Last updated: 9 August 2026
Thomas Super Store, operated by Westerman ("we", "us", "our"), protects customer data according to the GDPR / AVG principles of data minimisation, purpose limitation, storage limitation and appropriate security. This policy explains what we collect, why we need it, how long we keep it, and which suppliers help us run the webshop.
We do not store full card or bank details. Payments are handled by Mollie. Customer and order data that must be stored for checkout, fulfilment, invoicing and service is protected with HTTPS, restricted access and field-level encryption for sensitive data stored directly in our Netlify backend.
1. Data Controller
The data controller responsible for your personal data is:
Westerman (WETO Media)
Jadestraat 49
9743 HB Groningen
The Netherlands
KvK: 96618043
BTW-identificatienummer: NL005221270B02
Email: info@thomassuperstore.com
Website: thomassuperstore.com
If you have any questions about this Privacy Policy or how we handle your data, you can contact us at the email address above.
2. What Personal Data We Collect
We collect the following categories of personal data:
2.1 Information You Provide
- Checkout and order data: Name, email address, phone number, shipping address, country and, for US delivery, state; chosen shipping method, cart contents, discounts, order status and tracking information.
- Amazon marketplace orders: When you buy from Thomas Super Store through Amazon, we retrieve the order lines, recipient and delivery details, order status and fulfilment information from Amazon Selling Partner API so the order can use our normal protected fulfilment and label workflow.
- Cross-border shipment data: Order and product references, customs classification, country of origin, weights, values, product-certificate references and importer/broker references required to lawfully export, import and deliver the parcel.
- Payment information: Selected payment method and payment status. Full payment details are processed directly by Mollie and are not stored by us.
- Customer profile: The signed-in account view may keep a temporary copy in the current browser tab so the page works smoothly. Names, addresses and order history from the account are not persistently stored in browser Web Storage. Optional personalisation preferences can remain on the device so you do not have to choose them again.
- Sodor Points account: Account identifier, email address, points transactions, mission completion, reward claims, referral code and the connection between a referrer and a referred account. Purchase and return references are stored with the points entry so the balance can be calculated and corrected.
- Communication: Messages you send via email/contact forms and service notes needed to answer your request.
- Notifications: Email address and a product or destination-country reference for back-in-stock alerts, country-launch alerts or abandoned cart reminders.
- The Sodor Times: Email address, optional first name, explicit consent time and a choice of Dutch or English. The paper is only offered in those two languages. If you use the same email address for a Sodor Points account, the one-time newsletter bonus can be linked to that account.
- Review requests: After a fully delivered order, we may send one optional and neutral review request through Google or Trustpilot. Our standard Trustpilot method is an email sent by Thomas Super Store through Resend with a link to our public Trustpilot profile; no customer name, email address or order number is included in that link or sent to Trustpilot by us. If Trustpilot's optional Automatic Feedback Service is used, the minimum necessary invitation data (customer name, email address and order reference) is sent to Trustpilot so it can deliver the invitation. We record the provider, invitation method, sent time and, for direct review links, whether the button was clicked. A click does not prove that a review was written.
2.2 Information Collected Automatically
- Technical data: Basic server logs such as IP address, request time, browser type and error information, mainly for security and troubleshooting.
- Functional browser storage: Cart contents, language, wishlist, recently viewed products and optional personalisation preferences. Account details and order history are held only for the active tab session.
- Cookies: See Section 8 below.
- Referral and partner code data: When you use a partner or discount link, we store the code needed to apply the discount and attribute the order.
3. Why We Collect Your Data
We process your personal data for the following purposes:
- Order processing: To process, fulfil, ship and support your order.
- Customer service: To answer questions, handle returns and solve delivery issues.
- Transactional communication: To send order confirmations, payment reminders, invoices, back-in-stock alerts, requested country-launch alerts and shipping updates.
- Service feedback: To invite customers to leave an optional review after delivery and to improve our service.
- Marketing: To send The Sodor Times or other promotional content only when you have opted in. You can withdraw consent at any time without losing Sodor Points already validly earned.
- Loyalty programme: To operate Sodor Points, credit purchases and optional missions, process reward claims, attribute friend referrals, reverse points after returns and prevent programme abuse.
- Website improvement: To improve stock display, checkout, search and product availability.
- Legal obligations: To comply with tax, accounting, consumer, customs, import and product-safety obligations.
- Fraud and abuse prevention: To detect suspicious orders and protect the webshop.
4. Legal Basis for Processing
We process your personal data based on the following legal grounds under the GDPR:
- Contract performance (Art. 6(1)(b) GDPR): Processing necessary to fulfil our contract with you, including order processing, shipping, and returns.
- Legitimate interest (Art. 6(1)(f) GDPR): Processing necessary for our legitimate business interests, such as programme administration, referral attribution, fraud prevention, website analytics, and improving our services, provided these interests do not override your rights.
- Consent (Art. 6(1)(a) GDPR): Processing based on your explicit consent, such as marketing emails and non-essential cookies. You can withdraw consent at any time.
