PRIVACY POLICY

La Bottega by Chiara's Food  |  chiarasfood.nl

Last updated: April 2026

1. Who We Are

This website is operated by VOF Chiara's Food, trading as La Bottega by Chiara's Food.

Legal name: VOF Chiara's Food

Trading name: La Bottega by Chiara's Food

Address: Van Woustraat 201, 1074AN Amsterdam, Netherlands

KVK: 83454632

BTW: NL862880543B01

Email: chiara@chiarasfood.nl

Phone: +31 06 50 44 88 68

We are the data controller for the personal data processed through this website and our related services.


2. What Personal Data We Collect

2.1 Data you provide directly

When you place an order or create an account, we collect:

  • Full name

  • Email address

  • Billing and shipping address

  • Phone number

  • Payment information (processed securely by our payment providers; we do not store card details)

When you sign up for our newsletter or contact us, we collect your email address and any information you choose to share with us.

2.2 Data collected automatically

When you visit our website, we may automatically collect the following, subject to your cookie consent:

  • IP address and approximate location

  • Browser type and version

  • Pages viewed and time spent on the site

  • Referring website or search terms

  • Device and operating system information

This data is collected through cookies, log files, web beacons, tags, and pixels. Please see Section 5 (Cookies) for full details.


3. Legal Bases for Processing (GDPR Art. 6)

We only process your personal data when we have a valid legal basis. The table below sets out the purposes for which we process your data and the corresponding legal basis.

Processing purpose

Fulfilling your order: Processing your purchase, payment, shipping, and sending order confirmations — Legal basis: Contract (Art. 6.1.b GDPR)

Account management: Creating and managing your customer account — Legal basis: Contract (Art. 6.1.b GDPR)

Email marketing: Sending you newsletters and promotional communications — Legal basis: Consent (Art. 6.1.a GDPR). You can withdraw consent at any time by clicking 'unsubscribe' in any email.

Fraud prevention: Screening orders for potential risk or fraud — Legal basis: Legitimate interest (Art. 6.1.f GDPR). Our legitimate interest is to protect the business and our customers from fraudulent activity.

Website analytics: Understanding how visitors use our site to improve it — Legal basis: Consent (Art. 6.1.a GDPR), collected via our cookie consent tool.

Legal compliance: Retaining financial records and responding to legal requests — Legal basis: Legal obligation (Art. 6.1.c GDPR).


4. Who We Share Your Data With

We do not sell your personal data. We share your data with third-party service providers only to the extent necessary to operate our business. These include:

  • Shopify Inc. — our e-commerce platform (order processing, payments, store management)

  • Shopify Email — our email marketing tool

  • Google LLC — website analytics (Google Analytics)

  • Consentmo — cookie consent management

  • Payment providers (e.g. iDEAL, Klarna, Stripe) — secure payment processing

  • Shipping and logistics partners — fulfilment of your orders

  • Other third-party tools we use from time to time for operations, marketing, or customer communication

We may also disclose your data when required by law, court order, or to protect our legal rights.

All third-party processors are required to handle your data in accordance with applicable data protection law and our instructions.


5. International Data Transfers

Some of our service providers are based outside the European Economic Area (EEA). Where your data is transferred to a country that does not have an adequacy decision from the European Commission, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission under Art. 46 GDPR.

  • Shopify Inc. is based in Canada, which benefits from an adequacy decision by the European Commission.

  • Google LLC is based in the United States. Data transfers are covered by Standard Contractual Clauses and the EU-US Data Privacy Framework.

You can request further information about the specific safeguards in place by contacting us at chiara@chiarasfood.nl.


6. How Long We Keep Your Data

Order data: We retain order information for 7 years to comply with Dutch tax and accounting obligations (Belastingdienst requirements).

Customer account data: Retained for as long as your account is active. If you request account deletion, we will delete your data within 30 days, except where retention is required by law.

Email marketing data: Retained until you unsubscribe or request deletion.

Analytics data: Google Analytics data is retained for 26 months (configured in our Google Analytics settings). Aggregated and anonymised data may be retained longer.

Cookie consent records: Retained for 12 months as required to demonstrate compliance.


7. Cookies

We use cookies and similar technologies on our website. Cookies that are not strictly necessary require your consent before being placed on your device.

You can manage your cookie preferences at any time using our consent tool, which appears when you first visit the site. You can also reopen it at any time by clicking the cookie icon at the bottom of the page. A full and up-to-date list of the cookies we use is displayed within the consent tool itself.


8. Your Rights Under GDPR

As a data subject under the GDPR, you have the following rights:

  • Right of access — you can request a copy of the personal data we hold about you (Art. 15)

  • Right to rectification — you can ask us to correct inaccurate or incomplete data (Art. 16)

  • Right to erasure — you can ask us to delete your data in certain circumstances (Art. 17)

  • Right to restriction — you can ask us to restrict how we process your data (Art. 18)

  • Right to data portability — you can request your data in a machine-readable format (Art. 20)

  • Right to object — you can object to processing based on legitimate interest or for direct marketing purposes (Art. 21)

  • Right to withdraw consent — where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of prior processing

To exercise any of these rights, please contact us at chiara@chiarasfood.nl. We will respond within 30 days.

You also have the right to lodge a complaint with the Dutch data protection authority:

Autoriteit Persoonsgegevens

www.autoriteitpersoonsgegevens.nl


9. Do Not Track

Our website does not alter its data collection practices in response to Do Not Track signals from your browser. You can manage your preferences through our cookie consent tool instead.


10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the 'Last updated' date at the top of this page. We encourage you to review this policy periodically.


11. Contact Us

For any questions about this Privacy Policy, to exercise your rights, or to make a complaint, please contact us:

Email: chiara@chiarasfood.nl

Post: VOF Chiara's Food, Van Woustraat 201, 1074AN Amsterdam, Netherlands

Phone: +31 06 50 44 88 68