Privacy policy
Last updated: 15 July 2026
Privacy Policy
Last updated: 15 July 2026
1. About this Privacy Policy
Grid to Great B.V. takes the protection of your privacy and personal data seriously.
This Privacy Policy explains how Grid to Great B.V., hereinafter referred to as “Grid to Great”, “we”, “us” or “our”, collects, uses, stores and shares personal data when you:
- visit our websites;
- use our online store;
- purchase products or services from us;
- create or use a customer account;
- subscribe to our communications;
- contact us;
- enter into a business relationship with us; or
- otherwise interact with our products and services.
Grid to Great operates the website and online store, including the information, content, features, tools, products and services offered through them, collectively referred to as the “Services”.
Our online store is powered by Shopify. Shopify provides the e-commerce infrastructure that enables us to offer products and services, process orders and provide the online shopping experience.
For the purposes of applicable data protection legislation, including the General Data Protection Regulation, Grid to Great is generally the controller of the personal data described in this Privacy Policy.
Our company details are:
Grid to Great B.V.
Hengelosestraat 500
7521 AN Enschede
The Netherlands
Chamber of Commerce number: 06057207
Email: info@gridtogreat.com
Telephone: +31 (0)88 1660 100
2. What is personal data?
Personal data means any information relating to an identified or identifiable person. This includes information that directly identifies you, such as your name or email address, as well as information that can be linked to you indirectly, such as an IP address, device identifier or order history.
Information that has been irreversibly anonymised and can no longer reasonably be linked to an individual is not personal data.
3. Personal data we collect
The personal data we collect depends on how you interact with us and which Services you use.
3.1 Contact and identification details
We may collect:
- your name;
- company name;
- job title or position;
- email address;
- telephone or mobile number;
- billing address;
- postal address;
- delivery address;
- country of residence; and
- other identification or contact details you provide to us.
3.2 Account information
When customer account functionality is available and you create an account, we may process:
- your username or account identifier;
- your password in encrypted or otherwise protected form;
- account settings;
- communication preferences;
- saved addresses;
- language preferences; and
- information relating to the use and security of your account.
You are responsible for keeping your login details confidential and for notifying us if you suspect unauthorised use of your account.
3.3 Order and transaction information
When you view, order, return or exchange products or services, we may collect:
- the products or services you view;
- products added to your shopping cart or wishlist;
- products or services purchased;
- order numbers;
- transaction dates;
- order status;
- delivery and fulfilment information;
- information about returns, exchanges, cancellations or refunds;
- discount codes or promotional offers used;
- correspondence relating to the transaction; and
- your purchase and transaction history.
3.4 Payment and invoicing information
We may collect or receive:
- invoicing details;
- payment method;
- transaction identifiers;
- payment status;
- payment confirmation;
- bank account number and account holder name;
- VAT information; and
- information required for our financial records.
Payments made through our online store may be processed by Shopify, Shopify Payments or another payment service provider. Payment providers may directly collect payment card or financial information.
Grid to Great does not normally receive or store complete payment card details. We may receive limited information, such as the payment method, payment status and transaction reference.
We may also collect bank details from suppliers, creditors and other business partners when necessary to administer payments.
3.5 Communications
When you contact us, we may process:
- the content of your email, message or enquiry;
- correspondence with our customer service or other employees;
- information submitted through contact or support forms;
- notes relating to telephone calls or meetings;
- complaints and requests; and
- information you otherwise choose to provide to us.
Please do not send sensitive or confidential personal data unless it is necessary and we have specifically requested it.
3.6 Marketing information
We may collect:
- whether you have subscribed to a newsletter;
- your marketing preferences;
- your consent or withdrawal of consent;
- your interaction with our newsletters and other communications;
- whether an email was delivered or opened;
- whether you clicked a link in an email; and
- the date on which you subscribed or unsubscribed.
3.7 Device, browser and usage information
When you visit or use our websites or online store, we may automatically collect:
- your IP address;
- browser type and version;
- device type;
- operating system;
- language and regional settings;
- network information;
- cookie identifiers and similar identifiers;
- pages and products viewed;
- the date and time of your visit;
- referring and exit pages;
- interaction with website functions;
- shopping cart activity;
- navigation and browsing behaviour; and
- diagnostic, performance and error information.
