Introduction
This Privacy Policy explains how Simple Legumes collects, uses, stores, and shares personal data when you visit simplelegumes.com, contact us, purchase a physical product, purchase or access the Digital PDF, or otherwise interact with our services.
Simple Legumes is a trading brand operated by Dmytrii Krapyvianskyi, a sole trader established in the Czech Republic.
For the purposes of the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and other applicable data protection laws, Dmytrii Krapyvianskyi is the data controller for personal data processed directly by Simple Legumes.
Full legal and business identification details are available on our Legal Notice page.
For privacy-related enquiries, please contact: support@simplelegumes.com
Personal Data We Collect
The personal data we collect depends on how you interact with the website and our services.
2.1 Information You Provide Directly
This may include:
- your name
- email address
- shipping address
- apartment or unit information, if provided
- postal code
- city
- country
- state or region, where applicable
- telephone number
- order number
- products purchased
- messages sent through our contact form or by email
- information related to returns, refunds, complaints, or delivery issues
Our contact form currently collects:
- Name
- Message
If you contact us about an existing order, we may ask for additional information necessary to identify and assist with that order.
Data Collected Automatically When You Visit the Website
When you access simplelegumes.com, certain technical information may be processed automatically.
This may include:
- IP address
- date and time of access
- browser type and version
- device type
- operating system
- pages or resources requested
- referral information
- technical and security information
- approximate country or region derived from your network connection
- cookie and consent preferences
Some of this information is necessary for the website to function securely and reliably.
Processing may be based on our legitimate interest in operating, protecting, and maintaining the website under Article 6(1)(f) GDPR.
Regional Pricing and Country Detection
Simple Legumes uses Cloudflare to determine the approximate country from which a visitor accesses the website.
This information is used to display the appropriate regional price for physical books because international FedEx shipping costs vary by destination.
The country information is used for pricing and routing purposes and is not used by Simple Legumes to build an individual behavioural profile.
The legal basis for this processing is our legitimate interest in displaying accurate destination-based pricing and operating the website efficiently under Article 6(1)(f) GDPR.
Purposes and Legal Bases for Processing
We process personal data only where there is a valid legal basis.
5.1 Performance of a Contract
Under Article 6(1)(b) GDPR, we may process personal data where necessary to:
- process a physical book order
- process payment
- arrange shipment and delivery
- send order and delivery information
- provide access to the Digital PDF
- process a return or refund
- provide support relating to a purchase
- respond to pre-contractual requests
5.2 Legal Obligations
Under Article 6(1)(c) GDPR, we may process and retain personal data where necessary to comply with:
- accounting requirements
- tax requirements
- consumer protection law
- regulatory obligations
- legal claims
- lawful requests from public authorities
5.3 Legitimate Interests
Under Article 6(1)(f) GDPR, we may process personal data where reasonably necessary for legitimate business interests, including:
- website security
- fraud prevention
- troubleshooting
- customer support
- maintaining appropriate business records
- preventing misuse
- protecting legal rights
- improving website reliability
5.4 Consent
Under Article 6(1)(a) GDPR, we use consent where required for:
- Google Analytics
- Microsoft Clarity
- embedded YouTube content
- other optional non-essential technologies
You may withdraw your consent at any time through the “Cookie Settings” link in the website footer.
Cookies and Consent Management
Our website uses necessary technologies that are required for the website to function.
These may include technologies used for:
- website security
- checkout functionality
- remembering privacy preferences
- essential technical operation
Necessary technologies may operate without consent where permitted by law.
We also use optional technologies for:
- analytics
- session analysis
- embedded media
These optional technologies are activated only after the relevant consent has been provided.
Our cookie banner provides the following choices:
- Accept All
- Reject All
- Manage Preferences
Users may separately control:
- Necessary
- Analytics
- Embedded Media
Analytics and embedded media are disabled by default until consent is given.
Under Czech privacy guidance, non-technical cookies used for analytics or similar purposes generally require prior user consent, while strictly necessary technical cookies do not.
For further details, please see our Cookie Policy.
Google Analytics
With your consent, we use Google Analytics 4 to understand how visitors use the website.
