Skip to content
  • Return period of 30 days

  • Free shipping for orders over €250

marliesdekkers

Privacy policy

PRIVACY POLICY

Version 2.0
Last updated: [21.7.2026]

1. Who we are

Dare to Be B.V., trading as Marlies Dekkers, is the controller responsible for the processing of personal data described in this Privacy Policy.

Dare to Be B.V.
Voorhaven 17
3025 HC Rotterdam
The Netherlands

Company registration number: 58573089
VAT number: NL853094652B01
Email: webshop@marliesdekkers.com
Telephone: +31 (0)10 476 04 14

In this Privacy Policy, “Marlies Dekkers”, “we”, “us” and “our” refer to Dare to Be B.V.

2. Data Protection Officer

Our Data Protection Officer is:

Robert Heijveld
Email: Robert.Heijveld@marliesdekkers.com

You may use this email address to:

  • ask questions about this Privacy Policy;
  • exercise your GDPR or other privacy rights;
  • raise a privacy concern; or
  • request information about our processing activities.

3. Scope of this Privacy Policy

This Privacy Policy explains how we process personal data when you:

  • visit our website or webshop;
  • purchase or return a product;
  • create or use a customer account;
  • use the Marlies Dekkers mobile application;
  • contact Customer Care;
  • subscribe to marketing communications;
  • participate in promotions or competitions;
  • submit a product review;
  • interact with our advertising;
  • visit a participating Marlies Dekkers retail location;
  • apply for a job; or
  • otherwise interact with us.

A separate privacy notice may apply to specific activities, such as recruitment, in-store monitoring or a particular campaign.

4. Personal data we collect

Depending on how you interact with us, we may process the following categories of personal data.

4.1 Identity and contact information

This may include:

  • first and last name;
  • title;
  • billing and delivery address;
  • country;
  • email address;
  • telephone number;
  • date of birth, where voluntarily provided;
  • customer number;
  • account identifier; and
  • preferred language or market.

4.2 Order and transaction information

This may include:

  • products ordered;
  • product, colour and size selections;
  • order numbers;
  • purchase dates;
  • payment status;
  • delivery and tracking information;
  • discounts used;
  • returns, refunds and exchanges;
  • gift-card transactions;
  • final-sale status; and
  • customer-service history.

We do not normally receive complete payment-card information. Payment details are processed by our authorised payment providers.

4.3 Customer-account information

This may include:

  • login details;
  • saved addresses;
  • order history;
  • wishlists;
  • communication preferences;
  • profile information; and
  • loyalty or membership information.

4.4 Payment information

Payments may be processed through:

  • Shopify Payments; and
  • PayPal.

We may receive limited information from these providers, such as:

  • payment status;
  • payment method;
  • transaction reference;
  • fraud or risk result; and
  • partial payment-account identifiers.

4.5 Technical and usage information

This may include:

  • IP address;
  • browser and device type;
  • operating system;
  • cookie and device identifiers;
  • login and session information;
  • pages viewed;
  • clicks and interactions;
  • referral source;
  • approximate location derived from an IP address;
  • website performance data; and
  • error or security logs.

4.6 Marketing and preference information

This may include:

  • newsletter subscription status;
  • consent records;
  • marketing preferences;
  • preferred products, styles and sizes;
  • campaign engagement;
  • email opens and clicks, where permitted;
  • promotion participation;
  • birthday-promotion eligibility; and
  • unsubscribe or suppression records.

4.7 Customer-service information

This may include:

  • emails, chats and other correspondence;
  • complaint details;
  • support notes;
  • return information;
  • delivery issues;
  • product-quality concerns; and
  • photographs or other evidence supplied by you.

4.8 Review and user-generated content

This may include:

  • product reviews;
  • ratings;
  • review titles;
  • photographs or videos;
  • display name;
  • verified-purchase status;
  • incentive information; and
  • moderation records.

4.9 Fraud and security information

This may include:

  • transaction-risk indicators;
  • suspected misuse;
  • failed login attempts;
  • device and network signals;
  • chargeback information;
  • fraud-prevention results; and
  • security incident logs.

4.10 Recruitment information

Where you apply for a role, this may include:

  • contact details;
  • CV and application information;
  • employment and education history;
  • interview notes;
  • references;
  • work-authorisation information; and
  • information voluntarily supplied during recruitment.

A separate recruitment privacy notice may provide more detailed information.

