Privacy Policy
Last updated: August 31, 2026
1. Who we are
This policy explains how SORO Graphics, an independent design studio run by Visar Dema ("we", "us"), collects and uses personal data through sorographics.com. For data protection purposes we are the data controller. Contact: [email protected].
2. What we collect
| Data | When | Why |
|---|---|---|
| Name, email | Purchase, enquiry, newsletter signup | Deliver products, respond to you, send updates |
| Billing details | Checkout | Process payment, issue invoices, meet tax obligations |
| Country / IP-derived location | Visit, checkout | VAT determination, currency, fraud prevention |
| Usage & device data | Browsing the site | Analytics, advertising measurement, improving the site |
| Project materials | Design engagements | Delivering the agreed work |
We do not collect or store your full payment card details. Card data is handled directly by our payment processors.
3. Legal bases (EU/UK visitors)
- Contract: processing needed to deliver a product or service you bought.
- Legal obligation: keeping invoices and tax records.
- Consent: marketing emails, and non-essential cookies including advertising and analytics tracking.
- Legitimate interests: securing the site, preventing fraud, and understanding how the site is used.
4. Cookies and tracking
We use cookies and similar technologies. Essential cookies keep the cart and checkout working. Optional cookies support analytics and advertising, and are only set where you consent.
Specifically, we use:
- Meta Pixel and Conversions API (Meta Platforms Ireland Ltd.) — measures the performance of our advertising on Facebook and Instagram, and allows us to show relevant ads to people who have visited the site or bought from us. This may involve sharing hashed identifiers such as your email address with Meta for matching purposes.
- Google Analytics 4 (Google Ireland Ltd.) — understanding site traffic and behaviour.
- [YOUR PLATFORM — e.g. Shopify / Podia] — running the store, checkout and course access.
You can withdraw cookie consent at any time in cookie settings — the link is in the footer of every page — and control ad personalisation directly in your Facebook and Instagram ad settings.
5. Who we share data with
We share personal data only with service providers who help us run the business, and only as needed:
- Payment processors — [STRIPE / PAYPAL]
- Store and course platform — [YOUR PLATFORM]
- Email service provider — [MAILERLITE / KLAVIYO / BREVO]
- Advertising and analytics — Meta Platforms, Google
- Hosting provider — [YOUR HOST]
We do not sell your personal data. Some of these providers process data outside the EEA; where they do, transfers are covered by Standard Contractual Clauses or an equivalent safeguard.
6. How long we keep it
Order and invoice records: as long as tax law requires, typically [X] years. Marketing contacts: until you unsubscribe. Course accounts: for the duration of your access. Enquiries that don't become projects: [X] months.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict, or port your data, to object to processing, and to withdraw consent at any time. To exercise any of these, email [email protected]. You also have the right to complain to your local data protection authority.
8. Marketing emails
If you opt in, we'll send occasional emails about new courses, offers and studio work. Every email has an unsubscribe link, and unsubscribing takes effect immediately.
9. Children
The Site is not directed at children under 16, and we do not knowingly collect their data.
10. Security
We use appropriate technical and organisational measures, including HTTPS encryption and access controls, to protect your data. No method of transmission over the internet is entirely secure, and we cannot guarantee absolute security.
11. Changes
We may update this policy. The current version is always the one published here, with the date shown above.
12. Contact
Privacy questions: [email protected].