Privacy policy

Last updated: October 20, 2025

This Privacy Policy describes how Runerstrand, operated by MP Tech AB (“we”, “us”, “our”), collects, uses, discloses, and protects your personal data when you visit our website, make a purchase, interact with our social channels, receive marketing communications, or otherwise use our services (the “Services”). Runerstrand is powered by Shopify.

If there is any conflict between this Privacy Policy and our Terms of Service, this Privacy Policy governs how we collect, use and disclose personal data.

By using our Services, you acknowledge that you have read and understood this Privacy Policy.


1. Who we are (Data Controller)

Data Controller: MP Tech AB (trading as Runerstrand)
Org.nr: 559299-6424
Address: Vestagatan 9, 416 48 Göteborg, Sweden
Email: martin@mptech.se
Phone: +46 70 447 12 98

We have not appointed a Data Protection Officer (DPO). For privacy questions, contact us using the details above.


2. What personal data we collect

We may collect the following categories of personal data, depending on how you interact with us:

Identity & Contact: name, email, phone number, billing/shipping address.
Account Data: login details, preferences, saved items, order history.
Order & Payment: products purchased/returned, transaction data, partial payment details (we do not store full card numbers).
Device & Usage Data: IP address, browser/device type, language, cookie identifiers, pages viewed, actions taken, referral URLs.
Communications: messages to support, reviews, survey responses.
Marketing & Tracking: cookie/SDK identifiers, ad interactions, consent status.
SMS Data: phone numbers provided for marketing or notifications, message delivery status, engagement (opens, clicks, responses).
Inferences: interests, preferences, predicted purchase likelihood, browsing patterns.

We do not intentionally collect sensitive personal data.


3. Where the data comes from

  • Directly from you: account creation, checkout, forms, SMS opt-ins, customer service.

  • Automatically: via cookies, pixels, scripts and similar technologies.

  • Service providers: payments, hosting, analytics, fulfilment, SMS/email providers.

  • Advertising platforms: Google, Meta, TikTok, etc., depending on your settings and consent.

  • SMS service providers: such as Klaviyo for delivering text messages.


4. Why we process your data (Legal bases under GDPR)

We process your data only when we have a lawful basis for doing so:

Contract (Art. 6(1)(b)) – order processing, payments, delivery, returns, refunds, account functionality.
Legal obligation (Art. 6(1)(c)) – bookkeeping, tax, consumer protection, regulatory duties.
Legitimate interests (Art. 6(1)(f)) – site security, fraud prevention, analytics, improving our Services, and sending direct marketing to existing customers where legally permitted.
Consent (Art. 6(1)(a)) – non-essential cookies, newsletters, SMS marketing, personalized advertising. You may withdraw consent at any time.


5. How we use your data

We use your data to:

  • Provide and operate the Services.

  • Process orders, payments, deliveries, returns, refunds.

  • Send service messages (order confirmations, shipping updates).

  • Provide customer support and handle enquiries.

  • Personalize product recommendations and site content.

  • Improve our website, UX and performance (A/B testing, analytics).

  • Prevent fraud, maintain security and detect abuse.

  • Conduct marketing via email, SMS, ads and remarketing (with consent where required).

  • Comply with legal obligations.


6. SMS Marketing and Notifications

If you provide your phone number at checkout, through a sign-up form, or by texting a keyword, you may receive marketing text messages and notifications from Runerstrand. Message frequency may vary. Standard message and data rates may apply.

We use Klaviyo as our SMS service provider. To deliver SMS messages, your phone number and associated data (e.g., order information, device data, engagement metrics) may be shared with Klaviyo. This information is used only to operate and improve SMS delivery.

You can opt out of SMS marketing at any time by replying STOP to a message or by contacting us.

We do not sell or rent SMS opt-in data.


7. Cookies and Abandoned Cart SMS

Our website uses cookies and similar technologies to track items added to your cart, including when you abandon your cart. If you have opted into SMS communications, this information may be used to send SMS reminders about abandoned carts.

Example:
“Runerstrand’s website uses cookies to identify which products you add to your cart, including when you abandon your cart. This information is used to determine when we should send SMS reminders.”

SMS reminders are only sent with appropriate consent.


