
Privacy Policy
Privacy Policy
Last updated: 12 November 2025
This Privacy Policy explains how [NOSTALGIA BOOK ALBUM] (“Nostalgia Book,” “we,” “us,” “our”) collects, uses, discloses, and safeguards your information when you use our website or interact with us via WhatsApp, Instagram, email, or phone.
We are committed to handling your personal data lawfully, fairly, and transparently. This Policy aligns with applicable laws, including Bahrain’s Personal Data Protection Law (PDPL), and, where relevant, other data-protection frameworks.
1) Who controls your data
Data controller: [NOSTALGIA BOOK ALBUM]
Email: [Email]
Phone/WhatsApp: [97334595902]
Data protection contact (if any): [DPO/Representative Email]
2) What we collect
Identity & contact data: name, email, phone/WhatsApp, address.
Order data: theme, product choices, notes, delivery details, payment confirmation (we do not store full card details).
User Content: photos, captions, and any text you send for the book.
Communications: messages via WhatsApp/Instagram/email and call records where applicable.
Technical data: IP address, device/browser type, cookies, analytics events, and approximate location (derived from IP).
Marketing preferences: your choices for newsletters or promotional messages.
3) How we use your data (lawful bases)
To provide services and fulfill orders (contract): design, proofing, printing, delivery, customer support.
To communicate with you (contract/legitimate interests): updates, proofs, queries, support.
To improve our services and website (legitimate interests): analytics, troubleshooting, usability.
To comply with legal obligations (legal obligation): invoicing, tax and regulatory requirements.
Marketing with your consent (consent): newsletters, offers; you can opt out anytime.
4) WhatsApp, Instagram & third-party platforms
If you contact us via WhatsApp or Instagram, those platforms also process your data under their own policies. We recommend reviewing their privacy terms. We keep essential chat history for order tracking and customer support.
5) Payments
Payments are processed by [Payment Provider]. We receive confirmation of payment but do not store full card numbers. Your payment is subject to [Payment Provider]’s privacy and security practices.
6) Sharing your data
We share personal data only as needed to deliver the service:
Print & logistics partners (production and delivery).
Payment provider (to process your payment).
IT/service providers (hosting, email, analytics, CRM).
Legal/regulatory authorities (when required by law).
We require all partners to protect your data and use it only for the specified purpose.
7) International transfers
If we transfer your data outside the Kingdom of Bahrain, we take appropriate safeguards (e.g., contractual protections) to protect your information in line with PDPL requirements.
8) Data retention
We keep your data only as long as necessary:
Orders & invoices: [X] years to meet legal obligations.
Design files & User Content: [X] months/years after delivery to facilitate reprints/edits (you can ask us to delete earlier, unless we must retain for legal reasons).
Marketing data: until you unsubscribe or request deletion.
9) Your rights
Subject to applicable law, you may have the right to:
Access your personal data;
Rectify inaccurate or incomplete data;
Erase data (when no longer necessary or if processed unlawfully);
Restrict processing in certain circumstances;
Object to processing based on legitimate interests or direct marketing;
Withdraw consent at any time (for processing based on consent);
Portability (receive your data in a structured, machine-readable format).
To exercise your rights, contact [Email]. You may also lodge a complaint with the Personal Data Protection Authority (Kingdom of Bahrain).
10) Children’s data
Our services are intended for customers 18+. If you believe we have collected data from a minor without appropriate consent, contact us to delete it.
11) Security
We use reasonable technical and organizational measures to protect personal data. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.
12) Cookies & analytics
We use cookies/analytics to run the site and understand usage. You can control cookies via your browser settings. Disabling non-essential cookies may affect site performance. See [Link to Cookie Notice] for details.
13) Marketing preferences
We send marketing communications only with your consent or as permitted by law. You can unsubscribe at any time via the message footer or by contacting [Email].
14) Changes to this Policy
We may update this Policy occasionally. The “Last updated” date reflects the latest changes.
15) Contact
Questions about privacy? Email [Email] or message us on [97334595902].