Last updated: 8 October 2026

This policy explains how UAB Elanus, trading as Elanus Parts, processes personal data when you use www.elanusparts.com, create an account, contact us, subscribe to communications or buy products.

1. Data controller

UAB Elanus, company code 303223851, VAT code LT100012990914. Registered office: Laisvės pr. 91-68, Vilnius, Lithuania. Business, returns and postal address: Raudondvario pl. 164, LT-47173 Kaunas, Lithuania. Contact: info@elanusparts.com, +370 620 15921.

2. Data we collect

You provide: name, email, telephone, account credentials, billing and delivery details, company and VAT information, order and return details, product preferences, support messages and attachments, form submissions, newsletter and marketing choices. Full card credentials and PayPal login details are provided to the payment provider, not stored by us.

Technical data: IP address, browser, device, operating system, language, approximate location, session and security identifiers, cart, currency and account information, server and diagnostic logs, and anti-abuse signals. With Analytics consent we collect pages, traffic sources and interactions; with Marketing consent, advertising identifiers, campaigns, product, cart, checkout and conversion events. Protected forms may generate reCAPTCHA signals and response tokens.

Third-party data: payment status and transaction identifiers, carrier delivery status, campaign or affiliate identifiers, security signals and identity information from optional sign-in providers.

2.4 Google and Facebook sign-in

Social sign-in is optional; email sign-in and guest checkout remain available. Providers authenticate you on their services and return identity information. We do not receive your Google or Facebook password. We use the information to sign you in, offer account creation at your request or securely link an existing Elanus account. We may require an email verification code or authentication of your existing account. Matching email text alone does not prove account ownership for every provider or automatically merge accounts or guest orders.

Facebook returns a provider-specific identifier, name and, where available, email information. We retain a protected, pseudonymous sign-in link associated with your Elanus account. Facebook deauthorisation or a data-deletion request removes the relevant link and associated pending sign-in data, not records we must retain by law.

Google sign-in data

Access: Elanus Parts requests openid, email and profile. Our integration uses your Google account identifier, first and last name where available, email address, verification information and, where relevant, a hosted-domain claim to assess email verification. It processes authentication tokens and claims needed to validate the response, including issuer, intended recipient, validity and sign-in request identifiers. Other standard profile claims may be present, but the integration does not retain or display your photograph. We do not request access to Gmail messages, Drive files, contacts or calendar.

Use: we verify identity, recognise a securely linked account, support requested registration or linking and prevent impersonation and abuse. Name and email saved during confirmed registration become part of your Elanus customer record for the account and purchase services described here. Tokens are used during the callback, not stored for later background access to Google services.

Storage: the persistent link uses a keyed, pseudonymous representation of your Google identifier linked to your customer account; it is still personal data. We retain it until unlinking or deletion of the account and link. Temporary identity and sign-in data is encrypted. Attempts normally expire after 15 minutes and verification codes after 5 minutes. Expiry prevents further use, but physical deletion depends on periodic cleanup. Customer name and email follow section 9; orders and invoices have separate retention requirements.

Sharing: Google processes authentication under Google's Privacy Policy. We process returned data on our shop infrastructure. Hosting and authorised website-support providers may process it to operate and secure the account service; email providers process the recipient and message when verification is needed. Personnel access is limited to authorised support, operational and security needs. Disclosure may be required by law. The sign-in integration itself does not sell identity information or send Google tokens, sign-in links or temporary sign-in records to advertising platforms. Separate site advertising and conversion matching is described in sections 3, 5 and 7. Social sign-in does not subscribe you to newsletters or grant Analytics or Marketing consent.

Protection: HTTPS, signed-response validation, recipient, validity and request checks, and PKCE protect sign-in. Temporary records are encrypted and persistent identifiers use keyed digests. This does not mean every customer or order field is encrypted. Section 10 describes other safeguards; absolute security cannot be guaranteed.

Removal: request unlinking or account deletion at info@elanusparts.com; we may verify identity first. Unlinking does not delete your Elanus account or required order records. You can revoke Google's authorisation through Google Account third-party connections, but this does not erase information already held by Elanus Parts; contact us for deletion.

2.5 Checkout, wallets and service emails

Available payment methods depend on country, currency and order. They may include card, PayPal, bank transfer, Google Pay, Apple Pay or another identified provider. Express wallets provide the contact and delivery details you choose to share for the order, delivery availability, tax and final amount. These may differ from an address previously selected in the shop and do not themselves change your account identity or marketing choices.

Payment integrations process amount, currency, payment tokens, transaction identifiers and status, and browser, device and security information for availability, authentication (including 3-D Secure) and fraud prevention. Displayed wallets may contact providers for availability and security checks before you click. This is not advertising permission; device access and storage remain subject to our Cookie Policy. Necessary account and order emails may use an encrypted outgoing queue with delivery and retry records; they are separate from newsletters.

