Privacy Policy

Privacy Policy - Scent Stories by Joanna

Last updated: 20 November 2025


1. Introduction

This Privacy Policy explains how Scent Stories by Joanna (“we”, “us”, “our”) collects, uses, and protects your personal data when you visit our website, place an order, or contact us.

We process your data in accordance with the General Data Protection Regulation (GDPR) and Dutch privacy laws.

By using our website, you agree to the terms described in this Privacy Policy.


2. Who We Are

Scent Stories by Joanna
Business registered in the Netherlands

  • Company name: Scent Stories by Joanna

  • KvK number:

    98122274

  • VAT number:

    NL005309605B96

    Business address: Maarheeze, 6026 CW

  • Email: scentstoriesbyjo@gmail.com

We are the “data controller” of your personal data.


3. What Personal Data We Collect

We may collect the following information depending on your interaction with our website:

A. Information you provide

  • Name

  • Address

  • Email

  • Phone number

  • Payment details (processed securely by payment providers — we never see your full card number)

  • Order details and purchase history

  • Messages sent through our contact form or email

  • Customization text for custom candles or gift boxes

B. Information collected automatically

  • IP address

  • Device type

  • Browser type

  • Cookies and tracking data

  • Pages visited, time spent, and actions taken

C. Information from third parties

  • Payment providers (PayPal, Klarna, Stripe, etc.)

  • Shipping carriers (PostNL, DHL, UPS)

  • Marketing platforms (TikTok, Facebook, Instagram)

We only collect information necessary for providing our services.


4. Why We Collect Your Data (Legal Basis)

We use your personal data for:

A. Fulfilling your order

  • Processing payments

  • Preparing and shipping your products

  • Providing order updates

  • Managing returns and refunds

Legal basis: Contractual necessity

B. Customer service

  • Answering questions

  • Handling complaints

Legal basis: Legitimate interest or contract

C. Marketing (optional)

  • Sending promotions, updates, newsletters

  • Showing personalized ads on social media

  • Abandoned cart reminders

Legal basis: Consent

You can unsubscribe at any time.

D. Website improvement

  • Analytics

  • Performance optimization

  • Fraud prevention

Legal basis: Legitimate interest


5. Cookies

We use cookies to improve your browsing experience.

Types of cookies:

  • Essential cookies (needed for the website to function)

  • Analytics cookies (Google Analytics, privacy-friendly settings)

  • Marketing cookies (TikTok Pixel, Facebook Pixel, only after consent)

You can manage cookie preferences at any time through our Cookie Banner.


6. Sharing Your Data

We only share your data with trusted service providers when necessary:

  • Payment processors (Stripe, PayPal, Klarna, etc.)

  • Shipping companies (PostNL, DHL, UPS)

  • Website platforms (Shopify)

  • Email providers (Klaviyo, MailChimp, etc.)

  • Marketing platforms (Meta, TikTok — only with consent)

These parties are required to protect your data and may not use it for their own purposes.

We never sell your personal data.


7. Data Retention

We store your data only as long as necessary:

  • Order information: 7 years (Dutch tax law)

  • Customer service messages: 2 years

  • Marketing emails: until you unsubscribe

  • Cookie data: depending on type (max 2 years)

After these periods, your data is securely deleted.


8. Your Rights (GDPR Rights)

You have the right to:

✔ Access your personal data

✔ Correct inaccurate data

✔ Request deletion (“right to be forgotten”)

✔ Restrict processing

✔ Object to marketing

✔ Withdraw consent

✔ Receive your data in a portable format

✔ File a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens)

To exercise your rights, email us at [scentstoriesbyjo@gmail.com].

We respond within 7 days.


9. Data Security

We take appropriate measures to protect your data, including:

  • SSL encryption

  • Secure servers

  • Limited access to customer data

  • Secure checkout systems

  • Up-to-date security software

However, no system is 100% secure. We cannot guarantee absolute security, but we do our best to protect your data.


10. International Transfers

Some of our service providers may store data outside the EU (e.g., Shopify, Meta, TikTok, some cloud providers).

When this happens, we ensure appropriate safeguards such as:

  • Standard Contractual Clauses (SCCs)

  • GDPR-compliant data agreements


11. Third-Party Links

Our website may include links to other websites (Instagram, TikTok, YouTube, etc.).
We are not responsible for the privacy practices of these websites.


12. Changes to This Policy

We may update this Privacy Policy occasionally.
The “last updated” date at the top indicates when the latest changes were made.

Significant changes will be announced on our website.


13. Contact Information

For questions about your data or this Privacy Policy, contact:

📧 scentstoriesbyjo@gmail.com