Privacy policy
Privacy Policy
Last Updated: July 30, 2026
This Privacy Policy explains how TØMRERMESTER BO HVID ApS collects, uses, stores, shares and protects personal data when customers in Germany visit zhglxw.shop, place an order, select Cash on Delivery, receive free delivery or contact our customer service.
Please read this Privacy Policy carefully before using the website or providing personal data.
1. Data Controller
The data controller responsible for processing personal data through zhglxw.shop is:
Company Name:
TØMRERMESTER BO HVID ApS
Company Registration Number (CVR):
26552877
Registered Address:
Maglekærvej 20
4600 Køge
Denmark
Website:
zhglxw.shop
Email:
nampham11012001@gmail.com
In this Privacy Policy, TØMRERMESTER BO HVID ApS may be referred to as “the Company,” “we,” “us” or “our.”
2. Scope of This Privacy Policy
This Privacy Policy applies when a customer or visitor:
-
Visits or browses zhglxw.shop;
-
Views or searches for products;
-
Adds products to the shopping cart;
-
Creates or uses a customer account, where available;
-
Places or manages an order;
-
Selects Cash on Delivery;
-
Receives free standard delivery;
-
Tracks a shipment;
-
Contacts customer service;
-
Requests cancellation, return, exchange or refund;
-
Submits a review, photograph, video or other content;
-
Subscribes to marketing communications;
-
Otherwise interacts with our website or services.
3. Personal Data We May Collect
The personal data collected depends on how the customer uses our website and services.
Identity and Contact Data
We may collect:
-
Full name;
-
Delivery address;
-
Billing address, where applicable;
-
Postal code;
-
City;
-
Country;
-
Email address;
-
Telephone number;
-
Customer or account identifier;
-
Information required to verify identity.
Order and Transaction Data
We may collect:
-
Order number;
-
Products ordered;
-
Product model, size, colour or specification;
-
Quantity;
-
Purchase price;
-
Discounts or promotional information;
-
Order date;
-
Order status;
-
Cash on Delivery amount;
-
Payment and collection status;
-
Delivery status;
-
Tracking number;
-
Cancellation, return and refund information;
-
Communications relating to the transaction.
Customer Account Data
Where customer accounts are offered, we may collect:
-
Username;
-
Email address;
-
Encrypted password;
-
Saved delivery details;
-
Order history;
-
Communication preferences;
-
Shopping-cart information.
Customer-Service Data
When a customer contacts us, we may collect:
-
Name and contact details;
-
Order number;
-
Product information;
-
Description of the enquiry;
-
Complaint details;
-
Return or refund reason;
-
Photographs or videos;
-
Delivery evidence;
-
Copies of correspondence.
Customers should not provide personal data that is unnecessary for resolving their enquiry.
Technical and Usage Data
When the website is accessed, we may automatically collect:
-
IP address;
-
Browser type and version;
-
Browser language;
-
Device type;
-
Operating system;
-
Date and time of access;
-
Pages and products viewed;
-
Referring website;
-
Session duration;
-
Click and navigation information;
-
Shopping-cart activity;
-
Cookie or similar identifiers;
-
Approximate location derived from the IP address;
-
Security, error and performance logs.
Marketing and Preference Data
Where applicable, we may collect:
-
Marketing consent;
-
Newsletter subscription status;
-
Product interests;
-
Previously viewed or purchased products;
-
Advertising interactions;
-
Survey responses;
-
Communication preferences.
4. How We Collect Personal Data
We may collect personal data:
Directly From Customers
This includes information provided when customers:
-
Complete website forms;
-
Place an order;
-
Enter delivery details;
-
Create an account;
-
Select Cash on Delivery;
-
Contact customer service;
-
Submit a return or refund request;
-
Send photographs or videos;
-
Submit a product review;
-
Subscribe to marketing communications.
Automatically
Technical information may be collected through:
-
Cookies;
-
Server logs;
-
Session technologies;
-
Analytics tools;
-
Device identifiers;
-
Security tools;
-
Fraud-prevention systems.
