online store
Privacy Policy
The operator processes customer personal data, website visitor data, and data submitted through the on-site support chat only to the extent necessary for order placement, payment, delivery, after-sales support, handling customer enquiries, site operation, security, and compliance with Russian law. Analytics is enabled only after the user gives consent.
1. What data is processed
Full name, phone number, shipping address, email address, order contents, selected payment method and delivery method, order comments, and data needed to prepare the receipt and confirm the order.
When the on-site support chat is used, the operator also processes the visitor name, phone and/or email, message text, chat conversation identifier, chat visitor token, current page URL, referrer, and technical data needed to deliver messages and protect the chat from abuse.
Technical anti-spam data, internal audit logs, IP hash, and user agent needed to protect the checkout form from abuse and confirm the fact of order placement.
Traffic attribution, UTM/gclid/fbclid identifiers, and site visit information are processed only after analytics consent.
2. Purposes of processing
Order placement and fulfilment, communication with the customer, payment and delivery coordination, returns handling, and customer support.
Handling enquiries and correspondence through the on-site support chat, preserving the dialogue context, and allowing the manager to reply to the visitor.
Receipt and service notifications, site operation, abuse prevention, and bookkeeping within the scope required by law.
Visit analytics and site improvement only after user consent.
3. Legal basis and third parties
The legal bases for processing are the performance of a contract with the customer, steps taken before entering into a contract, fulfilment of legal obligations, and separate consent for cookie and analytics.
Data is shared only as necessary with YooKassa for payments, CDEK for delivery, the operator’s email infrastructure, and Beget hosting. Yandex.Metrika is enabled only after consent.
The on-site support chat uses the operator’s own self-hosted module on Russian infrastructure. Messages, contact details, and chat history are stored in a dedicated local PostgreSQL database controlled by the operator.
External messengers are not used as the primary customer channel and do not receive order data or support-chat conversations.
4. Storage and retention
Primary processing and storage are performed on a server and database hosted in Russia on the Beget platform in Saint Petersburg.
Order data and customer data used for contract fulfilment and accounting are retained for 5 years after the end of the reporting period, anti-spam data and technical logs for 30 days, notification outbox entries for 90 days after sending or final failure, and the consent cookie for 180 days.
Support-chat contacts and conversation history are retained for the period needed to handle the request, and if the conversation is tied to an order, return, or claim, they may be retained together with the relevant order materials.
Analytics attribution in the browser is retained for 30 days, the chat visitor token stays in browser local storage until the user clears it, and the checkout draft is kept only for the current browser session.
5. Customer rights
The customer may request clarification, restriction, blocking, deletion of personal data, or withdrawal of consent, if supported by law, by writing to the seller.
Requests concerning personal data can be sent to info@dh22.ru.
Data that must be kept for bookkeeping, tax, or other mandatory recordkeeping purposes is deleted only after the applicable legal retention period ends.
6. How to withdraw consent or request deletion
To request deletion, clarification, or restriction of processing, send an email to the seller. Include the order number or chat conversation reference if available, or describe the situation if there is no number.
Analytics consent can be withdrawn through the cookie settings on the website or by clearing the corresponding browser storage; after withdrawal, analytics is not loaded again until a new choice is made.