How Atelier Kirk collects, uses and protects your personal data — in line with the GDPR and applicable US privacy laws.
Last updated: 17 June 2026
1. Who is responsible
The controller responsible for personal data processed through the website operated under the Atelier Kirk brand is:
Kirk & Epstein Trading Limited
Flat 2304, 23/F, Ho King Commercial Centre, 2-16 Fa Yuen Street, Mong Kok, Hong Kong
Company Registration No.: 80591683
Email: service@atelierkirk.com
Phone: +1 (929) 865-1791
Atelier Kirk is the public trading name of Kirk & Epstein Trading Limited, a company incorporated in Hong Kong. For any question about this policy or your data, write to us at service@atelierkirk.com.
2. What data we collect
We only collect data we need to run the shop and fulfil your orders:
- Order and account data — the items you buy, order history and, if you create an account, your login details.
- Contact and delivery details — your name, billing and shipping address, email address and (where given) phone number.
- Payment data — collected and processed directly by our payment provider. We do not store full card numbers on our systems.
- Browsing and device data — IP address, browser and device type, pages viewed and anonymous performance metrics, used to deliver the site securely and keep it fast.
- Messages — anything you send us by email or through a contact form, so we can answer you.
3. Why we use it and our legal bases
For visitors in the EU/EEA, each purpose rests on a basis under Article 6 GDPR:
- Performance of a contract (Art. 6(1)(b)) — to take, deliver and support your order.
- Legal obligation (Art. 6(1)(c)) — to meet tax, accounting and consumer-law duties.
- Legitimate interests (Art. 6(1)(f)) — to keep the site secure, prevent fraud and understand aggregate performance.
- Consent (Art. 6(1)(a)) — for optional cookies and any marketing email, which you can withdraw at any time.
4. Who we share it with
We share data only with the providers that help us run the shop, each bound to process it on our instructions:
- our e-commerce and order-management platform, which stores orders, products and accounts;
- our payment provider, to authorise and settle your payment securely;
- shipping carriers, to deliver your order;
- Resend, to send transactional emails such as order and shipping confirmations;
- our content-delivery network (CDN) and security provider, for content delivery, performance and security.
We do not sell your personal data, and we do not share it for cross-context behavioural advertising.
5. International transfers
Because Kirk & Epstein Trading Limited is based in Hong Kong, your data may be processed in Hong Kong or in other countries outside the EEA. Where that happens, we rely on appropriate safeguards — such as the EU Standard Contractual Clauses or an equivalent mechanism — to protect your data to a standard comparable with that of your home jurisdiction.
6. Cookies
We use cookies that are strictly necessary for the cart, your session and your language choice, plus optional cookies only with your consent. You can read the detail in our Cookie Policy.
7. How long we keep it
We keep personal data only as long as needed for the purpose it was collected. Order and invoice data is retained to meet tax and accounting obligations (generally several years). Account data is kept while your account is active; server logs are deleted or anonymised after a short period.
8. Your rights
If you are in the EU/EEA, the GDPR gives you the right to access, rectify, erase, restrict and port your data, to object to certain processing, to withdraw consent at any time, and to lodge a complaint with your local data-protection supervisory authority.
If you are in the United States — including California (CCPA/CPRA) — you have the right to know what we collect, to access and delete your data, and to opt out of any sale or sharing of personal information. As stated above, we do not sell or share your personal data, and we will never discriminate against you for exercising your privacy rights.
To exercise any right, an informal message to service@atelierkirk.com is enough.
9. Children
Our shop is intended for adults. It is not directed at children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us with data, please contact us and we will delete it.
10. Changes and contact
We may update this policy as our shop or the law evolves; the date above always shows the current version. Questions about your privacy? Write to us at service@atelierkirk.com.