Privacy policy Bigroon
Privacy policy
Last updated: 14 September 2026
This privacy policy explains how Bigroon collects, uses, stores and shares personal data when you visit www.bigroon.com (the “Site”), place an order, contact us or otherwise use our services.
1. Who is responsible for your personal data?
The controller is OosterHard Commerce, trading as Bigroon, Torenlaan 5B, 1402 AT Bussum, the Netherlands.
Email: info@bigroon.com
We are established in the Netherlands and sell through Shopify to customers in several European markets and the United Kingdom.
2. Personal data we collect
Depending on how you use the Site, we may collect the following categories of personal data:
- Device and usage data: IP address, browser type, device information, operating system, time zone, cookie or similar identifiers, pages and products viewed, referring website or search term, and information about how you interact with the Site.
- Order and customer data: name, billing and delivery address, email address, telephone number, products ordered, order history, transaction information, payment method/type and payment status.
- Communications: information you provide when you contact customer service, send us an email, submit a form or otherwise communicate with us.
- Marketing preferences: your newsletter subscription, consent choices and preferences relating to cookies, analytics and marketing.
- Account or form data: any other information you choose to provide through an account, checkout or form.
Payments are processed by Shopify and/or the relevant payment provider. Bigroon does not normally receive or store your full payment-card number or security code. We may receive limited payment and transaction information needed to administer the order, such as the payment method, status and transaction reference.
We do not ask you to provide medical records or a diagnosis. Because some Bigroon products relate to mobility, a product choice or a message you voluntarily send us may sometimes reveal or suggest health-related information. We only use such information where necessary to respond to you or provide the requested service and, where required by law, on the basis of your explicit consent or another valid legal condition.
3. How we collect personal data
We collect data directly from you when you place an order, contact us, subscribe to marketing or complete a form. We also collect certain data automatically through cookies, pixels, server logs and similar technologies. We may receive limited data from service providers involved in payments, delivery, fraud prevention, analytics and customer service.
4. Why we use personal data and our legal bases
- Performance of a contract: to process and fulfil orders, take payment, arrange delivery, handle returns and refunds, provide order updates and customer service.
- Legal obligations: to meet tax, accounting, consumer-protection and other legal requirements, and to respond to lawful requests from authorities.
- Legitimate interests: to secure the Site, prevent fraud and abuse, maintain records, improve our services, understand general Site performance and establish, exercise or defend legal claims, provided these interests are not overridden by your rights.
- Consent: for non-essential cookies and similar technologies, certain analytics or advertising activities, and electronic marketing where consent is required. You can withdraw consent at any time.
5. Cookies and similar technologies
We use necessary cookies to operate the Site, remember your cart, support checkout, secure the Site and provide functions you request. We may also use analytics and marketing technologies where permitted. Where the law requires consent, non-essential technologies are not activated until you have made a choice.
You can change or withdraw your cookie preferences through the cookie settings available on the Site. Browser settings may also allow you to block or delete cookies, although doing so can affect Site functionality.
Server and log files may record actions on the Site together with data such as IP address, browser type, internet service provider, referring/exit pages and date/time stamps.
6. Who we share personal data with
We share personal data only where necessary for the purposes described in this policy. Recipients may include:
- Shopify, which provides our ecommerce platform. More information: Shopify Privacy Policy.
- payment providers and fraud-prevention providers;
- carriers, logistics and fulfilment partners;
- email, hosting, IT, customer-support and professional service providers;
- analytics and marketing providers where these services are enabled and lawfully used;
- public authorities, regulators, courts, advisers or other parties where disclosure is required by law or necessary to protect legal rights.
Where enabled and permitted, we may use services such as Google Analytics to understand how visitors use the Site. Where consent is required, these services are used only after consent. Google’s privacy information is available at policies.google.com/privacy. Google also provides an analytics opt-out tool at tools.google.com/dlpage/gaoptout.
7. International transfers
Some service providers may process personal data outside the country where you live, including outside the European Economic Area (EEA) or the United Kingdom. Where a restricted international transfer takes place, we use a lawful transfer mechanism where required, such as an adequacy decision, the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement/Addendum, or another legally permitted safeguard.
8. How long we keep personal data
We do not keep personal data longer than necessary for the purpose for which it was collected, unless a longer period is required by law.
- Order, invoice and core accounting records are generally retained for at least 7 years where required by Dutch tax and accounting rules.
- Records relating to certain EU VAT One Stop Shop or Import One Stop Shop schemes may need to be retained for 10 years where applicable.
- Customer-service correspondence is retained for as long as reasonably necessary to resolve the request and to deal with warranties, disputes or legal claims.
- Marketing data is used until you unsubscribe or withdraw consent, subject to keeping a minimal suppression record where necessary to honour your opt-out.
- Cookie and analytics data is retained according to the relevant cookie setting and provider retention configuration.
9. Your privacy rights
Depending on the law that applies to you, you may have the right to:
- receive information about how we use your data;
- access your personal data;
- correct inaccurate or incomplete data;
- request deletion of data;
- request restriction of processing;
- receive or transfer certain data in a portable format;
- object to processing based on legitimate interests;
- object at any time to direct marketing;
- withdraw consent at any time without affecting processing that was lawful before withdrawal; and
- have safeguards in relation to decisions based solely on automated processing that produce legal or similarly significant effects, where applicable.
To exercise a right, email info@bigroon.com. We may ask for information needed to verify your identity. We normally respond within one month where the GDPR or UK GDPR applies, subject to any lawful extension or exception.
10. Newsletter and direct marketing
If you receive marketing emails from us, you can unsubscribe at any time by using the unsubscribe link in the message or by contacting us. We will stop using your data for direct marketing when required, although we may keep a minimal record of your opt-out to ensure that we respect it.
11. Fraud prevention and automated tools
We and our service providers may use technical signals and automated tools to identify suspicious transactions, fraud, abuse or security risks. We do not intend to make decisions about you that have legal or similarly significant effects based solely on automated processing unless this is permitted by law and the required safeguards are in place.
12. Security
We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful loss, misuse, alteration, unauthorised access or disclosure. No internet transmission or storage system can, however, be guaranteed to be completely secure.
13. Children
The Site is not directed at children and we do not knowingly seek to collect personal data from children for marketing purposes. If you believe a child has provided personal data to us inappropriately, please contact us.
14. United Kingdom
For customers in the United Kingdom, processing is subject to the UK GDPR, the Data Protection Act 2018 and other applicable UK privacy and electronic-communications rules, as amended.
You have the right to raise a concern with the Information Commissioner’s Office (ICO). More information is available at ico.org.uk. You may first contact us at info@bigroon.com so that we can investigate your concern. We handle data-protection complaints in accordance with applicable UK requirements.
UK representative: OosterHard Commerce is established in the Netherlands and has no UK establishment. Where Article 27 UK GDPR requires the appointment of a UK representative for our UK activities, the representative’s contact details must be made available to UK customers and the ICO. We will add those details to this policy where applicable. You can always contact the controller directly using the details above.
15. Changes to this policy
We may update this privacy policy to reflect changes in our practices, services or legal obligations. The latest version will always be published on this page with the date of the most recent update.
16. Contact
For privacy questions, requests or complaints, contact:
OosterHard Commerce, trading as Bigroon
Torenlaan 5B
1402 AT Bussum
The Netherlands
Email: info@bigroon.com