1. Data Controller
The controller processing personal data under this Policy is:
- Sole Proprietor Evgeny Viktorovich Vigovsky
- TIN (ИНН): 380409102716
- OGRNIP: 324210000043335
- Address: 7 Pravaya Naberezhnaya Sugutki St., office 11, Cheboksary, Russia
- Website: https://chifat.ru
- Email for privacy matters: [email protected]
Person responsible for personal data processing — Evgeny Vigovsky personally (as a sole proprietor without staff).
2. Legal bases for processing
We process personal data on the following legal bases:
- Consent of the data subject — Art. 6(1)(a) GDPR, equivalent to Art. 6(1)(1) of Russian Federal Law 152-FZ.
- Performance of a contract to which the data subject is party — Art. 6(1)(b) GDPR (sourcing-as-a-service contract published on chifat.ru).
- Compliance with a legal obligation (Russian Tax Code, Accounting Law 402-FZ).
- Legitimate interest of the controller — security, fraud prevention, service improvement (with balancing test).
3. Purposes of processing and data composition
We process personal data strictly for the following purposes:
- User registration and authentication — name, email, phone, login, password stored as a hash.
- Provision of sourcing services (purchasing goods in China on client order) — name, email, phone, delivery address, order history, refund details.
- Contract conclusion and performance — name, TIN/company registration (for entities), banking details for invoices.
- Order status notifications and client communication — email, phone, communication history.
- Accounting and tax compliance — name, document details, transaction amounts.
- Marketing emails (only with separate opt-in consent) — email, name, interest segmentation.
- Website security and operation — IP address, user-agent, cookies, audit logs.
- Traffic and usability analytics (ONLY with consent to analytics cookies) — IP address, user-agent, cookies, data about actions on the site's pages, including Yandex.Metrika Webvisor session recordings (see section 9).
4. Categories of personal data
We process only ordinary categories of personal data. Special categories (health, race, religion, political views, sexual life) and biometric data are NOT processed.
- Full name
- Email address
- Phone number
- Delivery address
- Refund details (account/card number)
- TIN, company registration numbers (for business clients)
- Login and password stored as a hash (irreversible hashing)
- Order history (amounts, statuses)
- IP address, user-agent, cookies
- User behaviour data on the site (analytics; with consent to analytics — including Yandex.Metrika Webvisor session recordings, see section 9)
5. Categories of data subjects
- Individual clients (marketplace sellers)
- Sole proprietors (personal data as natural persons)
- Representatives of corporate clients (name, phone, email, position)
- Website visitors (non-registered — IP, cookies, metrics)
- Marketing newsletter subscribers (email, name, segment)
6. Types of processing operations
Processing method — mixed (automated + non-automated), via the Internet over secure channels.
Operations performed:
- Collection
- Recording
- Organisation
- Storage
- Adaptation or alteration
- Retrieval
- Use
- Disclosure by transmission to third parties — recipients; some of them are located outside the Russian Federation, see sections 9 and 10
- Anonymisation (for analytics)
- Restriction
- Erasure
- Destruction
7. Retention periods
Personal data is retained no longer than necessary for the purposes of processing, unless required otherwise by law.
- Client accounts — for the duration of the contract + 3 years (statute of limitations).
- Accounting documents and order data — 5 years after the end of the reporting year (Russian Accounting Law 402-FZ).
- Cookies and sessions — up to 1 year from last activity.
- Audit logs — 3 years from the record date.
- Marketing data — until consent withdrawal.
Upon achievement of processing purposes or consent withdrawal — personal data is erased or anonymised within 30 days, unless required otherwise by law.
8. Methods of processing
- Automated processing — via the chifat.ru information system.
- Non-automated processing — for paper-based primary accounting documents and written requests.
9. Disclosure to third parties
Personal data is disclosed to third parties — recipients — to the extent necessary for the purposes of processing. To recipients entrusted by the operator with processing (processors), data is disclosed on the operator's instructions under a contract with them (entrustment of processing, Art. 6(3) of 152-FZ). For service tasks, including preparing, translating and checking the materials of the site and the catalogue, the operator uses language-model and image-generation services; the personal data of clients and visitors is not transferred to them, and the requests the site sends to them are checked automatically before sending — a request in which personal data is detected is not sent.
Personal data recipients registry — /privacy/subprocessors. Main recipients:
- Cloud.ru (LLC Cloud Technologies), Russia — hosting of the site and databases; storage of RU citizens' personal data within Russia (Art. 18(5) of 152-FZ).
- Hetzner Online GmbH, Germany (processing in Finland, EU) — hosting of the server infrastructure; storage of the personal data of subjects who are not RU citizens.
