Privacy policy
At Woodnest, we are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains what data we collect, why we collect it, how we use it, with whom we share it, and what rights you have in relation to your data.
This policy applies to all personal data collected through our website at https://www.woodnest.co, our email communications, and any other channels through which you interact with us, including third-party marketplaces where we operate (such as Amazon, Etsy, and other European marketplaces).
This Privacy Policy was last updated on March 2026.
1. Who We Are (Data Controller)
The data controller responsible for your personal data is:
- Legal Name: Oui C'est Moi, Lda
- Trading As: Woodnest
- VAT Number: PT507421221
- Address: Caminho Senhora do Olival, Nº 15, 3260-427 Figueiró dos Vinhos, Leiria, Portugal
- Email: support@woodnest.co
- Phone: +351 932 600 637
For any questions or requests relating to your personal data, please contact us at support@woodnest.co.
2. Legal Basis for Processing
We process your personal data on the following legal bases under the General Data Protection Regulation (EU) 2016/679 (GDPR) and Portuguese Law (Lei nº 58/2019):
- Contract performance (Article 6(1)(b) GDPR): Processing necessary to fulfil your order, process payment, arrange delivery, and manage returns
- Legal obligation (Article 6(1)(c) GDPR): Processing required to comply with applicable laws, including tax, accounting, and consumer protection obligations
- Legitimate interests (Article 6(1)(f) GDPR): Processing for fraud prevention, website security, improving our services, and direct marketing to existing customers
- Consent (Article 6(1)(a) GDPR): Processing based on your explicit consent, including marketing communications to new subscribers, the use of non-essential cookies, behavioural tracking and analytics, and profiling for personalised advertising
3. What Data We Collect and Why
3.1 Order and account data
When you place an order, we collect your name, email address, delivery address, billing address, phone number, and order details. This data is used to process and fulfil your order, send order confirmations and shipping updates, manage returns and refunds, and comply with our legal and tax obligations.
3.2 Payment data
Payment transactions are processed by our payment service providers (see Section 5). We do not store your full card details. Depending on your chosen payment method, the following providers process your payment data: Shopify Payments, PayPal, MB Way (IfthenPay), Klarna, Scalapay, and SeQura. Each provider operates under its own privacy policy and applicable financial regulations.
3.3 Website usage data
When you visit our website, we automatically collect certain technical data including your IP address, browser type and version, operating system, pages visited, time spent on pages, referring URLs, and device information. This data is collected through cookies and tracking technologies (see Section 6) and is used to analyse website performance, improve user experience, and measure the effectiveness of our marketing.
3.4 Marketing data
If you subscribe to our newsletter or make a purchase, we collect your email address and, where provided, your name and preferences. This data is used to send you marketing communications, promotional offers, and product updates. You may unsubscribe at any time.
3.5 Communications data
When you contact us by email, phone, or through our chat tools, we collect and retain the content of your communications, your contact details, and the history of your interactions with us. This data is used to respond to your enquiries and improve our customer service.
3.6 Reviews and user-generated content
If you submit a product review through Trustpilot, Judge.me, or Loox, we collect your name, email address, order details, and the content of your review. This data is used to publish and manage reviews, respond to feedback, and improve our products and services.
3.7 Affiliate programme data
If you participate in our affiliate programme, we collect your name, email address, payment details, and referral activity. This data is used to track referrals, calculate commissions, and make payments.
3.8 Third-party marketplace data
Where you purchase from us through a third-party marketplace such as Amazon, Etsy, or other European platforms, we receive your name, delivery address, and order details from that marketplace in order to fulfil your order. Data processing on those platforms is also governed by the respective marketplace's privacy policy.
3.9 Profiling and automated decision-making
We use certain tools and services to build profiles of users and customers based on their browsing behaviour, purchase history, and interactions with our communications. This profiling is used to:
- Personalise the marketing communications you receive from us via Klaviyo (for example, sending product recommendations based on your purchase history or abandoned cart reminders)
- Build custom and lookalike audiences on advertising platforms such as Meta (Facebook/Instagram), Google, TikTok, Pinterest, and Snapchat, in order to show you relevant advertisements
- Analyse user behaviour on our website through Microsoft Clarity and Hotjar to improve the browsing experience
This profiling does not involve fully automated decision-making that produces legal or similarly significant effects on you. You have the right to object to profiling at any time, see Section 8 for details on how to exercise your rights.
