Privacy policy
Last updated: August 26, 2026
1. Who we are (data controller)
This privacy policy describes how Jacob Jensen A/S, trading as Jacob Jensen ("we", "us", "our"), collects, uses and discloses your personal data when you visit our online store and website (the "Store"), make a purchase, or otherwise communicate with us (together, the "Services").
We are the data controller for the processing described in this policy, unless stated otherwise. Our details:
• Company: Jacob Jensen A/S, trading as Jacob Jensen
• Business registration number (CVR): 42523747
• Address: Hejlskovvej 104, 7840 Højslev
• Email: info@jacobjensen.com
The Store is powered by Shopify. For certain processing, Shopify acts as our data processor, and for certain enhanced features Shopify acts as an independent controller; see Section 8.
2. Personal data we collect
Depending on how you interact with the Services, we collect the following categories of personal data:
• Contact details: your name, addresses, phone number and email address;
• Payment information: payment method, transaction details and payment confirmation. Card numbers are processed by our payment service providers; we do not store full card numbers.
• Account information: username, password, preferences and settings, if you create an account;
• Order and transaction information: products you view, add to cart or wishlist, purchase, return, exchange or cancel, and your order history;
• Communications: the content of your messages to us, for example customer support enquiries and reviews you submit;
• Device and usage information: IP address, device and browser information, unique identifiers, and information about how and when you use the Services, collected via cookies and similar technologies (see Section 5).
We collect personal data directly from you, automatically through your use of the Services (including via cookies), and from our service providers, such as payment and delivery providers, when they process data on our behalf or confirm transactions.
3. Purposes and legal bases
Under the EU General Data Protection Regulation (GDPR), we must have a legal basis for each purpose for which we process your personal data. We process your personal data for the following purposes:
• To provide the Services and fulfil your orders: processing your orders and payments, arranging delivery, handling returns, exchanges, withdrawals and guarantee claims, and managing your account. Legal basis: performance of a contract with you (GDPR Art. 6(1)(b)).
• To communicate with you: responding to your enquiries and providing customer support. Legal basis: performance of a contract, or our legitimate interest in serving customers and prospective customers (Art. 6(1)(b) and (f)).
• To comply with law: keeping accounting records and complying with tax, bookkeeping, consumer and other legal obligations. Legal basis: compliance with a legal obligation (Art. 6(1)(c)).
• Direct marketing by email: sending newsletters and other electronic marketing only if you have signed up for it. Legal basis: your consent (Art. 6(1)(a)), which you can withdraw at any time, for example via the unsubscribe link in every email. Where permitted by the Danish Marketing Practices Act, we may send you marketing for our own similar products after a purchase, with a clear option to opt out at the time your email address is collected and in every message.
• Marketing, personalisation and analytics: showing you personalised content, recommendations and advertising, and measuring how the Services are used, via cookies and similar technologies. Legal basis: your consent (Art. 6(1)(a)), collected through our cookie banner, which you can change or withdraw at any time (see Section 5).
• Security and fraud prevention: authenticating accounts, securing payments, and detecting and preventing fraud, abuse and security incidents. Legal basis: our legitimate interest in protecting the Services, our customers and our business (Art. 6(1)(f)), and in some cases compliance with a legal obligation.
• Legal claims: establishing, exercising or defending legal claims, and enforcing our terms and policies. Legal basis: our legitimate interest (Art. 6(1)(f)).
4. Where processing is based on legitimate interest
Where we rely on legitimate interest, we have assessed that our interest is not overridden by your interests or fundamental rights and freedoms. You have the right to object to processing based on legitimate interest at any time (see Section 10).
5. Cookies and similar technologies
We use cookies and similar technologies on the Store. Strictly necessary cookies are used to make the Store function, for example to keep your basket and process checkout, and are set without consent based on our legitimate interest in operating the Store. All other cookies, including functional, analytics and marketing cookies, are only set if you consent through our cookie banner.
You can change or withdraw your cookie consent at any time via cookie settings in the footer of the Store.
