Legal · Privacy Policy
Privacy Policy
This policy explains what personal data Navicrux collects, why, who we share it with, and the rights you have under the EU General Data Protection Regulation (GDPR) and the Dutch implementation (UAVG).
Last updated · 5 August 2026
01Who we are (controller)
Navicrux is registered in the Netherlands with the Chamber of Commerce (KVK) under number 42131912, established in Haarlem, the Netherlands (VAT / BTW: NL005520365B91). For questions about this policy or your data, contact us at operations@navicrux.com.
02Our roles: controller and processor
For personal data about our Merchants and their staff (account and billing data), Navicrux acts as a controller. For personal data that a Merchant provides so that we can fulfil their orders — for example their End Customers' names and shipping addresses — Navicrux acts as a processoron the Merchant's behalf, under a data processing agreement. In that case, the Merchant is the controller and is responsible for having a lawful basis to share that data with us.
03Personal data we collect
- Account data — name, business name, email, phone, role, and login identifiers (authentication is handled by our identity provider).
- Business & billing data — company details, VAT/tax identifiers, Wallet balance and transaction history. Card and bank details are handled by our payment provider (Mollie); we do not store full payment credentials.
- Fulfillment data — order details and End Customer information needed to ship Goods (name, delivery address, and where required for customs, contact details and item data). We process this as the Merchant's processor.
- Integration data — data from services you connect, such as your Shopify store (products, orders, store profile).
- Technical & usage data — IP address, device/browser information, log data, and how you use the Service, collected to operate and secure it.
04Why we use it & our legal bases
- To provide the Service — performance of our contract with you (Art. 6(1)(b) GDPR).
- To fulfil and ship orders — performance of the contract and, for End Customer data, on the Merchant's instructions as processor.
- To secure, improve and support the Service, and prevent fraud/abuse — our legitimate interests (Art. 6(1)(f)).
- To comply with law — including tax, accounting, customs, and anti–money-laundering/sanctions obligations (Art. 6(1)(c)).
- Marketing communications — only with your consent or on the basis of an existing business relationship, and you can opt out at any time.
05Who we share data with
We share personal data only as needed to run the Service, with categories of recipients including:
- Fulfillment Partners and carriers — to store, pick, pack, ship, and clear Goods through customs.
- Payment provider (Mollie) — to process Wallet top-ups.
- Technology providers — hosting, identity/authentication, database, and analytics providers that operate the platform on our behalf as sub-processors.
- Connected platforms you authorise, such as Shopify.
- Professional advisers and authorities — where required by law, or to establish, exercise or defend legal claims.
We do not sell your personal data.
06International transfers
Because fulfillment involves suppliers and warehousing outside the European Economic Area (including China and Hong Kong), some personal data — principally shipping details needed to deliver Goods — may be transferred internationally. Where we do this, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, and limit the data to what is necessary for delivery and customs.
07How long we keep data
We keep personal data only as long as needed for the purposes above and to meet legal obligations. Accounting and transaction records are retained for the statutory period (in the Netherlands, generally seven years). When data is no longer needed, we delete or anonymise it. As a processor, we handle Merchants' End Customer data according to the Merchant's instructions and our agreement.
08How we protect data
We use appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, and least-privilege practices. No system is perfectly secure, but we work to protect your data and to notify you and the relevant authority of a personal-data breach where required.
09Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased in certain circumstances;
- restrict or object to certain processing;
- data portability;
- withdraw consent at any time, where processing is based on consent.
To exercise these rights, contact operations@navicrux.com. Where we act as a processor for a Merchant, we will refer your request to that Merchant (the controller). You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl) or your local supervisory authority.
10Cookies & similar technologies
We use only strictly necessary cookies — those required to operate the Service and keep you securely signed in. These do not require consent under EU law. We do not use advertising or third-party tracking cookies. If we introduce analytics or other non-essential cookies in future, we will ask for your consent first and update this policy accordingly.
11Children
The Service is for businesses and is not directed to children. We do not knowingly collect data from anyone under 16.
12Changes to this policy
We may update this policy. We will post the new version with an updated date and, for material changes, take reasonable steps to notify you.
13Contact
For privacy questions or requests, contact operations@navicrux.com, or write to us at our registered office in Haarlem, the Netherlands (full registered address on file with the Dutch Chamber of Commerce). You can also reach us via our contact page.