4. How Long We Retain Your Data
We retain your personal data only for as long as necessary for the purposes for which it was collected, subject to any legal obligations to retain it for longer:
- Order and transaction data: 10 years, in accordance with Portuguese tax and accounting law (Código do IVA and Código do IRC)
- Marketing data: Until you unsubscribe or withdraw consent, or for a maximum of 3 years from your last interaction with us
- Customer service communications: 3 years from the date of your last interaction
- Cookie and analytics data: As set out in our Cookie Policy (Section 6)
- Review data: For as long as the review remains published, or until you request its removal
- Affiliate programme data: For the duration of your participation in the programme plus 3 years
5. Who We Share Your Data With
We share your personal data only where necessary with the following categories of third parties, all of whom act as data processors on our behalf or as independent data controllers under their own privacy policies:
E-commerce platform
- Shopify Inc. (USA) — our e-commerce platform and store operator. Shopify processes order, payment, and customer data on our behalf. Data may be transferred to the USA under standard contractual clauses. Privacy policy: https://www.shopify.com/legal/privacy
Payment processors
- Shopify Payments (processado por Stripe) — cartões de crédito e débito Visa, Mastercard, American Express, e Multibanco
- PayPal — pagamentos via conta PayPal
- MB Way — processado por IfthenPay. Privacy policy: https://ifthenpay.com/politica-de-privacidade
- Klarna — compra agora, paga depois
- Scalapay — compra agora, paga depois
- SeQura — compra agora, paga depois
Each payment processor operates under its own privacy policy and applicable financial services regulations.
Shipping and logistics
- CTT / BOU Express, DHL, UPS, DPD, GLS — for order fulfilment and delivery. We share your name, delivery address, and contact details with the relevant carrier.
Email marketing
- Klaviyo Inc. (USA) — email and SMS marketing, automated flows, and post-purchase communications. Data may be transferred to the USA under standard contractual clauses. Privacy policy: https://www.klaviyo.com/legal/privacy-notice
- Shopify Email — email marketing campaigns sent directly through the Shopify platform. Privacy policy: https://www.shopify.com/legal/privacy
Analytics and tracking
- Google Analytics / Google Ads / Google Search Console (Google LLC, USA) — website analytics, search performance monitoring, and advertising. Data may be transferred to the USA under standard contractual clauses
- Meta Platforms Inc. (USA) — Meta Pixel for Facebook and Instagram advertising and audience tracking
- TikTok — TikTok Pixel for advertising and audience tracking
- Pinterest — Pinterest Tag for advertising and audience tracking
- Snapchat — Snap Pixel for advertising and audience tracking
- Microsoft Clarity (Microsoft Corp., USA) — session recording and heatmap analytics
- Hotjar (Hotjar Ltd, Malta) — session recording, heatmaps, and user behaviour analytics
Customer service
- Shopify Inbox — live chat and customer communications
- We may in the future adopt additional customer service platforms such as Gorgias. If we do so, this policy will be updated accordingly
Reviews
- Trustpilot — customer review platform. Privacy policy: https://legal.trustpilot.com/end-user-privacy-terms
- Judge.me — product review platform
- Loox — photo review platform
Affiliate programme
- Our affiliate programme management platform, through which we track referrals and manage commission payments. This policy will be updated with the specific provider details once confirmed.
Legal and regulatory We may disclose your personal data to competent authorities, courts, or regulatory bodies where required by law or in connection with legal proceedings.
6. Cookies and Tracking Technologies
We use cookies and similar tracking technologies on our website to enable essential functionality, analyse website performance, and deliver personalised advertising.
