Politika ta' Privatezza
L-aħħar aġġornament: 25 July 2026
Din it-traduzzjoni hija pprovduta għall-konvenjenza tiegħek. Il-verżjoni legalment vinkolanti ta' dan id-dokument hija l-oriġinal bl-Ingliż.
This Privacy Policy explains how Ryan Wear LLC ("we", "us", "our") collects, uses, shares and protects personal data when you visit our website, place an order or otherwise interact with us. We are committed to protecting your privacy and to complying with the EU/EEA General Data Protection Regulation (GDPR), the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, and applicable United States federal and state privacy laws. This policy applies to the website at https://ryanwear.net. It should be read together with our Cookie Policy, Terms of Service, Imprint and Refund & Return Policy.
1. Who We Are (Data Controller and Contacts)
Ryan Wear LLC is the data controller responsible for your personal data and the seller / merchant of record for all orders worldwide. Ryan Wear LLC is also the manufacturer of the products for EU product-safety (GPSR, Regulation (EU) 2023/988) purposes.
- Company: Ryan Wear LLC
- Legal form: Limited Liability Company (LLC), formed in the State of New Mexico, USA
- Owner / managing member: Ryan Wear (sole owner / member)
- Principal place of business: 5203 Juan Tabo Blvd STE 2B, Albuquerque, New Mexico 87111, USA
- Contact email: service@ryanwear.net
EU Representative and Data-Protection Contact (Franotech OÜ)
For visitors and customers in the European Union and European Economic Area (EU/EEA), we have appointed an EU-based point of contact. Franotech OÜ acts in the following roles:
- Authorised EU distributor of Ryan Wear products within the European Union;
- EU responsible economic operator / product-safety responsible person (GPSR) under the EU General Product Safety Regulation (Regulation (EU) 2023/988, applicable since 13 December 2024) — i.e. the EU-based contact for product safety and compliance;
- EU Representative of the non-EU controller Ryan Wear LLC under Article 27 GDPR;
- EU data-protection contact / Data Protection Officer (DPO) for EU/EEA data-protection matters, as nominated by Ryan Wear LLC.
The contact details of Franotech OÜ are:
- Company: Franotech OÜ
- Address: Rotermanni tn 6, 10111 Tallinn, Estonia
- Contact email: service@ryanwear.net
- Telephone: +372 636 0743
UK Representative (Article 27 UK GDPR)
For visitors and customers in the United Kingdom, and separately from Franotech OÜ (which is our EU/EEA representative only), we have appointed a distinct UK-established representative under Article 27 UK GDPR. Franotech OÜ does not act as our UK representative, and our UK representative does not act for EU/EEA matters. The full name, UK postal address and contact details of our UK Article 27 representative are set out in the UK Visitors (UK GDPR) section below.
You may contact our UK representative on any matter relating to our processing of your personal data — by post at its UK address given in the "UK Visitors (UK GDPR)" section below, or by email to service@ryanwear.net marked *"for the attention of the UK Article 27 representative"*, which we forward to them. The appointment of a UK Article 27 representative does not transfer our responsibility as controller.
EU/EEA residents may contact Franotech OÜ for all data-protection matters (and for all product-safety matters) in addition to, or instead of, contacting Ryan Wear LLC directly. Please note that the Article 27 EU Representative and a Data Protection Officer (DPO) are technically distinct roles under the GDPR. Franotech OÜ acts as our Article 27 EU Representative — a point of contact for supervisory authorities and data subjects, which does not transfer compliance responsibility away from Ryan Wear LLC — and as our EU data-protection contact / DPO. The DPO role here is a voluntary EU data-protection point of contact; this is not a formal designation of a Data Protection Officer under Articles 37–39 GDPR, which we are not currently required to appoint. You may contact us in your own language, and you do not lose any of your rights by choosing one contact over another.
2. Scope of This Policy
This policy covers personal data we process when you:
- browse, search or otherwise use our website;
- place, pay for, receive or return an order for our products (a carry-on/travel backpack, a packable travel jacket, and a travel neck pillow);
- contact us for support, returns or other enquiries;
- subscribe to marketing communications or interact with our cookies and consent tools.
It does not cover third-party websites or services we link to, which have their own privacy policies. This policy is intended for our public website. References to a staging or test environment are internal and out of scope.
