Privacy policy
Privacy Policy – NORTHROW
This Privacy Policy explains which personal data we collect, how we use it, when we delete it, with whom we share it, and which rights you have.
Controller
North Row
Online men’s clothing brand and store
E-mail: roycebelmont@gmail.com
1. Data We Collect
We may process the following categories of personal data when you visit our website or place an order:
-
Identification data
First and last name -
Contact data
E-mail address, phone number (optional) -
Address data
Shipping and billing address -
Order data
Products ordered, quantities, prices, discounts, order status, order history -
Payment data
Information necessary to process payments (e.g. payment method, transaction IDs).We do not store full credit card numbers; payments are processed via external payment providers.
-
Usage and technical data
IP address, device information, browser type, pages visited, time and date of access, cookies and similar technologies (only where legally permitted and, where required, based on your consent).
2. Purposes and Legal Bases (GDPR)
We process your personal data for the following purposes and on the following legal bases under Art. 6 GDPR:
-
Order processing and delivery
-
To accept, process and deliver your orders, handle payments and manage your customer account.
-
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
-
-
Customer service and fraud prevention
-
To answer your questions, handle returns or complaints, and prevent misuse or fraud.
-
Legal basis: Art. 6(1)(f) GDPR (legitimate interests).
-
-
Compliance with legal obligations
-
To comply with tax, accounting and other legal retention or reporting duties.
-
Legal basis: Art. 6(1)(c) GDPR (legal obligation).
-
-
Improvement of our website and services / analytics
-
To analyse how our website is used, improve the user experience, optimize our product range and marketing. Wherever possible we use anonymised or pseudonymised data.
-
Legal basis: Art. 6(1)(f) GDPR (legitimate interests) and, where required, Art. 6(1)(a) GDPR (consent).
-
-
Marketing and newsletters
-
To send you product recommendations, offers and news about North Row, if you have registered for our newsletter or otherwise consented to marketing.
-
Legal basis: Art. 6(1)(a) GDPR (consent).
You can withdraw your consent at any time, e.g. via the unsubscribe link in any e-mail.
-
3. Cookies and Analytics
Our website uses cookies and similar technologies.
-
Strictly necessary cookies
These are essential for the basic functioning of the site (e.g. shopping cart, checkout, language settings). They are used without additional consent. -
Statistics and marketing cookies
These help us understand how visitors use our site and allow us to show more relevant offers and ads. We use these cookies only if you give your consent (where required by law).
You can manage or delete cookies via your browser settings. If we provide a cookie banner or preference center, you can change your choices there at any time.
4. Sharing of Data with Processors and Third Parties
We only share your data where necessary and in line with data protection laws, for example with:
-
Payment service providers
Such as credit card providers or payment platforms (e.g. Stripe, PayPal, Apple Pay, Google Pay), to process your payments. -
Logistics and shipping partners
Carriers and fulfillment providers who ship your order to you. -
IT / hosting / e-commerce providers
Shop platform, hosting providers, analytics and support tools (e.g. e-mail service, customer chat).
These companies act as processors on our behalf. We conclude GDPR-compliant data processing agreements with all processors and require them to implement appropriate technical and organisational security measures.
We do not sell your personal data.
5. Data Transfers Outside the EU / EEA
If personal data is transferred to countries outside the European Union (EU) or European Economic Area (EEA), we ensure that an adequate level of data protection is in place, for example by:
-
An adequacy decision of the European Commission, and/or
-
Standard Contractual Clauses (SCCs) approved by the European Commission, plus additional safeguards where necessary.
You can contact us if you would like more information about these safeguards.
6. Data Security
We implement technical and organisational measures to protect your personal data against unauthorised access, loss, misuse, alteration or destruction. These measures include, for example, access controls, encryption where appropriate, secure transmission methods and regular review of our security practices.
7. Storage Period
We only store your personal data for as long as necessary for the purposes stated in this Privacy Policy or as required by law.
Examples:
-
Order and contract data: kept for the duration of the contractual relationship and then for the statutory retention periods (usually 6–10 years under tax and commercial law).
-
Newsletter / marketing data: stored until you withdraw your consent or object to processing.
After the relevant period expires, the data will be deleted or anonymised.
8. Your Rights (under GDPR)
You have the following rights with regard to your personal data, subject to the conditions and limitations set out in the GDPR:
-
Right of access – to obtain confirmation whether we process your data and receive a copy of it.
-
Right to rectification – to correct inaccurate or incomplete data.
-
Right to erasure – to request deletion of your data where certain grounds apply (“right to be forgotten”).
-
Right to restriction of processing – to limit how we process your data in certain cases.
-
Right to data portability – to receive certain data in a structured, commonly used, machine-readable format and transmit it to another controller.
-
Right to object – to object, on grounds relating to your particular situation, to processing based on our legitimate interests (Art. 6(1)(f) GDPR), including profiling. You also have the right to object at any time to processing for direct marketing purposes.
-
Right to withdraw consent – where processing is based on your consent, you may withdraw it at any time with future effect.
-
Right to lodge a complaint – with a data protection supervisory authority, in particular in the EU/EEA member state of your habitual residence, place of work or place of the alleged infringement.
To exercise your rights, you can contact us at:
E-mail: roycebelmont@gmail.com
9. Children
Our services are not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that such data has been collected, we will delete it without undue delay.
10. Changes to this Privacy Policy
We may update this Privacy Policy from time to time, for example if our services change or when legal requirements are updated. The latest version is always available on this page. We will indicate the date of the last update at the end of this document.
Last updated: 06 December 2025