- Legal obligation (Art. 6(1)(c) GDPR): Processing required to comply with legal obligations, such as tax and accounting regulations.
5. Third Parties & Data Sharing
We share your data with the following trusted third parties, only to the extent necessary for providing our services:
- Netlify (hosting, serverless functions and encrypted webshop storage) — hosts the website and backend functions.
- Amazon Services (marketplace order source) — provides self-authorized Thomas Super Store Amazon order and recipient information through Selling Partner API and receives shipment confirmation and tracking after dispatch.
- Mollie B.V. (payments) — processes payments securely. Mollie does not share full payment details with us. Mollie Privacy Policy
- Moneybird (accounting and invoices) — stores invoice and administration records needed for Dutch accounting rules.
- PostNL, DHL, Monta or another contracted fulfilment/carrier partner (shipping) — receives the delivery and customs details needed to pack, export, import and deliver your order.
- Customs brokers, importers and competent authorities — for a cross-border order, the minimum required shipment, address, customs and certificate data may be shared with the appointed importer/broker and authorities such as HMRC/UK Border Force or US CBP/CPSC where legally required.
- Resend (email delivery) — sends order, payment reminder, stock-notification and expressly requested Sodor Times emails.
- Google Business Profile and Google Maps Platform (reviews) — lets us manage reviews for our own business profile and, when enabled, show selected Google Maps reviews with the required author and Google attribution. Google does not provide us with a reviewer's email address or order number. Use of Google services is subject to the Google Privacy Policy and Google Terms of Service.
- Trustpilot A/S (public review profile, optional invitation service and official website widget) — acts as an independent controller when a person follows our direct link, uses Trustpilot or publishes a review. The direct Resend invitation contains only a public Trustpilot profile link and does not transmit customer data to Trustpilot. If Automatic Feedback Service is enabled, Trustpilot also acts as our processor for the customer name, email address and order reference in the dedicated trigger. When the official Trustpilot widget is enabled, Trustpilot may process technical data about widget impressions, views and clicks. See the Trustpilot privacy terms and Trustpilot Data Processing Agreement.
- Cloudflare Worker / stock sync where configured — helps keep product availability up to date.
We do not sell, rent, or trade your personal data to any third party. We only share data when it is necessary for the services described above or when required by law.
6. Data Retention
We retain your personal data only for as long as necessary for the purposes described in this policy:
- Order, invoice and cross-border export evidence: Kept for 7 years where required for Dutch tax/accounting administration. For shipments outside the EU this record may include the commercial invoice, CN23/CP71 or equivalent customs documents, carrier reference, tracking events and delivery/export confirmation needed to substantiate the VAT and customs treatment.
- Other fulfilment and tracking data: Kept as long as needed for delivery, returns, warranty and customer service, then minimised where possible. Data that forms part of the cross-border tax/export record follows the separate 7-year period above.
- Amazon recipient data: Buyer and recipient PII retrieved through Amazon Selling Partner API is automatically removed from our operational order store 30 days after the latest recorded shipment. The non-personal commercial record, such as order reference, products, quantities, totals and shipment evidence, may remain where needed for accounting, disputes and legal obligations.
- Abandoned cart reminders: Automatically cleaned up. Active cart reminders are kept for a short period, normally no longer than 30 days; closed or sent reminders are normally removed after 14 days.
- Back-in-stock alerts: Waiting alerts are kept until the product returns or for up to 12 months; notified or cancelled alerts are normally removed after 30 days.
- Country-launch alerts: Waiting alerts are kept until delivery starts in the selected country or for up to 12 months, unless you ask us to remove them earlier.
- Review requests: Provider, invitation method, sent status and direct-link click status are stored with the order record for customer-service accountability. A click is never treated as proof of a review. Any manual Google review-to-order association expires automatically after 12 months, and Google review content held for administration is refreshed or removed within 30 days. Direct Trustpilot profile links do not disclose customer data to Trustpilot. If AFS is used, Trustpilot states in its Data Processing Agreement that invitation data submitted through its services may be retained for up to 2 years; data sent through a BCC invitation method may be retained for 30 days. We use a dedicated trigger rather than forwarding a full order confirmation.
- Sodor Points: Points entries are kept while the account is active and normally for no longer than 24 months after the loyalty relationship ends, unless a shorter deletion request applies or a longer period is necessary for an unresolved claim, fraud investigation or legal obligation. Individual unspent points expire after 18 months.
- Customer account: The account profile is kept while the account is active. After a verified deletion request, the login profile and non-required loyalty data are removed or anonymised unless specific data must remain for an order, return, fraud investigation or legal retention duty. Order and invoice records can therefore remain for the separate statutory period stated above.
- Login protection: Pseudonymous failed-login counters are normally removed within 48 hours. They contain hashes derived from the account and connection, not the submitted password.
- Browser storage: Cart, wishlist and optional personalisation preferences remain on your own device until you clear them or use the available remove options. The temporary signed-in account copy expires when the tab session ends and is removed on logout.