3. What Personal Data We Collect, Why, and on What Legal Basis
We collect only the personal data we need for the purposes described below. The table sets out the categories of personal data, the purpose, and the legal basis under Article 6(1) GDPR for EU/EEA visitors. For US visitors, the same processing is carried out as described, subject to the rights set out in Section 12.
| Data category | Examples | Purpose | Legal basis (Art. 6(1) GDPR) |
|---|---|---|---|
| Order & customer data | Name, shipping address, billing address, email, order contents, order value | To form and perform the sales contract, process and ship your order, handle returns and refunds, and communicate about your order | Art. 6(1)(b) — performance of a contract |
| Payment data | Confirmation of payment, partial/last-four card details and transaction reference provided by our payment processor (we do not store full card numbers) | To take payment, prevent fraud and process refunds | Art. 6(1)(b) — contract; Art. 6(1)(f) — legitimate interest in preventing fraud and securing transactions |
| Account / correspondence data | Support emails, messages, return/withdrawal requests, complaint records | To respond to enquiries, provide customer support and keep records of communications | Art. 6(1)(b) — contract; Art. 6(1)(f) — legitimate interest in answering and documenting your enquiries |
| Browsing, device & log data | IP address, browser type and version, device and operating system, referring pages, pages viewed, timestamps, security/firewall logs (collected via our CDN, Cloudflare) | To deliver, secure and maintain the website, prevent abuse/DDoS, and diagnose technical issues | Art. 6(1)(f) — legitimate interest in operating a secure, functioning website |
| Cookie & consent data | Cookie/storage identifiers and your consent choices (Strictly Necessary always on; Analytics; Marketing), with a consent timestamp | To remember your cookie preferences and apply analytics/marketing only where you consent | Art. 6(1)(a) — consent (for Analytics/Marketing); for the record of your choice itself, Art. 6(1)(c) — our legal obligation under Art. 7(1) GDPR to be able to demonstrate consent |
| Cart data | Items added to your cart, stored in your browser's localStorage | To remember items in your cart while you shop | Art. 6(1)(b) — performance of a contract / steps taken at your request (strictly necessary functionality, not a tracking cookie) |
| Marketing data | Email address, subscription status, engagement with our emails | To send newsletters, offers and product updates where you have opted in | Art. 6(1)(a) — consent |
| Legal & compliance data | Records needed for tax, accounting, consumer-law, product-safety and dispute purposes | To comply with our legal obligations and to establish, exercise or defend legal claims | Art. 6(1)(c) — legal obligation; Art. 6(1)(f) — legitimate interest in legal claims |
We do not intentionally collect special categories of personal data (such as health, biometric or political data), and we ask that you do not send us such data.
Legitimate Interests (Art. 6(1)(f))
Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms. The specific interests we pursue are: securing the website and preventing fraud and abuse; preventing payment fraud and chargebacks; responding to and documenting your enquiries; and establishing, exercising or defending legal claims. You may object to processing based on legitimate interests (see Section 8), and you may request more information about the relevant balancing assessment using the contacts in Section 1.
Is Providing Data Mandatory?
Providing order, billing and contact data is necessary to enter into and perform a contract of sale with you; if you do not provide it, we cannot process or deliver your order. Providing marketing data is voluntary and based on your consent. You are not under a statutory obligation to provide personal data simply to browse the public parts of the website.
Cart Storage
Your shopping cart is stored locally in your browser's localStorage. This is strictly necessary / functional storage that makes the shop work; it is not a tracking cookie and is not shared with third parties for advertising.
Payment Data
Card and payment processing is handled by our payment processor, Revolut. When you pay, your card details are entered and processed in Revolut's secure environment. We never receive or store full card numbers. We receive only confirmation of the transaction and limited information (such as the last four digits and a transaction reference) needed to manage your order, refunds and fraud prevention. Revolut is PCI-DSS compliant. Revolut acts as an independent controller for its own payment-processing, fraud-prevention, anti-money-laundering and regulatory purposes, and its processing is governed by its own privacy notice — see https://www.revolut.com/legal/privacy/. Any automated fraud screening or risk scoring applied to a transaction is carried out by Revolut under its own controllership; we do not ourselves make automated decisions that produce legal or similarly significant effects (see Section 8).
4. How We Collect Personal Data
We collect personal data:
- directly from you when you place an order, create an account (if available), contact us, or subscribe to marketing;
- automatically when you use our website, through server and security logs, cookies and similar technologies (see Section 10);
- from our service providers, such as our payment processor (transaction and fraud-related data) and our shipping carriers (delivery and tracking information), who provide us with order-related and delivery information.
