Privacy policy

PRIVACY POLICY

Last updated: September 2026

VelitFit Ltd. ("we", "us", "our") operates the website and online store velit.fit. This policy explains how we collect, use and protect your personal data.

1. Data controller

VelitFit Ltd. (ВелитФит ЕООД)
Company ID (ЕИК): BG208648905
Address: 121 Zapaden Park, entr. V, fl. 3, apt. 9, Sofia, Bulgaria
Email: 

2. What data we collect

Data you give us directly:

  • Full name
  • Email address
  • Phone number
  • Delivery and billing address
  • Payment details (processed securely by a payment provider — we do not store card numbers)
  • Messages and correspondence with us

Data collected automatically when you visit the site:

  • IP address, browser type and device
  • The pages you visit and the time of your visit
  • Actions on the site (clicks, scrolling, adding to cart)
  • Session recordings and heatmaps (only with your consent, via Microsoft Clarity and Mouseflow)
  • Advertising and conversion data (only with your consent, via the Meta Pixel and the OpenAI advertising pixel)
  • Hashed identifiers used to match conversions — your email address and phone number, irreversibly converted using SHA-256 inside your browser before they leave the site (only with your consent to marketing)

3. Legal basis for processing (GDPR)

We process your data only where we have a valid legal basis:

  • Contract — to process orders, deliver them and issue invoices
  • Legal obligation — for accounting and tax law
  • Legitimate interest — for security and fraud prevention
  • Consent — for marketing, analytics cookies and tracking tools (Meta Pixel, Microsoft Clarity, Mouseflow, OpenAI advertising pixel)

4. What we use the data for

  • Processing, confirming and delivering orders
  • Communicating with customers (email, phone)
  • Issuing invoices and meeting our accounting obligations
  • Improving the experience on the site
  • Analysing visitor behaviour (only with consent)
  • Measuring the results of our advertising and showing personalised ads and remarketing on Facebook, Instagram and ChatGPT (only with consent)
  • Protecting against fraud and abuse

5. Third-party tools

Meta (Facebook) Pixel — ID: 2756571474677216

We use the Meta Pixel to measure advertising, build audiences and run remarketing. The pixel is activated only with your explicit consent. Without consent, no data is collected.

  • Data: IP address, browser identifiers, on-site behaviour, conversions and, where advanced matching is enabled, an irreversibly hashed (SHA-256) email address and phone number
  • How it is transmitted: through the browser (pixel) and server-to-server (Conversions API via the Shopify platform)
  • Controller: Meta Platforms Ireland Ltd., Dublin, Ireland
  • Privacy policy: https://www.facebook.com/privacy/policy/
  • Cookies: _fbp (3 months), _fbc (2 years), fr (3 months)

Microsoft Clarity

We use Microsoft Clarity for session recordings, heatmaps and behavioural analysis. It is activated only with your explicit consent. Without consent, no data is collected.

  • Data: on-site behaviour, clicks, scrolling (no names, emails or direct identifiers — fields containing personal data are masked)
  • Data is stored on Microsoft servers in the USA
  • Transfer safeguard: EU–US Data Privacy Framework (EC adequacy decision, July 2023)
  • Privacy policy: https://privacy.microsoft.com/
  • Cookies: _clck (1 year), _clsk (1 day), _clgs (session)

Mouseflow

We use Mouseflow to record anonymised sessions, build heatmaps and funnels, and identify where visitors run into difficulty. Cursor movement, scrolling, clicks and the sequence of pages visited are recorded. The tool is activated only with your explicit consent. Without consent, no data is collected.

  • Data: on-site behaviour, clicks, scrolling, cursor movement, technical data about your device and browser
  • We have configured the tool with input-field masking — the contents of text fields, passwords and payment details are not recorded
  • Provider: Mouseflow ApS, Copenhagen, Denmark — acting as a processor on our behalf under a Data Processing Agreement (DPA)
  • Data belonging to EU customers is stored on servers within the European Union
  • Privacy policy: https://mouseflow.com/legal/privacy/
  • Opt out of recording: https://mouseflow.com/opt-out/
  • Cookies: mf_user (up to 1 year), mf_[site identifier] (session)

OpenAI advertising pixel (ChatGPT ads)

We use the OpenAI advertising pixel ("OpenAI Ads pixel") to measure the results of our ads shown inside ChatGPT and to run remarketing. The pixel is activated only with your explicit consent. Without consent, no data is collected.

  • Data: ad click identifier, the address of the page visited, on-site events (product view, add to cart, order), order value and contents, technical data about your browser and device
  • If advanced matching is enabled, your email address and phone number are irreversibly hashed (SHA-256) inside your browser and only the hash is transmitted to OpenAI, never the data in readable form
  • How it is transmitted: through the browser (pixel) and, where applicable, server-to-server (Conversions API)
  • Controller: OpenAI Ireland Limited, Dublin, Ireland — for EEA and Swiss data. For its advertising tools OpenAI acts as an independent controller, not as a processor on our behalf
  • Transfer safeguard: Standard Contractual Clauses (SCCs) under OpenAI's Ad Tools Data Processing Addendum
  • Privacy policy: https://openai.com/policies/eu-privacy-policy/
  • Cookies: __oppref (30 days)

Shopify (platform)

The store is built on Shopify. Shopify acts as a processor on our behalf under a Data Processing Agreement (DPA). Shopify is certified under the EU–US Data Privacy Framework.

