Privacy policy
Last updated: 28 November 2025
The purpose of this privacy policy is to inform you about the type of personal data collected when you use the website https://contract.vitracircle.com (the “Website”) and how we process, use and protect this data. This privacy policy complies with the Swiss Data Protection Act (hereinafter "SDSG"), the European General Data Protection Regulation (hereinafter "GDPR") and other applicable data protection regulations. The GDPR, the SDSG and other applicable data protection regulations may contain minor differences in the definitions used. The terminology in this Privacy Policy is based on the definitions in the GDPR, which have the same meaning in the SDSG. Please note, however, that whether and to what extent the GDPR, the SDSG or other data protection regulations apply to you depends on the individual case.
Vitra International AG, Klünenfeldstrasse 22, 4127 Birsfelden, Switzerland, operates the Website, including all related information, content, features, tools, products and services (the "Services"). The Services are based on Shopify technology. This Privacy Policy describes how we collect, use or share personal data when you visit, use or make a transaction using the Services or otherwise communicate with us. If there is a conflict between our Terms and Conditions and this Privacy Policy, this Privacy Policy shall prevail with respect to the collection, processing and sharing of your personal data.
What personal data do we collect or process?
When we use the term "personal data," we are referring to information that identifies you or another individual or can be directly associated with you. Personal data does not include information that has been collected anonymously or has been anonymised so that it cannot be used to identify or be associated with you. Depending on how you interact with the Services, where you live, and as permitted or required by applicable law , we may collect or process the following categories of personal data, including inferences drawn from that personal data:
- Contact details, including name, postal address, billing address, delivery address, telephone number and email address.
- Financial data, including credit, debit card and financial account numbers, payment card information, financial account information, transaction details, payment method, payment confirmation and other payment details.
- Account information, including username, password, security questions, configurations and settings.
- Transaction information, including items you view, add to your shopping cart, add to your wish list, or purchase, return, exchange, or cancel, as well as your past transactions.
- Communications with us, including the information you provide when communicating with us, such as when you submit a customer support request.
- Device information, including information about your device, browser or network connection, IP address and other unique identifiers.
- Usage information, including information about your interaction with the Services, including how and when you interact with or browse the Services.
Sources of personal data
We may collect personal data from the following sources:
- Directly from you We collect data when you create an account, access or use the Services, communicate with us, or otherwise provide us with your personal data.
- Automatically through the Services We collect data from your device, when you use our products or services or visit our Website, and through the use of cookies and similar technologies, among other things.
- From our service providers We collect data when, among other things, we engage service providers to enable certain technologies and when they collect or process your personal data on our behalf.
- From our partners and other third parties
How do we use your personal data?
Depending on how you interact with us or which of our services you use, we may use personal data for the following purposes:
- Provision, customisation and improvement of services. We use your personal data to provide you with services. This includes, among other things, fulfilling our contract with you, processing your payments, fulfilling your orders, storing your configurations and the items you are interested in, sending notifications related to your account, creating, maintaining and otherwise managing your account, organising shipping, facilitating returns and exchanges, allowing you to submit reviews, and creating a personalised shopping experience for you, for example by recommending products based on your purchases. This may also include using your personal data to better tailor and improve the Services.
- Marketing and advertising. We use your personal data for marketing and advertising purposes, for example to send marketing and promotional communications via email, SMS or post, and to display online advertisements for products or services for the Services or other websites, including based on items you have previously purchased or added to your shopping basket, as well as other activities related to the Services.
- Security and fraud prevention. We use your personal data to authenticate your account, provide a secure payment and shopping experience, detect, investigate or take action regarding potential fraudulent, illegal, unsafe or malicious activity, protect public safety and ensure the security of our Services. If you choose to use the Services and register for an account, you are responsible for protecting your account credentials. We strongly recommend that you do not share your username, password or other access credentials with anyone else.
