New arrivals every week — fast worldwide delivery & secure checkout
HomePrivacy Policy

Privacy Policy & Data Protection

Last updated: 15 September 2026UK GDPR & EU GDPR Certified

1. Introduction & Data Controller Information

PanyBox ("PanyBox", "we", "us", "our") is dedicated to upholding the highest standards of privacy, security, and confidentiality regarding your personal information. This Privacy Policy sets out how we collect, process, store, disclose, and protect your personal data when you visit, register, browse, or place orders through panybox.com and its affiliated web services.

For the purposes of the UK Data Protection Act 2018, the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR 2016/679), and international data privacy laws (including the California Consumer Privacy Act / CPRA), PanyBox operates as the official Data Controller. If you have questions regarding this Privacy Policy or your data protection rights, you can reach our Data Protection Officer at contact@panybox.com.

2. Lawful Bases for Data Processing

Under Article 6 of the UK/EU GDPR, we only collect and process your personal data when we have an authenticated lawful basis to do so:

  • Performance of a Contract: Processing necessary to fulfill our contractual obligations to you—such as processing payments, coordinating international delivery with carriers, sending order receipts, and managing your user account.
  • Legitimate Business Interests: Processing necessary for our legitimate interests in safeguarding platform cybersecurity, preventing fraudulent transactions, monitoring system performance, optimizing catalog navigation, and resolving customer inquiries.
  • Compliance with Legal Obligations: Processing necessary to comply with statutory fiscal accounting requirements, anti-money laundering regulations, tax filings, and mandatory customs declaration laws.
  • Freely Given Consent: Where you have explicitly opted in to receive promotional newsletters, marketing campaigns, or non-essential cookies. You have the absolute right to revoke consent at any time.

3. Categories of Personal Data We Collect

We collect only the minimum personal data strictly necessary to provide our services and ensure compliance:

  • Identity & Contact Information: Your full name, email address, telephone contact number, billing address, and recipient delivery address.
  • Transaction & Financial Records: Details of orders placed, purchased merchandise, order numbers, pricing subtotals, coupon codes applied, and payment transaction identifiers. Note: PanyBox does not store or process raw credit card numbers or security CVV codes. All cardholder payment processing is handled directly by PCI-DSS Level 1 certified gateways (Stripe).
  • Account Credentials: Hashed and salted login credentials, user identifiers, account security preferences, and wishlists.
  • Technical & Telemetry Data: Internet Protocol (IP) address, operating system, browser type and version, hardware device identifiers, network location, time zone settings, referral sources, and page clickstream patterns.
  • Customer Service Records: Communications, inquiries, support tickets, delivery issues, and user-generated product reviews and ratings.

4. How We Collect Personal Information

We gather personal data through multiple transparent touchpoints:

  • Direct Interactions: Data you provide directly when creating an account, entering delivery information at checkout, submitting contact forms, or writing product reviews.
  • Automated Technologies: Telemetry data collected automatically as you browse the website via secure session cookies, server access logs, and performance monitoring.
  • Third-Party Partners: Information received from payment processors (e.g. Stripe fraud risk assessment scores) and logistics carriers (e.g. courier tracking milestones and proof-of-delivery confirmations).

5. Data Usage & Processing Purposes

PanyBox processes your personal data strictly for defined, lawful commercial purposes:

  • Facilitating checkout, processing payment authorizations, and issuing itemized tax invoices;
  • Dispatching parcels with global logistics carriers, fulfilling cross-border supply orders, and providing real-time package tracking;
  • Preventing payment fraud, card testing, unauthorized bot attacks, and system abuse;
  • Administering customer accounts, password reset workflows, and order history archives;
  • Providing responsive customer support, handling returns, and issuing refunds under our Return Policy;
  • Maintaining compliance with statutory accounting, tax reporting, and customs documentation standards.

6. Third-Party Sharing & Service Disclosures

PanyBox will never sell, lease, rent, or trade your personal data to data brokers or unauthorized third parties for marketing purposes. We share personal data exclusively with trusted third-party service providers bound by strict contractual data processing agreements (DPAs):

  • Payment Gateways (Stripe, Inc.): Encrypted processing of card transactions under certified PCI-DSS Level 1 security standards;
  • Fulfillment & Logistics Providers: Vetted international suppliers (e.g. CJ Dropshipping) and shipping carriers (Royal Mail, FedEx, DHL, USPS, and national postal authorities) strictly to the extent required to dispatch and deliver your consignments;
  • Cloud Infrastructure & Database Hosts: Enterprise cloud servers, database clusters, and content delivery networks protected by encrypted perimeters;
  • Legal & Regulatory Authorities: Where disclosure is legally mandated by judicial subpoena, court order, or binding regulatory statutory requirement.

7. International Cross-Border Data Transfers

Because PanyBox operates an international commerce network fulfilling orders across global supply hubs, your personal data may be stored, processed, or transferred to servers located outside your country of residence (including the United Kingdom, the European Economic Area, the United States, and international manufacturing logistics hubs).

Whenever personal data is transferred across international borders, PanyBox ensures that appropriate safeguards are instituted in strict compliance with the UK GDPR and EU GDPR, including the execution of Standard Contractual Clauses (SCCs) approved by the European Commission, the UK International Data Transfer Addendum, and rigorous technical encryption standards.

