Trust and security

Security, privacy and payments

An overview of how we handle your data, how payments are protected, and what controls you have over your information.

This page is maintained by SIA "BRO Finance" (GOLFI.lv) to answer common security and privacy questions. It is not an independent certification.

Payments

Payments are processed via certified payment service provider EveryPay (SEB Baltic acquiring). We do not store full card numbers on our servers — card data is transmitted directly to the payment provider over an encrypted TLS channel.

What data we collect

For orders: name, email, phone, delivery address. For accounts: email and password (stored as a hash). For analytics: anonymized visit data, only after your cookie consent.

Retention periods

Order and accounting data — 5 years (Latvian law). Marketing subscriptions — until you unsubscribe. Closed accounts are anonymized within 30 days of request.

Infrastructure

The site runs on the Cloudflare global network with TLS 1.3 encryption. The database is hosted in the EU (Frankfurt) with daily backups and a 30-day retention policy.

Your rights (GDPR)

You can request a copy of your data, correction or deletion at any time from your account or by emailing info@golfi.lv. We respond within 30 days.

Cookies

By default we only use strictly necessary cookies. Analytics and marketing cookies load only after your explicit consent.

Security contact

If you discovered a vulnerability or a privacy issue — email security@golfi.lv. We acknowledge receipt within 48 hours.

Contact us