Privacy Policy

Last updated: 13 August 2026

This policy explains what personal data ODYSSAY collects when you visit this site, buy from it, create an account or sign up for our mailing list — why we collect it, who we share it with, how long we keep it, and what you can ask us to do about it.

We have tried to keep it specific. Where this policy names a cookie, a company or a retention period, that is the one actually in use — not a placeholder.

Who we are

This site is odyssaymusic.com, the official store of the musical project ODYSSAY. The data controller — the party that decides why and how your data is used — is:

If you have a question about your data, or want to make one of the requests described under Your rights, write to the address above and we will answer within one month.

What we collect, and why

When you browse the store

You can browse the whole catalogue without telling us anything about yourself. Our server keeps standard access logs — your IP address, the pages requested, the time, your browser and operating system — which exist to keep the site running and to investigate abuse or technical faults.

If you save products to your wishlist without being logged in, the product IDs are stored in a cookie in your own browser. Nothing about a guest wishlist reaches our database. If you are logged in, the same list is saved to your account instead, so it follows you between devices.

When you create an account

We ask for your email address and a password. Your username is generated from your email; your password is stored only as a cryptographic hash, so nobody at ODYSSAY can read it. As you place orders, your account also accumulates the billing and delivery details you enter and a history of what you have bought.

An account is optional. You can buy from us as a guest.

When you place an order

To sell you something and get it to you, we collect:

  • your name, email address and phone number;
  • your billing address, and the delivery address or Nova Post branch you choose;
  • what you ordered, in what size, for how much, and any note you leave with it;
  • your chosen payment method, and whether the payment succeeded;
  • the IP address and browser the order was placed from, which we keep as a fraud and chargeback record.

We also record how you arrived at the order — the site that referred you, any campaign tags in the link you followed, whether you were on a phone or a desktop, and how many times you had visited before ordering. This only happens if you allow Analytics cookies on our banner, and it is used to understand which channels bring real customers — never to build a profile or to make automated decisions about you.

We never see your card details. Card payments are handled entirely on monobank’s own pages and systems; what comes back to us is confirmation of whether the payment went through.

When you sign up for the mailing list

The form in our footer asks only for your email address. Alongside it we store the date and time you signed up, the IP address you signed up from, and the page the form was on. That record exists for one reason: it is the evidence that you asked to hear from us, which is what makes it lawful for us to write to you at all.

We use the list for tour dates, releases and product drops. You can leave it at any time — every email carries an unsubscribe link, and you can also just ask us. We do not sell, rent or share the list.

When you contact us

If you email or phone us, we keep the correspondence and whatever you tell us in it, so that we can deal with your question and refer back to it if you get in touch again.

Spam and abuse protection

Our registration form and mailing-list form are protected by Google reCAPTCHA v3, which tells real visitors apart from automated ones. To do that, Google collects information about your device and how you interact with the page — hardware and software details, your IP address, and mouse, touch and keyboard activity — and may read and set its own cookies. This happens in the background; there is nothing for you to click.

Your use of reCAPTCHA is subject to Google’s Privacy Policy and Terms of Service. We use it only on those two forms, and only to decide whether a submission is genuine.

We also apply two checks of our own to the mailing-list form: a hidden field that only automated software fills in, and a limit on how many sign-ups one IP address can make in a short period.

Cookies

Cookies are small files a site stores in your browser. Only the ones the store cannot run without are set automatically. Everything else waits for you: the scripts behind our optional cookies are delivered switched off and only start once you allow their group on the cookie banner, so nothing non-essential runs before you have said yes. We use no advertising cookies at all at present.

You can change or withdraw your choice whenever you like through the Cookie Settings link at the bottom of any page. Withdrawing a group deletes the cookies we set for it and reloads the page so its scripts stop running.

