Privacy policy

Last updated: [8/11/2025]

1) Controller & how to contact us

This website is operated by Chicago Boutique (“we”, “us”, “our”).
For any privacy questions or requests, contact: info@chicagoboutique.com

We do not publish a postal address here. For all privacy correspondence, please use the email above.

Our website uses HTTPS (SSL/TLS) to protect data in transit.


2) Data we process when you visit our site (server logs)

When you browse our site, our server processes technical data to deliver and secure the site:

  • IP address (shortened/anonymized where possible), date/time, requested URL, referrer URL, HTTP status, browser/device/OS, data volume.

Legal basis: our legitimate interest in operating a secure, stable website (GDPR Art. 6(1)(f)).
Retention: typically ~30 days, longer only for security investigations.


3) Cookies & consent

We use cookies and similar technologies:

  • Essential cookies (strictly necessary): enable core functions such as cart, checkout, and security.
    Legal basis: Art. 6(1)(b) and/or Art. 6(1)(f).

  • Marketing cookies (Meta only): Meta Pixel (Facebook/Instagram) for advertising and measurement if you consent.
    Legal basis: consent (Art. 6(1)(a)).

You can manage or withdraw consent anytime via our cookie banner and your browser settings. Some site features may not work without certain cookies.


4) Contacting us

If you contact us (e.g., form or email), we process the data you provide (name, email, message) to respond.

Legal basis: legitimate interest (Art. 6(1)(f)); if your request relates to a purchase/contract, Art. 6(1)(b).
Retention: until resolved plus any required archiving.


5) Accounts & orders

If you create an account or place an order, we process:

  • Identification & contact data (e.g., name, email, billing/shipping details),

  • Order details (items, price, delivery, payment status),

  • Account credentials (stored securely/hashed).

Purposes: account management, order fulfillment, customer service, legal compliance.
Legal basis: contract performance (Art. 6(1)(b)) and legal obligations (Art. 6(1)(c)).
Retention: per Dutch tax/commercial law (typically 7 years) then deletion or anonymization.


6) Emails & marketing

  • Newsletter (optional): If you subscribe (double opt-in), we send updates and offers.
    Legal basis: consent (Art. 6(1)(a)). You can unsubscribe anytime via the link in each email.

  • Existing customer emails: We may email about similar products you purchased.
    Legal basis: legitimate interest (Art. 6(1)(f)). You can opt out at any time.


7) Fulfillment, payments & shipping

To process orders, we share necessary data with processors (e.g., ecommerce platform/host, fulfillment partners, carriers) and with payment providers you choose at checkout (e.g., PayPal, Klarna/SOFORT, card processors).
Each payment provider may act as an independent controller for fraud checks under its own policy.

Legal basis: contract performance (Art. 6(1)(b)); legitimate interest in fraud prevention (Art. 6(1)(f)).


8) Analytics & advertising (Meta only)

We use Meta Pixel (Facebook/Instagram) to measure campaign performance and show relevant ads only if you consent via our cookie banner.

  • Provider: Meta Platforms Ireland Ltd. (EU) / Meta Platforms, Inc. (US).

  • Legal basis: consent (Art. 6(1)(a)).

  • Transfers outside EEA: where data is sent to Meta in the US, we rely on EU Standard Contractual Clauses (SCCs) and appropriate safeguards.

  • Your choices: manage/withdraw consent in our cookie banner; set ad preferences at https://www.facebook.com/adpreferences and review Meta’s policy at https://www.facebook.com/privacy/policy.

We do not use Google Analytics, Google Ads, or any other ad networks.


9) Social media links

Our site contains links or embedded elements for Facebook/Instagram. Data is sent to these platforms only when you click or interact with them. Their own privacy policies apply thereafter.


10) International data transfers

Some processors (e.g., Meta, certain payment or hosting providers) may process data outside the EEA.
Where required, we use SCCs and supplementary measures to protect your data.


11) Security

We apply appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or misuse.


12) Children

Our services are not directed to children under 16. If you believe a child provided data, contact us so we can delete it.


13) Your GDPR rights

You have the right to access, rectify, erase, restrict, port, and object to processing based on legitimate interests or direct marketing, and to withdraw consent at any time.
You also have the right to complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or your local authority.

To exercise rights: info@chicagoboutique.com


14) Retention

We keep personal data only as long as needed for the purposes above, including legal retention (e.g., 7 years for tax records), then delete or anonymize it.


15) Changes to this policy

We may update this policy. The current version will always be available on this page. Significant changes will be indicated where appropriate.