PRIVACY POLICY
1. INTRODUCTION
LOOM ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use and safeguard your personal data when you visit www.loomrugs.nl ("Website") or place an order with us, in accordance with the General Data Protection Regulation (GDPR) and Dutch data protection legislation.
2. DATA CONTROLLER
The data controller responsible for your personal data is:
LOOM
Email: hello@loomrugs.nl
Website: www.loomrugs.nl
3. WHAT DATA WE COLLECT
We may collect the following personal data:
- Contact information - name, email address, phone number
- Shipping information - street address, postal code, city, country
- Order information - products ordered, order value, order number
- Payment information - processed securely by our payment provider Mollie; we do not store your payment details
- Newsletter subscription - email address and subscription preferences
- Technical data - IP address, browser type, pages visited (collected automatically via server logs)
4. HOW WE USE YOUR DATA
We use your personal data for the following purposes:
- Processing and fulfilling your orders
- Sending order confirmations and delivery updates
- Responding to your enquiries and providing customer support
- Sending our newsletter (only with your explicit consent)
- Improving our website and services
- Complying with legal obligations
5. LEGAL BASIS FOR PROCESSING
We process your data on the following legal grounds:
- Contract performance - to process and deliver your orders
- Consent - for newsletter subscriptions; you may withdraw consent at any time
- Legitimate interest - to improve our services and prevent fraud
- Legal obligation - to comply with tax and accounting requirements
6. THIRD-PARTY SERVICES
We share your data only with trusted third parties that are necessary to provide our services:
- Mollie - payment processing (Mollie Privacy Policy)
- MailerLite - email communications and newsletters (MailerLite Privacy Policy)
- Shipping carriers - to deliver your order
We do not sell, rent or trade your personal data to any other third parties.
7. DATA RETENTION
We retain your order data for a maximum of 7 years to comply with Dutch tax and accounting obligations. Newsletter subscriber data is retained until you unsubscribe. If you request deletion of your data, we will comply within 30 days, except where retention is required by law.
8. YOUR RIGHTS
Under the GDPR, you have the following rights:
- Right of access - request a copy of your personal data
- Right to rectification - request correction of inaccurate data
- Right to erasure - request deletion of your data
- Right to restrict processing - request limitation of how we use your data
- Right to data portability - receive your data in a structured format
- Right to object - object to processing based on legitimate interest
- Right to withdraw consent - withdraw consent for newsletter at any time
To exercise any of these rights, contact us at hello@loomrugs.nl. We will respond within 30 days.
9. COOKIES
Our website uses only essential cookies required for the website to function properly (e.g. shopping cart, session management). We do not use tracking cookies or third-party advertising cookies. Essential cookies do not require consent under the GDPR.
10. DATA SECURITY
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss or alteration. All data is transmitted over encrypted connections (SSL/TLS). Payment data is handled exclusively by our PCI-compliant payment provider Mollie.
11. COMPLAINTS
If you believe we have not handled your data correctly, you have the right to file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.
12. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. The latest version is always available on this page. We encourage you to review this page periodically.
Last updated: May 2026
