Privacy policy

Privacy Policy

Effective date: 11 September 2026

Last updated: 12 September 2026

1. Who is responsible for your data?

SM Company Distribution Kft., trading as SneakerMood, is the controller of the personal data described in this notice. Registered office: 1089 Budapest, Kőris utca 2. I. em. 2. ajtó, Hungary. Company registration number: 01-09-458239. Hungarian tax number: 33083832-2-42. Contact: info@sneakermood.eu. This notice covers sneakermood.eu, purchases and related customer communications. It is information about our processing, not a request for blanket consent.

EU VAT identification number: HU33083832.

Customer service telephone: +31 6 11612622.

2. What we collect and where it comes from

You provide contact and account details, billing and delivery addresses, order selections, sizes, payment references, messages, return information and any photographs you send with a claim. We receive payment status and fraud indicators from payment providers and delivery or return updates from logistics providers. Someone buying a gift may provide a recipient's name and address; we use these details for delivery and related notices, not to subscribe the recipient to marketing.

When you use the store, Shopify and enabled services process technical information such as IP address, device and browser details, identifiers, shopping activity and consent settings. Optional tracking is subject to the choices explained below. Payment providers handle complete payment credentials; we receive the transaction information needed to administer the purchase. Please do not send passwords, complete card details or unnecessary identity documents to customer service.

3. Purposes, legal grounds and retention

The following periods distinguish operational records from information that must remain in restricted legal archives. A particular record is retained longer only where a specific legal duty, unresolved claim or applicable limitation period requires it.

Orders, payment, delivery and returns. We use identity, contact, address, product and transaction data to take steps you request before a purchase and perform the contract: GDPR Article 6(1)(b). Necessary evidence may then be retained for establishing or defending claims under Article 6(1)(f), normally for the applicable Hungarian five-year limitation period from when the claim becomes due, subject to interruption, suspension and longer mandatory periods.

Return and delivery evidence. When a return, non-delivery claim or disputed charge is examined, we use relevant carrier updates, proof of dispatch, correspondence, product-condition information and cost calculations to administer the contract under Article 6(1)(b) and establish or defend claims under Article 6(1)(f). These records follow the relevant order, complaint and claims retention periods above. Share only evidence needed for the issue; redact unrelated personal information.

Invoices and taxes. Billing and transaction records are processed under Article 6(1)(c). Hungarian accounting documents are retained for at least eight years under section 169 of Act C of 2000. Records subject to a longer tax requirement, including applicable OSS records, are retained for the required period, which may be ten years. This does not justify retaining all browsing or marketing data for that period.

Accounts and enquiries. Account administration and purchase enquiries rely on Article 6(1)(b); other enquiries rely on our legitimate interest in responding under Article 6(1)(f). Optional account information is kept while the account is active, then deleted or anonymised following closure when no longer needed. Ordinary enquiries are kept for up to two years after resolution. Formal consumer complaints and our replies are retained for three years under Hungarian consumer law; relevant claims evidence may require longer retention.

Security and misuse prevention. Technical logs, transaction risk indicators and necessary claim evidence support our legitimate interests in securing the store, preventing fraud and protecting property: Article 6(1)(f). We retain routine technical records only for the period necessary to detect, investigate and remedy security or operational issues. We determine that period by the type of record, the relevant risk, the time needed to investigate it and any outstanding incident, and review the continued need for retention. Evidence linked to a specific incident is restricted and retained until the investigation and any related claim period end. Unrelated browsing records are not kept for the full claims period merely because an incident occurred.

Newsletters, promotional codes and reminders. With your consent, we use your contact details, selected channel, language, subscription record and relevant promotion or purchase activity to send offers, launch notices, promotional codes and, where covered by your consent, abandoned-checkout or unused-code reminders: Article 6(1)(a). Each enabled channel, including email, SMS or platform messages, is subject to the consent given for it. Buying something or entering an address at checkout is not a subscription. We use marketing contact data until you withdraw consent, the relevant programme ends or the data are no longer needed for the consented purpose, whichever is earlier. We stop marketing on withdrawal and remove or restrict the related profile unless another stated legal ground requires particular records. Limited consent evidence and suppression data remain where necessary to prove compliance and respect the opt-out, under Articles 6(1)(c) and 6(1)(f), for the applicable compliance or claims period. Individual email open or click tracking requires the applicable notice and consent and is not implied by consent to receive messages alone.

