Privacy Policy
Privacy Policy
Effective date: 11 February 2026
Last updated: 11 February 2026
This Privacy Policy explains how ROCKET SCIENCE SIA (“we”, “us”, “our”) collects, uses, shares, and protects personal data when you visit and use itkkit.com (the “Website”) and purchase our products.
- 1) Data Controller
- 2) Personal data we collect
- 3) Why we use your data and legal bases (GDPR)
- 4) Who we share data with
- 5) International transfers
- 6) How long we keep your data
- 7) Your rights
- 8) Cookies and similar technologies
- 9) Automated decision-making and profiling
- 10) Security
- 11) Complaints
- 12) Children
- 13) Changes to this Policy
1) Data Controller
Controller: ROCKET SCIENCE SIA
Registration No.: 40103829035
Address: Zigfrīda Annas Meierovica bulvāris 18, LV-1050, Rīga, Latvia
Email: [email protected]
If you have questions about this Privacy Policy or your personal data, contact us by email.
2) Personal data we collect
A. Data you provide directly
- Account data (if you create an account): name, email, password (stored in hashed form), account preferences.
- Order data: name, phone number, email, billing/shipping address, ordered items, order history, returns/exchanges.
- Customer support communications: messages you send us and information you provide to resolve issues.
- Marketing preferences: email/SMS subscription status and communication preferences.
B. Payment data
Payments on our Website are processed by Stripe and PayPal. We receive payment-related information such as payment status, transaction/reference identifiers, and (where applicable) limited payment metadata (e.g., last four digits). We do not store full payment card details on our servers.
C. Data collected automatically
- Device and usage data: IP address, browser type, device identifiers, pages viewed, timestamps, referral URL, approximate location (derived from IP), and similar log data.
- Cookies and similar technologies: see Section 8.
D. Data from third parties
- Delivery and logistics partners (FedEx, DHL, DPD, EMS): delivery status updates, tracking events, and delivery issue details where relevant.
- Analytics/advertising providers (Google Analytics 4 and Meta Pixel): analytics and measurement information, depending on your cookie choices and device settings.
3) Why we use your data and legal bases (GDPR)
Where GDPR applies, we process personal data for the purposes below:
- To operate the Website and fulfill orders
Processing purchases, shipping, returns/exchanges, customer service, and account management.
Legal basis: performance of a contract (GDPR Art. 6(1)(b)). - To process payments and prevent fraud / ensure security
Payment verification, fraud screening, security monitoring, and abuse prevention.
Legal basis: legitimate interests (Art. 6(1)(f)) and/or performance of a contract (Art. 6(1)(b)). - To comply with legal obligations
Accounting, tax, consumer protection obligations, and responding to lawful requests from authorities.
Legal basis: legal obligation (Art. 6(1)(c)). - To improve our Website, products, and services
Analytics, performance monitoring, troubleshooting, and user experience improvements.
Legal basis: legitimate interests (Art. 6(1)(f)) and/or consent for certain cookies (Art. 6(1)(a)). - To send marketing communications (email and SMS)
We use Mailchimp for email and SMS marketing communications, where you have opted in and/or where permitted by applicable law.
Legal basis: consent (Art. 6(1)(a)) and, where permitted, legitimate interests (Art. 6(1)(f)).
You can opt out of marketing at any time using the unsubscribe link in emails, by following opt-out instructions in SMS messages, or by contacting us.
4) Who we share data with
We share personal data only as necessary for the purposes described above:
Service providers (processors)
- Payment processors: Stripe, PayPal (payment processing, disputes/chargebacks handling, fraud prevention).
- Email/SMS marketing platform: Mailchimp (newsletter and SMS distribution, subscription management, and related reporting).
- Delivery and logistics providers: FedEx, DHL, DPD, EMS (shipping and delivery tracking).
- Analytics/advertising tools: Google Analytics 4, Meta Pixel (measurement and analytics, subject to your cookie choices).
- IT, hosting, and security providers: infrastructure and security services used to operate and protect the Website.
Professional advisers
- Auditors, accountants, and lawyers where necessary for compliance and defense of claims.
Authorities
- Public authorities, regulators, and law enforcement where required by law.
We do not sell your personal data.
5) International transfers
Some of our service providers may process personal data outside the European Economic Area (EEA). Where this occurs, we use appropriate safeguards such as Standard Contractual Clauses (SCCs) and, where required, additional measures to protect your personal data.
6) How long we keep your data
We retain personal data only as long as necessary for the purposes described in this Policy, including:
- Orders, invoices, and accounting records: retained for the period required by applicable tax/accounting laws.
- Account data: retained while your account is active; you may request deletion (subject to legal retention requirements).
- Customer support communications: retained as needed to handle your request and for a reasonable period for quality, training, and dispute handling.
- Marketing data: retained until you unsubscribe/opt out or withdraw consent.
- Security and technical logs: retained for a reasonable period to ensure security and prevent fraud.
7) Your rights
Where GDPR applies, you have the right to:
- access your personal data;
- rectify inaccurate or incomplete data;
- request erasure (in certain circumstances);
- restrict processing (in certain circumstances);
- receive your data in a portable format (for data processed based on contract/consent);
- object to processing based on legitimate interests;
- withdraw consent at any time (where processing is based on consent);
- lodge a complaint with a supervisory authority (see Section 11).
To exercise your rights, contact us at [email protected].
8) Cookies and similar technologies
We use cookies and similar technologies for:
- Strictly necessary functions (shopping cart, security, core website functionality);
- Preferences (e.g., language and user settings);
- Analytics (Google Analytics 4) to understand usage and improve the Website;
- Marketing/measurement (Meta Pixel) to measure ad performance and support relevant advertising.
You can manage cookies through your browser settings. Where required by law, we request consent before using non-essential cookies. Where available, you may also be able to adjust cookie preferences using the “Cookie center” link in the Website footer.
9) Automated decision-making and profiling
We do not make decisions that produce legal or similarly significant effects solely by automated means.
We may use limited automated tools for fraud prevention and analytics/advertising measurement, which are not intended to create legal effects for you.
10) Security
We implement appropriate technical and organizational measures to protect personal data, including access controls, security monitoring, and encryption where appropriate. No method of transmission or storage is completely secure, but we work to protect your information.
11) Complaints
If you are located in the EEA, you have the right to lodge a complaint with your local supervisory authority. In Latvia, the supervisory authority is the Data State Inspectorate (Datu valsts inspekcija)
12) Children
Our Website is not intended for children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, please contact us at [email protected].
13) Changes to this Policy
We may update this Privacy Policy from time to time. The updated version will be published on the Website and the “Last updated” date will be revised.