1. Who we are
Phipower, a trade name of Mobisun B.V.
Ampèrestraat 21A
3861 NC Nijkerk
The Netherlands
Chamber of Commerce (KvK): 68972849
VAT ID: NL857669990B01
Email: info@phipower.org
Telephone: +31 85 303 35 01
For the purposes of the GDPR and other applicable privacy laws, Mobisun B.V. is the controller for Phipower's own processing of personal data.
2. Scope of this Privacy Policy
This Privacy Policy applies to personal data processed through Phipower's online store, customer service, marketing, product support, returns, warranty handling, professional enquiries and related business activities.
It does not govern the independent privacy practices of external websites or services that you choose to use outside Phipower.
3. Personal data we collect
Depending on how you interact with Phipower, we may process:
Identity and contact data
- name;
- email address;
- telephone number;
- billing and shipping address;
- country;
- company name, where applicable.
Order and commercial data
- products purchased or considered;
- order number and date;
- quantities;
- transaction amount and currency;
- shipping method and delivery status;
- returns, refunds and warranty history;
- customer-account order history.
Payment-related data
- selected payment method;
- payment status;
- transaction or payment reference;
- information required to reconcile a payment or refund.
Phipower does not normally receive or store complete payment-card credentials. Payment credentials are handled by the payment provider selected during checkout.
Account data
- customer-account identifiers;
- saved addresses and preferences;
- login/session information managed through Shopify;
- account and order history.
Customer-service and product-support data
- messages and correspondence;
- order numbers;
- product and troubleshooting information;
- photographs or videos you choose to provide;
- return and warranty information;
- records of the support provided.
Website, device and usage data
- IP address;
- browser and device information;
- operating system;
- pages and products viewed;
- referrer information;
- session and cookie identifiers;
- approximate location derived from technical data;
- interactions with our storefront, checkout and communications.
Marketing data
- newsletter or marketing subscription status;
- consent and preference records;
- campaign source;
- engagement with marketing communications where permitted.
4. Health and other sensitive information
Phipower sells wellness products. Customers may sometimes mention health conditions when asking a product question.
Please do not send medical records, diagnoses, treatment histories or other sensitive health information through normal contact, review, return or warranty forms unless the information is genuinely necessary and specifically requested.
Health data are special-category personal data under the GDPR and receive additional legal protection. If processing health information is genuinely necessary, Phipower will only process it where a valid legal basis and an applicable condition for special-category data exist, such as explicit consent where appropriate.
Phipower does not use customer-support information to diagnose medical conditions or create medical profiles.
5. How we collect personal data
We receive personal data:
- directly from you when you place an order, create an account, contact us, request a return or warranty service, subscribe to marketing or submit content;
- automatically when you use our Shopify storefront, subject to applicable cookie and tracking choices;
- from payment, shipping, fulfilment, support and other service providers where necessary to complete or support your transaction;
- from legitimate business partners when they refer a professional or commercial enquiry to us.
6. Why we process personal data and our legal bases
We process personal data only when we have a lawful basis.
Orders, checkout, delivery, returns and refunds
Purpose: to enter into and perform the sales agreement, process the order and provide after-sales service.
Legal basis: Article 6(1)(b) GDPR — performance of a contract or steps before entering into a contract.
Product support and customer service
Purpose: to answer questions, troubleshoot products, handle returns, warranty requests and complaints.
Legal basis: Article 6(1)(b) GDPR and, where appropriate, Article 6(1)(f) GDPR — our legitimate interest in providing effective customer service and maintaining accurate support records.
Accounting, tax, consumer-law and other legal requirements
Purpose: to maintain records, issue invoices, meet tax obligations and respond to legally valid requests.
Legal basis: Article 6(1)(c) GDPR — compliance with a legal obligation.
Fraud prevention and security
Purpose: to protect our store, transactions, accounts, systems and customers against fraud, abuse and security incidents.
Legal basis: Article 6(1)(f) GDPR — our legitimate interests in secure ecommerce and fraud prevention, and Article 6(1)(c) GDPR where a legal obligation applies.
Marketing communications
Purpose: to send newsletters, product updates, Knowledge Center content, research updates and offers.
Legal basis: consent under Article 6(1)(a) GDPR where consent is required, or another lawful direct-marketing basis where applicable.
Analytics, personalization and advertising
Purpose: to understand website use, improve the store, measure campaigns and provide personalization or advertising.