Google Analytics may process information such as:
- page views
- session information
- device and browser information
- approximate location
- interaction data
- technical identifiers
- analytics cookies
Google Analytics is activated only after consent is granted through our cookie preferences.
Google uses consent signals such as analytics_storage to determine whether analytics storage may be used.
The legal basis for this processing is Article 6(1)(a) GDPR — consent.
You may withdraw your consent at any time through Cookie Settings.
Microsoft Clarity
With your consent, we use Microsoft Clarity to understand how visitors interact with the website.
Clarity may be used to generate:
- session recordings
- heatmaps
- click information
- scrolling behaviour
- page navigation information
- device and browser information
- technical identifiers
We use this information to identify usability problems and improve the website experience.
Microsoft Clarity is activated only after analytics consent has been granted.
Microsoft requires a valid consent signal for users in the EEA, UK, and Switzerland and supports consent-based cookie operation.
The legal basis for this processing is Article 6(1)(a) GDPR — consent.
You may withdraw your consent at any time through Cookie Settings.
Embedded YouTube Content
Our website may contain embedded YouTube videos.
YouTube content is not loaded until you enable the Embedded Media category in Cookie Preferences or otherwise provide consent.
Once enabled, YouTube or Google may process information including:
- IP address
- device and browser information
- video interaction data
- cookies or similar technologies
- information relating to a Google account if you are logged in
The legal basis for loading embedded YouTube content is Article 6(1)(a) GDPR — consent.
You may withdraw this consent at any time through Cookie Settings.
Contact Form and Customer Support
If you contact us through the website or by email, we may process:
- your name
- email address
- message
- order-related information where relevant
Contact form messages are delivered to our customer support inbox.
We use this information only to:
- respond to your enquiry
- provide support
- resolve an issue
- process a request
- maintain necessary correspondence
The legal basis is generally:
- Article 6(1)(b) GDPR where your message relates to a purchase or potential purchase; or
- Article 6(1)(f) GDPR where we rely on our legitimate interest in responding to general enquiries
Email Services and Google
Customer-support email is managed using Google email services.
We may also use Google services internally to manage limited physical-order information.
For operational order tracking, we may maintain a simple internal Google Sheet containing limited information such as:
- order number
- customer name
- email address
- product
- order status
- shipment tracking number
We do not use this internal sheet for marketing or behavioural profiling.
Google may process information internationally in accordance with its own privacy framework. Google states that it relies on adequacy decisions, the EU-U.S. Data Privacy Framework, and Standard Contractual Clauses where applicable.
Physical Book Payments and Stripe
Payments for physical Paperback and Hardcover editions are processed through Stripe.
Stripe may process personal data including:
- name
- billing and payment information
- payment card information
- transaction data
- device and fraud-prevention data
- authentication information
Simple Legumes does not receive or store your full payment card number.
Stripe may act as a processor for certain payment services and as an independent controller for other activities, such as fraud prevention and regulatory compliance.
The legal basis for our use of Stripe to process an order is Article 6(1)(b) GDPR — performance of a contract.
PayPal
PayPal may be available as a payment method within the Stripe checkout flow.
If you choose PayPal, PayPal may process information necessary to complete the transaction, including:
- account information
- payment information
- billing information
- transaction details
- security and fraud-prevention information
PayPal processes personal data in accordance with its own privacy terms.
We receive only the information necessary to confirm and manage the purchase.
Digital PDF Purchases and Paddle
Digital PDF purchases are processed separately through Paddle.
Paddle acts as the Merchant of Record for Digital PDF transactions.
Paddle may process information including:
- name
- payment information
- billing information
- transaction information
- location information
- tax-related information
- fraud-prevention information
Paddle describes itself as a controller for personal data processed in connection with its Merchant of Record activities.
Simple Legumes receives limited information necessary to fulfil the purchase, including:
- customer email address
- Paddle transaction ID
This information is used to deliver the Digital PDF and provide customer support.
The legal basis for our processing is Article 6(1)(b) GDPR — performance of a contract.
Digital Delivery, Supabase and Resend
We use Supabase and Resend as part of the digital-delivery infrastructure.
