Privacy Policy
Welcome to the official website of stratonoakland.com.
Privacy Policy
1. Terms
This is the Privacy Policy of Shamanic Groove LTD (www.stratonoakland.com) (“Stratonoakland,” “we,” “our,” or “us”).
It explains how we collect, use, store, and disclose information obtained from our customers, visitors to our websites, and, in some cases, visitors to our customers’ websites (“Users”).
Capitalized terms not defined here have the meanings given in our Terms of Service, available at https://stratonoakland.com/privacy-policy/.
2. Purpose
Because we operate online, we must gather information from Users. Although this document is titled “Privacy Policy,” it covers every way we handle both personally identifiable information (“PI”) and anonymous information (“AI”)—collectively, “Information.”
Information transmitted to, collected by, processed by, or provided to us is not automatically deemed private. Please read this Policy carefully to understand how we treat such data.
3. Acceptance of this Privacy Policy
You accept this Policy when you:
-
browse or use our website (www.stratonoakland.com, hereafter “Website”);
-
place an order for Services (as defined in the Terms of Service); or
-
join our email list.
4. Changes to the Privacy Policy
If we make material changes, we will notify you by email, post a notice on the Website, or highlight the updated Policy on the Website itself.
You agree that electronic notices satisfy any legal communication requirements.
If you do not agree with the changes, we will continue to store and use PI collected before the change in accordance with the Policy that was in effect at that time.
5. Information We Collect & How We Use It
General use. We may use PI as required or permitted by law, including responding to legal process (court orders, subpoenas, etc.). We may disclose PI to law-enforcement or regulators as part of an investigation into Website activity (e.g., suspected violations), and we use commercially reasonable measures to limit such disclosure. We may also use PI in establishing or defending legal claims. Any information sent to us is not automatically confidential and may be shared with any person or entity, regardless of how you label it.
Customer account data. Customers provide us with names, addresses, phone numbers, usernames, credit/debit-card or bank details, and other PI needed to deliver Services. We may also obtain information from third parties (e.g., credit-rating agencies) and collect usage data about our Services. Combined, this data forms each customer’s “Registration & Billing Information.”
User inquiries. Users who contact us may need to provide additional information so we can resolve their questions or improve our business (“User Inquiry Information”).
Anonymous information. We collect AI about how you use the Website (browser type, IP address, previously visited URL, date & time of access, etc.). We place a cookie or pixel tag on your device containing a unique identifier. You can refuse to supply such data or block cookies, but portions of the site may not function correctly and some Services may be unavailable. We use AI to enhance the Website experience, tailor content, understand usage, verify proper behavior, and monitor security and integrity.
Third-party agents – access to and use of PI. We may contract with third parties to assist us—hosting, data storage, marketing, payment processing, order fulfillment, returns, etc. Those parties must agree in writing to protect your data at least to the level stated in this Policy.
External links & third-party content. Our Website contains links to other sites or third-party content (e.g., social-media links). We neither own nor control those parties and are not responsible for their information or privacy practices.
Customer inquiries. We use User Inquiry Information to identify Users personally when needed, to deliver our Services, and to market new products or services. We share this information with third parties only when:
-
we must diagnose and solve a Service issue that we cannot resolve internally; or
-
a third-party product vendor needs details about a particular customer.
Whenever we share User Inquiry Information, the recipient must keep it confidential. Note that third-party product vendors may have privacy policies that differ from ours; on request, we will provide their names and links to their policies.
Children’s information. We do not knowingly collect PI from children under 13. If a parent or guardian believes a child under 13 has provided PI to us, that parent should contact us immediately. Except when responding to legitimate requests from public authorities, Stratonoakland discloses children’s PI only to agents acting on our behalf and only for the purposes stated in this Policy (or any purpose stated at the time of collection).
6. Your Access and Ability to Modify PI
You may request access to, correction of, or updates to your PI by contacting us (see the “Contact” section). For security, we may ask you to verify your identity. You can also:
-
modify your data through your account dashboard; or
-
ask us to delete inquiry-related information via the contact form at https://stratonoakland.com/.
7. Deletion and Retention of PI
You may ask us to delete your PI, and we will make reasonable efforts to honor the request. However, we may retain and use PI for periods required or permitted by law or by sound business practice.
