Privacy policy
Last updated: July 21, 2026
This Privacy Policy explains how Frères de la Cité collects, uses, stores and shares personal data when you visit www.freresdelacite.com, make a purchase, create an account, join our mailing list or drop waitlist, interact with our advertisements, or otherwise communicate with us.
Frères de la Cité is the data controller responsible for the processing of personal data described in this Privacy Policy.
1. PERSONAL DATA WE COLLECT
Depending on how you use our website and services, we may collect the following personal data:
- Name;
- Billing and shipping address;
- Email address;
- Telephone number;
- Account and login information;
- Order and purchase information;
- Payment status and transaction information;
- Returns and refund information;
- Customer-service communications;
- Newsletter and marketing preferences;
- IP address;
- Approximate location information;
- Browser, device and operating-system information;
- Cookie identifiers and similar online identifiers;
- Pages viewed, links clicked and interactions with our website;
- Referring website or advertising source;
- Information about how you interact with our advertisements;
- Information you voluntarily provide to us.
We do not normally receive or store your complete payment-card details. Payments are processed by Shopify Payments or another payment provider available during checkout.
2. HOW WE COLLECT PERSONAL DATA
We may collect personal data:
- Directly from you when you place an order, create an account, join a waitlist, subscribe to marketing communications, request a return or contact us;
- Automatically through cookies and similar technologies;
- Through Shopify and connected applications;
- Through advertising and analytics platforms, including Google and Meta;
- From payment providers;
- From delivery and logistics companies;
- From fraud-prevention and security providers;
- From other service providers involved in operating our webshop.
3. HOW WE USE PERSONAL DATA
We may use personal data to:
- Process, confirm and deliver orders;
- Process payments, returns and refunds;
- Create and manage customer accounts;
- Provide customer service;
- Communicate about orders, deliveries, returns and account activity;
- Prevent fraud, misuse and security incidents;
- Maintain, secure and improve our website;
- Analyse website traffic and customer behaviour;
- Measure the effectiveness of marketing campaigns;
- Show relevant advertising where the required consent has been provided;
- Send newsletters, early-access invitations, drop notifications and promotional messages;
- Manage exclusive drops and purchase limits;
- Comply with legal, tax and accounting obligations;
- Establish, exercise or defend legal claims.
4. LEGAL BASES FOR PROCESSING
Under the General Data Protection Regulation, we process personal data on one or more of the following legal bases:
Performance of a contract
We process personal data where necessary to:
- Process an order;
- Receive payment;
- Deliver products;
- Manage customer accounts;
- Handle returns, refunds and complaints;
- Provide requested customer service.
Legal obligation
We process and retain certain information where required by law, including tax, accounting and consumer-protection obligations.
Legitimate interests
We may process personal data where necessary for our legitimate business interests, including:
- Operating and securing our webshop;
- Preventing fraud and abuse;
- Improving our services;
- Responding to customer enquiries;
- Protecting our legal rights.
We only rely on legitimate interests where those interests are not overridden by your rights and freedoms.
Consent
We rely on consent where required for:
- Non-essential analytics cookies;
- Advertising and tracking cookies;
- Personalised advertising;
- Certain marketing communications;
- Other optional processing activities.
You may withdraw your consent at any time. Withdrawal does not affect processing that took place before consent was withdrawn.
5. SHOPIFY
Our webshop is hosted by Shopify.
Shopify processes personal data to provide services including:
- Website hosting;
- Product and order management;
- Checkout;
- Customer accounts;
- Payment functionality;
- Security and fraud prevention;
- Technical support.
Personal data relating to customers in the European Economic Area is initially processed by Shopify International Limited in Ireland. Shopify may use affiliated companies and subprocessors to provide its services.
Shopify may process personal data outside the European Economic Area where necessary to provide its services. International transfers are handled using legally recognised safeguards where required.
6. PAYMENT PROVIDERS
Payments are processed by the payment methods made available during checkout.
Payment providers may receive information such as:
- Name;
- Billing details;
- Order amount;
- Payment method;
- Transaction information;
- Fraud-prevention information.
The selected payment provider processes information according to its own privacy terms and legal responsibilities.
We do not normally store complete credit-card details.
7. DELIVERY AND LOGISTICS PROVIDERS
We may share necessary personal data with delivery and logistics providers to fulfil your order.
This may include:
- Name;
- Shipping address;
- Email address;
- Telephone number;
- Order or parcel reference;
- Delivery instructions.
Delivery providers may use this information to deliver the order, provide tracking updates and resolve delivery problems.
8. GOOGLE ANALYTICS
We may use Google Analytics to understand how visitors use our website.
Google Analytics may process information such as:
- IP address;
- Approximate location;
- Device and browser information;
- Pages visited;
- Session duration;
- Referring websites;
- Website interactions;
- Purchases and conversion events.
Where consent is legally required, Google Analytics will only be activated after you have provided consent through our cookie banner.
Google Consent Mode may be used to communicate your consent preferences to Google and adjust the behaviour of Google tags.
9. META, FACEBOOK AND INSTAGRAM
We may use Meta technologies, including the Meta Pixel and Conversions API, in connection with Facebook and Instagram advertising.
These technologies may be used to:
- Measure advertising performance;
- Understand actions taken after an advertisement;
- Build advertising audiences;
- Display more relevant advertisements;
- Improve and optimise marketing campaigns;
- Measure purchases and other conversion events.
Information shared with Meta may include:
- Website events;
- Cookie identifiers;
- Device and browser information;
- IP address;
- Purchase and conversion information;
- Hashed contact information where applicable.
Meta marketing technologies will only be used where legally permitted and, where required, after consent has been provided.
