Privacy policy
PRIVACY AND PERSONAL DATA PROTECTION POLICY
Last updated: September 1, 2026
This policy clearly explains how the Greenleaf online store collects, uses, discloses and protects personal data when you visit green-leaf.gr, make a purchase, use a customer account, submit a return request or contact us.
Processing is carried out in accordance with the EU General Data Protection Regulation 2016/679 (“GDPR”), Greek Laws 4624/2019 and 3471/2006, and other applicable legislation.
1. Data controller
Petropoulos S. Dimitrios (Πετρόπουλος Σ. Δημήτριος), trading as “GreenLeaf”
Greek Tax Identification No.: 055131943 · Kalamata Tax Office
Iroon Polytechniou (Nea Eisodos), 24100 Kalamata, Greece
Telephone: +30 27210 97671
Privacy and data-rights email: info@green-leaf.gr
2. Data we collect and its sources
Depending on how you use our services, we may process:
- Identity and contact data: name, email, telephone number, billing address and delivery address.
- Order and transaction data: products, amounts, discounts, payment method and status, documents, delivery, tracking, returns, cancellations and order-related communications.
- Invoice data: business name, profession, tax number, tax office and other details, only when an invoice is requested.
- Customer account data: email, profile, preferences and order history. Sign-in is passwordless, using a one-time code sent by email or another sign-in method you may choose if offered.
- Payment data: full card numbers and security details are submitted directly to the payment provider. Greenleaf receives only the transaction and confirmation details required for the order, to the extent supplied by the provider.
- Communications and content: email or chat messages, support requests, photographs you send for product assessment, reviews and form responses.
- Marketing preferences: newsletter subscription or unsubscription, the time and method of consent and basic email performance data.
- Technical and usage data: IP address, device, browser, cookie identifiers, approximate country or region, language/market selection, pages and products viewed, searches, cart and website interactions.
Data is obtained directly from you, collected automatically when you use the website, or provided by services involved in a transaction, such as Shopify, payment providers and carriers.
You can purchase as a guest. In this case, Shopify creates or updates a customer profile using the order email so that the transaction can be fulfilled and the orders can later be accessed using the same email.
Information marked as required at checkout is necessary to perform the order or meet a legal obligation. If it is not provided, we might be unable to complete the purchase, payment or delivery. Newsletter subscription and acceptance of non-essential cookies are optional.
3. Purposes and legal bases
We use personal data only where an appropriate legal basis applies:
- Contract or pre-contractual steps — Article 6(1)(b) GDPR: checkout, payment, order confirmation, order fulfilment and delivery, customer accounts, order updates, customer service, returns, cancellations and refunds.
- Legal obligation — Article 6(1)(c) GDPR: tax and accounting records, issuing documents, compliance with consumer and product-safety law, and responding to lawful requests from authorities.
- Legitimate interests — Article 6(1)(f) GDPR: system and transaction security, fraud and misuse prevention, technical operation and service improvement, customer support, management of business and legal claims, and basic performance measurement that does not require consent. Before relying on a legitimate interest, we balance it against your rights and reasonable expectations.
- Consent — Article 6(1)(a) GDPR: newsletter delivery where required, non-essential cookies and similar technologies, personalised advertising and related measurement. You can withdraw consent at any time without affecting the lawfulness of earlier processing.
4. Customer accounts and sign-in
Customer accounts are provided through Shopify Customer Accounts. You enter your email and receive a six-digit one-time code. Greenleaf does not create or store a customer password for this sign-in method.
If you later choose an optional external sign-in provider displayed on the sign-in page, the provider may send Shopify the minimum data required for authentication, such as your email and a technical identifier. Use of that option is voluntary and is also subject to the relevant provider’s privacy policy.
5. Newsletter, cookies, analytics and personalisation
We send promotional email only where we have valid consent or another permitted legal basis. You can unsubscribe using the link in every marketing email or by contacting us. Unsubscribing does not affect operational messages about orders, accounts, returns or security.
Under our current settings, we do not use SMS or postal mail for promotional marketing. If this changes, this policy and the relevant consent choices will be updated before processing begins.
We use essential cookies for the store, cart, checkout, security, language and market functions. Analytics, functionality or advertising cookies are used, where required, only after consent through the cookie banner. You can change your choices using the store’s cookie-preferences control when available.
