Privacy policy
Last updated: 31 July 2026
This policy explains what personal data we collect when you visit casualremarks.co or buy from us, why we collect it, who receives it, how long we keep it, and what you can require us to do about it. It is written to be read, not to be survived.
1. Who is responsible for your data
The data controller is:
Edward Schaefer, sole trader Bergen, Norway support@casualremarks.co
Casual Remarks is a trading name of Edward Schaefer, sole trader. We are established in Norway. Because our establishment is in the European Economic Area, the EU and EEA General Data Protection Regulation (GDPR) applies to the processing described here, together with the Norwegian Personal Data Act and the Norwegian Electronic Communications Act. This applies to all customers, including customers in the United States, and it means US customers get GDPR level rights even though they are not resident in the EEA.
We have not appointed a Data Protection Officer, because we are not required to. Privacy questions go to support@casualremarks.co and are handled by the controller directly.
2. What this policy covers
Everything we do at casualremarks.co: browsing, checkout, order fulfilment, customer support, email marketing, and advertising measurement. It does not cover third party websites you reach through a link from ours, or the platforms where our ads appear, which have their own policies.
3. What we collect
Information you give us
- Identity and contact data: name, email address, phone number where you provide one.
- Delivery data: shipping address, and billing address where different.
- Order data: items ordered, size, price paid, currency, order number, order status, discount codes used.
- Correspondence: the content of emails you send us, including photos you attach to a claim.
- Marketing preferences: whether you opted in to our email list, and whether you later opted out.
Information collected automatically
- Device and technical data: IP address, browser type and version, user agent, operating system, device type, screen size, language and time zone setting.
- Usage data: pages viewed, products viewed, time on page, referring URL, search terms used on our site, items added to cart, checkouts started and completed.
- Cookies and similar technologies, including advertising identifiers and click identifiers passed in a link, such as the Meta click ID (fbclid).
Information we receive from others
- Payment confirmation and fraud risk signals from our payment providers. We never receive your full card number.
- Fulfilment and delivery status from our print partner and the shipping carrier.
- Aggregated advertising performance from Meta.
What we do not collect
We do not collect special category data (health, religion, political opinion, biometrics, and so on), and we ask you not to send it to us. We do not knowingly collect data from children. We do not store card numbers.
4. Why we use it, and our lawful basis
Taking, processing and fulfilling your order, printing it, shipping it and communicating about it. Data used: identity, contact, delivery and order data. Lawful basis: performance of a contract, Article 6(1)(b).
Taking payment and preventing fraud and chargeback abuse. Data used: order data, payment confirmation, device and IP data. Lawful basis: performance of a contract, Article 6(1)(b), and our legitimate interest in preventing fraud, Article 6(1)(f).
Providing customer support and handling claims, reprints and refunds. Data used: contact, order and correspondence data. Lawful basis: performance of a contract, Article 6(1)(b).
Keeping accounting and tax records. Data used: order and payment records. Lawful basis: legal obligation, Article 6(1)(c).
Running and securing the website, preventing abuse and fixing errors. Data used: technical and usage data. Lawful basis: our legitimate interest in operating a secure and functional site, Article 6(1)(f).
Sending marketing emails. Data used: email address and order history. Lawful basis: consent, Article 6(1)(a), withdrawable at any time.
Setting non essential cookies and using advertising and analytics technologies, including the Meta Pixel and the Meta Conversions API. Data used: technical, usage, identity and order data as described in section 6. Lawful basis: consent, Article 6(1)(a).
Measuring advertising performance and building audiences for future advertising. Data used: as described in section 6. Lawful basis: consent, Article 6(1)(a).
Establishing, exercising or defending legal claims. Data used: any of the above, as relevant. Lawful basis: our legitimate interest in defending our position, Article 6(1)(f), or legal obligation, Article 6(1)(c).
Where we rely on consent, you can withdraw it at any time and it costs you nothing. Withdrawal does not affect processing that already happened while consent was in place.
Where we rely on legitimate interests, we have weighed those interests against your rights, and you have a right to object. See section 11.
We do not carry out automated decision making or profiling that produces legal effects for you or similarly significantly affects you. Advertising audience segmentation is not that kind of decision.
5. Cookies and similar technologies
We use cookies and similar storage technologies for three purposes.
Strictly necessary. Making the site work: the shopping cart, checkout, session security, load balancing, fraud prevention, and remembering your cookie choice. These are set without consent because the site cannot function without them, in line with the exemption in the Norwegian Electronic Communications Act.
Analytics and performance. Understanding which pages and products people look at, in aggregate.
Advertising. The Meta Pixel and related identifiers, described in detail in section 6.
Analytics and advertising cookies are only set after you consent through our cookie banner. The banner appears on your first visit and lets you accept all, reject all non essential cookies, or choose by category. Rejecting non essential cookies leaves the store fully usable. You can reopen the banner and change or withdraw your choice at any time through the cookie preferences link in the site footer.