CookieWhat it doesHow long it lasts
woocommerce_cart_hash, woocommerce_items_in_cart, wp_woocommerce_session_*Remember what is in your basket and keep your session together through checkoutSession to 2 days
odyssay_consentRemembers which cookie groups you allowed6 months
sbjs_current, sbjs_first, sbjs_udata, sbjs_sessionAnalytics only, and only with your consent: records the site or campaign that brought you here so it can be attached to an order6 months
odyssay_wishlistHolds a guest wishlist in your own browser1 year
odyssay_preloader_seenStops the opening animation from replaying on every page you open30 minutes
wordpress_logged_in_*, wp-settings-*Keep you signed in and remember your preferencesSession to 1 year
Google reCAPTCHA cookiesSpam protection on the registration and mailing-list formsSet by Google; see their policy

You can clear or block cookies in your browser settings. Blocking the store’s own cookies will stop the basket and checkout from working.

Our legal grounds for using your data

Under the GDPR we have to have a lawful basis for everything we do with your data. Ours are:

What we doOur basis
Take, ship and support your order; run your accountPerformance of our contract with you
Send you the mailing listYour consent, which you can withdraw at any time
Set any cookie that is not strictly necessary, and record how you found usYour consent, given on the cookie banner and withdrawable there
Keep order and payment records for tax and accountingLegal obligation
Protect the site from spam, fraud and abuse; keep server logsOur legitimate interest in a store that works and is not defrauded

Who we share it with

We do not sell your data, and we do not share it for anyone else’s marketing. We pass it only to the companies that help us run the store, and only as much of it as each one needs:

  • monobank (Universal Bank, Ukraine) — processes card payments. Receives the order number, the amount and your name; handles your card details on its own systems, never ours.
  • Nova Post — delivers your order. Receives the recipient’s name, phone number and the chosen branch or address. Its branch-picker widget loads on our checkout page from Nova Post’s own servers.
  • Our hosting provider, [HOSTING PROVIDER] — stores the site and its database, and therefore holds everything above.
  • Google — provides reCAPTCHA, as described above.

We may also disclose data where the law requires it, or where it is necessary to establish or defend a legal claim.

Where your data goes

We operate from Ukraine, and monobank and Nova Post are Ukrainian companies, so your data is processed in Ukraine. The European Commission has recognised Ukraine as providing an adequate level of data protection, which means data can move from the EEA to us without further safeguards.

Google processes reCAPTCHA data in the United States and elsewhere, relying on the European Commission’s Standard Contractual Clauses and the EU–US Data Privacy Framework.

How long we keep it

  • Orders and payment records — kept for the period our tax and accounting obligations require, currently [X] years from the end of the year the order was placed.
  • Account data — kept for as long as your account is open. Close it and we delete it, apart from what we are obliged to keep under the line above.
  • Mailing-list sign-ups — kept until you unsubscribe, and the consent record for a short period after that, so we can show why we were writing to you.
  • Guest wishlists — kept in your browser for a year, or until you clear your cookies.
  • Server logs — kept for a short rolling period and then overwritten.
  • Correspondence — kept for as long as it is useful for support, then deleted.

How we protect it

The site is served over an encrypted connection. Passwords are stored hashed, never in readable form, and card details never reach us at all. Access to the store’s admin is limited to the people who need it. No system is perfectly secure, but we take the protection of your data seriously and will tell you and the relevant authority if a breach ever puts you at risk.

Your rights

You can ask us to:

  • Show you the personal data we hold about you, and give you a copy of it;
  • Correct anything that is wrong or out of date;
  • Delete it, where we have no obligation or overriding reason to keep it;
  • Restrict or object to what we are doing with it, including anything we do on the basis of our legitimate interests;
  • Send it on to you or to another company in a machine-readable format;
  • Withdraw your consent to the mailing list, at any time and without giving a reason. This does not affect anything we sent before you withdrew it.

Write to jonathan@jackmode.com and we will deal with it free of charge, within one month. We may need to verify who you are first.

If you think we have got it wrong, you can complain to a supervisory authority — in Ukraine, the Ukrainian Parliament Commissioner for Human Rights; in the EEA, the data protection authority of the country you live in. We would rather you came to us first.

Children

This store is not aimed at children, and we do not knowingly collect data from anyone under 16. If you believe a child has given us their data, tell us and we will delete it.

Changes to this policy

If we change how we handle your data, we will update this page and move the date at the top. Where a change matters to you — a new processor, a new purpose — we will say so plainly rather than leave you to spot it.