Privacy policy

Privacy Policy

Last updated: 30 July 2026

This is an English translation of our Danish privacy policy. The Danish version is the legally binding one — if the two differ, the Danish text applies.


1. Data controller

Limitless Card ApS
Niels Ebbesens Gade 22, 8900 Randers C, Denmark
Danish company reg. no. (CVR): 40223770
Email: noorbayt@growgineer.com

We are the data controller for the personal data we process about you when you visit noorbayt.com, buy from us or sign up for our newsletter.

We are not required to have a Data Protection Officer (DPO), and we have not appointed one. All questions about your data should be sent to the address above.


2. What data do we process — and why?

2.1 When you buy

Data Purpose Legal basis
Name, address, email, phone To deliver your order GDPR art. 6(1)(b) — performance of a contract
Order and payment data To complete and account for the purchase Art. 6(1)(b) and art. 6(1)(c) — legal obligation
Delivery address Passed to the printing facility and the carrier Art. 6(1)(b)
Correspondence with us Customer service, complaints, documentation Art. 6(1)(b) and art. 6(1)(f)

We do not see your full card details. They go directly to the payment provider.

2.2 When you sign up for the newsletter

Data Purpose Legal basis
Email address, and name if given To send news and offers Your consent, art. 6(1)(a), cf. section 10 of the Danish Marketing Practices Act
Whether you open and click in the email To keep the content relevant Consent, art. 6(1)(a)

You can withdraw your consent at any time using the unsubscribe link at the bottom of every email, or by writing to us. This does not affect the lawfulness of what we did before you withdrew it.

2.3 When you visit the site

Data Purpose Legal basis
IP address, browser, device, time Operation, security, abuse prevention Art. 6(1)(f) — legitimate interest
Necessary cookies (basket, session, security) To make the site work Art. 6(1)(f) + the exemption in the cookie rules
Statistics and marketing cookies Measurement and marketing Your consent

See our Cookie Policy for the full list and for how to change your choice.


3. Who do we share data with?

We never sell your personal data. We share it only with suppliers who process it on our behalf (data processors), and only what they need:

Recipient Role What they receive
Shopify (Shopify International Ltd., Ireland) E-commerce platform and hosting Order, account and visit data
Gelato (Gelato ASA, Norway, with printing facilities in the EU and globally) Printing and shipping Name, delivery address, order lines
Shopify Payments (Shopify International Ltd., Ireland) Card payments Payment and order data
MobilePay (Vipps MobilePay AS, Norway) Payment by MobilePay Payment and order data
Carrier (e.g. PostNord, DHL, GLS) Delivery Name, address, and phone and email for tracking where relevant
Our accountant / bookkeeping Accounts Invoice data

We have data processing agreements with the suppliers who process data on our behalf.

We may also disclose data where required by law, or where necessary to establish or defend a legal claim.

Transfers to countries outside the EU/EEA

Some of our suppliers process data outside the EU/EEA — among other reasons because Gelato prints at the facility closest to the recipient, and because Shopify has group companies in the USA and Canada.

Where that happens, we ensure a lawful basis, typically the European Commission's Standard Contractual Clauses (SCCs) or an applicable adequacy decision. You can obtain a copy of the basis by writing to noorbayt@growgineer.com.

If you order delivery to a country outside the EU/EEA, transferring your address there is necessary in order to perform the contract with you.


4. How long do we keep the data?

Type Retention period
Order and invoice data 5 years after the end of the financial year the purchase relates to (the Danish Bookkeeping Act)
Customer service correspondence Up to 2 years after the case is closed, or for as long as a complaint case is running
Newsletter Until you unsubscribe — after that we keep documentation of the consent and the unsubscription for up to 2 years
Cookies See the Cookie Policy — each cookie has its own lifetime
Log entries and security data Typically up to 12 months

When the purpose has been fulfilled, and no law requires us to keep the data, we delete or anonymise it.


5. Your rights

Under the General Data Protection Regulation you have the right to:

  • Access — to be told what data we hold about you, and to receive a copy
  • Rectification — to have incorrect data corrected
  • Erasure — to have data deleted once we no longer have a basis for holding it
  • Restriction — to have processing paused in certain cases
  • Objection — to object to processing based on legitimate interest. If you object to direct marketing, we always stop
  • Data portability — to receive the data you have given us yourself in a machine-readable format, or to have it passed on
  • Withdrawal of consent — at any time, without affecting the lawfulness of what happened beforehand

Write to noorbayt@growgineer.com. We reply within one month. If the case is complex, we may extend the deadline by two months — you will be told if we do.

We may ask for documentation of your identity before releasing data. That is to protect you from others gaining access to your data.


6. Security

The site runs over an encrypted connection (HTTPS). Access to customer data is limited to the people who need it, and is protected by password and two-factor authentication. Payment data is processed solely by our payment providers, see section 3.

If a personal data breach occurs that is likely to result in a high risk to your rights, we will notify you — and the Danish Data Protection Agency within 72 hours where the rules require it.


7. Children

The shop is aimed at adults. We do not knowingly collect data about children under 15. If we become aware that we have done so without the consent of a parent or guardian, we delete it.


8. Automated decisions

We do not make decisions about you based solely on automated processing, and we do not carry out profiling with legal effect for you.


9. Complaints

If you are unhappy with how we process your data, please write to us first.

You can always complain to:

The Danish Data Protection Agency (Datatilsynet)
Carl Jacobsens Vej 35, 2500 Valby, Denmark
Phone +45 33 19 32 00 · dt@datatilsynet.dk · www.datatilsynet.dk


10. Changes

We update this policy when our processing changes. The date at the top shows when it was last amended. For material changes we will give notice on the site or by email.