Last updated: 01.08.2026

This Privacy Policy explains how Strofix SIA ("Strofix", "we") collects, uses and protects your personal data when you use our website https://strofix.com/ and the services offered on it.


1. Data controller

  • Strofix SIA, a limited liability company registered in Latvia
  • Reg. No.: 40203493899
  • Address: Brūkleņu iela 56, Riga, LV-1058, Latvia
  • Email: info@strofix.com
  • Phone: +371 29128044

We have not appointed a data protection officer. For anything to do with your personal data, write to info@strofix.com and put "Personal data" in the subject line.


2. What personal data we collect

  • Identification data – name and surname; for business customers the company name and registration number.
  • Contact details – email address, phone number, delivery and invoicing address. When you place an order, part of this data also leaves for advertising platforms in hashed form – see section 8.
  • Order data – products ordered, order value, payment method, delivery method, order history.
  • Account data – if you create an account, your login details and the data held in it. Your account also has a customer number, which we use in our own systems and which is sent to our conversion measurement tool – see section 8.
  • Correspondence – the content of your enquiries and our replies.
  • Newsletter subscription – if you subscribe, your email address and the fact and time of the subscription.
  • Technical data and online identifiers – IP address, browser and device type, language, pages opened, the page that referred you, cookie and advertising identifiers.
  • Behavioural data – if you allow statistics or marketing cookies: how you move, scroll and click on our pages, and events such as viewing a product, adding it to the cart and completing an order. Today this condition is not fully true: our Servo conversion measurement collects order and browsing events regardless of your cookie choice, as described in section 8.
  • Your cookie choice – which cookie groups you allowed, and when.

We also receive data back from partners: delivery status from Omniva and DPD, and payment status from Maksekeskus AS. We use it only to complete your order.


3. Why we process your data and on what legal basis

Each purpose has its own legal basis under Article 6(1) of the General Data Protection Regulation (GDPR).

PurposeLegal basis
Your order, payment, delivery, returns and warrantyPerformance of a contract – Art. 6(1)(b)
Invoices and accounting recordsLegal obligation – Art. 6(1)(c) (Accounting Law, Grāmatvedības likums, and Latvian tax legislation)
Answering enquiries and customer supportPerformance of a contract or steps before entering into one – Art. 6(1)(b); if your enquiry does not concern an order, our legitimate interest in replying – Art. 6(1)(f)
Keeping the website, your account and the payment flow working, secure and free of fraudOur legitimate interests – Art. 6(1)(f)
Establishing, exercising or defending legal claimsOur legitimate interests – Art. 6(1)(f)
Loading the tag container that enforces your cookie choice, before you have made that choice. This sends Google a signal that a page was opened, with your IP address and browser type, but without cookies and without advertising identifiersOur legitimate interest in operating the mechanism that applies your choice – Art. 6(1)(f). No identifier is read from or stored on your device for this, so it is not covered by the consent rule in the Electronic Communications Law (Elektronisko sakaru likums). You can object – see section 12
Statistics cookies and website analytics (Google Analytics 4, Microsoft Clarity)Your consent – Art. 6(1)(a), given in the cookie banner
Marketing cookies, conversion measurement and advertising (Google Ads, Meta and the destinations named in section 8)Your consent – Art. 6(1)(a), given in the cookie banner
NewsletterYour consent – Art. 6(1)(a), given when you subscribe. For part of our older subscriber list we cannot show when the subscription was made; we are checking and cleaning that list
The part of our Servo conversion measurement that runs before you make a cookie choice, and that continues after you refuse marketing cookies: the cookies and identifiers described in section 8, and the events sent with themNo valid legal basis at present. This processing needs your consent under Art. 6(1)(a), and prior consent under the Electronic Communications Law for the storage on your device, and neither is obtained for it today. We are remediating this – see section 8, which also tells you how to have this processing stopped for you now

The legitimate interests we rely on are: keeping the shop, the customer account and the payment flow secure and free of fraud; keeping the records we need to establish, exercise or defend legal claims; replying to enquiries that do not yet concern an order; and loading the tag container that applies your cookie choice. You can object to this processing at any time – see section 12.