Analytics and advertising. Where enabled, optional analytics, advertising identifiers, campaign measurement, audience matching and related profiling operate on consent under Article 6(1)(a) and applicable cookie rules. We use browsing, product and purchase activity to measure campaigns and group consenting visitors by interests or purchasing activity so that advertisements are more relevant. We keep identifiable campaign and audience data only while needed for the stated, consented purpose and remove or restrict them when consent is withdrawn or the purpose ends, except for limited compliance evidence retained on another stated legal ground. A hashed email address can still be personal data. Necessary, limited operational statistics that do not involve optional tracking rely on our legitimate interest in operating and securing the store under Article 6(1)(f). Providers and data categories are described in section 4; section 5 explains cookie choices and provides further technology information.

Forms, chats and reviews. A form or chat used to request product or order assistance is processed under Article 6(1)(b), or Article 6(1)(f) for another enquiry. Records follow the enquiry, complaint or claim retention period above. Promotional messages and review invitations that require marketing consent use Article 6(1)(a). A review you choose to publish may display your chosen name and content; our legitimate interest is to provide reliable customer feedback. Our displayed copy is retained while relevant to the product or store and removed or anonymised when no longer needed, subject to lawful dispute evidence.

Discounts and affiliate accounting. We process cart contents, quantities, applicable discount rules and order totals to calculate the requested offer and perform the purchase under Article 6(1)(b). Consent-based tracking used to attribute an affiliate sale is separate from the financial records needed to settle commissions. Commission records rely on our legitimate interest in paying valid referrals and on applicable accounting duties; their relevant legal retention period applies. General bundle calculations are not, by themselves, a credit decision or permission for advertising profiling.

Providing the information marked necessary for payment, invoicing or delivery is required to complete the order. Marketing and non-essential tracking are optional; refusing them does not prevent an ordinary purchase.

4. Who receives information?

We give recipients access only for the relevant purpose and on an appropriate legal basis. Our authorised staff and contracted service providers assist with the functions below. A processor acts on our instructions under a data processing agreement; an independent controller is responsible for its own processing. An installed application does not mean that every optional tracking feature is used.

Shopify, Shop and Shop Pay. Shopify International Limited and relevant affiliates provide the store platform and associated functions such as search, account administration, order workflows, translation and messaging. Shopify acts as our processor for the store services covered by its Data Processing Addendum. Shopify's separate consumer services, including Shop and Shop Pay, are explained in its Consumer Privacy Policy.

Where enabled, Shopify Network Intelligence and related enhanced services may combine interactions and transactions with our store, other merchants and Shopify for personalised services, analytics and advertising. For that processing Shopify acts as an independent controller. Required consent applies, including to targeted advertising and non-essential device storage. Your Shopify privacy choices are available through the Shopify privacy portal.

Payments. Shopify Payments and the financial institutions, card networks or wallet providers involved in your chosen payment method process the payment, verification, refunds and disputes. Relevant information includes contact and billing details, order and transaction information, device information and fraud indicators. Providers may act independently for their payment, security and regulatory duties. If Klarna through Mollie is offered and you select it, necessary customer, address, purchase and payment information is shared with Mollie B.V. and the relevant Klarna entity for that service. Their own processing, including any credit assessment, is described in the Mollie Privacy Statement and Klarna Privacy Policy.

Invoicing and accounting. Számlázz.hu, operated by KBOSS.hu Kft., processes billing and transaction information to issue, store and administer invoices on our behalf. Our contracted accounting service receives the accounting records necessary for its work. Legally required invoice or tax information is also provided to the Hungarian tax authority, NAV, and other competent authorities where required.

Delivery and returns. Our contracted carrier is GLS General Logistics Systems Hungary Csomag-Logisztikai Kft., 2351 Alsónémedi, GLS Európa u. 2., Hungary. GLS and the delivery partners required for the route receive the recipient's name, delivery address, email, telephone, parcel and tracking information and, where relevant, cash-on-delivery amount. The MyGLS Professional integration supports label creation and shipment administration. Necessary logistics and fulfilment service providers receive the information required to prepare, deliver or return your order. GLS's own transport-related processing is governed by its applicable privacy notice; it is not treated as merely our marketing processor.

Messages, forms and support. Shopify Messaging, CWILL (SendWILL) Popup Email, Hulk Form Builder and CWILL AI Chat support the enabled subscription, form or customer-service functions. Their service operators may receive the contact details, consent record, message content and relevant order details needed for those functions. If an AI chat is used, its nature is identified in the interface; you may contact info@sneakermood.eu for human assistance. Contacting support does not subscribe you to advertising. The purposes and retention rules in section 3 apply to our records; a provider's wider independent reuse requires its own disclosed lawful basis.