Browsing data may be used for search, product recommendations, performance measurement and personalised advertising with the required consent. We do not make decisions based solely on automated processing that produce legal effects or similarly significantly affect you.
6. Recipients of personal data
We disclose only the data necessary for each service to the following categories of recipients:
- Shopify and technical providers of hosting, checkout, customer accounts, cloud services, security and store support.
- Payment providers, banks and fraud-prevention services, depending on the payment method you choose.
- Courier companies, carriers, packing or pickup partners, and tracking services.
- Providers of email, chat and customer service, reviews, search, geographical adaptation, translation and other online-store functions.
- Analytics, measurement and advertising providers, only in accordance with your consent choices and applicable law.
- Accountants, tax advisers, legal advisers, invoicing providers and other professional advisers subject to confidentiality obligations.
- Courts, tax, police or other public authorities where disclosure is lawfully required, and parties involved in a potential business reorganisation, subject to appropriate safeguards.
Processors act under contract and our instructions. Where a provider acts as an independent controller, as may be the case for certain payment providers or platforms, its own privacy policy also applies.
7. Shopify and Shopify Network Intelligence
The store is hosted and operated using Shopify. Shopify processes data to provide the platform and may act as an independent controller for certain services. When Shopify Network Intelligence is enabled, Shopify may combine interaction data with data from other merchants to provide enhanced services such as security, measurement, service improvement and —where permitted and subject to the required consent— personalisation or advertising.
We do not sell personal data for monetary consideration. Certain advertising disclosures might be characterised as “sharing”, “targeted advertising” or a similar concept under other privacy laws. In the EEA, the use of data for personalised advertising is based on consent where required.
More information is available in the Shopify Consumer Privacy Policy and the Shopify Privacy Portal.
8. Transfers outside the EEA
Some providers may process data outside the European Economic Area. Where no adequacy decision applies, we rely on the European Commission’s Standard Contractual Clauses or another lawful transfer mechanism and, where necessary, supplementary measures. You may request further information or a copy of the applicable safeguards, to the extent permitted, at info@green-leaf.gr.
9. Retention
We retain personal data only for as long as required for the relevant purpose:
- Order, payment and invoice records for the period required by tax, accounting and consumer law and for the establishment or exercise of legal claims.
- Profile data for as long as needed to provide the account and transaction history, subject to legal retention duties.
- Support, return and complaint records until the request is completed and for a reasonable period connected with warranties, disputes or legal claims.
- Newsletter data until consent is withdrawn or you unsubscribe, retaining only the minimum record required to prove and respect your choice.
- Cookies and technical data according to the duration shown by the cookie tool, security settings and the needs of each service.
After the relevant period expires, data is securely erased or anonymised unless further retention is required by law.
10. Security
We apply appropriate technical and organisational measures, including access controls, limited permissions, secure connections, system updates and providers with security safeguards. No system can guarantee absolute security. If a personal-data breach is identified, we follow the assessment, notification and communication duties required by applicable law.
11. Your rights
Subject to the conditions of the GDPR, you have the right to:
- access your data and receive a copy,
- rectify inaccurate or complete incomplete data,
- erase data where there is no lawful reason for further retention,
- restrict processing,
- data portability where applicable,
- object to processing based on legitimate interests and at any time to direct marketing,
- withdraw consent at any time, and
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, where applicable.
To exercise a right, email info@green-leaf.gr. We may request only the additional information necessary to verify your identity securely. We respond without undue delay and normally within one month in accordance with the GDPR. No fee applies unless a request is manifestly unfounded or excessive as provided by law.
You also have the right to lodge a complaint with the Hellenic Data Protection Authority or the supervisory authority of the EEA country where you live or work.
12. Children and third-party links
Our services are not specifically directed at children, and we do not seek to knowingly collect data from children who lack the legal capacity to enter into the relevant transaction. If you believe that a child has provided data without the required authorisation, please contact us.
The website may contain third-party links or integrations. Greenleaf does not control their independent privacy practices; please review their policies before using those services.
13. Changes and contact
We may update this policy when our services, providers or the law change. The latest version is published on this page with an updated date. Additional notice will be provided for material changes where required.
Privacy questions or rights requests