PRIVACY POLICY

Last updated: October 2, 2025

This Privacy Policy explains how we collect, use, store, and protect personal data when you visit or purchase from iconic-puzzles.com (the “Website”), or interact with our services, marketing tools, or customer support.

The Policy applies in accordance with:

  • Regulation (EU) 2016/679 (GDPR)

  • UK GDPR (Data Protection Act 2018)

  • Applicable national privacy laws

  • Meta Business Tools Terms (including Meta Pixel / Conversions API)

By using the Website or providing your data, you acknowledge that you have read and understood this Privacy Policy.


1. DATA CONTROLLER

The sole Data Controller responsible for processing personal data collected through this Website is:

ALL STAR PUZZLES LTD
16 Stirling Road, Office 2c
London, England, W3 8DJ
Primary Email: info@iconic-puzzles.com
Secondary Email (urgent/legal matters): allstarpuzzles.ltd@gmail.com

ALL STAR PUZZLES LTD determines all purposes and means of data processing related to the Website, advertising, customer management, analytics, and marketing activities.


2. ROLE OF IDON SRLS (NO DATA PROCESSING)

IDON SRLS is involved solely in the development of the physical products sold on the website.
IDON SRLS does not process or access user personal data, nor does it manage marketing, advertising, or customer data. It is not a Data Controller or Processor for the purposes of this Privacy Policy.


3. TYPES OF DATA WE COLLECT

Depending on your interaction with the Website, we may collect:

a) Account and Identification Data

  • Name and surname

  • Email address

  • Phone number (if provided)

  • Shipping/billing address

b) Order, Payment & Transaction Data

  • Products purchased

  • Order details

  • Payment status

  • Delivery information
    Payments are processed through third-party providers (e.g. Stripe, PayPal, Shopify Payments). We do not store your full payment card details.

c) Technical & Navigation Data

  • IP address

  • Device and browser information

  • Cookies and tracking identifiers

  • Log files and browsing actions

d) Marketing and Communication Data

  • Newsletter or promotional email preferences

  • Social media interactions

  • Consent to advertising cookies and Meta Pixel

e) Customer Service & Communication Data

  • Emails or messages sent to us

  • Support inquiries or claims


4. LEGAL BASES FOR PROCESSING

We process personal data under the following legal grounds:

  • Contract performance (Art. 6(1)(b) GDPR):
    Order processing, shipping, account creation, customer support.

  • Legal obligations (Art. 6(1)(c) GDPR):
    Tax, accounting, fraud prevention, and regulatory compliance.

  • Legitimate interests (Art. 6(1)(f) GDPR):
    Website security, anti-fraud monitoring, service improvement.

  • Consent (Art. 6(1)(a) GDPR & cookie laws):
    Marketing communications, advertising cookies, Meta Pixel tracking.

You may withdraw consent at any time without affecting lawfulness of prior processing.


5. PURPOSES OF PROCESSING

We use personal data for:

  • Processing and fulfilling orders

  • Managing payments and invoices

  • Shipping and logistics support

  • Responding to inquiries and customer service

  • Managing user accounts

  • Fraud prevention and website security

  • Sending newsletters and promotions (only with consent)

  • Analytics and performance tracking

  • Advertising campaigns and retargeting (e.g., via Meta Pixel)


6. COOKIES, META PIXEL & TRACKING TOOLS

We use cookies and similar technologies for functionality, analytics, and marketing.

Meta Business Tools / Meta Pixel

We may use Meta Pixel and/or Conversions API to:

  • Measure ad campaign performance

  • Create custom audiences

  • Analyze visits, purchases, and website behavior

Meta may collect or receive information (Event Data) as joint controller solely for the purposes agreed under GDPR Article 26. Data is used in aggregated form for ad delivery, measurement, and safety purposes.

Consent & Opt-Out

Where required by law (e.g., EU/UK):

A Cookie Policy or banner is displayed to manage preferences.


7. DATA SHARING WITH THIRD PARTIES

We may share data with trusted service providers strictly for the purposes stated above:

  • Payment processors (e.g. Stripe, PayPal, Shopify Payments)

  • Shipping and logistics providers

  • Customer support platforms

  • Email marketing & CRM tools

  • Technical hosting and IT providers

  • Advertising and analytics services (e.g. Meta, Google)

These third parties operate under data protection agreements and do not use personal data for unauthorized purposes.


8. INTERNATIONAL DATA TRANSFERS

If personal data is transferred outside the UK or EEA (e.g. to the US), we ensure legal safeguards such as:

  • Standard Contractual Clauses (SCCs)

  • Adequacy decisions

  • Additional security measures where required

Users can request more details by contacting us.


9. DATA RETENTION

We retain data only as long as necessary for the purposes collected:

  • Customer/account data: until account deletion or inactivity period

  • Transaction and billing data: up to 10 years (legal compliance)

  • Marketing data: until consent is withdrawn

  • Technical logs and cookies: as per Cookie Policy

After expiry, data is deleted or anonymized.


10. DATA SECURITY

We implement appropriate technical and organizational measures to protect personal data against:

  • Unauthorized access

  • Loss or alteration

  • Disclosure or destruction

  • Cyber threats

Only authorized personnel and service providers may access data where necessary.


11. USER RIGHTS (GDPR & UK GDPR)

You have the right to:

  • Access your personal data

  • Rectify inaccurate data

  • Request deletion (“right to be forgotten”)

  • Restrict or object to processing

  • Data portability (where applicable)

  • Withdraw consent at any time

  • File a complaint with a Supervisory Authority (e.g., ICO, Garante Privacy)

To exercise any rights, contact us at:
📩 info@iconic-puzzles.com
or for urgent matters: allstarpuzzles.ltd@gmail.com


12. CHILDREN'S DATA

We do not knowingly collect data from individuals under 13.
If we discover such data has been provided, we will delete it immediately.


13. CHANGES TO THIS POLICY

We may update this Privacy Policy to reflect legal, technical, or business changes. The updated version with the new date will be published on this page. Continued use of the Website implies acceptance.


14. CONTACT INFORMATION

For any questions, requests, or concerns related to this Privacy Policy or your personal data, you can contact us at:

ALL STAR PUZZLES LTD
16 Stirling Road, Office 2c
London, England, W3 8DJ
Primary Email: info@iconic-puzzles.com
Secondary Email: allstarpuzzles.ltd@gmail.com