Legal
Privacy policy
We collect as little as we can. What we do need is set out here: what, why, for how long, and what you can do about it.
Last updated on 21 September 2026
1. Who is responsible
The business below is the data controller for the data processed through this website. If you want to ask something about your data, email is the fastest channel.
- Name
- Cord & Collar
2. What data we process
If you order something, we process your name, delivery address, email address and the details of your order. Your payment details go straight to the payment provider: they never reach us and we do not store them.
If you personalise an item, we also process your dog's name and the neck size you give us. Those two travel along with your order line to the workshop as an attribute, because without them we cannot make the product.
If you email us, we process your message and your email address so that we can reply.
We also keep anonymous visitor figures: which pages are visited, and from what kind of device. That measurement works without cookies and without profiles, and cannot identify an individual visitor.
We process no special categories of personal data, and the shop is not aimed at children under sixteen.
3. Why, and on what legal basis
To carry out your order and keep you informed about it. Basis: performance of the contract with you.
To answer your questions and complaints. Basis: performance of the contract, or our legitimate interest in a working customer service.
To keep our books and retain invoices. Basis: the statutory obligation under tax law.
To see how the shop is used and to improve it. Basis: our legitimate interest in a website that works, weighed against your privacy — which is exactly why that measurement is anonymous.
We do not use your data for automated decision-making or profiling, and we sell it to no one.
4. Who we share it with
We rely on a handful of parties that process data on our behalf. We have a processing agreement with each of them, and they may only use the data for what we instruct them to do.
Beyond that, we share data where the law requires it — with the Dutch tax authority, for instance.
- Shopify International Ltd.
- Shop software, checkout and order processing.Processed in: IE / CA / USPrivacy policy
- Vercel Inc.
- Hosting of this website and anonymous visitor statistics.Processed in: US / EUPrivacy policy
5. Transfers outside the European Economic Area
Shopify and Vercel are non-European in origin, with establishments in the EU. In so far as data is processed outside the European Economic Area, that happens on the basis of the European Commission's standard contractual clauses or of a valid adequacy decision.
Where we have a choice, we choose processing within the EU.
6. How long we keep it
We keep order data and invoices for seven years. That is not our choice: the statutory retention period under tax law prescribes it.
We keep email correspondence for as long as it takes to deal with your question, and for at most two years after that, so we can find an earlier exchange.
The shopping bag expires on its own. The cookie policy states the exact period.
Anonymous visitor statistics cannot be traced back to you and therefore carry no retention period for personal data.
7. Your rights
You may see your data, have it corrected, or have it erased. You may have the processing restricted, object to processing based on a legitimate interest, and receive your data in a common file format so you can take it elsewhere.
Send an email saying what you want. You will hear from us within a month. To avoid handing data to the wrong person, we may ask for extra information that lets us establish it is really you.
Some data we are not allowed to erase while the statutory tax retention period runs. We will then tell you what stays and why.
If you disagree with how we handle your data, you can complain to the Dutch Data Protection Authority. You are free to do that at any time — though we would rather hear it from you first, while we can still put it right.
8. Security
The website runs entirely over an encrypted connection. The shopping bag is tracked with a cookie only the server can read, holding nothing but an internal reference.
Checkout happens in Shopify's environment, which is PCI-DSS compliant for that purpose. We store no payment details ourselves.
If you suspect a leak or a vulnerability, report it by email. We take such reports seriously and you will get an answer.
9. Changes
If the way we handle data changes, we amend this statement. The date at the top shows when that last happened.
Contact
A question this page doesn't answer
Send us a message with your order number and we'll look into it.
Terms & conditionsCookie policyRight of withdrawalDisclaimerContact