3. Purposes and legal bases

  • Accounts, sessions, carts and social sign-in: account, identity, verification, session, device and cart data; steps requested before a contract or performance of the account service, and legitimate interests in security and preventing account takeover.
  • Orders, delivery, returns, refunds and warranties: identity, contact, purchase, delivery, invoice and communication data; performance of a contract and legal obligations.
  • Payments and fraud prevention: amount, method, transaction status and identifiers, and security signals; contract performance, legal obligations and legitimate interests in preventing fraud.
  • Enquiries and compatibility support: contact details, messages, photographs and information you send; requested pre-contractual steps, contract performance or legitimate interests in support.
  • Security, diagnostics and legal claims: IP, device, session and log data; legitimate interests in reliability, security and establishing, exercising or defending claims.
  • Security Pro and reCAPTCHA contact-form protection: IP, browser, device, interactions, risk signals and response tokens; legitimate interests in preventing spam, fraud and abuse.
  • Accounting, tax and consumer-protection duties: purchase, payment, invoice, return and communication data; legal obligations.
  • Google Analytics 4: cookie identifiers, device and browser information, approximate location, pages and interactions; Analytics consent. Limited cookieless signals are explained in section 4.
  • Google and Meta advertising: advertising identifiers, campaigns, page views and conversions; Marketing consent.
  • OpenAI advertising measurement: browser and attribution identifiers, event ID, time, page, browser, products, quantity, value, currency, hashed email and available country, city, region and postcode; Marketing consent. See section 5.
  • Avelon attribution: click and payment transaction IDs, currency, promotional codes, product ID, name, category, quantity, price and reference; Marketing consent.
  • Maps, Google Merchant Reviews, Trustpilot, YouTube and SecurityMetrics: IP, browser, device, page and interactions; Marketing consent.
  • Newsletters: email, subscription and measured communication interactions; consent or another basis specifically permitted by direct-marketing law. You may opt out at any time.
  • Account and order emails: recipient, message, delivery and retry records; contract performance or requested steps, applicable legal obligations and legitimate interests in reliable delivery.

For legitimate interests, we assess necessity and balance your interests and rights; you may object as explained below. A lawful basis for personal-data processing does not itself authorise non-essential cookies or device access. Where required, separate technology consent must be obtained; a security or payment label does not exempt every technology.

4. Cookies and consent

The banner offers separate Analytics and Marketing choices; Necessary technologies remain active. The first-party elanus_consent cookie stores your choice for 180 days. Change or withdraw it through Cookie settings in the footer. See our Cookie Policy.

We use Google Consent Mode v2 in Advanced Mode. Before consent, Google storage signals are denied, so Analytics and advertising cookies must not be created. Google tags may still send limited cookieless consent and measurement signals, including consent status, time, page and device information and an IP address used for transmission. Google states that Analytics does not log or store IP addresses. Optional cookie-based processing starts only after the relevant consent.

YouTube embeds and the SecurityMetrics badge are blocked without Marketing consent: only local placeholders are shown, without their external iframe, script or image. The OpenAI Ads Pixel is also blocked without Marketing consent. Refusal or withdrawal stops new OpenAI Ads events; the website attempts to remove the accessible __oppref first-party cookie where technically possible.

Security Pro and Google reCAPTCHA protect the contact form as Necessary technology, independently of optional choices. Using the protected form may send Google technical and interaction signals to detect automation and set the _GRECAPTCHA security cookie. We use it for security and anti-abuse, not advertising.

5. OpenAI Ads measurement

With Marketing consent, the OpenAI Pixel measures product views (contents_viewed), successful cart additions or quantity increases (items_added), the first checkout start with a non-empty cart (checkout_started) and completed orders (order_created). For completed orders, the server may send the same event through the Conversions API; matching Pixel ID, event name and identifier allow deduplication.

Depending on availability, OpenAI receives event ID, time and type, page URL without query or fragment, browser user agent, __oppref attribution or __obref browser reference, product identifiers or references, names, content type, quantity, value and currency. Completed-order matching may include the normalised customer email as a SHA-256 hash and country, city, region and postcode from the order address; the raw email is not sent through this integration.

OpenAI uses these signals for conversion matching, attribution, advertising reporting and measurement. Receipt of an event does not guarantee attribution: an eligible advertising interaction and the applicable reporting rules are also required.

6. Avelon affiliate tracking

With Marketing consent, an eligible affiliate visit sets avln_cid for 30 days. For an eligible completed order, our server may send Avelon the click ID, payment transaction ID, currency, promo codes and purchased product information. The purchase payload excludes customer name, email, telephone and delivery address. Without required consent, the cookie is not created or is removed, and the order is not reported.