3.8 Business relationship information
If you are a customer, supplier, service provider or other business contact, we may also process:
- your organisation and role;
- website address;
- contractual information;
- information about products or services purchased or supplied;
- proposals and quotations;
- correspondence;
- project information;
- service history;
- payment and invoicing information; and
- other information relevant to our business relationship.
4. How we collect personal data
We may collect personal data from the following sources.
4.1 Directly from you
For example, when you:
- place an order;
- request a quotation;
- create an account;
- complete a form;
- contact us;
- subscribe to a newsletter;
- participate in an event or promotion;
- purchase or use a product or service; or
- otherwise provide information to us.
- 4.2 Automatically
We may automatically collect information through:
- cookies;
- pixels;
- tags;
- local storage;
- server logs;
- security software;
- Shopify technology;
- analytics technology; and
- similar technologies.
4.3 From service providers
We may receive information from providers that help us operate our business, such as:
- Shopify;
- payment providers;
- delivery and fulfilment providers;
- IT and hosting providers;
- analytics providers;
- marketing and email providers;
- customer service providers;
- security and fraud prevention providers; and
- professional advisers.
4.4 From partners and other third parties
We may receive personal data from:
- business partners;
- publicly accessible sources;
- social media platforms;
- event organisers;
- organisations you represent; and
- other parties where you have authorised the disclosure or where the disclosure is otherwise permitted by law.
5. Purposes and legal bases for processing
We only process personal data where there is an appropriate legal basis.
5.1 Providing products and services
We process personal data to:
- process and fulfil orders;
- provide products and services;
- process payments;
- send order and account notifications;
- arrange delivery;
- manage returns, exchanges and refunds;
- maintain customer accounts;
- provide customer support;
- respond to enquiries;
- prepare quotations;
- perform agreements;
- administer our business relationship; and
- provide information you have requested.
The legal basis is generally that processing is necessary to enter into or perform an agreement with you.
5.2 Operating and improving our websites and store
We process personal data to:
- operate our websites and online store;
- remember your preferences;
- maintain shopping cart functionality;
- improve navigation and functionality;
- analyse website and store performance;
- understand how our Services are used;
- test and develop new functions;
- personalise parts of the shopping experience; and
- diagnose and resolve technical issues.
Depending on the processing, the legal basis is our legitimate interest in operating and improving our Services or your consent where consent is legally required.
5.3 Customer service and communications
We process personal data to:
- communicate with you;
- answer questions;
- provide support;
- handle complaints;
- send administrative or transactional messages;
- notify you of changes affecting our products, Services or policies; and
- maintain our business relationship.
The legal basis is the performance of an agreement, taking steps at your request before entering into an agreement, or our legitimate interest in communicating effectively with customers and business contacts.
5.4 Marketing
We may process personal data to:
- send newsletters;
- inform you about products, services, events, news and articles;
- send promotional communications;
- measure the effectiveness of our communications;
- tailor communications to your interests; and
- display advertising where permitted.
Where required by law, we will obtain your consent before sending electronic marketing communications or using marketing cookies.
You can withdraw your consent or unsubscribe at any time by using the unsubscribe link in our emails or contacting us.
Withdrawing consent does not affect the lawfulness of processing carried out before consent was withdrawn.
Even after you unsubscribe from marketing communications, we may still send necessary non-promotional communications relating to an account, order, agreement, security issue or customer service request.
5.5 Security and fraud prevention
We process personal data to:
- protect our websites, online store and systems;
- authenticate users;
- prevent unauthorised access;
- detect and investigate fraud;
- identify malicious or unlawful activity;
- prevent misuse;
- enforce our terms and policies;
- protect our customers, employees and business partners; and
- maintain the security and integrity of our Services.
The legal basis is our legitimate interest in protecting our organisation, systems, users and Services. In some cases, processing may also be necessary to comply with a legal obligation.
5.6 Legal and administrative obligations
We may process personal data to:
- maintain financial and tax records;
- comply with statutory retention requirements;
- comply with court orders or lawful requests;
- respond to regulators, supervisory authorities or law enforcement;
- establish, exercise or defend legal claims;
- investigate disputes;
- enforce agreements; and
- comply with other legal obligations.
The legal basis is compliance with a legal obligation or our legitimate interest in protecting and exercising our legal rights.
6. Shopify
Our online store is hosted by Shopify.
