Privacy policy
Privacy Policy
Last updated: 30 July 2026
This is an English translation of our Danish privacy policy. The Danish version is the legally binding one — if the two differ, the Danish text applies.
1. Data controller
Limitless Card ApS
Niels Ebbesens Gade 22, 8900 Randers C, Denmark
Danish company reg. no. (CVR): 40223770
Email: noorbayt@growgineer.com
We are the data controller for the personal data we process about you when you visit noorbayt.com, buy from us or sign up for our newsletter.
We are not required to have a Data Protection Officer (DPO), and we have not appointed one. All questions about your data should be sent to the address above.
2. What data do we process — and why?
2.1 When you buy
| Data | Purpose | Legal basis |
|---|---|---|
| Name, address, email, phone | To deliver your order | GDPR art. 6(1)(b) — performance of a contract |
| Order and payment data | To complete and account for the purchase | Art. 6(1)(b) and art. 6(1)(c) — legal obligation |
| Delivery address | Passed to the printing facility and the carrier | Art. 6(1)(b) |
| Correspondence with us | Customer service, complaints, documentation | Art. 6(1)(b) and art. 6(1)(f) |
We do not see your full card details. They go directly to the payment provider.
2.2 When you sign up for the newsletter
| Data | Purpose | Legal basis |
|---|---|---|
| Email address, and name if given | To send news and offers | Your consent, art. 6(1)(a), cf. section 10 of the Danish Marketing Practices Act |
| Whether you open and click in the email | To keep the content relevant | Consent, art. 6(1)(a) |
You can withdraw your consent at any time using the unsubscribe link at the bottom of every email, or by writing to us. This does not affect the lawfulness of what we did before you withdrew it.
2.3 When you visit the site
| Data | Purpose | Legal basis |
|---|---|---|
| IP address, browser, device, time | Operation, security, abuse prevention | Art. 6(1)(f) — legitimate interest |
| Necessary cookies (basket, session, security) | To make the site work | Art. 6(1)(f) + the exemption in the cookie rules |
| Statistics and marketing cookies | Measurement and marketing | Your consent |
See our Cookie Policy for the full list and for how to change your choice.
3. Who do we share data with?
We never sell your personal data. We share it only with suppliers who process it on our behalf (data processors), and only what they need:
| Recipient | Role | What they receive |
|---|---|---|
| Shopify (Shopify International Ltd., Ireland) | E-commerce platform and hosting | Order, account and visit data |
| Gelato (Gelato ASA, Norway, with printing facilities in the EU and globally) | Printing and shipping | Name, delivery address, order lines |
| Shopify Payments (Shopify International Ltd., Ireland) | Card payments | Payment and order data |
| MobilePay (Vipps MobilePay AS, Norway) | Payment by MobilePay | Payment and order data |
| Carrier (e.g. PostNord, DHL, GLS) | Delivery | Name, address, and phone and email for tracking where relevant |
| Our accountant / bookkeeping | Accounts | Invoice data |
We have data processing agreements with the suppliers who process data on our behalf.
We may also disclose data where required by law, or where necessary to establish or defend a legal claim.
Transfers to countries outside the EU/EEA
Some of our suppliers process data outside the EU/EEA — among other reasons because Gelato prints at the facility closest to the recipient, and because Shopify has group companies in the USA and Canada.
Where that happens, we ensure a lawful basis, typically the European Commission's Standard Contractual Clauses (SCCs) or an applicable adequacy decision. You can obtain a copy of the basis by writing to noorbayt@growgineer.com.
If you order delivery to a country outside the EU/EEA, transferring your address there is necessary in order to perform the contract with you.
4. How long do we keep the data?
| Type | Retention period |
|---|---|
| Order and invoice data | 5 years after the end of the financial year the purchase relates to (the Danish Bookkeeping Act) |
| Customer service correspondence | Up to 2 years after the case is closed, or for as long as a complaint case is running |
| Newsletter | Until you unsubscribe — after that we keep documentation of the consent and the unsubscription for up to 2 years |
| Cookies | See the Cookie Policy — each cookie has its own lifetime |
| Log entries and security data | Typically up to 12 months |
When the purpose has been fulfilled, and no law requires us to keep the data, we delete or anonymise it.
5. Your rights
Under the General Data Protection Regulation you have the right to:
- Access — to be told what data we hold about you, and to receive a copy
- Rectification — to have incorrect data corrected
- Erasure — to have data deleted once we no longer have a basis for holding it
- Restriction — to have processing paused in certain cases
- Objection — to object to processing based on legitimate interest. If you object to direct marketing, we always stop
- Data portability — to receive the data you have given us yourself in a machine-readable format, or to have it passed on
- Withdrawal of consent — at any time, without affecting the lawfulness of what happened beforehand
Write to noorbayt@growgineer.com. We reply within one month. If the case is complex, we may extend the deadline by two months — you will be told if we do.
We may ask for documentation of your identity before releasing data. That is to protect you from others gaining access to your data.
6. Security
The site runs over an encrypted connection (HTTPS). Access to customer data is limited to the people who need it, and is protected by password and two-factor authentication. Payment data is processed solely by our payment providers, see section 3.
If a personal data breach occurs that is likely to result in a high risk to your rights, we will notify you — and the Danish Data Protection Agency within 72 hours where the rules require it.
7. Children
The shop is aimed at adults. We do not knowingly collect data about children under 15. If we become aware that we have done so without the consent of a parent or guardian, we delete it.
8. Automated decisions
We do not make decisions about you based solely on automated processing, and we do not carry out profiling with legal effect for you.
9. Complaints
If you are unhappy with how we process your data, please write to us first.
You can always complain to:
The Danish Data Protection Agency (Datatilsynet)
Carl Jacobsens Vej 35, 2500 Valby, Denmark
Phone +45 33 19 32 00 · dt@datatilsynet.dk · www.datatilsynet.dk
10. Changes
We update this policy when our processing changes. The date at the top shows when it was last amended. For material changes we will give notice on the site or by email.