Privacy policy

Last updated: 2026-10-03

Who is responsible for your data

DimpleMark, registered with the Dutch Chamber of Commerce under number 42163832, at Drostenburg 12, 1102 AM Amsterdam, The Netherlands, is the data controller for everything described on this page.

For any question about your data, or to exercise any of the rights below, write to hello@dimplemark.com.

What we collect, and why

When you place an order: your email address and shipping address, collected by our payment provider and passed to us, so we can make and send your stamp. The legal basis is performance of the contract between us. We need both, and a design to cut: without them there is no order we can fulfil, which is the only reason we ask.

Your stamp design, and any image you upload for it. This is what we cut, so we cannot make your order without it. It can contain your name or initials, so we treat it as personal data. The legal basis is performance of the contract.

If you ask to be told when shipping opens to your country: your email address and the country you named, kept only to answer that question. The legal basis is your consent, which you give by ticking the box on that form and can withdraw at any time by writing to us.

When you write to us: your email address and whatever you put in the message, kept so we can answer you and sort out any problem with your order. Where it concerns an order the legal basis is performance of the contract, and otherwise it is our legitimate interest in answering people who contact us.

Your language preference, stored in your own browser so the site does not switch language on you. This never reaches our servers and is not used to identify you.

Cookies and measurement

We use no advertising or tracking cookies, and nothing here follows you to another site. There is no cookie banner because nothing we or our providers store on your device needs your permission. Two things are stored all the same, and you should know about both.

The only thing this site stores in your browser is your chosen language. That is necessary for a feature you asked for, and it is not shared with anyone.

Our security and hosting provider, Cloudflare, sets a small number of strictly necessary cookies to tell real visitors from automated traffic and to keep the site available. The usual one is called __cf_bm, and Cloudflare may set others when it is defending the site. They carry no advertising or profiling purpose, they are not read by us, and under the ePrivacy rules they need no consent, but you should know they exist. Cloudflare publishes the current list and what each one does at developers.cloudflare.com, and that list is authoritative rather than anything we could copy here and keep true.

We count visits, using Cloudflare Web Analytics. A small script from Cloudflare runs when a page loads and reports the page you opened, the address you arrived from, your approximate country, and how quickly the page rendered. It sets no cookie, writes nothing to your device, and assigns you no identifier, so there is nothing to recognise you by on your next visit or on any other site. That is how Cloudflare documents the product, and it is why this site needs no cookie banner. We see only totals, never a trail belonging to one person.

That script also reads the tracking tags we put in our own links, so that when we post about the shop we can tell which post brought people here. The tag is written by us into the link you clicked. It says nothing about you.

We use this to understand whether the site works and whether anybody is finding it, on the basis of our legitimate interest under Article 6(1)(f). If you would rather not be counted, any content blocker that blocks cloudflareinsights.com will stop the script, and the site will work exactly as before.

We can also see how many people visit from the server records Cloudflare keeps in order to serve the page at all. That is not something placed on your device.

Our fonts are served from this site, not from a third party content network, so loading a page does not reveal your address to anyone but us and Cloudflare.

Who else sees your data

These are the service providers that receive your personal data. Each of them acts on our instructions and may not use your data for their own purposes, with one exception we set out below.

Stripe. Payment processing. Receives your name, email address and shipping address. Privacy policy: https://stripe.com/privacy

Resend. Sending your order confirmation. Receives your email address and order details. Privacy policy: https://resend.com/legal/privacy-policy

Cloudflare. Hosting the site, storing your order and your artwork, and protecting the site from automated traffic. Their server records tell us how many people visit, and their cookieless measurement script, which sets nothing on your device and does not identify you, tells us which pages are read and which link brought you here. Privacy policy: https://www.cloudflare.com/privacypolicy/

Stripe is the exception. For payments it also acts as a controller in its own right, because preventing fraud and meeting its own legal obligations as a payment institution are purposes it decides on, not ones we set. For those purposes its own privacy policy governs, not this one.

Any of these providers may process your data outside the European Economic Area, in the United States in particular. Where that happens we rely on a transfer mechanism approved under Chapter V of the GDPR: an adequacy decision, which for the United States means the EU-US Data Privacy Framework, or the European Commission's standard contractual clauses. Which one applies depends on the provider and on what they have certified, so write to us and we will tell you what covers a given one rather than guess at it here.

We never sell your data, and we never share it for advertising.

How long we keep it

Your uploaded artwork and your design are deleted 12 months after your order, automatically. We do not keep them longer in case you reorder: a new order means uploading again.

Your invoice record is kept for 7 years. Dutch tax law requires this and we have no choice about it, so the legal basis here is compliance with a legal obligation under Article 6(1)(c) rather than anything we decided. It covers the accounting record itself, not everything we ever held about you. After that period it is deleted too.

Your email address and shipping address are part of that order record and are kept for the same 7 years, unless you ask us to erase them sooner.

If you asked to be told when shipping opens to your country, we keep your address until we have told you, or until you ask us to remove it, whichever comes first. If shipping has not opened to your country within two years we delete it and start again rather than hold it indefinitely.

If you write to us, we keep the correspondence for as long as it takes to settle what you wrote about, and normally for up to two years afterwards in case the same question comes back. Longer only where we need it to establish, exercise or defend a legal claim, or where some other law tells us to keep it.

Cloudflare keeps its server records for a short period of its own, and its visit measurement is aggregated rather than stored against you. Neither is something we can look up by name.

If you ask us to erase your data before those periods are up, see the next section for exactly what happens.

Your rights

You have the right to ask what we hold about you, to correct it, to have it erased, to object to how we use it, and to ask us to restrict how we use it while a question about it is being settled. Write to us and we will answer within one month.

You can also ask for a copy of the data you gave us in a structured, machine-readable form, and ask us to send it to another company where that is technically possible. This one is narrower than the others: it covers the data you provided, handled automatically, where we rely on your consent or on our contract with you. In practice that is your order details and your design, not our own notes about an order.

Where we rely on your consent, which is only for the shipping notification list, you can withdraw it at any time by writing to us. Withdrawing it does not make what we did beforehand unlawful.

We do not make any automated decisions about you, and we do not profile you.

On an erasure request we delete what we are not required to keep, and we do it straight away rather than at the next convenient moment. In practice that means your email address, your shipping address, your design and your uploaded artwork. Where a provider holds a copy on our behalf we instruct them to delete it too, so far as their own legal obligations allow.

Two things survive an erasure request, and we would rather say so plainly than surprise you later. The accounting record of your order stays for as long as Dutch tax law requires, because Article 17(3)(b) of the GDPR gives way to a legal obligation, but no name, address or email remains attached to it. Stripe keeps its own record of the transaction under the financial and anti-money-laundering rules it is subject to, and that copy is not ours to erase. We will tell you the date the rest is deleted.

We may also keep something longer where we need it to establish, exercise or defend a legal claim. That is the exception in Article 17(3)(e), and we would tell you if it applied to you.

Please note that erasing your design means your order cannot be reprinted afterwards.

If you think we have handled your data wrongly, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, at autoriteitpersoonsgegevens.nl. We would rather you told us first so we can put it right.

DimpleMark Drostenburg 12, 1102 AM Amsterdam, The Netherlands KvK number: 42163832 VAT number: NL005546963B08 Email: hello@dimplemark.com Telephone: +31 85 369 7812