Privacy policy
Privacy Policy
This page explains, in plain language, exactly what personal data Valerive collects when you browse or shop with us, why we collect it, who we share it with, how long we keep it, and the rights you have over it under UK and Dutch/EU data protection law. We've written it for real customers, not lawyers, and we mean every word of it.
S Commerce, trading as Valerive, is the data controller responsible for the personal data described in this policy. That means we decide why and how your personal data is used when you visit valerive.com, create an account, place an order, or contact our customer care team. We are a company registered in the Netherlands, and we currently sell and ship exclusively to customers in the United Kingdom, which is why both Dutch/EU data protection law and UK data protection law apply to how we handle your information, as explained throughout this page.
We have not appointed a formal Data Protection Officer, because our size and the nature of our processing do not meet the threshold that makes a DPO mandatory under Article 37 of the GDPR. Instead, all privacy questions, requests and complaints are handled directly by our customer care team at the contact details in Section 15, and any request is treated with the same seriousness a dedicated DPO would give it.
This policy applies to personal data we collect through valerive.com, our checkout and order-tracking flow, our customer care channels (email, phone and live chat), and any marketing emails you choose to receive from us. It applies whether you're browsing our dress collections as a guest, creating an account, or completing a purchase.
It does not cover the privacy practices of third-party websites you may reach through links on our site, including our payment providers' own checkout pages, social media platforms, or delivery carrier tracking portals. We recommend reading their own privacy notices separately, as they act as independent controllers of the data you share directly with them.
We only collect what we genuinely need to sell you dresses, get your order to you, keep your account secure, and run a compliant business. Here is the complete list, broken down by category.
| Category | Examples | When collected |
|---|---|---|
| Identity & contact data | Full name, email address, phone number, delivery and billing address | Checkout, account creation, contact form |
| Order & transaction data | Items purchased, order value, order history, returns and refunds, gift messages | Every completed purchase |
| Payment data | Card type and last four digits, billing details, payment confirmation status | Checkout, via our payment provider |
| Technical & device data | IP address, browser type, device type, operating system, referring URL | Automatically, on every site visit |
| Browsing & usage data | Pages viewed, dresses browsed or added to cart/wishlist, time on site, click paths | Automatically, via cookies (Section 6) |
| Marketing preferences | Newsletter subscription status, email open/click activity, opt-out requests | When you subscribe, and while subscribed |
| Customer care records | Emails, chat transcripts, call notes, photos you send us of a faulty or damaged item | Whenever you contact us |
We do not knowingly collect any special category data (such as health, racial or ethnic origin, or religious belief) and we ask that you don't include this kind of information in messages to us unless it's strictly necessary — for example, describing a garment fit issue related to a disability so we can help you better.
Directly from you — when you create an account, place an order, subscribe to our newsletter, use live chat, or email our customer care team, you give us information yourself.
Automatically, as you browse — our website and cookies (Section 6) collect technical and behavioural data as you use valerive.com, such as which dresses you view and how you reached our site.
From trusted third parties — our payment provider confirms whether a payment was successful (without passing us your full card number), and delivery carriers share tracking and delivery-status updates with us so we can keep you informed about your order.
Under UK GDPR and EU GDPR, we can only use your personal data where we have a valid legal basis for doing so. Here is exactly how each basis applies to what we do.
| Purpose | Data used | Legal basis |
|---|---|---|
| Processing and fulfilling your order | Identity, contact, order, payment data | Performance of a contract with you |
| Customer service, returns & refunds | Contact, order, customer care records | Performance of a contract; legal obligation |
| Accounting, tax records & invoicing | Order, transaction, billing data | Legal obligation (Dutch tax law) |
| Fraud prevention & account security | Technical, order, payment data | Legitimate interest; legal obligation |
| Sending newsletters & promotional emails | Contact data, marketing preferences | Consent |
| Analytics, site improvement & testing | Technical, browsing/usage data | Consent (non-essential cookies); legitimate interest |
| Personalised advertising & retargeting | Technical, browsing/usage data | Consent |
Where we rely on legitimate interest, we've weighed our business need against your right to privacy and concluded it does not override your interests. Where we rely on consent — for marketing and for non-essential cookies — you can withdraw that consent at any time, as explained in Sections 6 and 13.