6. Who we share personal data with
We disclose personal data to the following categories of recipients, only to the extent necessary for the purposes described above:
• Shopify, which hosts the Store and processes data on our behalf (see also Section 8);
• service providers acting on our behalf, such as payment service providers, shipping and fulfilment providers, IT and hosting providers, customer support tools, and analytics providers, all bound by data processing agreements;
• marketing and advertising partners, only where you have consented to marketing cookies or signed up for marketing;
• public authorities, courts and professional advisers, where required by law or necessary to establish, exercise or defend legal claims;
• a buyer or successor in the event of a merger, acquisition or other business transfer, in which case this policy continues to apply to your data.
We do not sell your personal data.
7. International transfers
Some of our service providers, including Shopify, process personal data outside the EU/EEA. Where personal data is transferred out of the EU/EEA, we ensure an adequate level of protection, either because the European Commission has issued an adequacy decision for the recipient country, or by using the European Commission's Standard Contractual Clauses together with supplementary measures where needed. You can request a copy of the relevant safeguards by contacting us.
8. Relationship with Shopify
The Services are hosted by Shopify. Shopify collects and processes personal data about your access to and use of the Services in order to provide and improve them. In addition, we use certain Shopify enhanced features that incorporate data obtained from your interactions with our Store, with other merchants and with Shopify. For those enhanced features, Shopify is an independent controller responsible for the processing, including for responding to requests to exercise your rights regarding that processing. You can read more in the Shopify Consumer Privacy Policy at https://privacy.shopify.com and exercise rights regarding Shopify's processing via the Shopify Privacy Portal.
9. Retention
We keep personal data only as long as necessary for the purposes described in this policy. As a general rule:
• order and transaction data, including related communications, is kept for 5 years plus the current year after the end of the financial year, to comply with the Danish Bookkeeping Act;
• account data is kept for as long as your account is active and deleted 12 months after your last activity, unless we must keep it longer by law;
• marketing consents and related data are kept for as long as your consent is active and for 2 years after withdrawal, as documentation of the consent;
• customer support enquiries not linked to an order are kept for 12 months after the case is closed.
10. Your rights
Under the GDPR you have the following rights regarding your personal data. The rights may be subject to conditions and exceptions under applicable law, but where they apply, exercising them is free of charge:
• the right of access: to obtain confirmation of whether we process your data and a copy of it;
• the right to rectification: to have inaccurate data corrected and incomplete data completed;
• the right to erasure: to have your data deleted in certain circumstances;
• the right to restriction of processing in certain circumstances;
• the right to data portability: to receive data you have provided to us in a structured, commonly used, machine-readable format and to have it transmitted to another controller where technically feasible;
• the right to object to processing based on legitimate interest, and an unconditional right to object to processing for direct marketing;
• the right to withdraw consent at any time, without affecting the lawfulness of processing before the withdrawal.
You are not subject to decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you. We do not make such decisions.
To exercise your rights, contact us at info@jacobjensen.com. We may need to verify your identity before responding, and we will respond within the deadlines set by the GDPR, normally one month.
11. Complaints
If you are dissatisfied with how we process your personal data, please contact us first and we will do our best to resolve the matter. You also have the right to lodge a complaint with a supervisory authority. In Denmark, the supervisory authority is Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, www.datatilsynet.dk. If you live in another EU/EEA country, you can complain to the data protection authority in your country of residence.
12. Children
The Services are not directed at children, and we do not knowingly collect personal data about children under 18. If you are a parent or guardian and believe a child has provided us with personal data, please contact us and we will delete it.
13. Security
We use appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure and unauthorised access, taking into account the nature of the data and the risks involved. No transmission or storage system can be guaranteed to be completely secure, so please avoid sending sensitive information through unsecured channels.
14. Changes to this policy
We may update this privacy policy from time to time, for example to reflect changes in our practices or in the law. We will post the updated policy on this page and update the "Last updated" date. If changes are material, we will provide more prominent notice, for example in the Store or by email where required by law.
15. Contact
Questions about this policy or our processing of personal data can be sent to:
Jacob Jensen A/S, trading as Jacob Jensen
Hejlskovvej 104, 7840 Højslev, Denmark.
Email: info@jacobjensen.com