Legal
Last updated · 9 September 2026
Privacy Policy
What personal data we collect when you visit this site, book a workshop or hold a membership — why we collect it, who handles it for us, how long we keep it, and what you can ask us to do with it.
01
Who is responsible for your data
Helsinki Perfume Club is the controller of the personal data described on this page. That means we decide why it is collected and what happens to it, and we are the ones you hold to account for it.
Helsinki Perfume Club
Business ID
3289940-1
Address
Koronakatu 5, 02210 Espoo, Finland
Anything in this policy, and any request to use the rights set out below, goes to that address. We have not appointed a data protection officer; we are not required to.
02
What this policy covers
This policy covers helsinkiperfumeclub.com, the member area on it, and the email you send us at the address above.
It does not cover our online shop, which runs on Shopify at its own address, or Noses Club, which is a separate service on its own domain. Both publish their own privacy policies. Event pages hosted by Luma are likewise Luma’s own — see “Events and ticketing” below.
03
Visiting the site
The public pages need no account and ask for nothing. What is collected is limited to keeping the site running and to knowing, in aggregate, which pages and which language people actually read.
- Analytics — we use Google Analytics to count visits. It records a truncated IP address, an approximate location no finer than a city, the pages you open, the site you arrived from, and general device and browser information. It never receives your name, your email address or anything you type.
- Server logs — the web server records the requests it serves: IP address, time, the URL asked for and the browser identifying itself. These are kept briefly, to keep the site available and to look into abuse.
Analytics is the only non-essential processing on this site. You can switch it off for every site you visit with Google’s own browser add-on, or block its cookies in your browser — nothing else on the site changes if you do. Google Analytics opt-out
04
Writing to us
If you email us, we keep the message and your address for as long as it takes to answer you and to hold a record of what was agreed about a booking — no longer than 24 months after the last exchange, unless an invoice attached to it has to be kept for longer.
05
Membership accounts
Buying a membership creates an account. We store only what a membership needs to work:
- Your name, the email address you sign in with, and the phone number if the checkout asked for one.
- Your member number and the date you joined.
- Your membership status and renewal date, mirrored from Stripe on every change, and, if your membership is ending, the date it was cancelled and whether it was cancelled or lapsed for non-payment.
- The language you prefer, so our emails reach you in it.
- Identifiers linking your account to your customer and subscription records at Stripe.
- Sign-in codes and browser sessions, both stored only as one-way hashes, so a copy of our database contains no credential anyone could reuse.
We never see or store your card number, its expiry or its security code. Card details are entered on Stripe’s own checkout and stay with Stripe.
06
Who at the club can see your record
Running a membership means somebody has to be able to look at it. Club staff who administer memberships can see your membership record: your name, the address you sign in with, the phone number you gave at checkout, your member number, your membership status and renewal date, including when an ending membership was cancelled and why, whether our transactional email reached you, when you were first shown the member area introduction, and the identifiers linking your account to Stripe and to Luma.
They use it to answer you — “I paid but I cannot see the member-only events”, “I never got my sign-in code”, “please change the address I sign in with”. They cannot see your card details, which never reach us at all, and they cannot see a sign-in code or a session token: both are stored only as one-way hashes.
- Every administrative action on an account is recorded — granting or ending a free membership, changing a sign-in address, rotating a shop discount code, viewing that code, signing you out of your devices, adding you to the events tier, or deleting your account. The record holds what was done, to which member number, by whom, and when.
- That record is kept for 24 months and then deleted automatically. The one exception outlives its own subject: the record that an account was deleted survives the deletion, because that is what lets us show an erasure was actually carried out.
- Access is limited to the people who run the club, and signing in to it needs a one-time code sent to their own email address, exactly as your sign-in does. Those staff sessions last eight hours and are not extended by use.
07
Events and ticketing
Workshops and events are ticketed through Luma. When you register you give your details to Luma, which is its own controller for that registration and sends us the guest list for the event.
This site embeds Luma’s calendar, so Luma can set cookies in your browser when that part of a page loads.
08
Why we are allowed to process it
Each use above rests on one of four legal bases under the GDPR:
- Performance of a contract — running your membership, taking payment for it, sending the transactional email that goes with it, and seating you at a workshop you booked.
- Legitimate interest — keeping the site secure and available, understanding in aggregate how it is used, and answering messages you send us.
- Consent — analytics cookies, and any marketing email you have asked for. You can withdraw consent whenever you like; withdrawing it does not make what happened before unlawful.
- Legal obligation — Finnish accounting and tax law requires us to keep records of what was sold and to whom.
10
Where it is processed
This site and its database run on servers in the European Union.
Stripe, Google, Postmark and Luma are US companies and may process data outside the EEA. Where they do, the transfer relies on the EU–US Data Privacy Framework, on the European Commission’s standard contractual clauses, or on both.
11
How long we keep it
We delete what we no longer need, on these schedules:
- Membership records — while your membership is live, and for 24 months after it ends, so a returning member keeps their member number and their history.
- Sign-in codes, browser sessions and payment event records — deleted automatically 90 days after they are created. A sign-in code itself expires in ten minutes, or in 24 hours when it comes in the sign-in link of your welcome email.
- Records of administrative actions on member accounts — 24 months, as described above.
- Email correspondence — up to 24 months after the last message.
- Accounting records — for as long as Finnish accounting law requires, which is six years from the end of the accounting year for vouchers.
- Analytics — Google Analytics holds event-level data for 14 months; the aggregate reports built from it are kept longer.
When you ask us to delete your account we remove your member record and everything attached to it, keeping only what accounting law obliges us to keep.
13
Your rights
Wherever we hold data about you, the GDPR lets you:
- ask what we hold and receive a copy of it
- have anything inaccurate corrected — your name is editable on your membership card page
- ask us to delete it, where nothing obliges us to keep it
- ask us to restrict or stop a particular use of it
- object to any use we base on legitimate interest
- receive the data you gave us in a portable, machine-readable form
- withdraw a consent you gave, at any time
Write to the address at the top of this page and we will answer within one month. If we fail you, you can complain to the Finnish Data Protection Ombudsman.
14
How it is protected
The site is served over HTTPS only. Sign-in codes and session tokens are stored as one-way hashes, never in a form that could be replayed; a code expires in ten minutes (24 hours in the welcome email's sign-in link) and is void after five wrong attempts. Access to the database is limited to the people who run the service, and it is backed up regularly.
No system is perfectly secure, but this one is built so that a copy of our data would not let anyone into an account.
15
Children
This site is not directed at children, and our workshops and memberships are sold to adults. We do not knowingly collect personal data from anyone under 13. If you believe a child has given us data, write to us and we will delete it.
16
Changes to this policy
When this policy changes we update the date at the top of the page. If a change materially affects members, we tell them by email as well.