Legal basis: consent where required for non-essential cookies or tracking technologies; in limited cases a legitimate interest may apply to processing that does not require consent under applicable law.
Professional and B2B enquiries
Purpose: to respond to retailers, studios, practitioners, researchers, resellers and other business contacts.
Legal basis: Article 6(1)(b) GDPR for pre-contractual steps and Article 6(1)(f) GDPR for legitimate business relationship management.
7. Shopify
Our online store is powered by Shopify.
Shopify provides core ecommerce infrastructure such as hosting, storefront functionality, cart and checkout services, order management, customer-account functionality, security and fraud-prevention capabilities.
For core merchant services, Shopify may process personal data on our behalf as a processor or service provider. For certain Shopify services, Shopify may also process personal data for its own purposes as an independent controller.
You can read Shopify's Consumer Privacy Policy at shopify.com/legal/privacy/app-users.
Shopify's general privacy controls are available at privacy.shopify.com.
Shop Pay
If you choose Shop Pay, Shopify processes the information required to provide accelerated checkout, identity recognition and related Shop Pay functionality. Shopify's own privacy terms apply to the processing it carries out for Shop Pay.
8. Payment providers
At checkout, you may be offered one or more payment methods.
We share the information required to process your chosen payment method with the relevant payment provider. The provider may process information such as your name, billing information, transaction amount, payment instrument information, fraud-prevention signals and transaction status in accordance with its own privacy terms.
Phipower does not hardcode a list of payment providers in this Privacy Policy because the payment methods available can vary by country, currency, order value and Shopify configuration. The payment methods offered to you are shown during checkout.
9. Shipping, fulfilment, returns and professional service providers
We may share personal data with service providers where necessary to operate Phipower, including:
- fulfilment and warehouse partners;
- postal and courier services;
- return-handling partners;
- IT and hosting providers;
- customer-support systems;
- email and communication services;
- accountants, tax advisers, legal advisers and insurers;
- fraud-prevention and security providers.
We provide only the information reasonably necessary for the relevant service.
Where a provider acts as our processor, we require appropriate contractual and data-protection safeguards. Some providers act as independent controllers for their own legal or operational purposes.
10. Analytics, advertising and Shopify web pixels
Shopify provides analytics functionality and supports app pixels and custom pixels through Customer Events.
Phipower may use Shopify analytics and may configure analytics or advertising integrations. The exact integrations can change as the store evolves.
We do not name an analytics or advertising vendor in this Privacy Policy unless its use has been verified. Exact cookies, pixels, providers, purposes and durations should be documented in the current Phipower Cookie Policy and cookie-preference interface.
Where applicable law requires consent, non-essential analytics, marketing, personalization or advertising technologies should not be activated for that visitor until the required consent has been obtained.
Our store uses Shopify privacy controls or a compatible consent solution in regions where cookie consent is required. Your choices are used to control non-essential data collection through supported Shopify privacy mechanisms.
11. Cookies and similar technologies
We use cookies and similar technologies for different purposes.
Strictly necessary technologies support essential functions such as:
- cart and checkout;
- security;
- customer accounts and session continuity;
- market, language or store functionality.
Preference technologies can remember selected settings.
Analytics technologies can help us understand how the site is used.
Marketing or advertising technologies can measure campaigns, create audiences, personalize advertising or support related marketing features.
Where consent is required, non-essential technologies are used only after the required consent has been obtained.
You can manage available choices through the Phipower cookie/privacy controls.
For the most specific and current information about providers, cookies, pixels, purposes and durations, see the Phipower Cookie Policy.
12. International transfers
Phipower is established in the Netherlands and serves customers internationally.
Shopify and other service providers may process personal data in countries outside the European Economic Area.
The GDPR does not require all personal data to remain physically stored in the EEA, but transfers to countries outside the EEA must be protected by an appropriate transfer mechanism where required.
Depending on the recipient and destination, safeguards may include:
- an adequacy decision;
- Standard Contractual Clauses;
- another approved transfer mechanism; or
- a legally permitted derogation in limited circumstances.
We assess relevant service providers and transfer arrangements as part of our privacy and vendor management.
13. Retention
We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, support and dispute-resolution requirements.
Our general retention approach is:
Order, invoice and core accounting data: generally 7 years where required by Dutch tax and accounting rules.
OSS/IOSS transaction data: where the EU One Stop Shop or Import One Stop Shop rules apply, relevant records may need to be retained for 10 years.