Types of cookies we use:
- Strictly necessary cookies: Essential for the website to function. These include session cookies, shopping cart cookies, and security cookies. These cannot be disabled
- Analytics cookies: Used to understand how visitors interact with our website (Google Analytics, Microsoft Clarity, Hotjar)
- Marketing and advertising cookies: Used to track visits and conversions for advertising purposes and to build audience profiles for targeted advertising (Meta Pixel, Google Ads, TikTok Pixel, Pinterest Tag, Snapchat Pixel)
- Functional cookies: Used to remember your preferences and personalise your experience (Klaviyo, Shopify)
When you first visit our website, you will be presented with a cookie consent banner. Non-essential cookies will only be activated upon your explicit consent. You may withdraw or change your consent at any time by clicking the cookie settings link in the footer of our website.
You may also manage cookies through your browser settings, although disabling certain cookies may affect the functionality of the website. For more information on how to manage cookies, visit https://www.aboutcookies.org.
7. International Data Transfers
Some of our service providers are based outside the European Economic Area (EEA), including in the United States. Where we transfer personal data outside the EEA, we ensure that appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where the destination country has been recognised by the European Commission as providing an adequate level of data protection
The main providers involved in international transfers are Shopify (USA), Klaviyo (USA), Google (USA), Meta (USA), TikTok (USA/Singapore), Microsoft (USA), and Snapchat (USA).
8. Your Rights as a Data Subject
Under the GDPR and Portuguese law, you have the following rights in relation to your personal data:
- Right of access: You have the right to request a copy of the personal data we hold about you
- Right to rectification: You have the right to request correction of inaccurate or incomplete data
- Right to erasure: You have the right to request deletion of your personal data, subject to our legal obligations to retain certain data
- Right to restriction of processing: You have the right to request that we restrict the processing of your data in certain circumstances
- Right to data portability: You have the right to receive your data in a structured, commonly used, and machine-readable format
- Right to object: You have the right to object to processing based on legitimate interests, direct marketing, or profiling at any time
- Right to withdraw consent: Where processing is based on consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out prior to withdrawal
- Right not to be subject to automated decision-making: You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects on you
To exercise any of these rights, please contact us at support@woodnest.co. We will respond within 30 days of receiving your request. We may need to verify your identity before processing your request.
If you are not satisfied with how we have handled your request, you have the right to lodge a complaint with the Portuguese data protection authority:
CNPD — Comissão Nacional de Protecção de Dados Rua de São Bento, 148-3º, 1200-821 Lisboa Tel: +351 213 928 400 Web: www.cnpd.pt
9. Marketing Communications
If you have subscribed to our newsletter or made a purchase, we may send you marketing emails about our products, promotions, and news. You may unsubscribe at any time by clicking the unsubscribe link in any of our emails or by contacting us at support@woodnest.co.
We use Klaviyo and Shopify Email to manage our email marketing. Your email address and purchase history may be used to personalise the communications you receive from us based on your interests and behaviour.
We will never sell your personal data to third parties for their own marketing purposes.
10. California Residents — CCPA Notice
If you are a resident of California, you have additional rights under the California Consumer Privacy Act (CCPA), including:
- The right to know what personal information we collect, use, disclose, and sell
- The right to delete your personal information
- The right to opt out of the sale of your personal information
- The right to non-discrimination for exercising your CCPA rights
We do not sell your personal information to third parties. To exercise your rights under the CCPA, please contact us at support@woodnest.co.
11. Children's Privacy
Our website is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe we have inadvertently collected data from a child under 16, please contact us immediately at support@woodnest.co and we will delete it promptly.
12. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, or alteration. These measures include SSL encryption, access controls, and regular security reviews. However, no method of transmission over the internet is completely secure and we cannot guarantee absolute security.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the CNPD within 72 hours of becoming aware of the breach, and will notify affected individuals without undue delay where required by law.
13. Changes to This Privacy Policy
We reserve the right to update this Privacy Policy at any time to reflect changes in our practices, legal requirements, or the services we use. Changes will take effect immediately upon publication on this website. Where changes are material, we will notify you by email or by a prominent notice on our website. We encourage you to review this page periodically.
14. Contact
For any questions, requests, or concerns relating to this Privacy Policy or the processing of your personal data, please contact us:
- Email: support@woodnest.co
- Phone: +351 932 600 637 (national mobile network)
- Address: Oui C'est Moi, Lda (Woodnest), Caminho Senhora do Olival, Nº 15, 3260-427 Figueiró dos Vinhos, Leiria, Portugal



