Privacy policy

Privacy Policy – Maison Wren

1. Information on the collection of personal data and contact details of the data controller

1.1 We are pleased that you are visiting our website and thank you for your interest. In the following section, we inform you about the handling of your personal data when you use our website. Personal data is any data that makes it possible to identify you personally.
1.2 The data controller of this website according to the General Data Protection Regulation (GDPR) is Maison Wren. The controller of personal data is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data.
1.3 This website uses SSL or TLS encryption for security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or requests to the controller). You can recognize an encrypted connection by the string “https://” and the lock symbol in your browser bar.

2. Data collection when you visit our website

For purely informational use of our website, i.e., when you do not register or otherwise transmit information to us, we only collect the data that your browser sends to our server (so-called “server log files”). When you visit our website, we collect the following data, which is technically necessary to show you the website:

  • Our visited website

  • Date and time of access

  • Amount of data sent in bytes

  • Source/reference from which you came to the page

  • Browser used

  • Operating system used

  • IP address used (possibly in anonymized form)

Processing is carried out in accordance with Art. 6(1)(f) GDPR (AVG) on the basis of our legitimate interest in improving the stability and functionality of our website. The data will not be passed on or used for other purposes. However, we reserve the right to check the server log files afterwards if there are concrete signs of illegal use.

3. Cookies

To make visiting our website attractive and to enable the use of certain functions, we use cookies. Some cookies are session-based and are deleted when you close your browser; others are persistent and allow us or partners (“third-party cookies”) to recognize your browser on your next visit. When cookies are set, certain user information (e.g., browser, location data, IP address) may be processed. Persistent cookies are deleted after their specific lifetime.

Where cookies process personal data, processing takes place under Art. 6(1)(b) GDPR to fulfill a contract or Art. 6(1)(f) GDPR based on our legitimate interest in functionality and an efficient, user-friendly website. We may cooperate with advertising partners who place third-party cookies; details are provided in the sections below.

You can configure your browser to inform you about cookies, decide case-by-case, block them, or delete them. Help pages:

If you do not accept cookies, certain website functions may be limited.

4. Contacting us

If you contact us (e.g., via contact form or e-mail), we collect the personal data shown in the form or contained in your message. This data is used solely to answer your inquiry and for related technical administration. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in responding). If your contact aims to conclude a contract, Art. 6(1)(b) GDPR applies. Data will be erased once your request is resolved unless legal retention duties apply.

5. Data processing when opening a customer account and for contract fulfillment

Under Art. 6(1)(b) GDPR, we process personal data you provide to fulfill a contract or open a customer account. You may request deletion of your account at any time by contacting the controller. After contract end or account deletion, data is restricted and erased after statutory retention periods unless you consent to further use or we are legally permitted to continue processing.

6. Use of your data for direct advertising

6.1 Subscribing to our email newsletter

With your subscription, we send offers via email. Required field: your email address. We use double opt-in. By confirming, you consent under Art. 6(1)(a) GDPR. We store your IP, date, and time of signup to prevent misuse. You can unsubscribe anytime via the link in the newsletter or by contacting us; we then remove your email unless further use is permitted by law.

6.2 Newsletters to existing customers

If you provided your email while purchasing, we may email you offers for similar products based on our legitimate interest in direct advertising (Art. 6(1)(f) GDPR). You can object at any time; after objection, we stop using your email for advertising.

7. Data processing for order processing

We transmit necessary personal data to carriers for delivery and to payment institutions/service providers for payment. Legal basis: Art. 6(1)(b) GDPR.

8. Contact for review reminders

If you explicitly consent (Art. 6(1)(a) GDPR), we may send a one-time reminder to review your order. You can withdraw consent at any time by contacting the controller.

9. Use of social media: social plugins (Shariff solution)

9.1 Facebook

Plugins from Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA. Integrated via Shariff (HTML link) to prevent automatic data transfer. On click, Facebook’s page opens. Privacy policy: https://www.facebook.com/policy.php

9.2 Google+

Plugins from Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, integrated via Shariff. Privacy policy: https://www.google.com/intl/nl/policies/privacy/

9.3 Instagram

Plugins from Instagram LLC, 1601 Willow Rd, Menlo Park, CA 94025, USA, integrated via Shariff. Privacy policy: https://help.instagram.com/155833707900388/

(Note: Some referenced programs like “Google+” are deprecated; if you want, I can modernize these sections.)

10. Online marketing

10.1 DoubleClick by Google

We use DoubleClick (Google LLC) for ads and conversions, based on our legitimate interest (Art. 6(1)(f) GDPR). Info: https://www.google.com/policies/technologies/ads/

10.2 Google Ads Conversion Tracking

We use Google Ads conversion cookies (typically valid 30 days) to measure campaign performance (Art. 6(1)(f) GDPR). Privacy: https://www.google.nl/policies/privacy/
Opt-out plugin: https://www.google.com/settings/ads/plugin?hl=nl

11. Web analytics services

Google (Universal) Analytics with IP anonymization (“_anonymizeIp()”). Legal basis: Art. 6(1)(f) GDPR (statistics/optimization).
Opt-out: https://tools.google.com/dlpage/gaoptout?hl=nl
More info: https://support.google.com/analytics/answer/2838718?hl=nl&ref_topic=6010376

12. Retargeting / Remarketing / Recommendation advertising

Facebook Pixel (consent, Art. 6(1)(a) GDPR). Policy: https://www.facebook.com/about/privacy/
Google Ads Remarketing (legitimate interest, Art. 6(1)(f) GDPR). Ads info: https://www.google.com/policies/technologies/ads/
Opt-out: https://www.google.com/settings/ads/onweb/ and https://www.aboutads.info/choices/

13. Rights of the data subject

You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), notification (Art. 19), data portability (Art. 20), withdrawal of consent (Art. 7(3)), and complaint to a supervisory authority (Art. 77).

13.2 Right to object

You may object at any time to processing based on legitimate interests (Art. 6(1)(f)) on grounds relating to your situation. If you object to direct marketing, we stop processing for that purpose immediately.

14. Duration of storage of personal data

Storage duration follows statutory retention periods. After expiry, data is deleted unless needed for contract fulfillment/negotiations or a legitimate interest persists.


Contact
If you have any questions or feedback about this privacy policy, please contact us at info@maisonwren.com