Privacy policy

1. Controller and contact

The data controller is 1490 s.r.o., Company ID 05235847, VAT ID CZ05235847, registered office at Sudkův Důl 10, 395 01 Obrataň, Czech Republic (“UTOPIA”, “we” or “us”). Contact: ivo@utopia.direct.

2. Data, purposes and legal bases

We process identification, contact, billing, delivery, order, payment-status and communication data to enter into and perform purchase contracts, deliver orders, and handle complaints and returns. The legal basis is performance of a contract and pre-contractual steps.

We retain accounting, tax and other mandatory records to comply with legal obligations. We may process communications and necessary technical records for customer support, store security and the establishment, exercise or defence of legal claims, based on the contract or our legitimate interests as applicable.

We send newsletters only where we have valid consent or another lawful basis. We use Shopify to record consent and send the messages. Every marketing message provides an easy way to unsubscribe.

Depending on the customer's choices, Shopify and Shop may also send automated notifications about an abandoned cart, a product being back in stock, a price drop or a product viewed again. Sending is governed by the applicable consent settings, and the notifications can be disabled or unsubscribed from.

Google Analytics 4, Google Ads and Meta Pixel/Conversions API are used to measure traffic, the purchasing journey and advertising, and — only where permitted — to create advertising audiences. Optional analytics and marketing technologies run only after the relevant cookie consent. Consent can be changed or withdrawn through “Cookie settings” in the footer without preventing an ordinary purchase.

3. Cookies

We use strictly necessary technologies for the cart, checkout, security and consent choices; analytics and marketing technologies are used only after consent. The current cookie list and durations are shown in the cookie settings. Merely using the website does not constitute consent to optional cookies.

4. Recipients and processors

We disclose data only to the extent necessary for a particular purpose. The recipients and service providers typically include:

  • Shopify International Limited and the Shopify group for the online store, hosting, customer accounts, checkout, transactional and marketing messages, and Shop services. Where Shopify Network Intelligence or another Enhanced Service is enabled, Shopify may also process certain data as an independent controller under its Consumer Privacy Policy;
  • Shopify Payments and, depending on the selected method, the relevant card network or digital-wallet provider; PayPal for PayPal payments; and UTOPIA's bank for bank transfers;
  • Messenger or another carrier selected for the order. We disclose only the information needed to deliver and track the shipment, in particular the recipient's name, delivery address, telephone number, email address where required, and necessary shipment details. For Messenger deliveries, our Mesík application operates on Cloudflare Workers;
  • Fakturoid s.r.o., company ID 04656679, for issuing and managing invoices, and UOL a.s., company ID 24753157, for accounting and tax services;
  • Shopify for transactional emails, marketing-consent records and automated Shop remarketing, and Orderly Emails by FORSBERG+two ApS for customised email templates;
  • Google Ireland Limited for Google Analytics 4, Google Ads and Merchant Center, and Meta Platforms Ireland Limited for Meta Pixel and Conversions API, in each case according to cookie choices and integration settings;
  • Revoq, operated by BuschBytes / Jonas Busch, for the online withdrawal form; it may process identification and contact details, order and withdrawal information, IP address and device information.

We disclose data to public authorities only where required by law or necessary to protect legal rights.

5. International transfers

Some technology providers may process data outside the EEA. Where applicable, they use a mechanism recognised by the GDPR, such as an adequacy decision, standard contractual clauses, binding corporate rules and any necessary supplementary safeguards. Customer data from the EEA is initially received by Shopify International Limited in Ireland and may then be processed by Shopify affiliates and subprocessors, including in Canada and the United States. Details are provided in the policies of the relevant services; on request, we will provide available information about the transfer mechanism used.

6. Retention

We retain personal data only for as long as necessary for the relevant purpose:

  • orders and related contractual communication are generally kept for four years after completion of the order; information contained in tax documents is kept for ten years after the end of the relevant tax period;
  • other accounting documents are retained for the period required by law, generally five years after the end of the accounting period;
  • complaints, withdrawals and legal claims are retained while handled and generally for four years afterwards; longer only where a dispute is ongoing or the law requires it;
  • standalone customer-support communication is generally retained for three years after closure;
  • a customer account is retained until it is closed, without affecting the statutory periods applicable to orders, invoices or open cases;
  • newsletter data is retained until consent is withdrawn or an objection is made; a limited record of consent or unsubscribe status is retained for four further years to demonstrate compliance;
  • Revoq deletes data on its free plan after 90 days; evidence needed to document a withdrawal may be retained with the case file under the rule above;
  • under the latest verified GA4 settings, event data is retained for two months and user data for fourteen months; aggregated reports without direct identifiers may remain available for longer;
  • advertising-system and audience data is retained until consent is withdrawn, the audience is deleted or the period set by the provider expires, whichever occurs first;
  • our own technical and security logs are generally retained for 30 days, and longer only where needed to investigate a security incident or legal claim.

Afterwards, data is deleted or anonymised unless law or the protection of rights requires further retention. Backups are overwritten according to a secure retention cycle and are not used for ordinary processing.

7. Your rights

Subject to the GDPR, you may request access, rectification, erasure, restriction and portability, object to processing based on legitimate interests, and withdraw consent. You may complain to the Czech Office for Personal Data Protection, uoou.gov.cz.

We respond without undue delay, generally within one month. GDPR permits an extension in complex cases; if so, we will explain it in time. We may reasonably verify identity before disclosing data.

8. Automated decision-making

We do not make decisions based solely on automated processing that produce legal or similarly significant effects for you. Payment and ecommerce service providers may use automated security and fraud-risk mechanisms under their own terms.

9. Changes

We publish the current version and effective date on this page and provide appropriate notice of material changes. This policy is effective from 7 September 2026.

Sign up for the occasional newsletter from Utopia.