Privacy policy
4 September 2026
Demo notice. This is a portfolio demonstration. The company, products, prices and certifications below are fictional, and no real transactions take place. This text is a structural placeholder and is not legal advice.
What a shop built like this one would collect, on what legal basis, who would process it, and for how long.
01
Who is responsible
The controller would be MERIDIAN Demo SIA, Brīvības bulvāris, Riga, LV-1050, Latvia, registration number LV40000000000. As this is a demonstration, no such company exists.
Questions, or a request to exercise any of the rights below, go to hello@meridian.example.
02
What is collected
Four categories, and nothing else.
- Order data — the items ordered, the amount paid, the billing address, a shipping address for physical goods, and the email address the receipt goes to. Card numbers are never received: payment happens on Stripe’s own pages.
- Contact form data — the name, email address and message you submit, so the enquiry can be answered.
- Language preference — which of the four languages you chose, stored in your browser.
- Approximate country — derived from your network connection, and only if you allowed it. Never GPS, never a precise location, and never joined to your order.
03
Legal basis for each
- Order data — Article 6(1)(b), performance of a contract. Without it an order cannot be fulfilled.
- Accounting records — Article 6(1)(c), a legal obligation to keep records of transactions.
- Contact form — Article 6(1)(f), legitimate interest in answering an enquiry that was deliberately sent.
- Language preference — Article 6(1)(b) and strictly necessary: without it the site cannot show you the page you asked for.
- Approximate country — Article 6(1)(a), consent, given in the banner and withdrawable at any time on the cookies page.
- Marketing email — Article 6(1)(a), consent, given by ticking the box at checkout. Never assumed, never bundled with a purchase.
04
Who else processes it
Each of these acts as a processor under a data processing agreement and only on documented instructions.
- Stripe Payments Europe, Ltd. — payment processing, tax calculation and the order record. Stripe is the only party that sees card details.
- Resend — delivery of the receipt email and contact-form notifications.
- The hosting provider — serving the site and running the four API endpoints.
05
How long it is kept
- Order and transaction records — five years from the end of the financial year, to meet accounting obligations.
- Contact form messages — twelve months from the last message in the exchange.
- Language preference — until you clear your browser storage.
- Consent record — until withdrawn, plus a record of the withdrawal itself.
- Rate limiting counters — held in memory only and lost when the process restarts. Never written to disk.
06
Your rights
You may request access to your data, its correction, its erasure, restriction of its processing, and portability of what you provided. You may object to processing based on legitimate interest, and withdraw consent at any time without affecting processing that already happened on that basis.
A request is answered within one month and there is no charge unless it is manifestly unfounded or excessive.
You may also complain to a supervisory authority — in Latvia, the Data State Inspectorate; in Ukraine, the Ombudsman’s office.
07
International transfers and automated decisions
Some processors operate infrastructure outside the European Economic Area. Where that happens, transfers rely on the European Commission’s Standard Contractual Clauses or on an adequacy decision.
There is no automated decision-making producing legal effects. Stripe applies automated fraud checks that can decline a payment; no profile of you is built on this site.