Necessary cookies are used without consent, because the shop, the cart and the login cannot work without them. This is the exemption in the Electronic Communications Law (Elektronisko sakaru likums), which implements Article 5(3) of the ePrivacy Directive in Latvia.


4. Do you have to give us your data

To place an order you must give us the data marked as required in the order form – name, delivery address, email address and phone number. Without it we cannot conclude or perform the contract and cannot deliver the goods. For invoices to a company, the company name and registration number are required by Latvian accounting and tax legislation.

Everything else is voluntary. Consent to statistics or marketing cookies, and subscribing to the newsletter, are entirely your choice: if you refuse, your order, the price you pay and the service you receive are exactly the same, and the shop, the cart, the checkout and your account keep working in full.


5. Who receives your data

We share personal data with the recipients below. Where the table names a brand rather than a company, the contracting party is the entity named in the terms we have accepted with that provider; we will tell you which entity that is if you ask.

RecipientWhat it receivesRoleWhere the data is processed
Maksekeskus AS, owner of the MakeCommerce.lv payment platform (Estonia)The personal data needed to execute the payment. Card payments, Apple Pay, Google Pay and bank links are payment methods offered through this platform. We do not receive or store your full card numberController for the payment service it providesEuropean Economic Area
Omniva and DPDThe recipient's name, address, phone number and email address needed to deliver the parcelController for the delivery service it performsEuropean Economic Area
Google – Google Tag Manager, Google Analytics 4, Google AdsThe tag container loads on every visit, so a signal that a page was opened, with your IP address and browser type, reaches Google whatever you choose. Analytics and advertising data are linked to a cookie only if you allow the relevant groupProcessor for analytics; controller for its own purposes in the advertising productsEuropean Economic Area and United States
Microsoft – Microsoft ClarityHow you use the page, only if you allow statistics cookies. Clarity is not loaded before thatProcessor for the analytics serviceEuropean Economic Area and United States
MetaEvents about your visit and your orders, including contact data in hashed form – see section 8Joint controller with us for the collection and transmission of the event data; controller for what it does with the data afterwardsEuropean Economic Area and United States
TikTokNo TikTok script runs in your browser. TikTok is one of the destinations connected to our server-side dispatcher, so server-side events may reach it – see section 8Controller for what it does with the dataOutside the European Economic Area
Servo (servoad.com), our conversion measurement tool, with its capiProxy endpoint running on Google Cloud in the United States, region us-central1The browser and server-side events described in section 8, including the identifiers and the hashed contact data listed thereWe use it as our processor and it acts on our instructions. We are establishing in writing which legal entity operates servoad.com and confirming that role; Google Cloud is the infrastructure providerUnited States
NewsletterNewsletters are sent from our own shop platform. No separate email marketing platform is connected today; if we connect one we will name it here before we use itProcessor, once one is usedTo be stated when a provider is used
IT and hosting – the providers that host and maintain the websiteWhatever is stored in the shop, as part of hosting and maintenanceProcessors acting on our instructionsEuropean Economic Area
Accounting – our accounting service provider, and the State Revenue Service where the law requires itInvoices and accounting recordsProcessor; the State Revenue Service is a controller in its own rightLatvia

Joint control with Meta. For the event data that reaches Meta, both from your browser and from our server, we and Meta act as joint controllers for the collection and transmission stage, under the controller addendum that forms part of Meta's business tools terms. What Meta does with the data after that is governed by its own privacy policy. You can exercise your rights against either of us: write to info@strofix.com, or use Meta's own settings. We will give you the essence of this arrangement on request.

We do not sell personal data. We require every provider that processes personal data on our behalf to process it only on our instructions and to apply appropriate security measures, and we are completing our written data processing agreements under Article 28 GDPR with them.


6. Transfers outside the European Economic Area

Some of the services we use process data outside the European Economic Area, mainly in the United States. This concerns our analytics, advertising and conversion measurement providers, and it includes the hashed contact data and the customer number described in section 8. It also concerns the signal that reaches Google before you make a cookie choice, and our server-side conversion endpoint capiProxy, which runs on Google Cloud infrastructure in the United States region us-central1 and whose request logs contain IP addresses.