8. SMS Data Sharing with Third Parties

If this Privacy Policy refers to the sharing or sale of data with third parties, this does not include SMS opt-in data or SMS consent data. Such data is only shared with Klaviyo or other service providers strictly for the purpose of delivering SMS communications.

Example:
“SMS opt-in data and consent information will not be shared with any third party except as required to deliver SMS messages from Runerstrand.”


9. Location Data and Location-Based Services

If our SMS or marketing systems use IP-derived regional data, this is used only to:

  • Deliver regionally appropriate messages

  • Comply with telecommunications laws

  • Improve segmentation and deliverability

We do not collect precise GPS or real-time geolocation coordinates.
You may withdraw consent at any time.


10. Cookies and Similar Technologies

We use cookies, pixels and similar technologies for:

  • Site functionality and performance

  • Analytics and measurement

  • Personalization

  • Advertising and attribution

  • Abandoned cart tracking (email and SMS)

On your first visit, you will see a cookie banner allowing you to accept, reject, or manage non-essential cookies.

You may change your preferences at any time via “Cookie Settings” in our footer.

If your browser sends a Global Privacy Control (GPC) signal, we treat it as a valid opt-out where legally required.

See our Cookie Policy for more details.


11. Who we share data with

We share data only when necessary and with appropriate safeguards:

  • Shopify – store platform and hosting

  • Payment processors – to handle payments securely

  • Fulfilment and logistics partners – shipping, returns

  • Klaviyo – email and SMS delivery, analytics, segmentation

  • Cloud, IT, and analytics providers

  • Marketing and advertising partners (Meta, Google, TikTok, etc.) with consent

  • Professional advisors – auditors, accountants, legal advisors

  • Authorities – where required by law

  • Business transferees – in the event of a merger, acquisition or restructuring

We do not sell personal data.


12. Relationship with Shopify

Our store is hosted on Shopify. Shopify acts as our data processor and may also process certain data as an independent controller.
For details, visit:
https://privacy.shopify.com


13. International Transfers

Some partners and service providers are located outside the EEA/UK. When data is transferred internationally, we rely on:

  • Adequacy decisions

  • EU Standard Contractual Clauses (SCCs)

  • Additional safeguarding measures where required


14. Your Rights (EEA/UK)

You have the right to:

  • Access your data

  • Rectify incorrect data

  • Request erasure

  • Restrict processing

  • Data portability

  • Object to processing based on legitimate interests

  • Opt out of marketing at any time

  • Withdraw consent without affecting prior processing

To exercise your rights, contact: martin@mptech.se
We may request identity verification.

You can unsubscribe from marketing emails at any time via the link in each email.
Service/transactional emails will still be sent.
You can opt out of SMS at any time by replying STOP.


15. Children’s Data

Our Services are not intended for children. We do not knowingly collect data from individuals under the legal age of consent in their jurisdiction. If you believe a child has provided data to us, contact us and we will delete it.


16. Data Retention

We retain personal data only as long as required:

  • Orders & invoices: typically 7 years (legal obligation)

  • Account data: while the account is active

  • Marketing data: until you unsubscribe or after inactivity

  • Security and fraud logs: for investigation and prevention

  • SMS engagement data: retained by Klaviyo according to their retention schedule

When data is no longer needed, it is deleted or anonymized.


17. Security

We use technical and organizational measures such as encryption, access controls, monitoring, and least-privilege principles to protect personal data. No system is completely secure; keep your credentials confidential and notify us of suspected misuse.


18. Third-Party Websites

Our Services may link to third-party sites. Their privacy practices are governed by their own policies. We are not responsible for their content or handling of personal data.


19. Complaints

If you have concerns about our data practices, contact us first at martin@mptech.se.
You also have the right to lodge a complaint with your local supervisory authority.

In Sweden: Integritetsskyddsmyndigheten (IMY) – www.imy.se


20. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. Updates will be posted here and reflected in the “Last updated” date. Where required, we will notify you or request consent.


21. Contact Us

MP Tech AB / Runerstrand
Vestagatan 9
416 48 Göteborg
Sweden

Email: martin@mptech.se
Phone: +46 70 447 12 98