5. Recipients, Processors and Sub-Processors
We share personal data only with the parties below, and only as needed. These providers act as our processors (processing data on our documented instructions) or, where they determine their own purposes for limited functions (such as payment authorisation), as independent controllers. Where a recipient is an independent controller, its own privacy notice governs that processing and we encourage you to read it.
| Recipient | Role | What they receive | Location / transfer basis |
|---|---|---|---|
| Revolut | Payment processor / independent controller for payment processing | Payment and transaction data needed to take payment and process refunds (we do not store full card numbers) | EU/US — transfers under the EU–US Data Privacy Framework where certified, otherwise EU Standard Contractual Clauses; for UK personal data, the ICO IDTA / EU SCCs + UK Addendum, or the recipient's own DPF (UK Extension) certification where it holds one |
| Dediroom LLC | Hosting / infrastructure provider (processor) — operates the dedicated server on which the Site, its database and our tagging server run | As host, technically able to access the data stored on that server, including order and customer data, correspondence and server logs | Dedicated server located in the Netherlands (EU); data at rest remains in the EU. The provider itself is registered in the United States |
| Cloudflare | CDN, reverse proxy, security / DDoS protection — for the Site and for our tagging server `s.ryanwear.net`, so consented Google Analytics measurement traffic passes through its network in transit (processor) | Browsing, device and log data; IP addresses; traffic routed to our origin and tagging servers | Cloudflare global network incl. EU and US — transfers under the EU–US Data Privacy Framework where certified, otherwise EU Standard Contractual Clauses; for UK personal data, the ICO IDTA / EU SCCs + UK Addendum, or the recipient's own DPF (UK Extension) certification where it holds one |
| Google (Google Analytics 4 & Google Ads, managed via Google Tag Manager; Analytics routed via our own tagging server) | Analytics provider (our processor) and, for the Google Ads conversion and remarketing features, an independent controller under its own advertising terms — measurement data only if you opt in to Analytics and/or Marketing | If you opt in: online/cookie/device identifiers, pages viewed and events, and (for Marketing) ad-interaction and conversion data. Analytics data reaches Google from our tagging server; Ads conversion/remarketing data goes to Google directly from your browser. Google Analytics 4 receives your IP address with each request and uses it to derive an approximate location; Google states that it does not log or store it. Before any consent: nothing at all — no tag is loaded and your browser makes no request to Google | Google Ireland Limited (Ireland); data processed by Google LLC in the US. Google LLC is certified under the EU–US Data Privacy Framework; otherwise EU Standard Contractual Clauses. For UK personal data, the DPF UK Extension where certified, or the ICO IDTA / EU SCCs + UK Addendum |
| Gumlet Pte. Ltd. (Singapore) | Video hosting and player for our embedded product videos — provider under its own terms, only if you opt in to Marketing | Online/cookie/device identifiers and video-playback/performance data when you play an embedded video. The player is not loaded, and no data is sent to Gumlet, unless you opt in to Marketing | Singapore, and per Gumlet's published privacy notice EU customers' data is processed in Frankfurt (EU) with other data processed in the USA. Singapore is not covered by an EU adequacy decision, so every transfer outside the EEA relies on EU Standard Contractual Clauses under Art. 46 GDPR; for UK personal data, the ICO IDTA or EU SCCs + UK Addendum. The EU–US Data Privacy Framework is not relied on for Gumlet — it covers only certified US recipients |
| Our third-party carrier(s) | Delivery of your order | Name, shipping address, email/phone for delivery notifications | As applicable to the delivery destination |
| Franotech OÜ | EU distributor, GPSR responsible operator, Art. 27 EU Representative, EU data-protection contact / DPO | Data-protection and product-safety correspondence from EU/EEA residents | Estonia (EU) |
| Professional advisers, authorities | Legal, accounting, tax, regulatory and dispute handling | Data strictly necessary for the relevant purpose | As applicable |
Routing UK personal data through US-based sub-processors (for example the Cloudflare CDN and Revolut) is itself a restricted transfer under the UK GDPR, requiring an Article 46 safeguard or reliance on the sub-processor's own DPF (UK Extension) certification; the transfer bases above are stated for each jurisdiction accordingly (see Sections 6 and "UK Visitors (UK GDPR)").