- Communicating with you. We use your personal data to provide you with customer support and effective services, respond to your enquiries in a timely manner, and maintain our business relationship with you.
- Legal reasons. We use your personal data to comply with applicable law or respond to lawful process, including requests from law enforcement or regulatory authorities, to investigate or participate in civil investigations, potential or actual litigation or other adversarial proceedings, and to investigate or enforce potential violations of our terms or policies.
How do we share personal data?
In certain circumstances and where there is a legal basis to do so, we may share your personal data with third parties. Such circumstances may include:
- At Shopify, these are providers and other third parties who provide services on our behalf (e.g. IT management, payment processing, data analysis, customer support, cloud storage, fulfilment and shipping).
- We share personal data with business and marketing partners who provide marketing services to you and display advertisements to you. For example, we use Shopify to support personalised advertising with third-party services based on your online activities across various retailers and websites. Our business and marketing partners use your data in accordance with their own privacy policies. Depending on where you live, you may have the right to instruct us not to share information about you in order to show you targeted advertising and marketing based on your online activities across different retailers and websites.
- When you request or otherwise consent to us sharing certain information with third parties, for example to deliver products to you, or when you use social media widgets or login integrations.
- We share personal data with our affiliates or otherwise within our group of companies.
- In connection with a business transaction such as a merger or insolvency, to comply with applicable legal obligations (including responding to subpoenas, search warrants and similar requests), to enforce applicable terms of service or policies, and to protect or defend the Services, our rights and the rights of our users or others.
To the extent that we use external service providers to process personal data, these service providers have been carefully selected, commissioned in writing and are bound by our instructions. The service providers will not disclose this data to third parties, but will delete it after fulfilment of the contract and the expiry of statutory retention periods, unless consent has been given for further storage.
Relationship with Shopify
The Services are hosted by Shopify, which collects and processes personal data about your access to and use of the Services in order to provide and improve the Services to you. Data that you submit to the Services is shared with Shopify and third parties who may be located in countries other than your country of residence in order to provide and improve the Services to you. To protect, expand and improve our business, we also use certain advanced Shopify features that incorporate data and information from your interactions with our shop, other merchants and Shopify. To provide these advanced features, Shopify may use personal data collected from your interactions with our shop, other merchants and Shopify. In these circumstances, Shopify is responsible for processing your personal data, including responding to your requests to exercise your rights regarding the use of your personal data for these purposes. For more information about how Shopify uses your personal data and your rights, please see the Shopify Consumer Privacy Policy. Depending on where you live, you may be able to exercise certain rights regarding your personal data listed here Link to Shopify Privacy Portal.
Third-party websites and links
The Services may provide links to websites or other online platforms operated by third parties. If you follow links to websites that are not affiliate websites or are not controlled by us, you should review their privacy and security policies and other terms and conditions. We do not guarantee and are not responsible for the privacy or security of such websites, including the accuracy, completeness or reliability of the information contained on those websites. Information you provide in public or semi-public areas, including information you share on third-party social networking platforms, may also be viewed by other users of the Services and/or users of those third-party platforms, without restriction on their use by us or any third party. The inclusion of such links by us does not imply that we endorse the content of these platforms or their owners or operators, unless expressly stated in the Services.
Cookies and similar technologies
Cookies or similar technologies may be used on the Website. Cookies are small text files that are assigned to and stored on your device by the browser you are using via a characteristic string of characters and through which we receive certain information. Cookies cannot execute programmes or transmit viruses and therefore cannot cause any damage. They serve to make the Internet offering more user-friendly and effective overall.
Cookies may contain data that enables the device used to be recognised. In some cases, however, cookies only contain information about certain settings that cannot be traced back to a specific person. Cookies cannot directly identify a user.
We use cookies that are strictly necessary to navigate the Website, use basic functions and ensure the security of the Website; this is our overriding legitimate interest (Art. 6(1)(f) GDPR). These cookies do not collect any information about you for marketing purposes. Further information on the cookies that Shopify sets as a result of hosting the services can be found here: Shopify UK's cookie policy.
