GDPR / AVG COMPLIANT

PRIVACY
POLICY

Scalp Collectors Group CoC: 77967577 Version: May 2026

1. Data controller

The controller responsible for the processing of your personal data is:

Scalp Collectors Group
Email: scalpcollectorgroup@proton.me
Chamber of Commerce: 77967577
Country: Netherlands

We are bound by the General Data Protection Regulation (GDPR / AVG, Regulation EU 2016/679).

2. What personal data do we process?

We process the following categories of personal data:

  • Identification data: first name, last name
  • Contact data: email address, phone number (if provided)
  • Delivery data: shipping address, postal code, city, country
  • Transaction data: ordered products, order amount, payment status (payment data is processed by Shopify Payments — we do not see full card details)
  • Communication data: email correspondence
  • Technical data: IP address, browser type, page visits (collected via Shopify analytics and cookies)
  • Marketing opt-in: email address and consent for drop notifications (if subscribed)

3. Purposes and legal bases for processing

We process your data for the following purposes:

  • Performance of the purchase contract (Art. 6(1)(b) GDPR): processing your order, payment, production via Printful, and shipping.
  • Legal obligation (Art. 6(1)(c) GDPR): retention of accounting records and invoices in accordance with Dutch fiscal retention obligations (7 years).
  • Legitimate interests (Art. 6(1)(f) GDPR): fraud prevention and security of our systems.
  • Consent (Art. 6(1)(a) GDPR): sending drop notifications by email, only if you have signed up for this. You may withdraw your consent at any time via the unsubscribe link in any email.

4. Sharing with third parties

We share your data with third parties only to the extent necessary for the performance of the contract or as required by law:

  • Shopify Inc. (US) — e-commerce platform. Shopify is certified under the EU-US Data Privacy Framework. Privacy policy: shopify.com/legal/privacy.
  • Printful Inc. (US / EU) — production and shipping of orders. Your name and delivery address are shared for fulfilment purposes. Privacy policy: printful.com/policies/privacy-policy.
  • Email provider — for sending transactional emails and (with consent) drop notifications.
  • Tax authorities — where legally required.

We do not sell your personal data to third parties.

5. Retention periods

  • Order data: 7 years (fiscal retention obligation under Dutch law)
  • Marketing data (email list): for as long as you remain subscribed; deleted or anonymised immediately upon unsubscription
  • Customer service correspondence: maximum 2 years after resolution
  • Technical log data: maximum 90 days

6. Your rights as a data subject

Under the GDPR you have the following rights:

  • Right of access (Art. 15 GDPR): you may request what data we process about you.
  • Right to rectification (Art. 16 GDPR): correction of inaccurate data.
  • Right to erasure (Art. 17 GDPR): deletion of your data, to the extent permitted by legal retention obligations.
  • Right to restriction of processing (Art. 18 GDPR).
  • Right to data portability (Art. 20 GDPR).
  • Right to object (Art. 21 GDPR): objection to processing based on legitimate interests.
  • Right to withdraw consent (Art. 7(3) GDPR): for processing based on consent.

You may exercise your rights by sending an email to scalpcollectorgroup@proton.me. We will respond within 30 days.

You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens): autoriteitpersoonsgegevens.nl.

7. Cookies and tracking

Our webshop uses cookies via the Shopify platform. These include:

  • Functional cookies: for the operation of the shopping cart and checkout (necessary — no consent required).
  • Analytical cookies: Shopify Analytics for statistical purposes.

You can manage cookies via your browser settings. Note: disabling functional cookies may affect the operation of the webshop.

8. Security

We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or theft. All data transactions are encrypted via HTTPS. Payment data is processed exclusively through the secure Shopify Payments platform (PCI DSS certified).

9. Contact

For questions about your personal data:
scalpcollectorgroup@proton.me
CoC: 77967577