Privacy Policy
Last updated: 1 January 2026
EveraCart ("we", "us", "our") operates the website https://everacart.com (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our website, in accordance with the General Data Protection Regulation (GDPR), the Dutch Implementation Act for the GDPR (Uitvoeringswet AVG), and other applicable data protection legislation.
1. Data Controller
The data controller for the purposes of this Privacy Policy is:
EveraCart
Email: [email protected]
Website: https://everacart.com
2. Personal Data We Collect
We may collect the following categories of personal data:
2.1 Data You Provide Directly
- Contact form submissions: name, email address, subject, and message content
- Newsletter subscriptions: email address
- Correspondence: any data you share when communicating with us via email
2.2 Data Collected Automatically
- Usage data: pages visited, time spent on pages, referring URLs, and navigation paths
- Device data: browser type and version, operating system, screen resolution, and device type
- Connection data: IP address (anonymised where possible), internet service provider, and approximate geographic location (country/city level)
- Cookie data: as described in Section 7 below
3. Purposes and Legal Basis for Processing
We process your personal data for the following purposes:
| Purpose | Legal Basis (GDPR Art. 6) |
|---|---|
| Responding to contact form enquiries | Legitimate interest (Art. 6(1)(f)) |
| Sending newsletters (when subscribed) | Consent (Art. 6(1)(a)) |
| Website analytics and improvement | Legitimate interest (Art. 6(1)(f)) |
| Security and fraud prevention | Legitimate interest (Art. 6(1)(f)) |
| Legal compliance | Legal obligation (Art. 6(1)(c)) |
4. Data Sharing and Recipients
We do not sell your personal data. We may share your data with the following categories of recipients:
- Hosting providers: who store our website data on secure servers within the European Economic Area (EEA)
- Analytics providers: such as Google Analytics (with IP anonymisation enabled) to help us understand website usage
- Email service providers: to send newsletters and respond to enquiries
- Legal authorities: when required by law, court order, or legal process
All third-party processors are bound by data processing agreements in compliance with GDPR Article 28.
5. International Data Transfers
Where we use service providers based outside the EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, or we rely on an adequacy decision where available.
6. Data Retention
- Contact form data: retained for 12 months after the enquiry is resolved, then deleted
- Newsletter subscriptions: retained until you unsubscribe, then deleted within 30 days
- Analytics data: retained for 26 months (Google Analytics default with IP anonymisation)
- Server logs: retained for 90 days for security purposes
7. Cookies
Our website uses cookies — small text files stored on your device. We use the following types:
- Strictly necessary cookies: essential for the website to function (e.g., session management). These do not require consent.
- Analytics cookies: help us understand how visitors use our website. We use Google Analytics with IP anonymisation enabled. These cookies are only set with your consent.
- Preference cookies: remember your settings and choices. Set only with your consent.
You can manage cookie preferences at any time through our cookie consent banner or by adjusting your browser settings. Note that blocking certain cookies may affect website functionality.
8. Your Rights Under GDPR
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15): request a copy of the personal data we hold about you
- Right to rectification (Art. 16): request correction of inaccurate or incomplete data
- Right to erasure (Art. 17): request deletion of your personal data ("right to be forgotten")
- Right to restriction (Art. 18): request that we limit the processing of your data
- Right to data portability (Art. 20): receive your data in a structured, commonly used, machine-readable format
- Right to object (Art. 21): object to processing based on legitimate interest, including profiling
- Right to withdraw consent (Art. 7(3)): withdraw consent at any time where processing is based on consent
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
9. Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects or significantly affects you.
10. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include SSL/TLS encryption, secure hosting environments, access controls, and regular security reviews.
11. Children's Privacy
Our Service is not intended for individuals under 18 years of age. We do not knowingly collect personal data from minors. If we become aware that we have collected data from a person under 18, we will take steps to delete it promptly.
12. Third-Party Links
Our website contains links to third-party websites, including hotel booking platforms (e.g., Booking.com) and external resources. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing personal data.
13. Complaints
If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens):
Autoriteit Persoonsgegevens
P.O. Box 93374, 2509 AJ The Hague
Phone: +31 70 888 8500
Website: autoriteitpersoonsgegevens.nl
14. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page indicates the most recent revision. We will notify you of material changes by posting the updated policy on our website. Continued use of the Service after changes constitutes acceptance of the revised policy.
15. Contact
For questions, requests, or concerns about this Privacy Policy or our data practices, please contact us:
Email: [email protected]
Website: https://everacart.com/contact