Legal
Privacy policy
This policy explains what personal data we collect when you visit or buy from azharjewels.com, why, and what rights you have.
Last updated: 29 September 2026.
Who is responsible for your data
The data controller is Christian Calabro', sole trader in Malta, trading as Azhar Jewels. The postal address is in our Legal notice.
- Email for privacy requests: info@azharjewels.com
We have not appointed a data protection officer, as we are not required to.
What data we collect and why
| Why | What data | Legal basis |
|---|---|---|
| To process your order, deliver it and handle returns, withdrawals and guarantee claims | name, email, phone number, delivery and billing address, items ordered, order history, messages with us | Performance of the contract (GDPR art. 6(1)(b)) |
| To take payment and prevent fraud | payment status and method (we never see your full card number); fraud signals processed by Stripe | Contract (art. 6(1)(b)) and our legitimate interest in preventing fraud (art. 6(1)(f)) |
| To keep accounting and tax records | order, receipt and credit note data | Legal obligation (art. 6(1)(c)) |
| To record a withdrawal you send us online | order number, email, name, the date and time of your withdrawal | Legal obligation (art. 6(1)(c)): the online withdrawal function and its receipt |
| To answer your messages | name, email, the content of your message; on WhatsApp, your phone number and profile name; on Instagram, your username | Our legitimate interest in replying to you (art. 6(1)(f)), or steps before a contract (art. 6(1)(b)) |
| To send you our newsletter, if you subscribed | email address, date and wording of your consent | Your consent (art. 6(1)(a)). You can unsubscribe at any time |
| To tell you when a sold-out piece is back, if you ask for it on the product page ("Email me when it's back") | email address, the piece and size you asked about, the date of your request, the version of the notice shown under the field, and the date we wrote to you | Your request (art. 6(1)(b), steps you ask for before a contract). We write to you once about that piece, and never add you to our newsletter or any marketing list |
| To let you see your order | email address and order, through the private link in your order email | Contract (art. 6(1)(b)) |
| To remind you of an order you started and did not finish, with a link that brings your bag back | the email address you enter at checkout, the pieces in your bag, your destination country, the value of the bag, when the checkout started, the reminders we sent and whether you used their link | Our legitimate interest in reminding you of a purchase you began (art. 6(1)(f)), within the rules for emails about similar products to people who gave their address in a purchase (ePrivacy Directive art. 13(2)): we tell you under the email field, and every reminder lets you unsubscribe in one click. At most 3 reminders, within 3 days of the checkout, and none once you pay |
| To keep the site secure and working | IP address, browser and device data, bot-protection signals, processed by Cloudflare; we do not store your IP address | Our legitimate interest in security (art. 6(1)(f)) |
| To count visits to our pages, without cookies | the page visited, the website you came from, your country and type of device (mobile, tablet or desktop), with the day; no IP address, no cookie and no identifier, so a visit cannot be linked to you. If your browser sends Do Not Track or Global Privacy Control, we do not count the visit | Our legitimate interest in knowing how our site is used (art. 6(1)(f)) |
| To measure our website and advertising | pages viewed, products viewed, cart and purchase events, cookie identifiers, and for purchases your email, phone number, name, city, postcode and country in hashed form (turned into a code that cannot be read back) | Your consent (art. 6(1)(a)), given through the cookie banner |
| To know which campaign brought an order | campaign parameters in the link you clicked (for example utm, fbclid, gclid), saved with your order | Your consent (art. 6(1)(a)), given through the cookie banner: without it, nothing is saved |
| To ask for and publish product reviews | for the request, your email address and the order; for the review, the name you choose to show, rating, text, photos and date | For the request, your consent to our emails (art. 6(1)(a)), only if you gave it, one email per order; for the review, your consent given when you wrote it for Azhar Jewels, including on our previous shop. We remove a review whenever you ask |
If you bought from us or subscribed on our previous shop (on Shopify), your customer details, orders and newsletter choice moved with us to this site, so that your order history, guarantees and choices stay the same.
We do not sell your personal data. We do not make decisions about you based solely on automated processing that have legal or similarly significant effects. Stripe checks every payment automatically to prevent fraud, as an independent controller: if a payment is declined, you can write to us and pay in another way.