- Cloudflare Inc., USA — reverse proxy for all of the site's traffic (content delivery network, DNS, protection against attacks). The visitor's connection to the site, including form submissions, terminates at a Cloudflare edge node and is passed on to our server through it, so everything that passes through the site during a visit is available to that node: the IP address, request headers (cookies included), the content of requests and responses, including data entered into forms — including for visitors from Russia. Second leg — the Cloudflare Turnstile anti-bot check on the login, signup, password-recovery, contact, checkout and data-subject-request forms: when the form opens, the browser loads the challenge script from a Cloudflare node, which sees the IP address, user agent and browser details; on submit, the server passes the challenge result and the visitor's IP address to Cloudflare. The check itself does not pass the form content (as part of the site's traffic, that content goes through the Cloudflare proxy — see above). Loaded without consent — the ground is the same as for error monitoring: the operator's legitimate interest in securing the service (152-FZ Art. 6(1)(7)).
- Yandex Cloud (LLC Yandex.Cloud), Russia — the Postbox service for sending the site's service e-mails (the recipient's e-mail address, the text of the message).
Web analytics and service observability. chifat.ru uses the following analytics and error monitoring tools:
- Yandex.Metrika (LLC Yandex, RU) — site analytics counter and Webvisor session recording. Loaded ONLY after the user grants consent to analytics cookies (Art. 9 of 152-FZ / Art. 6(1)(a) GDPR). Webvisor records the visitor's session on the site's open pages: pointer movements, clicks, scrolling and the page content as the visitor sees it. The purpose of recording is analysing the usability of the site: finding navigation and page-layout errors. Excluded from recording: the pages of the personal account, the cart and checkout; all forms and input fields (catalogue search, enquiry, request, sign-in, sign-up, password recovery, passwords and two-factor authentication codes, data subject request), except the product quantity field; the e-mail address in the account menu; supplier contacts revealed on request. In the recording, excluded content is replaced: text with random characters of the same length, images with grey blocks, field content with asterisks. Analytics counters (Yandex.Metrika, PostHog, Plausible) load only if the page path is one of the site's sections, its variable part (a brand, supplier or product address, an order number) is in its own form, and the rest of the address carries nothing but a list page number, service parameters set by the site itself (each in the form the site sets it) and advertising and search tags (utm, yclid, gclid, ysclid, yrclid). If the address carries any other data — for example, an e-mail address in the path, a catalogue search query, a return path after sign-in, a parameter value outside its form, or anything after the “#” sign (except the site's links to the contacts section and to sections of its legal documents) — the counters do not load on that page; nor do they load when the browser reports as the previous page — ours or another site's — an address with other query parameters. Clicks on a supplier's e-mail and phone links are not reported to Metrika. Metrika form analytics is switched off. Webvisor recordings are kept by Yandex for 15 days, including the day of recording. Withdrawing consent stops the counter at once, after which the page reloads without it.
- PostHog (PostHog, Inc.; data storage in the EU, Germany) — product event analytics. Loaded ONLY after the user grants consent (Art. 9 of 152-FZ / Art. 6(1)(a) GDPR). Data is stored in the EU (Germany) under the DPA signed with PostHog Inc.
- Sentry (Functional Software, Inc.; the ingest is located in Germany, EU) — error and performance monitoring. Legal basis — legitimate interest of the controller (Art. 6(1)(f) GDPR / Art. 6(1)(7) of 152-FZ): security and service reliability. Error reports leave the territory of the Russian Federation — see section 10. Removed from the report before transmission: of the account details — the e-mail address, username and IP address (the account's internal record number and its role are kept); request content; cookies; the header describing the browser (user-agent); values from the page address (search and filter parameters, variable path segments). ⚠️ Scrubbing does not make the report anonymous: whatever lies outside the scrubbed details, or is not recognised by the scrubbing, remains available to the recipient — in particular, the sender's IP address, visible to the ingest when connecting (removing the field from the report body does not change that); browser and device details other than the removed user-agent header; stack frames (file paths and lines of our own source code), which are transmitted unscrubbed; and a personal or family name written into free-form error message text — the scrubbing does not recognise it. User consent is not required.
- Plausible Analytics (hosted on our own server at Hetzner, EU) — cookieless web analytics. No cookies, no IP address retention. Loaded after consent for consistency with the consent banner.
Cookie consent management is available in the consent window (shown on first visit) and on the “Cookie Policy” page (/privacy/cookies, the “Manage cookies” button). Consent withdrawal immediately stops loading of analytics trackers.
Disclosure is limited to the purposes named in section 3 and to the volume necessary to achieve them.
10. Cross-border data transfers
Storage localization. Personal data of Russian citizens is primarily stored in databases located within the territory of the Russian Federation (Cloud.ru data centre, Russian Federation). The localization requirement of Art. 18(5) of 152-FZ is met. Storage and transfer are different acts: localized storage does not by itself mean that no transfer leaves the country.
Cross-border transfer does take place. Part of the data is transferred to recipients located outside the Russian Federation — in particular, error and performance reports are sent to the Sentry ingest located in Germany, and product analytics data to the PostHog data centre in Germany. Personal data recipients registry — /privacy/subprocessors. The volume transferred is limited to what is necessary for the purposes named above.