From Service Providers
We may receive relevant information from:
-
Courier and logistics providers;
-
Warehousing and fulfilment providers;
-
Cash on Delivery collection partners;
-
E-commerce platforms;
-
Website-hosting providers;
-
Customer-support providers;
-
Fraud-prevention providers;
-
Analytics and advertising providers.
5. Cash on Delivery Data
Customers may pay for eligible orders using Cash on Delivery.
To process a Cash on Delivery order, we may collect and share:
-
Customer’s name;
-
Delivery address;
-
Telephone number;
-
Email address;
-
Order number;
-
Amount payable;
-
Delivery instructions;
-
Payment-collection status;
-
Information about failed or refused delivery.
The courier may contact the customer to confirm the address, arrange delivery or collect the amount due.
We do not collect complete payment-card information for a Cash on Delivery transaction.
Cash on Delivery Refunds
A refund for a Cash on Delivery order cannot normally be returned in cash by the courier.
Where a refund is approved, the customer may be asked to provide:
-
Name of the account holder;
-
IBAN or other required bank details;
-
BIC, where necessary;
-
Order number;
-
Information required to verify the refund recipient.
Refund details will be used only to process the refund, maintain required financial records and prevent fraud.
6. Free Shipping and Delivery Data
Standard shipping is free for eligible orders, but personal data must still be processed to prepare and deliver the order.
We may provide the courier or fulfilment provider with:
-
Recipient’s name;
-
Delivery address;
-
Postal code;
-
Telephone number;
-
Email address;
-
Order reference;
-
Package information;
-
Delivery instructions;
-
Cash on Delivery amount.
Courier providers may contact customers to:
-
Confirm delivery details;
-
Arrange delivery;
-
Provide tracking updates;
-
Request additional information;
-
Notify the customer of an attempted delivery;
-
Resolve delivery or payment problems.
7. Purposes of Processing
We may process personal data to:
-
Operate and maintain zhglxw.shop;
-
Display products and website content;
-
Maintain shopping-cart and checkout functions;
-
Create and manage customer accounts;
-
Accept and process orders;
-
Verify customer and order information;
-
Process Cash on Delivery orders;
-
Arrange free standard delivery;
-
Provide tracking information;
-
Communicate about an order or delivery;
-
Handle failed or refused deliveries;
-
Answer customer enquiries;
-
Process cancellations, returns, exchanges and refunds;
-
Handle damaged, defective or incorrect products;
-
Maintain transaction and accounting records;
-
Comply with tax and legal obligations;
-
Detect fraud and misuse;
-
Protect website and transaction security;
-
Analyse website performance;
-
Improve products and customer service;
-
Personalize website content;
-
Send marketing communications where permitted;
-
Establish, exercise or defend legal claims.
8. Legal Bases for Processing
We process personal data only where an appropriate legal basis applies.
Performance of a Contract
Personal data may be processed where necessary to:
-
Process an order;
-
Arrange Cash on Delivery;
-
Deliver a product;
-
Provide tracking information;
-
Respond to an order-related enquiry;
-
Process a return, exchange or refund.
Compliance With Legal Obligations
We may process and retain information where required for:
-
Accounting;
-
Tax reporting;
-
Consumer protection;
-
Product safety;
-
Fraud prevention;
-
Regulatory requests;
-
Court proceedings;
-
Other legal obligations.
Legitimate Interests
We may rely on legitimate interests to:
-
Prevent fraud and abuse;
-
Protect website security;
-
Verify suspicious orders;
-
Improve our services;
-
Maintain transaction records;
-
Respond to customer enquiries;
-
Analyse website performance;
-
Protect or enforce legal rights.
We will consider whether the customer’s rights and interests override our legitimate interests.
Consent
Where required, we will obtain consent before:
-
Using non-essential cookies;
-
Using certain analytics or advertising technologies;
-
Sending marketing emails;
-
Processing data for an optional purpose.
