Privacy Policy

Last updated: 1 August 2026

Data controller:
Olympia OL
Drouva st. 1, 27065 Ancient Olympia, Greece
Telephone: +30 26240 22650
Secure contact form: https://olympiaol.gr/contact/

This Privacy Policy explains how Olympia OL collects, uses, stores, shares and protects personal information when users visit olympiaol.gr, create an account, place an order, contact us, visit our physical store or submit a cancellation, return, refund, complaint or withdrawal request.

1. Personal information we collect

Depending on how a person interacts with us, we may collect:

  • identity and contact information, such as name, postal address, billing address, email address and telephone number;
  • account information, login identifiers and account preferences;
  • order and transaction information, including products purchased, quantities, prices, order number, delivery details, payment method, transaction references and refund status;
  • shipping, customs and delivery information, including tracking details and information needed for international transport or returned-goods procedures;
  • communications sent through the contact form, email, telephone or other support channels;
  • withdrawal, cancellation, return, refund, complaint and product-condition information;
  • marketing preferences and consent records;
  • technical information, such as IP address, browser type, device information, operating system, referring pages, security logs and cookie identifiers.

We do not require users to provide more information than is reasonably necessary for the relevant purpose. Refusal to provide information required for an order, delivery, payment, legal request or identity verification may prevent us from completing that activity.

2. Payment information

Online card payments are processed through the electronic payment platform of the National Bank of Greece or the relevant payment service provider. Olympia OL does not receive or store the complete card number, PIN or card-verification code used for an online payment.

For card payments made at the physical store, the POS provider and acquiring bank process the card transaction. Olympia OL may retain the receipt, transaction reference, amount, card type and a masked or truncated card reference where required for accounting, reconciliation, fraud prevention or refunds.

For bank transfers, we may receive the payer’s name, bank-account reference, payment amount, payment date, order reference and other information included in the transfer record.

Customers must never send complete payment-card numbers, PINs, card-verification codes or photographs of cards through email, the contact form or another unprotected channel.

3. How and why we use personal information

  • To process orders and provide products: to confirm orders, receive payment, package and ship goods, provide tracking information and communicate about the contract. The legal basis is performance of the contract or steps requested before entering into it.
  • To manage payments and refunds: to reconcile transactions, prevent duplicate or fraudulent refunds and return funds through the relevant payment provider. The legal bases are performance of the contract, legal obligations and legitimate interests in secure financial administration.
  • To provide customer support: to answer enquiries, investigate delivery problems and manage complaints. The legal bases are contract performance and legitimate interests in customer service.
  • To comply with legal obligations: including tax, accounting, consumer-protection, customs, product-safety, fraud-prevention and regulatory obligations.
  • To establish, exercise or defend legal claims: including maintaining records of orders, communications, withdrawals, returns and refunds. The legal bases are legal obligations and legitimate interests.
  • To maintain and secure the website: to prevent abuse, fraud, unauthorised access and technical failures and to maintain security and evidentiary logs. The legal bases are legitimate interests and, where applicable, legal obligations.
  • To send marketing communications: only where permitted by law, normally on the basis of consent or another lawful basis. Users may unsubscribe at any time.

4. Electronic withdrawal requests

When a user submits an electronic withdrawal statement, we process the information needed to identify and manage the request. This may include the name, order number, billing and confirmation email addresses, selected goods and quantities, the content of the statement, packaging condition, date and time of submission, request status, customer-facing communications, administrative notes and records of actions taken.

For security, fraud-prevention and evidentiary purposes, the withdrawal system may retain technical security records and an audit history. Where an IP-related identifier is retained by the system, it may be stored as an irreversible keyed hash rather than as the raw IP address.

A receipt or status message sent by the withdrawal system records the relevant action. It does not by itself establish that the statutory right applies, approve a return or confirm that a refund is due.

5. Cloudflare Turnstile and security checks

The website may use Cloudflare Turnstile to distinguish legitimate users from automated or abusive traffic. During verification, technical information such as the IP address, browser or device information and a security-verification token may be transmitted to Cloudflare.

