("processors"):
- Stripe — payment processing. See Stripe's privacy policy.
- Netlify — website hosting and waitlist form submissions.
- Klaviyo — storing your email address and sending our newsletter and offers.
- Meta (Facebook) — measuring which ads lead to visits and orders, and building advertising audiences. Only if you accept marketing cookies. For this, Meta and Brickstage act as joint controllers: we decide together what is collected and why, and Meta then uses the data for its own purposes under its own terms.
Some providers may process data outside the EU/EEA. Where that happens, transfers are covered by appropriate safeguards such as the EU Standard Contractual Clauses. Meta transfers data to the United States.
How long we keep it
- Waitlist/newsletter emails: until you unsubscribe.
- Order records: as long as required by Slovenian tax and accounting law (typically up to 10 years).
- Measurement data: 14 months, then deleted. Meta applies its own retention to whatever it receives.
Your rights (GDPR)
You have the right to access, correct, delete, restrict, or object to the processing of your personal data, and the right to data portability. You can withdraw consent for marketing at any time — every email has an unsubscribe link.
To exercise any of these, email brickstage.social@gmail.com. We'll respond within one month.
If you're unhappy with how we handle your data, you can complain to the Slovenian Information Commissioner (Informacijski pooblaščenec), ip-rs.si.
Cookies
Strictly necessary — a small amount of local storage keeps your shopping bag and any discount code you've applied. This is required for the shop to work and doesn't need consent.
Marketing and measurement — if you accept, we use the Meta (Facebook) pixel to see which ads lead to visits and orders, and Klaviyo to recognise you if you've joined our list. These only load after you click Accept, and you can change your mind at any time via cookie choices in the footer.
Our own measurement — we also record visits on our own servers rather than through a third party. This is what tells us how many people visited and where they came from. It follows the same consent rule: accept and we store a random identifier, decline and the visit is counted with nothing that could identify you.
Declining costs you nothing — the shop works exactly the same.
What we send to Meta
If you accept marketing cookies, we share data with Meta in two ways. The pixel in your browser sends events such as viewing a product or adding one to your bag. Our server sends the same events again, which is more reliable, and this is the only route we use to report a completed purchase.
What goes with those events: the page you were on, the value and contents of the order, the Facebook click identifier if you arrived from an ad, your IP address and browser, and a random identifier of ours. When we know your email address, from an order or from signing up, it is hashed before it is sent. Meta receives an irreversible fingerprint and never the address itself. We never send your name, your postal address, or your card details.
None of this happens if you decline. There is no server-side copy for visitors who have not accepted, and automated traffic such as crawlers is excluded entirely.
Changes
If we update this policy we'll change the date at the top. Material changes will be announced on the site.