Privacy policy
This policy explains which personal data we process when you visit santamood.com, place an order, create an account, leave a review or write to us: for what purpose, on what legal basis, who it is shared with, how long it is kept and how to exercise your rights.
Last updated: 15 September 2026.
Who is responsible for your data
The controller is NewZone, a private limited company incorporated under Belgian law, which operates the SantaMood brand and the santamood.com website.
- Registered office: Minervastraat 7, 1930 Zaventem, Belgium
- Company number: BE 0731.619.827
- Email address: info@santamood.com
For any question about your data, or to exercise your rights, write to us at this email address or by post to our registered office.
The data we process, and why
For each use, we state the data concerned, what we do with it and the legal basis it relies on, among those provided for in Article 6 of the General Data Protection Regulation (GDPR): the performance of a contract, a legal obligation, our legitimate interest or your consent.
Your order
Data: your email address, your first and last name, your company name if you give it, your delivery address (street, postcode, city, province or region, country), your phone number, the delivery method and pick-up point you chose, the items ordered, the amounts, the discount code used, the site language, the payment and shipping status, and the information Stripe sends back to us about each payment (it may include your name, your email address, your billing address and phone number, and the brand, country and last four digits of your card).
What for: recording and preparing your order, collecting payment, creating the shipping label and delivering to you, sending you the related messages (confirmation, dispatch, delivery, cancellation, refund), handling a withdrawal, a return, a complaint or a warranty claim, and checking that a promotion limited to a number of uses per customer is not exceeded.
Legal basis: the performance of the sales contract concluded with you (Article 6(1)(b) GDPR). Invoices and accounting records are also kept because the law requires us to do so (Article 6(1)(c)).
Reminders about an unfinished order
If you completed checkout without finishing payment, or if your payment was declined, we may send you a single reminder by email, a few hours later and never more than seven days after the order. Legal basis: our legitimate interest in letting you complete a purchase you started (Article 6(1)(f)). Each reminder contains a link to stop receiving them, which then applies to your email address.
Your customer account
Data: your first and last name, your email address, your password (stored in a form from which it cannot be recovered), your phone number and delivery address if you enter them, your language, the dates the account was created and last visited, and your order history.
What for: letting you log in, find and track your orders, change your details, download your data or close your account. Legal basis: the performance of the contract under which we provide this account (Article 6(1)(b)).
Our news and offers by email
If you tick the box provided when creating your account and then confirm your address, we may write to you about our news and offers. Legal basis: your consent (Article 6(1)(a)). We keep proof of this consent: its date, its origin, the text you accepted and the language. You can withdraw it at any time, without giving a reason, in “My account”, under “My details”, or by writing to us; withdrawal does not affect what was done before.
Reviews
Data: the name you choose to display, your email address (never published: it is used to check your purchase), your rating, the title and text of your review, the order number if you give it, the language, and the IP address and type of browser used.
What for: publishing your review on the site after moderation, marked as a “verified purchase” if it matches an order, and replying to it. Legal basis: your consent, given by sending us your review for publication (Article 6(1)(a)); you can ask for it to be removed at any time. The IP address and browser are used to filter out abusive submissions, based on our legitimate interest in protecting the site (Article 6(1)(f)).
After an order has been delivered, we may invite you by email, once for that order, to leave a review. Legal basis: our legitimate interest in gathering our buyers’ opinions (Article 6(1)(f)). Each invitation contains a link to stop receiving them.
Your messages
Data: your name, your email address, your message, the page language, and the IP address and type of browser used. We send you an acknowledgement of receipt by email, at most one a day; it does not repeat the content of your message.
What for: answering your request. Legal basis: the performance of the contract, or of steps taken at your request before entering into it, when your message is about an order (Article 6(1)(b)); for other requests, our legitimate interest in replying to you (Article 6(1)(f)). The IP address and browser are used to filter out automated submissions, based on our legitimate interest in protecting the site.
Site security
Data: to limit repeated login attempts, the email address entered, the IP address, and the date and result of each attempt; the IP address from which an address-confirmation or new-password link is requested; the server’s technical logs (IP address, page requested, date and time, browser). What for: protecting your accounts and the site against fraudulent access and abuse, and diagnosing faults. Legal basis: our legitimate interest in keeping the site and your data secure (Article 6(1)(f)).
Audience measurement and advertising measurement
Only if you accept it in the “Cookies” banner, we use Google Analytics, loaded through Google Tag Manager, to count visits, page views and purchases, and the Meta pixel to find out whether our ads shown by Meta lead to visits and purchases. Data: the address of the pages viewed, the identifiers stored in their cookies, the technical information your browser sends (including your IP address) and, on the page confirming a purchase, the order number, amount and currency — never your name, postal address or email address. Legal basis: your consent (Article 6(1)(a)). The details are in the “Cookies” section below.
