Skip to content
PromptBuddie

Template — to be reviewed before launch

This text is a template that has not yet been reviewed by a legal professional. It will be checked and completed before the shop launches.

Legal

Privacy statement

What personal data we process, why, how long we keep it and what your rights are.

Last updated: 29 September 2026

This privacy statement explains which personal data PromptBuddie processes when you visit our website, place an order, sign up for our newsletter or waitlist, submit a withdrawal request or contact us. We only process the data we actually need, keep it for no longer than necessary and never sell it.

1. Who is responsible for your data

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Company name
[company name — to be completed]
Trading as
PromptBuddie
Visiting and return address
[address — to be completed]
Email
[email address — to be completed]
Phone
[phone number — to be completed]
Chamber of Commerce (KvK)
[Chamber of Commerce (KvK) number — to be completed]
VAT number
[VAT number — to be completed]

For any question about privacy or your personal data, e-mail us at [email address — to be completed] or use our contact page.

2. Which personal data we process

Orders

  • E-mail address, name and shipping address.
  • Telephone number, only if you choose to provide it (optional, used by us or the carrier for delivery questions).
  • Order contents, order number, amounts, VAT and order and shipping status.
  • Payment status and a payment reference. Payments are processed by our payment service provider Mollie. We never see or store your card details or bank credentials.

Newsletter and waitlist

  • E-mail address and preferred language.
  • For the waitlist: the product you want to be notified about.
  • The status of your subscription and the dates on which you signed up, confirmed (double opt-in) and, if applicable, unsubscribed.

Withdrawal requests

  • Name, e-mail address, order number and the items you want to return.
  • Your reason for withdrawing, only if you choose to give one (always optional).
  • The date and time of your request and the reference number we assign to it.

Contact messages

  • Name, e-mail address, order number (optional) and the content of your message.

Technical data

  • A keyed hash (HMAC) of your IP address, used for rate limiting, to limit vote abuse and to prevent abuse of our forms and checkout. Your IP address is never stored in raw form.
  • A random, anonymous voter identifier in the pb_voter cookie when you take part in a community vote. On our servers we only store a keyed hash (HMAC) of it, to make sure each person votes only once.
  • Data needed for bot protection by Cloudflare Turnstile when you submit a form (for example browser and device signals). This check is used only to tell humans from automated abuse.

4. Who receives your data

We do not sell your personal data and do not share it with third parties for their own marketing. We use the following service providers, who process data on our behalf as processors under a data processing agreement, unless stated otherwise:

Supabase
Database, authentication and file storage, hosted in the EU region.
Vercel
Hosting and content delivery of our website.
Mollie
Payment service provider for iDEAL, Bancontact, cards, Apple Pay and other payment methods. For the payment itself Mollie may act as an independent controller, subject to its own privacy statement and its obligations as a regulated payment institution.
Resend
Sending transactional e-mails such as order confirmations, confirmation links and withdrawal acknowledgements.
Cloudflare
Turnstile bot protection on our forms.
Postal carrier
Delivery of your parcel. The carrier receives your name, shipping address and, if provided, your telephone number or e-mail address for delivery notifications.

We may also disclose personal data if we are legally required to do so, for example to the Dutch Tax Administration or on the basis of a court order.

5. Transfers outside the EEA

We prefer service providers that store data within the European Economic Area (EEA). Some of our providers are based in the United States or use sub-processors outside the EEA. In those cases personal data is only transferred with appropriate safeguards, such as certification under the EU-US Data Privacy Framework or the European Commission's Standard Contractual Clauses, supplemented where necessary with additional measures. You can contact us for more information about these safeguards.