Advertising, measurement and affiliates. Depending on the services enabled and your consent, recipients may include Meta for Facebook and Instagram advertising, Google for Google Ads and enabled analytics, TikTok, Pinterest and Shopify for Shop advertising. Shared data can include IP and device identifiers, cookie or advertising IDs, page and product activity, purchases, campaign references and, where separately enabled and covered by consent, hashed contact details for audience matching. Elevar supports configured event collection and routing to these destinations. Server-side routing does not remove applicable consent requirements.

Awin, GOAFFPRO and Webgains support enabled affiliate programmes, attribution and commission administration. Information may include referral identifiers, order reference, value, products and cancellation or return status. Optional cross-site tracking is subject to consent. Information necessary to settle a valid commission is restricted to that purpose; affiliates do not thereby receive permission for unrelated customer marketing. Advertising platforms and affiliate networks may act as independent or, for particular collection or matching operations, joint controllers. Where joint control applies, the essential allocation of responsibilities is made available with the relevant service information. We remain responsible for our own collection and disclosures.

Reviews. Trustpilot supports enabled review invitations and review services using relevant contact details, order reference and review content. An invitation that requires marketing consent is sent only with it. A review voluntarily published on an external platform is subject to that platform's privacy rules; this does not authorise us to publish your private correspondence.

Store tools and integrations. Channable, Mulwi Feeds and Flexify for Facebook support configured product feeds or sales-channel integrations. Section Store, Products import Wizard Pro, Booster Page Speed Optimizer, Pay. Payment Methods and Transcy support the enabled store functions. Customer information is shared with their operators only if required by the configured function and authorised access, not simply because a tool appears in our app list. Authorised administration integrations, including Shopify ChatGPT MCP App and Shopify CLI Connector App, may access store records within their granted permissions. Their use for administration does not authorise unrelated advertising or unrestricted reuse of customer information.

Our own bundle-discount extension applies bundle and discount rules using relevant cart or order information for the requested transaction. It is our functionality; the extension's name does not identify an additional independent third-party recipient. Any external hosting or contractor that actually receives personal data must fall within the disclosed technical-provider arrangements.

Professional advisers, courts and authorities receive information where necessary for legal obligations or substantiated claims. You may ask us which recipients received your personal data and for information about applicable controller arrangements and transfer safeguards.

Further provider information. Provider notices supplement this notice and explain the providers’ own processing.

Meta · Meta cookies · Google · Google cookies · TikTok · Pinterest · Shopify · Elevar · Awin · GOAFFPRO · Webgains

Facebook and Instagram (Meta). We use Facebook and Instagram advertising services provided in the European Region by Meta Platforms Ireland Limited, Ireland to measure advertising performance, attribute purchases and reach relevant audiences, including visitors who have consented to remarketing. Our legal basis for optional advertising tracking, audience matching and associated disclosures is your prior consent under Article 6(1)(a) GDPR and applicable rules on device storage/access. Consent is not a condition of buying from us.

Our configured Meta integration can transmit page and product views, cart and checkout events, purchases, order value and currency, timestamps, page URLs, IP address, browser/device information and cookie or event identifiers. Where advanced matching is enabled and covered by consent, hashed email addresses or telephone numbers can also be transmitted. Hashing does not make these data anonymous. Browser-based Meta Pixel and, where configured, Conversions API/server-side events are subject to the same applicable consent requirements; moving an event to a server does not bypass your choice. We do not send full payment-card details or special-category personal data for advertising.

For the collection and transmission of event data covered by Meta's Controller Addendum, we and Meta act as joint controllers within that defined scope. We are responsible for our website's information, lawful collection and consent implementation; Meta's responsibilities and the allocation of duties are set out in that addendum. Subsequent processing by Meta outside that joint scope is governed by its own responsibilities and Privacy Policy. Meta may associate events with a Meta account or other information it holds. You may exercise your rights against either joint controller; contact us at info@sneakermood.eu and we will address or coordinate your request.

You can refuse or withdraw advertising consent through Cookie preferences in our footer. Withdrawal stops future consent-dependent collection and sharing from our store; it does not automatically erase information lawfully processed earlier. You can separately request erasure and manage Meta's advertising preferences in your Meta account. We retain identifiable campaign/audience information only while necessary for the consented purpose, and delete or restrict it on withdrawal or when that purpose ends, except records needed on another disclosed lawful basis. Meta's own retention criteria and international processing are explained in its Privacy Policy and Cookie Policy; section 6 below explains the safeguards required for our international disclosures.

