Privacy policy
Global Privacy Policy
DOCUMENT ID: CB-POL-PRIVACY-V5.1 • LAST UPDATED: 2026 • CONTROLLER: CASEBOB SWEDEN1. Data Controller & Scope of Operations
This Privacy Policy governs the processing of personal information collected by Casebob Sweden ("CASE·BOB", "we", "us", or "our") when you access our digital storefront, interact with our user interfaces, make hardware purchases, or communicate with our technical desk (collectively, the "Services").
For the purposes of the General Data Protection Regulation (EU GDPR / UK GDPR), the California Consumer Privacy Act (CCPA/CPRA), the Personal Information Protection and Electronic Documents Act (PIPEDA, Canada), and the Privacy Act 1988 (Australia), the Data Controller responsible for your personal information is:
REGISTRATION NUMBER (ORG): 790713-4931 • VAT ID: SE790713493101
REGISTERED OFFICE: Fjällbo Park 23B, 415 74 Göteborg, Sweden
OFFICIAL SUPPORT DISPATCH: Digital Help & Intake Center →
2. Categories of Personal Information We Collect
We collect information that identifies, relates to, or could reasonably be linked, directly or indirectly, with you. We categorize this telemetry as follows:
- Direct Identifiers & Contact Telemetry: Full name, billing address, physical shipping address, email address, and telephone number.
- Commercial & Financial Records: Transactional logs, payment confirmation tokens, authorized payment methods (e.g., Klarna, Apple Pay, PayPal, Visa/Mastercard via PCI-DSS certified processors), purchase history, and items added to wishlists or carts. (Note: CASE·BOB never stores raw unencrypted payment card numbers).
- Account & Security Credentials: Passwordless 6-digit authentication logs, account preferences, and support desk ticket correspondence.
-
Hardware & Local Storage Telemetry: Active handheld device configuration (e.g.,
localStorage: casebob_user_modelandcasebob_device_name) utilized solely to lock down UI compatibility, device filtering, and correct variant sizing. - Device, Network & Usage Diagnostics: IP addresses, browser architecture, operating system signatures, regional time zones, referring URLs, clickstream paths, and interactions with our CAD controls.
3. Lawful Bases for Data Processing (GDPR Article 6)
We process your personal information strictly under established lawful grounds:
- Contractual Performance (Art. 6(1)(b) GDPR): Necessary to fulfill commercial transactions, fabricate bespoke/selected phone cases, orchestrate carrier delivery, and execute return or warranty authorizations.
- Legitimate Interests (Art. 6(1)(f) GDPR): Necessary to detect and mitigate payment fraud, secure network infrastructure, analyze catalog performance, and ensure device filter synchronization across your shopping session.
- Legal Obligations (Art. 6(1)(c) GDPR): Compliance with statutory obligations, including Swedish fiscal accounting mandates (Bokföringslagen (1999:1078)) requiring retention of commercial ledgers for 7 years.
- Consent (Art. 6(1)(a) GDPR): For direct marketing communications, dynamic ad tracking, and non-essential analytical cookies. Consent may be revoked at any moment.
4. Infrastructure Relationship with Shopify
Our commercial infrastructure is hosted by Shopify Inc. (Canada) and its regional affiliates (Shopify International Limited, Ireland). Shopify acts as our primary cloud data processor, providing secure hosting, checkout processing, and fraud detection algorithms.
Shopify may also process de-identified or aggregated telemetries across its merchant ecosystem to enhance platform reliability, prevent global fraud, and optimize consumer checkout. For detailed insight into Shopify's platform data processing, review the Shopify Consumer Privacy Policy.
5. Cookies, Local Storage & Global Privacy Control (GPC)
We deploy industry-standard HTTP cookies, web beacons, and modern HTML5 Local Storage tokens:
-
Functional Hardware Local Storage (Essential): We store your active device model selection (
casebob_user_model) directly inside your web browser’s local storage. This strictly functional token ensures your catalog view does not reset between page loads and prevents sizing errors. It contains zero personally identifiable data. - Core Transactional Cookies (Essential): Maintained by Shopify to authenticate user sessions, maintain shopping cart integrity, and power payment gateways.
- Analytical & Advertising Trackers (Optional): Pixels and analytical tags deployed to evaluate catalog engagement and serve tailored communications via third-party channels (e.g., Meta, Google).
6. Third-Party Disclosures & Sub-Processors
We do not sell personal data for monetary consideration. We disclose information solely to authorized sub-processors necessary to operate our global storefront:
- Distributed Manufacturing & Logistics: Regional print-on-demand manufacturing centers and fulfillment depots (who receive shipping names, street addresses, phone numbers, and variant models exclusively to print and ship parcels).
- Carrier Networks: National and commercial postal carriers (e.g., PostNord, DHL, USPS, Canada Post, Royal Mail) to complete physical deliveries.