Keeping track of your requests and refusals
When you exercise a right, erasure for example, we keep a record of your request and of how it was handled. If you refuse our reminders or our invitations to leave a review, we keep a fingerprint (hash) of your email address — the address itself is not stored in this list — so that we no longer send them to you, even after your other data has been erased. Legal basis: the obligations the GDPR places on us to respect your rights and be able to demonstrate it (Article 6(1)(c)).
Data carried over from our previous shop
Our previous online shop ran on the Shopify platform. We have carried over into our own system the customer accounts, the orders, the consents to receive our offers, the shop’s activity log and the contact details left during orders that were not completed; the latter are not used to send anything. As long as our Shopify account has not been closed, Shopify also keeps this data.
Do you have to give us this data?
The required fields in our forms are necessary: without them we cannot record or deliver your order (email address, name, address, postcode, city and country; the phone number for delivery outside Belgium; the province for delivery to Italy), create your account, publish your review or answer your message. The other fields are optional. Accepting measurement cookies and receiving our offers is entirely up to you: refusing changes nothing about your purchases.
Automated decisions
We do not take any decision based solely on automated processing, including profiling, that produces legal effects concerning you or similarly significantly affects you. Stripe itself analyses payments to detect and prevent fraud, as the controller of that processing; this check is covered by Stripe’s privacy policy.
Who receives your data
Your data is processed by NewZone, and only the people who need it for their work have access to it. We neither sell nor rent your data. We entrust it to the following service providers, for the service they provide to us:
- Stripe (Stripe Payments Europe, Limited, Ireland), for payment: Stripe receives the amount, the order number, the language and your email address, as well as what you enter in its payment form (your card number, for example), which never passes through our servers. For detecting and preventing fraud and for its own legal obligations, Stripe acts as a controller.
- Sendcloud (Sendcloud B.V., Eindhoven, Netherlands), for creating shipping labels and tracking parcels: Sendcloud receives your name, company, address, phone number and email address, the order number, the parcel weight and the chosen pick-up point. Sendcloud states that it deletes this data within 365 days after shipment.
- The carrier delivering your parcel (Mondial Relay, Bpost, DPD or UPS, depending on the country and delivery method chosen): it receives, through Sendcloud, the data needed for delivery.
- OVHcloud (OVH SAS, Roubaix, France), for sending our emails: OVHcloud receives your email address and the content of the messages we send you.
- Google (Google Ireland Limited, Ireland), for audience measurement, only with your consent.
- Meta (Meta Platforms Ireland Limited, Ireland), for advertising measurement, only with your consent. For the collection of this data on our site and its transmission to Meta, NewZone and Meta Platforms Ireland Limited are joint controllers (Article 26 GDPR), under an agreement published by Meta (“Controller Addendum”); what Meta then does with the data is its sole responsibility and is covered by its privacy policy, and Meta handles requests to exercise rights over the data it keeps.
- Our server’s hosting provider, for storing the site, its database and its backups.
We may also disclose data to our accountant, to a legal adviser or to a public authority (tax administration, courts, police) when the law requires it or to defend our rights.
Transfers outside the European Economic Area
Stripe, Google and Meta may transfer data to the United States, and Stripe to other countries. For the United States, they state that they rely on the EU–US Data Privacy Framework, recognised by an adequacy decision of the European Commission, and they provide for the standard contractual clauses adopted by the Commission. Sendcloud states that it may use sub-processors located outside the European Union and the European Economic Area, in particular by having them sign those standard contractual clauses. You can ask us where these safeguards are published.
How long we keep your data
- Orders, invoices and accounting records: seven years from 1 January of the year following the order, as required by Belgian VAT and accounting law. No automatic deletion is scheduled after that; you can ask us to erase what is no longer legally required.
- Customer account: for as long as it remains open. If you close it, your access is cut off immediately; your other data is erased or anonymised within one month of your request, except for the billing identity on your orders, which is kept until the end of the legal period and then erased.
- Cart: thirty days after it was last changed.
- Unpaid order: cancelled after thirty days if the payment provider confirms it was not paid; it then remains recorded as a cancelled order.
- Login attempts: thirty days. Browsing session: thirty minutes of inactivity. Choice made in the “Cookies” banner: six months.
- Consent to receive our offers: until it is withdrawn. List of refusals of reminders and invitations: with no time limit, so that your refusal continues to be respected.
- Published reviews: until you ask for them to be removed.
- Site error logs: twelve weeks. Database backups on the server: fourteen days for daily copies, eight weeks for weekly copies; erased data disappears from the backups as they are renewed.
- Google Analytics statistics linked to an identifier: two or fourteen months, depending on the setting of our Google Analytics account.
- Messages sent through the contact form, emails sent by the site, information received from Stripe about payments, IP addresses (and browser type) recorded with reviews, messages and requests for a confirmation or new-password link, shipping labels, unpublished reviews, server access logs, proof of consent, records of requests to exercise your rights and data carried over from our previous shop (activity log, contact details from unfinished orders): no maximum period has been set yet; you can ask for them to be erased at any time, subject to what the law requires us to keep.
