Privacy and Policy
This Privacy Policy explains how BizzOnWheels (“we”, “us”, “our”) collects, uses and protects your personal data when you visit our website and Shopify store, contact us or purchase our products.
By using our website or placing an order, you agree to the processing of your personal data as described in this Privacy Policy.
1. Who we are
The website and online store are operated by:
SC Bizz On Wheels SRL
Registered in Romania
City: Roman / Street Cuza voda no. 23
VAT / Tax number: R33412423
Trade Register no.: J27/437/23.07.2014
Email: office@bizzonwheels.com
For the purposes of data protection law (including the EU General Data Protection Regulation – GDPR), we are the data controller of your personal data.
2. What data we collect
We may collect and process the following categories of personal data:
a) Identity and contact data
-
first name, last name
-
company name
-
billing and delivery address
-
email address, phone number
-
country
b) Order and account data
-
products ordered, quantities, prices
-
order history and invoices
-
customer account details (if you create an account)
c) Payment data
-
limited payment information (e.g. last 4 digits of card, transaction ID)
-
we do not store full card numbers – payments are processed securely by third-party payment providers (e.g. card processors, Stripe, etc.)
d) Communication data
-
messages you send via contact forms, email or chat
-
support requests, quotes and technical questions
e) Usage and technical data
-
IP address, device type, browser, operating system
-
pages visited, time spent on the site, clicks and navigation
-
referring website or campaign
This information is typically collected via cookies and similar technologies (see our Cookie Policy).
3. How we use your data (purposes)
We process your personal data for the following purposes:
-
To process and deliver your orders
-
creating and managing orders
-
arranging shipping and delivery
-
sending order confirmations, invoices and updates
-
-
To provide customer support
-
answering questions via email or forms
-
handling warranty and service requests
-
managing returns and refunds
-
-
To manage your customer account (if applicable)
-
creating and maintaining your login
-
storing order history and preferences
-
-
To send marketing communication (with your consent)
-
newsletters about new products, case studies and promotions
-
content about food carts, mobile billboards and advertising bikes
-
-
To improve our website and products
-
analysing traffic and behaviour on the site
-
understanding which pages and products are most interesting
-
improving the user experience and product offering
-
-
To comply with legal obligations
-
bookkeeping and tax requirements
-
responding to lawful requests from authorities
-
4. Legal bases for processing (GDPR)
We process your data based on the following legal grounds:
-
Contract – to process and fulfil your order or to provide services you request.
-
Legitimate interest – to operate and secure our website, prevent fraud and understand how customers use our products and site.
-
Consent – for optional activities such as email marketing or certain cookies (analytics, advertising). You can withdraw your consent at any time.
-
Legal obligation – to comply with accounting, tax and other legal requirements.
5. Who we share your data with
We may share your personal data with trusted third parties, only when necessary:
-
Shopify – our e-commerce platform which hosts the online store.
-
Payment providers – to process card or online payments securely.
-
Shipping and logistics partners – to deliver your order worldwide.
-
IT and hosting providers – to keep the site running and secure.
-
Marketing and analytics tools – for newsletters, campaigns and anonymous usage statistics (e.g. email marketing platforms, analytics services).
These partners only receive the information needed to provide their services, and they are required to protect your data and use it only for the agreed purposes.
We do not sell your personal data to third parties.
6. International transfers
Some of our service providers (for example Shopify, payment processors or analytics tools) may be located outside the European Union/EEA.
Where this is the case, we take appropriate steps to ensure that your data is protected, such as:
-
using providers in countries recognised by the European Commission as providing an adequate level of data protection, or
-
using standard contractual clauses and other safeguards.
7. Data retention
We keep your personal data only for as long as necessary for the purposes described above, including:
-
for orders: as long as required by accounting and tax law (often 5–10 years);
-
for customer accounts: as long as your account remains active or until you ask us to delete it;
-
for marketing: until you unsubscribe or withdraw your consent;
-
for analytics: for the period defined in our cookie and analytics tools.
After these periods, data is deleted or anonymised where possible.
8. Your rights (EU/EEA and similar regimes)
You have certain rights regarding your personal data, subject to legal conditions:
-
Right to access – to know what data we hold about you.
-
Right to rectification – to correct inaccurate or incomplete data.
-
Right to erasure – to request deletion of your data where we have no legal reason to keep it.
-
Right to restriction – to limit how we use your data in certain cases.
-
Right to data portability – to receive your data in a structured, commonly used format and transmit it to another controller.
-
Right to object – to object to processing based on legitimate interest, and to object at any time to direct marketing.
-
Right to withdraw consent – where processing is based on your consent (e.g. newsletter, marketing cookies).
To exercise your rights, please contact us using the details in section 1. We may need to verify your identity before responding.
You also have the right to lodge a complaint with your local data protection authority. In Romania, this is the National Supervisory Authority for Personal Data Processing (ANSPDCP).
9. Security
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, alteration or disclosure, including:
-
using secure connections (HTTPS)
-
restricting access to data to authorised personnel only
-
using reputable hosting and payment providers with strong security standards.
However, no system is 100% secure and we cannot guarantee absolute security of information transmitted over the internet.
10. Third-party websites
Our website may contain links to third-party sites (for example social media, partners or press articles). We are not responsible for the privacy practices or content of these external sites. We encourage you to read their privacy policies.
11. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in law, our services or our data processing practices.
The latest version will always be available on this page and will include the date of the last update.