Insofar as we use cookies or similar technologies that go beyond the aforementioned purposes, this is done on the basis of your declaration of consent. Further information about the cookies we set can be found in our Consent Management Tool, provided by https://usercentrics.com/. There you can also configure your individual settings. We use the Consent Management Tool because we are legally obliged to manage and document declarations of consent.
Security and storage of your data
Please note that no security measures are perfect or impenetrable, and we therefore cannot guarantee "perfect security". In addition, information you send to us may be exposed to risks during transmission. We recommend that you do not use unsecure channels when transmitting sensitive or confidential information to us.
How long we retain your personal data depends on various factors. These include, for example, whether we need the data to manage your account, provide you with services, comply with legal obligations, resolve disputes or enforce other applicable contracts and policies.
Your rights and options
Depending on where you live, you may have some or all of the rights listed below in relation to your personal data. However, these rights are not absolute, may only apply in certain circumstances, and in certain cases we may refuse your request to the extent permitted by law.
- Right of access/information. You may have the right to request access to the personal data we hold about you.
- Right to erasure. You may have the right to request that we erase the personal data we hold about you.
- Right to rectification. You may have the right to request that we correct inaccurate personal data we hold about you.
- Right to data portability. You may have the right to obtain a copy of the personal data we hold about you and to request that we transfer it to a third party in certain circumstances and with certain exceptions.
- Managing communication preferences. We may send you promotional emails under certain circumstances. You can opt out of receiving these emails at any time by using the unsubscribe option included in our emails to you. If you opt out, we may still send you non-promotional emails, such as those about your account or orders you have placed.
- Right to object and right to restrict processing. You may have the right to request that we stop or restrict the processing of personal data for certain purposes.
- Withdrawal of consent. Where we rely on consent to process your personal data, you have the right to withdraw that consent. If you withdraw your consent, this will not affect the lawfulness of processing based on your consent before its withdrawal.
You can exercise these rights as indicated in the Services or by contacting us using the contact details provided below. For more information about how Shopify uses your personal data and your rights, including rights relating to data processed by Shopify, please visit https://privacy.shopify.com/en.
Exercising these rights will not result in any disadvantage to you. Where permitted or required by applicable law, we may need to verify your identity before we can process your requests. In accordance with applicable law, you may appoint an authorised representative to make requests on your behalf to exercise your rights. Before we accept such a request from a representative, we will require proof that you have authorised them to act on your behalf. This may require you to confirm your identity directly to us. We will respond to your request promptly in accordance with applicable law.
Complaints
If you have any complaints about how we process your personal data, please contact us using the contact details below. Depending on where you live, you have the right to object to our decision by contacting us using the contact details below or by submitting your complaint to the relevant data protection authority. For the European Economic Area, there is a list of competent data protection supervisory authorities. If you wish to access it, you can do so here.
International transfers
Please note that we may transfer, store and process your personal data outside the country in which you reside.
When we transfer your personal data outside the European Economic Area or the United Kingdom, we rely on recognised transfer mechanisms such as the European Commission's standard contractual clauses or equivalent contracts issued by the relevant UK authority, unless the data transfer is to a country that has been found to provide an adequate level of protection.
Changes to this privacy policy
We may update this privacy policy from time to time to reflect changes in our practices or for other operational, legal or regulatory reasons. We will post the revised privacy policy on this Website, update the "Last updated" date accordingly, and provide notice as required by applicable law.
Contact
If you have any questions about our data protection practices or this privacy policy, or if you wish to exercise any of your rights, please contact Vitra International AG, Klünenfeldstrasse 22, 4127 Birsfelden, Basel-Landschaft, Switzerland, or send an email to privacy@vitra.com . If you have any questions regarding data protection, you can also contact our data protection officer at dsb@vitra.com .