Information you submit through the online store is transmitted to and processed using Shopify’s systems. This may include contact details, account details, device information, usage information, order information, transaction information and limited payment information.
Shopify processes personal data to provide and maintain its e-commerce platform, facilitate transactions, protect the platform, prevent fraud and provide features used by our store.
For many processing activities, Shopify acts as a processor or service provider on behalf of Grid to Great. In those situations, Grid to Great determines the purposes of the processing and is the primary contact for requests concerning your personal data.
For some Shopify services and features, Shopify may process personal data for its own purposes and act as an independent controller. This may apply, for example, where you use a service for which you have a direct relationship with Shopify, or where Shopify uses data to operate, secure or improve its own services in accordance with its privacy documentation.
More information about Shopify’s processing of personal data, privacy controls and data subject requests is available in the Shopify Privacy Policy and through Shopify’s Privacy Portal.
7. Sharing personal data
We do not sell personal data for monetary consideration.
We may share personal data where necessary with trusted third parties that assist us in providing and operating our Services.
These parties may include:
- Shopify;
- payment service providers;
- banks and financial institutions;
- fulfilment, printing and delivery providers;
- postal and courier services;
- IT and cloud service providers;
- hosting providers;
- domain name registries;
- website and application providers;
- email and marketing platforms;
- analytics providers;
- security and fraud prevention providers;
- customer support providers;
- accountants, auditors, insurers and legal advisers;
- government agencies, regulators and courts; and
- other service providers necessary to fulfil an agreement with you.
Where possible, service providers acting on our behalf may only process personal data according to our documented instructions, applicable agreements and data protection legislation.
Certain recipients, such as banks, payment providers, tax authorities, courts and professional advisers, may act as independent controllers and process personal data in accordance with their own legal responsibilities and privacy policies.
We may also share personal data:
- where you direct or authorise us to do so;
- where disclosure is necessary to provide a requested service;
- to comply with a legal obligation;
- in response to a valid court order or lawful government request;
- to investigate suspected fraud or unlawful conduct;
- to protect the rights, safety and property of Grid to Great or others; or
- in connection with a merger, acquisition, restructuring, sale of assets, insolvency or similar corporate transaction.
- 8. Cookies and similar technologies
Our websites and online store use cookies and similar technologies.
A cookie is a small text file placed on your device when you visit a website. Cookies allow websites to recognise a device, remember preferences, maintain a shopping cart, process checkout activity and collect information about website use.
We may use the following categories of cookies.
8.1 Strictly necessary cookies
These cookies are required for essential functions, such as:
- loading and securing the website;
- maintaining a shopping session;
- remembering shopping cart contents;
- processing checkout activity;
- authenticating an account;
- detecting fraud; and
- remembering privacy or cookie choices.
These cookies cannot always be disabled through our website because the Services may not function properly without them.
8.2 Preference cookies
These cookies remember choices such as language, location, account preferences or other settings.
8.3 Analytics cookies
Subject to consent where required, we may use analytics cookies to understand how visitors use our websites and online store.
This may include Shopify analytics and Google Analytics where enabled. Analytics information helps us improve navigation, content, products, performance and functionality.
Where possible, we configure analytics services in a privacy-conscious manner, including by limiting data collection and retention. However, third-party analytics providers may process information in accordance with their own privacy documentation.
8.4 Marketing cookies
Subject to consent where required, we and our marketing partners may use cookies, pixels and similar technologies to:
- measure advertising effectiveness;
- understand which campaigns led to visits or purchases;
- personalise marketing;
- build audiences; and
- display advertising on our Services or other websites.
- You can manage non-essential cookie preferences through the cookie banner or cookie settings available on our website.
Refusing or withdrawing consent for non-essential cookies will not prevent you from accessing the basic website, but certain functions or personalisation features may be limited.
Browser settings may also allow you to delete or block cookies. Blocking all cookies may affect the operation of the online store.
9. Web server log files
Our web servers maintain log files to:
- identify and resolve technical problems;
- maintain website security;
- detect and prevent abuse;
- analyse system performance; and
- understand network capacity.
Log files may include:
- your IP address;
- the requested page or resource;
- the date and time of the request;
- browser information;
- device or network information; and
- technical response information.
Log files do not normally contain information entered into website forms.
Unless an incident, investigation or legal obligation requires longer retention, standard web server logs are automatically deleted after approximately one month.
Access is limited to authorised Grid to Great personnel and relevant hosting or IT service providers.