We use Google Analytics 4 (Analytics) and Google Ads conversion and remarketing tags (Marketing), managed through Google Tag Manager. No Google analytics or advertising cookie is set, and no analytics, conversion or remarketing data is sent to Google, unless you opt in to the relevant category via the consent banner (see Section 10).
Before anything else runs on the page we set Google Consent Mode v2 to `denied` for analytics, advertising and personalisation storage; only strictly necessary functionality and security storage is granted. On top of that, the Google tag container is not fetched at all until you opt in to Analytics or Marketing.
When you opt in, measurement runs through a tagging server we operate on our own domain (`s.ryanwear.net`, "server-side tagging"), hosted on our own infrastructure in the Netherlands. The tag container is loaded from that domain, and Google Analytics 4 measurement data is sent there first, where we process it and forward it to Google server-to-server. Google Ads conversion and remarketing data is the exception: it goes directly from your browser to Google's own domains. Cloudflare delivers and protects that server as our processor, as it does the rest of the Site.
Nothing reaches Google before you consent. Until you opt in to Analytics or Marketing, your browser makes no request of any kind to Google — no tag is loaded, no cookie is set, no identifier is created, and your IP address, user agent and page address are not disclosed to Google. If you never opt in, Google receives nothing about your visit. Full detail is in our Cookie Policy.
We will update this policy to name any further analytics or marketing providers, their locations and their transfer safeguards before activating them.
We embed product videos hosted by Gumlet. The Gumlet player is a third-party embed that sets its own cookies and processes video-playback data, so we treat it as a Marketing technology: it is loaded, and any data is sent to Gumlet, only after you opt in to the Marketing category. Until then a placeholder is shown in its place and no request reaches Gumlet. Gumlet processes this data under its own privacy notice — see https://www.gumlet.com/privacy.
We may also disclose personal data where required by law, to comply with legal process, to enforce our terms, to protect our rights, property or safety (or those of others), or in connection with a merger, acquisition or sale of assets (with continued protection of your data).
We do not sell your personal data. Except where you opt in to our Marketing category — which enables Google Ads remarketing/conversion tags — we do not "share" your personal data for cross-context behavioural advertising as those terms are defined under California and other US state laws. Where you do opt in to Marketing, the resulting use of cookies and identifiers for advertising may be treated as a "sale" or "sharing" under those laws; you can withdraw at any time by rejecting Marketing cookies or via the Global Privacy Control signal (see Section 12).
6. International Data Transfers
Ryan Wear LLC is established in the United States. Personal data is processed in the United States (by Ryan Wear LLC) and via Cloudflare's global content-delivery and security network. Because we collect personal data directly from you and operate from the US, when you place an order or use our website your personal data may be transferred to, stored in, or accessed from the United States and other countries outside the EU/EEA, including by our service providers. In addition, where you opt in to Analytics or Marketing, Google processes cookie/device identifiers, usage and ad-interaction data in the United States (via Google LLC, which is certified under the EU–US Data Privacy Framework); no analytics or advertising data reaches Google unless you consent. Before consent there is no transfer to Google at all — your browser does not contact Google (Section 5). After consent, Analytics data is transferred to Google from our tagging server in the Netherlands, and Ads conversion/remarketing data from your browser directly; the same safeguards below apply to both.
The United States has not received a general EU adequacy decision; instead, the EU–U.S. Data Privacy Framework (DPF) provides an adequacy decision (adopted 10 July 2023) that covers transfers to US organisations which have self-certified under, and appear on, the official Data Privacy Framework List. We rely on the following appropriate safeguards for transfers of EU/EEA personal data:
- EU–U.S. Data Privacy Framework (DPF): where the recipient is certified under, and listed on, the Data Privacy Framework List, we rely on the DPF (and its UK and Swiss extensions) as the transfer mechanism.
- EU Standard Contractual Clauses (SCCs): where the recipient is not DPF-certified, we rely on the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), together with supplementary technical and organisational measures where needed and applied with the relevant module (for example controller-to-controller or controller-to-processor). We do not rely on the Article 49 GDPR derogations for these flows: they are available only for occasional, non-repetitive transfers, which these are not.
