Privacy policy

Last updated: 6 May 2026

This Privacy Policy explains how Sole Proprietor MALYKHIN OLEKSANDR PAVLOVYCH (Tax ID: 3575106056), trading as Optimus Gang / OG (the “Seller”, “we”, “us” or “our”), collects, uses, discloses and protects your personal information when you visit, use or make a purchase through the website at optimus-gang-store.myshopify.com and any related online stores or services (the “Services”). The Services are powered by Shopify Inc.

This Policy is published in accordance with the Law of Ukraine “On Personal Data Protection”, Article 11 of the Law of Ukraine “On Information”, the General Data Protection Regulation 2016/679 (the “GDPR”) for visitors located in the European Economic Area, the UK GDPR, and applicable consumer-privacy laws in other jurisdictions.

By using the Services you acknowledge that you have read this Policy and understand the collection, use and disclosure of your information as described below. If you do not agree with this Policy, please do not use the Services.

1. Data Controller

The data controller for the personal information collected through the Services is:

Sole Proprietor MALYKHIN OLEKSANDR PAVLOVYCH
Tax Identification Number: 3575106056
Address: Yuriya Shums’koho Street, 6, Ukraine
Email: customerservice@optimusgang.com

2. Personal Information We Collect

We may collect or process the following categories of personal information depending on how you interact with the Services and where you live:

2.1. Information you provide directly

  • Contact details: name, surname, email address, phone number, billing and shipping addresses.
  • Order details: items purchased, order amount, currency, order history, preferences (sizes, colours), gift messages.
  • Account details (if you create an account): username, password (stored in hashed form by Shopify), saved addresses, wish-lists.
  • Payment information: card type, last four digits of the card, billing postcode and similar data needed to process the transaction. Full card numbers, expiry dates and CVV codes are entered directly into our payment processor and are not stored on our servers.
  • Communications: messages, complaints, returns requests and any other content you submit when contacting us.
  • Marketing preferences: your opt-in or opt-out choices for newsletters and promotional messages.

2.2. Information collected automatically

  • Usage and device data: IP address, browser type and version, operating system, device identifiers, language preferences, referring URL, pages and products viewed, click stream, session duration.
  • Cookies and similar technologies: see Section 7 below.
  • Geolocation data: approximate location derived from your IP address.

2.3. Information from third parties

  • Payment processors: confirmation that payment has been received or declined, fraud-prevention scores.
  • Shipping carriers: tracking numbers, delivery status updates.
  • Social-media platforms: if you interact with us via social-media buttons or log-in, we receive limited profile information consistent with your privacy settings on those platforms.
  • Analytics and advertising partners: aggregated reports about visitors and the performance of our marketing.

3. How We Use Personal Information

We use personal information for the following purposes:

  • Order fulfilment: to process and ship your orders, send order confirmations, manage returns, exchanges and refunds, and communicate with you about your orders.
  • Customer support: to respond to your questions, complaints and requests.
  • Account management: to create and maintain your account and authenticate you.
  • Personalisation and analytics: to understand how customers use the Services and to improve product offerings, store performance and user experience.
  • Marketing and advertising: to send newsletters, promotional offers and product updates — but only with your consent or where otherwise permitted by law — and to measure the performance of our advertising. You can withdraw consent at any time (see Section 9).
  • Fraud prevention and security: to detect, investigate and prevent fraudulent activity, abuse of the Services and security incidents.
  • Legal compliance: to comply with applicable laws, court orders and lawful requests by public authorities, and to protect our rights and the rights of others.

4. Legal Bases (GDPR / EU Visitors)

If you are located in the European Economic Area or the United Kingdom, we rely on the following legal bases:

  • Performance of a contract — to fulfil your order and provide the Services you have requested.
  • Legitimate interests — to operate, improve and protect our business, including analytics, fraud prevention and direct communications about similar products you have already purchased.
  • Consent — for marketing emails, certain cookies and any processing where consent is required by law. You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
  • Legal obligation — to comply with tax, accounting, anti-money-laundering and other obligations.