What happens to the error-report data. The scrubbing described in section 9 applies to the reports sent to Sentry, and to those only. This scrubbing does not render the transferred data anonymous: whatever lies outside the scrubbed details, or is not recognised by the scrubbing, remains available to the recipient — in particular the sender's IP address, visible to the ingest when connecting. Details are in section 9.
This scrubbing is not applied to product-analytics data. PostHog events leave with the properties the application passed to them; there is no separate scrubbing stage on that path. The ground for that transfer is the user's consent (Art. 9 of 152-FZ / Art. 6(1)(a) GDPR): without consent PostHog is not loaded at all and no events are sent.
Legal basis for the transfer. The states to which the transfers named in this section are made — Germany and Finland — are included in the list of foreign states providing adequate protection of the rights of personal-data subjects, approved by Roskomnadzor Order No. 128 of 5 August 2022. The notification of intent to carry out cross-border transfer of personal data (Art. 12(3) of 152-FZ) has been submitted to Roskomnadzor and accepted by it. The processing itself rests on the controller's legitimate interest in the security and reliability of the service (Art. 6(1)(f) GDPR / Art. 6(1)(7) of 152-FZ) and, for analytics tools loaded upon consent, on the subject's consent (Art. 6(1)(a) GDPR / Art. 9 of 152-FZ).
Data of subjects who are not RU citizens. Personal data of subjects who are not RU citizens (PRC citizens — see below) is stored separately — at Hetzner Online GmbH (Germany; processing in Finland, EU). Personal data of Russian citizens is not copied there. The requirements of the GDPR are observed wherever the regulation applies to the processing (Art. 3 GDPR) — regardless of the data subject's citizenship. ⚠️ This is a statement about storage, not about connections: where the Plausible analytics hosted at the same provider is loaded (with consent), a visitor from Russia does connect to the Hetzner server, and that server sees the IP address and the request headers. Storage and connection are different acts; see section 9.
The service is not yet available to citizens of the PRC. PRC law (PIPL, Art. 38–39) requires a separate consent of the data subject and a personal information protection impact assessment before any cross-border transfer. Until these prerequisites are in place, registration of PRC citizens is refused and their personal data is not collected.
11. Security measures
In accordance with Art. 18.1 and Art. 19 of 152-FZ (and equivalent GDPR Art. 32), the following measures are applied:
Legal and organisational measures
- Person responsible for personal data processing appointed.
- Internal Personal Data Processing Regulation issued; this Policy published.
- Internal compliance control with 152-FZ / GDPR requirements.
- DSAR (Data Subject Access Request) procedure implemented — requests for a copy of the data, its portability and erasure (with withdrawal of consent to processing) are filed in the personal cabinet (“Personal data (152-FZ)” section) and via /privacy/data-request.
Technical measures
- Encryption of personal data at rest and in transit.
- Irreversible password hashing.
- Role-based access control.
- Logging of user and administrator actions.
- Backups with encrypted copies.
- Network segmentation.
- Protection against password guessing and attacks on the site.
- Two-step verification of data subject requests.
12. Rights of the data subject
Under Arts. 14, 20, 21 of 152-FZ (equivalent to GDPR rights):
- Right of access — obtain information about processed data, purposes, retention, third-party disclosures.
- Right to rectification — request correction of inaccurate or incomplete data.
- Right to erasure — request processing cessation and data destruction upon consent withdrawal or purpose achievement.
- Right to withdraw consent — at any time: in the personal cabinet (“Personal data (152-FZ)” section, “Request deletion” — withdrawal of consent to processing together with erasure of the data) or at [email protected].
- Right to object to marketing processing — by email at [email protected] or via the request form /privacy/data-request (request type — objection to processing).
- Right to lodge a complaint — contact Roskomnadzor (rkn.gov.ru) or local supervisory authority, or go to court.
Response period — up to 10 business days (Art. 14(4) of 152-FZ). Erasure period — 30 days from consent withdrawal (Art. 21(5) of 152-FZ).
13. How to contact us
You may submit requests regarding personal data processing via:
- Email: [email protected]
- Online form: /privacy/data-request.
- Personal cabinet: the “Personal data (152-FZ)” section — “Request data copy”, “Request deletion” (withdrawal of consent to processing with erasure of the data), “Request portability”.
The request must contain: full name, identifier (email or contract number), request content. Two-step verification of email/account ownership is required.
Response time — 10 business days from receipt.
14. Policy changes
The controller may modify this Policy. A new version is published on this page (chifat.ru/en/privacy/policy) with its number and effective date. When a new version comes out, the cookie consent window is shown to site visitors again: a choice made under the previous version does not apply until the visitor makes it anew.
Current version: 1.6, effective 2026-09-25.
Previous versions: v1.5 (2026-09-24), v1.4 (2026-09-23), v1.3 (2026-09-08), v1.2 (2026-09-07), v1.1 (2026-05-14), v1.0 (2026-04-16).