- Direct collection by a non-EU controller: where personal data is provided directly to Ryan Wear LLC by you, on your own initiative, when you order from or use our website in the EU/EEA, this is generally not an "international transfer" within the meaning of Chapter V GDPR (per EDPB Guidelines 05/2021 on the interplay between Article 3 and Chapter V), because there is no separate EU-established exporter making the data available — instead, the GDPR applies to that processing extraterritorially under Article 3(2), and Franotech OÜ acts as our Article 27 EU Representative. The Article 27 representative is not itself a transfer tool. Where we subsequently make such data available to a separate recipient in a third country (an onward transfer), we apply the DPF or SCCs as set out above.
UK-Origin Transfers
The mechanisms above are EU instruments and are named for the jurisdiction they cover. For UK-origin transfers we use the ICO International Data Transfer Agreement (IDTA) (preferred for UK-only flows) or EU SCCs + the ICO's UK International Data Transfer Addendum, each supported by a documented Transfer Risk Assessment. The IDTA cannot satisfy the EU GDPR and the EU SCCs alone cannot satisfy the UK GDPR — each mechanism is named for the jurisdiction it covers. We do not rely on the UK–US "data bridge" (the UK Extension to the EU–US Data Privacy Framework) unless the specific US recipient is actually certified to the Data Privacy Framework, has opted into the UK Extension, and appears on the Data Privacy Framework List. Further detail is set out in the "UK Visitors (UK GDPR)" section.
You may request more information about these safeguards, or a copy of the relevant clauses, using the contact details in Section 1.
7. How Long We Keep Your Data (Retention)
We keep personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting, tax and reporting requirements. Where we cannot state a fixed period, we set out the criteria we use to determine it.
| Data | Retention period / criterion |
|---|---|
| Order, invoicing and tax records | 7 years, to meet our tax and accounting retention obligations |
| Customer account & contact details | For the life of your account or customer relationship, then deleted or anonymised |
| Support / returns / withdrawal correspondence | Up to 24 months after resolution, unless needed longer for a related claim |
| Marketing data | Until you unsubscribe or withdraw consent, then promptly deleted from active marketing lists |
| Cookie / consent records | For the life of your consent plus up to 12 months; your consent preference is stored in your browser and is re-requested after 12 months (see Section 10) |
| Server & security logs | Up to 12 months, unless needed longer for a security investigation |
When the retention period or criterion is met, we securely delete or anonymise the data. Exact periods may be confirmed on request and may vary where a legal hold or ongoing dispute applies.
8. Your Data-Protection Rights (GDPR / EU/EEA)
If you are in the EU/EEA, you have the following rights in respect of your personal data. We will respond within the time limits set by law — generally one month, extendable by two further months for complex or numerous requests. Exercising your rights is free of charge; we may only refuse or charge a reasonable fee where a request is manifestly unfounded or excessive.
| Right | What it means |
|---|---|
| Right of access | To obtain confirmation of whether we process your data and a copy of it |
| Right to rectification | To have inaccurate or incomplete data corrected |
| Right to erasure ("right to be forgotten") | To have your data deleted in certain circumstances |
| Right to restriction | To limit how we process your data in certain circumstances |
| Right to data portability | To receive certain data in a structured, machine-readable format and have it transmitted to another controller |
| Right to object | To object to processing based on legitimate interests, and to object to direct marketing at any time |
| Rights regarding automated decisions | Not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects — we do not carry out such decision-making ourselves (any automated payment-fraud screening is performed by Revolut as an independent controller; see Section 3) |
| Right to withdraw consent | To withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal |
| Right to lodge a complaint | To complain to a data-protection supervisory authority (see below) |
How to Exercise Your Rights
To exercise any of these rights, contact us at service@ryanwear.net, or contact our EU Representative and data-protection contact Franotech OÜ (see Section 1). We may need to verify your identity before acting on a request.
Right to Complain to a Supervisory Authority
If you believe we have not handled your data lawfully, you have the right to lodge a complaint with a data-protection supervisory authority — in particular the authority in your own EU/EEA Member State of residence, place of work, or the place of the alleged infringement. As an additional option, because our EU Representative is established in Estonia, you may also contact the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, AKI) — https://www.aki.ee. The appointment of an Article 27 representative does not create a one-stop-shop or determine a lead authority. We would, however, appreciate the chance to address your concerns first.