Supabase
Supabase is used to store product files and support delivery infrastructure.
We do not maintain customer profiles in Supabase as part of this process.
Supabase provides a Data Processing Addendum addressing GDPR and international transfer requirements.
Resend
Resend is used only for transactional emails, including Digital PDF delivery and other service-related emails.
Information processed may include:
- recipient email address
- transaction-related email content
- delivery information
- technical delivery metadata
We do not currently use Resend for marketing emails.
Resend states that a GDPR Article 28 Data Processing Addendum applies to accounts and includes international transfer safeguards such as Standard Contractual Clauses.
Cloudflare
Our website is hosted using Cloudflare Pages and uses Cloudflare infrastructure for website delivery, security, and technical functionality.
Cloudflare may process technical information including:
- IP address
- request information
- browser and device information
- security events
- technical logs
- approximate geographic information
We also use Cloudflare functionality to determine the visitor’s approximate country for regional pricing.
The legal basis for this processing is generally our legitimate interest in operating a secure and functional website under Article 6(1)(f) GDPR.
Cloudflare publishes information about international data transfers, data subject rights, security, and retention in its Privacy Policy.
Shipping and FedEx
Physical books are shipped using FedEx Priority.
To arrange delivery, we may provide FedEx with information necessary for the shipment, including:
- recipient name
- delivery address
- telephone number
- shipment information
- customs-related information where required
Where necessary for delivery notifications or customs processing, FedEx may also process contact information.
The legal basis for providing delivery information is Article 6(1)(b) GDPR — performance of a contract.
FedEx processes shipment-related personal data in accordance with its own privacy notice. FedEx states that for services in Europe, personal data is controlled by FedEx Express International B.V.
Transactional Emails
We may send service-related emails including:
- order confirmations
- payment confirmations
- digital delivery emails
- shipping information
- tracking information
- return or refund communications
- support responses
These emails are necessary to provide the requested service and are not marketing communications.
We currently do not:
- send unsolicited marketing emails
- operate a newsletter
- send abandoned-cart emails
- send back-in-stock notifications
- automatically send review-request emails
If this changes, this Privacy Policy will be updated and additional consent will be obtained where legally required.
We Do Not Sell Personal Data
Simple Legumes does not sell or rent personal data.
We do not provide customer lists to:
- advertising data brokers
- unrelated advertisers
- third parties for their independent direct-marketing purposes
We currently do not upload customer lists to advertising platforms for Custom Audiences, Customer Match, or similar advertising purposes.
Sharing of Personal Data
Depending on the service used, personal data may be shared with or processed by:
- Stripe
- PayPal
- Paddle
- FedEx
- Cloudflare
- Microsoft
- Supabase
- Resend
- professional advisers or public authorities where legally required
We share only the information reasonably necessary for the relevant service.
Some providers may act as processors, while others may act as independent controllers for certain purposes.
International Data Transfers
Some service providers used by Simple Legumes operate globally and may process personal data outside the European Economic Area.
Where required by applicable law, international transfers may rely on mechanisms such as:
- European Commission adequacy decisions
- the EU-U.S. Data Privacy Framework
- Standard Contractual Clauses
- another legally permitted transfer mechanism
Different providers use different transfer mechanisms depending on the processing involved.
For example, Google states that it uses adequacy decisions, the EU-U.S. Data Privacy Framework, and Standard Contractual Clauses where applicable.
Data Retention
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected and for any applicable legal retention period.
Retention depends on the category of information. For example:
Order and Transaction Data
Order and transaction information may be retained for as long as required to:
- fulfil the order
- process refunds or complaints
- establish or defend legal claims
- comply with Czech accounting, tax, and commercial record-keeping requirements
Customer Support Messages
Support correspondence may be retained for as long as reasonably necessary to resolve the request and, where relevant, to maintain evidence relating to an order, dispute, or legal claim.
Physical Order Management Records
Internal operational order records may be retained while required for fulfilment, delivery tracking, customer support, accounting, and legal obligations.
Digital Delivery Information
Digital purchase information necessary to identify and support a Digital PDF purchase may be retained for as long as reasonably necessary to provide access, customer support, protect against abuse, and comply with legal requirements.
