Privacy policy

Van Den Broek Life

Effective 8 March 2026

What this means for you

  • We collect data to process your orders, operate our website, and send you relevant communications.
  • We use cookies. You can manage your preferences at any time via the cookie banner on our website.
  • We work with trusted third-party services. A full list with details is in this policy.
  • We do not sell your personal data to third parties.
  • You have rights over your data — access, correction, deletion, portability, and objection.
  • Questions: info@vandenbroeklife.com

1Who We Are

Van Den Broek Life B.V. is the data controller responsible for processing your personal data in connection with this website and webshop.

Van Den Broek Life B.V.
Albert Glasstraat 3, 2082 EC Santpoort-Zuid, Netherlands
info@vandenbroeklife.com  ·  +31 6 15 91 78 04

The Dutch supervisory authority for data protection is the Autoriteit Persoonsgegevens (AP). You have the right to lodge a complaint with the AP at any time: autoriteitpersoonsgegevens.nl, +31 88 180 52 50.

2What Data We Collect and Why

Order and transaction data

When you place an order we collect your name, delivery address, email address, telephone number, order contents, and payment method. We do not store full card details — these are processed directly by our payment providers. Legal basis: Art. 6(1)(b) GDPR — necessary for contract performance. Retention: 7 years in accordance with Dutch tax law.

Account data

If you create an account we store your name, email address, order history, and loyalty points balance. Legal basis: Art. 6(1)(b) GDPR — necessary for contract performance. Retention: duration of your account plus 1 year after last activity.

Browsing and behaviour data

When you visit our website, technical data is collected automatically including your IP address, browser type, device type, pages visited, and time spent on pages. This data is used to operate the website, analyse usage, and improve our marketing. Legal basis: Art. 6(1)(f) GDPR for strictly necessary cookies; Art. 6(1)(a) GDPR for all non-necessary cookies (your consent). Retention: as set out in the cookie tables in Article 4.

Communications data

When you contact us by email, contact form, or WhatsApp, we store the content of your message and your contact details for the purpose of handling your inquiry. Legal basis: Art. 6(1)(b) GDPR where related to an order; Art. 6(1)(f) GDPR for general inquiries. Retention: duration of our relationship plus 2 years.

Marketing data

If you subscribe to our newsletter or SMS communications, we store your email address and/or phone number and your communication preferences. Legal basis: Art. 6(1)(a) GDPR — your consent. You can unsubscribe at any time via the link in any email or by contacting us directly.

We do not process any special categories of personal data such as health data, biometric data, or data revealing racial or ethnic origin.

Data transmitted over the internet cannot be guaranteed to be fully secure. We use SSL/TLS encryption across all pages of this website, indicated by "https://" in your browser address bar.

3Hosting and Infrastructure

Shopify

Our website and webshop are hosted by Shopify International Ltd., 2nd Floor Victoria Buildings, 1-2 Haddington Road, Dublin 4, Ireland. Personal data collected on this website — including IP addresses, order data, contact details, and browsing data — is stored on Shopify's servers. For EU residents, data is processed and stored in Ireland. Shopify may also transfer data to Canada and the United States under Standard Contractual Clauses (SCCs) approved by the European Commission. Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR. Shopify Privacy Policy.

Cloudflare

We use Cloudflare, Inc. for website performance and security, including DDoS protection and content delivery. Cloudflare processes IP addresses and request metadata. Data may be transferred to the United States under SCCs. Legal basis: Art. 6(1)(f) GDPR. Cloudflare Privacy Policy.

Server log files

Our hosting infrastructure automatically collects server log data including browser type, operating system, referring URL, IP address, and time of request. This data is used solely for technical operation and security of the website and is not combined with other data sources. Legal basis: Art. 6(1)(f) GDPR.

4Cookies and Consent

We use cookies and similar tracking technologies on this website. Cookies are small data files stored on your device. We use Cookiebot by Usercentrics (Domain Group ID: 27449b8e-3530-4292-87cd-6058a74f8a1d) as our consent management platform. You can view, change, or withdraw your consent at any time by clicking the cookie settings button at the bottom of any page on our website.

Cookies are grouped into four categories. Necessary cookies are always active. All other categories require your consent before being set.

Necessary (14 cookies)

These cookies are required for the website to function. They cannot be switched off.

Preferences (2 cookies)

These cookies remember your settings and preferences to improve your experience.

Statistics (9 cookies)

These cookies collect anonymous data to help us understand how visitors use our website.

Marketing (11 cookies)

These cookies are used to show you relevant advertisements and to measure the effectiveness of our marketing campaigns.

Managing your cookie preferences: You can accept, decline, or customise your cookie preferences at any time by clicking the cookie settings button at the bottom of any page. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.

