Privacy Policy

Last updated: August 31, 2026

1. Who we are

This policy explains how SORO Graphics, an independent design studio run by Visar Dema ("we", "us"), collects and uses personal data through sorographics.com. For data protection purposes we are the data controller. Contact: [email protected].

2. What we collect

DataWhenWhy
Name, emailPurchase, enquiry, newsletter signupDeliver products, respond to you, send updates
Billing detailsCheckoutProcess payment, issue invoices, meet tax obligations
Country / IP-derived locationVisit, checkoutVAT determination, currency, fraud prevention
Usage & device dataBrowsing the siteAnalytics, advertising measurement, improving the site
Project materialsDesign engagementsDelivering the agreed work

We do not collect or store your full payment card details. Card data is handled directly by our payment processors.

3. Legal bases (EU/UK visitors)

  • Contract: processing needed to deliver a product or service you bought.
  • Legal obligation: keeping invoices and tax records.
  • Consent: marketing emails, and non-essential cookies including advertising and analytics tracking.
  • Legitimate interests: securing the site, preventing fraud, and understanding how the site is used.

4. Cookies and tracking

We use cookies and similar technologies. Essential cookies keep the cart and checkout working. Optional cookies support analytics and advertising, and are only set where you consent.

Specifically, we use:

  • Meta Pixel and Conversions API (Meta Platforms Ireland Ltd.) — measures the performance of our advertising on Facebook and Instagram, and allows us to show relevant ads to people who have visited the site or bought from us. This may involve sharing hashed identifiers such as your email address with Meta for matching purposes.
  • Google Analytics 4 (Google Ireland Ltd.) — understanding site traffic and behaviour.
  • [YOUR PLATFORM — e.g. Shopify / Podia] — running the store, checkout and course access.

You can withdraw cookie consent at any time in cookie settings — the link is in the footer of every page — and control ad personalisation directly in your Facebook and Instagram ad settings.

5. Who we share data with

We share personal data only with service providers who help us run the business, and only as needed:

  • Payment processors — [STRIPE / PAYPAL]
  • Store and course platform — [YOUR PLATFORM]
  • Email service provider — [MAILERLITE / KLAVIYO / BREVO]
  • Advertising and analytics — Meta Platforms, Google
  • Hosting provider — [YOUR HOST]

We do not sell your personal data. Some of these providers process data outside the EEA; where they do, transfers are covered by Standard Contractual Clauses or an equivalent safeguard.

6. How long we keep it

Order and invoice records: as long as tax law requires, typically [X] years. Marketing contacts: until you unsubscribe. Course accounts: for the duration of your access. Enquiries that don't become projects: [X] months.

7. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict, or port your data, to object to processing, and to withdraw consent at any time. To exercise any of these, email [email protected]. You also have the right to complain to your local data protection authority.

8. Marketing emails

If you opt in, we'll send occasional emails about new courses, offers and studio work. Every email has an unsubscribe link, and unsubscribing takes effect immediately.

9. Children

The Site is not directed at children under 16, and we do not knowingly collect their data.

10. Security

We use appropriate technical and organisational measures, including HTTPS encryption and access controls, to protect your data. No method of transmission over the internet is entirely secure, and we cannot guarantee absolute security.

11. Changes

We may update this policy. The current version is always the one published here, with the date shown above.

12. Contact

Privacy questions: [email protected].