Privacy Policy

We collect what an order needs and little else, we don't track you across the web, and our analytics set no cookies. Here is exactly what happens to your data.

Ostuinfo eesti keeles — the same information in Estonian.

1. Controller

ProEngineering OÜ, registry code 12603169, Kirsi 6-41, 10616 Tallinn, Estonia. E-mail: info@wetoutlet.com. Phone: +372 566 00707.

2. What we collect and why

  • Ordering and delivery (contract, GDPR art 6(1)(b)) — name, e-mail, phone, delivery address, order and payment confirmation data. Without this data we cannot fulfil the order.
  • Customer account (contract) — login e-mail, order history, saved addresses.
  • Business account applications(contract / legitimate interest) — company name, registry code and VAT number, verified against the EU VIES registry.
  • Support enquiries (legitimate interest, art 6(1)(f)) — the content of our correspondence, including anything you send us through the form on our Support page: your message, your e-mail address, and the order number if you give one.
  • Accounting (legal obligation, art 6(1)(c)) — invoicing data, as required by Estonian accounting law.
  • Problem reports (legitimate interest) — the bug button at the bottom of our pages sends what you write and whether it is a fault or an idea, together with the page address without any part after a “?” and with order numbers and other codes cut out, your browser’s identification string, window size, language and time zone, and the names of recent errors on the page. Every report also carries a picture of the page as it was when you opened the form. Before the picture is drawn, every form field is emptied and covered in grey, and on your account pages and in the confirmation after a support message all text and images are left blank, so the picture shows only the layout. The picture is drawn in your browser; what you see does not change. Our pages also report their own errors automatically, without a click: the error message, the address of the script and the line, the page path and your browser. Nothing you typed into a form is sent. The button and the automatic error reports are off during checkout and on order pages.
  • Website statistics (legitimate interest) — self-hosted Umami analytics. It sets no analytics cookies and processes the page URL, referrer, browser, device, language, country and a pseudonymous session identifier derived from technical request data. Raw IP addresses are not retained. We do not send names, e-mail addresses, account IDs or order details to analytics.

3. Cookies

We use cookies and similar technologies necessary for the cart, the account, checkout security and fraud prevention. Stripe may set payment-security and authentication cookies when its payment interface is used. We set no advertising or cross-site tracking cookies. If optional analytics or preference technologies are introduced later, they will be activated only after consent where consent is required.

4. Recipients and processors

  • Stripe Payments Europe Ltd — card payment processing, together with the banks and card networks that settle the payment;
  • DPD Eesti AS and its partner carriers in the destination country — delivery;
  • hosting, backup and IT infrastructure — our own servers, located in the European Union;
  • product image storage and processing — our own EU infrastructure;
  • self-hosted Umami analytics — our own EU infrastructure;
  • problem reports — buglog.leonov.ee, a collector on our own server in Estonia, shared with our owner’s other sites;
  • web font delivery — api.fontshare.com (Indian Type Foundry);
  • our accounting service provider — statutory bookkeeping;
  • state authorities — only where required by law.

We do not sell or rent personal data. Some service providers may process personal data outside the EEA. Where that happens, the transfer is based on an adequacy decision — including the EU–US Data Privacy Framework for certified recipients — or on Standard Contractual Clauses with appropriate supplementary safeguards. For the payment provider, see the Stripe Privacy Policy and the Stripe Data Transfers Addendum; a copy of the applicable safeguards can be requested at info@wetoutlet.com.

5. How long we keep it

  • Order, contract and claims data — for the duration of contract performance and the limitation period for related claims (generally 3 years from performance; where a dispute has arisen, until it is finally resolved).
  • Accounting source documents — 7 years from the end of the financial year in which the transaction was recorded (Accounting Act § 12).
  • Support correspondence — kept while your enquiry is open and afterwards only for as long as it may still be needed for a related claim, return or warranty question. Ask us to delete it and we will, unless an invoice has to stay for the accounting period below.
  • Customer account — until you ask us to delete it.
  • Abandoned carts and unfinished checkouts — kept while they can still be resumed. Ask us to delete yours and we will.
  • Problem reports and their page pictures — kept while they are needed to find and fix the problem; there is no automatic deletion.
  • Technical server logs and analytics events — kept only as long as needed for security, troubleshooting and traffic measurement, and deleted or aggregated once that purpose is served.

On expiry, data is deleted or anonymised.

Backups of our servers are kept separately and purged on a schedule we are setting; until then a deleted item can remain in a backup.

6. Your rights

You have the right of access, rectification, erasure, portability, restriction and objection (including to direct marketing), and you may withdraw consent at any time. Write to info@wetoutlet.com — we respond within one month. We may need to verify your identity before acting on a request.

You can also complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, Tatari 39, 10134 Tallinn, info@aki.ee) or to the supervisory authority in your own country.

7. Security

Data is accessible only to the people who need it for their work. Payment data is handled exclusively by the payment provider over encrypted channels and never reaches our servers.

8. Changes

We may update this policy. The current version, with its date, is always published on this page.

Last updated 10 October 2026