Privacy policy

Privacy Policy — Bunny Mansions

Last updated: 19 May 2026

This Privacy Policy explains how Bunny Mansions ("we", "us", "our") collects, uses, stores and shares personal data when you visit, use or purchase from bunnymansions.com (the "Site"), or when you otherwise communicate with us (together, the "Services").

We are the data controller for the personal data described in this Privacy Policy, unless stated otherwise.

We are not required to appoint a Data Protection Officer under Article 37 GDPR. For any privacy-related questions, please contact us using the details below.

Contact details Bunny Mansions Michiel de Ruyterweg 208 2628 BA Delft The Netherlands Email: info@bunnymansions.nl

Please read this Privacy Policy carefully. If you do not agree with how we handle your personal data, please do not use the Site.

1. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our business, our Services, our use of service providers, or legal and regulatory requirements.

When we update this Privacy Policy, we will publish the updated version on the Site and change the "Last updated" date above. If we make significant changes that materially affect how we use your personal data, we will give you reasonable advance notice where appropriate and, where required by law, ask for your consent again.

2. What personal data we collect

We collect personal data in different ways, depending on how you use our Services.

2.1 Information you give us directly

Contact information Name, email address, phone number, billing address and shipping address.

Order information Products purchased, order history, payment confirmation, delivery details, returns, exchanges and related customer service information.

Account information Username, login credentials protected through appropriate technical security measures by our ecommerce platform, account preferences and account history.

Shopping behaviour on our Site Products viewed, items added to your cart, wishlists, gift card use and similar shopping activity.

Customer support information The content of messages you send to us, including messages sent by email, contact form, Shopify Inbox chat, social media or other communication channels.

Marketing preferences Whether you have subscribed to our newsletter, your language preference, email preferences and any other preferences you have indicated.

Reviews If you choose to submit a review through our review platform, we may process your name, review content, rating, order reference and related review information.

2.2 Information we collect automatically

When you use the Site, we may automatically collect certain information through cookies and similar technologies. Non-essential tracking is only activated after you consent through our cookie banner.

This may include:

Usage data Pages visited, time spent on the Site, links clicked, products viewed, referring URL and similar information about how you use the Site.

Device and browser data Device type, operating system, browser type, screen resolution and similar technical information.

Network data IP address, approximate location based on IP address, internet service provider and related technical information.

Cookie, pixel and tracking data Information collected through cookies, pixels, tags and similar technologies, as explained in section 7 of this Privacy Policy.

2.3 Information from third parties

We may receive personal data from third parties that help us provide, improve, market and secure our Services. These include:

Shopify Our ecommerce platform, which supports hosting, checkout, order management, customer accounts, customer support (Shopify Inbox) and related ecommerce services. Depending on the specific Shopify service used, Shopify may act as our processor or as an independent controller, as described in Shopify's own privacy documentation.

Payment processors Payment providers help process payments, refunds and fraud checks. Depending on the payment method selected, this may include providers for iDEAL, credit cards, PayPal or other payment options.

Shipping and fulfilment partners Shipping carriers and fulfilment partners help us deliver your order and confirm delivery.

Judge.me Our review platform, which helps us request, collect, manage and display customer reviews.

Google Provides analytics and advertising services through Google Analytics and Google Ads.

Meta Provides advertising and measurement services for Facebook and Instagram.

WeTracked Provides server-side conversion tracking and attribution.

Klaviyo Our email service provider, which manages newsletter subscriptions, customer segmentation, email flows and marketing emails.

3. How we use your personal data and our legal basis

Under the General Data Protection Regulation (GDPR), and for direct marketing also under the Dutch Telecommunications Act (Telecommunicatiewet, Article 11.7), we need a legal basis for every use of your personal data.