8. Security
We employ technical, physical, and administrative safeguards designed to protect PI against loss and against unauthorized access, use, or disclosure. Passwords are stored on our servers in encrypted form. Unless this Policy states otherwise, employees must keep all such information confidential.
9. HIPAA
The Health Insurance Portability and Accountability Act (HIPAA) does not apply to the services we provide. We are neither a “Covered Entity” nor a “Business Associate” as defined under HIPAA. Consequently, our Service is not designed to meet HIPAA standards, and it must not be used to submit, store, or disclose information that would be subject to HIPAA in a HIPAA-compliant manner.
10. Testimonials
Under our Terms of Service (https://stratonoakland.com/terms-of-services/) you may provide us with a testimonial regarding your use of the Services.
-
We may, at our discretion, use that testimonial to promote our Services.
-
You agree that we may display your first name, last initial, state, voice or likeness, and/or contact details alongside the testimonial.
-
If you later wish us to stop using your testimonial, contact us via the details in Section 19 of the Terms of Service and we will cease use as soon as your request is processed.
11. Privacy complaints from EU & Swiss citizens
Stratonoakland complies with the EU-U.S. and Swiss-U.S. Privacy Shield Frameworks as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information from EU member countries and Switzerland.
-
We have certified that we adhere to the Privacy Shield Principles of Notice, Choice, Accountability for Onward Transfer, Security, Data Integrity & Purpose Limitation, Access, and Recourse/Enforcement/Liability.
-
Stratonoakland remains responsible and liable, under the Principles, if any third-party agent processes PI in a way that conflicts with the Principles—unless we prove we are not responsible for the event giving rise to the damage.
-
Stratonoakland is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission.
-
Under certain conditions, you may invoke binding arbitration before a Privacy Shield Panel.
How to raise a complaint
-
First contact us at
Mail: stratonoaklandprivacy@stratonoakland.com
Address: Svoboda Str. 7, Floor 2, 2800 Sandanski, Bulgaria
We will attempt to resolve your issue free of charge. -
If unresolved, we will refer the matter to BBB EU Privacy Shield, a non-profit alternative dispute-resolution provider located in the United States and operated by the Council of Better Business Bureaus.
Visit www.bbb.org/EU-privacy-shield/for-eu-consumers/ for more information or to file a complaint. -
If still unresolved, binding arbitration before a Privacy Shield Panel may be available in limited circumstances.
12. Policy Date
This Privacy Policy was last updated on 29 August 2022.
Website Privacy Notice
A. Scope for stratonoakland.com & my.stratonoakland.com
Protecting your personal data (“data” or “PI”) is very important to us.
Capitalized terms not defined here have the meanings in our Terms of Service (https://stratonoakland.com/terms-of-services/).
Controller & Data-Protection Officer
Shamanic Groove LTD
Svoboda Str. 7, Floor 2, 2800 Sandanski, Bulgaria
Email (general): office@stratonoakland.com
Email (DPO): office@stratonoakland.com
EU-U.S. & Swiss-U.S. Privacy Shield
Stratonoakland remains certified under, and adheres to, the Privacy Shield Principles (Notice; Choice; Accountability for Onward Transfer; Security; Data Integrity & Purpose Limitation; Access; Recourse, Enforcement & Liability).
If we transfer your PI to a third party, we remain responsible and liable if that party processes it contrary to the Principles—unless we prove we were not responsible for the event giving rise to the damage.
We are subject to the investigatory and enforcement powers of the U.S. FTC.
Changes to this Policy
If we make material changes, we will notify you via email, post a notice on the Website, or highlight the updated Policy on-site.
You agree that such electronic communications satisfy any legal notice requirements.
Legal Bases for Processing (GDPR)
Unless otherwise stated, we rely on:
-
Art. 6 (1)(a) GDPR – your consent.
-
Art. 6 (1)(b) – processing necessary to perform a contract.
-
Art. 6 (1)(c) – compliance with a legal obligation.
-
Art. 6 (1)(d) – protection of vital interests.
-
Art. 6 (1)(f) – our legitimate interests, provided they are not overridden by your rights.
Retention Periods
We delete or anonymize data in accordance with Art. 17 & 18 GDPR once the purpose is fulfilled, unless legal retention rules require longer storage. During any extended retention, processing is blocked and the data are not used for other purposes.