Where We Sell
We sell and ship to customers in the European Union / European Economic Area (EEA), the United Kingdom (UK) and the United States. Because we offer goods to individuals in the UK, the UK GDPR (as it forms part of UK law) applies to that processing under its extra-territorial scope (Article 3(2)(a)), in addition to the EU GDPR for EU/EEA individuals. The UK-specific position is set out in the new "UK visitors" section below.
9. UK Visitors (UK GDPR)
This section applies if you are in the United Kingdom. It sits alongside, and does not replace, the EU/EEA provisions above.
Extra-Territorial Scope
Ryan Wear LLC is a controller established outside the UK that offers goods to data subjects in the UK. Our processing of UK personal data is therefore subject to the UK GDPR (and the Data Protection Act 2018) under its extra-territorial scope in Article 3(2)(a) UK GDPR.
UK Article 27 Representative
As we are established outside the UK and offer goods to individuals in the UK, we have appointed a UK-established representative under Article 27 UK GDPR. Our UK representative is: Sunburn Shark LTD, 128 City Road, London EC1V 2NX, United Kingdom (registered in England and Wales, company number 17350545). You may contact our UK representative on any matter relating to our processing of your personal data; this does not transfer our responsibility as controller.
This is a separate appointment from Franotech OÜ, which is our EU representative only. Franotech OÜ does not act as, and does not cover, our UK representative role. You can reach our UK representative by post at the UK address above, or by email to service@ryanwear.net marked *"for the attention of the UK Article 27 representative"*; we forward such messages to them. Postal contact at the UK address is always available to you and to the ICO.
UK Supervisory Authority and Right to Complain
The UK supervisory authority is the Information Commissioner's Office (ICO). If you are in the UK and believe we have not handled your personal data lawfully, you have the right to lodge a complaint with the ICO (ico.org.uk; make a complaint at https://ico.org.uk/make-a-complaint/; helpline 0303 123 1113) — ideally after first raising the matter with us so we have the chance to resolve it.
Complaints to Us
We operate a data-protection complaints process, and you may complain to us as well as to the ICO. We will acknowledge a complaint (the ICO indicates within around 30 days) and respond without undue delay. This reflects the new statutory complaints-handling duty for controllers introduced by the Data (Use and Access) Act 2025 (DUAA), which takes effect on 19 June 2026.
UK Data-Subject Rights
UK individuals have the same catalogue of rights as set out in Section 8 — on parity with the UK GDPR — including the rights of access, rectification, erasure, restriction, data portability, objection, withdrawal of consent, and the right to lodge a complaint. You may exercise these rights via service@ryanwear.net or through our UK representative (see above). We do not need to duplicate the full table here; the same rights, conditions and response times apply.
UK-to-US International Transfers
When you order from or use our website, your personal data is transferred to and processed in the United States by Ryan Wear LLC and via our service providers. For these transfers of UK personal data to the United States, we rely on the ICO International Data Transfer Agreement (IDTA) (or, where EU SCCs are used, the EU Standard Contractual Clauses together with the ICO's UK International Data Transfer Addendum), supported by a documented Transfer Risk Assessment. We do not rely on the UK–US "data bridge" (the UK Extension to the EU–US Data Privacy Framework) unless the specific US recipient is actually certified to the Data Privacy Framework, has opted into the UK Extension, and appears on the Data Privacy Framework List.
Retention and Legal Basis
The retention periods and criteria in Section 7, and the legal bases in Section 3, apply equally to UK individuals (read against the corresponding provisions of the UK GDPR).
10. Cookies and Consent
We use cookies and similar technologies to operate the website, remember your preferences, and — only where you consent — to run analytics and marketing. For a full description of each cookie and similar technology, its provider and its duration, see our Cookie Policy. We present a granular consent banner with the following categories:
- Strictly Necessary — always on; required for the site and cart to function (including the browser localStorage cart, which is functional and not a tracking cookie).
- Analytics — set only with your consent; helps us understand how the site is used. We currently use Google Analytics 4 in this category. Its tag can only act — set cookies or send data — after you opt in; the container carrying it is loaded on every page view (see Section 6).
- Marketing — set only with your consent; used for advertising and measuring campaigns, and to load embedded third-party content such as our Gumlet-hosted product videos. We currently use Google Ads conversion and remarketing tags and the Gumlet video player in this category (in addition to our first-party affiliate cookie), loaded only after you opt in.
