Last updated: April 15, 2026


1. Introduction

This Privacy Policy explains how UAB Itemsbox (“we”, “us”, “our”), operating the website itemsbox.lt, collects, uses, stores, and shares your personal data. We are committed to protecting your privacy and complying with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable Lithuanian data protection law.

By using our website or placing an order, you acknowledge this Privacy Policy.


2. Who We Are

Company: UAB Itemsbox
Address: Pilies g. 14, Klaipėda, Lithuania
Email: info@itemsbox.lt
Phone: +370 602 21251
Website: https://itemsbox.lt


3. What Personal Data We Collect

3.1 Account Registration

When you create an account on our website, we collect:

  • Full name
  • Email address
  • Password (encrypted)
  • Billing and shipping address

3.2 Orders and Purchases

When you place an order, we collect:

  • Name and contact details
  • Billing and delivery address
  • Order contents and value
  • Payment confirmation data (we do not store full card numbers)
  • Invoice details (including company name and VAT number, if applicable)

3.3 Custom Orders and Inquiries

When you contact us regarding custom packaging, printing, or plotter services, we collect:

  • Name and contact details
  • Any information you voluntarily provide in your message or uploaded files (e.g., design files, measurements)

3.4 Website Analytics

We collect anonymised or pseudonymised data about how visitors use our website, including:

  • Pages visited, time spent, click paths
  • Device type, browser, operating system
  • Approximate geographic location (country/city level)
  • Referral source (e.g., Google, social media)

This data is collected via cookies and analytics tools (see Section 9 – Cookies).

3.5 Marketing Communications

If you opt in to marketing, we collect:

  • Email address
  • Name (optional)
  • Communication preferences

4. Legal Bases for Processing

We only process your personal data when we have a valid legal basis under GDPR Article 6:

PurposeLegal Basis
Processing your order and delivering productsContract performance (Art. 6(1)(b))
Creating and managing your accountContract performance (Art. 6(1)(b))
Issuing invoices and fulfilling tax obligationsLegal obligation (Art. 6(1)(c))
Responding to customer service enquiriesLegitimate interest (Art. 6(1)(f))
Sending marketing emails (with your consent)Consent (Art. 6(1)(a))
Website analytics and performance improvementLegitimate interest (Art. 6(1)(f))
Fraud prevention and securityLegitimate interest (Art. 6(1)(f))

Where we rely on legitimate interest, we have balanced our interests against your rights and determined they do not override your privacy interests.

Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.


5. How We Use Your Data

We use your personal data to:

  • Process, fulfil, and deliver your orders
  • Send order confirmations, shipping updates, and invoices
  • Manage your customer account
  • Respond to your questions and support requests
  • Process custom packaging or printing inquiries
  • Send promotional emails or newsletters (only with your consent)
  • Improve our website and product offerings through analytics
  • Comply with legal and accounting obligations
  • Prevent fraud and maintain security

We will never sell your personal data to third parties.


6. Data Processors and Third Parties

To operate our business, we share data with trusted service providers (data processors) who process data on our behalf and under our instructions:

ProcessorPurposeLocation
WooCommerce / WordPressE-commerce platform, order managementEU/US (Privacy Shield)
Payment gateway (e.g., Paysera, Stripe, or similar)Secure payment processingEU
Shipping / courier partnersOrder deliveryEU
Google AnalyticsWebsite usage analyticsUS (Standard Contractual Clauses)
Email service provider (e.g., Mailchimp or similar)Transactional and marketing emailsUS (Standard Contractual Clauses)
Accounting softwareInvoicing and financial recordsEU
Web hosting providerWebsite and data hostingEU

Where processors are located outside the European Economic Area (EEA), we ensure appropriate safeguards are in place (Standard Contractual Clauses or adequacy decisions).

We do not share your data with any third party for their own marketing purposes.


7. Data Retention

We retain personal data only for as long as necessary for the purposes it was collected:

Data CategoryRetention Period
Order and transaction records10 years (Lithuanian accounting law requirement)
Customer account dataDuration of account + 2 years after last activity
Marketing consent and communicationsUntil you unsubscribe or withdraw consent
Analytics data26 months (anonymised after 14 months)
Customer support correspondence3 years after the enquiry is resolved
Custom order design files1 year after order completion, unless agreed otherwise

After the retention period expires, data is securely deleted or anonymised.


8. Your Rights Under GDPR

As a data subject under GDPR, you have the following rights:

  • Right of access – You may request a copy of the personal data we hold about you.
  • Right to rectification – You may ask us to correct inaccurate or incomplete data.
  • Right to erasure (“right to be forgotten”) – You may request deletion of your data, subject to legal retention obligations.
  • Right to restriction of processing – You may ask us to limit how we use your data in certain circumstances.
  • Right to data portability – You may request your data in a structured, machine-readable format.
  • Right to object – You may object to processing based on legitimate interest, including direct marketing.
  • Right to withdraw consent – Where processing is based on consent, you may withdraw it at any time.
  • Right to lodge a complaint – You have the right to complain to the Lithuanian supervisory authority.

To exercise any of your rights, please contact us at info@itemsbox.lt. We will respond within 30 days. We may need to verify your identity before processing your request.


9. Cookies

Our website uses cookies to ensure proper functionality, analyse traffic, and (with your consent) deliver relevant marketing. Cookies are small text files stored on your device.

Types of cookies we use:

  • Strictly necessary cookies – Required for the website and shopping cart to function. These cannot be disabled.
  • Analytics cookies – Help us understand how visitors interact with our site (e.g., Google Analytics). Enabled only with your consent.
  • Marketing cookies – Used to track effectiveness of campaigns. Enabled only with your consent.

You can manage or withdraw your cookie consent at any time via the cookie banner on our website, or by adjusting your browser settings. Withdrawing consent will not affect cookies already placed.


10. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, alteration, or disclosure. These include:

  • SSL/TLS encryption for all data transmitted on our website
  • Encrypted password storage
  • Access controls limiting who can access personal data internally
  • Regular software and security updates
  • Secure hosting infrastructure within the EU

While we take all reasonable steps to protect your data, no internet transmission is completely secure. We encourage you to use a strong, unique password for your account.