This processing is carried out for website and form security, fraud prevention and protection against automated abuse. Cloudflare may process information outside the European Economic Area under the transfer safeguards applicable to its services.

6. Cookies and similar technologies

The site uses essential cookies required for core functions such as shopping-cart operation, checkout, account login, security and consent preferences.

Analytics, preference or marketing cookies are used only in accordance with the choices offered through the site’s consent mechanism and applicable law. Users can review or change available choices through the cookie settings.

Browser settings can also block or delete cookies, but disabling essential cookies may prevent parts of the site from functioning correctly.

7. Who may receive personal information

We share personal information only where reasonably necessary and subject to appropriate contractual, confidentiality or legal safeguards. Recipients may include:

  • hosting, website-maintenance, security, email and technical-service providers;
  • payment service providers, the National Bank of Greece, acquiring banks and POS providers;
  • postal operators, couriers, freight providers, fulfilment partners and customs brokers;
  • accountants, tax advisers, legal advisers, auditors and insurers;
  • public authorities, courts, tax authorities, customs authorities or regulators where disclosure is required or legally justified.

We do not sell personal information to advertisers.

8. International transfers

Some payment networks, carriers, customs intermediaries or technology providers may process information outside Greece or outside the European Economic Area.

Where data-protection law requires safeguards for such transfers, we use an available lawful mechanism, such as an adequacy decision, approved contractual clauses or another permitted safeguard.

9. Retention

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected and to comply with tax, accounting, customs, consumer-protection, fraud-prevention and other legal obligations.

Order, invoice and payment records may be retained for the period required by applicable accounting and tax law. Withdrawal, return, refund, complaint and audit records may be retained for as long as necessary to comply with legal obligations, maintain evidence and establish, exercise or defend legal claims.

Contact-form messages that do not lead to a transaction or continuing legal need are deleted or anonymised when no longer reasonably required. Test or demonstrably fictitious data should be removed when it is no longer needed for testing.

After the applicable retention period, information is deleted or anonymised where reasonably possible.

10. Security

We use reasonable technical and organisational measures designed to protect personal information against accidental loss, unauthorised access, alteration, disclosure or destruction. Measures may include encrypted transmission, access controls, security monitoring, backups, logging and software maintenance.

No method of transmission or storage is completely risk-free. Users should protect their account credentials and avoid sending sensitive payment or identification information through unprotected channels.

11. Data-protection rights

Subject to applicable law and any relevant exceptions, individuals may have rights to:

  • request access to their personal information;
  • request correction of inaccurate or incomplete information;
  • request deletion of information where there is no lawful reason to retain it;
  • request restriction of processing;
  • object to processing based on legitimate interests or to direct marketing;
  • receive certain information in a portable format;
  • withdraw consent at any time where processing relies on consent;
  • lodge a complaint with a competent supervisory authority.

To exercise a right, use the contact details below. We may request information reasonably necessary to verify identity and prevent unauthorised disclosure. Some rights are subject to legal exceptions, including obligations to retain transaction, tax, customs or legal-claim records.

Individuals in Greece or another European Economic Area country may also contact their competent supervisory authority. The Greek supervisory authority is the Hellenic Data Protection Authority.

12. Marketing communications

Where a user has subscribed to marketing communications, we may send information about products, offers or company news. Every electronic marketing message will provide an unsubscribe method where required.

Withdrawing from marketing does not stop essential communications about an order, delivery, payment, withdrawal request, refund, security matter or other active transaction.

13. Children’s information

The site and its products are not directed to children for the purpose of collecting personal information. A parent or guardian who believes that a child has supplied personal information without appropriate authorisation should contact us so that we can investigate and take suitable action.

14. Changes to this policy

We may update this Privacy Policy when our processing activities, service providers or legal obligations change. The updated version will be published on this page with a revised date.

Material changes will be communicated through the site or another appropriate method where required by law.

15. Contact

For questions about this Privacy Policy or the processing of personal information, contact:
Olympia OL
Drouva st. 1, 27065 Ancient Olympia, Greece
Telephone: +30 26240 22650
Secure contact form: https://olympiaol.gr/contact/

Related pages: Shipping & Cancellation Policy and Payment Methods.