Privacy Policy
Last updated: June 6, 2026
This Privacy Policy explains how Vera Lumin B.V. collects, uses, shares, and otherwise processes personal data when you visit or use our website, place an order, create an account, join Vera Privé, use your wishlist, request a back-in-stock or pre-order notification, contact us, interact with our social media or business profiles, or otherwise interact with Vera Lumin through our connected sales, advertising, analytics, and service channels.
CONTROLLER
Vera Lumin B.V., Posthoornstraat 11, Apt. 3, 3011 WD Rotterdam, The Netherlands, email: vera@veralumin.com, is the controller for the processing described in this Privacy Policy.
Where a third-party platform or service, such as Shopify, Shop, Google, Meta, Pinterest, TikTok, or another connected platform, determines its own purposes and means for processing personal data through its own account, app, marketplace, advertising network, analytics product, business profile, or checkout environment, that platform may also act as an independent controller for that separate processing. In those cases, the platform's own privacy notice, terms, and privacy settings also apply.
PERSONAL DATA WE COLLECT
Depending on how you interact with Vera Lumin, we may collect and process the following categories of personal data:
- Identity and contact details: such as your name, billing address, shipping address, physical address, email address, phone number, country, language preference, and currency or market preference.
- Account and authentication data: such as your customer account details, login credentials, account ID, authentication status, password reset information, and, if you choose to use it, information connected to “Continue with Google” or another third-party sign-in method.
- Order, payment, invoice, and transaction data: such as products ordered, product size, colour, style, collection, order history, order value, payment status, payment method, transaction references, invoice details, VAT or tax details where applicable, shipping details, customs or import information where applicable, return details, refund details, chargeback or dispute information, and customer service history. We do not receive or store your full payment card number.
- Product preference, wishlist, and stock-notification data: such as products viewed, products added to your wishlist, saved products, product interests, size or style preferences, back-in-stock requests, pre-order interests, notification preferences, and related product activity.
- Vera Privé loyalty data: such as loyalty membership status, tier, points, rewards, discounts, referrals, spending history used to calculate tier status, and loyalty-related account activity.
- Customer service and communications data: such as messages you send to us, emails, complaints, questions, return requests, non-conformity or warranty-related information, and photos or videos you choose to provide in connection with a product, delivery, return, or complaint.
- Marketing and consent preference data: such as newsletter subscriptions, unsubscribe records, cookie choices, advertising consent records, marketing preferences, campaign identifiers, UTM parameters, email open and click data where available, and records needed to demonstrate or manage your consent choices.
- Device, browser, and usage data: such as IP address, approximate geolocation, browser type, browser version, operating system, device identifiers, cookie identifiers, client ID cookies, session identifiers, referring URLs, pages viewed, products viewed, search activity, cart activity, checkout events, purchase events, browsing behaviour, interaction data, and store analytics data.
- Sales-channel, advertising, and platform interaction data: such as interactions with Vera Lumin listings, shops, ads, product feeds, product pins, social commerce posts, Google Business Profile, Google Shopping listings, Pinterest, TikTok, Instagram, Facebook, YouTube, Shop, and other connected platforms.
- Public review and profile data: if you leave a review, comment, tag, message, or other public interaction on platforms such as Google, Instagram, Facebook, Pinterest, TikTok, or Shop, we may process your public profile name, username, review content, rating, photo, video, and the content of your interaction to respond, moderate, or manage our business presence.
Shopify app privacy screens may describe certain personal data as “sensitive data”, such as name, email address, phone number, and physical address. Under EU data protection law, these are generally treated as personal data, not necessarily as “special categories of personal data”. We do not intentionally collect special categories of personal data, such as health information, biometric data, or information about your sex life or sexual orientation. Because Vera Lumin sells lingerie and loungewear, your product choices, order history, wishlist, or size preferences may reveal personal preferences. We process that information only for the purposes described in this Privacy Policy. Please do not send us special category data unless it is strictly necessary for your request.
HOW WE COLLECT PERSONAL DATA
We collect personal data in the following ways:
- Directly from you: when you place an order, create an account, join Vera Privé, save a wishlist item, request a notification, contact us, subscribe to marketing, submit a return request, or otherwise provide information to us.