5Analytics and Performance

Google Tag Manager

We use Google Tag Manager provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Tag Manager is a container tool that manages the loading of other tags on our website. It does not independently collect personal data or set cookies. It does collect your IP address, which may be transferred to Google's parent company in the United States under SCCs. Legal basis: Art. 6(1)(a) GDPR.

Google Analytics 4

We use Google Analytics 4 provided by Google Ireland Limited to analyse how visitors use our website. Data collected includes page views, session duration, device and browser type, traffic sources, and e-commerce transactions. This data is aggregated and anonymised where possible. Data is transferred to Google servers in the United States under SCCs. Legal basis: Art. 6(1)(a) GDPR — your consent. You can opt out of Google Analytics tracking by installing the Google Analytics opt-out browser add-on. Google Privacy Policy.

Microsoft Clarity

We use Microsoft Clarity provided by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Clarity records anonymised session replays, heatmaps, and click behaviour to help us understand how visitors interact with our website. Form inputs are masked and no keylogging occurs. Data may be transferred to the United States under SCCs. Legal basis: Art. 6(1)(a) GDPR — your consent. Microsoft Privacy Statement.

6Advertising

Meta Pixel (Facebook and Instagram)

We use the Meta Pixel provided by Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. The Meta Pixel tracks conversions from our Meta advertising campaigns, builds custom audiences for retargeting, and measures the effectiveness of our ads on Facebook and Instagram. Data including browsing behaviour and purchase events may be transferred to Meta's parent company in the United States under SCCs. Legal basis: Art. 6(1)(a) GDPR — your consent. Meta Privacy Policy.

Google Ads and Remarketing

We use Google Ads provided by Google Ireland Limited for conversion tracking and remarketing. Google Ads Conversion Tracking measures which of our advertisements lead to purchases or other desired actions. Google Ads Remarketing allows us to show targeted advertisements to previous visitors of our website across the Google advertising network. We may also use customer matching, which involves uploading email addresses to Google to match with existing Google account holders for targeted advertising. Data is transferred to the United States under SCCs. Legal basis: Art. 6(1)(a) GDPR — your consent. Google Privacy Policy.

Google DoubleClick

Google DoubleClick, operated by Google Ireland Limited, is used for ad serving, frequency capping, and measuring ad performance. Data is transferred to the United States under SCCs. Legal basis: Art. 6(1)(a) GDPR — your consent.

7Email, SMS and Onsite Marketing

Klaviyo

We use Klaviyo, operated by Klaviyo, Inc., 125 Summer Street, Boston, MA 02110, USA, for email newsletters, automated email flows, SMS communications, and onsite behaviour tracking. When you subscribe to our newsletter or place an order, your email address, name, order history, and browsing behaviour on our website may be shared with Klaviyo. Klaviyo uses this data to send communications on our behalf and to help us personalise those communications based on your interests and behaviour. Klaviyo does not use your data to contact you independently or share it with third parties. Data is transferred to the United Kingdom and United States under SCCs. Legal basis: Art. 6(1)(a) GDPR for marketing communications; Art. 6(1)(b) GDPR for transactional order communications. You can unsubscribe from marketing communications at any time via the unsubscribe link in any email. We have concluded a Data Processing Agreement with Klaviyo. Klaviyo Privacy Policy.

8Reviews and Loyalty

Judge.me

We use Judge.me, operated by Judge.me LLC, PO Box 7403, Jackson, Wyoming 83002, USA, to collect and display product reviews. With your consent, we share your email address, order number, and order date with Judge.me so they can send you a review invitation. When you submit a review, your name, email address, and order details are processed by Judge.me to verify that the review relates to a genuine purchase. This processing is carried out on the basis of our legitimate interest in ensuring the authenticity of customer reviews (Art. 6(1)(f) GDPR), except where your consent is required. Data may be transferred to the United States. Judge.me Privacy Policy.

Yotpo / Swell

We use Yotpo, operated by Yotpo Ltd., 400 Lafayette Street, New York, NY 10003, USA, for our customer loyalty programme (Swell). Yotpo processes your name, email address, order history, and points balance to manage your loyalty account and rewards. Data is transferred to the United States under SCCs. Legal basis: Art. 6(1)(b) GDPR — necessary for the loyalty programme. Yotpo Privacy Policy.

9Operational Third Parties

The following third-party services process personal data as part of our day-to-day operations. All are engaged under Data Processing Agreements or equivalent contractual safeguards where required.

Sufio — Invoicing

Sufio, operated by Sufio s.r.o., generates professional invoices for your orders. Your name, address, and order data are processed for this purpose. Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(c) GDPR (legal obligation to issue invoices). Sufio Privacy Policy.