Google, Microsoft and Meta state that they participate in the EU–US Data Privacy Framework; for transfers to a recipient covered by it we rely on the European Commission's adequacy decision for that framework. Where a recipient is not covered by an adequacy decision, we rely on the standard contractual clauses adopted by the European Commission as they are included in the terms we have accepted with that provider. We are completing our file of these documents, and for the Servo service and the TikTok destination we are still establishing which mechanism applies.

You can ask us for more information about the safeguards that apply to a particular transfer at info@strofix.com.


7. Cookies and similar technologies

Cookies are small files that a website stores on your device. On your first visit a banner asks what you allow. It offers three options presented in the same way – Accept, Reject and Configure – so refusing is exactly as easy as accepting. Cookies are divided into three groups: Necessary, Statistics and Marketing. Only the Necessary group is switched on in advance.

Changing or withdrawing your choice. At the bottom of every page, next to our other policies, there is a link called Cookie settings (Sīkdatņu iestatījumi in the Latvian version). It opens the cookie settings window with the same three groups. Switch a group off and save, and we stop using the cookies in that group. Cookies already stored on your device can remain there until they expire; you can delete them at any time in your browser settings. Withdrawing consent is as easy as giving it, and it does not affect the lawfulness of processing carried out before you withdrew it. There is one thing this does not currently stop – our Servo conversion measurement. See section 8, which explains what still happens and how to have it stopped for you.

How long your choice lasts. Your choice is stored on your device in the cookiesplus cookie for 180 days. After 180 days the cookie expires and the banner is shown again, so the cookie's lifetime and the validity of your choice are the same period. You do not have to wait – you can change your choice at any time through the Cookie settings link.

The record we keep of your choice. Besides the cookie on your device, our consent module keeps a record on our server of the choices made – the choice itself and the date and time – so that we can show consent was given. This log currently goes back to when the module was installed, and we have not yet set an automatic deletion period for it.

Before you choose. Until you make a choice, our Google measurement tags run in a restricted mode: they set no cookies and read no identifiers stored on your device. Google still receives a signal that a page was opened, together with your IP address and browser type, without cookies and with advertising identifiers removed. If you refuse statistics and marketing cookies, it stays that way for the whole visit. Microsoft Clarity and our Meta tags in the tag container are not loaded at all until you allow the relevant group. One tool is an exception today: our Servo conversion measurement runs before you choose and keeps sending events after a refusal – see section 8.

The cookies we are aware of on strofix.com are listed below. The storage periods were measured in a browser on 01.08.2026. A provider can change a period, and a provider can add a cookie we have not yet seen. Besides cookies, the Servo script stores data in your browser's local storage. On a visit measured on 01.08.2026 the keys were servo_uid, servo_sid, servo_eid, servo_fbp and servo_consent – a visitor identifier, a session identifier, your customer number, a copy of the Meta identifier and a record of your cookie choice. A further key, servo_click_ids, is added when you arrive from an advertisement. Local storage is storage on your device in the same way a cookie is, it is not cleared when the browser closes, and the cookie settings window does not list it.

Necessary – always active, no consent required.

NameSet byPurposeStorage period
cookiesplusstrofix.comStores your cookie choices180 days
PrestaShop-#strofix.comSession, shopping cart, selected language, logged-in state480 hours (20 days)

Statistics – set only if you allow this group.

NameSet byPurposeStorage period
_clckMicrosoft ClarityRecognises the browser across Clarity sessions1 year
_clskMicrosoft ClarityLinks the page views of one visit into a single recording1 day
_gaGoogleDistinguishes visitors in Google Analytics400 days
_ga_#GoogleKeeps the session state for a Google Analytics property400 days

Marketing – set only if you allow this group, with the exception described in section 8.