- Automatically through our website and store technologies: including Shopify, cookies, pixels, tags, analytics tools, server-side events, app embeds, customer events, and similar technologies.
- From service providers and connected apps: including Shopify, Shopify Payments, Shop, Sufio, Joy Loyalty, Swish, Stoq, logistics providers, payment providers, fraud-prevention services, and technical support providers.
- From sales, advertising, analytics, and social platforms: including Google, Meta, Pinterest, TikTok, Shop, Instagram, Facebook, YouTube, and Google Business Profile, where you interact with our listings, ads, shops, business profiles, or connected services.
PURPOSES AND LEGAL BASES
We process personal data for the purposes and legal bases below. Where we rely on legitimate interests, we do so only where our interests are not overridden by your rights and freedoms.
- Operating our website, online store, checkout, customer accounts, and Shopify store functions: to perform our contract with you, to take steps at your request before entering into a contract, and for our legitimate interests in operating a secure and functional ecommerce store.
- Orders, payments, delivery, returns, refunds, exchanges where applicable, and customer service: to perform our contract with you and to take steps at your request before entering into a contract.
- Invoices, accounting, tax records, customs records, payment records, and other legal compliance: to comply with legal obligations.
- Fraud prevention, payment security, chargeback handling, website security, abuse prevention, and legal claims: for our legitimate interests and, where applicable, to comply with legal obligations or to establish, exercise, or defend legal claims.
- Customer accounts, Vera Privé loyalty features, wishlist functionality, referrals, rewards, and requested back-in-stock or pre-order notifications: to perform the service you requested, to take steps at your request before entering into a contract, and for our legitimate interests in administering customer features. Where electronic marketing or notification consent is required, we rely on your consent.
- Transactional and service communications: to perform our contract with you, provide customer support, send order confirmations, shipping updates, invoices, return updates, account notices, and other non-marketing service messages.
- Marketing emails and promotional communications: based on your consent. For existing customers, where Dutch and EU rules allow us to contact you about similar products using a soft opt-in, we may rely on our legitimate interests, and you can opt out at any time.
- Analytics, store performance measurement, and service improvement: for our legitimate interests where the data is strictly necessary, aggregated, or non-invasive; and, for non-essential analytics cookies, pixels, tags, or similar technologies, based on your consent.
- Advertising, retargeting, conversion measurement, audience creation, customer matching, and campaign optimisation: based on your consent where required, including for tools such as Google Ads, Google Analytics advertising features, Meta Pixel, Meta Conversions API, Pinterest Tag, Pinterest Conversions API, TikTok Pixel, TikTok Events API, and similar technologies.
- Sales channels and product listing platforms: to make our products available through connected channels such as Shop, Google & YouTube, Pinterest, TikTok, Facebook, Instagram, and other Shopify-supported sales channels, based on our contract with you where you buy through or interact with those channels, and our legitimate interests in managing product availability, catalogues, orders, and sales channels. Any non-essential tracking or advertising through those channels is based on consent where required.
- Google Business Profile and public platform interactions: to manage our business listing, respond to reviews or messages, understand profile performance, and communicate with customers, based on our legitimate interests and, where applicable, your direct request or consent.
SALES CHANNELS, ADVERTISING, ANALYTICS, AND CONNECTED APPS
We use Shopify and connected apps, sales channels, advertising platforms, and analytics tools to operate and grow our store. These tools may have technical access to, receive, or generate personal data depending on your actions, your consent choices, the integration settings, and the specific feature used. Not every data category is shared in every case.
- Shopify, Online Store, Shop, Shop Pay, Shopify Payments, Shopify Email, and Shopify Flow: used to operate our website, checkout, payments, customer accounts, order management, automations, transactional communications, marketing emails, Shop channel presence, Shop-related order tracking, Shop sales channel analytics, and related Shopify services. Data may include identity and contact details, order details, payment status, shipping details, account data, device and browser data, approximate geolocation, and store interaction data.