Sendcloud — Shipping

Sendcloud, operated by Sendcloud B.V., Eindhoven, Netherlands, generates shipping labels for your orders. Your name, delivery address, and phone number are shared with Sendcloud and passed to the relevant carrier. Legal basis: Art. 6(1)(b) GDPR. Sendcloud Privacy Policy.

ParcelWill (Parcel Panel) — Order Tracking

ParcelWill provides the order tracking functionality on our website. Your order number and carrier tracking data are processed to display shipment status. Legal basis: Art. 6(1)(b) GDPR. ParcelWill Privacy Policy.

DeliveryMatch — Shipping Method Selection

DeliveryMatch processes your delivery address and order data to present appropriate shipping options at checkout. Legal basis: Art. 6(1)(b) GDPR.

DHL Express Commerce / Post and DHL Shipping

DHL is our primary carrier. Your name, delivery address, and telephone number are shared with DHL for the purpose of delivering your order. Data may be processed in countries outside the EU in accordance with DHL's transfer mechanisms. Legal basis: Art. 6(1)(b) GDPR. DHL Privacy Notice.

Upsell by AMP — Onsite Offers

Upsell by AMP displays product recommendations and upsell offers on our website based on your cart contents and browsing behaviour. No personally identifiable data is shared with this service. Legal basis: Art. 6(1)(f) GDPR — legitimate interest in presenting relevant product offers.

Omi — Onsite Popups and Offers

Omi displays onsite popups and promotional offers. If you submit your email address via an Omi popup, this is shared with our Klaviyo account. Browsing behaviour data is processed to determine when and to whom popups are shown. Legal basis: Art. 6(1)(a) GDPR where an email is submitted; Art. 6(1)(f) GDPR for behavioural triggering.

Langify — Translations

Langify provides translated versions of our website. Langify does not process personal data beyond what is necessary to render the correct language version of a page.

Lifetimely LTV and Profit by AMP — Internal Analytics

Lifetimely processes your order history and customer data to provide us with internal revenue analytics and customer lifetime value reporting. This data is used solely for our internal business analysis and is not shared with third parties. Legal basis: Art. 6(1)(f) GDPR — legitimate interest in understanding business performance.

WhatsApp Business

We use WhatsApp Business, operated by WhatsApp Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland, for customer communication. Messages are end-to-end encrypted. WhatsApp does not have access to message content, but does process metadata including sender, recipient, and timestamp. WhatsApp may share metadata with its parent company Meta Platforms Inc. in the United States. We have concluded a Data Processing Agreement with WhatsApp for Business use. Legal basis: Art. 6(1)(f) GDPR — legitimate interest in providing efficient customer communication. Communication content is retained until you request deletion or the purpose no longer applies. WhatsApp Privacy Policy.

Payment Providers

We offer the following payment methods. When you make a purchase, your payment data is processed directly by the relevant provider under their own terms and privacy policy. We do not store full payment card details.

  • Shopify Payments — Shopify International Ltd., Dublin, Ireland. Privacy Policy.
  • PayPal — PayPal (Europe) S.a.r.l. et Cie, S.C.A., Luxembourg. Privacy Policy.
  • Apple Pay — Apple Inc., Cupertino, CA, USA. Privacy Policy.
  • Google Pay — Google Ireland Limited, Dublin, Ireland. Privacy Policy.
  • American Express — American Express Europe S.A., Frankfurt, Germany. Privacy Policy.
  • Mastercard — Mastercard Europe SA, Waterloo, Belgium. Privacy Policy.
  • Visa — Visa Europe Services Inc., London, United Kingdom. Privacy Policy.

10Your Rights

Under the GDPR you have the following rights in relation to your personal data:

  • Right of access — You can request a copy of the personal data we hold about you.
  • Right to rectification — You can ask us to correct inaccurate or incomplete data.
  • Right to erasure — You can ask us to delete your personal data. This right is subject to our legal retention obligations — for example, we are required to retain invoice and order data for 7 years under Dutch tax law.
  • Right to restriction — You can ask us to limit how we use your data in certain circumstances, for example while a dispute about accuracy is being resolved.
  • Right to data portability — You can request your data in a structured, machine-readable format to transfer to another service, where technically feasible.
  • Right to object — You can object to processing based on our legitimate interest (Art. 6(1)(f) GDPR) at any time. You can also object to the use of your personal data for direct marketing at any time, including profiling related to direct marketing.
  • Right to withdraw consent — Where processing is based on your consent, you can withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

To exercise any of these rights, email us at info@vandenbroeklife.com. We will respond within 30 days. We may ask you to verify your identity before acting on a request.

If you are not satisfied with our response, you have the right to lodge a complaint with the Autoriteit Persoonsgegevens (AP):
autoriteitpersoonsgegevens.nl  ·  +31 88 180 52 50

You also have the right to use the European Commission's Online Dispute Resolution platform: ec.europa.eu/consumers/odr.