Your rights
At any time, you can:
- access the data we hold about you and obtain a copy;
- have inaccurate data corrected or incomplete data completed;
- have your data erased, except data the law requires us to keep or that is still needed, for example for an ongoing dispute;
- have the processing of your data restricted;
- receive the data you provided to us in a structured, commonly used and machine-readable format, or ask us to transmit it to another controller;
- object, on grounds relating to your particular situation, to processing based on our legitimate interest, and, without giving a reason, to reminders and invitations to leave a review;
- withdraw your consent, without affecting what was done before.
If you have an account, “My account” lets you change your details, download your data and close your account. For any other request, write to us at:
We reply within one month, which may be extended by two further months for a complex request or if we receive many; in that case we tell you within the first month. To protect your data, we may ask you to confirm your identity, for example by writing to us from the email address linked to your account or order.
To withdraw your consent to measurement cookies, use the “Cookies” link at the bottom of every page; for our offers by email, “My account” or a simple message; for reminders and invitations to leave a review, the link in each of those emails.
If you believe that the processing of your data does not comply with the rules, you can lodge a complaint with the Belgian Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit), Rue de la Presse 35, 1000 Brussels, phone +32 (0)2 274 48 00, contact@apd-gba.be, www.dataprotectionauthority.be — or with the supervisory authority of the European Union country where you live or work. You can also write to us first: we will look for a solution with you.
Cookies
A cookie is a small file that a website stores in your browser. santamood.com uses strictly necessary cookies, which do not require your consent, and, only if you accept them, audience measurement and advertising measurement cookies. The site stores nothing else in your browser (no local storage and no session storage).
Strictly necessary cookies
- sm_session, set by santamood.com: protects our forms against fraudulent submissions and remembers that you are logged in to your account and which order is being paid. It is set on pages that contain a form, on the cart and checkout, and on any page once your cart contains items; information pages do not set it. Duration: until you close the browser; the session expires after thirty minutes of inactivity.
- sm_panier, set by santamood.com when you add an item: finds your cart again using a randomly drawn identifier that contains no personal data. Duration: thirty days after the cart was last changed.
- sm_consentement, set by santamood.com when you make a choice in the banner: remembers that choice, without any identifier. Duration: six months.
- sm_appareil_admin and sm_appareil_client, set by santamood.com when you log in to your account: recognise a device that has logged in before, so that it is not locked out by someone else’s login attempts on your address. They contain a signature and a date, not your address in readable form, and give no access without your password. Duration: six months.
- __stripe_mid and __stripe_sid, set by Stripe under the santamood.com domain name, on the payment page only: fraud prevention, to assess the risk of a payment attempt. Duration: one year for __stripe_mid, thirty minutes for __stripe_sid.
- On the payment page, Stripe’s form also sets cookies on domains other than ours, covered by Stripe’s cookie policy: for example m, on m.stripe.com, for fraud detection (two years according to Stripe), or a security cookie from hcaptcha.com, an anti-bot service loaded inside that form (thirty minutes).
Cookies that require your consent
They are set only after you consent, and never on the checkout, the payment page, your account, order tracking or a page opened from a personal link (review invitation, address confirmation, tracking, return from payment). Without JavaScript, neither the banner nor these tools are loaded.
- Audience measurement — Google Analytics, loaded through Google Tag Manager (Google): _ga, to distinguish visitors, and _ga_ followed by our account identifier, to keep the session state, both set under the santamood.com domain name. Duration: two years according to Google (browsers may shorten it, to 400 days at most for Chrome).
- Advertising measurement — Meta pixel (Meta): _fbp and _fbc, set under the santamood.com domain name, which identify the browser so that Meta can provide its advertising and measurement services. Duration: 90 days according to Meta.
Giving, refusing or withdrawing your consent
On your first visit, a banner offers you “Reject all”, “Accept all” or “Choose”, purpose by purpose, with no box ticked in advance. Refusing changes nothing about your visit or your purchases. You can change your mind at any time with the “Cookies” link at the bottom of every page, which reopens the banner. If you withdraw your consent, the Google and Meta cookies stored under the santamood.com domain name are deleted and the page reloads; any cookies Meta may have set on its own domains, such as facebook.com, cannot be deleted by our site: you can remove them in your browser settings. Your choice is kept for six months; you are also asked again if we add a purpose or a recipient.
You can also block or delete cookies in your browser settings; without the strictly necessary cookies, the cart, checkout and logging in to your account do not work.
Security
We take technical and organisational measures to protect your data: encrypted connection (HTTPS), passwords stored in an irreversible form, administration restricted to authorised people, limits on login attempts, and regular backups. Your card details are entered in Stripe’s form and never pass through our servers. As no transmission over the Internet is completely secure, choose a strong password and do not share it with anyone.
Links to other websites
Our site contains links to other websites, for example our social media pages. These links set no cookies and send nothing until you click; the sites you open then apply their own privacy policy.
Changes to this policy
We update this policy when the site, our service providers or the law change. The version in force is the one published on this page, with its update date. If a change affects the cookies that require your consent, the banner asks for your choice again.