Privacy Policy
Last updated: 13 July 2026
1. Who we are
This Privacy Policy explains how Grigshin ("we", "us", "our") collects, uses, discloses and protects your personal data when you use our online store at https://grigshin.com and its related services and API at https://api.grigshin.com (together, the "Service"). Grigshin is the data controller of your personal data for the purposes of the GDPR and the Law of the Republic of Armenia "On the Protection of Personal Data".
- Privacy contact: privacy@grigshin.com
2. Scope
This policy applies to personal data we process about customers who register, browse, place orders or contact us; and staff users (administrators, managers, accountants) who use the administrative area. It does not cover third-party websites or payment pages that we link to but do not operate.
3. What personal data we collect
3.1 Account and profile data
- Full name, email address, phone number (optional), delivery address
- Password — stored only as a salted BCrypt hash; we never store or have access to your plaintext password
- Account role, status, optional loyalty discount percentage, order count, timestamps
3.2 Order and delivery data
- Recipient name, email, phone; delivery address and notes
- Order contents, quantities, prices, subtotal, tax, shipping fee and total
- Payment method, status, currency (AMD) and paid date
3.3 Payment data
Grigshin uses the ArCa / bank card-payment gateway. We do not collect, see or store your card number, expiry date, CVV or cardholder name. You enter those details directly on the bank's secure hosted payment page. We store only non-card transaction data: provider name, internal order reference, gateway order ID, amount, currency, payment status and gateway status codes.
3.4 Cart and favourites
Product links and quantities tied to your account, revealing your product interests.
3.5 Communications
We send transactional emails (verification, password reset, staff invitations). We store delivery status and security token hashes, but not the content of these emails.
3.6 Technical and usage data
- IP address (recorded in the admin audit log; used transiently for rate-limiting)
- HTTP request metadata: method, path, response status, timing, correlation ID
- A single essential authentication cookie (see Section 7)
3.7 Security tokens and audit records
- Session / refresh tokens — stored as SHA-256 hashes; the usable token is in an HttpOnly, SameSite cookie
- Email-verification and password-reset tokens — stored as hashes; the token is sent only to your email
- Staff invitations — email, role, and hashed invitation token
- Administrative audit log — acting staff user ID, email, role (snapshotted), action, affected record, response status, client IP, timestamp
4. How we collect your data
- Directly from you — when you register, edit your profile, place an order, or contact us.
- Automatically — technical and usage data generated as you use the Service.
- From our staff — when an administrator creates an order on your behalf or invites a staff user.
5. Why we use your data, and our legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Create and manage your account; authenticate you | Performance of a contract (Art. 6(1)(b)) |
| Process, deliver and support your orders | Performance of a contract (Art. 6(1)(b)) |
| Take and reconcile online payments | Performance of a contract (Art. 6(1)(b)) |
| Send transactional emails | Performance of a contract / legitimate interests (Art. 6(1)(b)/(f)) |
| Keep the Service secure — prevent fraud, rate-limit, audit admin actions | Legitimate interests (Art. 6(1)(f)) |
| Keep accounting and tax records | Legal obligation (Art. 6(1)(c)) |
| Improve and maintain the Service | Legitimate interests (Art. 6(1)(f)) |
6. Payments
Online card payments are handled by the ArCa card-payment system. When you pay by card you are redirected to the bank's PCI-DSS-compliant hosted payment page. Grigshin never receives your full card data. We also offer cash on delivery and bank transfer.
7. Cookies
The Service uses a single strictly necessary cookie: refresh_token — an HttpOnly, SameSite cookie scoped to the authentication endpoints. It keeps you signed in and cannot be read by JavaScript. See our Cookie Policy for full details.
8. Who we share your data with
We do not sell your personal data. We share it only with:
- Payment gateway / acquiring bank (ArCa) — to process card payments.
- Cloud hosting and storage providers — our application and database are hosted with a cloud provider; product images are stored on Google Cloud Storage.
- Email delivery provider — to send transactional emails.
- Delivery / courier partners — to deliver your orders (recipient name, address, phone).
- Professional advisers and authorities — where legally required or to establish, exercise or defend legal claims.
9. International data transfers
Some providers may process data on servers outside the Republic of Armenia and the EU/EEA. Where this occurs, we ensure adequate protection through appropriate safeguards such as the European Commission's Standard Contractual Clauses.
10. How long we keep your data
- Account and profile data — for as long as your account is active; deleted or anonymised on request.
- Order and payment records — retained for the period required by Armenian tax and accounting legislation (generally at least 5 years), even after account deletion.
- Security tokens — expire automatically (access ~15 min, refresh ~7 days) and are cleaned up.
- Server logs — retained briefly for security and troubleshooting, then rotated/deleted.
11. How we protect your data
- Encryption in transit (HTTPS/TLS) for all traffic.
- Passwords stored only as BCrypt hashes (work factor 12); session, verification and reset tokens as SHA-256 hashes.
- HttpOnly, SameSite authentication cookies and short-lived, stateless access tokens.
- Role-based access control and a full audit log of administrative changes.
- Rate limiting of authentication requests.
12. Your rights
Subject to applicable law, you have the right to: access your data; rectification of inaccurate data; erasure where no overriding legal ground applies; restriction of processing; data portability; object to processing based on legitimate interests; withdraw consent at any time.
To exercise any right, contact us at privacy@grigshin.com. We will respond within one month. You may also lodge a complaint with the Personal Data Protection Agency of the Ministry of Justice of the Republic of Armenia (www.pdp.am).
13. Children
The Service is intended for adults and is not directed to children. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us.
14. Changes to this policy
We may update this policy from time to time. When we do, we will change the "Last updated" date above and, where changes are significant, provide a more prominent notice.
15. Contact us
Email: privacy@grigshin.com (general support: support@grigshin.com)