10. Firewall and website security
We use firewall and security technology to protect our website against vulnerabilities, malicious requests, repeated unauthorised login attempts and other forms of misuse.
Our security tools may record:
- your IP address;
- the request submitted;
- the date and time;
- attempted login or access information; and
- other technical security information.
Routine firewall records are generally stored for one day.
Where suspected misuse or a security incident is detected, information may be retained for longer. An IP address may be temporarily blocked. In cases of repeated or serious abuse, the block may be extended or made permanent where this is reasonably necessary to protect our Services.
Security providers may maintain temporary threat or abuse lists. As a result, an IP address associated with repeated abuse may also be blocked from other websites using the same security provider.
11. Email communications and tracking
Where legally permitted, emails sent by us may contain technology that records whether a message was delivered, opened or interacted with.
We use this information to:
- determine whether communications are functioning;
- measure engagement;
- improve our content;
- tailor communications; and
- identify which information may be relevant to recipients.
Where consent is required, we will only use such tracking after receiving consent.
You may unsubscribe from promotional emails at any time. When you unsubscribe, we may retain your email address on a suppression or unsubscribe list. This is necessary to ensure that we respect your preference and do not add the email address to future marketing campaigns.
You may contact us if you want to object to other forms of email tracking or request deletion of associated information, subject to applicable legal exceptions.
We cannot guarantee that emails or other electronic communications sent to us will always be received or processed immediately. We are not liable for consequences caused solely by a message not being received or being processed later than expected, except where liability cannot legally be excluded.
12. Third-party websites and integrations
Our Services may contain links to websites, platforms or services operated by third parties.
We are not responsible for the privacy, security, accuracy or content of third-party services that are not controlled by Grid to Great.
Third-party services may collect personal data independently and apply their own privacy policies and terms. We recommend reviewing those policies before providing personal data.
The inclusion of a link or integration does not necessarily mean that Grid to Great endorses the relevant third party.
Information you publish through public or semi-public functions, including social media platforms, may be visible to other users and may be further used or shared by those users.
13. International transfers
Some of our service providers, including Shopify and certain cloud, IT, analytics, marketing or payment providers, may process personal data outside the European Economic Area.
Countries outside the European Economic Area may not always provide the same level of data protection as countries within the European Economic Area.
Where personal data is transferred internationally, we use an applicable transfer mechanism where required, such as:
- an adequacy decision adopted by the European Commission;
- the European Commission’s Standard Contractual Clauses;
- binding corporate rules;
- contractual protections approved under applicable legislation; or
- another legally recognised transfer mechanism.
Shopify may process information through entities and service providers located in countries including Ireland, Canada and the United States. Shopify states that it uses applicable legal safeguards for transfers outside the European Economic Area.
You may contact us for additional information about the safeguards applicable to a particular transfer.
14. Security
We use appropriate technical and organisational measures to protect personal data against:
- loss;
- unauthorised access;
- alteration;
- disclosure;
- destruction;
- misuse; and
- other unlawful processing.
These measures may include access controls, encryption, authentication, monitoring, firewalls, backups, supplier agreements and organisational security procedures.
Access to personal data is limited to employees and service providers that need the information to perform their duties.
No security measure or method of transmission over the internet is completely secure. We therefore cannot guarantee absolute security.
You are responsible for protecting account credentials and should not share passwords or access details with others. Please contact us immediately if you suspect unauthorised access to your account or personal data.
15. Retention of personal data
We do not retain personal data longer than necessary for the purposes for which it was collected, unless longer retention is required or permitted by law.
The applicable retention period depends on factors such as:
- the nature and sensitivity of the personal data;
- the purpose for which it was collected;
- whether an account or business relationship remains active;
- the duration of an agreement;
- legal, tax and accounting obligations;
- warranty or limitation periods;
- the need to resolve disputes;
- fraud and security risks; and
- the establishment, exercise or defence of legal claims.
In general:
- account information is retained while the account is active and for an appropriate period afterwards;
- order and customer information is retained as necessary to fulfil orders, provide support and comply with legal obligations;
- financial and administrative records are retained for the applicable statutory period;
- marketing information is retained until you unsubscribe, withdraw consent or object, unless limited retention remains necessary to record your preference;
- support correspondence is retained as long as reasonably necessary to handle the request and maintain appropriate records;
- routine server logs are generally deleted after approximately one month;
- routine firewall records are generally deleted after one day, unless misuse or an incident requires longer retention; and
- information relevant to a dispute, investigation or legal claim may be retained until the matter and applicable limitation periods have ended.
