Privacy Policy
We only process the personal data we need to run this shop, and we don't sell it or use it for advertising. This page explains what we collect, why, and your rights under the GDPR.
Who is responsible for your data
The data controller is Cleverupps, Stationslaan 39, 1980 Zemst, Belgium — company number (KBO/BCE) 0724.738.765, VAT BE 0724.738.765. For anything privacy-related, email info@cleverupps.be.
What we collect
- Order details: what you bought, order reference, amounts, and any personalization text you enter.
- Customer details: name, email address, and phone number if you provide one.
- Shipping address: street, number, postal code, city, and country.
- Payment references: the Mollie payment ID and payment status. We never see or store card or bank details.
- Email communication: messages you send us and order emails we send you.
- Technical data: essential cookies (cart, language, admin session) and standard server logs (IP address, time, requested page) kept for security.
Why we process it
- Fulfilling your order and delivering it (performance of a contract).
- Processing your payment via Mollie (performance of a contract).
- Shipping via Sendcloud and the carrier (performance of a contract).
- Customer support and handling returns or warranty claims (contract / legitimate interest).
- Preventing fraud and keeping the shop secure (legitimate interest).
- Keeping accounting records we are legally required to keep (legal obligation).
Who processes data for us
We share data only with processors we need to run the shop, and only what each of them needs:
- Mollie (payments) — receives the order amount and reference to process your payment.
- Sendcloud and the delivery carrier (shipping) — receive your name and delivery address to deliver your parcel.
- Brevo (transactional email) — receives your email address and order summary to send order confirmations.
- Supabase (product image storage) — hosts product images; no customer data is stored there.
- Our hosting provider — runs the shop's server and database within the EU.
How long we keep it (retention periods)
We only keep personal data as long as necessary for legal and operational purposes:
- Orders & invoices: 7 years — required by Belgian accounting law.
- Support emails: up to 2 years after your request is resolved.
- Shopping cart / session data: up to 90 days.
- Server logs: 30–90 days, for security purposes.
- Newsletter: until you unsubscribe (we currently don't send a newsletter).
Your rights
Under the GDPR you can ask us at any time to:
- access the personal data we hold about you,
- correct inaccurate data,
- delete data we no longer need to keep,
- restrict processing while a request is being handled,
- receive your data in a portable format,
- object to processing based on legitimate interest.
Complaints
If you believe we handle your data incorrectly, email us first — we'll do our best to fix it. You also have the right to complain to the Belgian Data Protection Authority (gegevensbeschermingsautoriteit.be / autoriteprotectiondonnees.be).
Security
The shop runs over HTTPS, payment happens entirely on Mollie's secured pages, cart and session cookies are signed and HTTP-only, and access to order data is restricted and password-protected.
International transfers
Our processors are established in the EU and we aim to keep all data within the EU/EEA. Where a provider processes data outside the EEA, this only happens under the safeguards the GDPR requires, such as an adequacy decision or the European Commission's Standard Contractual Clauses.