Customers may withdraw consent at any time. Withdrawal does not affect processing carried out lawfully before consent was withdrawn.
9. Cookies and Similar Technologies
The website may use cookies and similar technologies.
Essential Cookies
Essential technologies may be used to:
-
Operate the website;
-
Maintain the shopping cart;
-
Provide secure checkout;
-
Remember privacy choices;
-
Maintain login sessions;
-
Prevent fraud;
-
Protect website security.
These technologies may be used without consent where they are strictly necessary to provide a service expressly requested by the user.
Optional Cookies
With consent where required, optional cookies may be used to:
-
Measure website traffic;
-
Analyse visitor behaviour;
-
Remember preferences;
-
Personalize content;
-
Measure advertising effectiveness;
-
Display relevant advertising.
Optional analytics, advertising and personalization technologies will not be activated before valid consent is obtained where consent is legally required.
Customers may change or withdraw cookie consent through the cookie settings available on the website.
10. Marketing Communications
We may send marketing communications where the customer has consented or where another lawful basis applies.
Marketing messages may contain information about:
-
Products;
-
Discounts;
-
Special offers;
-
Promotions;
-
New services.
Customers may unsubscribe at any time by:
-
Using the unsubscribe link in a marketing email;
-
Changing available account preferences;
-
Contacting nampham11012001@gmail.com.
Customers may continue to receive necessary service communications relating to orders, delivery, returns, security or account administration.
11. Sharing Personal Data
We may share personal data where necessary with:
-
Courier and logistics providers;
-
Warehousing and fulfilment providers;
-
Cash on Delivery collection partners;
-
Website-hosting providers;
-
E-commerce platforms;
-
Cloud-service providers;
-
Customer-support providers;
-
Email-service providers;
-
IT and security providers;
-
Fraud-prevention providers;
-
Analytics and advertising providers;
-
Accountants and tax advisers;
-
Lawyers and professional advisers;
-
Regulators, courts and public authorities.
Service providers are expected to process personal data only for authorized purposes and in accordance with applicable contractual and legal requirements.
We do not sell customers’ personal data to independent third-party advertisers.
12. Disclosure Required by Law
We may disclose personal data where reasonably necessary to:
-
Comply with applicable law;
-
Respond to a valid court order;
-
Respond to a lawful government or regulatory request;
-
Investigate fraud or security incidents;
-
Protect the safety and rights of customers or third parties;
-
Establish, exercise or defend legal claims;
-
Complete a merger, restructuring or transfer of business assets.
13. International Data Transfers
Some service providers may process or store personal data outside Germany, Denmark or the European Economic Area.
Where an international transfer requires additional safeguards, we may rely on:
-
A European Commission adequacy decision;
-
Standard Contractual Clauses;
-
Binding Corporate Rules;
-
Additional technical and organizational safeguards;
-
Another legally permitted transfer mechanism.
Customers may contact us for further information about safeguards used for an applicable transfer.
14. Data Retention
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected.
Retention periods may depend on:
-
The duration of the customer relationship;
-
Order-processing requirements;
-
Delivery and Cash on Delivery records;
-
Return and refund periods;
-
Accounting and tax obligations;
-
Product-guarantee requirements;
-
Fraud-prevention requirements;
-
Legal limitation periods;
-
Ongoing complaints or disputes;
-
The need to establish or defend legal claims.
When personal data is no longer required, it will be securely deleted, anonymized or restricted from further use where immediate deletion is not legally possible.
15. Data Security
We use reasonable technical and organizational measures designed to protect personal data against:
-
Unauthorized access;
-
Accidental loss;
-
Unlawful disclosure;
-
Alteration;
-
Destruction;
-
Misuse;
-
Unauthorized processing.
Security measures may include:
-
Access restrictions;
-
Password protection;
-
Secure server environments;
-
Encryption where appropriate;
-
Security monitoring;
-
Fraud-prevention controls;
-
Data backups;
-
Restricted employee and contractor access.
