Privacy Policy
This Privacy Policy explains what personal data The Resell Lab(“we”, “us”, “our”) collects when you use this site, why, and what rights you have over it, in line with the EU General Data Protection Regulation (GDPR) and the Danish Data Protection Act.
1. Who we are
The Resell Lab ([COMPANY INFO — legal name, CVR number, and address]) is the data controller responsible for your personal data described in this policy.
2. What data we collect
When you make a purchase, we (via our payment processor, Stripe) collect your email address and payment details, and Stripe processes your card information directly — we never see or store your full card number. We also automatically receive standard technical data (such as IP address and browser type) through our hosting provider, Netlify, as part of normal web traffic logging. We do not use tracking cookies or analytics on this site beyond what Stripe and Netlify require to process payments and serve pages.
3. Why we collect it and our legal basis
We use your email address to deliver your purchased supplier link and any order-related communication. This processing is necessary to perform the contract formed when you complete a purchase (GDPR Article 6(1)(b)). Technical/log data is processed under our legitimate interest in keeping the site secure and functioning (GDPR Article 6(1)(f)).
4. Who we share it with
We share data with the third parties needed to run this service: Stripe (payment processing) and Netlify (hosting and serverless functions). Both may process data outside the EU/EEA under their own applicable safeguards (such as the EU Standard Contractual Clauses). We do not sell your personal data, and we do not share it with any supplier linked from this site — suppliers never receive your information from us.
5. How long we keep it
We retain order and payment records for as long as required by Danish bookkeeping law (currently five years from the end of the relevant financial year), and delete or anonymize other data once it is no longer needed for the purposes above.
6. Your rights
Under GDPR, you have the right to request access to, correction of, or deletion of your personal data, to object to or restrict certain processing, and to receive your data in a portable format. You also have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet, www.datatilsynet.dk) or your own country’s data protection authority. To exercise any of these rights, contact us using the details below.
Questions or requests regarding your data? Contact us at [CONTACT EMAIL].