We may use your personal data for the following purposes:

Purpose

Data used

Legal basis

Processing your order, payment, shipping, returns and exchanges

Contact data, order data, payment confirmation, shipping data

Performance of a contract, Article 6(1)(b) GDPR

Creating and managing your customer account

Account data, contact data, order history

Performance of a contract, Article 6(1)(b) GDPR

Providing customer support

Contact data, order data, support messages

Legitimate interest, Article 6(1)(f) GDPR

Sending newsletters, promotions and product updates

Email address, name, marketing preferences, engagement data

Consent, Article 6(1)(a) GDPR and Article 11.7 Telecommunicatiewet

Sending product-related emails about our own similar products to existing customers

Email address, order history

Legitimate interest under the soft opt-in rule, Article 6(1)(f) GDPR and Article 11.7(3) Telecommunicatiewet

Inviting you to leave a product review

Name, email address, order data

Consent, collected at checkout

Displaying reviews you submit

Review content, rating, display name, product purchased where relevant

Consent, Article 6(1)(a) GDPR

Improving our Site and Services

Usage data, order trends, support feedback

Legitimate interest, Article 6(1)(f) GDPR

Fraud prevention and Site security

Account data, usage data, network data, technical data

Legitimate interest, Article 6(1)(f) GDPR

Analytics through Google Analytics

Cookie data, usage data, device data

Consent through our cookie banner, Article 6(1)(a) GDPR

Advertising and conversion tracking through Google Ads, Meta and WeTracked

Cookie data, pixel data, event data, advertising identifiers

Consent through our cookie banner, Article 6(1)(a) GDPR

Keeping unsubscribed email addresses on a suppression list

Email address

Legitimate interest, Article 6(1)(f) GDPR — to make sure we do not accidentally email you again

Complying with legal obligations, including tax and accounting obligations

Order data, invoice data, payment data

Legal obligation, Article 6(1)(c) GDPR

Handling legal claims or disputes

Relevant order, payment, communication and support data

Legitimate interest, Article 6(1)(f) GDPR

 

4. Marketing emails — your consent matters

This section explains our marketing email practices in detail because it is one of the most important parts of this Privacy Policy.

4.1 Newsletter and promotional emails

We only send newsletter and promotional emails if you have actively given consent, for example by signing up through our newsletter form, popup or by ticking a marketing opt-in checkbox at checkout. We do not use pre-ticked consent boxes. Each consent is recorded with the date, source and form wording used at the time.

4.2 Soft opt-in for existing customers

If you have purchased a product from us, we may email you about our own similar rabbit-care products under the soft opt-in rule in Article 11.7(3) of the Dutch Telecommunicatiewet. This applies only if:

  • Your email address was collected in the context of a sale;

  • You were given a clear, easy opportunity to opt out at the moment your email was collected; and

  • Every marketing email afterwards includes a clear, easy way to opt out.

4.3 Review requests

When you place an order and consent to receiving a review request, we may invite you to leave a review through Judge.me. You can opt out of review request emails at any time using the unsubscribe link in the email.

4.4 How to unsubscribe

You can unsubscribe at any time by:

  • Clicking the unsubscribe link in any email we send you; or

  • Emailing info@bunnymansions.nl with the subject line "Unsubscribe".

Withdrawing consent does not affect any processing we carried out before you withdrew it. After you unsubscribe, we keep your email address on a suppression list so that we do not accidentally email you again. This suppression data is not used for marketing.

5. Who we share your personal data with

We share personal data only where necessary to provide our Services, operate our business, comply with legal obligations, or protect our legitimate interests. We do not sell your personal data for monetary consideration.

Note for California residents and other US visitors: under California law (CCPA/CPRA), sharing data with advertising partners such as Google and Meta for targeted advertising may be considered "sharing" or "selling." You can opt out of all such sharing at any time by rejecting Targeting cookies in our cookie banner or by changing your cookie preferences through the link in our footer. See section 13 for more on US-specific rights.

