Personal Data Protection
Personal Data Protection Policy — 1store.lv
Last updated: January 2026
This Personal Data Protection Policy explains how the online store 1store.lv, operated by Mercurius Trade SIA (hereinafter — we), processes personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), the Latvian Personal Data Processing Law and other applicable regulations.
1. Data controller and contact details
Data controller: Mercurius Trade SIA
Reg. No.: 40203063532, VAT No.: LV40203063532
Address: Rēzeknes iela 3a, Riga, LV-1073, Latvia
Email: 1store@mercurius.lv
Phone: +371 2771 8811
Contact person for data protection: for questions about the processing of personal data, please write to 1store@mercurius.lv with the subject line "Data protection".
Data Protection Officer (DPO): not appointed at present, because our data processing is generally not of a kind for which Article 37 of the GDPR requires the mandatory appointment of a DPO (for example, large-scale processing of special categories of data). Should this change, the information will be updated.
2. What personal data may be processed
We may process the following categories of personal data:
- Identification and contact details: first name, surname, email address, telephone number.
- Delivery/invoice details: delivery address, invoice address, company details (where applicable).
- Order details: the products ordered, the amount, the order status, the history of communication about the order.
- Technical data: IP address, browser/device data, website usage data, cookie identifiers.
- Payment data: depending on the payment method — payment information (for example, payment status). If card payment service providers are used, card details (number/CVV) are processed by the payment provider, not by us.
3. Where we obtain the data from
- directly from you (when placing an order, when contacting us);
- from technology platforms and service providers (for example, the e-commerce platform, hosting, analytics) — only to the extent necessary for the operation of the website;
- from logistics/payment partners — in order to fulfil the order and to provide the payment status.
4. Purposes of processing and the legal basis
We process personal data only for specific purposes and on an appropriate legal basis (Article 6 of the GDPR):
4.1. Order processing and delivery
Purpose: accepting the order, picking it, communication, delivery, handing the goods over.
Basis: performance of a contract (GDPR 6(1)(b)).
4.2. Payment processing and accounting
Purpose: preparing invoices, recording payments, accounting obligations.
Basis: compliance with a legal obligation (GDPR 6(1)(c)) and performance of a contract (GDPR 6(1)(b)).
4.3. Customer support, complaints, claims, warranty process
Purpose: answering questions, handling claims, coordinating warranty/service.
Basis: performance of a contract (GDPR 6(1)(b)) and legitimate interests (GDPR 6(1)(f)) — to provide a quality service and to protect our legal interests.
4.4. Website security and fraud prevention
Purpose: IT security, incident prevention, limiting malicious activity.
Basis: legitimate interests (GDPR 6(1)(f)).
4.5. Marketing
Purpose: sending news and offers if you have consented to this.
Basis: consent (GDPR 6(1)(a)) — you may withdraw your consent at any time.
5. Cookies and similar technologies
The website may use cookies and similar technologies to ensure the operation of the website, for statistics and (where applicable) for marketing. Details are set out in our Cookie Policy.
6. Recipients of the data
We may pass personal data only to those recipients who need it in order to provide the service, for example:
- e-commerce platform and IT service providers (for example, the e-commerce platform, hosting, email notifications);
- delivery/courier service providers (to carry out the delivery);
- payment service providers (to process payments, where applicable);
- accounting and legal service providers (to meet regulatory requirements, to resolve disputes);
- public authorities (where required by law).
7. Transfers of data outside the EU/EEA
Some of the technology service providers we use may process data outside the European Union / European Economic Area. In such cases the transfer is carried out on the basis of appropriate safeguards, for example: an adequacy decision of the European Commission, Standard Contractual Clauses (SCC) or other solutions provided for by the GDPR.
If you have questions about specific recipients or safeguards, please write to 1store@mercurius.lv.
8. Automated decision-making and profiling
As a rule, we do not carry out automated decision-making that would produce significant legal effects for you (Article 22 of the GDPR). If personalisation is used in any function of the website (for example, analytics or marketing segments), this is done in accordance with the cookie settings and your choices.
9. Data retention periods
We keep data only for as long as is necessary for the specific purpose or as required by law. Typical periods:
- Invoices and accounting documents: up to 10 years (in accordance with accounting requirements).
- Order and communication data for customer support/claims: usually up to 3 years after the last activity (if there is no dispute).
- Marketing consent: until the consent is withdrawn.
- Cookie/analytics data: in accordance with the cookie settings and the configuration of the services used (see the Cookie Policy).
Once the periods have expired, the data is deleted or anonymised, unless the law provides otherwise.
10. Your rights
Under the GDPR you have the right to:
- request access to your data;
- request rectification of the data;
- in certain cases, request erasure of the data;
- restrict the processing;
- object to processing based on legitimate interests;
- receive the data in a portable format (where applicable);
- withdraw your consent (where the processing is based on consent).
Please send requests to 1store@mercurius.lv. We will normally reply within 1 month. In complex cases the period may be extended in accordance with the GDPR, and you will be informed of this.
11. Security measures
- SSL/TLS encryption (secure data transmission);
- access control and access restrictions;
- software updates and technical protection measures;
- the data minimisation principle — we process only what is necessary.
12. Personal data breaches
If a personal data protection incident occurs, we assess it and take the necessary action. Where the GDPR requires it, we inform the supervisory authority and/or the data subjects within the prescribed time limits.
13. Complaints and the supervisory authority
If you believe that your personal data is being processed improperly, we first invite you to contact us: 1store@mercurius.lv.
You have the right to lodge a complaint with the supervisory authority:
Data State Inspectorate (Datu valsts inspekcija, DVI)
Website: dvi.gov.lv
Address: Elijas iela 17, Riga, LV-1050
Phone: +371 67223131
Email: pasts@dvi.gov.lv
14. Related documents
15. Changes to the policy
We reserve the right to update this policy. The current version is always available on the website 1store.lv. In the event of significant changes, information may be published on the website or sent by email where this is justified and possible.