5. How we collect personal data

We collect personal data:

  • directly from you;
  • automatically when you use our website or mobile application;
  • from Shopify and our commerce infrastructure;
  • from payment providers;
  • from Bleckmann and delivery partners;
  • from customer-service and review providers;
  • from marketing and analytics providers, subject to consent requirements;
  • from social-media platforms when you interact with us;
  • from fraud-prevention providers;
  • from Marlies Dekkers group entities or retail channels;
  • through authorised shopping agents acting at your request; and
  • from public sources where legally permitted.

6. Why we process personal data

We process personal data only where we have an appropriate legal basis.

6.1 Processing and fulfilling orders

We process identity, contact, order, payment-status and delivery information to:

  • process purchases;
  • accept and fulfil orders;
  • collect payment;
  • arrange delivery;
  • provide tracking;
  • process returns and refunds;
  • handle gift-card transactions;
  • send order communications; and
  • manage warranty or conformity claims.

Legal basis: Performance of a contract and steps taken at your request before entering into a contract.

6.2 Logistics and returns

We share relevant order, contact and delivery information with Bleckmann and the applicable parcel carrier to:

  • pick and pack orders;
  • arrange delivery;
  • process returned products;
  • update inventory;
  • investigate delivery issues; and
  • provide shipment status information.

Legal basis: Performance of a contract and our legitimate interests in managing efficient logistics.

6.3 Customer accounts

We process account information to:

  • create and administer accounts;
  • authenticate users;
  • save preferences;
  • show order history;
  • maintain wishlists; and
  • provide account functionality.

Legal basis: Performance of a contract or our legitimate interest in providing requested account features, depending on the feature.

6.4 Date of birth and birthday promotions

Providing your date of birth should be optional.

Where you provide it, we may use it to:

  • determine eligibility for birthday or loyalty promotions;
  • personalise birthday communications; and
  • avoid sending age-inappropriate communications where relevant.

We do not require your full date of birth to complete a standard purchase unless there is a separate lawful reason.

Legal basis: Consent for birthday marketing and personalisation, or our legitimate interests where permitted and reasonably expected.

You may withdraw this consent or remove your date of birth by contacting us or updating your account where that option is available.

6.5 Customer Care

We process contact, order and correspondence information to:

  • answer questions;
  • process complaints;
  • assist with returns;
  • investigate delivery issues;
  • handle product-quality concerns; and
  • protect and establish legal rights.

Legal basis: Performance of a contract, compliance with legal obligations and our legitimate interests in supporting customers and resolving disputes.

6.6 Legal and financial compliance

We process transaction, invoice, tax, return and compliance information to:

  • maintain legally required financial records;
  • comply with VAT and tax rules;
  • administer One Stop Shop reporting where applicable;
  • respond to lawful authority requests;
  • comply with consumer-protection rules; and
  • establish, exercise or defend legal claims.

Legal basis: Compliance with legal obligations and our legitimate interests in protecting legal rights.

6.7 Fraud prevention and security

We process technical, account and transaction information to:

  • authenticate users;
  • detect and prevent fraud;
  • prevent chargebacks and misuse;
  • protect customer accounts;
  • secure our systems;
  • investigate incidents; and
  • enforce our Terms.

Legal basis: Our legitimate interests in protecting customers, our business and our systems, and compliance with legal obligations where applicable.

6.8 Service communications

We use contact information to send necessary communications including:

  • order confirmations;
  • payment updates;
  • shipment notifications;
  • return and refund updates;
  • product-safety notices;
  • account-security messages; and
  • material service changes.

Legal basis: Performance of a contract, legal obligations and our legitimate interests in administering our services.

These messages are not marketing communications and may still be sent when you have unsubscribed from newsletters.

6.9 Direct marketing

Subject to applicable law, we may use contact, purchase, preference and engagement information to send:

  • newsletters;
  • product launches;
  • promotions;
  • birthday offers;
  • event invitations;
  • back-in-stock messages;
  • browse or basket reminders; and
  • personalised recommendations.

Legal basis: Consent where required, or legitimate interests where direct marketing is permitted without consent.

You can unsubscribe at any time by:

  • using the unsubscribe link in an email;
  • changing your account preferences; or
  • contacting our Data Protection Officer.

We may retain limited suppression information to ensure that your unsubscribe choice continues to be respected.

