Privacy Policy
Last updated: 1 August 2026
This Privacy Policy explains how Ursa Leather collects, uses, shares and protects your personal data when you visit ursaleather.com or place an order with us. We are committed to handling your data in line with the EU General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act (Personopplysningsloven).
1. Who we are (data controller)
The data controller responsible for your personal data is:
LOISEL HANDEL (trading as Ursa Leather)Organisation number: 935 772 168
Dalsbergstien 22d, 0170 Oslo, Norway
Email: hello@ursaleather.com
2. Personal data we collect
- Identity & contact data — name, email address, shipping and billing address, and phone number (if provided).
- Order data — the products you buy, order value, order history and correspondence about your orders.
- Payment data — payments are processed by Stripe. We receive confirmation of payment and limited details (such as the payment method type and last digits); we do not store your full card number.
- Account data — if you create an account: your login credentials (stored securely) and saved addresses. If you sign in with Google, we receive your name and email from Google.
- Technical & usage data — IP address, browser and device information, and identifiers stored in your browser (see section 6).
- Analytics & advertising data — if you accept cookies: which pages you viewed, which products you looked at, and how far you got through checkout, together with a random identifier that lets us tell one visit from another. See section 6.
- Communications — messages you send us by email or through the site.
3. How we use your data
- To process and deliver your orders, take payment and issue refunds.
- To manage your account and provide customer support.
- To send transactional emails (order confirmations, shipping updates, password resets).
- To meet legal and accounting obligations (e.g. bookkeeping and tax records).
- To prevent fraud and keep the site secure.
- To remind you about an unfinished order, if you left items in your cart after giving us your email address at checkout. We send at most one reminder per cart.
- If you accept cookies: to measure how the shop is used — which pages people visit and where they abandon checkout — so we can fix what is not working, and to measure whether our advertising leads to orders.
4. Legal bases for processing
We rely on the following legal bases under the GDPR:
- Performance of a contract — to process and fulfil your orders and manage your account.
- Legal obligation — to keep accounting and tax records.
- Legitimate interests — to secure our site, prevent fraud, improve our service and remind you of an unfinished order, where these interests are not overridden by your rights.
- Consent — for analytics and advertising cookies only. We ask before setting any, nothing depends on your answer, and you can withdraw it at any time from Cookie settings in the footer without giving a reason. Withdrawing does not affect anything done while consent was in place.
5. Sharing your data and our processors
We do not sell your personal data. We share it only with service providers ("processors") who help us run the store, under agreements that require them to protect your data:
- Stripe — payment processing.
- Google — account sign-in (Google OAuth), address autocomplete (Google Maps), and, if you accept cookies, website measurement and advertising (Google Analytics and Google Ads).
- Resend — sending our emails.
- Web3Forms — delivering messages sent through the contact form.
- Cloudflare — website hosting and content delivery.
- Hetzner — backend server hosting (Germany, EU).
- Backblaze B2 — file/image storage.
Some of these providers may process data outside the European Economic Area (EEA). Where that happens, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. We may also disclose data where required by law.
6. Cookies and local storage
Analytics and advertising cookies are off until you switch them on. The first time you visit, a bar at the bottom of the page asks, offering Accept and Reject as equal choices — nothing is stored to measure you unless you accept, and the shop works exactly the same either way. You can change your answer at any time from Cookie settings in the footer.
Always on: local storage
We use your browser's local storage — not cookies — for the few things the shop cannot work without: which basket is yours, which region you are shopping in, whether you accepted cookies, and, if you are signed in, your session. This is storage you have in effect asked for by using the shop, so it does not require consent. It stays on your device, and you can clear it at any time in your browser settings — doing so will empty your basket and sign you out.
Only with your consent: analytics and advertising
We use Google Analytics 4 to see how the shop is used, and Google Ads to see whether our advertising leads to orders. If you accept, Google sets these cookies:
_gaand_ga_<id>— tell one visitor apart from another, so we can count how many people reach each step of checkout. Up to 2 years._gid— the same, over a single day. 24 hours._gcl_au— records that you arrived from one of our adverts, so we can tell which adverts lead to orders. 90 days.
We use these to count and compare, not to build a picture of you as a person. We do not send Google your name, email address or postal address, and we do not use this data to make any decision about you individually.
If you reject, none of those cookies are set. Google's tag still registers that a page was viewed, but without any identifier, so the visit cannot be linked to you or to anything you do later. This is Google's consent mode, and it is what lets us count visits in the aggregate without tracking anyone who said no. Choosing Reject from Cookie settings after having accepted also deletes the cookies listed above.
Always on: our providers
Some providers set their own cookies whenever their code runs, because the shop cannot function without them:
- Stripe — payment processing and fraud prevention, on the checkout page.
- Cloudflare — security and delivery of the site itself.
- Google Maps — address autocomplete on the checkout and account pages.
Blocking these may stop checkout from working.
7. How long we keep your data
We keep your personal data only as long as necessary:
- Order and transaction records — retained for at least 5 years to comply with the Norwegian Bookkeeping Act (Bokføringsloven).
- Account data — kept while your account is active; deleted on request or after a prolonged period of inactivity.
- Unfinished baskets — a basket you never checked out with, and the email address attached to it, are kept until you ask us to delete them.
- Messages you send us — kept for as long as we need them to answer you, and for a reasonable period afterwards.
- Analytics data — visit-level data held by Google Analytics is deleted automatically after at most 14 months. The aggregate reports built from it (visitor counts and the like) contain nothing that identifies you and are kept longer.
8. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you.
- Have inaccurate data corrected.
- Have your data erased ("right to be forgotten"), where applicable.
- Restrict or object to processing.
- Receive your data in a portable format.
- Withdraw consent at any time, where processing is based on consent.
To exercise any of these rights, email us at hello@ursaleather.com. You also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet, datatilsynet.no).
9. Security
We take reasonable technical and organisational measures to protect your data, including encryption in transit (HTTPS) and processing payments through PCI-compliant providers. No method of transmission or storage is completely secure, but we work to protect your information and to notify you and the authorities of any breach where required by law.
10. Contact us
For any privacy question or request, contact us at hello@ursaleather.com or by post at the address above.