Privacy Policy
Privacy Policy
1. Who we are (controller)
This website (ivandouwes.nl) is operated by Ivan Douwes, a contemporary artist based in the Netherlands. For privacy matters, Ivan Douwes is the data controller.
Contact: use our contact form (Send an email).
2. Scope
This policy explains how we process personal data when you browse the site, use the contact form, or purchase original artworks or prints. We ship within the EU/EEA and to selected international destinations. We do not sell personal data and we do not run advertising or analytics trackers on this site.
3. What data we process and why
Browser storage (localStorage) on our site. The following is stored only in your browser and is not sent to our servers as a user profile:
- Collection contents (items, options, quantities)
- Language preference (English, Dutch, German, or Austrian German)
- Currency display preference
- Theme preference (light or dark)
- Whether you have dismissed the storage notice
This storage is strictly necessary for basic site functions (collection, language, display preferences). We do not use it for advertising or cross-site tracking.
Orders and payments. Checkout and card payments are handled by Stripe. On Stripe’s payment page, Stripe collects payment details, your name, email address, billing information, and delivery address. We never receive or store your full card number. After a successful payment, our server receives a signed webhook from Stripe with order details needed for fulfilment: name, email, shipping address, amounts, and a summary of items ordered. We keep that information in a private order log (outside the public website) and send a fulfilment notification to our studio inbox. Public “sold” status for original works does not include your contact details.
Shipping. Your delivery name and address are used to pack and ship your order. We share shipping details with the carrier(s) we use to deliver the work, and only for that purpose.
Contact form. If you send a message, your name, email address, and message are submitted through Formspree and forwarded to us by email so we can reply. Formspree processes the submission as a service provider; its privacy policy also applies to that step.
Server and security logs. Our hosting environment may log technical data such as IP address, time, requested URL, and browser user-agent for security, abuse prevention, and reliability. These logs are not used for marketing.
Fonts. Typefaces are self-hosted with the website. Your browser does not need to contact Google Fonts (or similar third-party font CDNs) to render this site.
Offline / installable site. Older versions of the site may have registered a service worker for caching. The current site does not rely on offline install for core shopping. You can clear site data in your browser settings at any time.
What we do not do. We do not use third-party advertising cookies, marketing pixels, or analytics products (such as Google Analytics) on this website. We do not build marketing profiles from your browsing.
4. Legal bases (GDPR / AVG)
- Contract (Art. 6(1)(b)) — processing order, payment-related, and shipping data to sell and deliver artworks you purchase
- Legal obligation (Art. 6(1)(c)) — retaining business and tax records of sales as required under Dutch law
- Consent (Art. 6(1)(a)) — processing contact-form messages you choose to send; you may withdraw consent by asking us to delete the correspondence (we will still need to keep anything we must retain by law)
- Legitimate interests (Art. 6(1)(f)) — keeping the site secure and reliable (server logs), and using strictly necessary browser storage for collection and preferences; you may object where applicable
5. Who receives your data
We only share personal data with parties that need it to run the shop, host the site, or deliver your order:
- Stripe (privacy policy) — payment and checkout (including billing/shipping address collection on their pages)
- Formspree (privacy policy) — delivery of contact-form messages
- (Fonts) — typefaces are self-hosted; we do not use Google Fonts on the current site
- Google (Gmail) (privacy policy) — studio inbox for order notifications and contact messages forwarded by email
- Hosting provider — operates the servers that run this website and related logs
- Shipping carriers / fulfilment partners — name and delivery address (and contact details if needed for delivery) when we ship your order
Some providers are located in, or process data in, countries outside the European Economic Area (including the United States). Where personal data is transferred outside the EEA, transfers rely on appropriate safeguards such as the EU–US Data Privacy Framework (where a provider is certified) and/or Standard Contractual Clauses, together with the provider’s own compliance measures.
6. Cookies and similar technologies
On our domain we do not set tracking, advertising, or analytics cookies. Preferences and collection state use localStorage (see section 3), not marketing cookies.
When you go to Stripe Checkout to pay, you leave our checkout flow for Stripe’s pages, which may use cookies and similar technologies under Stripe’s policy. Submitting the contact form involves Formspree’s service, which may set its own cookies under Formspree’s policy. Those technologies are controlled by those providers, not by us.
7. How long we keep data
- Order and fulfilment records — retained for as long as needed to fulfil the order and for our legal/tax administration (typically up to 7 years under Dutch record-keeping rules), then deleted or anonymised where feasible
- Contact messages — kept only as long as needed to handle your enquiry and any follow-up, then deleted from active mailboxes/tools we control (copies may remain in automated email backups for a limited period)
- Server logs — retained for a limited operational period for security and troubleshooting, then rotated or deleted according to hosting practice
- Browser storage — remains on your device until you clear site data or remove it in your browser settings
8. Security
We use HTTPS for the website, keep payment card data with Stripe (PCI-compliant payment provider), store fulfilment logs outside the public web root, and limit access to order information to what is needed to run the studio. No method of transmission or storage is perfectly secure; if you believe there has been a data incident affecting you, contact us promptly.
9. Your rights
Under the GDPR (AVG), you have rights regarding personal data we hold about you, including:
- Access — obtain confirmation and a copy of your data
- Rectification — correct inaccurate data
- Erasure — request deletion, subject to legal retention duties (for example tax records of sales)
- Restriction — request that we limit processing in certain cases
- Portability — receive data you provided in a structured, commonly used format, where applicable
- Objection — object to processing based on legitimate interests
- Withdraw consent — where processing is based on consent (for example contact messages), without affecting prior lawful processing
To exercise these rights, send a message via the contact form. We will respond without undue delay and within one month (extendable where the law allows for complex requests). You may also lodge a complaint with the Dutch Data Protection Authority: Autoriteit Persoonsgegevens.
10. Children
This shop is aimed at adults. We do not knowingly collect personal data from children for marketing. If you believe a child has provided personal data through the contact form or an order, contact us and we will delete it where we are not required to keep it.
11. Changes to this policy
We may update this policy when our practices or legal requirements change. The “Last updated” date at the top will change when we do. The current version always applies to new use of the site; for significant changes affecting ongoing processing we will take additional steps where required by law.