Cookies are small text files stored on your device. We use them, along with similar technologies like pixels, to run our store, remember your cart, understand how customers use our site, and — only with your consent — show you relevant advertising. Under the UK and EU rules on electronic communications (PECR and the ePrivacy framework), any cookie that isn't strictly necessary requires your opt-in consent before it's set, which we ask for through the cookie banner shown on your first visit.
You can change your mind at any time by revisiting the cookie settings link in our site footer, or by adjusting your browser's cookie controls, which let you block or delete cookies at a per-site level. Blocking essential cookies may stop parts of checkout from working correctly.
| Category | What it does | Consent needed? |
|---|---|---|
| Essential / strictly necessary | Keeps your cart, checkout session and account login working; load-balancing and security | No — required for the site to function |
| Analytics & performance | Measures site traffic and behaviour (for example, via Google Analytics) so we can improve navigation and product pages | Yes — opt-in |
| Marketing, advertising & retargeting | Pixel-based tools (such as Meta/Facebook and Google Ads pixels) that let us show you relevant dresses on other sites and measure ad performance | Yes — opt-in |
| Functional preference cookies | Remembers preferences like currency, previously viewed items and your cookie choices themselves | No, or only where non-essential features are involved |
The exact analytics and advertising tools active on our store may change as we refine our marketing; whichever tools are live, they only run for non-essential purposes with your consent, and never collect payment card details.
We don't keep personal data indefinitely. Retention periods are set by how long we need the data for the purpose it was collected, plus any legal minimum that applies, most notably Dutch tax law's requirement to keep financial records for seven years.
| Data type | Retention period |
|---|---|
| Order, invoice & transaction records | 7 years from the date of the transaction, per Dutch tax law (Algemene wet inzake rijksbelastingen) |
| Customer account data | While your account remains active, plus up to 2 years of inactivity before deletion |
| Customer care emails & chat records | Up to 3 years from the last contact, to handle any follow-up or dispute |
| Marketing & newsletter data | Until you unsubscribe or withdraw consent, then removed from active marketing lists promptly |
| Analytics & advertising cookie data | Typically 30 days to 24 months depending on the specific cookie, per the tool provider's own retention settings |
We never sell your personal data. We share only what each partner needs to do their specific job for us, under contracts that require them to protect your data and use it solely for the purpose we've engaged them for.
| Partner type | Examples | Why |
|---|---|---|
| E-commerce platform | Shopify Inc. / Shopify International | Hosts our store, checkout and order management systems |
| Payment processing | Shopify Payments and the card scheme/wallet you choose (Visa, Mastercard, American Express, Maestro, Apple Pay, Google Pay, Shop Pay) | Securely processes your payment; we never see or store full card numbers |
| Order tracking | ParcelPanel | Lets you track your delivery status using your order and tracking number |
| Delivery & postal carriers | Royal Mail, Evri, Parcelforce or similar UK carriers | Delivers your order to the address you provide |
| Email & marketing platform | Our email service provider, connected via our Shopify platform | Sends order confirmations, shipping updates and, where you've opted in, newsletters |
| Analytics & advertising | Tools such as Google Analytics, Google Ads and Meta (Facebook/Instagram) advertising, where you've consented to non-essential cookies | Measures site performance and shows relevant advertising |
| Authorities | Tax authorities, law enforcement, regulators | Only where we are legally required to disclose data |
Some of the partners listed in Section 8, including our platform, analytics and advertising providers, process data on servers located outside the UK and the European Economic Area, most commonly in the United States. Where this happens, we rely on legally recognised safeguards — including the UK's International Data Transfer Agreement (IDTA) and the EU Standard Contractual Clauses (SCCs), or the provider's certification under an adequacy-recognised framework — to ensure your data continues to receive a level of protection equivalent to UK and EU law.
A limited amount of order data — specifically the shipping name, delivery address and order reference needed to fulfil your purchase — is shared with logistics and fulfilment partners so your dress can be picked, packed and dispatched to you. We limit this to what's strictly necessary for delivery and do not share your full customer profile, payment details or browsing history for this purpose.