6.10 Personalisation

We may use purchase and preference information to provide basic personalisation, such as:

  • recognising your preferred language or market;
  • remembering recently viewed products;
  • displaying relevant products; and
  • tailoring content based on information you directly provided.

Advanced Bloomreach profiling or personalisation is not currently active.

Before introducing materially new profiling through Bloomreach or another platform, we will:

  • assess the legal basis;
  • update this Privacy Policy where required;
  • update the cookie and consent configuration;
  • obtain consent where necessary; and
  • perform a data-protection impact assessment where legally required.

6.11 Analytics and improvement

Subject to applicable consent requirements, we may use analytics and technical information to:

  • understand website and application performance;
  • measure conversion and customer journeys;
  • identify errors;
  • improve navigation and merchandising;
  • conduct business reporting;
  • forecast demand; and
  • measure campaign performance.

Tools may include:

  • Google Analytics 4;
  • Elevar;
  • Google Cloud;
  • BigQuery; and
  • Shopify analytics.

Legal basis: Consent where analytics or tracking technologies require it; otherwise, our legitimate interests in improving our services.

6.12 Product reviews

We process review information through Yotpo or another authorised provider to:

  • request and publish reviews;
  • verify purchases;
  • label incentivised reviews;
  • moderate unlawful or irrelevant content;
  • detect fake or suspicious reviews; and
  • calculate aggregate ratings.

Customers may receive a 10% incentive for submitting a review. The incentive is provided for submitting an honest review and is not dependent on giving a positive rating.

Incentivised reviews will be identified clearly where required.

Legal basis: Performance of a requested service, our legitimate interests in obtaining authentic customer feedback and consent where relevant.

6.13 Mobile application

Our mobile application is currently available in selected markets, including Germany, the United States, France, the Netherlands, Norway and additional international markets.

We may process account, transaction, device and engagement information to:

  • operate the application;
  • provide customer-account functionality;
  • support purchases;
  • deliver push notifications where permitted;
  • personalise application settings; and
  • analyse technical performance.

NewStore and supporting service providers may process information on our behalf in connection with the mobile application.

Legal basis: Performance of a contract, consent where required and our legitimate interests in operating and improving the application.

6.14 Recruitment

We process applicant information to:

  • review applications;
  • communicate with candidates;
  • organise interviews;
  • assess suitability; and
  • comply with employment-related obligations.

Legal basis: Steps taken at the applicant’s request before entering into a potential employment contract, compliance with legal obligations and our legitimate interests in recruitment.

7. Cookies and similar technologies

We use cookies, pixels, tags, server-side tracking and similar technologies for:

  • essential webshop functionality;
  • security;
  • preference storage;
  • analytics;
  • personalisation;
  • advertising; and
  • campaign measurement.

Our consent-management platform is Consentmo.

Consentmo is configured to support applicable GDPR requirements and Google Consent Mode v2. However, the legal effectiveness of consent depends on the actual configuration, vendors, scripts and consent signals in use.

Non-essential technologies are activated only after consent where required by law.

You can change or withdraw your choices at any time through the cookie-preference centre.

More information is provided in our Cookie Policy.

8. Profiling and automated decision-making

We may use limited segmentation to organise customers by characteristics such as:

  • market;
  • purchase history;
  • product preferences;
  • communication engagement; or
  • loyalty status.

We do not currently use Bloomreach for advanced personalisation or profiling.

We do not intend to make decisions based solely on automated processing that produce legal or similarly significant effects, except where:

  • necessary to enter into or perform a contract;
  • authorised by applicable law; or
  • based on explicit consent,

and appropriate safeguards are provided.

Automated fraud or payment-risk checks may affect whether a payment or order requires additional review. Where appropriate, you may contact us to request human review.

9. Who we share personal data with

We may share personal data with the following categories of recipients.

9.1 E-commerce infrastructure

This includes Shopify and supporting providers used to operate:

  • the webshop;
  • checkout;
  • customer accounts;
  • payments;
  • order administration; and
  • commerce-related functionality.

9.2 Payment providers

This includes:

  • Shopify Payments; and
  • PayPal.

These providers may process data as our processor or as an independent controller, depending on the relevant activity.

9.3 Logistics and delivery providers

This includes:

  • Bleckmann; and
  • parcel carriers selected according to destination and delivery method.

They receive only the information reasonably necessary to fulfil, deliver, track or return orders.

