Over 500+ products
Privacy policy – Swenico Pouches

Information·Swenico

Privacy policy

Updated 2026 · 13 sections

01

Controller and contact details

Swenico AB (company registration number 559386-6188), Rörläggarvägen 47, 168 33 Bromma, Sweden, is the controller for processing in the Swenico Pouches online store at swenicopouches.com.

Privacy questions and requests to exercise your rights may be sent to info@swenicopouches.com. This policy applies to visitors, customers, account holders, newsletter subscribers and reviewers.

02

Data used for purchases and delivery

When you shop with us, we process your name, email address, telephone number, shipping and billing addresses, country, ordered products, SKUs, nicotine strength, quantities, prices, discount code, payment status, order number and order history. We also store necessary payment references and receipt or invoice links, as well as any tracking link.

This information is needed to enter into and perform the purchase contract, take payment, deliver the order, send order and delivery messages, handle returns, complaints, refunds and customer service, and meet accounting and consumer-protection requirements.

03

BankID age verification

For delivery to Sweden, we use Idura and BankID to verify that you are at least 18. We process the verification result, time and method. If the age service supplies a Swedish personal identity number as verification evidence, it is transferred in a short-lived protected verification token and stored with the order. If the service supplies only an over-18 result, no personal identity number is stored.

The check is performed to comply with statutory age-verification requirements for tobacco-free nicotine products. A failed or missing result prevents the purchase. We do not use this data for profiling. If you believe the result is incorrect, you may cancel the purchase and contact us for manual assistance.

04

Payment, accounts and sign-in

Stripe processes payment and card details in the embedded checkout. Swenico receives payment status, payment references, a receipt or invoice link and the contact, billing and shipping information entered there, but we do not receive complete card details.

If you create an account, we process your email address, name, password in protected form, profile details, order history and technical account identifiers. When you use Google sign-in, we receive the basic details Google provides, normally your name, email address and account identifier. Sign-in data is used to provide and protect your account.

05

Newsletters, offers and reviews

If you subscribe to the newsletter, we store your email address, the time and source of consent and a secure unsubscribe token. This processing is based on your consent. You may withdraw it at any time through the unsubscribe link without affecting earlier processing.

When you submit a review, we process your chosen display name, rating, review text, associated product and, if you are signed in, your account identifier. Reviews are moderated before publication. Do not include sensitive or unnecessary personal data in free text. Moderation and publication rely on our legitimate interest in relevant and reliable product reviews.

We use information about previous discount-code use to prevent fraud and repeated use contrary to the offer terms. This relies on our legitimate interest in protecting the business.

07

Recipients and service providers

We never sell personal data. We disclose only what is needed to providers performing a service: Stripe for payments, Idura and BankID for age verification, the selected carrier for delivery, Resend for transactional emails and newsletters, Google when you choose Google sign-in, and Lovable Cloud for website hosting, database, authentication, storage and email delivery infrastructure.

Google also provides web fonts and may then receive technical connection data such as your IP address. Trusted advisers and authorities may receive data when needed for legal claims or required by law. The selected carrier is shown at checkout or in the dispatch message.

08

Cookies and browser storage

We do not currently use analytics or advertising measurement. The following functional storage is used so that the store and your choices work:

  • swenico-locale – language selection, cookie for up to one year.
  • swenico-visitor – recognises a returning browser for the welcome offer, cookie for up to one year.
  • swenico-age-verified – remembers your local 18+ confirmation. It does not replace the BankID check at checkout.
  • swenico-cart-v1 and swenico-favorites-v1 – cart and saved products in local storage until you remove them.
  • swenico-welcome-offer and swenico-discount-code – remember a displayed offer and selected discount code locally.
  • Sign-in data is stored locally to keep you signed in. The BankID token, guest-checkout selection and latest order are stored temporarily for the current checkout session.

You can clear cookies and local storage in your browser settings. This may sign you out and remove your cart, wishlist, language choice and checkout progress.

09

How long we keep data

  • Order and accounting records are normally kept for seven years after the end of the calendar year in which the financial year ended, to the extent required by Swedish accounting law.
  • Personal identity numbers and age evidence are kept for as long as needed to demonstrate the statutory age check and handle legal claims, after which they are erased or anonymised.
  • Account data is kept while the account exists. Information also forming part of an order or accounting record may need to be kept longer.
  • Newsletter data is kept until you unsubscribe; limited information may then be retained to respect your wish not to receive further messages.
  • Reviews are kept while relevant or until removed following a justified request.
  • Customer-service and security data is kept for as long as the matter or security need requires, then erased or anonymised.

10

Transfers outside the EU/EEA

Some providers are global and may process data outside the EU/EEA. When this occurs, we and the provider use a lawful transfer mechanism, such as an adequacy decision, the EU–US Data Privacy Framework for certified US recipients, or the European Commission's standard contractual clauses with supplementary safeguards where needed.

11

Security and access

We use encrypted connections, access controls, separate administrator roles, restricted permissions and logical security measures. Access is limited to people and providers who need the information for their duties. No transmission or storage can be guaranteed entirely risk-free, but we continuously work to prevent unauthorised access, alteration and loss.

12

Your rights

You may request access, rectification, erasure, restriction and, where applicable, data portability. You may object to processing based on legitimate interests or direct marketing and withdraw consent at any time. You may also request information about safeguards for international transfers.

Contact info@swenicopouches.com. We may need to verify your identity before releasing or changing data. Erasure does not apply to information we must retain by law or need for legal claims. We normally respond within one month.

13

Complaints and changes

If you are dissatisfied with our processing, you may complain to the Swedish Authority for Privacy Protection at imy.se, or to the supervisory authority where you live or work.

We update this policy when our processing or the rules change. The latest version is always available here, and we will provide suitable notice of material changes. Last updated: 27 September 2026.