You can also block or delete cookies in your browser settings. Blocking strictly necessary cookies will break checkout.
6. Meta Pixel and Meta Conversions API
This section describes our advertising measurement in full, because it is the processing most people care about and the one most stores describe least clearly.
What we run. We operate the Meta Pixel in your browser and the Meta Conversions API from our server. Both send data to Meta under a single dataset, ID 2241179283368185. We use them to measure whether our advertising works, to attribute orders to the ads that produced them, and to build audiences for future advertising.
Who receives the data. Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, is the recipient. Meta Platforms Ireland Limited may transfer the data to Meta Platforms, Inc. in the United States under its own arrangements. For the collection of this data and its transmission to Meta, we and Meta Platforms Ireland Limited act as joint controllers under Article 26 GDPR, on the terms of Meta's Controller Addendum. Meta's own subsequent processing of the data is carried out by Meta as an independent controller under its own Data Policy, at https://www.facebook.com/policy.php, and we have no control over it.
Which events are sent. The following event types, and no others:
- PageView. You loaded a page on casualremarks.co.
- ViewContent. You looked at a product page, including which product and its price.
- AddToCart. You added an item to the cart, including which item and its price.
- InitiateCheckout. You began checkout, including cart contents and value.
- Purchase. You completed an order, including order value, currency, and the items bought.
What is transmitted with those events. Events fire in two ways at once, browser side through the Pixel and server side through the Conversions API, and the two are matched and deduplicated by Meta using a shared event ID. The server side transmission through the Conversions API includes, where available:
- Your email address, hashed. It is hashed with SHA-256 before it leaves our systems, so Meta does not receive it in readable form.
- Your phone number, hashed, where you gave one, using the same method.
- Your IP address, transmitted with the event so that Meta can match and attribute it.
- Your browser user agent, the Meta browser ID and click ID cookies (_fbp and _fbc) where present, and the page URL, event ID and event timestamp.
- Order value, currency, product identifiers and quantity for commercial events.
- Where you provided them at checkout, hashed versions of your first name, last name, city, state, postal code and country, used only for match quality.
We do not send Meta the content of your messages to us, your full payment details, or any special category data. We do not sell this data.
Lawful basis: consent. All Meta Pixel and Conversions API processing described here is carried out on the basis of your consent under Article 6(1)(a) GDPR, and consent for the storage of and access to information on your device under the Norwegian Electronic Communications Act.
How consent is collected. Through the cookie banner shown on your first visit. Nothing in this section runs before you give consent. If you reject non essential cookies, the Pixel does not load and no Conversions API event is sent for you, browser side or server side. The store works normally either way.
How to withdraw consent, and the opt out route. Any of these works, and none of them requires an explanation:
- Open the cookie preferences link in the footer of any page on casualremarks.co and switch advertising off, or reject all non essential cookies. This takes effect immediately and stops both the Pixel and the Conversions API for you going forward.
- Email support@casualremarks.co with the subject line OPT OUT and the email address you used with us. We will suppress future advertising events tied to you and, on request, ask Meta to delete data associated with you.
- Adjust your own Meta settings at https://www.facebook.com/adpreferences and https://accountscenter.meta.com, where you can review and disconnect off Meta activity through the "Your activity off Meta technologies" tool.
- Block advertising cookies in your browser, or use a tracking protection feature or extension.
Withdrawal stops future processing. It does not undo processing that lawfully took place beforehand. To have data already sent deleted, use route 2 and we will action it and pass the request on.
Retention. We do not hold a separate copy of Pixel or Conversions API event data ourselves beyond what is described elsewhere in this policy. Meta stores and retains event data under its own retention rules, which we do not control.
7. Who else receives your data
We share personal data only with the parties below, only for the purposes stated, and never in exchange for money.
- Shopify. Our ecommerce platform and hosting provider, acting as our processor under a data processing agreement. Shopify processes order, contact, payment and browsing data on our instructions to run the store and checkout. Shopify International Limited (Ireland) and Shopify Inc. (Canada) are the relevant entities. Their privacy policy is at https://www.shopify.com/legal/privacy.
- Payment processors. Payments are handled by Shopify Payments and, where offered at checkout, PayPal and Shop Pay. They act as independent controllers for payment and fraud prevention, under their own privacy policies. They receive the payment and billing data needed to take the payment. We receive only confirmation and limited fraud signals, never your full card number.
- Printify and its print provider. Printify Inc. and the print facility fulfilling your order receive your name, delivery address, contact email and the item details needed to print and ship your order, and nothing else. They act as our processors for that purpose.
- Shipping carriers. The carrier receives your name, delivery address and, where needed, your email or phone number for delivery notifications.
- Meta Platforms Ireland Limited. As described in section 6, on the basis of consent.