Our live consent banner presents "Accept all" and "Reject non-essential" with equal prominence (the same size and format), so that accepting and rejecting are equally easy. Your choice is stored for 12 months, after which we ask you again. The banner also honours the Global Privacy Control (GPC) browser signal as an automatic opt-out of analytics and marketing cookies. Strictly-necessary cookies remain always on; analytics and marketing are opt-in only. Your consent choice (and a timestamp) is recorded in your browser so that we can remember and re-apply your preferences. You can change or withdraw your choices at any time via the Cookie settings link / consent tool.
A summary of the cookies and similar technologies we set is below; the full register (name, purpose, provider and duration of each) is maintained in the Cookie Policy. The Analytics and Marketing entries (Google Analytics 4 and Google Ads) are already included below; any further analytics or marketing tools will be added here before they are activated.
| Name / key | Type | Purpose | Provider | Duration / storage |
|---|---|---|---|---|
| ryanwear-consent (consent preference) | Strictly Necessary | Stores your cookie-consent choices (Analytics / Marketing on or off) and a timestamp | Ryan Wear LLC | localStorage; re-requested after 12 months |
| Shopping cart | Strictly Necessary | Remembers the items in your cart while you shop | Ryan Wear LLC | localStorage; persists until changed or cleared |
| Cloudflare security/CDN (e.g. __cf_bm) | Strictly Necessary | Security, DDoS protection and traffic routing | Cloudflare | Session / short-lived |
| rw_aff (affiliate referral) | Marketing (set only after you opt in) | Remembers which affiliate/partner link you arrived through so their discount applies automatically at checkout and the partner is credited for the sale; a first-party identifier, not shared with third-party advertisers | Ryan Wear LLC | Cookie; 60 days (last click wins) |
| _ga, _ga_* (Google Analytics 4) | Analytics (set only after you opt in) | Measures site usage in aggregate; GA4 receives the IP address to derive approximate location and Google states it does not log or store it | Cookie; up to 2 years | |
| _gcl_au, IDE (Google Ads) | Marketing (set only after you opt in) | Ad-conversion measurement and cross-site remarketing | Cookie; up to approx. 13 months | |
| Gumlet player (e.g. _gum*) | Marketing (set only after you opt in) | Plays our embedded product videos and produces anonymous viewing/performance analytics; the player is loaded only when you opt in | Gumlet | Cookie / localStorage; session to persistent |
In addition to the first-party affiliate-referral cookie rw_aff described above, our Analytics category uses Google Analytics 4 and our Marketing category uses Google Ads conversion/remarketing tags, both managed via Google Tag Manager. These tags fire only after you opt in to the relevant category: no Google cookie is set and no analytics, conversion or remarketing data is sent to Google unless you consent. Google Consent Mode v2 is pre-set to `denied` for analytics, advertising and personalisation storage before anything runs, and Google's tag container is not fetched at all until you opt in — so before consent your browser makes no request to Google whatsoever. When you opt in, the container is loaded from our own tagging server (`s.ryanwear.net`, hosted in the Netherlands) and Google Analytics measurement is routed through it; Google Ads conversion and remarketing data still goes to Google directly. See Section 6 and the Cookie Policy for full details. If we introduce any further analytics or marketing tools, they will only be set after you opt in, and this policy will be updated first.
For EU/EEA users, consent for non-essential cookies and similar technologies is handled in line with the GDPR and applicable national telecoms/cookie rules (in Germany, the TDDDG).
11. Children's Data
Our website and products are intended for adults and are not directed at children. The ages below concern children's data consent, not the right to purchase: purchasing requires being 18 or over (or the age of majority where you live), as set out in our Terms of Service, which is a separate matter from the data-consent ages here.
For EU/EEA users, where we rely on consent for information-society services, the minimum digital-consent age under Article 8 GDPR is 16, but each Member State may lower it to as little as 13 (for example, 13 in Estonia and 16 in Germany). We do not knowingly collect personal data from children below the applicable age. For US residents, we do not knowingly sell or share the personal information of consumers under 16 (a CCPA threshold; see Section 12). If you believe a child has provided us with personal data, please contact us and we will delete it.
12. Your US State Privacy Rights
This section applies to residents of US states with comprehensive consumer-privacy laws. As of 1 January 2026, twenty states have comprehensive privacy laws in effect: California (CCPA/CPRA), Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Florida, Delaware, New Jersey, Nebraska, New Hampshire, Minnesota, Maryland, Tennessee, Indiana, Kentucky and Rhode Island. Although these laws differ in detail, they grant a common core of consumer rights and disclosures, summarised below; the specific rights available to you depend on your state of residence.
