Your data. Clearly explained.
Privacy policy.
This policy explains which personal data World Coffee Gear collects, why we use it, who may receive it and the choices and rights available to you.
Last updated: 8 September 2026We collect data needed to run our shop, fulfil orders and provide support.
We do not sell or rent your personal data to other organisations.
Data is shared only with providers needed for our services or where the law requires it.
You can exercise your GDPR rights or withdraw consent at any time.
1. Who we are
World Coffee Gear B.V. is responsible for the processing described in this policy unless we expressly state that we act only on behalf of another organisation.
World Coffee Gear B.V.
Ericssonstraat 2
5121 ML Rijen
The Netherlands
Chamber of Commerce: 83953019
Email: hello@worldcoffeegear.eu
Telephone: +31 (0)88 800 9853
2. Scope and our privacy roles
This policy applies to visitors to worldcoffeegear.eu, consumers, business customers, reseller and company-account applicants, suppliers, contacts and people who submit a support, return, warranty, withdrawal or customisation request.
World Coffee Gear as controller
We act as controller when we determine why and how personal data is used, including for our own webshop, customer and business accounts, applications, order administration, support, invoicing, newsletters, security and legal compliance.
World Coffee Gear as processor for fulfilment
When we fulfil an order for an e-retailer, that retailer normally remains the controller for its end-customer data and World Coffee Gear processes the data on the retailer's documented instructions. This may include receiving order data through an API, forwarding delivery details to Dimass Group B.V. and a carrier, providing sales and return information in the back office and handling a retailer-initiated order or return. These activities are governed by our agreement and, where required, a data processing agreement with the retailer.
We may act as an independent controller for limited related purposes where we have our own legal obligations, for example accounting, fraud prevention or responding to a lawful request.
3. Personal data we process
Depending on your relationship with us, we may process:
- Identity and contact data: name, billing and delivery address, email address and telephone number.
- Business data: company name, job title, Chamber of Commerce information, VAT number, sales channels and reseller or company-account information.
- Account data: account identifier, login and security data, preferences and account status. Passwords are stored in protected form and are not available to us as readable text.
- Order and transaction data: products, quantities, prices, discounts, payment status, delivery, tracking, invoices, refunds and order history.
- Payment data: payment method, payment status and, where relevant, bank account information for transfers or refunds. Full card details are processed by the payment provider and are not available to us.
- Support and form data: messages, return or warranty details, withdrawal requests, photographs, videos, supporting documents and other information you choose to provide through email or Jotform.
- Customisation data: artwork, logos, contact details, requested positioning and quotation or approval information.
- Website and device data: IP address, browser and device information, cookie identifiers, page interactions, referral information and security logs.
- Marketing data: newsletter subscription, consent status, campaign interaction and communication preferences.
- Fulfilment data: end-customer name, address, contact details, order, delivery and return information received from an e-retailer.
We do not intentionally request special-category data, such as health, biometric, religious or political information. Please do not include such data in open text fields or uploads unless it is strictly necessary and we have specifically requested it.
4. Why we use data and our legal bases
| Purpose | Main legal basis |
|---|---|
| Creating and managing an account, processing an order, payment, delivery, return, withdrawal, warranty request or customisation order | Performance of a contract or steps requested before entering into a contract |
| Reviewing reseller, company-account and fulfilment applications and managing the business relationship | Pre-contractual steps, performance of a contract and our legitimate interest in selecting and serving suitable business partners |
| Customer service, answering questions and handling complaints | Performance of a contract and our legitimate interest in providing support and improving our service |
| Accounting, VAT validation, invoicing, OSS records and compliance with tax or other legislation | Compliance with a legal obligation |
| Protecting the website, accounts and transactions; preventing fraud, misuse and security incidents; establishing or defending legal claims | Our legitimate interests in secure operations and legal protection, and where applicable a legal obligation |
| Sending the newsletter and other consent-based marketing | Your consent, which you may withdraw at any time |
| Analytics, campaign measurement, personalisation, OptinMonster and non-essential embedded content | Your prior consent where required; see our Cookie Policy |
| Product safety notices, recalls and essential service messages | Compliance with legal obligations, performance of a contract and our legitimate interest in product and customer safety |
Where we rely on legitimate interests, we consider the necessity of the processing, our interest and the possible impact on you. You may object to this processing as described below.
5. Sources and data you must provide
We usually receive data directly from you through our webshop, account, email, telephone, Jotform or another application form. We may also receive data from an e-retailer for fulfilment, from payment and delivery providers, from a VAT validation service, or from publicly accessible business registers when verifying a business application.
Data marked as required during checkout, registration or an application is needed to process the request, conclude or perform the contract, or meet a legal requirement. Without it, we may be unable to create the account, approve an application, accept payment or deliver the order. Optional fields are identified as such or can be left blank.
6. Who may receive personal data
We share only the data needed for the relevant service. Recipients may include:
- Hosting, ecommerce and IT providers, including Magento service providers and Hypernode.