Server-Log Data
For purely informational visits you do not need to provide active PI.
Your browser automatically transmits:
-
date & time of access
-
browser type & settings
-
operating system
-
previously visited URL
-
transferred data volume & access status
-
your IP address
These data are stored on our servers—separate from other PI—for up to 7 days and are used solely to deliver the site, ensure IT security, verify attacks, and maintain stability. Legal basis: Art. 6 (1)(b), (c) & (f) GDPR.
Shopping Cart & my.stratonoakland.com Portal
When you place an order through our cart, you must provide certain PI that we need to process the transaction. Mandatory fields are marked; other fields are optional.
-
We process this data to fulfill your purchase (Art. 6 (1)(b) GDPR).
-
A customer account is created so you can manage future purchases; you may edit or delete data there at any time.
-
We store the IP address used at sign-up, plus time of registration and confirmation, to verify your identity and prevent misuse (Art. 6 (1)(c) & (f) GDPR).
-
Payment details may be passed to our bank or payment processor.
-
All checkout traffic is TLS-encrypted to prevent unauthorized access.
Contact Forms, E-mail, Telephone
-
Pure information requests are processed with your consent (Art. 6 (1)(a)).
-
If the inquiry relates to a contract, we process it under Art. 6 (1)(b).
-
Required fields: name & e-mail; all other data are voluntary.
-
Messages may be stored in our CRM and are deleted once handled unless legal retention rules require otherwise.
Newsletter
-
Double-opt-in: after signing up you must confirm via a link sent to your e-mail.
-
If unconfirmed within 24 hours, data are blocked and erased after one month.
-
We log IP address and timestamps for proof of consent (Art. 6 (1)(c) & (f)).
-
You can unsubscribe anytime via the link in each newsletter or by e-mailing contact@stratonoakland.com.
-
We track newsletter opens and clicks using 1-pixel web beacons combined with your e-mail and a unique ID to improve content relevance.
Legal basis: Art. 6 (1)(a) GDPR.
Your GDPR Rights
You may, at no charge:
-
Access your data (Art. 15)
-
Rectify inaccurate data (Art. 16)
-
Erase data (“right to be forgotten,” Art. 17)
-
Restrict processing (Art. 18)
-
Data portability (Art. 20)
-
Object to processing (Art. 21)
Contact us via https://stratonoakland.com/ to exercise any right.
You also have the right to lodge a complaint with a supervisory authority.
Social-Media Integrations
For privacy, our site uses static social buttons. No data reach a social network until you actively click a button (consent under Art. 6 (1)(a)). Providers:
-
Facebook – Meta Platforms, Inc.
-
LinkedIn – LinkedIn Ireland Unlimited Company
-
YouTube – Google LLC
-
Twitter – Twitter International Company
All providers participate in the EU-U.S. Privacy Shield.
Third-Party Processors
We rely on vetted service providers—hosting, data storage, marketing, payment, fulfilment—who process data only per our instructions under Art. 28 GDPR. Each must protect your privacy to the level set in this Policy. If we transfer your PI to any third party, we remain liable under the Privacy Shield unless we prove we are not responsible for any breach.
Cookies & Analytics
Tool | Purpose | Opt-Out |
---|---|---|
Google Analytics (with IP masking) | Site usage stats, remarketing | Browser add-on: https://tools.google.com/dlpage/gaoptout/ |
DoubleClick by Google | Ad relevance & frequency capping | Ads settings: https://www.google.com/settings/ads |
Facebook Pixel | Measure ad conversions | http://optout.aboutads.info/#/ |
Bing Ads | Conversion tracking | http://choice.microsoft.com/opt-out |
Hotjar | UX heatmaps & sessions | https://www.hotjar.com/policies/do-not-track/ |
Glassdoor | Job-related analytics | https://www.glassdoor.com/about/privacy.htm |
You can block cookies in your browser; some features may then be unavailable. Legal basis: Art. 6 (1)(f) (legitimate interest in analytics & security) unless consent is required.
Security Measures
We apply technical, physical, and administrative safeguards—including SSL/TLS encryption, encrypted password storage, and strict access controls—to protect PI against loss, misuse, or unauthorized disclosure