Privacy policy

Last updated: 17 May 2026

This privacy policy describes how I, Jonas Lindholm, collect and manage your personal data when you shop from jonaslindholm.se or otherwise contact me.

Data Controller

JONAS LINDHOLM Åhusvägen 21, 1302 121 51 Johanneshov Sweden Email: contact@jonaslindholm.se

I am the data controller for the information you provide to me. I have not appointed a data protection officer as my business does not require one under GDPR.

What data do I collect?

When you shop from me I collect:

  • Name, email address, phone number
  • Delivery and billing address
  • Payment information (handled by my payment providers)
  • Order history and purchase information

When you visit my website I collect:

  • Information about how you use the website (via cookies)
  • IP address, browser type and device information

Why do I collect your data?

I use your personal data to:

  • Process and deliver your order (legal basis: performance of a contract, Article 6(1)(b) GDPR)
  • Process payments (legal basis: performance of a contract, Article 6(1)(b) GDPR)
  • Send order confirmations and delivery information (legal basis: performance of a contract, Article 6(1)(b) GDPR)
  • Accounting and invoicing (legal basis: legal obligation, Article 6(1)(c) GDPR)
  • Customer support (legal basis: legitimate interest, Article 6(1)(f) GDPR)
  • Marketing to existing customers (legal basis: legitimate interest, Article 6(1)(f) GDPR)
  • Marketing to new customers via newsletter (legal basis: consent, Article 6(1)(a) GDPR)
  • Prevent fraud and keep the website secure (legal basis: legitimate interest, Article 6(1)(f) GDPR)
  • Improve the website and customer experience (legal basis: legitimate interest, Article 6(1)(f) GDPR)

Who do I share your data with?

I share your data with the following third-party providers who help me run my business:

  • Shopify
    • e-commerce platform powering my website
  • Shopify Payments
    • card payments (Visa, Mastercard, Maestro), Apple Pay and Google Pay
  • Klarna
    • installment payments and invoice
  • QuickPay
    • Swish payments
  • DHL
    • shipping, delivery and parcel tracking
  • Propel Replay
    • web analytics and behavioural analysis (session recordings and heatmaps to improve the customer experience)
  • Easy Ban Country Blocker
    • security and access app that processes the visitor's IP address, geographic location, ISP/ASN information and referral source to block traffic from specific countries, IP addresses, VPN/proxy users and malicious bots, and to prevent fraud and protect website content. Legal basis: legitimate interest (Article 6(1)(f) GDPR).

These providers process your data in accordance with their own privacy policies and only for the purposes for which I have engaged them. I never sell your personal data to third parties.

How long do I retain your data?

  • Order data and invoices: 7 years (in accordance with the Accounting Act)
  • Marketing data (newsletter): Until you unsubscribe
  • Account details: Until you request deletion of your account
  • Cookies and web analytics: Up to 24 months

Cookies

I use cookies to make the website function and to improve your experience. Cookies also help me understand how visitors use the website.

You can change your cookie settings in your browser at any time, but some features of the website may then stop working.

Read more about Shopify's use of cookies here: https://www.shopify.com/legal/cookies

Web analytics and behavioural analysis

I use Propel Replay to understand how visitors use my website and to improve the customer experience. Propel collects:

  • Session data (how you navigate the website, what you click on, how you scroll)
  • IP address and geographic location
  • Browser, device and operating system
  • Shopping cart contents and abandoned carts
  • For logged-in customers: name, email and purchase history

This information is used to:

  • Identify technical issues and improve website usability
  • Understand which products and pages are most interesting
  • Detect and block bots and fraudulent traffic

Data is shared with Propel Commerce (USA) and protected under the European Commission's standard contractual clauses. You can decline the use of Propel via the cookie banner on the website.

Read more about Propel's privacy policy here: https://www.propelcommerce.io/session-recording-now-privacy-policy

Your rights under GDPR

You have the following rights regarding your personal data:

  • Right of access – You can request a copy of the data I hold about you
  • Right to rectification – You can request that I correct inaccurate data
  • Right to erasure – You can request that I delete your data (with certain exceptions, e.g. accounting requirements)
  • Right to data portability – You can request your data in a machine-readable format
  • Right to withdraw consent – You can unsubscribe from the newsletter at any time
  • Right to object – You can object to processing based on legitimate interest
  • Right to restrict processing – You can request that I limit how I use your data

Contact me at contact@jonaslindholm.se and I will help you. I aim to respond within a few days, but no later than 30 days as required by GDPR.

International data transfers

Some of my providers (e.g. Shopify and Propel Commerce) may process your data outside the EU/EEA. When this occurs I use the European Commission's standard contractual clauses to ensure your data is protected in accordance with GDPR.

Security

I take technical and organisational measures to protect your personal data against unauthorised access, loss or misuse. However, no security measure is 100% secure and I cannot guarantee absolute security.

Children

To shop from my website you must be at least 18 years old. I do not collect data from persons under 18. If you are a guardian and discover that your child has provided data to me, please contact me and I will delete it.

Complaints

If you have complaints about how I handle your personal data, please contact me first at contact@jonaslindholm.se.

If you are not satisfied with my response you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY): www.imy.se

Changes to this policy

I may update this privacy policy as needed. The latest version is always available at jonaslindholm.se. Major changes will be communicated by email.