10. COOKIES AND SIMILAR TECHNOLOGIES
We use cookies and similar technologies for:
- Essential website functionality;
- Shopping-cart and checkout functionality;
- Security and fraud prevention;
- Customer-account functionality;
- Remembering preferences;
- Website analytics;
- Advertising measurement;
- Personalised advertising.
Essential cookies
Essential cookies are necessary for the website to function properly. These may be used without consent where permitted by law, but visitors must still be informed about them.
Analytics and advertising cookies
Analytics, advertising and tracking cookies will only be placed where the required consent has been provided.
These cookies may be used to understand website behaviour, measure advertising performance and personalise advertisements.
You can accept, reject or adjust non-essential cookies through our cookie banner. You can later change your choices through the cookie-preferences link on our website.
Consent must be freely given and properly obtained before non-essential tracking technologies are activated.
11. EMAIL MARKETING, WAITLISTS AND EARLY ACCESS
When you subscribe to our newsletter or join a drop waitlist, we may use your email address to send:
- Product announcements;
- Early-access codes;
- Private drop links;
- Drop notifications;
- Restock messages;
- Event information;
- Promotional offers;
- Other marketing communications.
We send marketing communications only where legally permitted.
You may unsubscribe at any time by:
- Clicking the unsubscribe link in an email;
- Changing your account preferences where available;
- Contacting us at support@freresdlc.com.
Transactional messages concerning orders, deliveries, refunds, security issues or customer-service requests are not marketing messages and may still be sent where necessary.
12. SHARING PERSONAL DATA
We may share personal data with service providers that help us operate our business, including:
- Shopify;
- Payment providers;
- Delivery and logistics providers;
- Email and newsletter providers;
- Analytics providers;
- Google;
- Meta;
- Hosting and technical providers;
- Fraud-prevention providers;
- Customer-support providers;
- Accountants;
- Legal advisers;
- Professional advisers;
- Government bodies, courts or regulators where legally required.
These parties may process personal data on our behalf or according to their own independent legal responsibilities.
We do not sell customer lists for money.
Certain advertising activities may qualify as data sharing under the laws of some countries. Where applicable, we provide the legally required controls and information.
13. DATA RETENTION
We retain personal data only for as long as necessary for the purposes described in this Privacy Policy or where required by law.
Typical retention periods include:
- Order, invoice and accounting records: seven years;
- Records covered by applicable EU VAT One Stop Shop schemes: ten years where legally required;
- Customer-service communications: for as long as necessary to resolve the issue and maintain appropriate records;
- Customer accounts: until the account is deleted or is no longer reasonably required;
- Newsletter and waitlist information: until you unsubscribe, withdraw consent or the information is no longer required;
- Cookie and analytics information: according to the retention settings used by the relevant platform;
- Fraud and security information: for as long as reasonably necessary to protect our business and customers;
- Legal-claim information: for as long as necessary to establish, exercise or defend a legal claim.
Dutch businesses generally retain core accounting records for seven years. Certain records connected to EU VAT schemes must be retained for ten years.
14. YOUR PRIVACY RIGHTS
Subject to applicable law, you may have the right to:
- Access your personal data;
- Receive information about how your personal data is used;
- Correct inaccurate or incomplete personal data;
- Request deletion of personal data;
- Restrict processing;
- Object to certain processing;
- Withdraw consent;
- Receive certain personal data in a structured, commonly used and machine-readable format;
- Lodge a complaint with a supervisory authority.
To exercise a privacy right, contact us at:
Please provide enough information for us to identify you and understand your request. We may request additional information where reasonably necessary to verify your identity.
Privacy requests are generally handled free of charge, except where a request is manifestly unfounded or excessive as permitted by law.
You may also lodge a complaint with the Dutch supervisory authority:
Autoriteit Persoonsgegevens
15. DIRECT MARKETING RIGHTS
You may object at any time to the use of your personal data for direct marketing.
You may also withdraw consent for personalised advertising or marketing cookies through our cookie-preference settings.
Direct marketing involving personal data often requires consent or another valid legal basis.
16. AUTOMATED DECISION-MAKING
We do not intend to make decisions that produce legal or similarly significant effects based solely on automated processing.
Our service providers may use automated systems for purposes such as:
- Fraud detection;
- Payment security;
- Advertising optimisation;
- Website personalisation.
Where legally required, further information or appropriate safeguards will be provided.
17. SECURITY
We use reasonable technical and organisational measures to protect personal data against:
- Loss;
- Misuse;
- Unauthorised access;
- Unauthorised disclosure;
- Alteration;
- Destruction.
These measures may include access controls, encrypted connections, account security, restricted permissions and service-provider security measures.
No online system can be guaranteed to be completely secure.
18. CHILDREN
Our webshop is not specifically directed at young children.
We do not knowingly use children’s personal data for personalised advertising without the consent or other legal basis required by law.
Where a child cannot lawfully provide consent or enter into a purchase independently, permission from a parent or legal guardian may be required.
19. THIRD-PARTY LINKS
Our website may contain links to third-party websites, social-media platforms or services.
We do not control the privacy, security or content practices of independent third parties. Their own privacy policies and terms apply.
We recommend reviewing their privacy information before providing personal data.
20. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy where necessary to reflect changes in:
- Our services;
- Technology;
- Service providers;
- Marketing activities;
- Legal obligations;
- Business practices.
The latest version will be published on our website with an updated revision date.
CONTACT
Frères de la Cité
E. Thomassen à Thuessinklaan 13A
9713 JP Groningen
The Netherlands
Email: info@freresdlc.com
Chamber of Commerce No.: 93428642
VAT No.: NL866394953B01