- Shop and Shopify Network Intelligence: where enabled and required for Shop functionality, Shopify may process data to provide Shop-related features such as product discovery, order tracking, Shop store visibility, Shop analytics, Shop reviews, shopping activity sync for customers signed in with a Shop account, service improvement, fraud prevention, and related Shopify services. Shop may have its own privacy controls and settings for customers who use Shop.
- Google services: we may use Google & YouTube, Google Merchant Center, Google Ads, Google Analytics, Google Search Console, and Google Business Profile. The Google & YouTube sales channel may sync product and relevant store information with Google Merchant Center. Google Ads and Google Analytics may process website events such as page views, product views, add-to-cart events, checkout events, purchases, campaign source, device and browser data, client ID cookies, and approximate location. Where enabled and lawful, Google conversion features may use hashed customer-provided data, such as email address, phone number, name, or address, for conversion measurement and matching. Hashed identifiers are not readable in plain text but may still be personal data where they can be matched to an account.
- Google Business Profile: if you find, message, call, review, request directions to, or otherwise interact with Vera Lumin through Google Business Profile or Google Search/Maps surfaces, Google may process your interaction under its own terms and privacy notices. We may receive or view information such as your review content, rating, public profile name, message content, call or direction interaction metrics, and profile performance insights, depending on the Google feature used.
- Meta, Facebook, and Instagram: we use Facebook & Instagram by Meta, Instagram Shopping, Facebook Shop, Meta Pixel, Meta advertising tools, and related Meta integrations. These tools may process product catalogue data, store events, customer data-sharing events, browsing behaviour, purchase events, order values, product identifiers, IP address, browser and operating system, approximate geolocation, cookie or event identifiers, and, where advanced or maximum data sharing is enabled and lawful, personal identifiers such as name, email address, phone number, and location for matching, measurement, and advertising purposes.
- Pinterest: we use the Pinterest sales channel, Pinterest product catalogue features, Pinterest Tag, Pinterest advertising, and related conversion measurement tools. These tools may process product feed data, page visits, product views, category views, searches, add-to-cart events, checkout events, purchase events, wishlist-related events, IP address, browser and operating system, browsing behaviour, client ID or cookie identifiers, and related conversion or ad performance data.
- TikTok: we use TikTok sales, advertising, pixel, and data-sharing tools. Depending on the data-sharing level and your consent choices, TikTok may process customer data and browsing behaviour from our store, including product views, cart and checkout events, purchase events, IP address, browser and operating system, approximate geolocation, cookies or event identifiers, and, where advanced matching or similar features are enabled and lawful, contact or matching data such as email address, phone number, name, or location.
- Sufio: used to create, manage, send, and store invoices, credit notes, and related tax or accounting documents. Sufio may process customer names, contact details, billing and shipping addresses, order details, payment status, VAT or tax information where applicable, product details, quantities, and prices.
- Joy Loyalty: used to administer Vera Privé, including loyalty membership, tiers, points, rewards, referrals, coupon or discount rewards, and loyalty-related customer support. Joy may process customer profile details, email address, order and spending history, loyalty activity, rewards, tier status, and related Shopify customer data.
- Swish / Wishlist King: used to provide wishlist and saved-product functionality. Swish may process customer identifiers, email address where linked to an account or wishlist, wishlist contents, product interests, wishlist events, and device or browsing information needed to provide and improve the wishlist functionality.
- Stoq: used for pre-order, backorder, waitlist, and back-in-stock notification functionality. Stoq may process product interest data, email address, phone number if you choose SMS or phone-based notifications, notification requests, product and inventory data, order data where pre-orders are used, and related customer or device data needed to provide the requested notification or pre-order functionality.
Some connected apps and channels may technically be able to view or edit categories of Shopify store data such as customers, products, orders, order history, discounts, marketing data, online store data, store analytics, Shopify admin data, custom data, and other store data. We use these permissions only for the purposes described in this Privacy Policy and according to the app or platform settings we enable.