6. How long we keep your data

  • Orders, invoices and related payment data: seven years after the end of the financial year, because of the statutory tax retention obligation.
  • Newsletter: until you unsubscribe. After unsubscribing we only keep a record of your e-mail address and the fact that you unsubscribed, so we can respect your choice and prove it.
  • Sign-ups that are never confirmed (double opt-in): deleted periodically.
  • Waitlist: until we have notified you that the product is available, or earlier if you withdraw your consent.
  • Withdrawal requests: as part of the records of the order concerned, so for the same period as the order.
  • Contact messages: as long as necessary to handle your question, and no longer than two years, unless the message is part of an order record.
  • Rate-limiting hashes: short-lived, deleted automatically after the relevant time window has passed.
  • Vote records (keyed hashes of the voter ID and IP address only): for as long as the vote round and its results are online, after which they are deleted.

7. No automated decision-making or profiling

We do not make decisions based solely on automated processing that have legal effects for you or similarly significantly affect you, and we do not create profiles of you. Automated bot protection and rate limiting only block technical abuse; if you believe you were blocked by mistake, please contact us.

8. Security

We take appropriate technical and organisational measures to protect your personal data against loss and unlawful processing, including:

  • Encryption of all connections (HTTPS/TLS).
  • Strict access control: only authorised staff can access customer data, and the database enforces row-level security.
  • Confirmation, unsubscribe and order-access links contain random tokens that we only store in hashed form.
  • Identifiers such as IP addresses and voter IDs are only stored as keyed hashes.
  • Least-privilege access for our systems and service providers.

If a data breach nevertheless occurs that is likely to pose a risk to you, we will notify the Autoriteit Persoonsgegevens and, where required, you.

9. Your rights

Under the GDPR you have the following rights:

  • Right of access: you can ask which personal data we process about you.
  • Right to rectification: you can have incorrect or incomplete data corrected.
  • Right to erasure: you can ask us to delete your data, unless we are required to keep it (for example for tax purposes).
  • Right to restriction of processing.
  • Right to data portability: you can receive the data you provided to us in a structured, machine-readable format.
  • Right to object to processing based on our legitimate interest.
  • Right to withdraw your consent at any time, for example via the unsubscribe link in our e-mails.

To exercise your rights, e-mail [email address — to be completed] or use our contact page. We will respond within one month. We may ask you to verify your identity before we act on your request, to prevent your data from ending up with someone else.

10. Complaints

Do you have a complaint about how we handle your personal data? Please contact us first, we will gladly look for a solution together. You also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens, or with the supervisory authority in the EU country where you live.

11. Cookies and local storage

We only use cookies and similar technologies that are strictly necessary for the website to work:

pb-cart-v1 (localStorage)
The contents of your shopping cart, kept in your browser's localStorage. This data stays on your device and is not sent to us until you check out.
pb_voter (cookie)
A functional, signed, httpOnly cookie with a random anonymous identifier (SameSite=Lax, valid for 1 year). It is used only to enforce one vote per person in community votes. On our servers we only store a keyed hash (HMAC) of it; it contains no name, e-mail address or other personal details.
pb_voted:<round> (localStorage)
Remembers on your device which concept you voted for in a vote round, so the page can show your choice.
Admin session cookies
Supabase Auth session cookies, only for our staff when logged in to the shop management environment. They are never set for customers.
Cloudflare Turnstile
May store technical data that is strictly necessary for bot protection when you submit a form.

We do not use tracking, marketing or advertising cookies, and we do not place third-party trackers or pixels. We only use cookieless, aggregated first-party statistics that cannot identify you. Because we only use strictly necessary cookies, no cookie consent banner is required.

12. Children

Our products are toys, but our shop is aimed at adults. Orders must be placed by an adult, for example a parent or guardian. Children under 16 may not sign up for our newsletter or waitlist without the consent of a parent or guardian. We do not knowingly process personal data of children under 16. If you believe we have done so, please contact us and we will delete the data.

13. Changes to this privacy statement

We may update this privacy statement, for example when our services or the law change. The most recent version is always published on this page, with the date of the last update at the top. If a change significantly affects you, we will inform you in advance where possible.