Website and Security Logs
Technical and security logs may be retained according to operational, security, and service-provider retention settings.
Consent Records
Cookie and consent preferences may be retained for as long as necessary to remember and demonstrate your privacy choices.
Once information is no longer required, it may be deleted, anonymised, or retained only where continued storage is legally required.
Data Security
We use reasonable technical and organisational measures designed to protect personal data against:
- unauthorised access
- accidental loss
- alteration
- disclosure
- misuse
- destruction
We also rely on established service providers for payments, infrastructure, email, delivery, and digital fulfilment.
However, no electronic transmission or storage system can be guaranteed to be completely secure.
Your Rights Under the GDPR
Where the GDPR applies, you may have the following rights:
- Right of access — Article 15 GDPR
- Right to rectification — Article 16 GDPR
- Right to erasure — Article 17 GDPR
- Right to restriction of processing — Article 18 GDPR
- Right to notification regarding rectification, erasure, or restriction — Article 19 GDPR
- Right to data portability — Article 20 GDPR
- Right to object — Article 21 GDPR
- Right to withdraw consent — Article 7(3) GDPR
- Right to lodge a complaint with a supervisory authority — Article 77 GDPR
These rights are subject to the conditions and exceptions provided by applicable law.
To exercise your rights, contact: support@simplelegumes.com
We may request reasonable information to verify your identity before fulfilling certain requests.
Right to Object
Where we process personal data based on our legitimate interests under Article 6(1)(f) GDPR, you have the right to object to such processing on grounds relating to your particular situation.
If you object, we will stop the relevant processing unless we can demonstrate compelling legitimate grounds that override your rights and interests, or the processing is necessary for the establishment, exercise, or defence of legal claims.
If personal data is ever processed for direct marketing, you have the right to object to such processing at any time.
We currently do not use customer personal data for direct marketing.
Withdrawal of Consent
Where processing is based on consent, you may withdraw that consent at any time.
For website analytics and embedded media, consent can be changed or withdrawn using the “Cookie Settings” link in the website footer.
Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
Right to Lodge a Complaint
If you believe that your personal data has been processed unlawfully, you have the right to lodge a complaint with a competent data protection authority.
Our principal supervisory authority in the Czech Republic is:
Úřad pro ochranu osobních údajů (ÚOOÚ)
Czech Office for Personal Data Protection
The Czech authority accepts complaints relating to alleged breaches of data protection law.
You may also contact us first at support@simplelegumes.com so that we have an opportunity to address your concern.
Automated Decision-Making
Simple Legumes does not itself make decisions based solely on automated processing that produce legal or similarly significant effects on customers.
Payment providers such as Stripe, Paddle, PayPal, or other financial-service providers may use automated fraud-prevention, authentication, or risk systems as part of their own services.
Such processing is governed by the relevant provider’s privacy documentation.
Children’s Privacy
Simple Legumes is not specifically directed at children.
We do not intentionally collect personal data from children for marketing or profiling purposes.
If you believe that personal data relating to a child has been provided to us inappropriately, please contact: support@simplelegumes.com
Sensitive Personal Data
We do not intentionally request or collect special categories of personal data such as:
- medical information
- health conditions
- biometric information
- political opinions
- religious beliefs
- other sensitive personal information
Please do not submit sensitive personal data through the contact form unless it is genuinely necessary for us to respond to your request.
Third-Party Links
The website may contain links to third-party websites or services, including social-media or video platforms.
When you leave simplelegumes.com, the third party’s own privacy terms apply.
Simple Legumes is not responsible for the privacy practices of websites or services that we do not control.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect:
- changes to our services
- changes to providers
- changes to website functionality
- changes to legal requirements
- changes to our privacy practices
The most current version will always be published on this page.
The “Last updated” date at the top shows when the policy was most recently revised.
Where required by law, we will provide additional notice of material changes.
Contact
If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact: support@simplelegumes.com
Simple Legumes is operated by Dmytrii Krapyvianskyi.
Full legal and business identification details are available on our Legal Notice page.