PRIVACY POLICY
This privacy policy of stichd sportmerchandising B.V. provides you with information about what happens to any personal data that you provide to us, or any personal data that we may collect when you visit our website jamaicastore.puma.com (“Website”) and / or when you purchase any goods on the Website, why we do this and what your rights are when we process your personal data. We take your privacy seriously and maintain a strict privacy policy including appropriate security.
stichd sportmerchandising B.V. will hereinafter be referred to as "stichd ", "we" or "us". Should you have any questions or if you need any more information, please contact us via privacy@stichd.com. This privacy policy was last updated on 01.07.2024.
1. SCOPE, DATA CONTROLLER AND DEFINITIONS
1.1. Scope of this privacy policy
This privacy policy applies to your visit and the use of the Website, including when purchasing goods, and any measures relating to the execution and / or cancellation of an online purchase, sending of newsletters and other informative or service-related e-mails, contacting our customer service and for our marketing activities engaging third party websites.
1.2. The controller of your personal data
Unless otherwise indicated in this privacy policy, stichd is the controller for the processing of your personal data when visiting and / or purchasing goods on the Website. Please find our contact details below.
- stichd sportmerchandising B.V.
- De Waterman 2
- 5215 MX ‘s-Hertogenbosch
- The Netherlands
- Registered under number 63490757 with the Dutch Chamber of Commerce
- Tel: + 31 73 688 93 93
- Email: info.jamaicastore@stichd.com
- Privacy contact: privacy@stichd.com
1.3. Definitions
This privacy policy is based on the following terms from the EU General Data Protection Regulation, which we have defined for ease of understanding.
• GDPR refers to the Regulation (EU) 2016/679 of the European Parliament and of the European Council dated 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation).
• The recipient is a natural or legal person, public authority, agency or any other body to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the context of a particular enquiry, in accordance with Union or Member State law, shall not be regarded as recipients; the processing of such data by public authorities shall comply with the applicable rules on data protection and the purposes of the processing; Examples of possible recipients: banks/payment service providers, logistics and shipping service providers and IT service providers; for more information see Article 4).
• Personal data refers to any information relating to an identified or identifiable natural person ("data subject's personal data"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. Examples of personal data: name, contact details, bank or credit card details.
• The data controller is the natural or legal person, public authority, agency or any other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union law or Member State law, the controller or the specific criteria for its nomination may be determined by Union law or Member State law. For the data processing activities described in this privacy policy, stichd is the data controller unless otherwise specified (see article 1.2.).
• PUMA Group means all legal entities that are affiliated with PUMA SE, including PUMA Europe GmbH, PUMA United Kingdom Limited and PUMA North America Inc.
• Processing refers to any operation or set of operations which is performed on personal data or on a set of personal data, whether or not by automatic means, such as collection, recording, organisation, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure or destruction.
• The processor is a natural or legal person, public authority, agency or other body which processes personal data on behalf of the data controller.
2. PURPOSES, LEGAL GROUNDS AND RETENTION PERIODS FOR OUR PROCESSING OF YOUR PERSONAL DATA
We may only process personal data for a reason specified in the GDPR and only as long as and to the extent that it is necessary for purposes specified in this section of the privacy policy or based on legal requirements, the so-called legal basis of processing which are captured in Article 6 of the GDPR. In the following paragraphs of this chapter, we indicate per type of processing purpose on which legal basis we process the personal data, for which purposes and for how long we store your personal data (chapter 3). Note that we may process your personal data for more than one legal basis depending on the specific purpose for which we are using your data.
2.1. Processing of your data when you visit our Website
If you visit our Website in order to find out about our products and services, purchasing goods in our online shop through the Website or otherwise actively transferring information to us (including when you reach out for customer support of otherwise interact with us), we will process your personal data for the following purposes and on the following legal bases:
2.1.1. Provision of the Website and IT security
We process your personal data that is technically necessary to enable us to make the Website available and to ensure stability and security when you visit it. This includes the following personal data:
• IP address
• Type and version of the browser
• Operating system and platform
• The full Uniform Resource Locator (URL)
For security purposes, this personal data is stored in server log files, which are automatically deleted after 30 days. This data processing is technically necessary to enable you to use our Website and for our legitimate interest in ensuring IT security (legal basis: Article 6(1)(f) GDPR).
2.1.2. Provision of localised Website
We also process your personal data that is technically necessary to enable us to provide you with a localised version of the Website, in particular with regards to different currencies. This data processing is necessary for our legitimate interest in adapting our website to your needs (legal basis: Article 6(1)(f) GDPR). For security purposes, this personal data is stored in server log files, which are automatically deleted after 30 days.
2.1.3. Use of cookies
We use cookies on our website, as more fully described in our cookie settings. Cookies are small text files that are stored in the browsers of your end devices when you visit our Website. Cookies allow your actions and settings on our Website to be tracked, saved and recognised for the duration of the browser session or even beyond. In addition, cookies and their respective cookie identifiers ensure that your browser is recognised. After leaving the website, you can, for example, restore the contents of your shopping basket or see the last viewed products. For more information on the use of cookies on our Website, the cookie categories and for individual settings, please see our cookie settings.
2.1.4. Website analysis
In order to continuously optimise our service, we use Google Analytics which statistically evaluates our Website. Google Analytics a website analysis service of Google Inc. ("Google"). Google Analytics uses analytical cookies (that enable an analysis of the use of our Website). The information generated by the cookie when using our Website is usually transferred to a Google server in the USA, where it is stored. However, as we use Google Analytics with the addition "anonymizeIP", Google will in advance limit the IP address of the website visitor within the member states of the European Union (EU) or in other states that are part of the Agreement on the European Economic Area (EEA), thus excluding any direct association with you. Only in exceptional cases will the full IP address be transferred to a Google server in the USA and truncated there. On behalf of stichd, Google will use this information to evaluate the use of the Website, to compile reports on website activity, to analyse the results, to improve the adaptation of our digital ads and to provide further services to stichd in connection with the use of the Website. The IP address transmitted from the user's browser in connection with Google Analytics will not be merged by Google with any other data. More information on Google's terms of use and data protection can be found at:
• https://policies.google.com/terms
• https://policies.google.com/privacy
This data processing is necessary for our legitimate interest to carry out analyses to improve our website and products, and to advertise our products on the internet in an appropriate and effective manner (legal basis: Article 6(1)(f) GDPR). This data will be kept for a maximum of 26 or shorter in case the Analytics Data Retention setting is set to anything shorter than 26 months, or until a decision to unsubscribe is made as described below.
• Unsubscribe from Google Analytics:
You can generally prevent your personal data (including your IP address) from being processed by Google Analytics by downloading and installing the browser add-on available at the following link:
• https://tools.google.com/dlpage/gaoptout
In this case, a permanent opt-out cookie (name: "ga-disable-UA-[...]") is set in the browser you are currently using, which prevents your data from being recorded when you visit our Website with this specific browser in the future. If you use a different browser, Google Analytics is in principle enabled, unless the opt-out cookie is also set in this browser. Please note that Google Analytics will be re-enabled if you delete the above opt-out cookie from your browser.
2.1.5. Individual recommendations on our Website
When you visit our web pages we use Google Ads to process data on your user behaviour, such as products viewed and contents of your shopping cart, in order to show you individual recommendations on our Website based on this data. For further information on data processing by Google Ads, please consult the Google privacy policy under the following link:
• https://policies.google.com/privacy
This data processing is necessary for our legitimate interest in creating a better user experience by providing customised recommendations (legal basis: Article 6(1)(f) GDPR). This data will be kept for a maximum of 26 months or until a decision to unsubscribe is made as described below. Unsubscribe from individual recommendations: You can object to this data processing by clicking on the following unsubscribe link:
• Google Ads: https://adssettings.google.com
2.1.6. Links to third party websites
The Website can contain links to third party websites. When you click on one of those links, you will visit another website or internet resource. stichd has no responsibility or liability whatsoever for, or control over, those websites or internet resources and their personal data collection, use and disclosure. We advise you to carefully read the privacy policy and terms of use of each such website.
2.1.7. Display of advertisements/retargeting on third party websites
When you visit our Website, tags and cookies are set by our retargeting service provider(s) to track which products you have viewed or purchased on our Website. Using this information, we can then show you individual offers of our products on third party websites through our retargeting service provider(s) and analyse the results to further improve our advertising. For more information on the data processing by our retargeting service provider(s) for retargeting purposes, please consult the relevant privacy policy below and unsubscribe via the following links:
• Meta Ads: https://www.facebook.com/about/privacy
This data processing is necessary for our legitimate interest to advertise our products on the internet in an appropriate and efficient manner (legal basis: Article 6(1)(f) GDPR). This data will be kept for a maximum of 24 months or until a decision to unsubscribe is made as described below. Unsubscribe from retargeting: You can object to this data processing by clicking on the following link(s) for unsubscribing from the respective service provider(s) for retargeting:
• Meta ads: https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen
2.1.8. Customer service
Depending on the subject of your request with our customer service, we rely on your personal data stored in our systems in the context of other data processing activities (e.g., data that you have provided during a purchase or when addressing our customer service (including live chat) for any reason). We may also collect data from external sources if and to the extent necessary to fulfil your request, such as logistics service providers for the tracking of your shipment or an investigation request. In the context of requests concerning a (pre)contractual relationship with you, this data processing is necessary for the performance of a contract (provision of customer service) with you (legal basis: Article 6(1)(b) GDPR). If you want to exercise your rights against us, the corresponding data processing is necessary in order to comply with a legal obligation (legal basis: Art. 6(1)(c) GDPR). If you like to receive information or make a complaint about our products or services, the respective data processing is necessary for our legitimate interest in responding to your information request or complaint (legal basis: Article 6(1)(f) GDPR). For direct contact please reach out to: info.jamaicastore@stichd.com.
2.2. E-mail marketing
2.2.1. Sending the e-mail newsletter to subscribers
If you have subscribed to receive e-mail newsletters, PUMA Europe GmbH, PUMA United Kingdom Limited or PUMA North America Inc., depending on your location, will send you newsletters and marketing communications from time to time to inform you about PUMA products, services, partnerships, promotions, offers and other initiatives. This data processing is based on your consent (legal basis: Article 6(1)(a) GDPR).
Withdrawal of consent:
If you change your mind, you can withdraw your consent and subscription to the newsletter at any time by sending an e-mail with your unsubscription request to our customer service (service@puma.com) and/or by clicking on the "Unsubscribe" link at the bottom of each newsletter. These data will be processed until the consent is withdrawn.
2.5. Data processing in the case of orders in the online shop
We process your personal data in connection with the purchase of goods in the online shop at our Website.
2.5.1. Purchase and payment of goods in the online shop
We process your personal data (such as contact details, shipping and payment information) when you purchase goods from the online shop at the Website. If you purchase goods on behalf of another person (third party), we will process the third party's personal data (name and contact details) for the purpose of the fulfilment of the order, including shipment of the products, to that third party you indicated. Make sure you are authorised to provide such personal data. This data processing is necessary for the performance of a contract with you (legal basis: Article 6(1)(b) GDPR). According to the law, we must retain the data related to contractual relationships for 7 years.
2.5.2. Payments with Klarna and with PayPal
Klarna: In order to offer you the widest possible choice of payment methods, we use the services of Klarna Bank AB (publ), at Sveavägen 46, 111 34 Stockholm.Klarna is a payment service provider that allows you to choose different payment methods and additional services when using Klarna. This includes, for example, purchase by invoice, installment payments and other services, such as separate buyer protection.
To select the payment methods of Klarna, a user account with Klarna is required. The payment for your orders is made to Klarna. You can find further information about the terms of use of Klarna for your respective country at: https://www.klarna.com/international/terms-and-conditions.
Depending on which payment methods you choose (e.g. "Pay now", "Pay in 30 days", installment payment options), it may be necessary that your personal data is transmitted by Klarna to credit rating agencies cooperating with Klarna in order to perform an identity and credit check. For this purpose, Klarna processes personal data on its own responsibility. The transmission of your data is necessary for the processing of your order with the payment method you have chosen at Klarna as well as for the confirmation of your identity and the administration of your payment.
According to our information, this usually involves your contact information (e.g. first and last name, telephone number, email and postal address), data for processing the purchase contract (e.g. bank details, account and card number, billing and delivery address, items purchased, price paid, order status and chargeback information).
Please note that Klarna may also share your personal data with other subcontractors and other affiliated companies, for example if this is necessary to fulfill the contractual obligations of your purchase.
You can find more detailed information on the personal data processed by Klarna and the legal basis for this for your respective country at: https://www.klarna.com/international/privacy-policy/
PayPal: We also offer you the option to pay for your order with the online payment service provider PayPal. The payment method PayPal is a service of PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg. If you choose PayPal as payment method, your contact details will be transmitted to PayPal. To use PayPal as a payment method, a user account with PayPal is required.
PayPal's services also include separate buyer protection in addition to the online payment service.
The transmission of your data is necessary for the processing of your order with the payment method you have chosen at PayPal as well as for the confirmation of your identity and the administration of your payment.
According to our information, the personal data transmitted to PayPal is usually your contact information (e.g. first and last name, telephone number, email and postal address, customer account), data for processing the purchase contract (e.g. bank details, account and card number, billing and shipping address, purchased items, price paid, order status and chargeback information). Please note that PayPal may also share your personal data with other subcontractors and other affiliated companies, for example, if this is necessary to fulfill the contractual obligations of your purchase.
Depending on which payment methods PayPal makes available to you, it may be necessary for your personal data to be transmitted by PayPal to credit rating agencies in order to carry out an identity and credit check. This serves to check your identity and creditworthiness with regard to the order you have placed. For this purpose, PayPal processes personal data on its own responsibility. You can find more detailed information on the processing of your personal data by PayPal at: https://www.paypal.com/webapps/mpp/ua/privacy-full.
2.5.3. Fraud and credit check
We check, based on your device and predefined rules, whether the order should be categorised as suspicious with regard to fraud. If fraud is suspected, we will additionally carry out an individual check of the order. The result of this manual fraud check may be positive, which would lead to the order being approved. However, if the suspicion of fraud persists, we may decide to cancel the order, depending on the specific case. This data processing is necessary for our legitimate interest in preventing and minimizing the risk of payment defaults, false details being used and fraud (legal basis: Article 6(1)(f) GDPR). This data will be kept for the period that is required under Dutch law for 7 years compliance with the applicable legislation and Scheme Rules compliance purposes (fraud prevention and fraud investigation).
2.5.4. Cancellation of purchase
In all cases of cancellation of the purchase (e.g., withdrawal from the contract), we will process your personal data for the return of the goods and the refund of the purchase price. This data processing is necessary for the performance of a contract with you (legal basis: Article 6(1)(b) GDPR) and/or to comply with a legal obligation (legal basis: Article 6(1)(c) GDPR). According to the law, we must retain the data related to contractual relationships for 7 years.
2.6. Other processing
2.6.1. Performing internal audits
Your personal data may be processed in the context of audits conducted in relation to the organisation of stichd and PUMA SE. Your data may also be processed appropriately under certain circumstances in order to identify and correct misconduct within the company and to implement compliance programs and measures. This data processing is necessary in order to comply with our legal obligations (legal basis: Article 6(1)(c) GDPR) and/or for our legitimate interest to monitor processes and efficiency within stichd, to correct misconduct and fraud cases, to enforce and/or defend our rights and to find out about possible criminal offences (legal basis: Article 6(1)(f) GDPR). According to the law, we must retain the data related to contractual relationships for 7 years.
2.6.2. Performing analyses
Based on your data, which we process in accordance with the meaning of chapter 2 of this privacy policy, we can perform analyses. These serve as a basis for our business decisions, to improve our products and services, to adapt to the needs of our customers. The analyses made on this basis are no longer personal, so it is no longer possible to trace them back to you. This data processing is necessary for our legitimate interest to improve our products and services and to conduct marketing activities (legal basis: Article 6(1)(f) GDPR).
3. RETENTION AND DELETION OF YOUR PERSONAL DATA
We will only store your personal data for as long and as far as is necessary for the purposes mentioned in this privacy policy or as long and as far as we have a legal requirement to do so. By law, different retention periods apply to different types of records and data, whereas legal storage periods can be up to 10 years in some cases. This can be longer if we are required to keep personal data longer because of the applicable law or when necessary for our legitimate business interest, including legal investigations or disputes. If we need to keep any personal data longer for our legitimate business interest and protecting our legal rights, we will keep the necessary information for this purpose until the relevant claim(s) have been settled.
4. TRANSFER OF PERSONAL DATA AND CATEGORIES OF RECIPIENTS
Your personal data can be transferred/disclosed to the following categories of recipients:
1. Other companies with the stichd group within the scope of a group-internal collaborative process. Such data processing, if applicable, is necessary for the purpose of our legitimate interest to run our administration activities efficiently and collaboratively, and to improve our products and services (legal basis: Article 6(1)(f) GDPR).
2. PUMA Europe GmbH, PUMA United Kingdom Limited and PUMA North America Inc. (part of PUMA Group) for the purpose of sending of newsletters and marketing communications. The transfer of your personal data is based on your consent (legal basis: Article 6(1)(a) GDPR).
