Privacy Policy
Last updated: 19 August 2026
This Privacy Policy explains how Ursa Leather collects, uses, shares and protects your personal data when you visit ursaleather.com or place an order with us. We are committed to handling your data in line with the EU General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act (Personopplysningsloven).
1. Who we are (data controller)
The data controller responsible for your personal data is:
LOISEL HANDEL (trading as Ursa Leather)Organisation number: 935 772 168
Dalsbergstien 22D, 0170 Oslo, Norway
Email: hello@ursaleather.com
2. Personal data we collect
- Identity & contact data: name, email address, shipping and billing address, and phone number (if provided).
- Order data: the products you buy, order value, order history and correspondence about your orders.
- Payment data: payments are processed by Stripe. We receive confirmation of payment and limited details (such as the payment method type and last digits); we do not store your full card number.
- Account data: if you create an account: your login credentials (stored securely) and saved addresses. If you sign in with Google, we receive your name and email from Google.
- Technical & usage data: IP address, browser and device information, and identifiers stored in your browser (see section 6).
- Measurement data: which pages were viewed, roughly where in the world the request came from, and how quickly the page loaded — as counts, with no identifier and nothing stored on your device. If you arrived from one of our adverts, the click reference Google added to the address. See section 6.
- Communications: messages you send us by email or through the site.
- Mailing list data: if you sign up for our mailing list: your email address, the date you signed up, whether you confirmed it, and where you signed up from (the footer form or the checkout page). We keep this as proof that you asked to subscribe.
3. How we use your data
- To process and deliver your orders, take payment and issue refunds.
- To manage your account and provide customer support.
- To send transactional emails (order confirmations, shipping updates, password resets).
- To meet legal and accounting obligations (e.g. bookkeeping and tax records).
- To prevent fraud and keep the site secure.
- To remind you about an unfinished order, if you left items in your cart after giving us your email address at checkout. We send at most one reminder per cart.
- To email you about new products, if you signed up for our mailing list. Signing up sends one email asking you to confirm your address; nothing follows unless you click the link in it. Every email has an unsubscribe link.
- To measure how the shop is used (which pages people reach and where they give up) so we can fix what is not working, and to measure whether our advertising leads to orders. Neither requires identifying you — see section 6.
4. Legal bases for processing
We rely on the following legal bases under the GDPR:
- Performance of a contract: to process and fulfil your orders and manage your account.
- Legal obligation: to keep accounting and tax records.
- Legitimate interests: to secure our site, prevent fraud, improve our service and remind you of an unfinished order, where these interests are not overridden by your rights.
- Consent: for our mailing list. Your consent is the address you entered and the confirmation link you clicked, and you withdraw it from the unsubscribe link in any of those emails; withdrawing does not affect anything done while it was in place. Nothing else on this site asks for consent, because nothing else needs it — we set no analytics or advertising cookies at all.
5. Sharing your data and our processors
We do not sell your personal data. We share it only with service providers (“processors”) who help us run the store, under agreements that require them to protect your data:
- Stripe: payment processing.
- Google: account sign-in (Google OAuth), address autocomplete (Google Maps), and advertising (Google Ads — we report that an advert led to an order, using the click reference described in section 6).
- Resend: sending our emails.
- Web3Forms: delivering messages sent through the contact form.
- Cloudflare: website hosting and content delivery.
- Hetzner: backend server hosting (Germany, EU).
- Backblaze B2: file/image storage.
Some of these providers may process data outside the European Economic Area (EEA). Where that happens, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. We may also disclose data where required by law.
6. Cookies and local storage
We set no analytics or advertising cookies at all, which is why this site asks you nothing when you arrive. There is no cookie bar because there is nothing to ask about: we removed Google Analytics rather than keep asking for permission to run it. What remains is local storage the shop cannot work without, and a measurement tool that identifies nobody. Both are described below.
Always on: local storage
We use your browser's local storage, not cookies, for the few things the shop cannot work without: which basket is yours, which region you are shopping in, roughly which country you are in so we can quote a delivery date and a currency, and, if you are signed in, your session. This is storage you have in effect asked for by using the shop, so it does not require consent. It stays on your device, and you can clear it at any time in your browser settings. Doing so will empty your basket and sign you out.
Measurement, without identifying you
To see whether the shop is working — which pages people reach, where they give up — we use Cloudflare Web Analytics. It is the reason we could remove Google Analytics and the cookie bar along with it:
- It sets no cookies and stores nothing on your device.
- It creates no identifier for you, so one visit cannot be joined to another, today or ever.
- It does not follow you to any other website, because it exists only on this one.
- It records the page, roughly where in the world the request came from, and how quickly the page loaded — as counts, not as a record of a person.
Because none of this is personal data, there is nothing here for you to consent to, and nothing for us to delete on request. That is the trade we made deliberately: we know less about you than an ordinary shop does, and we would rather have that than a banner.
If you arrived from one of our adverts
We advertise on Google. When you click one of our adverts, Google adds a click reference to the web address you land on. We keep that reference in your browser's local storage for up to 90 days, and if you place an order we attach it to that order and tell Google the advert led to a sale. It tells us which adverts are worth paying for. The reference identifies the click, not you: it is not linked to your name or email address on Google's side, we never receive a profile of you in return, and if you do not order it is simply discarded. Clearing your browser storage removes it.
Always on: our providers
Some providers set their own cookies whenever their code runs, because the shop cannot function without them:
- Stripe: payment processing and fraud prevention, on the checkout page.
- Cloudflare: security and delivery of the site itself.
- Google Maps: address autocomplete on the checkout and account pages.
Blocking these may stop checkout from working.
7. How long we keep your data
We keep your personal data only as long as necessary:
- Order and transaction records: retained for at least 5 years to comply with the Norwegian Bookkeeping Act (Bokføringsloven).
- Account data: kept while your account is active; deleted on request or after a prolonged period of inactivity.
- Unfinished baskets: a basket you never checked out with, and the email address attached to it, are kept until you ask us to delete them.
- Messages you send us: kept for as long as we need them to answer you, and for a reasonable period afterwards.
- Mailing list: kept until you unsubscribe. We then keep a record that you unsubscribed, so you cannot be added back by mistake; ask us and we will delete that too. An address that is never confirmed is deleted after one year.
- Measurement data: our web analytics identifies nobody and produces only counts, so there is no visit-level record of you to keep or delete. The click reference from one of our adverts is held in your own browser for at most 90 days, and on an order for as long as the order itself.
8. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you.
- Have inaccurate data corrected.
- Have your data erased (“right to be forgotten”), where applicable.
- Restrict or object to processing.
- Receive your data in a portable format.
- Withdraw consent at any time, where processing is based on consent.
To exercise any of these rights, email us at hello@ursaleather.com. You also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet, datatilsynet.no).
9. Security
We take reasonable technical and organisational measures to protect your data, including encryption in transit (HTTPS) and processing payments through PCI-compliant providers. No method of transmission or storage is completely secure, but we work to protect your information and to notify you and the authorities of any breach where required by law.
10. Contact us
For any privacy question or request, contact us at hello@ursaleather.com or by post at the address above.