NameSet byPurposeStorage period
servo_ctxServoKeeps the advertising context of your visit (for example the Google click identifier) for conversion measurement90 days
_servo_sidServoSession identifier. Links the events of one visit to each other, and is sent to Servo and on to the destinations named in section 8. Despite the name, it is not deleted when you close the browser, so it also links your later visits to the earlier ones90 days
_fbpMetaMeasures the results of Meta advertising90 days
_gcl_auGoogleAttributes a conversion to a Google advertisement90 days
_gcl_awGoogle AdsStores the advertisement click identifier (gclid) so an order can be attributed to the advertisement you came from. Set only when you arrive from a Google advertisement90 days

If you arrive from a Google advertisement, Google may set further cookies whose name begins with _gcl_. The cookie settings window does not yet list _servo_sid among the marketing cookies; we are adding it there so that the banner and this policy match.

You can also delete cookies at any time in your browser settings.


8. The measurement and advertising tools we use

Most of these tools are loaded through Google Tag Manager (container GTM-TCFDHF55), which decides what may run according to your cookie choice. The Servo script, and the Meta script that Servo loads, are embedded in the website itself and do not currently go through the container – see the note at the end of this section.

Google Analytics 4. If you allow statistics cookies, we measure how the website is used – which pages are opened, where visitors arrive from and which steps they complete. Measurement runs into two Analytics properties, G-DTZNER112E and G-CXMGE0GD1E. The second is older and still collects so that past and present figures stay comparable. Google Analytics and Google Ads share a single Google tag (GT-WRDF4SR), so analytics data can also be used for advertising conversion measurement and for audience lists in Google Ads. If you do not want your data used for advertising, refuse the Marketing group and the Statistics group.

Microsoft Clarity. If you allow statistics cookies, we use Microsoft Clarity. Clarity records how you use the page – mouse movement, clicks, scrolling, the order in which you open pages and how long you stay – and turns this into a replay of the visit and heatmaps of the most-used areas. We use it only to find usability problems, not to identify you, and we do not use the recordings to read what you type into forms. Clarity offers a masking setting for form fields, and we are re-checking which mode is in use on this website. If you do not allow statistics cookies, Clarity is not loaded.

Google Ads. In connection with marketing cookies we measure which advertisements lead to an order (conversion tracking ID AW-11336127022) and set the cookie _gcl_au.

Meta. If you allow marketing cookies, the Meta tags in our tag container send events about your visit to Meta (Meta dataset ID 1510090779662371). Separately from those tags, our Servo script loads a Meta script of its own, which sets the _fbp cookie in your browser when the page opens, before you have made any cookie choice. A completed order is reported to Meta twice over: once from your browser, if you return to the order-confirmation page after paying, and once from our server, which reports it whether you return or not. Both carry the same order number as the event identifier, so Meta counts one purchase and not two. What the server sends is described below.

Conversion measurement (Servo). Besides the tags in the tag container, we use a conversion measurement tool called Servo, and it works on two levels.

In your browser, its script is loaded from servoad.com. It sets the cookie _servo_sid and writes the identifiers listed in section 7 to local storage, and it sends events as you use the site – pages opened, products viewed, items added to the cart and orders completed. Our shop adds a companion cookie, servo_ctx, which carries the advertising click identifier of your visit through to our server.

On our server, when an order is paid, our shop sends an event of its own directly to an endpoint called capiProxy, which runs on Google Cloud infrastructure in the United States, region us-central1. From there a dispatcher forwards the event to the four destinations connected for our account: Google Ads, Meta (Conversions API), TikTok and Google Analytics 4. We describe this level separately because it happens outside your browser, where you cannot see it and cannot block it with browser settings.

What the server-side order event contains. It carries the event type, the event identifier and the time; the order value, the currency, the order number, the number of items and the identifiers, quantities, prices and titles of the products ordered; the address of the order-confirmation page; the advertising identifiers _fbp and _fbc, the Google click identifier gclid, the Servo session identifier _servo_sid and the campaign values of your visit; a record of what you chose in the cookie banner; your customer number in our shop, which is sent as it stands, without hashing; and your email address, phone number, first name, surname, city, postcode and country, each converted into a SHA-256 hash before it leaves our server. It also carries your Google Analytics identifiers _ga_client_id and _ga_session_id, taken from the analytics cookie and sent without hashing. As with any request sent over the internet, an IP address reaches the endpoint as well and appears in its logs.

