Privacy & Cookie Policy

Last updated: November 2025

1. Introduction

This Privacy & Cookie Policy explains how PHOAF ["we", "our", "us"] collects, uses, and protects your personal data when you visit or make a purchase from www.phoaf.com [the "Website"].

We are committed to protecting your privacy and processing your data in accordance with the EU General Data Protection Regulation [GDP]) and the Dutch Data Protection Act [AVG].

By using our Website, you agree to this Policy.

2. Who We Are

PHOAF
Amsterdam, The Netherlands
KvK: 72727632
VAT: NL474610615B01
Email: studio@phoaf.com

For all privacy-related matters, please contact us via the email address above.

3. Information We Collect

We collect the following types of personal data:

A. Information you provide directly

  • Name
  • Billing and shipping address
  • Email address and phone number
  • Payment details [processed securely by our payment providers]
  • Any correspondence you send to us [e.g. customer support]

B. Information collected automatically

  • IP address and device type
  • Browser type and version
  • Website interaction data [pages viewed, time on page, etc.]
  • Cookies and similar technologies [see section 8 below]

4. How We Use Your Data

Purpose Legal Basis
To process, fulfill, and deliver your order Performance of a contract
To communicate with you regarding orders or returns Performance of a contract
To manage your account and customer support Legitimate interest
To send newsletters or marketing [only if you opt in] Consent
To comply with legal, VAT, and customs obligations Legal obligation
To improve our website and customer experience Legitimate interest

We will never sell or rent your personal data to third parties.

5. Sharing of Data

We share personal data only when necessary to operate our business, with:

  • Shopify our e-commerce and hosting provider [Shopify Inc., Canada and Shopify International Ltd., Ireland]
  • Payment processors such as Shopify Payments or PayPal
  • Shipping partners and customs agents for order delivery
  • Marketing tools e.g. Google Analytics, Meta [Facebook/Instagram] Pixel, Klaviyo [email marketing] only if you consent to cookies
  • Professional advisers accountants, auditors, legal counsel
  • Authorities if required by law [e.g. tax or customs]

All partners are bound by confidentiality and data protection obligations consistent with the GDPR.

6. Data Retention

We retain your data only as long as necessary for the stated purposes or as required by law:

  • Order and invoicing data: 7 years [Dutch tax law]
  • Customer support messages: up to 2 years
  • Newsletter subscriptions: until you unsubscribe
  • Cookie data: see retention periods in section 8

7. Your Rights

Under the GDPR, you have the right to:

  • Access your data
  • Rectify inaccurate information
  • Erase your data ["right to be forgotten"]
  • Restrict processing
  • Object to processing [e.g. marketing]
  • Data portability [receive your data in a structured format]

To exercise your rights, please email studio@phoaf.com. We will respond within 30 days.

You may also lodge a complaint with the Autoriteit Persoonsgegevens [Dutch Data Protection Authority]: https://autoriteitpersoonsgegevens.nl

8. Cookies and Similar Technologies

Our Website uses cookies and similar technologies to provide a smooth shopping experience, analyze traffic, and personalise content and advertising.

A. What are cookies?

Cookies are small text files stored on your device that help us recognise you and remember your preferences.

B. Types of cookies we use

Type Purpose Examples / Providers Retention
Essential cookies Required for website functionality, cart and checkout process Shopify Session / short-term
Analytics cookies Help us understand how visitors use our site Google Analytics 4 [IP anonymised] Up to 2 years
Marketing cookies Used for remarketing and measuring ad performance [only if you consent] Meta Pixel, Google Ads, Klaviyo Up to 2 years
Preference cookies Remember your country, language, or cart contents Shopify Session / 1 year

C. Cookie consent
When you visit our Website for the first time, you will see a cookie banner. You can accept all cookies, reject non-essential cookies, or adjust your preferences. You may also disable or delete cookies at any time via your browser settings.

D. Third-party cookies
Some cookies are placed by third-party services integrated into our site [e.g. analytics, ads, social media]. These parties may process your data outside the EU under appropriate safeguards such as EU Standard Contractual Clauses.

9. International Data Transfers

As we use Shopify and global service providers, your data may be transferred outside the EU [e.g. to Canada or the United States]. We ensure adequate protection through data-transfer agreements and EU Standard Contractual Clauses approved by the European Commission.

10. Security

We take appropriate technical and organizational measures to protect your data from unauthorized access, loss, or misuse. Payment details are encrypted and processed only by certified providers through secure connections.

11. Children

Our Website is not intended for persons under the age of 16. We do not knowingly collect personal data from minors.

12. Updates to this Policy

We may update this Privacy & Cookie Policy periodically to reflect changes in law or business practice. The latest version will always be available on our Website, with the date of the last revision shown at the top.

13. Contact

If you have any questions or requests concerning your personal data or this Policy, please contact: studio@phoaf.com