Privacy policy

At Mammut, your privacy is our priority. This Privacy Policy explains how we collect, use, share, and protect your personal data when you visit our website or purchase from our store, in compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.


1. Who We Are

Mammut is the controller of your personal data.


2. What Data We Collect

We may collect the following categories of personal data:

  • Identity Information: Name, email address, phone number, shipping/billing address

  • Payment Information: (processed securely via third-party providers – we do not store card details)

  • Order History & Account Details

  • Device Information & Browsing Data: IP address, browser type, operating system, referring URLs, page views, and cookies

  • Marketing Preferences and Communication History


3. How We Use Your Data

We process your data for the following purposes:

  • To process and deliver your orders

  • To create and manage your customer account

  • To communicate with you (order confirmations, customer service, updates)

  • To improve our website and services

  • To comply with legal obligations

  • With your consent, to send you newsletters or marketing communications


4. Legal Bases for Processing

Under GDPR, we rely on the following legal grounds:

  • Performance of a contract: When processing your orders

  • Consent: For sending marketing communications

  • Legal obligation: For tax, accounting, and compliance purposes

  • Legitimate interests: For website security, analytics, and service improvement


5. How We Share Your Data

We may share your data with:

  • Trusted service providers: such as payment processors (e.g., Stripe, PayPal), shipping companies, and IT/cloud hosting providers

  • Legal authorities: when required by law or for fraud prevention

  • Analytics and marketing tools (e.g., Google Analytics, Meta/Facebook, Klaviyo) – only with your consent for cookies/ads

We do not sell your personal data to third parties.


6. International Data Transfers

Some of our service providers may be located outside the European Economic Area (EEA). In such cases, we ensure that adequate safeguards (such as EU Standard Contractual Clauses) are in place to protect your data.


7. Data Retention

We retain your data only as long as necessary to fulfill the purposes outlined in this policy, or as required by law (e.g., 7 years for accounting records).


8. Your Rights Under GDPR

You have the right to:

  • Access your personal data

  • Correct inaccurate or incomplete data

  • Erase your data ("right to be forgotten")

  • Restrict or object to processing

  • Withdraw consent at any time (e.g., for marketing)

  • Data portability – request a copy in a structured, machine-readable format

  • Lodge a complaint with your local Data Protection Authority


9. Cookies and Tracking Technologies

We use cookies and similar technologies for functionality, analytics, and marketing. You can manage your preferences in our [Cookie Settings] or via your browser.

For more details, see our [Cookie Policy].


10. Marketing Communications

You can opt in or out of marketing emails at any time. A link to unsubscribe is included in every marketing message. We only send you marketing with your clear, affirmative consent.


11. Security

We implement appropriate technical and organisational measures to protect your personal data, including encryption, secure servers, and access controls.


12. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated "Effective Date". Please review it regularly.