Privacy policy

Privacy Policy
Last updated: May 2026

YoungMind ("we," "us," "our") operates useyoungmind.com. 
This policy governs how we collect, store, use, and protect personal data.

─────────────────────────────────────────
1. DATA CONTROLLER
─────────────────────────────────────────

The data controller responsible for your personal data is YoungMind, 
operating under Czech law. Contact: vitekoliversmma@gmail.com

─────────────────────────────────────────
2. DATA WE COLLECT
─────────────────────────────────────────

We collect the following categories of personal data:

- Identity data: full name
- Contact data: email address, phone number (if provided)
- Transactional data: billing address, shipping address, order history, 
  payment method type (we do not store full card numbers)
- Technical data: IP address, browser type, device type, operating system, 
  pages visited, time on site, referral source
- Marketing data: email marketing preferences, ad interaction data

─────────────────────────────────────────
3. LEGAL BASIS FOR PROCESSING (GDPR)
─────────────────────────────────────────

We process your data under the following legal bases:
- Contract performance: to process and fulfill your orders
- Legal obligation: to comply with tax and accounting laws
- Legitimate interest: fraud prevention, site security, analytics
- Consent: email marketing (you may withdraw consent at any time)

─────────────────────────────────────────
4. HOW WE USE YOUR DATA
─────────────────────────────────────────

Your data is used to:
- Process, fulfill, and track your orders
- Communicate order status and updates
- Provide customer support
- Send marketing communications (only with your explicit consent)
- Prevent fraud and abuse
- Improve our website, products, and services
- Comply with legal and regulatory obligations

─────────────────────────────────────────
5. COOKIES & TRACKING TECHNOLOGIES
─────────────────────────────────────────

We use cookies and similar tracking technologies including:
- Essential cookies (required for checkout and site function)
- Analytics cookies (Google Analytics — anonymized IP)
- Marketing cookies (Meta Pixel, Google Ads)

You may manage cookie preferences via our cookie consent banner. 
Disabling non-essential cookies may affect site functionality and 
the relevance of ads you see.

─────────────────────────────────────────
6. THIRD-PARTY DATA SHARING
─────────────────────────────────────────

We do not sell your personal data. We share data only where necessary 
with the following categories of processors:

- Shopify Inc. (e-commerce platform and data hosting)
- Payment processors (Stripe, PayPal, or equivalent)
- Shipping carriers (for order fulfillment only)
- Email service providers (for transactional and marketing emails)
- Meta Platforms Inc. and Google LLC (aggregated/hashed data for 
  advertising purposes only, under respective data processing agreements)

All third-party processors are contractually bound to process your 
data only as instructed and in compliance with applicable law.

─────────────────────────────────────────
7. DATA RETENTION
─────────────────────────────────────────

We retain personal data for the following periods:
- Order and transactional data: 10 years (Czech accounting law requirement)
- Email marketing data: until you unsubscribe or request deletion
- Technical/analytics data: 26 months
- Customer support communications: 3 years

─────────────────────────────────────────
8. YOUR RIGHTS (EU/GDPR)
─────────────────────────────────────────

As an EU data subject, you have the right to:
- Access: request a copy of your personal data
- Rectification: correct inaccurate data
- Erasure: request deletion ("right to be forgotten"), subject to 
  legal retention obligations
- Restriction: limit processing in certain circumstances
- Portability: receive your data in a structured, machine-readable format
- Objection: object to processing based on legitimate interest
- Withdraw consent: for marketing at any time, without penalty

To exercise any of these rights, contact: vitekoliversmma@gmail.com
We will respond within 30 days. Identity verification may be required.

You also have the right to lodge a complaint with the Czech data 
protection authority (ÚOOÚ): www.uoou.cz

─────────────────────────────────────────
9. CHILDREN'S DATA
─────────────────────────────────────────

Our website is operated for and by adults (parents/guardians). We do 
not knowingly collect personal data from children under the age of 16. 
If you believe a child has submitted data to us, contact us immediately 
for deletion.

─────────────────────────────────────────
10. SECURITY
─────────────────────────────────────────

We implement industry-standard technical and organizational measures 
to protect your data, including SSL encryption, access controls, and 
regular security reviews. However, no method of transmission over the 
internet is 100% secure, and we cannot guarantee absolute security.

─────────────────────────────────────────
11. CHANGES TO THIS POLICY
─────────────────────────────────────────

We may update this policy periodically. The "last updated" date at 
the top of this page will reflect changes. Continued use of our 
website after changes constitutes acceptance of the revised policy.