Privacy and cookie policy

Valid from: 21 September 2026
Your privacy matters to us. This policy explains which personal data we process, why, on what legal basis, who we share it with, how long we keep it and what rights you have. It is based on the General Data Protection Regulation (Regulation (EU) 2016/679, GDPR), the Slovenian Personal Data Protection Act (ZVOP-2) and the Slovenian Electronic Communications Act (ZEKom-2).
1. Controller
- SPLETNA PRODAJA IN DRUGE STORITVE, BERNARDA FLEISCHMANN S.P.
- Kokolajnščak 31, 9244 Sv. Jurij ob Ščavnici, Slovenia
- Tax number: 76734960, registration number: 9900179000
- E-mail: fleischmanncoins@gmail.com
We have not appointed a data protection officer, as the law does not require us to. For any question about personal data, please write to the e-mail address above.
2. What data we process and why
Orders and performance of the contract
When you place an order (as a guest or registered customer), we process your name, delivery and billing address, e-mail address, phone number, where applicable company name and tax number, order contents, chosen payment and shipping method, order comment and payment data (amount, date and, for cards, only the last four digits and card type as reported by Stripe).
Purpose: accepting and fulfilling the order, payment, delivery, order status updates, handling withdrawals and conformity claims.
Legal basis: performance of a contract (Article 6(1)(b) GDPR).
Order notifications
We automatically send you an order confirmation by e-mail (with payment details and QR code), a payment received notice and a shipping notice with the tracking number. These messages are part of performing the contract (Article 6(1)(b) GDPR) and are not advertising.
Invoices and accounting
We keep invoice data and pass it to our accounting service because tax and accounting laws require us to (Article 6(1)(c) GDPR).
Customer account
If you register, we process your name, e-mail address, password (stored encrypted), saved addresses, order history and wishlist. Legal basis: the contract for the use of the customer account (Article 6(1)(b) GDPR).
You can request deletion of your account in your account or by e-mail. The account is deleted automatically 10 days after the request. Order data we must keep by law is retained, while the personal data in the account is anonymised.
Contact form, product questions and offers to sell coins
When you write to us, we process your name, e-mail address, optionally your phone number and the content of your message (for product questions, also the product concerned). Purpose: answering your question or offer. Legal basis: your consent given by ticking the box in the form (Article 6(1)(a) GDPR) and steps taken at your request before entering into a contract (Article 6(1)(b) GDPR).
Product reviews
If you submit a review, we publish the name you entered (it can be a nickname), your rating and text. Legal basis: your consent (Article 6(1)(a) GDPR).
Newsletter
If you subscribe to the newsletter, we process your e-mail address (and name, if you are registered) to send you news and offers from our shop. Legal basis: your consent given by ticking the box when subscribing (Article 6(1)(a) GDPR and Article 226 ZEKom-2).
You can unsubscribe at any time via the unsubscribe link in every message, in your account or by e-mail. Withdrawing consent does not affect the lawfulness of processing before the withdrawal.
Website security and form protection
We protect the login, registration, contact, newsletter and checkout forms against abuse and bots with Google reCAPTCHA v3. When a form is used, the service assesses whether it is being filled in by a human and sends Google technical data about your device and browser and your IP address. Google may also process this data for its own purposes; see the Google privacy policy. The service is loaded only on pages with the forms listed above.
On every visit the server records technical data (IP address, time, requested page, browser) in server logs. Legal basis for both: our legitimate interest in the security of the shop and preventing abuse (Article 6(1)(f) GDPR).
Establishing and defending legal claims
We may use order and communication data where necessary to establish or defend legal claims. Legal basis: legitimate interest (Article 6(1)(f) GDPR).
3. Who we share data with
We share data only to the extent needed for each purpose. We do not sell personal data.
- Website hosting: Neoserv d.o.o., Slovenia (processor).
- Card payments: Stripe Payments Europe Ltd., Ireland. Stripe processes card data directly and as an independent controller for payment and fraud prevention purposes. Some data may be transferred to Stripe, Inc. in the USA.
- Form protection: Google (Google Ireland Limited, Ireland, and Google LLC, USA) for the reCAPTCHA service.
- Delivery: Pošta Slovenije d.o.o. or another delivery service handling the parcel (name, address, phone and e-mail for delivery notifications). For shipments outside the EU, also the customs authorities of the destination country.
- Public authorities, where the law requires us to.
We have data processing agreements in place with our processors.
4. Transfers outside the EU
When Stripe and Google reCAPTCHA are used, data may be transferred to the USA. Such transfers are based on the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework or on standard contractual clauses adopted by the European Commission.
For deliveries to countries outside the EU, we necessarily share delivery data with the local postal or delivery service, as this is required to perform the contract you concluded with us (Article 49(1)(b) GDPR).
