Legal
Privacy Statement
We sell to you, so we hold your data. This page says exactly what we hold, why we are allowed to, who else sees it, how long it stays and how you get rid of it.
Version 1.0 · in force since 7 September 2026
1. Who is responsible
The controller is Borderstride Morrow, De Brulen 28, 2370 Arendonk, Belgium — enterprise number 0731.511.147, VAT BE0731511147.
For any question about your data, write to relay@borderstride.com or telephone +32 474 29 01 04. We have not appointed a data protection officer; we are not required to and would rather you reach a person directly.
2. What we collect
When you buy
- Your name and email address
- Your country, and for business purchases your company name and VAT number
- The product bought, the amount, the currency and the date
- The payment reference from our payment provider, and whether the payment succeeded
- Your invoice and its contents
- Whether you waived your right of withdrawal, and when
We never receive or store your card number. Card details are entered directly with our payment provider, which handles them under its own responsibility. What reaches us is a reference and a result.
When you enquire
- What you put in the enquiry form: name, company, website and your message
- A one-way hash of your IP address, to make rate limiting work without keeping the address itself
When you simply read the site
Nothing that identifies you. There is no analytics, no tracking pixel, no advertising network and no external font or script. See our Cookie Statement.
3. Why, and on what legal basis
To sell to you and deliver what you bought — Article 6(1)(b), performance of a contract
Your name, email, country and order details, so that we can conclude the sale, arrange delivery with the supplier, handle your withdrawal or complaint, and refund you where due.
To invoice and account for VAT — Article 6(1)(c), legal obligation
Belgian invoicing and VAT law, including the Union One Stop Shop scheme, requires us to issue and keep invoices containing your details, and to record the VAT treatment applied.
To handle payments and disputes — Article 6(1)(b) and (c)
Payment references, and where a payment is disputed, the evidence needed to answer it: the order, the delivery confirmation and the correspondence.
To prevent fraud and abuse — Article 6(1)(f), legitimate interests
Hashed IP addresses, rate-limit counters and login records. Our interest is keeping the service and other buyers safe; the impact on you is minimal because we do not retain the underlying address.
To answer your enquiry — Article 6(1)(f), legitimate interests
You approached us about a possible business relationship, and we process what you sent in order to reply. If nothing follows, we delete it.
4. Who else sees your data
- Our payment provider, which processes the payment. It acts as a separate controller for payment data under its own privacy terms, not on our instruction.
- The supplier of the product you bought, which receives your name and email address in order to give you access and support you. The supplier is named on the product page and on your invoice. Where the supplier uses your data for its own purposes, it is a controller in its own right for those purposes.
- Our email provider, which delivers invoices and notifications on our instruction, as a processor. Its servers are in the European Union.
- Our accountant and, where required, the tax authorities, for the statutory accounting and VAT obligations.
We do not sell data, we do not share it for advertising, and we do not enrich it with data bought elsewhere.
5. Transfers outside the European Economic Area
Many of our suppliers are established outside the EEA. Giving you access to the product you bought therefore means transferring your name and email address to a third country.
Where the European Commission has not adopted an adequacy decision for that country, the transfer is made under the Standard Contractual Clauses of Implementing Decision (EU) 2021/914 — Module One or Module Two depending on whether the supplier processes the data for its own purposes. Each such transfer is supported by a written transfer impact assessment covering the law of the destination country and the additional measures applied, including encryption in transit and at rest and the minimum necessary set of fields. The assessment is reviewed annually.
You may ask us for a copy of the safeguards applying to your own purchase.
6. How long we keep it
Retention is not uniform, because two obligations pull in opposite directions. Deleting everything on request would breach the statutory retention of accounting records; keeping everything indefinitely would breach data protection. So the two categories are separated.
- Invoices and accounting records
Ten years from the end of the year in which the invoice was issued. This is a statutory obligation and a deletion request does not override it. - Order and delivery data
Kept while needed to support the purchase and to answer a possible dispute, and in any case until the last payment-dispute window has closed. - Withdrawal-waiver record
Kept with the invoice, as evidence of what was agreed. - Support correspondence
Two years after the matter is closed. - Enquiries that lead nowhere
Twelve months, then deleted. - Security and audit logs
Retained for the period needed to investigate incidents, then removed on a scheduled routine.
7. Your rights
You may ask us to give you access to your data, correct it, delete it, restrict what we do with it, or hand it over in a portable format. You may object to processing based on our legitimate interests. Where processing rests on consent, you may withdraw it at any time without affecting what was done before.
Write to relay@borderstride.com. We answer within one month and will tell you if we need longer. There is no charge. We may ask you to confirm your identity — not to obstruct you, but so that we do not hand your data to someone else.
One honest limit: where a statutory retention applies, we can restrict processing but not delete. We will say so plainly rather than pretend the data is gone.
8. Complaints
If you think we have handled your data badly, tell us first — we would rather fix it. You also have the right to lodge a complaint with the Belgian Data Protection Authority, Drukpersstraat 35, 1000 Brussels, dataprotectionauthority.be, or with the supervisory authority in your own country.
9. Security
The application runs on a dedicated server under our own management, not on shared hosting. Access requires two-factor authentication. Personal data is encrypted at field level in the database, so that a database copy on its own does not disclose it. Every material action is written to a tamper-evident audit log. Backups are encrypted and restore procedures are tested, because an untested backup is an assumption rather than a backup.
10. Automated decisions
We take no decisions about you by automated means that produce legal effects or similarly significant effects. VAT-number validation and fraud checks may flag an order, but a person decides what happens next.
11. Changes
We update this statement when what we do changes. The version and its date are at the top of this page. If a change materially affects you, we tell buyers by email rather than quietly republishing.