Privacy Policy

Last updated: November 21, 2025

This Privacy Policy (“Policy”) explains how Tirisi Online B.V. (“Tirisi”, “we”, “us”, “our”) collects, uses, shares, and protects your Personal Information when you visit tirisi.com (the “Website”) and use any related features or services (the “Services”).

Tirisi Online B.V. is the Data Controller.
Tirisi Jewelry B.V. acts as Joint Controller for all data processed within the Tirisi Group.

By using the Website or providing information to us, you agree to this Policy.

1. Automatic collection of information

When you visit the Website, our servers automatically collect data such as:

  • IP address
  • Browser type/version
  • Operating system
  • Device details
  • Language settings
  • Pages visited and time spent
  • Referring pages
  • General location (based on IP)
  • Access dates and times

This information helps us detect abuse, improve performance, and maintain security.

2. Collection of personal information

To use certain features, you may provide:

  • Name and contact information
  • Delivery and billing details
  • Account details (username, password)
  • Payment information (handled by Stripe)
  • Order history
  • Product registration details
  • IP address and device identifiers
  • Any messages or files you submit

You may choose not to provide information, but some functionality may not work.

3. Privacy of children

We do not knowingly collect data from individuals under 18.
If you believe we have received such data, contact us at info@tirisi.com.

4. Legal basis for processing

We process your Personal Information under:

Contract

To process orders, deliver products, manage your account, or provide support.

Legal Obligation

Including Dutch tax law and Wwft (AML/KYC) requirements.

Consent

For marketing emails and non-essential cookies.

Legitimate Interest

For fraud prevention, service improvement, security monitoring, and internal analytics.

5. Payment processing (Stripe)

Payments are handled by Stripe, a PCI-compliant provider.
We do not store or access your full card details.

Stripe Privacy: https://stripe.com/privacy

6. AML / KYC compliance

For certain high-value orders, we may request identification documents to comply with Dutch Wwft regulations.
These are kept 5 years, as required by law.

7. Use of personal information

We use your information to:

  • Process and deliver orders
  • Maintain your account
  • Provide customer support
  • Send confirmations and service updates
  • Send marketing communications (only with consent)
  • Improve the Website
  • Detect and prevent fraud
  • Comply with legal obligations
  • Personalize your experience

8. Sharing of information

We do not sell Personal Information.

We only share it when necessary to operate the Website, deliver orders, comply with the law, or provide support.

8.1 Tirisi Group (Joint Controllers)

Your information is shared between:

Tirisi Online B.V. — Data Controller
Tirisi Jewelry B.V. — Joint Controller

Both follow this Policy.

8.2 External Service Providers

We share limited data with trusted partners:

Hosting & Technical Infrastructure

  • SiteGround — hosting, backups, security

E-commerce Platform

  • WooCommerce (Automattic)

Backend System

  • XCore

Customer Service

  • Gorgias — support communications

Internal Operations

Email Marketing

  • ActiveCampaign — newsletters, automation
    (only for users who opted in)

Accounting & Tax

  • Exact — invoicing and compliance

Shipping & Logistics

  • FedEx — delivery, tracking

Warehouse Scanning

All service providers act as Data Processors.

9. Analytics and marketing tools

Used only after consent via CookieYes:

  • Google Analytics 4
  • Google Tag Manager
  • Meta Pixel (Facebook/Instagram)
  • TikTok Pixel
  • Pinterest Tag
  • LinkedIn Insight Tag
  • Hotjar

10. Data transfers outside the EU

Some providers operate outside the EU/EEA (e.g., Stripe, Meta, Google).
When they process data, they use:

  • Standard Contractual Clauses (SCCs)
  • or equivalent safeguards

We ensure EU-level protection always applies.

11. Retention of information (Dutch Law)

We keep Personal Information only as long as necessary or as required by law.

Legally Required (Netherlands)

  • Orders, payments, invoices: 7 years (Belastingdienst)
  • AML/KYC (high-value purchases): 5 years (Wwft)

Operational Retention

  • Customer accounts: as long as active, deleted after 2 years of inactivity
  • Customer service emails: 2 years
  • Product registrations: warranty period + 2 years
  • Marketing email consent: 5 years after last interaction
  • Unsubscribe records: indefinitely (to avoid emailing you again)
  • Analytics data: up to 14 months (GA4 default)
  • Cookie consent logs (CookieYes): 12 months
  • Security logs: 6–12 months

After these periods, data is deleted or anonymized.

12. Your GDPR rights

You may request:

  • Access
  • Correction
  • Deletion
  • Restriction
  • Objection
  • Data portability
  • Withdrawal of consent

Email: info@tirisi.com

You may also contact the Autoriteit Persoonsgegevens.

13. CCPA rights (California residents)

You may request:

  • Disclosure of collected information
  • Deletion
  • Disclosure of third-party sharing

We do not sell Personal Information.

14. Cookies

We use cookies for essential functionality, analytics, and marketing.
Consent is managed by CookieYes.

Essential Cookies

Required for checkout, login, and site security.
Always active.

Analytics Cookies (consent-based)

GA4, Hotjar, Pinterest, LinkedIn.

Marketing Cookies (consent-based)

Meta, TikTok, Pinterest, Google Ads.

You may change your preferences anytime through the cookie banner.

15. Social media features

If you interact with social buttons (Instagram, Facebook, Pinterest, etc.), those providers may collect certain data according to their own policies.

16. Email marketing

If you subscribe:

  • ActiveCampaign sends newsletters and promotions
  • You can unsubscribe anytime
  • Transactional emails (order confirmations, service messages) will still be sent

ActiveCampaign Privacy: https://www.activecampaign.com/legal/privacy-policy

17. Push notifications

Optional.
You can disable them from your device settings.

18. Security

We apply multiple layers of protection:

  • Encrypted data transmission
  • Firewalls and server hardening
  • Secure hosting infrastructure
  • Access control
  • Monitoring and logging
  • Regular backups
  • Privacy training for staff

No system is perfect, but we take reasonable steps to protect your information.

19. Data breach

If a breach occurs that may affect your rights, we will notify you and authorities when legally required.

20. External links

We are not responsible for the privacy practices of websites we link to.

21. Changes to this policy

We may update this Policy periodically.
The revised version becomes effective upon publication on this page.

22. Acceptance of this policy

By using the Website, you confirm your acceptance of this Policy.

Contacting us

If you have questions, concerns, or requests about your Personal Information, you may contact us at:

Tirisi Online B.V.
Lemelerbergweg 42
1101 AM Amsterdam
The Netherlands
Email: info@tirisi.com

© 2026 Tirisi Jewelry B.V. All rights reserved.