24HRS Collective
Legal

Privacy

We keep data collection to what we need to run the shop and the collective. This policy explains what we collect, why, and what you can ask us to do with it.

Last updated — August 2026

Controller

24HRS Collective, Amsterdam, The Netherlands, is the data controller. For any privacy question or request, write to 24hrscollective@gmail.com.

What we collect

Order data (name, email, shipping and billing address, phone, order contents), payment status (never full card numbers), newsletter email address if you subscribe, customer service correspondence, and technical data such as IP address, device and pages visited.

Why we use it

To process and deliver your order and handle returns (performance of a contract); to send marketing emails if you opted in (consent, withdrawable at any time); to prevent fraud and to improve the site (legitimate interest); and to keep invoices for tax purposes (legal obligation).

Who we share it with

Shopify (store and checkout platform), payment providers, carriers such as PostNL and DHL, our email and analytics providers, and our accountant. They only process data on our instructions. Where data leaves the EEA, it is covered by Standard Contractual Clauses.

Cookies

We use functional cookies needed for the cart and checkout, and analytics cookies to understand how the site is used. You can block or delete cookies in your browser; the cart and checkout will not work without functional cookies.

How long we keep it

Order and invoice data is kept for 7 years as required by Dutch tax law. Newsletter data is kept until you unsubscribe. Support correspondence is kept for 2 years.

Your rights

You can request access, correction, deletion, restriction or portability of your data, and object to processing based on legitimate interest. Email 24hrscollective@gmail.com and we respond within 30 days. You may also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

Security

The site runs over HTTPS and payments are handled by PCI-compliant providers. Access to personal data inside the collective is limited to the people who need it.