Privacy Policy

Privacy Policy

Last updated: 2026-07-03

This Privacy Policy explains how [LABEL NAME] (“we”, “us” or “our”) collects, uses, stores and shares personal information when you visit or make a purchase from [WEBSITE URL] (the “Store”).

We operate a record label and online store selling vinyl records, CDs, cassettes, merchandise and related products.

Nothing in this policy limits your legal rights under applicable privacy and data protection laws, including the EU General Data Protection Regulation, UK GDPR and other applicable consumer privacy laws.

1. Who we are

The data controller responsible for your personal information is:

Bonebag Records
Tjärhovsgatan 18
904 20 Umeå
Sweden
info@bonebagrecords.com
+46703696663

If you have any questions about this Privacy Policy or your personal information, contact us at info@bonebagrecords.com.

2. Personal information we collect

We may collect the following types of personal information.

Information you provide to us

When you place an order, contact us, create an account, subscribe to our mailing list or otherwise interact with the Store, we may collect:

  • Name

  • Email address

  • Billing address

  • Shipping address

  • Phone number

  • Order details

  • Payment-related information

  • Customer account details

  • Messages, support requests and correspondence

  • Marketing preferences

  • Any other information you choose to provide

We do not directly store full payment card details. Payments are processed by Shopify Payments and/or third-party payment providers.

Information collected automatically

When you visit the Store, certain information may be collected automatically, including:

  • IP address

  • Browser type and version

  • Device information

  • Time zone

  • Pages viewed

  • Products viewed

  • Referring website or search terms

  • Interactions with the Store

  • Cookies and similar tracking technologies

Information from third parties

We may receive information from third-party services we use to operate the Store, such as:

  • Shopify

  • Payment processors

  • Shipping and fulfilment providers

  • Email marketing platforms

  • Analytics providers

  • Advertising platforms

  • Customer support, review or loyalty apps

3. How we use your personal information

We use personal information for the following purposes:

  • To process, fulfil and ship orders

  • To take payment and prevent fraud

  • To provide order confirmations, shipping updates and customer support

  • To manage returns, refunds, exchanges and complaints

  • To create and manage customer accounts

  • To communicate with you about your order or enquiry

  • To send marketing emails or messages, where you have consented or where otherwise permitted by law

  • To improve our Store, products, releases and customer experience

  • To understand website traffic and customer behaviour

  • To run advertising and measure the performance of campaigns

  • To comply with tax, accounting, legal and regulatory obligations

  • To protect our rights, customers, Store and business

4. Legal bases for processing

Where GDPR, UK GDPR or similar laws apply, we rely on the following legal bases:

  • Contract: to process and fulfil your orders, manage payments, arrange shipping and handle returns or customer service.

  • Consent: to send marketing communications, use certain cookies or process optional information where consent is required.

  • Legal obligation: to keep records required for tax, accounting, consumer protection or legal compliance.

  • Legitimate interests: to operate and improve our business, prevent fraud, secure the Store, respond to enquiries and understand customer behaviour, provided those interests are not overridden by your rights.

  • Vital or public interest: only where legally necessary and applicable.

5. Shopify

Our Store is hosted on Shopify. Shopify provides the e-commerce platform that allows us to sell our products to you.

Shopify processes personal information on our behalf so that we can operate the Store, process orders, manage payments, prevent fraud and provide customer services. Shopify may also process certain personal information as an independent controller in accordance with its own privacy practices.

You can read more about Shopify’s privacy practices in Shopify’s own privacy documentation.

6. Payments

Payments are processed securely by Shopify Payments and/or other payment providers available at checkout, such as [PAYPAL / KLARNA / APPLE PAY / GOOGLE PAY / OTHER PROVIDERS].

We receive limited payment-related information, such as payment status, transaction reference, billing details and fraud analysis information. We do not directly store full card numbers or card security codes.

Payment providers process your information in accordance with their own privacy policies and security standards.

7. Shipping and fulfilment

We share necessary order and delivery information with shipping carriers, postal services, fulfilment partners and customs authorities where required.

This may include your name, delivery address, email address, phone number, order contents, package weight, value and customs information.

For international orders, your personal information may be included on customs forms or shared with authorities, carriers and brokers as required for import/export processing.

8. Marketing communications

If you sign up to our mailing list or otherwise agree to receive marketing, we may send you emails about new releases, pre-orders, restocks, merch drops, events, discounts and label news.

You can unsubscribe at any time by clicking the unsubscribe link in our emails or contacting us at info@bonebagrecords.com.

We will not sell your personal information to third parties.

