Privacy Policy

Last updated: 2026

⚠ Placeholder text. This page is a working draft. Have a privacy professional review it for your jurisdiction(s) before going live.

1. Data controller

Lorévine("Lorévine", "we") is the data controller for personal data processed via https://www.lorevine.nl.

2. What we collect

  • Account information: name, email, profile picture (when you sign in with Google), password hash (when you sign up with email).
  • Order information: shipping address, phone number, order contents, order status. We do not store card details — payments are processed by Stripe.
  • Usage information: IP address, browser type, pages visited, referrer URL, timestamps.
  • Cookies: see our Cookie Policy.

3. Why we process your data (legal basis)

  • Performance of a contract (Art. 6(1)(b) GDPR): processing your order, shipping, and customer service.
  • Legal obligation (Art. 6(1)(c)): tax, accounting, and consumer-rights obligations.
  • Legitimate interest (Art. 6(1)(f)): site security, fraud prevention, basic analytics.
  • Consent (Art. 6(1)(a)): non-essential cookies, marketing emails. You can withdraw consent at any time.

4. Recipients

We share data only with processors needed to run the service:

  • Payments: Stripe Payments Europe, Ltd. (Ireland)
  • Hosting: Vercel Inc. (data may be processed in the US under SCCs)
  • Database / file storage: Supabase
  • Transactional email: Resend
  • Authentication (optional): Google LLC
  • Carriers (for shipping addresses): e.g. PostNL, DHL, GLS

5. International transfers

Some processors (e.g. Vercel, Stripe) may process data outside the EEA. Where this is the case, transfers rely on Standard Contractual Clauses or equivalent safeguards.

6. Retention

Order and invoice records are retained for 7 years to meet Dutch tax law obligations. Marketing consents are kept until withdrawn. You may request deletion of your account at any time, subject to retention obligations above.

7. Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you
  • Have it corrected if inaccurate
  • Request erasure (subject to legal exceptions)
  • Restrict or object to processing
  • Receive your data in a portable format
  • Withdraw consent for processing based on consent

To exercise these rights, contact us at hello@lorevine.nl.

8. Complaint authority

You have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl, or with your local supervisory authority.

9. Security

We use industry-standard measures (HTTPS, hashed passwords, access controls). No system is perfectly secure; in case of a breach we will notify affected users and the supervisory authority within the timeframes required by Articles 33–34 GDPR.

10. Children

Our store is not directed at children under 16. We do not knowingly collect data from children.

11. Changes to this policy

We may update this policy from time to time. The "Last updated" date at the top will reflect the most recent change.

12. Contact

Privacy questions: hello@lorevine.nl.