Last updated: April 2026
Y-US? is an online print-on-demand clothing store operated from the Basque Country, Spain. We are the data controller for the personal data processed through this website.
Account data
When you register or log in, we receive your name and email address from our authentication provider (Auth0/Okta). We store your account identifier and access role.
Order data
When you place an order, Stripe Checkout provides us with your name, email address, shipping address, items ordered, amounts, and currency. This is stored in our database to fulfil and track your order.
Contact form data
When you use our contact form, we receive your name, email address, and the message you submit.
Analytics data (consent-dependent)
If you accept analytics cookies, we collect page views, scroll depth, product interactions, cart activity, device type, browser, viewport size, language preference, timezone, and UTM campaign parameters. If you accept session recordings, PostHog may record anonymised screen interactions with all form inputs masked.
Technical data
Your IP address is used transiently to enforce rate limits on certain endpoints (e.g. contact form) and is not stored persistently. Session tokens are stored as secure, signed cookies.
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Processing and fulfilling orders | Performance of contract (Art. 6(1)(b)) |
| Sending order confirmation and tracking emails | Performance of contract (Art. 6(1)(b)) |
| Account management | Performance of contract (Art. 6(1)(b)) |
| Analytics and session recordings | Consent (Art. 6(1)(a)) |
| Security, fraud prevention, rate limiting | Legitimate interest (Art. 6(1)(f)) |
| Tax and accounting records | Legal obligation (Art. 6(1)(c)) |
We do not sell your personal data. We share it only with the service providers listed below, solely to operate this store.
| Recipient | Purpose | Location |
|---|---|---|
| Stripe | Payment processing | USA (SCCs) |
| Printful | Order printing and fulfilment | USA/EU (SCCs) |
| Auth0 (Okta) | User authentication | EU |
| Resend | Transactional email delivery | USA (SCCs) |
| Amazon Web Services | Media storage and CDN | EU |
| PostHog | Analytics (consent-only) | EU (eu.i.posthog.com) |
| Google Analytics | Site analytics (consent-only, when active) | USA (SCCs) |
SCCs = Standard Contractual Clauses — the EU-approved mechanism for lawful data transfers to third countries.
| Data type | Retention period |
|---|---|
| Order data | 7 years (Spanish tax law) |
| Account data | Until you request deletion |
| Analytics events | 2 years |
| Contact form submissions | 12 months |
| Session tokens | 8 hours |
Under the GDPR you have the right to:
To exercise any of these rights, email us at info@y-us.eu. We will respond within 30 days.
You have the right to lodge a complaint with the Spanish data protection supervisory authority:
Agencia Española de Protección de Datos (AEPD) www.aepd.es
For full details of the cookies we use, see our Cookie Policy.
We may update this policy from time to time. Material changes will be reflected in the "Last updated" date above. Continued use of the site after changes are posted constitutes acceptance of the updated policy.