We may share personal data with the following recipients:

Recipient

What they may receive

Why

Shopify (including Shopify Inbox)

Order data, account data, checkout data, customer support conversations

Hosting and operating our ecommerce platform and customer support chat

Payment processors

Payment information, transaction details, fraud-related information

Processing payments, refunds and fraud checks

Shipping carriers and fulfilment partners

Name, address, email address, phone number, order and delivery information

Delivering your order and managing fulfilment

Judge.me and WebwinkelKeur

Name, email address, order reference, review content and rating

Requesting, collecting and displaying reviews

Google

Cookie data, usage data, advertising and analytics data

Analytics, advertising and conversion measurement — only after you consent in the cookie banner

Meta

Cookie data, pixel data, event data and advertising data

Advertising and conversion measurement — only after you consent in the cookie banner

WeTracked

Conversion event data, attribution data and related technical data

Server-side conversion tracking — only after you consent in the cookie banner

Klaviyo

Email address, name, marketing preferences, order history and email engagement data

Managing newsletter subscriptions, customer segmentation, email flows and marketing emails

Professional advisors

Relevant business, order, accounting or legal information

Accountants, lawyers, tax advisors and other professional advisors

Government authorities or regulators

Information required by law

Tax, legal, regulatory or enforcement obligations

Buyer, successor or restructuring party

Relevant customer, order and business data

Only in case of a sale, merger, restructuring or transfer of our business, subject to appropriate safeguards


Where third parties process personal data on our behalf, we have appropriate data processing agreements in place as required by the GDPR.

6. International data transfers

Some of our service providers, including Shopify, Google, Meta, Judge.me, WeTracked and Klaviyo, may process personal data outside the European Economic Area (EEA), including in the United States.

If you order from the United Kingdom, your personal data is processed in line with UK GDPR. Transfers from the UK to other countries rely on equivalent UK transfer mechanisms.

Where personal data is transferred outside the EEA or UK, we rely on appropriate safeguards, such as:

  1. The European Commission's Standard Contractual Clauses (or the UK equivalent, the International Data Transfer Agreement);

  2. An adequacy decision by the European Commission or the UK government, such as the EU–US Data Privacy Framework where applicable; or

  3. Other lawful transfer mechanisms under the GDPR or UK GDPR.

Where we rely on the EU–US Data Privacy Framework, we only do so for providers that are certified under that framework. Where this is not available, we rely on Standard Contractual Clauses and, where required, additional transfer safeguards.

You can contact us at info@bunnymansions.nl for more information about these safeguards.

7. Cookies and tracking technologies

We use cookies and similar technologies on our Site.

Some cookies are strictly necessary for the website to function, for example for the shopping cart, checkout, security and language settings. These cookies do not require consent.

We only activate non-essential cookies and similar technologies, such as performance cookies, targeting cookies, Meta Pixel, Google Ads tags and server-side conversion tracking, after you have given consent through our cookie banner.

When you first visit the Site, our cookie banner lets you accept all cookies, reject non-essential cookies, or manage your preferences by category. You can change or withdraw your consent at any time through the cookie settings link in our footer.

Our cookie banner uses the following four categories:

Category

Purpose

Consent needed?

Examples

Strictly necessary cookies

Required for the Site to function

No

Cart, checkout, security, Shopify session cookies

Functional cookies

Remember preferences or improve functionality

Yes

Language preferences, recently viewed products

Performance cookies

Help us understand how the Site is used

Yes

Google Analytics

Targeting cookies

Show relevant ads and measure advertising performance

Yes

Meta Pixel, Google Ads, WeTracked


For Shopify's own cookies, please see Shopify's cookie information at shopify.com/legal/cookies.

8. How long we keep your personal data

We keep personal data only for as long as necessary for the purposes described in this Privacy Policy, unless we are legally required or permitted to keep it for longer.

Data category

Retention period

Reason

Order, invoice and payment data

7 years

Dutch tax and accounting obligations (Algemene wet inzake rijksbelastingen)

Customer account data for active accounts

Until you delete your account or request deletion, unless we must keep certain data for legal reasons

Account management

Customer account data for inactive accounts

We aim to delete or anonymise inactive account data after 3 years, in line with our internal data retention review

Reasonable inactivity period

Marketing email subscribers

Until you unsubscribe or withdraw consent

Email marketing management

Unsubscribed email addresses

Indefinitely on a suppression list

To make sure we do not accidentally email you again

Customer support records

Usually 3 years after last contact

Service quality, dispute handling and business administration

Reviews

As long as the review is published, or until you ask us to remove it where removal is legally possible

Review management and transparency

Cookie consent records

Usually 12 months, after which we may ask again

Consent management

Third-party analytics and advertising data

Depends on the relevant platform settings and our account configuration

Analytics, attribution and advertising measurement


For third-party analytics and advertising tools, retention periods depend on the relevant platform settings and our account configuration. Where possible, we configure retention periods to be no longer than necessary for analytics, attribution and advertising measurement.