- When personal data is no longer required, we delete, anonymise or securely archive it in accordance with our retention procedures.
16. Children’s data
Our Services are not directed specifically at children under the age of 16, and we do not knowingly collect personal data from children under 16 without the required permission.
If you are a parent or guardian and believe that a child has provided personal data to us, please contact us. Where appropriate, we will take steps to delete the information.
17. Your privacy rights
Subject to the conditions and exceptions in applicable law, you may have the following rights.
17.1 Right to information
You have the right to receive clear information about how we process your personal data.
17.2 Right of access
You may request confirmation of whether we process personal data about you and request access to that data.
17.3 Right to rectification
You may request that inaccurate personal data be corrected and that incomplete personal data be completed.
17.4 Right to erasure
You may request deletion of your personal data in certain circumstances.
The right to erasure is not absolute. We may retain information where processing remains necessary, for example to:
- comply with legal or administrative obligations;
- maintain financial records;
- establish, exercise or defend legal claims;
- prevent fraud;
- protect the rights of others; or
- perform another processing activity permitted by law.
17.5 Right to restriction
You may request that we temporarily or permanently restrict certain processing, for example while the accuracy or lawfulness of the processing is being assessed.
17.6 Right to object
You may object to processing based on our legitimate interests.
When you object, we will stop the relevant processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or unless processing is necessary for legal claims.
You have an absolute right to object to the use of personal data for direct marketing. When you object to direct marketing, we will stop using your personal data for that purpose.
17.7 Right to data portability
Where processing is based on consent or an agreement and is carried out by automated means, you may have the right to receive personal data you provided to us in a structured, commonly used and machine-readable format.
Where technically feasible, you may also request that we transfer the data directly to another controller.
17.8 Right to withdraw consent
Where processing is based on consent, you may withdraw that consent at any time.
Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
17.9 Rights concerning automated decisions
Where applicable, you may have rights relating to decisions based solely on automated processing that produce legal or similarly significant effects.
17.10 Right to complain
You have the right to lodge a complaint with a competent data protection supervisory authority.
In the Netherlands, the supervisory authority is:
Autoriteit Persoonsgegevens
The Dutch Data Protection Authority
You may find its current contact information through the official website of the Autoriteit Persoonsgegevens.
We encourage you to contact us first so that we have an opportunity to address your concerns.
18. Exercising your rights
You can exercise your privacy rights free of charge by contacting us at:
Grid to Great B.V.
Subject: Privacy
Hengelosestraat 500
7521 AN Enschede
The Netherlands
Email: info@gridtogreat.com
Telephone: +31 (0)88 1660 100
Please describe your request clearly and state which right you want to exercise.
We may request additional information where reasonably necessary to verify your identity. This is intended to prevent personal data from being disclosed, changed or deleted at the request of an unauthorised person.
Do not send a copy of an identity document by ordinary email unless we specifically request it and provide an appropriately secure method. Where identity verification is required, we will seek to use a proportionate method and collect no more information than necessary.
We normally respond within one month after receiving a complete request. Where permitted by law, this period may be extended if a request is complex or if we receive multiple requests. If an extension is necessary, we will inform you and explain the reason.
There may be circumstances in which we cannot fully comply with a request. Where this occurs, we will explain the applicable reason, unless the law prevents us from doing so.
19. Keeping your information up to date
We ask that you keep your personal data accurate and current.
You may update certain account information directly through your account, where this functionality is available. You may also contact us by email or post to notify us of changes.
20. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect:
- changes to our Services;
- changes to our processing activities;
- operational developments;
- new technologies;
- changes to service providers; or
- legal or regulatory requirements.
The revised policy will be published on our website with an updated “Last updated” date.
Where required by law, we will provide additional notice or request renewed consent.
We recommend reviewing this Privacy Policy periodically.
21. Contact
For questions, requests or complaints concerning this Privacy Policy or our handling of personal data, please contact:
Grid to Great B.V.
Attn: Privacy
Hengelosestraat 500
7521 AN Enschede
The Netherlands
Email: info@gridtogreat.com
Telephone: +31 (0)88 1660 100