Privacy Policy
We strive to keep all our clients data private and only collect data that we need to fulfill orders or membership obligations. We do not sell data. Ever. We only share data with fulfillment partners (Amazon and GameQuest) for physical order delivery.
Detailed and Legal Privacy Policy
Last Updated: March 28, 2026
This Privacy Policy explains how Just In Time Worlds Oy (the “Company,” “we,” “us,” or “our”) collects, uses, shares, and protects your personal information when you use our website and purchase products from our webstore. We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR).
​
1. Information We Collect
We collect only the personal information necessary to fulfill your orders and provide customer support. This includes:
-
Contact Information: Name, email address, phone number, and shipping/billing address.
-
Payment Information: Payment details (processed securely by our payment providers (Stripe and PayPal); we do not store full payment information).
-
Order Information: Products purchased, order history, and order status.
-
Technical Information: IP address (for fraud prevention and order processing).
We do not collect unnecessary personal data or sell/share your information for marketing or advertising purposes.
​
2. Legal Basis and Purpose of Processing
We process your personal data based on the following legal grounds:
-
Contract Performance: To fulfill your order, process payments, and deliver products (Article 6(1)(b) GDPR).
-
Legal Obligation: To comply with tax, accounting, and regulatory requirements (Article 6(1)(c) GDPR).
-
Legitimate Interest: To prevent fraud, improve our services, and respond to customer inquiries (Article 6(1)(f) GDPR).
​
3. How We Use Your Information
Your personal data is used only for:
-
Processing and fulfilling your orders.
-
Communicating with you about your order (e.g., confirmations, shipping updates).
-
Resolving customer service issues.
-
Complying with legal obligations (e.g., tax records).
-
Preventing fraud or abuse.
-
Sending newsletters if you signed up for receiving news. You can always withdraw consent for this.
​
4. Sharing Your Information with Third Parties
We share your personal data only with trusted third-party service providers who assist in order fulfillment and delivery:
-
Fulfillment Partners: Amazon and ShipQuest receive your name, address, and contact details solely to ship your order. These partners act as data processors and are bound by Data Processing Agreements (DPAs) to ensure GDPR compliance.
-
Payment Processors: Your payment information is processed securely by our payment provider (e.g., Stripe, PayPal). We do not store or share full payment details.
No other third parties receive your personal data unless required by law.
​
5. Data Transfers Outside the EU
If your data is transferred outside the EU/EEA (e.g., to Amazon or ShipQuest in the US), we ensure compliance using:
-
Standard Contractual Clauses (SCCs): For transfers to countries without an EU adequacy decision.
-
Adequacy Decisions: For transfers to countries recognized by the EU as providing adequate data protection (e.g., UK, Japan).
​
6. Your Rights Under GDPR
You have the following rights regarding your personal data:
-
Access: Request a copy of the personal data we hold about you.
-
Rectification: Correct inaccurate or incomplete data.
-
Erasure: Request deletion of your data (subject to legal obligations).
-
Restriction: Restrict processing of your data in certain circumstances.
-
Portability: Receive your data in a structured, machine-readable format.
-
Objection: Object to processing based on legitimate interests.
To exercise these rights, contact us at: [privacy@mariemullany.com].
We will respond to your request within one month.
​
7. Data Retention
We retain your personal data only as long as necessary:
-
Order Information: 7 years (for tax and legal compliance).
-
Customer Support Communications: 2 years after resolution.
-
Inactive Accounts: Deleted after 2 years of inactivity.
​
8. Data Security
We implement technical and organizational measures to protect your data, including:
-
Encryption of sensitive information.
-
Regular security audits.
-
Restricted access to personal data.
​
9. Cookies and Tracking
Our website uses essential cookies to enable core functionality (e.g., shopping cart, order processing). We do not use tracking or analytics cookies without your explicit consent.
​
10. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. Updates will be posted on this page with the effective date.
​
11. Contact Us
For questions or concerns about this policy or your data, contact:
Marie Mullany
Email: [privacy@mariemullany.com]
Address: Muurla, Finland
