Privacy Policy
Updated: 16 August 2026
This policy explains what personal data we collect through the Vestho platform, why we collect it, who we disclose it to, and what rights you have, in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Romanian law.
1. Who the data controller is
The controller of your personal data is BEAU ROMANIA SRL, with VAT no. 50630070, registered with the Trade Registry under J2024027087006, with its registered address at Str. Doftanet nr. 201, sat Bustenari, comuna Bustenari, județul Prahova, cod poștal 107602, România ("Vestho", "we").
We have not appointed a Data Protection Officer (DPO), as our activity does not fall under Art. 37 GDPR. Any request regarding your data should be sent to contact@vestho.ro.
2. What data we collect
We only collect the data necessary to create your account, process your orders, and provide you with support. The categories of data are:
- Account data: your email address and password (stored encrypted, not in plain text).
- Profile data: name, phone number, and your preference regarding receiving marketing communications — both optional, filled in by you after account creation.
- Delivery data: the recipient's name, address (street, city, county, postal code), and phone number, collected for each order.
- Payment data: your card is processed directly by Stripe, our payment processor; we never see or store your card number, only an internal transaction identifier.
- Review data: the rating given, the review text, and, if you choose to add them, photos of the product.
- Data provided if you apply as a brand: the brand name, description, category, contact details, and a sample photo; if approved, the bank details for payments are collected directly by Stripe Connect, not by us.
- Communications: the messages you send us through support or the contact form.
3. Special categories of data
We do not request and do not intentionally process data in the special categories set out in Art. 9 GDPR (racial or ethnic origin, religious beliefs, health data, sexual orientation, etc.). Please do not include such information in reviews, photos, or messages sent to support.
4. Purposes and legal grounds
We process your data only for the purposes below, each with a distinct legal basis (Art. 6 GDPR):
- Creating and managing your account, processing orders, and related communication — performance of a contract (Art. 6(1)(b)).
- Issuing invoices and keeping accounting records — legal obligation (Art. 6(1)(c)).
- Preventing payment fraud and securing the platform — legitimate interest (Art. 6(1)(f)), balanced against your interests.
- Debugging technical errors and, if you choose to accept it, anonymized visual session monitoring to reproduce errors — legitimate interest, respectively consent (Art. 6(1)(f), Art. 6(1)(a)).
- Sending marketing communications — only with your explicit consent, which you may withdraw at any time (Art. 6(1)(a)).
5. Who we disclose data to
We do not sell your data. We disclose it only to the partners strictly necessary to deliver your order and operate the platform:
- The Brands you buy from receive the delivery data needed to ship your order; each Brand acts as an independent controller for the data it receives for this purpose, under its own privacy policy. We recommend checking a Brand's policy if you have questions about how it uses the delivery data it receives.
- Stripe (payment processing and, for Brands, payment of the commission and amounts owed through Stripe Connect) — Stripe Payments Europe, Ltd.
- Resend (sending transactional emails: order confirmation, shipping, brand application).
- Sentry (technical error monitoring; we do not send your IP address or request content to Sentry by default).
- Public authorities, when required by law (for example tax or judicial bodies).
6. Public visibility of reviews
Reviews shown on a product page include only the rating, the review text, and, if you chose to add them, photos — without your name or other information that could directly identify you. The review remains linked to your account in our internal records, so that we can respond to any complaints.
7. Transfers outside the European Economic Area
Some of the providers listed above (Stripe, Resend, Sentry) may process data outside the EEA, including in the United States. These transfers are carried out under the Standard Contractual Clauses approved by the European Commission (Art. 46(2)(c) GDPR) or another recognized mechanism, such as the EU-US Data Privacy Framework, where applicable.
8. How long we keep your data
Account and profile data are kept for as long as your account is active, plus a reasonable period after closure, to respond to any disputes.
Documents underlying accounting records (invoices, proof of payment) are kept for 10 years, in accordance with Accounting Law no. 82/1991.
Reviews remain publicly visible for as long as your account is active, unless you request their deletion.
Technical error logs (Sentry) are kept according to the provider's retention policy, typically a few months, solely for debugging purposes.
Data related to cookies is detailed in the Cookie Policy.
9. Your rights
Regarding your data, you have the right to access, rectify, erase, restrict, port, and object, as well as the right to withdraw your consent at any time, without affecting the lawfulness of processing carried out before the withdrawal (Art. 15-22 GDPR).
You can exercise these rights by writing to us at contact@vestho.ro; we respond within one month of receiving the request, a period that may be extended by up to two additional months for complex requests, in which case we will inform you of the reason for the extension (Art. 12(3) GDPR). We may ask you for additional information to confirm your identity before acting on your request.
You also have the right to file a complaint with the National Supervisory Authority for Personal Data Processing (www.dataprotection.ro), if you consider that the processing infringes your rights.
10. Cookies
How we use cookies is detailed separately in the Cookie Policy.
11. Data security
We apply appropriate technical and organizational measures (Art. 32 GDPR): traffic is encrypted via TLS, passwords are stored encrypted, and access to the database is restricted through row-level security policies, so that each user can only access their own data.
12. Data breach notification
If a personal data breach occurs that poses a risk to your rights and freedoms, we will notify the National Supervisory Authority for Personal Data Processing within 72 hours of becoming aware of it, in accordance with Art. 33 GDPR, and we will inform you directly, without undue delay, when the incident poses a high risk to you, in accordance with Art. 34 GDPR.
13. Automated decisions
We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR).
14. Minors
The Platform is not directed at minors under 16. If you are under 16, you may only create an account with the consent of a parent or legal guardian (Art. 8 GDPR).
15. Changes to this policy
We may update this policy to reflect legal or operational changes. The date of the last update is shown at the top of this document; significant changes will be communicated to you.
16. Contact
For any question about your data, you can write to us at contact@vestho.ro or at Str. Doftanet nr. 201, sat Bustenari, comuna Bustenari, județul Prahova, cod poștal 107602, România.