We at THEBROWNPAPERBAG care about how your personal data is handled and deeply appreciate your trust in us to handle it in a careful and sensible manner.
This document describes our privacy policy in relation to the processing of personal data about you and other users of our website(s), including subscribers to our newsletters, social media and other digital services. For the sake of clarity, please note that this privacy policy does not apply to the processing of personal data about employees, consultants, vendors or service providers. This privacy policy may be updated from time to time, and we recommend that you check this page regularly to stay up to date on any changes we have made. This privacy policy supplements, but does not replace, other policies and terms that applies to any specific service made available by THEBROWNPAPERBAG AB or any of the group companies covered by the privacy policy.

WHO ARE WE?

THEBROWNPAPERBAG is registerred under the business registration number.: 38032143 and is part of an international group of companies controlled by RTR Nordic AB. This privacy policy applies to the collection and further processing of personal data about you, collected by any means or from other sources by THEBROWNPAPERBAG AB and its affiliated group companies. Personal data may be collected by THEBROWNPAPERBAG AB or any of the other group companies and will then be processed in a central database managed on our behalf by our parent company RTR Nordic. Your personal data will be made available to the other group entities by THEBROWNPAPERBAG and/or RTR Nordic AB in accordance with this privacy policy. For your information, RTR Nordic operates the e-commerce platform www.thebrownpaperbag.net on behalf of THEBROWNPAPERBAG AB.

HOW TO CONTACT US?

For questions regarding this privacy policy or your rights as a data subject, we kindly ask you to contact our customer care team using the following details:

WHAT INFORMATION DO WE COLLECT?

We may collect the following categories of personal data about you: Your basic information, that is e.g. your name, address, email address, telephone number, age, other demographics and preferences. Information about your interaction with us, e.g. what products you buy online or in-store, payment information, returns, consumer service contacts, survey information, participation in contests or events etc. Information about you obtained from social networks etc., e.g. comments or behaviour, that we cooperate with. Information about your digital activities on our website(s), such as browsing history, newsletter activity and physical presence, through cookies, pixel tags and similar technologies such as beacons and WiFi access points, including IP-addresses and MAC-addresses. We may share personal data about you within the group companies mentioned above. Please also confer with the section “How do we share your personal information” below. Further, information about you obtained via different technologies and/or from different sources can be combined, e.g. if you become a member of our loyalty program we may link existing information on your purchase history with us to your profile.

HOW DO WE USE YOUR PERSONAL INFORMATION?

The information about you may be used for the following purposes: Processing of orders, claims and returns, administration of your membership of our loyalty program, including providing you with benefits, provision of the various functions and services on the website(s), providing newsletters and other communications and services requested by you, consumer analysis and segmentation, marketing of goods and services, customising the content of newsletters, other communications and other media, e.g. websites and apps, providing support and communication, evaluating and developing our products and services.
The processing of your personal data will in some cases be necessary to conclude or perform a contract with you, e.g. to complete orders in our web-shop, to accept products in commission, comply with your requests (e.g. send you newsletters or otherwise provide you with information that is customised to your interests), to provide you with benefits as part of your membership of our loyalty program. In addition, the processing of your personal data may also be based on our legitimate interests to make us more knowledgeable about you and to develop and evaluate our products and services, as well as creating statistics and analysing such data.

COMMUNICATIONS AND MARKETING

If you give consent, we will send you marketing communications by email and other technologies. You may always opt out of receiving such emails, either directly through the communication via an un-subscription link, or by contacting us. You may object to the processing of your personal data for direct marketing purposes at any time, whereafter communication from us will cease.

HOW DO WE SHARE YOUR PERSONAL INFORMATION?

As mentioned above, we may share personal data about you within the companies in our group, including with our parent company RTR Nordic AB. If you are a member of our loyalty program, your personal data may also be shared with our vendors in order to provide you with the benefits of the loyalty program as well as providing you with the best customer service in physical shops. We may share your personal data with third party providers such as credit card companies and shipping companies in order to complete your orders and carry out shipments. For the sole purpose of supporting our business, third party processors may process your information, but only to the extent necessary for us to conduct our business. We have procedures in place which ensure that these third party processors protect your privacy. We may also share your personal information with third parties that assist us with marketing towards you, including, but not limited to social networks. We will always ensure that such third parties only use the personal information to promote our goods and services in accordance with our instructions. We may use and disclose personal information to parties connected with the proposed or actual financing, securitisation, insuring, sale, assignment or other disposal of all or part of our business or assets, for the purposes of evaluating and/or performing the proposed transaction. Our successors or assignees may use and disclose your personal information for similar purposes as those described in this privacy policy. We do not sell, share or transfer your personal information to any third parties except as described in this privacy policy.

WHEN DO WE DELETE YOUR PERSONAL INFORMATION?

The retention of your personal data depends on the purpose of the processing. For analysis purposes, user and event data acquired through Google Analytics does not automatically expire. We will retain your personal data for as long as we are legally required to do so. For example, we are obliged to retain information relating to sales for a certain time period in order to comply with applicable bookkeeping regulations.Personal data, which is not subject to a legal obligation and which is not linked to a membership subscription, will be retained for 24 months.

INTERNATIONAL TRANSFERS

We may transfer your personal data to countries outside the EU/EEA, including group companies. If we do this, it will either be to a country that is deemed by the authorities to provide an adequate level of protection, or subject to a written data processor agreement containing obligations for the disclosing and receiving party. The agreement will be based on the "Standard Contractual Clauses" approved by the European Commission or similar.

COOKIES

We will collect information, including personal data, about you using cookie technology. A cookie is a small text file logged on your computer which helps your internet browser in navigating our website(s) and makes full use of their features and services. For futher information, please consult your browsers cookie settings.

YOUR RIGHTS AS A DATA SUBJECT

At any time you are entitled to recall any consent you may have given with respect to our use of your personal data. Furthermore, you have the right to access your personal data and to obtain information about how we process it at any time. You may modify your personal data if it is incorrect, ask us to limit or cease the processing of your personal data, delete it, as well as object to the processing of your personal data, including processing for the purpose of direct marketing and profiling related to such direct marketing. You may ask us to disclose your personal data in a machine readable format. To modify your membership subscription and/or marketing communications, please change your preferences in the relevant section of the pertinent website(s) or click on the link in our newsletter(s). Due to e-mail production schedules, you may still receive e-mails that are already in production. You may at any time object to the processing of your personal data for direct marketing purposes by contacting using the above contact information.

HOW DO WE PROTECT YOUR INFORMATION?

We care about the protection of your personal data and will apply industry standard security measures to ensure that your data is adequately protected.

OTHER WEBSITES

Our website(s), social media pages, communications etc. may contain links to third party websites which are not affiliated with our group companies and thereby are not covered by this privacy policy. If you access other sites using the links provided, the operators of these sites may collect information from you which will be used by them in accordance with their privacy policy, which may differ from ours.

ANY QUESTIONS?

We are always happy to hear from you and welcome any questions, comments and concerns about privacy. Please visit our contact page or write to us using the contact information provided above. If your inquiry concerns a specific group entity, please state this when you contact us.