RECIPIENTS AND PROCESSORS
Depending on how you use our store, we may share personal data with the following recipients, processors, service providers, or independent controllers:
- Shopify and related Shopify services used to operate the store, including Online Store, Shop, Shop Pay, Shopify Payments, Shopify Email, Shopify Flow, Shopify analytics, customer accounts, checkout, and related infrastructure;
- Payment processors, banks, card networks, and fraud-prevention services used through Shopify Payments or other payment methods available at checkout;
- Shipping, fulfilment, returns, customs, and logistics partners, including FedEx and our fulfilment and returns partner 3PL Service Netherlands;
- Sufio, to create, send, and manage invoices, credit notes, and related tax documents;
- Joy Loyalty, to administer Vera Privé and loyalty-related features;
- Swish / Wishlist King, to provide wishlist and saved-product functionality;
- Stoq, to provide pre-order, back-in-stock, waitlist, and stock notification functionality;
- Google, including Google & YouTube, Google Merchant Center, Google Ads, Google Analytics, Google Search Console, and Google Business Profile;
- Meta, including Facebook, Instagram, Meta Pixel, Meta advertising tools, Facebook Shop, and Instagram Shopping;
- Pinterest, including Pinterest sales channel, Pinterest Tag, Pinterest catalogues, and Pinterest advertising tools;
- TikTok, including TikTok sales channel, TikTok Pixel, TikTok Events API, TikTok advertising tools, and related TikTok integrations;
- Professional advisers, accountants, auditors, insurers, legal advisers, IT providers, security providers, and business administration providers;
- Public authorities, tax authorities, customs authorities, regulators, law enforcement, courts, or other parties where disclosure is required by law or necessary to establish, exercise, or defend legal claims.
COOKIES AND SIMILAR TECHNOLOGIES
We use strictly necessary cookies and similar technologies to operate our website, shopping cart, checkout, customer account features, payment processing, fraud prevention, security, privacy preferences, and core store functionality.
We place or activate non-essential cookies, pixels, tags, analytics technologies, advertising technologies, retargeting technologies, conversion measurement technologies, customer event tools, and similar technologies only after you have given consent through our cookie banner, unless a specific technology is strictly necessary or otherwise permitted by applicable law.
Non-essential technologies may include Google Analytics, Google Ads and Google tag, Meta Pixel and related Meta conversion tools, Pinterest Tag and related Pinterest conversion tools, TikTok Pixel and related TikTok event tools, Shopify or Shop marketing and analytics features, and app-related technologies connected to loyalty, wishlist, stock notification, or advertising features.
Continued browsing, scrolling, or inactivity does not count as consent. You can accept or refuse non-essential cookies by purpose, and you can withdraw or change your choices at any time through the cookie settings link on our website. If you refuse or withdraw consent, we will not intentionally load non-essential analytics or advertising technologies for you, although strictly necessary technologies may still operate.
You can also manage certain advertising and privacy preferences directly through your browser and through the privacy settings offered by platforms such as Google, Meta, Pinterest, TikTok, Shopify, and Shop.
MARKETING, ADVERTISING, AND PROFILING
We may use personal data to send marketing emails, display ads, measure ad performance, build or exclude advertising audiences, understand campaign performance, and show more relevant products or content, but only where we have an appropriate legal basis and, where required, your consent.
Advertising and analytics tools may create or use profiles based on browsing behaviour, product interest, cart activity, purchase events, campaign interactions, and similar data. These profiles are used for marketing measurement, audience segmentation, retargeting, and campaign optimisation. We do not use this profiling to make decisions that produce legal effects or similarly significant effects concerning you.
You can unsubscribe from marketing emails at any time by using the unsubscribe link in the message or by contacting us at vera@veralumin.com. You can also change your cookie and advertising preferences through the cookie settings link on our website.
GOOGLE BUSINESS PROFILE, SOCIAL MEDIA, AND THIRD-PARTY PLATFORMS
If you interact with Vera Lumin through Google Business Profile, Google Search, Google Maps, Instagram, Facebook, Pinterest, TikTok, YouTube, Shop, or another third-party platform, that platform may process your personal data under its own privacy notice and account settings. This may include your profile name, username, review or comment content, messages, likes, follows, shares, tags, photos, videos, call or direction interactions, ad interactions, and other platform activity.