9.4 Marketing and customer-engagement providers

This may include providers used for:

  • newsletters;
  • campaigns;
  • consent records;
  • customer segmentation;
  • push notifications; and
  • future personalisation.

Bloomreach Engagement may process data as part of our customer-engagement infrastructure, even where advanced personalisation is not yet active.

9.5 Analytics and technology providers

This may include:

  • Google Analytics 4;
  • Google Cloud;
  • BigQuery;
  • Elevar;
  • Shopify analytics; and
  • technical integration providers.

9.6 Review providers

This includes Yotpo, which may process review invitations, ratings, review content, verified-purchase status and incentive information.

9.7 Mobile-application providers

This includes NewStore and supporting providers used to operate and maintain the mobile application.

9.8 Product and order-management providers

This includes providers supporting our:

  • product information management;
  • order management;
  • inventory;
  • integrations; and
  • data exchange.

This may include our Mendix-based PIM and OMS environments and their authorised service providers.

9.9 Professional advisers

We may share information with:

  • lawyers;
  • accountants;
  • auditors;
  • insurers;
  • consultants; and
  • security specialists.

9.10 Authorities and legal recipients

We may disclose personal data to:

  • courts;
  • regulators;
  • tax authorities;
  • law-enforcement bodies; or
  • other recipients,

where legally required or necessary to protect legal rights.

9.11 Corporate transactions

Information may be disclosed in connection with:

  • a merger;
  • restructuring;
  • acquisition;
  • financing;
  • reorganisation; or
  • sale of assets,

subject to appropriate confidentiality and data-protection measures.

10. International data transfers

Some providers may process personal data outside the European Economic Area.

Where data is transferred to a country not recognised as providing adequate protection, we use an appropriate safeguard where required, such as:

  • European Commission Standard Contractual Clauses;
  • an applicable adequacy decision;
  • Binding Corporate Rules; or
  • another recognised transfer mechanism.

Where appropriate, we also assess whether additional contractual, technical or organisational protections are necessary.

You may contact our Data Protection Officer for more information about the safeguards relating to a particular transfer.

11. Retention periods

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including legal, tax, accounting, security and dispute-resolution obligations.

Our general retention approach is as follows.

Order, transaction and tax records

We retain relevant order, invoice, payment-status, delivery, return and tax records for:

  • seven years where the normal Dutch fiscal retention period applies; or
  • ten years where required for One Stop Shop reporting, another cross-border VAT obligation or another applicable legal requirement.

We may retain a limited transaction record for the longer applicable period without retaining every item of customer-service or marketing data associated with that purchase.

Customer accounts

We retain account information while the account remains active.

Where an account has been inactive, we will review whether it remains necessary and may delete or anonymise the account after three years of inactivity, except for transaction records that must be retained longer.

Customer-service correspondence

We generally retain routine customer-service correspondence for up to three years after the matter is closed.

Information relating to a dispute, product claim, fraud investigation or legal proceeding may be retained for longer where reasonably necessary.

Returns, complaints and product claims

We generally retain information relating to returns and complaints for up to five years after closure, unless a longer period is required for a legal claim, product-safety matter or statutory obligation.

Marketing information

We retain marketing profile and preference information until:

  • you withdraw consent;
  • you object to direct marketing;
  • the information is no longer required; or
  • there has been no meaningful engagement for two years,

whichever occurs first, subject to periodic review.

We may retain limited suppression information for longer to ensure that we do not send marketing after you have opted out.

Date of birth

Where provided for birthday promotions, we retain your date of birth while your account and relevant marketing permission remain active.

It will be removed where:

  • you withdraw consent;
  • you request deletion;
  • the account is deleted; or
  • the information is no longer required,

unless retention is legally necessary.

Consent records

We retain consent and preference records for as long as necessary to demonstrate compliance and manage your current choices.

Cookie and analytics data

Retention periods for individual cookies and identifiers are described in the Cookie Policy and consent-preference centre.

Fraud and security records

We retain fraud and security information for as long as reasonably necessary to:

  • detect repeated fraud;
  • protect accounts and systems;
  • investigate an incident; and
  • establish or defend legal claims.

The period will depend on the nature and seriousness of the risk.

Recruitment data

Unsuccessful applicant data is generally deleted within four weeks after the recruitment process ends, unless the applicant consents to retention for future opportunities.

Where consent is given, it may be retained for up to one year, subject to applicable Dutch employment rules.

