ICONS OF CYCLING

Privacy policy

What we collect when you order, why we need it, who else sees it, and how to get it back or removed.

Last updated 9 August 2026

  1. Who is responsible
  2. What we collect, and on what legal basis
  3. Simply visiting the site
  4. Where your data actually sits
  5. Who else processes your data
  6. Transfers outside the EEA
  7. How long we keep it
  8. Your rights
  9. Cookies and local storage
  10. Security
  11. Children
  12. Changes

01Who is responsible

The controller of your personal data is:

Echelons (eenmanszaak)
Melis Stokelaan 19, 1948 DA Beverwijk, Netherlands
KvK 84317663
kirsten.vansteenberge1@gmail.com

We are a one-person business selling a single book. We do not have a data protection officer, and we are not required to appoint one.

02What we collect, and on what legal basis

We collect only what an order needs. There is no account, no newsletter, no profiling and no advertising.

DataWhyLegal basis (GDPR)
NameTo address the parcel and the certificateArt. 6(1)(b) — performance of a contract
Email addressOrder confirmation, delivery updates, questions about your orderArt. 6(1)(b)
Phone numberSo the courier can reach you about deliveryArt. 6(1)(b)
Delivery addressTo send the bookArt. 6(1)(b)
Dedication text, if you provide oneSo the author can write it into your copyArt. 6(1)(b)
Quantity, order reference, language, payment detailsTo process and record the saleArt. 6(1)(b)
Which link brought you here (for example a code on a card in a shop)To understand which channels work, in aggregateArt. 6(1)(f) — legitimate interest
Invoice and transaction recordsTax and accounting obligationsArt. 6(1)(c) — legal obligation

We never see your card or bank details. Payment is handled entirely by Mollie on their own pages. We receive only whether the payment succeeded, the amount, and the method used.

Providing this data is necessary to buy the book. Without it we cannot conclude or perform the contract. You may object at any time to the source-tracking described above, and it will not affect your order.

03Simply visiting the site

If you only look at the site and do not order, we do not collect anything that identifies you. Our host processes standard server request data — IP address, time, page requested, browser type — which is technically unavoidable in serving a web page and is used only to deliver the site and protect it from abuse. That processing rests on Art. 6(1)(f).

We do not use Google Fonts, Google Analytics, Meta pixels, advertising networks or session recording. Typefaces are served from our own domain, so no third party learns you were here.

04Where your data actually sits

This website stores nothing. It passes your order to Mollie and forgets it. But the order itself has to live somewhere, and we would rather be specific than reassuring:

WhereWhatHow long
Mollie's systemsThe payment and the order details attached to itSeven years, per Dutch tax law
Our email accountThe order notification we receive, and any correspondence with youOrder emails seven years; other correspondence up to two years
Our accounting recordsInvoice dataSeven years, per Dutch tax law
Occasional exportsA spreadsheet of orders, used to write shipping labelsDeleted once the parcels are sent

Access to all of these is protected by two-factor authentication. Order exports are deleted after use rather than kept.

05Who else processes your data

We use a small number of processors, each under a data processing agreement, each strictly for the purpose stated:

ProcessorRoleWhat they receive
Mollie B.V. (Netherlands)PaymentsName, email, address, order details, payment data
Cloudflare, Inc.Hosting and delivery of the siteRequest data; order data in transit
Resend (email delivery)Sending your confirmationName, email, order details
Postal carrierDelivering the parcelName, address, phone number

We do not sell personal data, we do not share it for anyone else's marketing, and we do not pass it to anyone beyond the parties above except where the law obliges us to.

06Transfers outside the EEA

Mollie is a Dutch company and processes within the EU. Cloudflare and Resend are US companies that may process data outside the EEA. Where that happens, transfers are covered by the European Commission's Standard Contractual Clauses together with the technical measures those providers apply. You may ask us for details of these safeguards.

07How long we keep it

After those periods the data is deleted.

08Your rights

Under the GDPR you may ask us to:

Email kirsten.vansteenberge1@gmail.com and we will respond within one month. There is no charge. We may ask a question to confirm it is really you, so that we do not hand your data to someone else.

If you are unhappy with how we have handled your data, you can complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or to the authority where you live.

We do not carry out automated decision-making or profiling that produces legal effects for you.

09Cookies and local storage

This site sets no tracking cookies. Nothing is stored on your device for advertising, profiling or cross-site tracking.

We store one thing locally, and only after you have answered the notice: your choice about optional measurement. That preference stays in your browser, is never sent to us, and exists purely so we do not ask again. Under Art. 5(3) of the ePrivacy Directive, storing a preference you have just expressed is strictly necessary and needs no separate consent.

If optional measurement is switched on, we use Cloudflare Web Analytics, which is cookieless and produces aggregate counts only — pages viewed, roughly where visitors came from. It does not fingerprint you, follow you across sites, or build a profile. You can change your answer at any time from the link in the footer.

10Security

The site is served only over HTTPS and stores no personal data of its own. Payment happens on Mollie's own systems. Our view of orders is behind a password with rate limiting against guessing, and content security and framing protections are applied at the server.

Every account that can reach your data — payments, email, hosting — is protected by two-factor authentication. We keep the data set deliberately small, because the safest data is the data you never collected.

If a breach occurs that is likely to risk your rights and freedoms, we will report it to the Autoriteit Persoonsgegevens within 72 hours of becoming aware of it, and tell you directly without undue delay where the risk to you is high.

11Children

This shop is not aimed at children and we do not knowingly collect data from anyone under 16. If you believe a child has provided us with personal data, write to us and we will delete it.

12Changes

If we change this policy we will update the date at the top. Material changes affecting your rights will be communicated by email to anyone with an order in progress.

See also our terms of sale and accessibility statement.

Icons of Cycling is published by teNeues. The copies sold here are ordinary trade copies from the author's own stock, signed and numbered by him personally. They are not a separate teNeues edition, and this site is not affiliated with or endorsed by the publisher.

← Back to the book