Hashing replaces the value with a fixed-length code, so we do not send the readable text. This is pseudonymisation, not anonymisation. The receiving platform can compare our hash with the hash of contact data it already holds and so match the event to an existing account there – that is the whole purpose of sending it. Under the GDPR these hashed values remain your personal data, and so do the advertising identifiers and your customer number, which is not hashed at all. Put plainly: when you place an order, your contact details do leave our shop for advertising platforms in this coded form.

TikTok. No TikTok pixel and no TikTok script runs in your browser on this website. However, TikTok is one of the destinations connected to the dispatcher described above, so server-side events may reach TikTok. We are reviewing whether this destination is needed for our account.

Please note – the Servo script is not yet behind the cookie banner. As the website is configured today, the Servo script loads when the page opens, before you have made any cookie choice. On a visit where no choice has been made, an event is already sent to the capiProxy endpoint, and the cookies _fbp, _servo_sid and servo_ctx are written to your device.

Pressing Reject does not stop it. Refusing at the banner, or switching the Marketing group off afterwards, does not switch this tool off. The script is told what you chose, and it then leaves out the contact fields – email, phone, first name, surname, city, postcode, country and your customer number. It does not leave out your Google Analytics identifiers: if you allowed statistics cookies but refused marketing, _ga_client_id and _ga_session_id are still forwarded to the advertising platforms named above. But the event is still sent, and it still carries the advertising identifiers _fbp and _fbc, the Google click identifier, the campaign values of your visit and the Servo session identifier, and the cookies and local storage entries stay on your device. The tool's own documentation treats those identifiers as routing hints rather than personal data. We do not describe them that way: under the GDPR they are personal data, because they single out your device and can be linked back to you. So a refusal today reduces what is sent. It does not stop the sending.

Two things follow from that, and you should know both. If you allow marketing cookies later in the same visit, the tool links the events it has already collected during that visit to your contact data. And when your order is paid, our shop sends the server-side event described above whatever you chose at the banner; your choice travels with the event, and where you refused, the receiving service is instructed to apply the advertising platform's limited-data-use handling. That is a restriction on what the platform may afterwards do with the data. It is not a decision to withhold the data.

We have no valid legal basis for the part that runs without your consent, and we are not going to pretend otherwise. We are changing the site so that the Servo script, and the Meta script it loads, run only after you allow marketing cookies; the tool has a strict mode that holds every event back until consent is given, and this website does not run it today. Until that change is made, the cookie settings are not a working remedy for this tool, and we will not pretend otherwise: today this tool cannot be switched off for a single visitor. Write to info@strofix.com and we will tell you when the gate is in place, and ask every platform that received data about you to erase it under Article 17. Events already forwarded cannot be recalled by us. You can also delete these cookies in your browser settings, but that clears what is already on your device rather than stopping what is sent, so we do not offer it as the remedy.


9. Profiling and automated decision-making

We do not take decisions about you based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.

If you allow marketing cookies, our advertising partners use data about your visit for profiling for advertising purposes – to measure how our advertisements perform and to decide which of our advertisements you are shown on other websites. This has no effect on the prices you see, on your order or on the service you receive. You can stop it by withdrawing your consent to marketing cookies, which stops the Google and Meta tags in our tag container. It does not yet stop the events our Servo tool sends with the advertising identifiers; for that, write to info@strofix.com as described in section 8.


10. Your right to object to direct marketing

You have the right to object at any time to the processing of your personal data for direct marketing purposes, including profiling connected with direct marketing. You do not have to give a reason, and we stop that processing.

You can do this by switching the Marketing group off through the Cookie settings link at the bottom of every page, by using the unsubscribe link in any newsletter we send you, or by writing to info@strofix.com. Switching the Marketing group off stops the Google and Meta tags in our tag container. It does not currently stop our Servo conversion measurement, so if you want that stopped as well, write to info@strofix.com – see section 8.