- Email service provider. The system that sends order confirmations, shipping notifications and, if you opted in, marketing emails, receives your email address and order details as our processor.
- Professional advisers and authorities. Accountants, auditors and legal advisers under confidentiality, and public authorities or courts where we are legally required to disclose.
- A buyer or successor, if the business or its assets are ever sold or reorganised. You would be told before your data became subject to a different privacy policy.
We do not sell personal data, and we do not share it with data brokers.
8. International transfers
We are in Norway, our customers are in the United States, and several of our providers are outside the EEA. Personal data is therefore transferred out of the EEA, principally to the United States and Canada.
Those transfers are protected by one or more of the following: the European Commission's Standard Contractual Clauses together with supplementary technical and organisational measures; an adequacy decision, including the EU and Canada adequacy decision and the EU and US Data Privacy Framework where the recipient is certified; or, for the delivery of an order you placed to an address you gave us, the transfer being necessary for the performance of your contract under Article 49(1)(b) GDPR.
You can request a copy of the relevant safeguards by emailing support@casualremarks.co.
9. How long we keep it
- Order and transaction records: retained for five years after the end of the accounting year in which the order was placed, to meet Norwegian bookkeeping and tax obligations. This retention is a legal obligation and cannot be shortened by a deletion request.
- Customer support correspondence: three years from the last message in the thread.
- Marketing subscriber data: until you unsubscribe, and then a minimal suppression record kept indefinitely so that we do not email you again by mistake.
- Cookie consent records: up to two years, as evidence that consent was given or refused.
- Website analytics and technical logs: up to 14 months, then deleted or aggregated so that individuals can no longer be identified.
- Advertising event data held by Meta: governed by Meta's retention rules, not ours.
When a retention period ends, data is deleted or irreversibly anonymised.
10. Security
Your connection to our store is encrypted with TLS. Checkout and payment run on Shopify's PCI DSS compliant infrastructure. Access to customer data is limited to the people who need it, protected by strong authentication. Identifiers sent to Meta through the Conversions API are hashed before transmission.
No system is perfectly secure, and we will not claim otherwise. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Norwegian Data Protection Authority within 72 hours as required by Article 33 GDPR, and we will notify you directly where Article 34 requires it.
11. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you, and receive a copy.
- Rectification of data that is inaccurate or incomplete.
- Erasure of your data, where there is no overriding legal reason for us to keep it. Bookkeeping records are the usual exception.
- Restriction of processing while a dispute about accuracy or lawfulness is resolved.
- Data portability, receiving the data you gave us in a structured, commonly used, machine readable format, or having it sent to another controller where technically feasible.
- Object to processing based on legitimate interests, on grounds relating to your particular situation, and to object at any time and without reason to processing for direct marketing.
- Withdraw consent at any time, where processing is based on consent, including advertising and email marketing. See section 6 for the advertising route.
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not make such decisions.
How to exercise them. Email support@casualremarks.co from the address you used with us, and say which right you are exercising. We reply within one month, as required by Article 12(3) GDPR, and usually much faster. If a request is complex we may extend by up to two further months and will tell you why within the first month. There is no charge, unless a request is manifestly unfounded or excessive.
We may need to confirm your identity before acting, so that we do not disclose your data to somebody else.
Complaints. If you think we have handled your data unlawfully, please tell us first. You also have the right to complain to a supervisory authority. Ours is:
Datatilsynet (Norwegian Data Protection Authority) Postboks 458 Sentrum, 0105 Oslo, Norway https://www.datatilsynet.no
12. Rights of United States residents
Depending on your state of residence, you may also have rights under state privacy laws, including in California, Colorado, Connecticut, Virginia, Texas and other states with comparable statutes: to know what personal information is collected and disclosed, to access it, to correct it, to delete it, to opt out of targeted advertising and of any sale or sharing of personal information, and not to be discriminated against for exercising those rights.
We do not sell personal information for money. Our use of the Meta Pixel and Conversions API described in section 6 may qualify as "sharing" for cross context behavioural advertising, or as "targeted advertising", under some of those laws. You can opt out through the cookie preferences link in our footer, by rejecting non essential cookies, by sending a Global Privacy Control signal from your browser, which we honour as an opt out, or by emailing support@casualremarks.co.
To exercise any state privacy right, email support@casualremarks.co. You may use an authorised agent, and we will ask for proof of authorisation. We do not charge for this and we do not offer a worse price or service to people who use these rights.
13. Children
Our store is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, email support@casualremarks.co and we will delete it.
14. Changes to this policy
We update this policy when our processing changes. The "last updated" date at the top always reflects the current version. If a change materially affects how we use your data, and in particular if it changes anything in section 6, we will make it clear on the site and, where the change requires it, ask for your consent again.
15. Contact
Casual Remarks Edward Schaefer, sole trader Bergen, Norway support@casualremarks.co
Privacy emails get the same reply time as everything else. One business day.