8. Technical & Organizational Data Security Measures

We deploy robust, institutional-grade security safeguards designed to protect personal data from unauthorized access, alteration, destruction, disclosure, or breach:

  • End-to-End Encryption: All data transmitted between your browser and our platform is encrypted using modern Transport Layer Security (TLS 1.3 / SSL) protocols;
  • Cryptographic Password Protection: Account passwords are never stored in plaintext and are protected using high-iteration cryptographic hashing algorithms (Bcrypt / Argon2);
  • Perimeter Defense: Automated rate limiters, web application firewalls (WAF), Cross-Site Request Forgery (CSRF) tokens, parameterized SQL queries to prevent SQL injection, and strict input sanitization against Cross-Site Scripting (XSS);
  • Role-Based Access Controls (RBAC): Administrative access to order databases is strictly restricted on a least-privilege basis to authorized personnel utilizing multi-factor authentication (MFA);
  • Zero Raw Card Storage: PanyBox never captures, stores, or handles unencrypted payment card primary account numbers (PAN) or card verification codes (CVV).

9. Data Retention & Archival Policies

We retain personal information only for the duration necessary to satisfy the purposes for which it was gathered, including satisfying any contractual, legal, accounting, tax, or statutory reporting obligations.

Under statutory UK and international financial regulations, transaction records, invoices, and proof-of-delivery documentation are retained for up to seven (7) years following transaction completion. Personal information tied to your account will be retained while your account remains active and will be permanently deleted or anonymized upon receipt of an authenticated account closure and erasure request, subject to overriding statutory compliance obligations.

10. Your Statutory Data Protection Rights

Depending on your geographic location, applicable data privacy legislation (including UK GDPR, EU GDPR, and CCPA) grants you enforceable rights regarding your personal information:

  • Right of Access: You have the right to request a formal copy of the personal data we hold about you (Subject Access Request);
  • Right to Rectification: You may request the immediate correction of inaccurate or incomplete personal information;
  • Right to Erasure ("Right to Be Forgotten"): You may request the permanent deletion of your personal data where there is no overriding legal basis for its continued processing;
  • Right to Restriction: You may request that we temporarily suspend the processing of your data while an inquiry or accuracy dispute is pending;
  • Right to Data Portability: You may request your personal data in a structured, commonly used, and machine-readable format;
  • Right to Object: You have the absolute right to object at any time to the processing of your data for direct marketing purposes;
  • Right to Withdraw Consent: Where processing is predicated upon your consent, you may withdraw your consent at any time without affecting the lawfulness of prior processing.

To exercise any of your statutory rights, please send your request in writing to our Data Protection Officer at contact@panybox.com. We will verify your identity and respond to your request within thirty (30) calendar days, free of charge.

11. Cookies & Tracking Technologies

PanyBox utilizes cookies, session tokens, and local storage mechanisms to guarantee the functionality and security of our platform:

  • Strictly Necessary Cookies: Essential for user authentication, maintaining shopping cart sessions, preventing fraud, and executing CSRF security checks. The platform cannot function properly without these cookies;
  • Performance & Analytics Cookies: Anonymous aggregated metrics that allow us to evaluate visitor traffic, page load performance, and catalog engagement to optimize site usability;
  • Preference Cookies: Remember your regional currency selections, locale settings, and display preferences.

You can adjust your browser settings at any time to reject or delete cookies. However, please be aware that disabling essential cookies will impair key features of the platform, including user login and the checkout process.

12. Protection of Children's Privacy

PanyBox is an adult commercial retail platform. Our services, catalog, and ordering facilities are not directed to individuals under the age of 16 (or under 18 where required by applicable local law). We do not knowingly solicit or collect personal data from children. If we discover that personal data from a child has been inadvertently gathered without verified parental consent, we will take immediate steps to permanently delete that data from our production databases.

13. California & US State Privacy Rights (CCPA / CPRA Notice)

For residents of California and states with comprehensive privacy legislation (such as Virginia, Colorado, Connecticut, and Utah):

  • Notice of Collection: We collect the categories of personal identifiers and commercial transaction data detailed in Section 3 of this policy;
  • No Sale or Sharing of Personal Data: PanyBox does not "sell" personal information, nor do we "share" personal data for cross-context behavioral advertising within the definitions of the California Consumer Privacy Act (CCPA/CPRA);
  • Non-Discrimination: We will never discriminate against, penalize, or charge differential prices to any customer who exercises their statutory privacy rights.

14. Supervisory Authority & Complaints

If you believe that PanyBox has processed your personal information in breach of applicable data protection legislation, you have the statutory right to lodge a formal complaint with the competent supervisory data protection authority:

  • United Kingdom: Information Commissioner's Office (ICO) — https://ico.org.uk
  • European Union: You may contact the Data Protection Authority in your respective EU member state of residence.

15. Amendments to This Privacy Policy

PanyBox reserves the right to periodically update this Privacy Policy to reflect modifications in our operational practices, regulatory updates, or newly introduced platform features. Any revisions will be published directly on this page with an updated "Last modified" effective date. We recommend checking this page periodically to remain informed about how we safeguard your personal data.

16. Contact Our Data Protection Officer

For questions, formal legal notices, or Subject Access Requests regarding your privacy and personal data, please contact:

Exercise Your Data Privacy Rights

To submit a Subject Access Request (SAR), request erasure, or inquire about our data security practices: