Privacy policy
Privacy Policy — Bunny Mansions
Last updated: 19 May 2026
This Privacy Policy explains how Bunny Mansions ("we", "us", "our") collects, uses, stores and shares personal data when you visit, use or purchase from bunnymansions.com (the "Site"), or when you otherwise communicate with us (together, the "Services").
We are the data controller for the personal data described in this Privacy Policy, unless stated otherwise.
We are not required to appoint a Data Protection Officer under Article 37 GDPR. For any privacy-related questions, please contact us using the details below.
Contact details Bunny Mansions Michiel de Ruyterweg 208 2628 BA Delft The Netherlands Email: info@bunnymansions.nl
Please read this Privacy Policy carefully. If you do not agree with how we handle your personal data, please do not use the Site.
1. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our business, our Services, our use of service providers, or legal and regulatory requirements.
When we update this Privacy Policy, we will publish the updated version on the Site and change the "Last updated" date above. If we make significant changes that materially affect how we use your personal data, we will give you reasonable advance notice where appropriate and, where required by law, ask for your consent again.
2. What personal data we collect
We collect personal data in different ways, depending on how you use our Services.
2.1 Information you give us directly
Contact information Name, email address, phone number, billing address and shipping address.
Order information Products purchased, order history, payment confirmation, delivery details, returns, exchanges and related customer service information.
Account information Username, login credentials protected through appropriate technical security measures by our ecommerce platform, account preferences and account history.
Shopping behaviour on our Site Products viewed, items added to your cart, wishlists, gift card use and similar shopping activity.
Customer support information The content of messages you send to us, including messages sent by email, contact form, Shopify Inbox chat, social media or other communication channels.
Marketing preferences Whether you have subscribed to our newsletter, your language preference, email preferences and any other preferences you have indicated.
Reviews If you choose to submit a review through our review platform, we may process your name, review content, rating, order reference and related review information.
2.2 Information we collect automatically
When you use the Site, we may automatically collect certain information through cookies and similar technologies. Non-essential tracking is only activated after you consent through our cookie banner.
This may include:
Usage data Pages visited, time spent on the Site, links clicked, products viewed, referring URL and similar information about how you use the Site.
Device and browser data Device type, operating system, browser type, screen resolution and similar technical information.
Network data IP address, approximate location based on IP address, internet service provider and related technical information.
Cookie, pixel and tracking data Information collected through cookies, pixels, tags and similar technologies, as explained in section 7 of this Privacy Policy.
2.3 Information from third parties
We may receive personal data from third parties that help us provide, improve, market and secure our Services. These include:
Shopify Our ecommerce platform, which supports hosting, checkout, order management, customer accounts, customer support (Shopify Inbox) and related ecommerce services. Depending on the specific Shopify service used, Shopify may act as our processor or as an independent controller, as described in Shopify's own privacy documentation.
Payment processors Payment providers help process payments, refunds and fraud checks. Depending on the payment method selected, this may include providers for iDEAL, credit cards, PayPal or other payment options.
Shipping and fulfilment partners Shipping carriers and fulfilment partners help us deliver your order and confirm delivery.
Judge.me Our review platform, which helps us request, collect, manage and display customer reviews.
Google Provides analytics and advertising services through Google Analytics and Google Ads.
Meta Provides advertising and measurement services for Facebook and Instagram.
WeTracked Provides server-side conversion tracking and attribution.
Klaviyo Our email service provider, which manages newsletter subscriptions, customer segmentation, email flows and marketing emails.
3. How we use your personal data and our legal basis
Under the General Data Protection Regulation (GDPR), and for direct marketing also under the Dutch Telecommunications Act (Telecommunicatiewet, Article 11.7), we need a legal basis for every use of your personal data.
We may use your personal data for the following purposes:
|
Purpose |
Data used |
Legal basis |
|---|---|---|
|
Processing your order, payment, shipping, returns and exchanges |
Contact data, order data, payment confirmation, shipping data |
Performance of a contract, Article 6(1)(b) GDPR |
|
Creating and managing your customer account |
Account data, contact data, order history |
Performance of a contract, Article 6(1)(b) GDPR |
|
Providing customer support |
Contact data, order data, support messages |
Legitimate interest, Article 6(1)(f) GDPR |
|
Sending newsletters, promotions and product updates |
Email address, name, marketing preferences, engagement data |
Consent, Article 6(1)(a) GDPR and Article 11.7 Telecommunicatiewet |
|
Sending product-related emails about our own similar products to existing customers |
Email address, order history |
Legitimate interest under the soft opt-in rule, Article 6(1)(f) GDPR and Article 11.7(3) Telecommunicatiewet |
|
Inviting you to leave a product review |
Name, email address, order data |
Consent, collected at checkout |
|
Displaying reviews you submit |
Review content, rating, display name, product purchased where relevant |
Consent, Article 6(1)(a) GDPR |
|
Improving our Site and Services |
Usage data, order trends, support feedback |
Legitimate interest, Article 6(1)(f) GDPR |
|
Fraud prevention and Site security |
Account data, usage data, network data, technical data |
Legitimate interest, Article 6(1)(f) GDPR |
|
Analytics through Google Analytics |
Cookie data, usage data, device data |
Consent through our cookie banner, Article 6(1)(a) GDPR |
|
Advertising and conversion tracking through Google Ads, Meta and WeTracked |
Cookie data, pixel data, event data, advertising identifiers |
Consent through our cookie banner, Article 6(1)(a) GDPR |
|
Keeping unsubscribed email addresses on a suppression list |
Email address |
Legitimate interest, Article 6(1)(f) GDPR — to make sure we do not accidentally email you again |
|
Complying with legal obligations, including tax and accounting obligations |
Order data, invoice data, payment data |
Legal obligation, Article 6(1)(c) GDPR |
|
Handling legal claims or disputes |
Relevant order, payment, communication and support data |
Legitimate interest, Article 6(1)(f) GDPR |
4. Marketing emails — your consent matters
This section explains our marketing email practices in detail because it is one of the most important parts of this Privacy Policy.
4.1 Newsletter and promotional emails
We only send newsletter and promotional emails if you have actively given consent, for example by signing up through our newsletter form, popup or by ticking a marketing opt-in checkbox at checkout. We do not use pre-ticked consent boxes. Each consent is recorded with the date, source and form wording used at the time.
4.2 Soft opt-in for existing customers
If you have purchased a product from us, we may email you about our own similar rabbit-care products under the soft opt-in rule in Article 11.7(3) of the Dutch Telecommunicatiewet. This applies only if:
-
Your email address was collected in the context of a sale;
-
You were given a clear, easy opportunity to opt out at the moment your email was collected; and
-
Every marketing email afterwards includes a clear, easy way to opt out.
4.3 Review requests
When you place an order and consent to receiving a review request, we may invite you to leave a review through Judge.me. You can opt out of review request emails at any time using the unsubscribe link in the email.
4.4 How to unsubscribe
You can unsubscribe at any time by:
-
Clicking the unsubscribe link in any email we send you; or
-
Emailing info@bunnymansions.nl with the subject line "Unsubscribe".
Withdrawing consent does not affect any processing we carried out before you withdrew it. After you unsubscribe, we keep your email address on a suppression list so that we do not accidentally email you again. This suppression data is not used for marketing.
5. Who we share your personal data with
We share personal data only where necessary to provide our Services, operate our business, comply with legal obligations, or protect our legitimate interests. We do not sell your personal data for monetary consideration.
Note for California residents and other US visitors: under California law (CCPA/CPRA), sharing data with advertising partners such as Google and Meta for targeted advertising may be considered "sharing" or "selling." You can opt out of all such sharing at any time by rejecting Targeting cookies in our cookie banner or by changing your cookie preferences through the link in our footer. See section 13 for more on US-specific rights.
We may share personal data with the following recipients:
|
Recipient |
What they may receive |
Why |
|---|---|---|
|
Shopify (including Shopify Inbox) |
Order data, account data, checkout data, customer support conversations |
Hosting and operating our ecommerce platform and customer support chat |
|
Payment processors |
Payment information, transaction details, fraud-related information |
Processing payments, refunds and fraud checks |
|
Shipping carriers and fulfilment partners |
Name, address, email address, phone number, order and delivery information |
Delivering your order and managing fulfilment |
|
Judge.me and WebwinkelKeur |
Name, email address, order reference, review content and rating |
Requesting, collecting and displaying reviews |
|
|
Cookie data, usage data, advertising and analytics data |
Analytics, advertising and conversion measurement — only after you consent in the cookie banner |
|
Meta |
Cookie data, pixel data, event data and advertising data |
Advertising and conversion measurement — only after you consent in the cookie banner |
|
WeTracked |
Conversion event data, attribution data and related technical data |
Server-side conversion tracking — only after you consent in the cookie banner |
|
Klaviyo |
Email address, name, marketing preferences, order history and email engagement data |
Managing newsletter subscriptions, customer segmentation, email flows and marketing emails |
|
Professional advisors |
Relevant business, order, accounting or legal information |
Accountants, lawyers, tax advisors and other professional advisors |
|
Government authorities or regulators |
Information required by law |
Tax, legal, regulatory or enforcement obligations |
|
Buyer, successor or restructuring party |
Relevant customer, order and business data |
Only in case of a sale, merger, restructuring or transfer of our business, subject to appropriate safeguards |
Where third parties process personal data on our behalf, we have appropriate data processing agreements in place as required by the GDPR.
6. International data transfers
Some of our service providers, including Shopify, Google, Meta, Judge.me, WeTracked and Klaviyo, may process personal data outside the European Economic Area (EEA), including in the United States.
If you order from the United Kingdom, your personal data is processed in line with UK GDPR. Transfers from the UK to other countries rely on equivalent UK transfer mechanisms.
Where personal data is transferred outside the EEA or UK, we rely on appropriate safeguards, such as:
-
The European Commission's Standard Contractual Clauses (or the UK equivalent, the International Data Transfer Agreement);
-
An adequacy decision by the European Commission or the UK government, such as the EU–US Data Privacy Framework where applicable; or
-
Other lawful transfer mechanisms under the GDPR or UK GDPR.
Where we rely on the EU–US Data Privacy Framework, we only do so for providers that are certified under that framework. Where this is not available, we rely on Standard Contractual Clauses and, where required, additional transfer safeguards.
You can contact us at info@bunnymansions.nl for more information about these safeguards.
7. Cookies and tracking technologies
We use cookies and similar technologies on our Site.
Some cookies are strictly necessary for the website to function, for example for the shopping cart, checkout, security and language settings. These cookies do not require consent.
We only activate non-essential cookies and similar technologies, such as performance cookies, targeting cookies, Meta Pixel, Google Ads tags and server-side conversion tracking, after you have given consent through our cookie banner.
When you first visit the Site, our cookie banner lets you accept all cookies, reject non-essential cookies, or manage your preferences by category. You can change or withdraw your consent at any time through the cookie settings link in our footer.
Our cookie banner uses the following four categories:
|
Category |
Purpose |
Consent needed? |
Examples |
|---|---|---|---|
|
Strictly necessary cookies |
Required for the Site to function |
No |
Cart, checkout, security, Shopify session cookies |
|
Functional cookies |
Remember preferences or improve functionality |
Yes |
Language preferences, recently viewed products |
|
Performance cookies |
Help us understand how the Site is used |
Yes |
Google Analytics |
|
Targeting cookies |
Show relevant ads and measure advertising performance |
Yes |
Meta Pixel, Google Ads, WeTracked |
For Shopify's own cookies, please see Shopify's cookie information at shopify.com/legal/cookies.
8. How long we keep your personal data
We keep personal data only for as long as necessary for the purposes described in this Privacy Policy, unless we are legally required or permitted to keep it for longer.
|
Data category |
Retention period |
Reason |
|---|---|---|
|
Order, invoice and payment data |
7 years |
Dutch tax and accounting obligations (Algemene wet inzake rijksbelastingen) |
|
Customer account data for active accounts |
Until you delete your account or request deletion, unless we must keep certain data for legal reasons |
Account management |
|
Customer account data for inactive accounts |
We aim to delete or anonymise inactive account data after 3 years, in line with our internal data retention review |
Reasonable inactivity period |
|
Marketing email subscribers |
Until you unsubscribe or withdraw consent |
Email marketing management |
|
Unsubscribed email addresses |
Indefinitely on a suppression list |
To make sure we do not accidentally email you again |
|
Customer support records |
Usually 3 years after last contact |
Service quality, dispute handling and business administration |
|
Reviews |
As long as the review is published, or until you ask us to remove it where removal is legally possible |
Review management and transparency |
|
Cookie consent records |
Usually 12 months, after which we may ask again |
Consent management |
|
Third-party analytics and advertising data |
Depends on the relevant platform settings and our account configuration |
Analytics, attribution and advertising measurement |
For third-party analytics and advertising tools, retention periods depend on the relevant platform settings and our account configuration. Where possible, we configure retention periods to be no longer than necessary for analytics, attribution and advertising measurement.
After the applicable retention period, we delete or anonymise personal data, unless we are legally required or permitted to keep it longer.
9. Your rights
Under the GDPR (and UK GDPR for UK customers), you have several rights in relation to your personal data.
You have the right to:
Access your data You can ask us for a copy of the personal data we hold about you.
Correct your data You can ask us to correct inaccurate or incomplete personal data.
Delete your data You can ask us to delete your personal data, where legally possible.
Restrict processing You can ask us to temporarily limit how we use your personal data in certain situations.
Data portability You can ask to receive certain personal data in a structured, commonly used and machine-readable format.
Object to processing You can object to processing based on legitimate interest, including direct marketing.
Withdraw consent Where we rely on your consent, you can withdraw that consent at any time.
Not be subject to automated decision-making You have the right not to be subject to automated decision-making that produces legal or similarly significant effects. We do not currently use such automated decision-making.
How to exercise your rights
Email info@bunnymansions.nl with the subject line "Privacy Request".
Please tell us which right you want to exercise and provide enough information for us to identify your request. We may ask you for proof of identity to make sure we do not share personal data with the wrong person.
We will respond within one month. If your request is complex or if you have made multiple requests, we may extend this period by up to two additional months. If we need more time, we will let you know.
There is no fee for exercising your rights, unless your request is clearly unfounded, excessive or repetitive.
10. Children's data
Our Services are not intended for children under the age of 16.
We do not knowingly collect personal data from children under 16. If you are a parent or guardian and believe that your child has provided personal data to us, please contact us at info@bunnymansions.nl. If appropriate, we will delete the data.
11. Security
We take appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
These measures may include:
-
Use of reputable ecommerce, payment, review and marketing platforms;
-
TLS/SSL encryption for data transmitted through the Site;
-
Access controls for internal systems;
-
Limiting access to personal data to people who need it for their role;
-
Regular review of access permissions; and
-
Appropriate data processing agreements with service providers where required.
No website, platform or system is completely secure. If you believe your account or personal data has been compromised, please contact us immediately at info@bunnymansions.nl.
12. Complaints
If you have a complaint about how we handle your personal data, please contact us first at info@bunnymansions.nl. We will try to resolve your complaint.
If you are not satisfied with our response, you have the right to lodge a complaint with the relevant data protection authority:
-
In the Netherlands: Autoriteit Persoonsgegevens — autoriteitpersoonsgegevens.nl
-
In the United Kingdom: Information Commissioner's Office (ICO) — ico.org.uk
-
Elsewhere in the EEA: Your local data protection authority — edpb.europa.eu
13. Notice for US visitors and California residents
If you visit the Site from the United States, including California, this section applies in addition to the rest of this Privacy Policy.
We do not sell personal data for monetary consideration. However, under California law (CCPA/CPRA), sharing personal data with advertising partners such as Google and Meta for targeted advertising can be considered "sharing" or "selling."
You can opt out of all such sharing by:
-
Rejecting Targeting cookies in our cookie banner when you visit the Site;
-
Changing your cookie preferences at any time through the cookie settings link in our footer; or
-
Emailing info@bunnymansions.nl with the subject line "Do Not Sell or Share My Personal Information".
California residents also have additional rights under the CCPA/CPRA, including the right to know, the right to delete, the right to correct, the right to limit use of sensitive personal information, and the right to non-discrimination for exercising these rights. To exercise these rights, contact us using the details above.
14. Links to third-party websites
Our Site may contain links to third-party websites, platforms or social media pages. We are not responsible for the privacy practices, content or security of third-party websites. We recommend that you read the privacy policies of any third-party websites you visit.
15. Contact
If you have questions about this Privacy Policy or how we handle your personal data, contact us at:
Bunny Mansions Michiel de Ruyterweg 208 2628 BA Delft The Netherlands Email: info@bunnymansions.nl
This Privacy Policy is available in English and Dutch. In case of any discrepancy, the Dutch version prevails for customers based in the Netherlands.