Who we share your data with
We use trusted service providers. They process your data only on our instructions (processors), unless stated otherwise.
| Provider | What they do for us | Where |
|---|---|---|
| Cloudflare, Inc. | Website hosting, database and file storage, sending and forwarding email, bot protection, security | EU and USA |
| Stripe (Stripe Payments Europe, Limited) | Payment processing and fraud prevention. For some purposes, such as fraud prevention and financial regulation, Stripe acts as an independent controller | EU, with transfers outside the EU |
| Meta (Meta Platforms Ireland Limited) | Measuring our advertising (Meta Pixel and Conversions API), only with your consent. For the Pixel, we and Meta are joint controllers for collecting the data on our site and sending it to Meta; Meta is responsible for what it does with it afterwards | EU and USA |
| Google (Google Ireland Limited) | Website statistics (Google Analytics 4) and advertising measurement (Google Ads), only with your consent | EU and USA |
| Resend (Resend, Inc.) | Sending our newsletter, its confirmation emails and review requests, only to people who agreed to receive them | USA |
| Packlink (Packlink Shipping S.L.) | Creating shipping labels: it receives the name, address, phone number and email of the recipient | Spain |
| Carriers (such as Correos, SEUR, GLS, UPS, InPost, Mondial Relay) | Delivering your parcel. They receive your name, address, phone number and email | EU |
| Our accountant and tax authorities | Accounting and tax obligations | EU |
If you write to us on WhatsApp, your messages are handled by WhatsApp (WhatsApp Ireland Limited, a Meta company) under its own terms and privacy policy, as an independent controller; we use them only to answer you.
When data is transferred outside the European Economic Area, for example to the USA, we rely on an adequacy decision (such as the EU-US Data Privacy Framework, for certified companies) or on the European Commission's standard contractual clauses.
How long we keep your data
- Orders, receipts and accounting records: 10 years after the end of the year of the order, for our tax and accounting obligations.
- Guarantee and withdrawal records: for the duration of the legal guarantee (up to 3 years from delivery), plus the time needed to handle any claim.
- Messages: up to 24 months after our last exchange, unless they belong to an order record.
- Back-in-stock requests: we delete each request 30 days after we email you, or 180 days after you made it if the piece does not come back. You can delete it sooner with the link in our email, or by writing to us.
- Unfinished checkouts: we delete the email address and the links of an unfinished checkout 30 days after it started; what remains (the pieces and the value) no longer identifies you. You can stop the reminders at any time with the link in each of them, or by writing to info@azharjewels.com. We then keep only a one-way fingerprint of your email address (a code from which the address cannot be read back), so that we do not write to you again; it also stops our newsletter and review requests.
- Newsletter: until you unsubscribe. We then keep only your email address in a suppression list, so that we do not write to you again, and a record of your consent and withdrawal.
- Reviews: as long as they are published, or until you ask us to remove them.
- Advertising and statistics data: Google Analytics keeps statistics linked to its cookies for at most 14 months; Meta and Google keep advertising data under their own policies. Cookie durations are in our Cookie policy.
- Technical and security logs: a few days at Cloudflare; our own logs never contain your email or address.
- Backups: copies of our database are kept for up to 12 weeks, then deleted.
Cookies
We use cookies and similar technologies. Only the ones strictly necessary for the shop to work are active without your consent. Details and your choices are in our Cookie policy.
Your rights
You have the right to:
- access your data and receive a copy;
- correct inaccurate data;
- delete your data, when we no longer need it or you withdraw consent;
- restrict or object to certain processing, including direct marketing at any time;
- portability: receive the data you gave us in a common format;
- withdraw your consent at any time, without affecting what happened before. For cookies, use the "Cookie settings" link at the bottom of every page.
To exercise your rights, write to info@azharjewels.com. We reply within one month. We may ask you to confirm your identity.
You also have the right to lodge a complaint with a supervisory authority: in Malta, the Information and Data Protection Commissioner (IDPC), which is our lead authority; or the authority of the country where you live or work (in Spain, the Agencia Española de Protección de Datos).
Children
Our shop is for adults: you must be 18 or over to buy (see our Terms and conditions). We do not knowingly collect personal data from children. If you think a child has given us personal data, write to us and we will delete it.
Security
We protect your data with encryption in transit, access controls on our admin area and providers that meet recognised security standards. Payments are handled entirely by Stripe.
Changes to this policy
We may update this policy. The date at the top shows the latest version. If a change is significant, we will tell you by email or on the site.