- Financial Payment Gateways: PCI-DSS Level 1 compliant financial intermediaries (Klarna, Stripe, PayPal, Apple Pay, Shop Pay).
- Regulatory & Law Enforcement: Disclosures executed exclusively pursuant to enforceable court orders, subpoenas, or statutory audits.
7. Cross-Border International Data Transfers
As an international e-commerce operator, data collected in the European Economic Area (EEA), the UK, Canada, or Australia may be transferred to, stored, and processed in Sweden, the United States, or other operational jurisdictions.
Whenever personal information originating from the EEA or UK is transferred outside these territories, we ensure an equivalent degree of protection by implementing European Commission Standard Contractual Clauses (SCCs), UK International Data Transfer Agreements (IDTA), or by relying on jurisdictions with formal Adequacy Decisions.
8. Data Retention Schedule
We retain personal telemetries only for as long as strictly necessary to fulfill the transactional purposes for which they were captured:
- Order Ledgers & Invoices: Retained for 7 full fiscal years following the transaction date to comply with the Swedish Bookkeeping Act (Bokföringslagen).
- Customer Support Tickets & RMA Logs: Retained for 24 months following case closure to administer the 12-Month Hardware Warranty and resolve subsequent inquiries.
- Marketing Telemetry: Retained until the individual executes an unsubscribe request or revokes affirmative consent.
9. Territorial Privacy Rights & Statutory Disclosures
Under the EU/UK GDPR, you retain the Right of Access (Art. 15), Right to Rectification (Art. 16), Right to Erasure / "Right to be Forgotten" (Art. 17), Right to Restriction of Processing (Art. 18), Right to Data Portability (Art. 20), and Right to Object to Processing (Art. 21). You also have the unrestricted right to lodge a complaint with your competent supervisory authority. In Sweden, this is Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, www.imy.se.
Residents of California, Virginia, Colorado, Connecticut, Utah, and other US jurisdictions maintain specific statutory protections:
- Notice at Collection: We collect direct identifiers, commercial purchase records, internet activity, and device telemetries for the business purposes described in Section 2.
- No Sale or Sharing of Sensitive Data: CASE·BOB does not sell your personal information for monetary profit. We do not collect or process Sensitive Personal Information (SPI) for inferring characteristics or profiling.
- Right to Opt-Out of Targeted Advertising ("Sharing"): To opt out of automated advertising pixels or data sharing, transmit a Global Privacy Control (GPC) signal or visit our Data Sharing Opt-Out Page.
- Non-Discrimination: We will never discriminate against you, alter hardware pricing, or degrade service quality for exercising your privacy rights.
In compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and Quebec’s Act Respecting the Protection of Personal Information in the Private Sector (Law 25): Personal information transferred outside Quebec or Canada is governed by contractual sub-processor assessments ensuring equivalent security safeguards. You maintain the right to access and rectify your information, or withdraw consent at any time, subject to legal or contractual restrictions. Unresolved complaints may be addressed to the Office of the Privacy Commissioner of Canada (OPC) at www.priv.gc.ca.
In accordance with the Australian Privacy Principles (APPs): You have the right to request access to and correction of your personal telemetries. When disclosing data to overseas sub-processors (pursuant to APP 8), CASE·BOB takes reasonable operational measures to ensure that international recipients do not breach the APPs. Australian users may lodge unresolved regulatory grievances directly with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
10. Protection of Minors
Our Services are not designed for or intentionally directed to children under 16 years of age. We do not knowingly capture or process personal records belonging to minors. If you are a parent or legal guardian and believe your minor child has submitted personal details to our storefront, submit an immediate ticket via our FAQ & Help Center to execute a permanent data purge.
11. Technical & Organizational Security Safeguards
CASE·BOB leverages robust security protocols provided by Shopify’s SOC 2 and SOC 3 compliant infrastructure, including full TLS 1.3 cryptographic transit encryption, strict API key isolation, and role-based administrative access controls.
However, no global electronic transmission or cloud storage architecture is 100% impenetrable. Customers are strongly cautioned to safeguard their personal authentication credentials and refrain from transmitting confidential payment card data over unencrypted channels.
12. How to Exercise Your Rights & Contact Us
To submit a verified request regarding your personal data (Access, Erasure, Correction, or Portability), or to appeal a prior data decision:
- Digital Support Desk: Submit an inquiry directly through our unified portal at casebob.com/pages/faq-help-center.
- Shopify Consumer Privacy Portal: You may also audit or exercise rights associated with multi-store network telemetries via privacy.shopify.com.
- Postal Correspondence: Casebob Sweden, Attn: Data Protection Desk, Fjällbo Park 23B, 415 74 Göteborg, Sweden.
// VERIFICATION PROTOCOL: To protect account security, we verify all data requests against the registered checkout email before processing records. We resolve all verified statutory inquiries within 30 days (or statutory local deadlines).