We process the information we receive or can access from those platforms to respond to you, manage our business presence, handle customer service, moderate inappropriate content where possible, understand performance, and improve our products and communications.
WHEN PERSONAL DATA IS REQUIRED
Certain personal data is required to place and fulfil an order, process payment, issue invoices, deliver products, handle returns, comply with tax and accounting obligations, and provide customer service. If you do not provide required information, we may not be able to complete your order or provide the requested service. Personal data used for marketing, non-essential analytics, advertising, wishlist features, loyalty features, back-in-stock notifications, and similar optional features is generally optional, but some features may not work without the data needed to provide them.
INTERNATIONAL TRANSFERS
Some of our service providers and connected platforms may process personal data outside the European Economic Area, the United Kingdom, or Switzerland, including in the United States or other countries that may have different data protection laws.
Where required, we rely on an adequacy decision or appropriate safeguards, such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum or equivalent safeguards, and supplementary measures where required. You may request further information about those safeguards by contacting us.
RETENTION
We retain personal data only for as long as necessary for the purposes for which it was collected, unless a longer retention period is required or permitted by law.
- Order, invoice, tax, customs, and accounting records are generally retained for 7 years, or longer where required by law or necessary for legal claims.
- Account data is retained while your account remains active and for a reasonable period thereafter, unless deletion is required earlier by law or by a valid request.
- Vera Privé loyalty data is retained while your membership remains active and for a reasonable period thereafter to administer rewards, tier status, customer support, and legal claims, unless deletion is required earlier by law.
- Wishlist data is retained while your wishlist or account remains active, or until you remove wishlist items, delete your account, or request deletion, subject to legal or technical retention requirements.
- Back-in-stock, pre-order, and waitlist notification data is retained until the notification is sent, the request expires, you withdraw your request, or the data is no longer needed for the feature, unless a longer period is needed for legal, fraud-prevention, or accounting purposes.
- Customer service, return, complaint, and non-conformity records are retained for as long as necessary to handle the matter and for a reasonable period afterwards to manage follow-up requests, legal claims, or compliance obligations.
- Marketing subscription and unsubscribe records are retained for as long as necessary to manage your preferences, prevent unwanted marketing, and demonstrate compliance.
- Consent records and cookie preference records are retained for as long as necessary to demonstrate and manage your choices.
- Analytics, advertising, pixel, and platform event data is retained according to our settings, the applicable cookie duration, and the retention settings of the relevant platform or provider.
SECURITY
We use appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure. These measures include using reputable ecommerce, payment, hosting, app, and logistics providers, restricting access to personal data, and using security features available within Shopify and our connected services. No method of transmission or storage is completely secure, but we take reasonable steps to protect personal data.
AUTOMATED DECISION-MAKING
We do not make decisions based solely on automated processing that produce legal effects or similarly significant effects concerning you. Fraud-prevention, payment, or security tools may automatically flag certain transactions or activity for review, but important decisions are not made solely by automated means where this would have a legal or similarly significant effect on you.
CHILDREN
Our website and products are not intended for children. We do not knowingly collect personal data from children under 16. If you believe that a child has provided personal data to us, please contact us so that we can take appropriate steps.
YOUR RIGHTS
Subject to applicable law, you may have the right to request access to your personal data, rectification, erasure, restriction of processing, objection to processing, and data portability.
You also have the right to object at any time to processing for direct marketing purposes, including related profiling. Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.
To exercise your rights, please contact vera@veralumin.com. We may need to verify your identity before responding to a request. We will respond within the period required by applicable law.
Some personal data may also be controlled by third-party platforms such as Shopify, Shop, Google, Meta, Pinterest, TikTok, Instagram, Facebook, or Google Business Profile. You may also be able to exercise privacy rights directly through those platforms' account settings, privacy tools, or support channels.
COMPLAINTS
If you have a complaint about how we process personal data, please contact us first at vera@veralumin.com. You also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens, or with the supervisory authority in your country of residence or place of work.
CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect changes in our business, website, apps, sales channels, advertising tools, analytics tools, service providers, or legal requirements. The latest version will always be available on this page and will show the date of the most recent revision.