No internet transmission or electronic-storage system can be guaranteed to be completely secure.
16. Personal-Data Breaches
If a personal-data breach occurs, we will assess the nature, scope and potential consequences of the incident.
Where legally required, we will notify:
-
The competent data-protection authority;
-
Affected individuals where the breach is likely to result in a high risk to their rights and freedoms.
Customers who suspect unauthorized access to their account or personal data should contact us promptly.
17. Customer Data-Protection Rights
Subject to applicable law, customers may have the following rights:
Right of Access
Customers may request confirmation of whether we process their personal data and obtain a copy of eligible data.
Right to Rectification
Customers may request correction of inaccurate data or completion of incomplete data.
Right to Erasure
Customers may request deletion of personal data where the applicable legal requirements are met.
Deletion may not be possible where information must be retained to comply with legal obligations, process an order, prevent fraud or defend legal claims.
Right to Restriction
Customers may request restriction of processing in certain circumstances.
Right to Data Portability
Where applicable, customers may request eligible data in a structured, commonly used and machine-readable format.
Right to Object
Customers may object to processing based on legitimate interests for reasons relating to their particular situation.
Right to Object to Direct Marketing
Customers may object to the use of their personal data for direct marketing at any time.
Right to Withdraw Consent
Where processing is based on consent, customers may withdraw that consent at any time.
Rights Relating to Automated Decisions
Where applicable, customers may have the right not to be subject to certain decisions based solely on automated processing that produce legal or similarly significant effects.
Right to Lodge a Complaint
Customers may lodge a complaint with a competent data-protection supervisory authority.
18. Exercising Privacy Rights
To exercise a data-protection right, contact:
Email: nampham11012001@gmail.com
The request should include:
-
Full name;
-
Email address used for the order or account;
-
Order number, where relevant;
-
A clear description of the request;
-
Information reasonably necessary to verify identity.
We may request additional proof of identity before disclosing, correcting, transferring or deleting personal data.
A request may be restricted or refused where:
-
The requester’s identity cannot be verified;
-
Disclosure would adversely affect another person’s rights;
-
We are legally required to retain the information;
-
The request is manifestly unfounded or excessive;
-
Another legal exemption applies.
We will respond within the period required by applicable data-protection law.
19. Children and Minors
The website is not specifically directed at children.
A person who does not have the legal capacity to enter into a purchase contract must use the website only with the authorization and supervision of a parent or legal guardian.
We do not knowingly seek to collect unnecessary personal data from children.
20. Third-Party Websites
The website may contain links to independent third-party websites or services.
This Privacy Policy does not govern the privacy practices of independent third parties.
Customers should review the relevant third party’s privacy policy before submitting personal data.
21. Changes to This Privacy Policy
We may update this Privacy Policy because of:
-
Changes in applicable law;
-
Regulatory or court guidance;
-
Changes to our services;
-
Changes to courier or fulfilment providers;
-
Changes to website technologies;
-
Security developments;
-
Changes in our business operations.
The latest version will be published on zhglxw.shop.
Where appropriate, material changes may also be communicated through the website or by email.
22. Complaints
Customers are encouraged to contact us first so that we can investigate and attempt to resolve the concern.
Because the Company is established in Denmark, customers may also submit a complaint to the Danish Data Protection Agency:
Datatilsynet – Danish Data Protection Agency
Carl Jacobsens Vej 35
2500 Valby
Denmark
Email: dt@datatilsynet.dk
Customers in Germany may also contact the competent data-protection authority for their place of residence, place of work or the location of the alleged infringement.
23. Contact Information
For questions about this Privacy Policy or our processing of personal data, contact:
Company Name:
TØMRERMESTER BO HVID ApS
Company Registration Number (CVR):
26552877
Registered Address:
Maglekærvej 20
4600 Køge
Denmark
Website:
zhglxw.shop