PRIVACY POLICY & GDPR

Last updated: February 2026

1. General

This Privacy Statement describes how trailtales.gr collects and processes personal data when you browse, create an account, or place an order. If you do not agree with the following, you may discontinue using the site.

The policy may be updated when legislation or site operations change. It is advisable to check it occasionally.


2. What data may be collected

Depending on how you use the site, the following may be collected: contact details (name, email, phone), shipping/billing details, order details, and technical connection data (e.g., IP, device/browser type, cookies).

Minimization Principle: We collect only what is necessary for the e-shop to function correctly and for orders to be completed.

3. Orders & Customer Service

When you place an order, data is used for: order registration/execution, communication regarding its progress, product shipping, invoicing where required, and pre/post-purchase support.

Legal Basis: contract execution (order) and/or compliance with legal obligations (e.g., tax/accounting).


4. User Account

If you create an account, necessary details are stored so you can log in, view order history, and complete future purchases more quickly.


5. Communication (forms, emails, messages)

If you contact us (form, email, or message), we use your details only to reply and serve your request. They may be retained for a reasonable period to maintain a support history.


Minors: If you are under 16 years old, you need parent/guardian consent for services based on consent (e.g., marketing cookies).

6. Cookies, Statistics & Consent

The site uses cookies to function correctly (e.g., cart/checkout) and, if you choose, for statistics and/or marketing. Non-essential cookies are activated only after your choice via the banner.

To change options, use the Manage button on the banner.

For more, see the separate Cookies Policy page.


7. Who data may be shared with

To operate an e-shop, strictly necessary data may be transferred to partners/service providers, such as: hosting companies, payment providers, shipping/courier companies, and technical support. These providers receive only what is needed for their service.


8. Retention Period

Data is retained only as long as necessary for the purpose it was collected. Orders/invoicing may be retained longer where there is a legal obligation (e.g., tax). Cookie consent data is retained in your browser according to your choice.


9. Security (HTTPS/SSL)

Communication with the site is conducted via encryption (HTTPS). Additionally, security practices are applied to limit unauthorized access (e.g., access controls, software updates).


10. Your Rights (GDPR)

You have the right to access, rectification, erasure, restriction, portability, and objection to processing, where applicable. If processing is based on consent, you may withdraw it at any time.


Contact: Send a request via the Contact page of the site (or via the details listed there).

If you believe your rights are being violated, you may also address the DPA: www.dpa.gr