1. Controller
The business below determines the purposes and means of its own webshop processing. Send privacy questions or requests to tradepalacecards@gmail.com.
- Business name
- Trade Palace
- Business address
- Fijistraat 7, 1339 NP Almere
- KVK number
- 89213092
- VAT identification number
- NL0000000
- Phone
- 06000000000
- Support hours
- Maandag t/m vrijdag, 10:00–17:00
2. Sources of data
We receive most data directly from you when you create an account, order, return an item, contact us or subscribe. We also receive status and reference data from payment, delivery, address and email providers, and our systems generate security and usage data.
3. Categories of personal data
The data we process depends on how you use the webshop.
- Identity and account data: name, email address, language preference, account status, and authentication and security data.
- Transaction data: basket, orders, products, billing and delivery address, amounts, VAT, discounts, payment status and transaction references, dispatch, invoices, returns, inspections and refunds.
- Technical and security data: IP address, browser and device data, timestamps, session data, login and security events, and data used for abuse prevention and rate limiting.
- Communication and preference data: product reviews, ratings, the abbreviated name shown with a review, review reports, support messages and attachments, language, newsletter subscription, consent status, confirmation and unsubscribe records, and email delivery status.
4. Specific service providers
To operate the webshop, we use the following categories and providers where relevant to your use:
- Stripe processes payment details, payment methods, fraud and risk signals, transactions, refunds and payment disputes. Complete card details are processed directly by Stripe.
- PostNL receives the necessary name, address, contact and shipment data for delivery, track & trace and delivery investigations.
- DigitalOcean provides hosting, databases and object storage for product media, invoices and encrypted backups, among other things.
- Twilio SendGrid processes email address, name, language, message content, template data and delivery status for transactional messages, support acknowledgements and newsletters. For emails sent through the webshop, we disable open and click measurement and the addition of Google Analytics tracking. Necessary delivery, failure and unsubscribe information is still processed.
- Google Places receives the address search text you enter when you use address autocomplete. You can also enter your address without using those suggestions.
5. Purposes and lawful bases
We link each processing activity to a purpose and lawful basis.
- Agreement or pre-contractual steps: account and basket functions, orders, payment, delivery, invoices, returns, refunds and customer support.
- Legal obligation: tax records, invoices, consumer rights, product safety, recalls and cooperation with competent authorities.
- Legitimate interest: security, fraud prevention, abuse and incident investigation, evidence of transactions and improvement of reliable business operations. We balance this interest against your rights and expectations.
- Consent: newsletters and other optional marketing. A subscription becomes active only after confirmation and you can withdraw consent at any time free of charge.
6. Recipients
We share only the data needed by service providers for their work. Our bookkeeper receives the purchase, order and invoice information necessary to prepare tax returns, including names, addresses and transaction amounts where necessary. Professional advisers and competent authorities may also receive data where a valid legal basis applies.
We do not sell personal data or provide it to third parties for their own advertising. Providers must protect data appropriately by contract and technical measures and may process it only for their agreed role.
7. Transfers outside the EEA
Some providers or group companies may process data outside the European Economic Area. Where no adequate level of protection has been recognised, Trade Palace requires a valid transfer mechanism, such as European Commission standard contractual clauses, and additional measures where necessary. You may request information about the applicable safeguards from tradepalacecards@gmail.com.
8. Local browser storage and similar technologies
The webshop uses functional browser storage for your language, basket, wishlist, account and session tokens, and temporarily unsaved seller product work. This data is needed for the selected function or to keep your session secure.
Trade Palace only uses Google Analytics with your prior consent to measure general webshop usage and completed orders. This measurement is not loaded without consent. We do not use advertising or behavioural profiling cookies. Payment and security services may use strictly necessary technologies for payment and fraud prevention.
9. Retention periods
Order, payment, refund and invoice data forming part of tax records is generally retained for 7 years. Transactions under the EU OSS scheme are retained for 10 years after the end of the relevant year. After two years without recorded account activity, we review your customer account for deletion. You receive a warning giving you at least 30 days to keep your account by signing in. Open orders, returns, disputes and justified retention exceptions postpone deletion. Account deletion removes login, profile, address, basket, wishlist and review data; necessary tax records remain separately retained. Ordinary support messages are deleted two years after closure. Routine application security events are deleted after 90 days unless necessary evidence must be retained for an ongoing incident. Return and dispute information is retained as needed for handling and applicable rights. Newsletter data is kept until unsubscribe; necessary consent and suppression evidence may remain longer. Data in recovery backups expires under the backup retention policy and is not reused for ordinary business operations.
10. Your privacy rights
Depending on the lawful basis and circumstances, you may request access, correction, deletion, restriction or portability, object to processing, and withdraw consent. Withdrawal is not retroactive, and data subject to a legal retention duty cannot be deleted immediately.
Send a request to tradepalacecards@gmail.com. We generally respond within one month and may request information necessary to verify your identity. You may complain to the Dutch Data Protection Authority or, if you live elsewhere in the EEA, your local supervisory authority.
11. Required and optional data
Fields needed to secure an account, conclude and perform an order, process payment, deliver or meet legal obligations are required; without them the relevant function cannot be provided. Newsletter subscription and marketing consent are optional. You do not have to provide a substantive reason for an ordinary withdrawal.
12. Automated checks
Trade Palace uses automated security, stock, payment-status and fraud-prevention checks. Stripe may perform its own automated risk analyses for payments. Trade Palace does not use its own profiling to take solely automated decisions with legal or similarly significant effects. Contact us if you believe a payment or order was blocked incorrectly.
13. Security and changes
We use appropriate technical and organisational measures, including access restrictions, encrypted connections, secured storage and backups, monitoring and limited staff permissions. No system is risk-free. We update this notice and its date after a material change; for new processing we request consent where the law requires it.
