Privacy policy
Last updated: 30 July 2026.
Who is responsible for your data
Stowkit (stowkit.eu) is a trading name of Botlease (KVK 95943420), the data controller for personal data processed through this shop. Contact: via our contact form.
What we collect and why
- Order data: your name, email, shipping address and order contents. We need this to process and deliver your order and to provide support. Legal basis: performance of a contract.
- Your cart: while you browse, your cart lives in your own browser and nowhere else. The moment you start checkout, the items in it and the address you fill in are sent to our own API (on our hosting) so the amount can be recalculated server-side and the order can be placed, and from there on to the payment and fulfilment partners below.
- Payment data: handled by our payment provider on its own secure page. We receive a payment status and a reference, not your full card number.
- Communications: messages you send us, kept so we can help you.
Who we share it with
These are all the outside parties that receive data. Each processes it on our instructions under a processing agreement, except where noted below. We never sell your data.
- Stripe (Ireland, part of a US group): payment. You enter your card or iDEAL details on Stripe's own page; we pass on the order amount, your email address and the order reference, and get back a payment status.
- CJ Dropshipping (China, with EU warehouses): fulfilment. Receives your name, address, email and the ordered products so your parcel can be packed and shipped. There is a second thing you should know: the product photos on this site are served straight from CJ's image servers (
cf.cjdropshipping.comandoss-cf.cjdropshipping.com). So on any page with product photos your browser fetches those images from CJ directly, which shows CJ your IP address, your browser details and which page you were looking at. That happens before any cookie question, because loading the photos is simply part of showing you the page and no cookie or tracker is involved. It does mean their servers see you. - Pexels (Pexels GmbH, Germany, part of the Australian Canva group): photo hosting. The home page, the category and collection pages, the guides and the news articles show stock photos served straight from Pexels' image servers (
images.pexels.com), and nearly every page on this site opens a connection to that host in advance so those photos load faster — including pages that then show none. Either way your browser contacts Pexels directly, so their servers see your IP address, your browser details and which page you were looking at. Just like the CJ images above, that happens before any cookie question, because the photos are part of showing you the page, and no cookie or tracker is involved. The files travel over a content-delivery network, so the machine that answers may sit outside the EU. Pexels is not acting on our instructions here; it hosts the photos and we link to them. - Resend (United States): email delivery. Sends your order confirmation and the messages from our contact form, so it processes your name, email address and the content of those messages.
- Vercel (United States): hosting and visitor statistics. Every request to this site runs through Vercel's servers, so it processes your IP address and browser data in order to deliver the page, and it produces our page-view counts (see below).
- Meta Platforms (Ireland, with transfers to the United States): advertising measurement, and only when both of these are true: we have switched our advertising pixel on and you pressed Accept in the cookie bar. Meta then also uses what it receives for its own purposes, so unlike the parties above it does not act on our instructions alone. The pixel has been configured since 30 July 2026, so the cookie bar appears on your first visit and this transfer takes place from the moment you press Accept. Press Decline, or answer nothing at all, and nothing is requested from Meta.
For the parties in the United States, that transfer rests on the EU standard contractual clauses or the EU–US Data Privacy Framework, depending on the provider; for CJ Dropshipping in China it rests on the standard contractual clauses.
How long we keep it
We keep order and invoice data for as long as required by law (Dutch tax law generally requires seven years for financial records) and delete other data when it is no longer needed.
Your rights
Under the GDPR you can request access to, correction of, or deletion of your personal data, object to processing, or ask for a copy of your data. Send your request via our contact form. You also have the right to complain to your national data-protection authority.
Cookies and similar techniques
We keep this short, because there is not much to keep track of. Three categories:
- Functional (always on): your shopping cart, your light/dark preference, your cookie choice and, briefly, the order you just placed are stored in your browser's own local storage. That is storage on your device, not a cookie sent to us. The keys are
stowkit.cart.v1,stowkit.theme,stowkit.consent.v1, plusstowkit.lastOrderorstowkit.pendingOrderafter checkout (an order reference, your email address, the items you ordered and the total — and for a demo order your name — so the confirmation page can show them) andstowkit.purchaseTracked(an order reference, so one order is never counted twice). If your browser blocks local storage we use session storage instead, which your browser itself throws away when you close the tab. The two order records are deleted as soon as you open the confirmation page for that order; if you never open it, the record stays in your own browser until you clear this site's data. The rest you can clear yourself in your browser settings too. Without this storage the shop cannot work, so no consent is required. - Statistics (always on, cookieless): we use Vercel Web Analytics to count page views. It sets no cookie and stores no identifier on your device, but it does derive a short technical hash from the incoming request (things like your IP address and browser) to tell the page views within one visit apart. That hash is not linked to your name or your order, and no profile is built about you across visits or across other websites.
- Advertising (only with your consent): our Meta (Facebook and Instagram) pixel has been configured since 30 July 2026, which is why a cookie bar appears on your first visit and asks before anything is loaded. Nothing is requested from Meta until you answer it. Press Accept and we load that pixel so we can measure which of our ads lead to a visit or a sale; it reads and sets cookies from Meta and shares data with Meta Platforms. What it sends is the pages and products you look at, the products you add to your cart, the start of a checkout and the order you place, with the amounts involved. Press Decline, or answer nothing at all, and not a single byte is requested from Meta.
Advertising cookies are only placed with your consent (Article 6(1)(a) GDPR and Article 11.7a of the Dutch Telecommunications Act). You can change your mind at any time: the Cookie settings link at the bottom of every page (it appears whenever there is advertising to consent to) erases your stored choice and opens the bar again, so withdrawing costs you exactly as many clicks as agreeing did. We also store when you answered and which version of the question you answered, so that if we ever change what we ask for, we ask again instead of leaning on an old yes. Questions, or would you rather we deleted data we already received? Mail hallo@botlease.nl.
Contact
Questions about your privacy? Use the form on our contact page; we reply within one business day. See also our Terms & conditions.