Do Not Sell or Share My Personal Information
We do not sell your personal information for money. However, if you opt in to our Marketing category, we use Google Ads remarketing and conversion tags, and the resulting use of cookies and identifiers for cross-context behavioural / targeted advertising may be treated as a "sale" or "sharing" of personal information under the California Consumer Privacy Act (as amended by the CPRA) and equivalent terms under other state laws. This happens only with your opt-in and you can stop it at any time (see below). We do not knowingly sell or share the personal information of consumers under 16 years of age (a CCPA threshold that is separate from the EU Article 8 ages in Section 11).
You can opt out of this "sale"/"sharing" and targeted advertising at any time by selecting "Reject non-essential" (or turning Marketing off) in our "Cookie settings" panel. Our consent banner also recognises the Global Privacy Control (GPC) universal opt-out signal as a valid opt-out of the sale/sharing of personal information and of targeted advertising, and Marketing stays off automatically when a GPC signal is present (see Section 10).
Sensitive Personal Information
We do not collect or use sensitive personal information (as defined under California and similar state laws) for the purpose of inferring characteristics about you, and we do not sell or share it.
Your Rights
Subject to your state's law and applicable exceptions, you may have the right to:
- Know / access the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients;
- Delete personal information we have collected from you;
- Correct inaccurate personal information we hold about you;
- Data portability — obtain a copy of your personal information in a portable, usable format;
- Opt out of the sale or sharing of personal information and of targeted advertising (for us this can occur only where you opt in to Marketing / Google Ads; you can opt out at any time via our "Cookie settings" panel or the GPC signal);
- Limit the use of sensitive personal information (we do not use it for purposes that trigger this right);
- Opt out of profiling in furtherance of decisions producing legal or similarly significant effects (we do not engage in such profiling);
- Non-discrimination — we will not discriminate against you for exercising any of these rights, including by denying goods or services, charging different prices, or providing a different level of quality.
How to Exercise Your US State Rights
To exercise these rights, contact us at service@ryanwear.net. We will verify your request as required by law. You may use an authorised agent to submit a request on your behalf where permitted; we may require proof of authorisation. If we deny a request, you may have the right to appeal by contacting us at the same address; where your state provides for it, you may also contact your state Attorney General (or, in California, the California Privacy Protection Agency).
Categories of Information (CCPA Notice)
For California residents, the categories of personal information we collect map to those in Section 3 (identifiers; commercial information such as order history; internet/network activity such as browsing and device data; and customer-service records). We collect this for the business and commercial purposes described in Section 3, retain it as described in Section 7, and disclose it to the recipients described in Section 5. A written copy of this policy is available on request.
13. How We Protect Your Data
We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse or alteration, including encryption in transit (HTTPS), access controls, and our CDN/security layer (Cloudflare). Card payments are processed by Revolut, which is PCI-DSS compliant, so that we never hold full card numbers. No method of transmission or storage is completely secure, but we work to protect your data.
In the event of a personal-data breach, we will act in accordance with our legal obligations. For EU/EEA personal data, this includes notifying the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach (Article 33 GDPR), and notifying affected individuals where the breach is likely to result in a high risk to their rights and freedoms (Article 34 GDPR). Where US state law requires it, we will also notify affected residents and authorities as required.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology or the law. The version in force is the one published on this page; where changes are material, we will take reasonable steps to notify you.
15. How to Contact Us
For any privacy question or request:
- Controller: Ryan Wear LLC, 5203 Juan Tabo Blvd STE 2B, Albuquerque, New Mexico 87111, USA
- Email: service@ryanwear.net
- EU Representative / data-protection contact / DPO: Franotech OÜ, Rotermanni tn 6, 10111 Tallinn, Estonia — service@ryanwear.net · +372 636 0743
- UK Representative (Article 27 UK GDPR): a separate UK-established representative (not Franotech OÜ); full name, UK postal address and contact details are in the "UK Visitors (UK GDPR)" section
See also our Imprint for full company identification, and our Cookie Policy, Terms of Service and Refund & Return Policy.
Disclaimer
This Privacy Policy is provided for transparency about how we handle personal data and does not constitute legal advice. For advice on your specific situation, please consult a qualified professional.
