Free shipping on orders over €70Free shipping on orders over €70Free shipping on orders over €70Free shipping on orders over €70Free shipping on orders over €70Free shipping on orders over €70Free shipping on orders over €70Free shipping on orders over €70

Privacy Policy

Last updated: 21 May 2026

2. What Data We Collect

Account data: When you register or log in, we collect your email address and any profile information you provide (e.g. name, delivery address). This is processed by our authentication and database provider on our behalf.

Order data: When you place an order, we collect billing and shipping information, and order details. Payment card data is handled exclusively by Stripe and is never stored on our servers.

Technical data: With your consent, our performance monitoring service collects anonymised metrics (e.g. page load times, Core Web Vitals) to help us improve the site. No personal identifiers are included in this data.

Usage data: We use Vercel Analytics to collect anonymised, aggregated usage statistics (page views, referral source, approximate country, device type). No cookies are used and no personal data is stored.

Communications: If you contact us by email, we retain that correspondence to respond to your enquiry.

Newsletter: If you subscribe to our newsletter, we collect your email address and preferred language to send you marketing communications (new products, offers, skincare tips). You may unsubscribe at any time via the link in every email.

3. Legal Basis for Processing

Contract performance (Art. 6(1)(b) GDPR): Processing your account and order data is necessary to fulfil your purchases and manage your account.

Consent (Art. 6(1)(a) GDPR): We process performance monitoring data (Core Web Vitals via Speed Insights) only after you give explicit consent via our cookie banner.

Consent — Newsletter (Art. 6(1)(a) GDPR): Newsletter emails are sent only on the basis of your explicit consent, given when you submit your email address via the newsletter sign-up form. You may withdraw consent at any time by clicking the unsubscribe link in any newsletter email, and we will stop sending marketing communications within 10 business days.

Legitimate interests (Art. 6(1)(f) GDPR): We process anonymised, aggregated usage data via Vercel Analytics (cookieless, no personal identifiers stored) under our legitimate interest in understanding how visitors use the site. We also rely on this basis to protect the security and integrity of our service.

4. Third-Party Service Providers

Authentication & Database Provider

We use a third-party provider to manage user accounts and store order data. This provider processes data on servers within the EU/EEA under a data processing agreement with us.

Stripe (Payment Processing)

Payments are processed by Stripe, Inc. Stripe is PCI-DSS Level 1 certified. We share only the order amount and currency with Stripe; card details never pass through our systems. See Stripe Privacy Policy.

Performance Monitoring Service

With your consent, we use a third-party performance monitoring service that collects anonymised Core Web Vitals data (e.g. page load speed) to help us improve the site. No personal data is transmitted.

Vercel Analytics

We use Vercel Analytics to collect anonymous, aggregated usage statistics (page views, referrer, country, device type). No cookies are set and no personal data is stored. See the Vercel Privacy Policy.

5. Cookies

We use essential cookies for authentication and payment security (Stripe), and — with your consent — performance monitoring cookies (Speed Insights). Vercel Analytics collects anonymised usage statistics without any cookies or consent requirement. See our Cookie Policy for a full list.

6. Data Retention

Account and order data is retained for as long as your account is active and for up to 7 years afterwards to comply with tax and accounting obligations. You may request deletion at any time (subject to legal retention requirements) by contacting us at hello@ypheskincare.cy.

Email correspondence is retained for up to 2 years. Anonymised usage data processed via Vercel Analytics is not stored by us; Vercel retains aggregated statistics in accordance with their own privacy policy.

7. Your Rights

Under the GDPR (and equivalent legislation) you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request erasure of your data
  • Restrict or object to processing
  • Data portability
  • Withdraw consent at any time (without affecting prior processing)
  • Lodge a complaint with the Cyprus Commissioner for Personal Data Protection

To exercise any right, email us at hello@ypheskincare.cy. We will respond within 30 days.

8. International Transfers

Where data is transferred outside the EEA (for example by payment processors based in the US), appropriate safeguards are in place including Standard Contractual Clauses and/or adequacy decisions.

9. Changes to This Policy

We may update this policy from time to time. The "Last updated" date at the top of this page will reflect any changes. Continued use of the site after changes constitutes acceptance of the revised policy.

Subscribe to our newsletter