3. IT service providers, marketing services providers, payment providers and other service providers who, among other things, prepare the platforms, databases and tools for our products and services (e.g., the website, sell goods, sending informative e-mails), analyse user habits on the website, and process your personal data on our behalf during the purchase process.
4. Data analytics providers. In connection with the use of Google Analytics and Google Ads, including tags and cookies, your personal data may be transferred to the USA.
5. In order to provide you with a localised version of the website, we transfer your personal data to a third-party service provider in the USA.
6. For the delivery and return of your purchased goods on the website (including notifications about the delivery status of orders), we transfer your personal data to our contracted providers for handling the purchase / return and the shipping (e.g., DHL, UPS, TNT, Rebound etc.). The transfer of your personal data is based on the performance of a contract with you (legal basis: Article 6(1)(b) GDPR).
7. In addition, we transfer your personal data if we are legally obliged to do so (for example, to the authorities in the context of a criminal investigation or to the appropriate data protection supervisory authorities. This transfer of personal data is necessary in order to comply with a legal obligation (legal basis: Article 6(1)(c) GDPR) or where we reasonably conclude that its necessary for defending, exercising or establishing our legal rights for our legitimate interest (legal basis: Article 6(1)(f) GDRP).
5. RIGHT TO OBJECT TO DATA PROCESSING ON THE BASIS OF LEGITIMATE INTERESTS
We process your personal data within the meaning of chapter 2, based on our legitimate interest to ensure IT security on our Website, to adapt our website to your needs, to perform analyses and marketing activities, to inform you about our product reviews, to remind you about purchases that have not yet been completed, to prevent fraud and abuse, to prevent non-payment, to take care of our customers, to secure, strengthen and improve our legitimate interest (including in court if necessary) and to carry out our international management and cooperation. Please contact privacy@stichd.com for information on the balancing of interests by stichd. Notwithstanding the specific possibilities to object to the processing of data described in chapter 2 (e.g. the links to unsubscribe), you have the right to object at any time to the processing of your personal data on the basis of our legitimate interests in accordance with Article 6(1)(f) GDPR for reasons relating to your particular situation by sending an e-mail to privacy@stichd.com. We will then no longer process your data for these purposes, unless our legitimate interests for processing outweigh them or the processing is for the establishment, exercise, or substantiation of legal claims. If you object to the processing of your data, we will process the personal data collected in this context in order to respond to your request. This data processing is necessary in order to fulfil a legal obligation (legal basis: Article 6(1)(c) GDPR).
6. RIGHT TO WITHDRAW CONSENT
If you have given us permission to process your personal data, you can withdraw this permission at any time. The withdrawal of your consent is effective for the future and does not affect the lawfulness of processing based on consent before the withdrawal. Unless specifically provided for in chapter 2, please send your withdrawal of consent to privacy@stichd.com. If you withdraw your consent, we will process your personal data collected in this context in order to respond to your request. This data processing is necessary in order to fulfil a legal obligation (legal basis: Article 6(1)(c) GDPR).
7. YOUR OTHER DATA PROTECTION RIGHTS
In accordance with the GDPR, you have the following rights to exercise and to request from us that we:
• Provide you with information on your personal data that we process (Article 15 GDPR)
• Rectify your personal data stored on our systems (Article 16 GDPR)
• Delete your data (Article 17 GDPR)
• Restrict your data (Article 18 GDPR)
• Export your data (Article 20 GDPR)
Please send your request with at least your first and last name by e-mail to privacy@stichd.com or in writing to stichd sportmerchandising B.V., de Waterman 2, 5215 MX 's-Hertogenbosch, the Netherlands. If you exercise these rights, we will process your personal data to respond to your request. This data processing is necessary in order to fulfil a legal obligation (legal basis: Article 6(1)(c) under GDPR). Regardless of your rights mentioned above, you may lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data by stichd is in breach of the GDPR (Article 77 GDPR).
8. CHANGES TO THIS PRIVACY POLICY
The provisions of this privacy policy, including the information on cookies referred to, apply to the version in force at the time the online shop is used. stichd reserves the right to supplement and amend the content of this privacy policy. The updated privacy policy shall apply from the time it is published on our Website. In the event of substantial or material changes to the privacy policy, in particular changes that affect the processing of your personal data already collected by us, we will inform you in advance (e.g., by e-mail or via our Website).