Privacy Policy
How Filterion collects, uses and protects your personal data, and the rights you have over it under the GDPR.
Last updated: 28 July 2026
Who is responsible for your data
Filterion AB (trading as Filterion), organisation number 559568-9984, Mjödvägen 6, 746 50 Bålsta, Sweden, is the data controller for the personal data described here. You can reach us at hello@filterion.se for anything in this policy, including to exercise any of your rights.
What we collect, and why
We collect only what we need to sell you a product and meet our legal obligations. We do not buy personal data from third parties, and we do not build advertising profiles.
| Data | Why we have it | Legal basis |
|---|---|---|
| Name, e-mail address, delivery and billing address, phone number if you give one | To take payment, deliver your order and handle returns or complaints | Performance of a contract (GDPR art. 6(1)(b)) |
| Order history — what you bought, when, the amount and currency | Customer service, warranty and returns handling, and our statutory bookkeeping | Contract, and legal obligation (art. 6(1)(b) and 6(1)(c)) |
| Payment confirmation and the last digits and type of card | To reconcile payments and process refunds. We never receive or store your full card number. | Contract, and legal obligation (art. 6(1)(b) and 6(1)(c)) |
| Whether you have opted in to marketing e-mail | So we only e-mail you if you asked us to, and can prove that you did | Consent (art. 6(1)(a)), which you may withdraw at any time |
| Technical records of failed order events, which may contain the order details above | To detect and repair problems in our order processing, so that an order is never silently lost | Legitimate interests (art. 6(1)(f)) — a reliable, auditable order pipeline |
Our own systems keep a copy of your order and customer record so that we can serve you without depending on a single provider. That copy holds your name, e-mail address, order totals, order dates and marketing preference, together with the underlying order events we receive from our store platform.
Cookies
We use two cookies, both strictly necessary to operate the shop, and no others:
cartId— identifies your shopping basket so its contents survive page loads. Not readable by scripts. Expires after 30 days.cartCount— holds only the number of items in your basket, so the basket icon can display it without an extra request. Expires after 30 days.
We run no analytics, advertising, tracking or profiling scripts of any kind on this website. There is no Google Analytics, no advertising pixel and no third-party tracker. Because both cookies are strictly necessary to provide a service you have asked for, we do not need to ask your consent for them, and we therefore do not show a cookie banner.
Completing a purchase takes you to a checkout hosted by Shopify, which sets its own cookies necessary for payment and fraud prevention. Shopify’s own privacy notice governs that step.
Who else processes your data
We share personal data only with providers that help us run the shop, and only as far as they need it. They act on our instructions and may not use your data for their own purposes, except where they act as independent controllers for payment and fraud prevention.
| Provider | What they do | Where |
|---|---|---|
| Shopify | Store platform, checkout, order and customer records | Canada / EU / United States |
| Shopify Payments | Card payment processing. We never see or store your full card details. | EU / United States |
| Turso | Database holding our copy of order and customer records | EU (Ireland) |
| Hetzner | Application hosting | EU (Finland) |
| Cloudflare | Authoritative DNS only. Our sites are not proxied, so ordinary visitor traffic does not pass through Cloudflare. | Global |
| MXroute | E-mail delivery for correspondence sent to and from our addresses | United States |
We also share the delivery address and contact details with the carrier handling your parcel, and we disclose data to authorities where the law requires it. We never sell your personal data.
Transfers outside the EU/EEA
Our application servers and our order database are located inside the EU. Some of the providers above are established outside the EU/EEA, or may support us from outside it. Where personal data is transferred outside the EU/EEA, we rely on the European Commission’s Standard Contractual Clauses or an adequacy decision, together with additional safeguards where they are needed. You can ask us for details of the safeguards that apply to a particular transfer.
How long we keep it
- Accounting records — including invoices and the order data that supports them: seven years after the end of the financial year, as required by the Swedish Bookkeeping Act.
- Customer and order records outside that obligation: kept while we have an ongoing relationship with you and for a reasonable period afterwards for warranty and complaint handling.
- Marketing consent and e-mail address: until you withdraw consent or ask us to remove you.
- Technical error records: kept only as long as needed to diagnose and repair the problem.
Your rights
Under the GDPR you may ask us to:
- give you a copy of the personal data we hold about you (art. 15);
- correct anything inaccurate or incomplete (art. 16);
- erase your data where we no longer have grounds to keep it (art. 17);
- restrict how we use it while a question about it is resolved (art. 18);
- provide it in a portable, machine-readable form, or send it to another provider (art. 20);
- stop processing based on our legitimate interests, by objecting to it (art. 21).
Where we rely on your consent, you may withdraw it at any time — this does not affect processing carried out before you withdrew it. Every marketing e-mail also contains an unsubscribe link.
Write to hello@filterion.se and we will respond within one month. There is no charge. Note that we cannot erase data we are legally required to retain, such as completed accounting records — in that case we will restrict its use instead and tell you why.
Complaints
If you believe we have handled your personal data unlawfully, please tell us first so we can put it right. You also have the right to complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), Box 8114, 104 20 Stockholm, imy.se, or to the supervisory authority in the EU country where you live.
Changes to this policy
We may update this policy as our services change. The date at the top always reflects the current version, and we will give notice of significant changes before they take effect.