After the applicable retention period, we delete or anonymise personal data, unless we are legally required or permitted to keep it longer.

9. Your rights

Under the GDPR (and UK GDPR for UK customers), you have several rights in relation to your personal data.

You have the right to:

Access your data You can ask us for a copy of the personal data we hold about you.

Correct your data You can ask us to correct inaccurate or incomplete personal data.

Delete your data You can ask us to delete your personal data, where legally possible.

Restrict processing You can ask us to temporarily limit how we use your personal data in certain situations.

Data portability You can ask to receive certain personal data in a structured, commonly used and machine-readable format.

Object to processing You can object to processing based on legitimate interest, including direct marketing.

Withdraw consent Where we rely on your consent, you can withdraw that consent at any time.

Not be subject to automated decision-making You have the right not to be subject to automated decision-making that produces legal or similarly significant effects. We do not currently use such automated decision-making.

How to exercise your rights

Email info@bunnymansions.nl with the subject line "Privacy Request".

Please tell us which right you want to exercise and provide enough information for us to identify your request. We may ask you for proof of identity to make sure we do not share personal data with the wrong person.

We will respond within one month. If your request is complex or if you have made multiple requests, we may extend this period by up to two additional months. If we need more time, we will let you know.

There is no fee for exercising your rights, unless your request is clearly unfounded, excessive or repetitive.

10. Children's data

Our Services are not intended for children under the age of 16.

We do not knowingly collect personal data from children under 16. If you are a parent or guardian and believe that your child has provided personal data to us, please contact us at info@bunnymansions.nl. If appropriate, we will delete the data.

11. Security

We take appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

These measures may include:

  1. Use of reputable ecommerce, payment, review and marketing platforms;

  2. TLS/SSL encryption for data transmitted through the Site;

  3. Access controls for internal systems;

  4. Limiting access to personal data to people who need it for their role;

  5. Regular review of access permissions; and

  6. Appropriate data processing agreements with service providers where required.

No website, platform or system is completely secure. If you believe your account or personal data has been compromised, please contact us immediately at info@bunnymansions.nl.

12. Complaints

If you have a complaint about how we handle your personal data, please contact us first at info@bunnymansions.nl. We will try to resolve your complaint.

If you are not satisfied with our response, you have the right to lodge a complaint with the relevant data protection authority:

13. Notice for US visitors and California residents

If you visit the Site from the United States, including California, this section applies in addition to the rest of this Privacy Policy.

We do not sell personal data for monetary consideration. However, under California law (CCPA/CPRA), sharing personal data with advertising partners such as Google and Meta for targeted advertising can be considered "sharing" or "selling."

You can opt out of all such sharing by:

  • Rejecting Targeting cookies in our cookie banner when you visit the Site;

  • Changing your cookie preferences at any time through the cookie settings link in our footer; or

  • Emailing info@bunnymansions.nl with the subject line "Do Not Sell or Share My Personal Information".

California residents also have additional rights under the CCPA/CPRA, including the right to know, the right to delete, the right to correct, the right to limit use of sensitive personal information, and the right to non-discrimination for exercising these rights. To exercise these rights, contact us using the details above.

14. Links to third-party websites

Our Site may contain links to third-party websites, platforms or social media pages. We are not responsible for the privacy practices, content or security of third-party websites. We recommend that you read the privacy policies of any third-party websites you visit.

15. Contact

If you have questions about this Privacy Policy or how we handle your personal data, contact us at:

Bunny Mansions Michiel de Ruyterweg 208 2628 BA Delft The Netherlands Email: info@bunnymansions.nl

This Privacy Policy is available in English and Dutch. In case of any discrepancy, the Dutch version prevails for customers based in the Netherlands.