🚚 Free shipping on orders over €100
Log in

Legal

Privacy Policy

Effective from 1 January 2025 · GDPR (EU 2016/679)

1. Data controller

The data controller is the operator of VICI. Eyewear. Contact: hello@vici.sk. For any questions about your data, please email us.

2. What data we collect

  • Contact data — name, email, phone, delivery address (when placing an order).
  • Prescription data — SPH, CYL, AX, PD and ADD values entered during lens configuration.
  • Payment data — card number, expiry and CVV are never stored on our servers. Payment is processed by Stripe.
  • Technical data — IP address, browser type, referrer URL, visit time (via server logs and Supabase).

3. Purposes and legal bases

PurposeLegal basisRetention
Order fulfilmentContract (Art. 6(1)(b))10 years (accounting)
DeliveryContractUntil order completed
Customer accountConsent / contractUntil account deleted
Customer supportLegitimate interest (Art. 6(1)(f))3 years
Security & fraud preventionLegitimate interest1 year

4. Third-party service providers

We share your data only with trusted providers bound by GDPR-compliant data processing agreements:

  • Supabase, Inc. — database, authentication and file storage. Data stored in EU (Frankfurt). supabase.com/privacy
  • Stripe, Inc. — card payment processing (PCI-DSS Level 1). stripe.com/privacy
  • PayPal Holdings, Inc. — alternative payment method.
  • DHL Express — parcel delivery. We share recipient name, address and phone number.
  • OpenAI, Inc. — OCR recognition of prescription photos. Photos are not stored for model training (API use).
  • Resend, Inc. — transactional emails (order confirmation, support).

5. Cookies

We only use technically necessary cookies required for the shopping cart, authentication (Supabase session) and security (CSRF protection). We do not use third-party analytics or advertising cookies without your consent.

6. Your rights

You have the following rights regarding your personal data:

  • Right of access — request a copy of all personal data we process about you.
  • Right to rectification — request correction of inaccurate or incomplete data.
  • Right to erasure ("right to be forgotten") — request deletion of your data, subject to legal obligations.
  • Right to restriction — request temporary restriction of processing.
  • Right to portability — receive your data in machine-readable format (JSON/CSV).
  • Right to object — object to processing based on legitimate interest.

Send all requests by email to hello@vici.sk. We will respond within 30 days.

7. Security

We implement appropriate technical and organisational measures: HTTPS/TLS encryption, Row Level Security in the database (Supabase RLS), payment data tokenisation (Stripe) and admin access controls.

8. Policy updates

We may update this policy. We will notify you of significant changes by email (if you are a customer) or by notice on this page.

Your cart

Your cart is empty

Browse our collection and find the perfect pair for you.