9. Cookies and tracking technologies

We use cookies and similar technologies to operate the Store, remember your preferences, improve performance, analyse traffic and support marketing.

Cookies may be used for:

  • Essential store functions, such as cart, checkout and security

  • Analytics and performance measurement

  • Advertising and retargeting

  • Remembering preferences

  • Fraud prevention

Where required by law, we will ask for your consent before using non-essential cookies.

You can manage cookies through your browser settings and, where available, through our cookie banner or privacy settings.

Disabling some cookies may affect how the Store works.

10. Analytics and advertising

We may use analytics and advertising tools such as:

  • Shopify analytics

  • Google Analytics

  • Meta/Facebook Pixel

  • TikTok Pixel

  • Google Ads

  • Klaviyo, Mailchimp or other email marketing tools

  • Other Shopify apps and marketing services

These tools may collect information about how you use the Store and may use cookies or similar technologies. They help us understand store performance, measure advertising and show relevant content or ads.

Please remove or edit this section if you do not use these services.

11. Sharing your personal information

We may share personal information with trusted third parties where necessary to operate the Store and provide our services, including:

  • Shopify

  • Payment processors

  • Shipping carriers and fulfilment providers

  • Email marketing providers

  • Analytics providers

  • Advertising platforms

  • IT, hosting and security providers

  • Customer support, reviews, loyalty or returns apps

  • Accountants, lawyers, insurers and professional advisers

  • Tax, customs, regulatory or law enforcement authorities where required

We require service providers to process personal information only as necessary to provide their services and in accordance with applicable law.

12. International transfers

We sell internationally and use service providers that may process personal information in countries outside your own, including outside the EU/EEA, UK or Switzerland.

Where required, we rely on appropriate safeguards for international transfers, such as adequacy decisions, standard contractual clauses or other lawful transfer mechanisms.

13. How long we keep personal information

We keep personal information only for as long as necessary for the purposes described in this policy, including to fulfil orders, provide customer support, comply with tax and accounting obligations, resolve disputes and enforce agreements.

Typical retention periods may include:

  • Order and transaction records: retained for the period required by tax, accounting and consumer laws.

  • Customer service messages: retained for as long as needed to handle enquiries and maintain business records.

  • Marketing data: retained until you unsubscribe or request deletion, unless we need to keep limited information to respect your opt-out.

  • Website analytics: retained according to the settings of the analytics tools we use.

14. Your rights

Depending on where you live, you may have rights over your personal information, including the right to:

  • Access the personal information we hold about you

  • Correct inaccurate or incomplete information

  • Request deletion of your personal information

  • Object to certain processing

  • Restrict certain processing

  • Withdraw consent where processing is based on consent

  • Request portability of your information

  • Opt out of marketing communications

  • Lodge a complaint with your local data protection authority

To exercise your rights, contact us at [EMAIL ADDRESS].

We may need to verify your identity before responding to your request.

15. EU/EEA and UK customers

If you are located in the EU/EEA or UK, you may also have the right to complain to your local data protection authority.

16. California and other regional privacy rights

If you are located in California or another region with specific privacy laws, you may have additional rights, such as the right to know what personal information is collected, the right to request deletion, the right to correct information and the right to opt out of certain sharing or targeted advertising.

We do not sell personal information in the traditional sense. However, some privacy laws may define certain advertising or analytics activities as “sharing” or “targeted advertising.”

To make a privacy request, contact us at [EMAIL ADDRESS].

Please update this section if your Store targets customers in California, Colorado, Connecticut, Virginia, Utah or other jurisdictions with specific privacy requirements.

17. Children’s privacy

Our Store is not intended for children. We do not knowingly collect personal information from children under the age required by applicable law.

If you believe a child has provided us with personal information, contact us at [EMAIL ADDRESS] and we will take appropriate steps to delete it.

18. Security

We take reasonable technical and organisational measures to protect personal information against loss, misuse, unauthorised access, disclosure, alteration and destruction.

However, no website, payment system or internet transmission is completely secure. You are responsible for keeping your account login details confidential.

19. Third-party links

Our Store may contain links to third-party websites, platforms, artists, distributors, streaming services, social media pages or other services.

We are not responsible for the privacy practices of third-party websites. Please review their privacy policies before providing personal information.

20. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our practices, services, apps, legal requirements or Shopify features.

The updated version will be posted on this page with a new “Last updated” date.

21. Contact us

For questions about this Privacy Policy or your personal information, contact us at:

Bonebag Records
Tjärhovsgatan 18
904 20 Umeå
Sweden
info@bonebagrecords.com
+46703696663