5. How long we keep data
- Orders and invoices: 10 years after the end of the year in which the invoice was issued (tax and accounting rules).
- Other contract and complaint documentation: until the limitation periods for contractual claims expire.
- Customer account and wishlist: until you delete the account.
- Newsletter: until you unsubscribe. We keep proof of consent and unsubscription for 5 years after you unsubscribe to be able to demonstrate lawful sending.
- Contact form and product questions: 1 year after the communication ends, unless the message becomes part of a contract.
- Product reviews: while the review is published or until you withdraw consent.
- Server logs: up to 6 months.
After that, data is deleted or anonymised.
6. Your rights
Regarding your personal data, you have the right to:
- access your data and obtain a copy (Article 15 GDPR),
- rectification of inaccurate data (Article 16 GDPR),
- erasure (Article 17 GDPR), except where we must keep data by law,
- restriction of processing (Article 18 GDPR),
- data portability for data you gave us under a contract or consent (Article 20 GDPR),
- object to processing based on legitimate interest (Article 21 GDPR),
- withdraw consent at any time, without affecting the lawfulness of processing before the withdrawal (Article 7(3) GDPR).
Send your request to fleischmanncoins@gmail.com or through the contact form. We will reply without undue delay and within one month at the latest; for complex or numerous requests we may extend this by up to two further months, in which case we inform you within one month of receiving the request (Article 12(3) GDPR). Exercising your rights is free of charge. If we cannot reliably verify that the request comes from you, we will ask you for additional confirmation of your identity.
If you believe we process your data unlawfully, you may lodge a complaint with the supervisory authority: Information Commissioner of the Republic of Slovenia (Informacijski pooblaščenec), Dunajska cesta 22, 1000 Ljubljana, Slovenia, e-mail gp.ip@ip-rs.si, phone +386 1 230 97 30, www.ip-rs.si, or with the supervisory authority in the EU country where you live. We would appreciate it if you contacted us first so we can try to resolve the issue.
7. Do you have to provide data?
Data marked as required at checkout is necessary to conclude and perform the contract. Without it we cannot accept the order. The newsletter, reviews and other forms are voluntary.
We do not make automated decisions or create profiles that have legal or similarly significant effects on you.
8. Minors
The shop is not intended for children. Persons under 15 should not create an account or subscribe to the newsletter without the consent of a parent or guardian (Article 8 ZVOP-2).
9. Security
The website uses an encrypted connection (HTTPS). Only persons who need data for their work have access to it. We do not store payment card data, as it is processed by Stripe.
10. Cookies
Cookies are small text files that a website stores in your browser. We treat similar technologies, such as the browser's local storage, the same way.
Under Article 225 ZEKom-2 we may use without your consent only cookies that are strictly necessary for the website to work or for a service you have explicitly requested. For all other cookies we ask for your consent first.
Managing your consent
On your first visit a cookie bar is shown. You can accept or reject optional cookies or choose individual groups. Until you consent, we do not set optional cookies. Your choice is stored for 90 days, after which we ask again. You can change your choice at any time in the cookie settings (link in the footer) or delete cookies in your browser settings.
Cookie groups
- Necessary cookies - make the shop work and cannot be switched off: session and login, cart, selected language and store, protection of forms against forged requests, faster page loading, your stored cookie choice, bot protection (Google reCAPTCHA) and fraud prevention for card payments (Stripe).
- Analytics cookies - would help us understand how visitors use the website. Set only with your consent.
- Marketing cookies - would allow ads tailored to your interests. Set only with your consent.
We currently do not use third-party analytics or marketing tools. If we introduce them, we will list them in the cookie list and set them only with your consent.
Main necessary cookies
- PHPSESSID - your session ID on the server (up to 100 days).
- form_key - a random key that protects forms against forged requests.
- private_content_version, section_data_ids, mage-cache-sessid, mage-cache-storage - displaying personal content (cart, login) and faster page loading.
- X-Magento-Vary - faster page loading from the server.
- store - the selected language or store.
- mage-messages - displaying messages on the page (e.g. "item added to cart").
- consent cookie - stores your cookie choice (90 days).
- _GRECAPTCHA - Google reCAPTCHA, protecting forms against bots.
- __stripe_mid, __stripe_sid - Stripe, fraud prevention for card payments (checkout only).
The cookie list is updated over time. The full, current list with purposes and durations is on the cookie settings page (link in the footer).
11. Changes to this policy
We update this policy when we change how we process data or when the law changes. The current version is always published on this page, with the date it takes effect at the top. We inform registered customers of significant changes by e-mail.
Purchases are also governed by our General terms and conditions.