5. Cookies and similar technologies

Technologies strictly necessary for the service you request, such as cart operation, checkout security and remembering consent choices, may operate without optional consent. Optional analytics, advertising, audience matching and affiliate tracking require the relevant prior consent where applicable. This applies to browser cookies, pixels and consent-dependent server-side disclosures.

Use Cookie preferences in the website footer to accept, reject or change optional categories. Withdrawing consent applies to future consent-based processing and does not affect the lawfulness of processing before withdrawal. Rejecting optional tracking does not prevent an ordinary purchase. Browser controls provide additional options but do not replace our consent controls. Marketing subscription and permission for individual email open or click tracking are separate choices where the law requires this.

The purposes, providers, data categories and retention rules are explained in sections 3 and 4. The Shopify preferences panel manages consent categories; it is not a complete inventory of every third-party technology. Shopify's Cookie Policy explains its platform cookies and their lifetimes. Session cookies end with the session; persistent cookies expire according to the technology and configuration or are deleted earlier. Provider documentation below gives further details. Only services actually enabled on our store and permitted by the applicable consent choices may process data; a provider's full cookie list is not a statement that we use every listed cookie.

We do not activate a new consent-dependent purpose on the basis of unrelated earlier consent. If you cannot access the preferences, or want details of a technology encountered on our store, contact info@sneakermood.eu. We assist with your choice and provide the relevant information.

6. International transfers

Some providers process data outside the EEA. Transfers require an applicable lawful safeguard: an adequacy decision covering the recipient and processing, or appropriate safeguards such as the European Commission's standard contractual clauses, supplemented where necessary. US transfers relying on the EU–US Data Privacy Framework are limited to appropriately certified recipients and covered processing. We do not rely on your use of the website as consent to unrestricted transfers. Ask us for information about a particular transfer or a copy of the relevant safeguards, with necessary confidential details redacted.

Shopify processes information internationally, including through locations in Canada and Singapore. For covered transfers between Shopify group companies from the EEA, Shopify uses its approved Binding Corporate Rules as described in its Data Processing Addendum. Other transfers use the applicable adequacy decision or appropriate safeguards, as relevant to the recipient. Shopify platform-cookie details are available in its Cookie Policy. Our use of optional technologies is subject to the choices in section 5.

7. Your rights and choices

Subject to the GDPR conditions, you can request access, correction, erasure, restriction and data portability. You can object at any time to direct marketing, including associated profiling. You can also object to processing based on legitimate interests for reasons relating to your situation. Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of earlier processing. Unsubscribe links stop marketing; necessary order or legal notices may still be sent.

Send requests to info@sneakermood.eu. We normally respond within one month. Where legally justified by complexity or the number of requests, we may extend by up to two further months, explaining this within the first month. We use proportionate identity checks. Requests are normally free; the GDPR permits a reasonable fee or refusal for manifestly unfounded or excessive requests. Erasure does not override a valid legal retention duty.

You may complain to the Hungarian National Authority for Data Protection and Freedom of Information (NAIH), 1055 Budapest, Falk Miksa utca 9–11., Hungary; ugyfelszolgalat@naih.hu; naih.hu, or to the supervisory authority in your country of habitual residence or work or where the alleged infringement occurred. You may also seek a judicial remedy.

8. Automated decisions, security and updates

Automated tools can identify inconsistencies in transaction, payment, device or address information and flag an order for fraud review. A risk indicator assists the review; a member of our team reviews a flagged order before we decide to reject it on that basis. You can provide an explanation, correct inaccurate information and request human review by writing to info@sneakermood.eu. A payment provider may make its own payment or credit decision, including an automated decision under its own lawful arrangements; the provider's notice explains that processing and the available rights.

Ordinary bundle calculations apply the disclosed discount rules to cart contents and quantities. Consent-based marketing segmentation uses the interests and activity described in section 3 to select advertisements or messages. These functions do not by themselves decide whether you can enter into a purchase contract. We do not introduce a solely automated decision with legal or similarly significant effects without an applicable legal basis, prior information about the relevant logic and consequences, and the safeguards required by Article 22 GDPR.

We use appropriate access controls and technical and organisational safeguards. No system is completely risk-free. Our marketing is not directed to children under 16; where valid consent requires parental authorisation, we obtain it or do not carry out that consent-based processing. Suspected inappropriate collection can be reported to us.

We update this notice when our practices or legal requirements change and give additional notice or obtain fresh consent where required. A new notice does not retrospectively legitimise a different use of previously collected information.

Login

Forgot your password?

Don't have an account yet?
Create account

Join us as seller