Privacy Policy
How Nørreport Clothing handles your data.
Last updated: 1 August 2026
Who is responsible
Nørreport Clothing, Lyngbyvej 15, 9520 Skørping, Denmark, is responsible for the personal data described here. For privacy requests, contact isarsindri@icloud.com.
What we collect
When you join early access, we collect your email address, optional name, shopping interest, consent timestamp, and signup source. If you create a customer account, we collect your name, email address, password hash, privacy acknowledgement timestamp, and account session information. During checkout, Stripe collects payment, shipping, billing, and phone details. We do not receive or store raw card numbers.
Why we use it
We use early-access details to send the marketing updates you opt into. We use customer account details to provide account and checkout functionality. We use order details to complete purchases, provide customer support, prevent abuse, and meet legal obligations. Our legal bases are consent for marketing, contract performance for accounts and purchases, and legitimate interests for security.
What is required
An email address and marketing consent are required to join early access. An email address, name, password, and privacy acknowledgement are required to create an account. Checkout details requested by Stripe are required to process and deliver an order. Optional shopping interests are used only to make future launch messages more relevant; you can join without selecting a specific category.
Service providers
We use Cloudflare for hosting, database, network security, rate limiting, and Turnstile bot checks; Stripe for payment and checkout services; and Resend or Cloudflare Email Service for transactional email delivery. These providers process data only as needed to provide their services. We may also disclose information where required by law or where necessary to establish, exercise, or defend legal claims.
Cookies, security, and technical data
Essential cookies are used to keep signed-in customer and administrator sessions secure. The storefront also stores the contents of your cart in your browser. We currently use first-party aggregate counters for product views and add-to-cart actions without advertising cookies or cross-site tracking. Our hosting and security provider may process request information such as an IP address, browser details, timestamps, and security signals to deliver the site, apply rate limits, and detect abuse. Rate-limit identities are stored as salted hashes for a limited cleanup period. We use technical and organisational safeguards appropriate to the data we hold, including restricted dashboard access, password hashing, encrypted connections, and server-side validation. No online service can guarantee absolute security.
International processing
Some service providers may process data outside Denmark or the European Economic Area. Where that happens, the provider is expected to use a lawful transfer mechanism and appropriate safeguards, such as an adequacy decision or standard contractual clauses. Provider privacy documentation may contain more detail about its locations and subprocessors.
How long we keep data
Early-access records are kept until you unsubscribe, withdraw consent, or the list is no longer needed, with periodic review for inactive records. Customer accounts are monitored for authenticated activity: accounts used within the last 365 days remain active; around 335 days of inactivity, we send a warning and allow a further 30 days to sign in. If the account is still inactive, we email an export of the account information and previous orders before deleting the account. Order records may be retained in anonymised form where needed for fulfilment, support, disputes, bookkeeping, tax, or other legal obligations. Password-reset links expire after 30 minutes and can be used only once. Signed customer sessions normally expire after 30 days and administrator sessions after eight hours. Temporary abuse-prevention records are deleted after their rate-limit window and cleanup period.
Your rights
Depending on where you live, you may have privacy rights including access, correction, deletion, restriction, objection, and a copy of information you supplied. You may unsubscribe from marketing or withdraw consent at any time by using an unsubscribe link or contacting us; withdrawal does not affect processing that was lawful before withdrawal. We may need to verify your identity before completing a request.
Automated decisions
Shopping-interest selections may be used to group early-access messages, but we do not use the information covered by this policy to make solely automated decisions that produce legal or similarly significant effects.
Questions and complaints
Contact us first if you have a question about this policy or how your information is handled. You also have the right to complain to the Danish Data Protection Agency, Datatilsynet, or the data-protection authority where you live or work. Visit Datatilsynet's complaint guidance for contact and filing information. We may update this policy when the store, service providers, or legal requirements change; the date at the top identifies the current version.