7. Recipients

We disclose information where necessary for the described purposes. Recipients may include:

  • hosting, maintenance, security, email and IT providers;
  • PayPal, Braintree, Google for Google Pay, Apple for Apple Pay and other providers identified at checkout, where enabled; banks, card networks and fraud-prevention services;
  • postal, courier, fulfilment and customs services;
  • accounting, legal, audit and professional advisers, and authorities where disclosure is legally required;
  • Google Ireland Limited for Analytics, advertising consent signals, Merchant Reviews, Maps, YouTube and reCAPTCHA; Google for chosen Google authentication;
  • Meta Platforms Ireland Limited for consent-based Pixel measurement and chosen Facebook authentication;
  • OpenAI for consent-based Pixel and Conversions API measurement, matching and attribution;
  • Trustpilot A/S for widgets and review services; SecurityMetrics, Inc. for the consent-controlled certification badge; Avelon for consent-based attribution and sale reporting;
  • newsletter management and email-delivery providers for subscribed communications.

Payment providers handle payment credentials under their own notices. We receive transaction-administration information, not full stored card credentials. The specific Google sign-in disclosures in section 2.4 explain that integration; choosing it does not grant marketing consent.

8. International transfers

Providers or group companies may process data outside Lithuania or the EEA. Where GDPR Chapter V applies, we use or require an applicable safeguard: adequacy decisions, European Commission Standard Contractual Clauses, approved binding corporate rules or another lawful mechanism. Contact us for relevant safeguards.

Provider notices: Google, YouTube and reCAPTCHA; Meta; OpenAI; Trustpilot; SecurityMetrics; PayPal; Apple.

9. Retention and deletion

We retain data only as needed for its purpose and legal, accounting, tax, warranty, security or dispute requirements. Principal periods are:

  • Orders, invoices, payments and accounting records: statutory accounting and tax periods, generally 10 years, or longer for an active dispute.
  • Customer accounts: while active and until deletion is requested, except legally or contractually required records.
  • Support and compatibility enquiries: normally up to 3 years after closure; longer when an order, warranty or dispute requires it.
  • Social sign-in links: until unlinking or account-and-link deletion, subject to separately required records.
  • Temporary sign-in: attempts expire after 15 minutes, email codes after 5 minutes. Expired attempts and anti-abuse counters are invalid and removed periodically, not necessarily immediately. Cleanup depends on activity. Facebook deletion receipts are valid for 30 days, then eligible for cleanup.
  • Service-email queue: encrypted content is cleared when marked sent; sent technical records are eligible for cleanup after 30 days. Failed or uncertain deliveries remain for review and resolution, not longer than needed. Cleanup depends on the mail worker.
  • Newsletters: until withdrawal or termination; limited suppression data may remain to respect opt-out.
  • Security and diagnostic logs: normally up to 30 days, longer for incidents or legal claims.
  • Avelon cookie and configured diagnostic log: 30 days; consent cookie: 180 days.
  • Analytics user and event data: up to 14 months under the configured setting.
  • OpenAI measurement identifiers and events: provider retention controls and notice; cookie durations may depend on provider and browser. Other provider data follows applicable provider controls and notices.

Data no longer required is deleted or anonymised unless retention remains legally required or permitted.

10. Security

Safeguards include HTTPS, access controls, security updates, restricted administration and protected secrets. Specific sign-in safeguards are described in section 2.4. No transmission or storage system is completely secure.

11. Your rights

Subject to applicable conditions and exceptions, you may request access, correction, erasure or restriction; object to legitimate-interest processing and direct marketing; receive eligible data in a structured, commonly used, machine-readable format and request portability; withdraw consent without affecting earlier lawful processing; and complain to a supervisory authority.

Email info@elanusparts.com. We may verify identity. We normally respond within one month, subject to lawful extensions. Removing a social link or revoking Google authorisation does not automatically delete separately retained customer, order or invoice records.

12. Supervisory authority

You may complain to the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija), L. Sapiegos str. 17, LT-10312 Vilnius, Lithuania: vdai.lrv.lt. EEA residents may also contact their local authority.

13. Automated decisions

We do not make solely automated decisions with legal or similarly significant effects on you. Advertising providers may create audiences or profiles after Marketing consent, but we do not use that profiling for such decisions about customers.

14. Changes

We update this policy when processing, providers or obligations change, publishing the version and date here. Where required, we provide additional notice or request new consent.

15. Contact

Privacy requests: UAB Elanus, info@elanusparts.com, +370 620 15921, Raudondvario pl. 164, LT-47173 Kaunas, Lithuania.

Product added to wishlist
Product added to compare.