Legal

Privacy Policy

Last updated: 13 August 2026

This policy describes the personal data handled by the Drabalon website, account and ordering features.

Privacy Contact

The single privacy contact is contact@drabalon.com, from the verified Drabalon legal-business configuration.

For every category below, you can request access, correction or deletion by email. Some information may need to be kept where it is required for account access, open communication, order records, payment records or legal obligations.

Account Details

Collected: name, email address, optional phone number and optional account address fields. Why: to create an account, identify the customer, prefill checkout and provide account support. Storage: MySQL tables for users and saved addresses. Processors: website hosting and database provider; email provider if support is requested. Retention: while the account is active or as needed for open requests and legal records. Rights: request access, correction or deletion by email.

Login Information

Collected: email, password during login, session cookie, CSRF token, last login time and password reset token hashes. Passwords are never stored in plain text; the API stores password hashes only. Why: authentication, password reset and abuse prevention. Storage: MySQL for password hashes, reset token hashes and last login time; PHP session storage for login state. Processors: hosting and database provider; email provider for reset links. Retention: account credentials remain while the account exists; reset links expire after one hour and previous unused reset links are marked used when a new one is created.

Customer Addresses

Collected: shipping and billing address lines, postal code, city and country. Why: to save customer addresses and arrange Swiss delivery or pickup. Storage: MySQL user address and order address fields. Processors: hosting and database provider; the Swiss geo.admin.ch address search API may receive typed address search text when autocomplete is used; delivery providers only when needed for an order. Retention: saved account addresses remain until changed or deleted; order addresses are kept with order records while required for fulfilment, support and legal/accounting needs.

Cart Data

Collected: product id, title, price, variant or finish, quantity, product type, collection, image path and any personalisation summary attached to a cart item. Why: to show and edit the cart, preview checkout and prepare an order request. Storage: browser localStorage under the Drabalon cart key. Processors: none unless the customer later submits a real order or manually prepares an email. Retention: until the customer clears browser storage, removes cart items or checkout clears the cart after a verified successful order.

Custom Text and Uploaded Images

Collected: custom text entered in the editor and artwork or image files selected for preview and submission. Why: to preview placement and send a personalised or custom request to Drabalon. Storage: preview data remains in browser memory; the selected source file or generated mockup is transmitted to Drabalon's email service only when the customer submits the request. Retention: browser memory is cleared when the page is closed or reset; request emails and attachments are kept only while needed to answer, quote, produce or document the request.

Generated Mockups

Collected: a generated mockup PNG when the customer chooses to include the preview with a submitted request and no separate source artwork is attached. Why: to give Drabalon a visual placement reference. Storage and processors: transmitted through the website and Drabalon's email provider with the request. Retention: kept with the related correspondence while needed to answer, quote, produce or document the request.

Contact-Form Data

Collected: name, email, reason, subject, message and an optional JPG, PNG, WebP, SVG or PDF attachment. Why: to send the enquiry securely to Drabalon and return a confirmation. Storage and processors: the website transmits the form through the hosting service and Drabalon's email provider. Retention: correspondence and attachments are kept while needed to answer, manage requests and retain necessary business records.

Order Information

Collected when an order is submitted: optional account id, products, variants, quantities, totals in CHF, shipping amount, optional extras, delivery preference, customer details, billing and delivery addresses, order status, terms version and accepted-at time. An account is not required for guest checkout. Why: to create, review, fulfil and support orders. Storage: MySQL orders and order items tables. Processors: hosting and database provider; email provider for transactional messages; delivery, payment or accounting providers when needed. Retention: retained for fulfilment, support, accounting and legal record needs.

Payment-Provider References

Collected when payment features are enabled by an admin: payment status, method, external payment link, payment reference and paid-at date. Why: to send payment requests, track payment state and support the order. Storage: MySQL order payment fields. Processors: SumUp if a SumUp payment link is created; possible TWINT, bank or pickup-payment channels when configured; email provider for payment emails. Drabalon systems do not store card details.

Server, Security Logs and IP Addresses

Collected by the application: rate-limit records based on the request IP address and, for some actions, email plus IP. These records are stored as hashed file names with counters and reset times, not as raw IP database rows. Why: to reduce abusive login, registration and password-reset attempts. Storage: temporary server files. Processors: hosting provider. Retention: records contain a reset time and may remain until overwritten, removed by server temporary-file cleanup or cleared after successful login for login attempts. Server or hosting logs may also record request details such as IP address and error information according to the hosting setup.

Language Preference

Collected: selected language code EN, FR or DE. Why: to keep the interface language between pages. Storage: browser localStorage and, where practical, the URL language parameter. Processors: none. Retention: until the customer changes language, clears browser storage or removes the URL parameter.

Analytics and Cookies

Current code does not include Google Analytics, tracking pixels or embedded analytics scripts. Cookies used by the application are PHP session cookies for login state and CSRF protection; they are configured as HTTP-only and use the Secure flag when the request is HTTPS. Language and cart data use browser localStorage, not cookies.

Social-Media Links

The footer links to Instagram and Facebook. Drabalon does not embed social-media tracking widgets in the current code. If a customer clicks a social link, that platform receives the visit according to its own privacy practices.

Hosting and Email Providers

Drabalon currently uses OVH infrastructure for website hosting, MySQL database storage and transactional or support email delivery. OVH processes the technical data needed to serve the website, store account and order records, and deliver messages. Other providers are listed here if the live service changes.