- Fulfilment and delivery providers, including Dimass Group B.V., PostNL, DHL, DPD and GLS.
- Payment providers, including Mollie and the payment method selected during checkout.
- Administration providers, including Exact Online and Webwinkelfacturen.nl.
- Form and support providers, including Jotform.
- Email and marketing providers, including Intuit Mailchimp and OptinMonster.
- Analytics, security and embedded-content providers, including Google Analytics, Google Tag Manager, Google reCAPTCHA and YouTube, after consent where required.
- Manufacturers and brand partners where their technical assessment or action is necessary for a warranty, safety or product-support matter.
- Professional advisers and public authorities where necessary for legal advice, a legal claim or compliance with a binding obligation.
Providers acting as our processors may use the data only on our documented instructions, must protect it and may not use it for their own unrelated purposes. Some parties, such as payment providers and carriers, may also act as independent controllers for parts of their service.
We do not sell or rent personal data.
7. Transfers outside the European Economic Area
Some providers, including Google, YouTube, Intuit Mailchimp, Jotform and OptinMonster, may process or make personal data accessible outside the European Economic Area. Where this occurs, we use a transfer mechanism recognised under the GDPR, such as an adequacy decision, including the EU–US Data Privacy Framework where the recipient is validly certified, or European Commission Standard Contractual Clauses together with additional safeguards where required.
You may contact us for further information about the safeguards applicable to a particular transfer.
8. How long we retain data
We retain personal data only for as long as necessary for the relevant purpose:
| Data or record | General retention period |
|---|---|
| Invoices, payments, purchase and sales administration | 7 years after the end of the relevant financial year; records covered by the EU One Stop Shop scheme are retained for 10 years |
| Customer account | For as long as the account is active and generally up to 12 months after closure or inactivity; legally required transaction records are retained separately for the applicable statutory period |
| General enquiries and support correspondence | Up to 12 months after the matter has been closed, unless needed for an order, warranty matter or legal claim |
| Reseller, company-account or fulfilment application | During the relationship and generally up to 12 months after it ends; an unsuccessful application is generally deleted within 12 months |
| Raw Jotform submissions and uploaded files | Generally deleted from Jotform no later than 12 months after the request has been fully resolved |
| Return, withdrawal, warranty, complaint or dispute records | For the time needed to handle the matter and afterwards for as long as necessary for legal obligations or the establishment, exercise or defence of legal claims |
| Newsletter data | Until consent is withdrawn; a minimal suppression record may be retained to ensure that the opt-out continues to be respected |
| Cookie, consent and analytics data | According to the periods stated in our Cookie Policy, generally no longer than 2 years |
| Security logs | Generally up to 12 months, unless longer retention is required to investigate an incident or establish or defend a claim |
When data is no longer required, it is deleted or anonymised. A longer period may apply where legislation requires it, a dispute is ongoing or evidence is reasonably needed for a legal claim.
9. Your privacy rights
Subject to the conditions of the GDPR, you may:
- request access to your personal data;
- have inaccurate or incomplete data corrected;
- request erasure of data that is no longer needed;
- request restriction of processing;
- receive certain data in a structured, commonly used and machine-readable format or have it transferred to another controller;
- object to processing based on our legitimate interests;
- object at any time to the use of your data for direct marketing;
- withdraw consent at any time, without affecting processing carried out before withdrawal; and
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, subject to the exceptions in the GDPR.
Send your request to hello@worldcoffeegear.eu. We normally respond without undue delay and no later than one month after receiving the request. If a request is complex or several requests have been made, this period may be extended by up to two further months; we will explain this within the first month.
Exercising your rights is normally free. If we reasonably doubt your identity, we may ask for limited additional information needed to verify it. Please do not send a copy of your identity document unless we specifically request it and explain how to provide it securely.
A request may be limited or refused where the GDPR permits this, for example where information must be retained by law or deletion would adversely affect the rights of another person.
Complaints
Please contact us first so that we can try to resolve your concern. You also have the right to lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens, through its official website, or with the supervisory authority in the EU country where you live or work.
10. Security and automated decisions
We apply appropriate technical and organisational measures designed to protect personal data against loss, misuse and unauthorised access, alteration or disclosure. Measures include access controls, secure connections, protected account credentials, backups, supplier agreements and procedures for handling incidents. No online system can, however, be guaranteed to be completely secure.
We do not use solely automated decision-making that produces legal effects or similarly significantly affects you. Analytics and marketing tools may group website interactions or measure campaigns after consent, but they do not independently decide whether you may purchase from us or exercise your legal rights.
11. Children
Our webshop and business services are not directed at children under 16 and we do not knowingly collect their data through consent-based services without the permission required by law. If you believe a child has provided personal data to us without valid permission, please contact us.
12. Changes to this policy
We may update this policy when our services, providers or legal obligations change. The current version is always published on this page with its latest revision date. If a change materially affects how we use data, we will provide an additional notice where appropriate.
Questions about your data?
World Coffee Gear B.V. — Privacy contact