Privacy Policy

Plankton Zoo
Operated by Once Upon a Time in Finland Oy


1. Who We Are

Plankton Zoo is an online store operated by Once Upon a Time in Finland Oy, registered in Finland.

Website: https://planktonzoo.fi

This Privacy Policy explains how we collect, use, store, and protect personal data in accordance with the EU General Data Protection Regulation (GDPR) and Finnish data protection law.


2. What Personal Data We Collect and Why

a) Orders and Customer Accounts

When you place an order or create an account, we collect personal data necessary to fulfill our contractual obligations, including:

  • Name

  • Billing and shipping address

  • Email address

  • Phone number (if provided)

  • Order details and purchase history

This data is used for:

  • Order processing and delivery

  • Customer service and communication

  • Refunds and returns

  • Legal and accounting obligations


b) Payments

Payments are processed by third-party payment service providers.
We do not store or process full payment card details on our servers.

Payment providers receive only the data required to complete the transaction and are responsible for their own GDPR compliance.


c) Comments

When visitors leave comments on the site, we collect:

  • The data shown in the comments form

  • IP address

  • Browser user agent string

This data is collected to help with spam detection.

An anonymized hash of your email address may be shared with the Gravatar service to display a profile image, if you use Gravatar.
Gravatar’s privacy policy is available at: https://automattic.com/privacy/


d) Media Uploads

If you upload images to the website, you should avoid uploading images containing embedded location data (EXIF GPS).
Visitors may be able to download and extract location data from images published on the site.


3. Cookies

We use cookies to ensure the proper functioning of the website and webshop.

Cookies may include:

  • Comment form cookies (name, email, website) for convenience

  • Temporary cookies to test browser compatibility

  • Login cookies and screen preference cookies for registered users

  • Session cookies required for WooCommerce cart and checkout functionality

Cookie durations vary from session-based to up to one year, depending on purpose.

You can control or delete cookies through your browser settings.


4. Embedded Content from Other Websites

Pages and articles on this site may include embedded content (such as videos, images, or articles).

Embedded content from other websites behaves as if you visited that website directly and may:

  • Collect data about you

  • Use cookies

  • Include third-party tracking

  • Monitor your interaction with embedded content


5. Who We Share Your Data With

We only share personal data with third parties when necessary to operate the webshop, including:

  • Payment service providers

  • Shipping and logistics partners

  • IT and hosting providers

  • Automated spam detection services

If you request a password reset, your IP address will be included in the reset email.

We do not sell or rent personal data.


6. How Long We Retain Your Data

  • Order and accounting data is retained as required by Finnish law

  • Customer account data is stored while the account remains active

  • Comments and their metadata are retained indefinitely to manage moderation

  • Data not required for legal or operational purposes is deleted upon request where possible


7. Your Rights Under GDPR

You have the right to:

  • Request access to your personal data

  • Request correction of inaccurate data

  • Request deletion of your personal data

  • Request restriction of processing

  • Object to certain types of processing

  • Receive your data in a portable format

Requests can be made by contacting us using the details below.

Some data cannot be erased if retention is required by law (e.g. accounting records).


8. Where Your Data Is Sent

Visitor comments may be checked through automated spam detection services.

Data may be processed outside the EU only when necessary and only with appropriate safeguards in place, in accordance with GDPR.


9. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in legal requirements or our operations.

The version published on the website at the time of data collection applies.


10. Contact Information

For privacy-related questions or data requests, please contact:

Once Upon a Time in Finland Oy / Plankton Zoo

Email: contact@planktonzoo.fi

Address:
Terrisuontie 114
04390 Jäniksenlinna
Finland