5. How We Share Personal Information

We do not sell your personal information. We may share it in the following circumstances:

  • Service providers acting on our behalf, including:
    • Shopify Inc. — e-commerce platform that hosts the store, processes orders and provides analytics;
    • payment processors — to authorise and complete your transactions (including, but not limited to, the Hutko payment gateway);
    • shipping carriers — LLC “Nova Poshta” for deliveries within Ukraine and JSC “Ukrposhta” for international deliveries, plus any other carrier you choose at checkout;
    • email and SMS providers — to send transactional and marketing communications;
    • analytics and advertising providers — to measure traffic and the effectiveness of our marketing.
  • Professional advisors — lawyers, accountants and auditors, where necessary.
  • Authorities — when required by law, court order or other legal process.
  • Business transfers — in the context of a merger, sale or transfer of all or part of our business, subject to confidentiality obligations.
  • With your consent — for any other purpose disclosed at the time we collect the information.

We require all service providers to use personal information only as necessary to provide their services to us and in accordance with applicable law.

6. International Transfers

The Services use Shopify infrastructure, which may store and process personal information on servers located outside Ukraine, including in Canada, the United States and the European Union. Where personal information of EU/UK residents is transferred to a country that has not been recognised as providing an adequate level of data protection, we rely on appropriate safeguards such as the Standard Contractual Clauses approved by the European Commission.

7. Cookies and Similar Technologies

We use cookies, pixels, local storage and similar technologies to operate the Services, remember your preferences, secure your account, analyse usage and personalise content and ads.

  • Strictly necessary cookies are required for core functionality (e.g. cart, checkout, login). They cannot be disabled.
  • Analytics cookies help us understand how visitors use the site so we can improve it.
  • Marketing cookies may be set by us or our advertising partners to deliver and measure relevant ads on third-party sites.

You can control non-essential cookies through our cookie banner (where available) and through your browser settings. Note that disabling certain cookies may affect the functionality of the Services.

8. Data Retention

We keep personal information only for as long as is necessary for the purposes described in this Policy, including:

  • Order and transaction records: for as long as required by tax, accounting and consumer-protection laws of Ukraine (typically not less than 3 years and up to 5 years).
  • Account data: for the duration of your account plus a reasonable retention period afterwards, unless you request earlier deletion.
  • Marketing data: until you withdraw consent or unsubscribe.
  • Server logs and analytics data: typically up to 26 months in aggregated or pseudonymised form.

9. Your Rights

Subject to applicable law, you have the right to:

  • access your personal information and obtain a copy;
  • request correction of inaccurate or incomplete information;
  • request deletion (“right to be forgotten”) where applicable;
  • restrict or object to certain processing, including direct marketing;
  • data portability;
  • withdraw consent where processing is based on consent;
  • lodge a complaint with the Ombudsman of the Verkhovna Rada of Ukraine for Human Rights (the supervisory authority for personal-data protection in Ukraine) or, if you are an EU/UK resident, with your local data-protection authority.

To exercise any of these rights, please contact us at customerservice@optimusgang.com. We may need to verify your identity before responding.

10. Children

The Services are not directed to children under the age of 14. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.

11. Security

We implement reasonable technical and organisational measures designed to protect your personal information against unauthorised access, loss, misuse or alteration. Communication on our checkout pages is encrypted using TLS. However, no method of transmission over the Internet or electronic storage is 100% secure.

12. Changes to This Policy

We may update this Policy from time to time. The “Last updated” date at the top of the page indicates when changes were last made. Material changes will be highlighted on the Services or notified to you by email where appropriate.

13. Contact

If you have any questions about this Policy or our handling of your personal information, please contact:

Sole Proprietor MALYKHIN OLEKSANDR PAVLOVYCH
Tax Identification Number: 3575106056
Address: Yuriya Shums’koho Street, 6, Ukraine
Email: customerservice@optimusgang.com