- Communication records: Kept as long as needed to handle the request and protect legal/customer-service interests.
7. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access: You can request a copy of all personal data we hold about you.
- Right to rectification: You can request that we correct any inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): You can request that we delete your personal data, unless we have a legal obligation to retain it.
- Right to restriction: You can request that we restrict the processing of your data in certain circumstances.
- Right to data portability: You can request your data in a structured, commonly used, machine-readable format and have it transferred to another controller.
- Right to object: You can object to the processing of your data based on legitimate interest, including direct marketing.
- Right to withdraw consent: Where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us at info@thomassuperstore.com. We will respond to your request within 30 days, as required by the GDPR.
You also have the right to file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.
8. Cookie Policy
Our website uses cookies to ensure proper functionality and to improve your experience. Cookies are small text files stored on your device.
8.1 Types of Cookies We Use
- Essential cookies: Required for the website to function correctly (e.g., shopping cart, login session). These cannot be disabled. Duration: session or up to 1 year.
- Functional cookies: Remember your preferences such as language and currency settings. Duration: up to 1 year.
- Privacy-friendly first-party analytics: Help us understand how visitors interact with our website (e.g., product views, cart additions, device category and broad location such as country/city). We do not store IP addresses, raw user-agent strings, customer names, email addresses or full referrer URLs in analytics. Analytics events are kept for up to 90 days.
- Google Analytics 4: Loads only after you choose “Accept All”. It measures page views, site interactions, approximate location and technical device/browser information so we can improve the store. Google Signals and personalised advertising are disabled. Google uses the IP address briefly to derive coarse location and then discards it before the address is logged. The analytics cookie lifetime is limited to 1 year. If you choose “Necessary Only”, the Google tag is not loaded. See Google's Privacy Policy.
- Google Ads conversion measurement: Loads only after you choose “Accept All”. Advertising storage and advertising measurement data are then enabled solely to connect an ad click to a completed paid order. The conversion contains the order number, total value and currency; we do not send the customer's name, email address or delivery address. Advertising personalisation, remarketing signals and Google Signals remain disabled.
- Trustpilot widget: When the official widget is enabled, it loads only after the section comes into view. Trustpilot states that its TrustBox widgets do not set cookies, but it may process technical interaction data such as impressions, views and clicks under its own privacy terms.
- Marketing cookies: Used to show relevant advertisements on other platforms, only with your explicit consent. Duration: up to 1 year.
For limited analytics, we use aggregated first-party measurements to improve the store and stock planning. If you choose "Necessary Only", we do not store a persistent analytics identifier; the store can still count anonymous product and cart events without building an individual visitor profile.
8.2 Managing Cookies
When you first visit our website, you will be shown a cookie banner where you can choose which types of cookies to accept. You can change your cookie preferences at any time through your browser settings or by contacting us.
Please note that disabling essential cookies may affect the functionality of our website (e.g., you may not be able to add items to your cart).
9. Data Security
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or misuse. These measures include:
- SSL/TLS encryption on all pages of the website.
- Secure payment processing through Mollie; full payment credentials are not stored by us.
- Encryption of sensitive customer/order fields in backend storage where the Thomas Super Store backend stores them directly.
- Passwords are never stored in readable form. Each password is protected with its own random salt and a deliberately slow PBKDF2-SHA-256 hash; older hashes are upgraded after a successful login.
- Customer login sessions use server-side records and an HttpOnly, Secure and SameSite-protected cookie. The browser cannot read the session secret through JavaScript.
- Rate limiting for login, registration, password reset, payment-status and order lookup routes, plus automatic invalidation of active sessions after a password reset.
- No-store cache headers for checkout, account, tracking and backend API responses containing customer data.
- Automatic cleanup of temporary abandoned-cart, stock-alert and expired reservation records.
- Server-validated, time-limited administrator sessions before protected management pages or backend actions can be accessed.
- Data minimisation: we only ask for the fields needed to process the order, notification or support request.
10. International Data Transfers
Your personal data is primarily processed within the European Economic Area (EEA). If we transfer data outside the EEA (e.g., through third-party service providers), we ensure adequate protection through:
- EU adequacy decisions
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Other appropriate safeguards under the GDPR
For an order to Great Britain or the United States, necessary delivery, customs and product-certificate data is also processed in the destination country to perform the contract and comply with import and product-safety law. We limit this to the data required for that shipment and the applicable legal record.
11. Children's Privacy
Our website and services are not directed at children under the age of 16. We do not knowingly collect personal data from children under 16 without parental consent. If you believe we have inadvertently collected data from a child under 16, please contact us and we will promptly delete it.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. The updated version will be posted on this page with a revised "Last updated" date. We encourage you to review this page periodically.
If we make significant changes that affect how we process your data, we will notify you via email or a prominent notice on our website.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Westerman (operating Thomas Super Store)
Email: info@thomassuperstore.com
The Netherlands
We aim to respond to all privacy-related enquiries within 30 days.