Reviews

Published reviews may remain available while the relevant product or review service remains active.

Supporting verification and moderation data may be retained for a reasonable period to demonstrate review authenticity and address complaints.

When a retention period ends, data is deleted, anonymised or restricted unless continued retention is legally required.

12. Your privacy rights

Subject to applicable conditions and exceptions, you may have the right to:

  • request access to your personal data;
  • correct inaccurate or incomplete information;
  • request deletion;
  • restrict processing;
  • object to processing based on legitimate interests;
  • object at any time to direct marketing;
  • receive certain data in a portable format;
  • withdraw consent at any time;
  • request human intervention in certain automated decisions; and
  • lodge a complaint with a supervisory authority.

To exercise a right, contact:

Robert.Heijveld@marliesdekkers.com

We may ask for information reasonably necessary to verify your identity and protect your account.

We will respond within the period required by applicable law.

13. Right to object

You may object at any time to processing for direct marketing, including related profiling.

Where processing is based on legitimate interests for another purpose, you may object on grounds relating to your particular situation.

We will stop the relevant processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is necessary for legal claims.

14. Withdrawing consent

Where processing is based on consent, you may withdraw consent at any time.

Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

You can withdraw consent by:

  • using an email unsubscribe link;
  • changing your account settings;
  • updating your cookie preferences; or
  • contacting our Data Protection Officer.

15. Children

Our webshop and application are not directed at young children.

We do not knowingly collect personal data from children who cannot lawfully provide the relevant information or consent themselves.

Where a minor places an order or joins a promotion, the involvement of a parent or legal guardian may be required.

Date of birth should not be mandatory for a standard customer account or purchase unless a separate lawful reason applies.

16. Security

We use appropriate technical and organisational measures designed to protect personal data against:

  • unauthorised access;
  • accidental loss;
  • misuse;
  • alteration;
  • disclosure; and
  • destruction.

These measures may include:

  • role-based access controls;
  • authentication;
  • encryption where appropriate;
  • monitoring;
  • vendor-management procedures;
  • incident-response processes;
  • backups; and
  • business-continuity controls.

No online service can be guaranteed to be completely secure.

17. Personal-data breaches

Where a personal-data breach occurs, we assess the potential risk to affected individuals.

We notify the relevant supervisory authority and affected individuals where required by applicable law.

18. Shopping assistants and agentic commerce

You may choose to interact with Marlies Dekkers through an authorised digital assistant, shopping agent, marketplace or commerce platform.

Depending on the service, the agent or platform may provide us with:

  • selected products;
  • size or colour preferences;
  • contact details;
  • delivery information;
  • order instructions;
  • payment or transaction status; and
  • consent or preference signals.

We process this information to:

  • answer the request;
  • provide product information;
  • prepare or fulfil an order;
  • provide customer support; and
  • prevent fraud.

The provider of the assistant or commerce platform may act as an independent controller for its own activities. Its own privacy policy will apply to that processing.

We will not assume that an agent is authorised to share unnecessary or sensitive information on your behalf.

19. Third-party websites and social media

Our website or application may contain links to external websites, applications or social-media services.

Those third parties process information under their own privacy policies. We recommend reviewing their policies before providing personal data.

20. Complaints and supervisory authority

You have the right to lodge a complaint with the data-protection supervisory authority in the country where you live, work or believe an infringement occurred.

Our Dutch supervisory authority is:

Autoriteit Persoonsgegevens

You may contact us first so that we have an opportunity to resolve your concern, but you are not required to do so.

21. Changes to this Privacy Policy

We may update this Privacy Policy to reflect:

  • changes in law;
  • new providers or systems;
  • changes to our webshop or application;
  • new processing activities;
  • changes to profiling or personalisation; or
  • organisational changes.

Where a change materially affects your rights or how we use your information, we will provide an appropriate notice and obtain new consent where required.

The latest-update date will be displayed at the top of this Policy.

22. Language

The English version is the controlled master version of this Privacy Policy.

Translations may be provided for convenience and local compliance. Where mandatory law requires information to be interpreted or provided in a particular local language, that requirement will prevail.

23. Contact

For questions, privacy requests or complaints, contact:

Data Protection Officer: Robert Heijveld
Email: Robert.Heijveld@marliesdekkers.com

Or write to:

Dare to Be B.V.
Attn. Data Protection Officer
Voorhaven 17
3025 HC Rotterdam
The Netherlands