Returns, warranty and product-support records: generally for the time needed to handle the request and for a reasonable period afterwards. Routine closed support records may normally be retained for up to 2 years after closure unless a longer period is justified by a dispute, legal claim, safety issue or another legal obligation.
Customer-service correspondence: generally up to 2 years after the last meaningful contact unless it forms part of an order, complaint, warranty matter or legal record requiring longer retention.
Customer-account data: while the account remains active, plus a limited period afterwards where necessary. Transaction data that must be retained for legal reasons may remain stored separately.
Marketing preferences: until you unsubscribe, withdraw consent or the data are no longer needed. We may retain a minimal suppression record so that an opt-out remains respected.
Cookie and analytics data: according to the lifespan and configuration described in the Cookie Policy and the relevant platform settings.
We may retain data longer where necessary to establish, exercise or defend legal claims or to meet a legal obligation.
14. Security
We use reasonable technical and organizational measures appropriate to the nature of the data and risks involved.
These can include:
- encrypted connections;
- access controls;
- account and platform security;
- restricted internal access;
- secure service providers;
- backups and updates;
- fraud and abuse prevention;
- procedures for responding to security incidents.
No online system can provide absolute security.
15. Your privacy rights
Subject to applicable law, you may have the right to:
- access personal data we hold about you;
- correct inaccurate or incomplete data;
- request deletion of data;
- request restriction of processing;
- receive certain data in a portable format;
- object to processing based on legitimate interests;
- object to direct marketing at any time;
- withdraw consent where processing is based on consent;
- exercise rights concerning certain solely automated decisions, if applicable.
To exercise a right, contact info@phipower.org.
Please provide enough information for us to identify the relevant data. We may request additional information where reasonably necessary to verify identity and protect your privacy.
Where Shopify processes information on our behalf, Shopify provides merchant tools that can assist us with access, correction and deletion requests.
United States privacy rights
Depending on your state of residence and whether a particular state privacy law applies to Phipower, you may have additional rights concerning access, deletion, correction, portability, targeted advertising, sale or sharing of personal information, or certain profiling.
Where an applicable opt-out mechanism is available, you can use the privacy controls presented on our store.
16. Marketing communications
You can unsubscribe from Phipower marketing emails at any time by using the unsubscribe link in the message or contacting info@phipower.org.
Unsubscribing from marketing does not stop transactional or service communications such as:
- order confirmations;
- delivery information;
- return or refund messages;
- warranty support;
- legally required notices.
Where a marketing activity requires consent, we keep a record of that consent and respect its withdrawal.
17. Reviews and user-generated content
If you provide Phipower with a testimonial, review, photograph or similar content outside an installed review service, we will use identifiable content for public marketing only where we have an appropriate legal basis and, where required, your permission.
18. Children
The Phipower store is intended primarily for adults.
We do not knowingly seek to collect children's personal data for marketing purposes. If you believe a child has provided personal data without the required authorization, contact info@phipower.org so that we can assess and, where appropriate, remove the information.
19. Automated decision-making
Phipower does not intend to make decisions about customers based solely on automated processing where those decisions produce legal or similarly significant effects.
Automated tools may nevertheless be used for operational purposes such as fraud detection, security, spam prevention, recommendations or marketing segmentation.
If we introduce legally significant automated decision-making, we will provide the disclosures and rights required by applicable law.
20. Changes to this Privacy Policy
We may update this Privacy Policy to reflect:
- changes in Shopify settings or features;
- new or removed apps and service providers;
- changes in our products or business processes;
- legal or regulatory developments.
The last-updated date above identifies the current version.
We recommend reviewing this policy periodically. Where a material change requires additional notice or consent, we will provide it as required.
21. Complaints
If you have a privacy concern, please contact Phipower first at info@phipower.org.
You also have the right to lodge a complaint with a competent data-protection authority.
For Phipower's establishment in the Netherlands, the supervisory authority is the Autoriteit Persoonsgegevens.
You may also be entitled to contact the supervisory authority in the country where you normally live or work.
22. Contact
For privacy questions, requests or complaints:
Phipower, a trade name of Mobisun B.V.
Ampèrestraat 21A
3861 NC Nijkerk
The Netherlands
KvK: 68972849
VAT ID: NL857669990B01
Email: info@phipower.org
Telephone: +31 85 303 35 01