6. Cookies

Strictly necessary cookies (no consent required — needed for the store to work):

  • _session_id — store session (Shopify, expires at the end of the session)
  • cart — cart contents (Shopify, 2 weeks)
  • secure_customer_sig — customer authentication (Shopify)
  • storefront_digest — access protection (Shopify)

Analytics cookies (consent required):

  • _clck — Clarity visitor identifier (Microsoft, 1 year)
  • _clsk — links sessions in Clarity (Microsoft, 1 day)
  • _clgs — Clarity session data (Microsoft, end of session)
  • mf_user — Mouseflow browser identifier (Mouseflow, up to 1 year)
  • mf_[site identifier] — identifier of the current Mouseflow session (Mouseflow, end of session)

Marketing cookies (consent required):

  • _fbp — identification for Meta ads (Meta, 3 months)
  • _fbc — tracking of clicks from ads (Meta, 2 years)
  • fr — ad delivery frequency (Meta, 3 months)
  • __oppref — identifier of a click from a ChatGPT ad (OpenAI, 30 days)

Managing cookies: On your first visit you will see a banner where you can accept, reject or customise your choice. You can change your settings at any time using the icon in the bottom left corner of the site. Under Art. 7(3) GDPR you have the right to withdraw your consent at any time, as easily as you gave it.

7. Disclosure to third parties

We share personal data only where necessary:

  • Shopify — hosting and order management (processor, DPA in place)
  • Payment providers — to process payments
  • Courier companies — to carry out deliveries
  • Mouseflow — only where consent to analytics has been given (processor, DPA in place)
  • Microsoft — only where consent to analytics has been given
  • Meta Platforms — only where consent to marketing has been given
  • OpenAI — only where consent to marketing has been given. For its advertising tools OpenAI processes the data as an independent controller for its own purposes, including measuring and improving its advertising services, in accordance with its own privacy policy
  • Competent authorities — only where legally required

We do not sell or rent out your data to third parties for their own marketing purposes.

8. International data transfers

Some providers process data outside the EU:

  • Mouseflow (Denmark) — data belonging to EU customers is stored within the EU; Standard Contractual Clauses and the EU–US Data Privacy Framework apply to any sub-processors outside the EU
  • Shopify (Canada/USA) — EU–US Data Privacy Framework + Standard Contractual Clauses
  • Microsoft (USA) — EU–US Data Privacy Framework (EC decision, July 2023)
  • Meta (USA/Ireland) — EU–US Data Privacy Framework + Standard Contractual Clauses
  • OpenAI (USA/Ireland) — Standard Contractual Clauses; the controller for the EEA is OpenAI Ireland Limited

9. Retention periods

  • Order and invoice data — 10 years (accounting legislation)
  • Customer account — until deletion, or 3 years after the last activity
  • Email correspondence — 3 years
  • Consent records (logs) — 5 years
  • Clarity sessions — up to 13 months (Microsoft's policy)
  • Mouseflow recordings and heatmaps — up to 12 months
  • Meta Pixel data — up to 180 days (Meta's policy)
  • OpenAI advertising pixel data — in accordance with OpenAI's retention policy

10. Your rights

Under the GDPR you have the following rights:

  • Right of access (Art. 15) — to receive a copy of the data we hold about you
  • Right to rectification (Art. 16) — to have inaccurate data corrected
  • Right to erasure (Art. 17) — the "right to be forgotten", subject to certain conditions
  • Right to restriction (Art. 18) — to limit how your data is processed
  • Right to portability (Art. 20) — to receive your data in a machine-readable format
  • Right to object (Art. 21) — to processing based on legitimate interest
  • Right to withdraw consent (Art. 7(3)) — at any time, without affecting processing carried out beforehand

To exercise your rights:  — we respond within 30 days.

Supervisory authority in Bulgaria: Commission for Personal Data Protection (CPDP)
Address: 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, Bulgaria
Website: https://www.cpdp.bg
Email: 

11. Security

We apply the following protective measures:

  • SSL/TLS encryption of all communications
  • Shopify PCI DSS Level 1 compliance for payments
  • Masking of fields containing personal data in session-recording tools
  • Restricted access to personal data — authorised persons only
  • In the event of a security breach we notify the CPDP within 72 hours (Art. 33 GDPR)

12. Children

Our services are not intended for persons under 18. If we discover that we have collected a child's data without parental consent, we delete it immediately.

13. Changes to this policy

We will notify you by email or through a notice on the site of any material changes. The current version, together with the date it was last updated, is always available on this page.

14. Contact

VelitFit Ltd.
Email: 
Address: 121 Zapaden Park, entr. V, fl. 3, apt. 9, Sofia, Bulgaria