Skip to main content
700+ pouches from 55 brands
Free EU Shipping Over €45
Same-Day Dispatch Before 2pm CET
SnusFriend

Privacy Policy

Effective date: 31 March 2026

1. Data Controller

Nordic Express AB, trading as SnusFriend ("we", "us", or "our"), registered in Sweden, is the data controller for personal data collected through the website at snusfriends.com. For any questions about this policy, contact us at support@snusfriends.com.

2. Scope

This Privacy Policy applies to all personal data we collect when you browse our website, create an account, place an order, contact customer support, subscribe to marketing communications, leave product reviews, or participate in community features.

3. Data We Collect

We collect the following categories of personal data:

  • Account data: name, email address, and encrypted password when you create an account.
  • Order data: shipping address, billing information, order history, and payment transaction references (we do not store full card numbers).
  • Usage data: pages visited, products viewed, search queries, device information, browser type, IP address, and referring URLs.
  • Community data: product reviews, ratings, and profile information you choose to share.
  • Communication data: email correspondence, support tickets, and newsletter preferences.

4. Legal Basis for Processing

We process your data under the following legal bases (GDPR Art. 6):

  • Contract performance: processing orders, managing your account, and providing customer support.
  • Legitimate interests: improving our services, fraud prevention, website analytics, and personalisation.
  • Consent: sending marketing emails, setting non-essential cookies, and collecting community content.
  • Legal obligation: age verification, tax records, and regulatory compliance.

5. Cookies

We use cookies and similar technologies to operate the Site, remember your preferences, and analyse usage. For full details, see our Cookie Policy.

Essential cookies are required for the Site to function. Analytics and marketing cookies are only set with your consent.

6. Payment Processing

Payments are processed by our commerce partner, Nyehandel, and their payment providers. We do not store your full credit card numbers, CVV codes, or other sensitive payment credentials on our servers. Payment providers operate under their own privacy policies and PCI DSS compliance requirements.

7. Third-Party Services

We share data with the following categories of third parties, each under appropriate data processing agreements:

  • Supabase (database and authentication) — stores account, order, and application data. EU-hosted infrastructure.
  • Nyehandel (commerce and fulfilment) — processes orders, payments, and shipping. Swedish company.
  • PostHog (product analytics) — collects anonymised usage data to help us improve the shopping experience. EU-hosted.
  • Sentry (error monitoring) — captures technical errors to maintain site reliability. No personal data is intentionally collected.
  • Vercel (hosting) — serves the website and processes HTTP requests.

We do not sell your personal data to any third party.

8. Data Retention

  • Account data: retained for as long as your account is active, plus 30 days after deletion.
  • Order data: retained for 7 years to comply with tax and accounting regulations.
  • Usage and analytics data: retained for up to 26 months in anonymised form.
  • Marketing consent records: retained for as long as the consent is valid, plus 3 years.

9. Your Rights

Under GDPR, you have the following rights:

  • Access: request a copy of your personal data.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure: request deletion of your data ("right to be forgotten").
  • Restriction: limit how we process your data.
  • Portability: receive your data in a structured, machine-readable format.
  • Objection: object to processing based on legitimate interests or direct marketing.
  • Withdraw consent: withdraw consent at any time for processing based on consent.

To exercise any of these rights, contact us at support@snusfriends.com. We will respond within 30 days.

10. Data Security

We implement appropriate technical and organisational measures to protect your data, including encryption in transit (TLS), secure authentication, access controls, and regular security reviews. However, no method of transmission over the Internet is 100% secure.

11. International Transfers

Your data is primarily stored within the EU. Where data is transferred outside the EEA (e.g., to US-based sub-processors), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions.

12. Children

Our Site is not intended for individuals under 18 years of age. We do not knowingly collect data from minors. If we become aware that we have collected data from someone under 18, we will promptly delete it.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date. We encourage you to review this page periodically.

14. Contact and Complaints

For privacy-related questions or to exercise your rights, contact us at support@snusfriends.com.

If you are not satisfied with our response, you have the right to lodge a complaint with your local Data Protection Authority. For the current storefront, the relevant supervisory authority is the Swedish Authority for Privacy Protection (IMY) at www.imy.se.