Our store runs on Shopify's infrastructure, which encrypts data in transit using TLS/SSL and encrypts sensitive data at rest, and is independently assessed against PCI DSS for payment security. We restrict internal access to personal data to staff who genuinely need it to do their job, and we review our data-handling practices regularly as our business grows.
No online system can be guaranteed 100% secure. If we ever become aware of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours as UK and EU law requires, and will contact affected customers directly where the risk to you is high.
Under UK GDPR (Articles 15–22) and EU GDPR, you have the following rights over your personal data. These apply regardless of whether you've made a purchase.
Ask us to confirm what personal data we hold about you and receive a copy of it.
Ask us to correct inaccurate or incomplete personal data, such as an old delivery address.
Ask us to delete your personal data, subject to legal retention obligations such as Section 7's 7-year tax rule.
Ask us to pause using your data in certain circumstances, for example while we investigate an accuracy dispute.
Ask us to provide data you gave us in a structured, commonly used, machine-readable format, or transfer it to another provider.
Object to processing based on legitimate interest, and to direct marketing at any time, with no need to give a reason.
Withdraw consent for marketing or non-essential cookies at any time, without affecting processing already carried out.
Not be subject to a decision based solely on automated processing that has legal or similarly significant effects on you. See Section 14.
Email support@valerive.com telling us which right you'd like to exercise, or use our Privacy Opt-Out & Data Rights Request page.
To protect your data from being handed to the wrong person, we may ask you to confirm details such as your order number or the email address on your account before proceeding.
We action or respond to your request free of charge within one calendar month. For complex or numerous requests, we may extend this by a further two months, and we'll always tell you if we need to.
We only send marketing emails, such as new arrivals or promotions, to customers who have actively opted in — for example, by subscribing through our website footer or checking a box at checkout. We never add you to marketing lists just because you placed an order, in line with the UK and EU rules on electronic marketing (PECR and the ePrivacy Directive).
Every marketing email we send includes an unsubscribe link, which takes effect immediately. You can also opt out at any time by emailing support@valerive.com or using our Privacy Opt-Out & Data Rights Request page. Opting out of marketing never affects transactional emails, like order confirmations or shipping updates, which we send to fulfil your contract with us.
We use limited, everyday automation — for example, automated fraud-screening on payments and algorithm-driven product recommendations based on your browsing — to run our store efficiently and to show you dresses more relevant to you. None of this automation makes a decision with legal or similarly significant effect on you without human involvement; for example, we do not use automated systems to decide whether to accept or cancel an order without a person able to review it on request.
If you're ever concerned that an automated process has affected you unfairly, contact us and we'll have a person review the outcome.
Our dresses and this website are intended for customers aged 18 and over. We do not knowingly collect personal data from children, and we do not knowingly market to or sell to minors. If you believe a child has provided us with personal data, please contact us at support@valerive.com and we will delete it promptly.
Because S Commerce is established in the Netherlands and sells to customers in the United Kingdom, both frameworks below apply to our processing of your data at the same time; neither replaces the other.
We hope you'll always come to us first, and we take every privacy question seriously. But you have the right to lodge a complaint directly with a supervisory authority at any time, particularly one in the country where you live, work, or where you believe an issue took place.
The Information Commissioner's Office is the UK's independent regulator for data protection rights, reachable at ico.org.uk.
The Autoriteit Persoonsgegevens is the Dutch data protection authority and is competent for matters concerning S Commerce, reachable at autoriteitpersoonsgegevens.nl.
We review this Privacy Policy at least every 12 months, and sooner whenever the personal data we collect, the tools we use, or applicable UK or Dutch/EU data protection law changes. The version in force is always the one published here, dated at the top of this page.
If we make a material change that affects how we use your personal data, we will take reasonable steps to let you know — for example, by email or a notice on this page — before the change takes effect.
Monitored 24/7. Write to support@valerive.com — replies within 5 hours.
Call +31 6 26269395, Monday–Friday, 09:00–18:00 CET/CEST.
Use our Privacy Opt-Out & Data Rights Request page or the Contact page.