Privacy notice
This notice explains how Lilclo Oy processes personal data in the marjoja.fi service.
Issued and last updated on 2 August 2026.
1. Controller and contact details
Lilclo Oy (Business ID 3351169-1) Service: marjoja.fi Privacy contact: Veli-Antti Riihimäki Email: info@pikkuvaate.fi
2. Who this notice applies to
This notice applies to service visitors, people joining the waitlist, buyers, sellers, and people dealing with customer service or administration.
3. Personal data we process
The data we process depends on how you use the service:
- Account and sign-in data: email address, encrypted or identity-provider-managed credentials, user identifier, user type, account status and event timestamps.
- Seller identity and contact details: first and last name, phone number and, for business sellers, company name, Business ID and contact person details.
- Information added by sellers: public name, introduction, images, products, prices, quantities, availability, pickup addresses and coordinates, delivery areas, and pickup and delivery times.
- Buyer and transaction data: name, email, phone number, optional delivery address, cart and order contents, selected fulfilment method and time, order status, messages and reviews.
- Waitlist data: email address, postcode, selected search criteria, language, and the version and timestamp of consent.
- Payment and billing data: Stripe customer and payment method identifiers, card brand, last four digits and expiry, charges, statements and receipts. Lilclo Oy does not store the full card number or security code.
- Technical and security data: IP address, browser and device information, request identifiers, timestamps, session and cookie data, error and security logs, and service usage events. If location is used, we process the supplied postcode or device-provided location for search.
4. Sign in with Google
When you choose Sign in with Google, Google gives the service the Google Account identifier needed to verify sign-in and, depending on the permissions we request, your email address, name and profile image. We use these only to create and identify your account and sign you in. Google processes sign-in data under its own privacy policy.
Lilclo Oy does not receive or store your Google Account password. You can manage or revoke the Google connection granted to marjoja.fi in your Google Account settings. Removing the connection from Google does not automatically delete your marjoja.fi account.
5. Google Analytics
With your consent, we use Google Analytics 4 to measure and improve the use of marjoja.fi. Google Analytics is not loaded and no data is sent to it before analytics consent. Advertising, ads personalisation and Google Signals features are disabled.
Analytics may receive a pseudonymous cookie identifier, browser and device category, approximate geographic area, a safely limited page type, and service usage events such as searches, product views, cart actions, orders and registration. We do not send names, email addresses, phone numbers, street addresses, coordinates, message contents, free-form search terms, or URLs or page titles containing personal data.
6. Sources of data
We mainly receive data from you when you register, sign in, search for sellers, join the waitlist, place an order, publish a seller profile or communicate in the service. Google sign-in data comes from Google with your permission. Payment status data comes from Stripe. Technical data is also created automatically when you use the service.
7. Purposes and legal bases
- Contract and pre-contractual steps: creating an account, signing in, publishing a seller profile, brokering products, placing and fulfilling orders, communication, processing payments and customer service.
- Legal obligation: retaining accounting, tax and other statutory records and responding to lawful authority requests.
- Legitimate interests: service security, preventing misuse, troubleshooting, availability monitoring, handling legal claims, and improving the service with privacy-conscious usage statistics.
- Consent: waitlist and availability notifications, precise device location, and any optional marketing or analytics cookies. Consent can be withdrawn at any time.
8. Recipients and disclosures
We do not sell personal data. Data is processed only by parties that need it to provide the service:
- Order parties: the seller receives buyer contact and order details needed to fulfil the order. Buyers see the profile, product, availability and pickup details the seller has marked as public.
- Amazon Web Services (AWS): authentication, databases, files, email, logs, monitoring and other technical service production.
- Google: Sign in with Google, Google Maps links opened by the user, and consent-based Google Analytics 4 usage analytics.
- Geoapify: converting seller-entered pickup-point addresses into coordinates. Geoapify receives the address and ordinary technical data when the lookup is made.
- Stripe: adding a payment card, payments, charges and payment fraud prevention.
- OpenStreetMap map and tile services: displaying maps. The provider may receive ordinary technical data such as the IP address.
- Authorities, courts and advisers when required by law or necessary to establish, exercise or defend legal claims.
9. Transfers outside the EU and EEA
The service's primary AWS region is Finland (eu-north-1), but some providers may also process data outside the EU or EEA. Such transfers rely on an adequacy decision, the European Commission's Standard Contractual Clauses with supplementary safeguards where required, or another lawful transfer mechanism.
10. Retention periods
We keep data only for as long as its purpose, the contract, security or law requires. Our current main principles are:
- Account and profile data is kept while the account is active. After a deletion request, it is deleted or anonymised unless a retention duty described below prevents this.
- Operational personal data relating to closed orders and customer service may be kept for up to 2 years to investigate issues and handle legal claims.
- Accounting, payment, receipt and other statutory financial records are generally kept for 7 years.
- Security and audit data may be kept for up to 7 years where needed to investigate misuse, monitor the service or handle legal claims.
- Short-lived data is generally deleted in 1–90 days depending on purpose: quote calculations in 1 day, profile-view deduplication in 2 days, quarantined files in 7 days, idempotency data in 30 days and notification delivery records in 90 days. A legal hold may exceptionally extend retention.
- Google Analytics user-level and event-level data is retained for 14 months. The user-data retention period resets upon new user activity. This period does not apply in the same way to aggregated Google Analytics standard reports.
11. Cookies and browser storage
We use strictly necessary session and access cookies to protect sign-in, orders and messages. We also store the selected postcode (up to 1 year) and language preference in the browser. You can remove these in browser settings, but blocking necessary storage may break service functions.
Your cookie choice is stored in the necessary berrymarket_consent cookie for up to 180 days. If you accept analytics, Google Analytics may set the _ga cookie used to distinguish users and the _ga_* cookie used to maintain session state. Their default lifetime is up to 2 years, although browsers may limit it. Withdrawing consent prevents new analytics calls and removes analytics cookies controlled by the service.
12. Protecting data
We protect data with measures including encryption in transit and, where appropriate, at rest, restricted access, separated environments, logging, monitoring, backups, and key and secret management. Buyer contact details and waitlist emails are encrypted or pseudonymised, and sensitive identifiers are not stored in search indexes or ordinary logs. Data is accessible only to authorised people and providers who need it for their work.
13. Automated decision-making
We do not make decisions based solely on automated processing that produce legal or similarly significant effects under Article 22 GDPR. Security and anti-abuse rules may nevertheless restrict or reject a request automatically. You can ask us to review the situation by contacting us.
14. Your rights
Depending on applicable law and the legal basis, you have the right to:
- access your personal data, receive a copy, and ask us to correct inaccurate or incomplete data;
- ask us to delete data where there is no longer a lawful basis for keeping it;
- ask us to restrict processing in certain circumstances;
- object to processing based on legitimate interests for reasons relating to your situation, and object to direct marketing at any time;
- receive data you supplied, processed automatically based on consent or contract, in a structured and machine-readable format;
- withdraw consent at any time without affecting processing carried out lawfully before withdrawal.
15. Exercising rights and complaints
Send requests to info@pikkuvaate.fi. We may ask for more information to verify your identity. We generally respond within one month. You also have the right to lodge a complaint with the Office of the Data Protection Ombudsman.
16. Changes to this notice
We update this notice when the service or law changes. The latest version is published on this page, and we will notify you of material changes in the service or by email where appropriate.
Back to marketplace
