Privacy Policy
Rehall (RSD B.V.) Privacy Policy
Effective Date: September 20, 2024
Last Updated: August 6, 2025
Rehall (RSD B.V.) places great importance on your privacy. We only process data necessary to improve our services and handle the information we collect about your use of our services with care. Your data will never be shared with third parties for commercial purposes without your explicit consent.
This privacy policy applies to the use of our website and the services available through it. In this document, we explain:
-
which personal data we collect,
-
how we use it,
-
with whom and under what conditions we share it,
-
how we secure your data,
-
and what rights you have with regard to your personal data.
If you have any questions, please contact our Data Protection Officer via the contact details at the end of this document.
Data Processing
Below we describe how we process, store, and secure personal data, and who is involved in this process.
E-commerce Software – Shopify
Our webshop is built using Shopify software. The personal data you provide to us is shared with Shopify. This party offers technical support and has access to data only when necessary. Shopify applies appropriate security measures, such as SSL encryption and a strict password policy. Data may be processed in the United States, in compliance with the EU-U.S. Data Privacy Framework.
Email and Mailing Lists – Klaviyo
For our email communication and newsletters, we use Klaviyo. Your email address, name, and purchase history may be stored within this platform to send you relevant content. Klaviyo processes your data solely on behalf of Rehall and does not use it for its own purposes. Every email contains a clear unsubscribe link.
Payment Processing – iDEAL, Shopify Payments, Credit Cards, and Klarna
To process payments in our webshop, we use several payment methods, including iDEAL, credit cards (via Shopify Payments), and Klarna (pay later).
-
Shopify Payments processes transactions via iDEAL and credit cards (Visa, Mastercard, etc.). This payment provider stores your payment details in accordance with the strictest security standards (such as PCI DSS).
-
Klarna offers pay-later options and conducts a creditworthiness check in this process. Klarna processes personal data such as name, address details, phone number, and payment history. More information can be found on Klarna’s website.
All mentioned parties take appropriate technical and organizational measures to protect your data. Your data will only be used to process payments and not for commercial purposes.
Reviews – Trustpilot
We collect reviews through Trustpilot. If you leave a review, we share your name and email address with Trustpilot so they can verify your identity and contact you if necessary. Trustpilot applies security measures to protect your data.
Shipping and Logistics – DHL, PostNL, DPD, GLS
To ship orders, we use multiple carriers: DHL, PostNL, DPD, and GLS. For this purpose, we share data such as your name, address, and city with these parties. This data is used solely for delivery and not for other purposes.
Invoicing and Accounting – Exact Online
For our financial administration, we use Exact Online. Your personal data, such as name, address, and invoice details, are shared with this software to maintain accurate bookkeeping. Exact treats this data confidentially and does not use it for its own purposes.
Automatically Collected Data
When visiting our website, certain data is automatically collected, such as your IP address, browser information, and click behavior. This data is used to improve our website and user experience. When such data can be traced to an individual, we treat it as personal data under the GDPR.
Cookies
We use cookies for technical functionality, analytical purposes, and (with consent) marketing purposes.
Google Analytics is used to analyze visitor behavior. IP addresses are anonymized before processing.
International Data Transfers
Some of our partners, such as Shopify, Klaviyo, and Google, are located outside the European Economic Area (EEA). Where they process personal data, they do so in compliance with the EU-U.S. Data Privacy Framework or appropriate model contracts, ensuring your data remains adequately protected.
Data Retention
We retain your data for as long as you are our customer. If you indicate that you no longer wish to use our services, we treat this as a request to be forgotten. Your data will then be retained for a maximum of two years after your last contact or purchase, unless legal obligations require a longer retention period.
Your Rights
Under the GDPR, you have the following rights:
-
Right of access: You may request to view your personal data.
-
Right to rectification: You may have incorrect data corrected.
-
Right to restriction: You may request to limit the processing of your data.
-
Right to data portability: You may request to have your data transferred to a third party.
-
Right to object: You may object to the processing of your data.
-
Right to erasure: You may request the permanent deletion of your data.
Requests can be submitted via the contact details below. We will respond within 30 days and may ask you to verify your identity.
Changes to This Privacy Policy
We reserve the right to amend this privacy policy. The most recent version will always be available on our website. In case of substantial changes in how we process personal data, we will notify you via email or a website banner.