Last Updated: 1 October 2025
Welcome to Xylvra! We are committed to protecting your privacy and handling your personal data with transparency and care. This Privacy Policy explains how Xylvra (“we,” “us,” or “our”) collects, uses, shares, and protects your personal information when you visit or make a purchase from https://xylvra.com/ (the “Site”). We are a sole proprietorship located at 40 Abbey Street Upper, North City, Dublin, Dublin D01 F9N3, IE.
We adhere to the General Data Protection Regulation (GDPR) (EU) 2016/679 and the Data Protection Act 2018 (Ireland), which sets out your rights regarding your personal data.
1. What Information We Collect
a) Information You Provide to Us: When you make a purchase or attempt to make a purchase through the Site, we collect certain information from you, which we refer to as “Order Information.” This includes:
- Your name
- Billing address
- Shipping address
- Payment information (e.g., credit card numbers – please note we do not store full credit card details on our servers; these are processed securely by our third-party payment providers)
- Email address
- Phone number
b) Information We Collect Automatically (Device Information): When you visit the Site, we automatically collect certain information about your device and how you interact with our Site. This includes:
- Information about your web browser
- IP address
- Time zone
- Some of the cookies that are installed on your device
- Information about the individual web pages or products that you view
- What websites or search terms referred you to the Site
- Information about how you interact with the Site
We refer to this automatically-collected information as “Device Information.”
2. How We Use Your Information (Legal Basis)
We use the “Order Information” that we collect generally to fulfill any orders placed through the Site. This includes processing your payment information, arranging for shipping, and providing you with invoices and/or order confirmations. Our legal basis for this processing is:
- Performance of a contract: To fulfill your order and provide you with the products you’ve purchased.
Additionally, we use this Order Information to:
- Communicate with you regarding your order or inquiries.
- Screen our orders for potential risk or fraud. (Legal Basis: Legitimate Interests – to protect our business from fraudulent transactions).
- Provide you with information or advertising relating to our products or services, but only if you have given us your explicit consent where required by law. (Legal Basis: Consent, or Legitimate Interests – to grow our business where consent is not required).
We use the “Device Information” to help us screen for potential risk and fraud (in particular, your IP address), and more generally to improve and optimize our Site (for example, by generating analytics about how our customers browse and interact with the Site, and to assess the success of our marketing and advertising campaigns). Our legal basis for this processing is:
- Legitimate Interests: To improve our services, website, and provide a better customer experience.
- Consent: For non-essential cookies and tracking technologies.
3. Sharing Your Personal Information
We share your Personal Information with third parties to help us use your Personal Information, as described above. These third parties include:
- Service Providers: We use WooCommerce to power our online store. We also work with secure third-party payment processors (e.g., Stripe, PayPal) to handle transactions, and shipping companies (e.g., An Post) to deliver your orders. These service providers are only given the information they need to perform their specific services and are required to protect your information.
- Analytics Providers: We use analytics services (e.g., Google Analytics) to help us understand how our customers use the Site. You can learn more about how Google uses your Personal Information here: https://policies.google.com/privacy. You can also opt-out of Google Analytics here: https://tools.google.com/dlpage/gaoptout.
- Legal Requirements: We may also share your Personal Information to comply with applicable laws and regulations, to respond to a subpoena, search warrant or other lawful request for information we receive, or to otherwise protect our rights.
4. International Transfers
While Xylvra is based in IE, some of our service providers may be located outside of the European Economic Area (EEA). When we transfer your personal data outside the EEA, we ensure that appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission, or by ensuring the recipient is part of an adequacy decision where applicable.
5. Your Data Protection Rights (GDPR)
As a data subject in the EU/EEA, you have the following rights concerning your personal data:
- The right to be informed: You have the right to know how your personal data is collected and used. This Privacy Policy serves to fulfill this right.
- The right to access: You have the right to request copies of your personal data that we hold.
- The right to rectification: You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
- The right to erasure (“right to be forgotten”): You have the right to request that we erase your personal data, under certain conditions.
- The right to restrict processing: You have the right to request that we restrict the processing of your personal data, under certain conditions.
- The right to object to processing: You have the right to object to our processing of your personal data, under certain conditions (e.g., direct marketing).
- The right to data portability: You have the right to request that we transfer the data that we have collected to another organization, or directly to you, under certain conditions.
- The right to withdraw consent: Where our processing is based on your consent, you have the right to withdraw that consent at any time.
If you make a request to exercise any of these rights, we have one month to respond to you. To do so, please contact us using the contact details provided at the end of this Privacy Policy.
6. Data Retention
When you place an order through the Site, we will maintain your Order Information for our records unless and until you ask us to erase this information. This is necessary to fulfill orders, process returns, handle warranties, and comply with legal obligations (e.g., tax records). The retention period will be determined by the nature of the data and legal requirements.
7. Cookies and Other Tracking Technologies
Our Site uses “cookies” to enhance your browsing experience. Cookies are small data files that are placed on your device or computer and often include an anonymous unique identifier.
- Strictly Necessary Cookies: These are essential for the website to function correctly (e.g., enabling shopping cart functionality, secure login).
- Performance Cookies: These collect information about how you use our website (e.g., which pages you visit most often), which helps us improve the site’s performance.
- Functionality Cookies: These remember choices you make (e.g., language preferences) to provide a more personalized experience.
- Targeting/Advertising Cookies: These are used to deliver more relevant advertising to you and to measure the effectiveness of advertising campaigns.
You can control and manage cookies in various ways. Most web browsers allow you to block or delete cookies through their settings. Please be aware that if you choose to disable cookies, some features of our Site may not function properly. For more information about cookies, and how to disable them, visit http://www.allaboutcookies.org.
8. Data Security
We implement reasonable security measures designed to protect your personal data from accidental loss, unauthorized access, use, alteration, and disclosure. These measures include using SSL encryption for data in transit and securing our backend systems. However, no internet transmission or electronic storage is ever 100% secure, and we cannot guarantee absolute security.
9. Children’s Privacy
Our Site is not intended for individuals under the age of 16. We do not knowingly collect personal data from children under 16. If you are a parent or guardian and believe your child has provided us with personal data, please contact us so we can take steps to delete that information.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time in order to reflect, for example, changes to our practices or for other operational, legal or regulatory reasons. We will post any new policy on this page and update the “Last Updated” date at the top of the policy.
11. Contact Us
For more information about our privacy practices, if you have questions, or if you would like to make a complaint, please contact us by e-mail at contact@xylvra.com or by phone at +353 1 874 7687.
You can also write to us at: Xylvra 40 Abbey Street Upper North City, Dublin D01 F9N3 IE
If you are not satisfied with our response to your complaint, you have the right to lodge a complaint with the Data Protection Commission (DPC) in Ireland, which is our supervisory authority. You can find their contact details and information on how to lodge a complaint on their website: https://www.dataprotection.ie.