⚠ Placeholder text. This page is a working draft. Have a privacy professional review it for your jurisdiction(s) before going live.
1. Data controller
Lorévine("Lorévine", "we") is the data controller for personal data processed via https://www.lorevine.nl.
- KVK number: 98981684
- VAT (BTW): NL005364653B43
- Email: hello@lorevine.nl
2. What we collect
- Account information: name, email, profile picture (when you sign in with Google), password hash (when you sign up with email).
- Order information: shipping address, phone number, order contents, order status. We do not store card details — payments are processed by Stripe.
- Usage information: IP address, browser type, pages visited, referrer URL, timestamps.
- Cookies: see our Cookie Policy.
3. Why we process your data (legal basis)
- Performance of a contract (Art. 6(1)(b) GDPR): processing your order, shipping, and customer service.
- Legal obligation (Art. 6(1)(c)): tax, accounting, and consumer-rights obligations.
- Legitimate interest (Art. 6(1)(f)): site security, fraud prevention, basic analytics.
- Consent (Art. 6(1)(a)): non-essential cookies, marketing emails. You can withdraw consent at any time.
4. Recipients
We share data only with processors needed to run the service:
- Payments: Stripe Payments Europe, Ltd. (Ireland)
- Hosting: Vercel Inc. (data may be processed in the US under SCCs)
- Database / file storage: Supabase
- Transactional email: Resend
- Authentication (optional): Google LLC
- Carriers (for shipping addresses): e.g. PostNL, DHL, GLS
5. International transfers
Some processors (e.g. Vercel, Stripe) may process data outside the EEA. Where this is the case, transfers rely on Standard Contractual Clauses or equivalent safeguards.
6. Retention
Order and invoice records are retained for 7 years to meet Dutch tax law obligations. Marketing consents are kept until withdrawn. You may request deletion of your account at any time, subject to retention obligations above.
7. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you
- Have it corrected if inaccurate
- Request erasure (subject to legal exceptions)
- Restrict or object to processing
- Receive your data in a portable format
- Withdraw consent for processing based on consent
To exercise these rights, contact us at hello@lorevine.nl.
8. Complaint authority
You have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl, or with your local supervisory authority.
9. Security
We use industry-standard measures (HTTPS, hashed passwords, access controls). No system is perfectly secure; in case of a breach we will notify affected users and the supervisory authority within the timeframes required by Articles 33–34 GDPR.
10. Children
Our store is not directed at children under 16. We do not knowingly collect data from children.
11. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top will reflect the most recent change.
12. Contact
Privacy questions: hello@lorevine.nl.