Privacy Policy

Last updated: 19 August 2026

1. Who we are

MadeWeird is operated by DeBray ICT Diensten.

The controller responsible for processing personal data through this website is:

DeBray ICT Diensten / MadeWeird
Sophiastraat 23
4191 GG Geldermalsen
The Netherlands

KVK: 92503276
VAT ID: NL004962713B82
Email: info@madeweird.nl

Under the GDPR, organisations must explain what information they process, why they process it, the relevant legal basis, recipients, retention periods and individuals’ rights.

2. Personal data we may collect

Depending on how you use MadeWeird, we may process:

  • name;
  • email address;
  • billing information;
  • country and address information where required;
  • order and transaction information;
  • customer-account information;
  • purchased products and download history;
  • correspondence with us;
  • information submitted through our Project Request form;
  • uploaded project/reference files;
  • technical information such as IP address, browser information and security logs;
  • cookie and consent information;
  • information needed to prevent fraud or abuse.

We aim to collect only information that is reasonably necessary for the relevant purpose, in line with the GDPR principle of data minimisation.

3. Why we process your information

We may process personal information to:

  • process and fulfil orders;
  • provide digital downloads;
  • manage customer accounts;
  • process custom project requests;
  • communicate about an order or project;
  • provide customer support;
  • process payments and refunds;
  • maintain accounting and tax records;
  • prevent fraud, abuse and security incidents;
  • operate and improve the website;
  • comply with legal obligations;
  • manage cookie consent;
  • establish, exercise or defend legal claims.

4. Legal bases

Depending on the processing activity, we rely on one or more of the following GDPR legal bases:

Performance of a contract

We process information required to sell products, provide downloads, perform custom projects and provide customer support relating to an agreement.

Legal obligation

Certain financial, tax, accounting and transaction information must be retained where required by law.

Legitimate interests

We may process limited information where necessary for legitimate business interests, such as website security, fraud prevention, administration and defending legal claims, provided those interests are not overridden by your rights.

Consent

Where legally required, we ask for consent, for example for certain non-essential cookies or similar tracking technologies.

You may withdraw consent where processing is based on consent. Withdrawal does not affect processing that was lawful before consent was withdrawn.

5. Payments and Stripe

Payments are processed using Stripe.

When you make a payment, relevant personal and transaction information is transmitted to Stripe so that Stripe can process the transaction, prevent fraud and provide payment services.

MadeWeird does not receive or store your full debit or credit-card number.

Stripe processes personal data under its own privacy terms and legal responsibilities.

6. FluentCart

MadeWeird uses FluentCart within WordPress to manage products, customer details, orders, checkout information and digital delivery.

Order information handled through FluentCart is stored within the MadeWeird WordPress environment and associated systems as necessary to fulfil purchases and administer the store.

7. Project Request form

When you submit a Project Request, we may collect information including:

  • your name;
  • email address;
  • requested service;
  • platform;
  • estimated budget;
  • deadline;
  • project description;
  • references or links;
  • uploaded reference files.

We use this information to evaluate your request, communicate with you and, where applicable, prepare or perform an agreement.

Please do not submit sensitive personal information that is not necessary for your project.

8. Cookies and Cookiebot

MadeWeird intends to use Cookiebot by Usercentrics to manage cookie consent.

Cookiebot can record and manage consent choices and provide a Cookie Declaration listing cookies and trackers found on the website. The declaration can automatically categorise them and allow visitors to change or withdraw consent.

Non-essential cookies or similar technologies requiring consent will be handled through the cookie-consent mechanism where applicable.

For detailed information, see our Cookie Policy.

9. Service providers

We may share personal data with service providers where reasonably necessary to operate MadeWeird, for example:

  • payment-processing providers such as Stripe;
  • website hosting and infrastructure providers;
  • WordPress-related service providers;
  • consent-management providers such as Cookiebot/Usercentrics;
  • email-delivery providers;
  • security, backup or technical-support providers;
  • accountants, professional advisers or authorities where legally required.

We do not sell personal information to advertisers.

10. International transfers

Some service providers may process information outside the Netherlands or European Economic Area.

Where international transfers are subject to GDPR requirements, we expect appropriate transfer mechanisms or safeguards to be used as required by applicable law.

11. Retention

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including applicable legal, accounting and tax requirements.

Different information may therefore have different retention periods.

For example:

  • order and accounting information may be retained for statutory administration periods;
  • project correspondence may be retained for as long as reasonably necessary to perform and document the project;
  • unsuccessful project requests may be deleted when they are no longer reasonably needed;
  • technical/security logs may be retained for a shorter period unless needed to investigate an incident.

GDPR principles require personal data to be stored no longer than necessary, while allowing retention where another legal obligation requires it.

12. Security

We take reasonable technical and organisational measures to protect personal information against unauthorised access, loss, misuse or disclosure.

However, no internet-based service can guarantee absolute security.

13. Your GDPR rights

Subject to applicable conditions, you may have the right to:

  • access your personal data;
  • correct inaccurate data;
  • request deletion;
  • request restriction of processing;
  • object to certain processing;
  • receive certain data in a portable format;
  • withdraw consent;
  • lodge a complaint with a competent supervisory authority.

The GDPR requires controllers to facilitate these rights and provide individuals with relevant privacy information.

To exercise a privacy right, contact:

info@madeweird.nl

We may need to verify your identity before processing certain requests.

14. Children

MadeWeird is not intended to knowingly collect unnecessary personal information from young children.

If you believe a child has provided personal information without appropriate authorisation, please contact us.

15. Changes

This Privacy Policy may be updated when our website, providers or legal obligations change.

The latest version will be published on this page with the updated revision date.

16. Contact

Privacy questions can be sent to:

info@madeweird.nl

DeBray ICT Diensten / MadeWeird
Sophiastraat 23
4191 GG Geldermalsen
The Netherlands