11. How long we keep your data

CategoryRetention
Invoices and accounting records5 years, as required by the Accounting Law (Grāmatvedības likums)
Order and delivery data3 years after the order is completed – the limitation period for claims arising from a commercial transaction under the Commercial Law (Komerclikums). We keep an individual order longer only while it is the subject of an actual dispute or claim, until that ends
Customer account dataFor as long as your account exists. You can request deletion from the personal data section of your account; we then delete your account data, except the invoices and accounting records in the first row of this table, which we are required to keep
Enquiries and correspondenceUp to 3 years from the last message, or until a related dispute or claim ends
Newsletter subscriber recordUntil you unsubscribe. We keep the record that you subscribed, and when, for up to 3 years afterwards as evidence of your consent
Record of your cookie choice on your device180 days – the lifetime of the cookiesplus cookie, after which the banner asks again
Record of your cookie choice on our serverKept as evidence that consent was given. This log currently goes back to when the consent module was installed; we have not yet set an automatic deletion period for it
Cookies and local storage on your deviceEach cookie has its own lifetime, from the end of your visit to 400 days – see section 7. The local storage entries named in section 7 have no expiry date and stay until you clear them in your browser
Server-side conversion events and the request logs of the capiProxy endpointThe endpoint runs in our own Google Cloud project (region us-central1, United States), so the endpoint and its request logs are under our control; the events themselves are also held by the Servo service. We are establishing the exact periods and will state them here. You can ask us to delete the events collected about you at info@strofix.com
Analytics and advertising data held by the providersGoogle Analytics keeps event data for the retention period configured on each property (Google offers 2 or 14 months); Microsoft Clarity and the advertising platforms apply their own periods. We are confirming the exact settings and will state them here

12. Your rights

Under the GDPR you have the right to:

  • Access – to be told whether we process your data and to receive a copy of it.
  • Rectification – to have inaccurate or incomplete data corrected.
  • Erasure – to have your data deleted where one of the grounds in Article 17 GDPR applies.
  • Restriction of processing – to have processing limited, for example while we check whether your data is accurate or how an objection should be resolved.
  • Objection – to object, on grounds relating to your particular situation, to processing based on our legitimate interests; and to object to direct marketing at any time, without giving a reason (see section 10).
  • Data portability – for data you gave us that we process on the basis of consent or of a contract and by automated means, to receive it in a structured, commonly used, machine-readable format and to have it sent to another controller where technically feasible.
  • Withdrawal of consent – to withdraw consent at any time. This does not affect the lawfulness of processing carried out on the basis of your consent before you withdrew it. For cookies, use the Cookie settings link at the bottom of every page, described in section 7. For the one tool this does not currently stop, see section 8.
  • Complaint – to lodge a complaint with a supervisory authority (see section 13).

To use any of these rights, write to info@strofix.com or to our postal address above. If you have an account at strofix.com you can also download your data and submit rectification and erasure requests from the personal data section of your account; these requests come to us and we act on them. If you ordered as a guest or never registered, use email.

So that we do not disclose your data to someone else, we may ask for further information to confirm your identity. We answer within one month of receiving your request. If the request is complex we may extend this by up to two further months and will tell you why. Using your rights is free of charge, unless a request is manifestly unfounded or excessive.


13. Lodging a complaint

If you consider that we have infringed your rights, you can lodge a complaint with the supervisory authority. In Latvia this is Datu valsts inspekcija (the Data State Inspectorate):

If you live or work in another EU or EEA country, you can also complain to the supervisory authority of that country.


14. Data security

We apply technical and organisational measures appropriate to the risk to protect your data against unauthorised access, disclosure, loss and destruction. These include an encrypted connection to the website, restricted access to the shop administration, and a requirement on the providers that handle data on our behalf to process it only on our instructions and to apply appropriate security measures. We are completing our written data processing agreements with those providers under Article 28 GDPR.


15. Changes to this policy

We may update this policy. The current version is always published on this page with the date of the last update at the top. If we make substantial changes we will publish a notice on the website before the change takes effect.


16. Contact

For any question about your personal data, write to info@strofix.com or call +371 29128044.

group_work Cookie consent