Privacy Policy
Last updated: September 2026
1. Who We Are
Colrs.io is operated by Martin Sinkgraven van Lakwijk, registered in the Netherlands under KvK number 83971467, with registered address at Walingstuin 18, 1902 BC Castricum, The Netherlands ("Colrs.io", "we", "us", "our").
Contact: privacy@colrs.io
This Privacy Policy explains how we process personal data when you visit our Platform, create an account, purchase Products, become a Creator or Affiliate, or otherwise use our services.
The Platform is intended for users aged 18 and over. We do not knowingly collect personal data from children.
1.1 Definitions
In this Privacy Policy:
- "Buyer" means any individual who purchases Products through the Platform.
- "Creator" (also referred to as "Vendor" in the Platform interface) means an independent professional who supplies digital Products through the Platform.
- "Affiliate" means a participant in the Colrs.io Affiliate Program who promotes the Platform in return for commission.
- "Platform" means the Colrs.io website, marketplace, and related services.
- "Product" means any digital tool supplied by a Creator and sold through the Platform.
1.2 Our Role as Data Controller
Colrs.io is the controller for personal data processed through the Platform, including the customer account, the sale, and any platform-mediated messaging. A Creator receives a Buyer's name and email address in only two cases. The first is when the Buyer initiates support contact through the contact form on the Creator's page. The second is where the Creator has selected manual licence delivery for a Product, in which case the Creator receives the Buyer's name and email address for each qualifying sale so that the licence key or access credential can be issued. For that support correspondence and for that delivery correspondence the Creator acts as an independent controller, because the Creator independently determines how that request or delivery is handled, subject to the obligations set out in our Vendor Agreement. Where a Creator notifies Buyers of a Product update, the message is sent through the Platform by Colrs.io and the Creator does not receive the Buyer list. Between Colrs.io and a Creator there is therefore no joint-controller arrangement. There is one processing operation for which Colrs.io does act as a joint controller with a third party, namely the Meta Pixel; this is described in section 2.11. If Colrs.io ever ceases operation of the Platform, a Creator may receive the name and email address of Buyers of their Products so that they can continue to provide access and support; see section 2.13.
2. What Data We Collect and Why
2.1 Account Registration (Buyers)
When you create an account, we collect your name and email address. Your password is stored using industry-standard one-way hashing and is never stored in plain text. This data is necessary to provide access to the Platform and to fulfil purchases.
Legal basis: Contract performance (Article 6(1)(b) GDPR).
2.2 Creator Registration
When you register as a Creator, we additionally collect your business name, business address, portfolio URL, tax information, VAT identification number (if applicable), and payout details. Payout details (IBAN and account holder name, or PayPal address) are used to pay you by SEPA bank transfer or PayPal. This data is required to operate your Creator account and to comply with financial and tax regulations.
Legal basis: Contract performance and legal obligation (Article 6(1)(b) and 6(1)(c) GDPR).
2.3 Purchases and Orders
When you make a purchase, we collect your name, email address, billing address, and order details. Payment card details are not stored by us – they are processed directly by Stripe. We store a transaction reference for record-keeping.
Our payment provider Stripe applies automated fraud detection when processing payments; a payment that is flagged as high-risk may be automatically declined. If you believe a payment was wrongly declined, contact support@colrs.io and we will review it.
Stripe Link. When you pay by card, Stripe offers you the option to save your details with Link, its own faster-checkout service. Link is a separate consumer service of Stripe and not part of the payment processing we instruct Stripe to carry out. Creating a Link account is optional and always requires an action by you; if you leave the Link section untouched, no Link account is created and your payment is processed as an ordinary card payment. Where you do sign up, Stripe is the data controller for the personal data it processes for Link, and that processing is governed by the Link Privacy Policy rather than by this policy. Your email address and phone number are passed to Stripe's payment field to prefill the checkout; this happens for every card payment, whether or not you use Link.
Legal basis: Contract performance and legal obligation.
2.4 Business Verification (restricted countries)
We do not sell to private individuals in every country. In a number of countries, selling to consumers would immediately oblige us to register for local VAT or sales tax, so we have suspended sales to private individuals there. A business buyer in those countries can request verification of its business status in order to purchase. The current list of countries is published on our FAQ page.
Verification is optional. If you do not request it, we simply cannot sell to you; there is no other consequence.
What we collect: your email address, your business registration number, your business name, and, depending on the country, the opening date of the business and the name of its legal representative, or a copy of your business registration certificate (PDF, JPG or PNG).
How we check it. This depends on the country:
- Republic of Korea: we send the registration number, the opening date and the representative's name to Kynode, a verification service operated by Nodemetrics, Republic of Korea, which acts as our processor and submits them to the Korean National Tax Service (NTS) for an authenticity check. Only the result (match or no match) comes back to us.
- Countries with a public business register: we look up the registration number ourselves in the official public register of that country. Nothing is sent to a third party; we record which register we consulted and keep a screenshot as evidence.
- Other countries: you upload a copy of your registration certificate. The file is stored on our server outside the public web directory, is readable only by the site administrator, and is never shared with third parties.
What happens afterwards. If the check succeeds, we record the outcome and place the registration number and country on your customer account and on each order, as evidence for the tax treatment applied. The representative's name, the opening date and any uploaded certificate are not copied to your account or orders.
Legal basis: taking steps at your request prior to entering into a contract, because a successful check is a precondition for the purchase (Article 6(1)(b) GDPR); our legal obligation to establish the tax status of the customer and to keep evidence of it in our records (Article 6(1)(c) GDPR, Article 18 of Implementing Regulation (EU) 282/2011 and Article 52 of the Dutch General Tax Act); and our legitimate interest in not becoming liable for registration and tax in countries where we do not sell to consumers (Article 6(1)(f) GDPR). You may object to processing based on legitimate interest; see section 6.
Retention: see section 5.
2.5 Checkout Consent Records
At checkout, we record your explicit consent to immediate delivery and waiver of the right of withdrawal, including a timestamp. This is stored as part of your order record.
Legal basis: Legal obligation (Article 6:230p BW; Directive 2011/83/EU as amended).
2.6 Self-Billing Records (Creators and Affiliates)
For Creators and Affiliates, we generate self-billing invoices on your behalf for amounts owed to you through the Platform. These invoices contain your name, business address, VAT identification number (if applicable), and transaction details. They are stored as part of our financial records.
Legal basis: Contract performance and legal obligation (Article 6(1)(b) and 6(1)(c) GDPR).
2.7 Communications
When you contact us by email or via the Platform, we store your messages and contact details to respond and to keep a record of communications.
Legal basis: Legitimate interest (Article 6(1)(f) GDPR).
2.8 Newsletter and Email Delivery
We use Brevo to deliver our transactional emails and, where you have subscribed, our newsletter. If you sign up for the newsletter, we process your email address to send you updates. Subscribing is always optional and is never a condition of receiving a Product, including free Products. You can unsubscribe at any time via the link in every email. Brevo primarily processes this data on our behalf within the EU and applies appropriate safeguards where international transfers occur.
Legal basis: Consent for the newsletter (Article 6(1)(a) GDPR); legitimate interest and contract performance for transactional emails.
2.9 Affiliate Program
If you join our Affiliate Program, we process your name, email address, business and tax details, VAT identification number, payout details, and referral and commission records, in order to operate your participation and to issue self-billing invoices for your commissions. The referral cookie that attributes a visitor's purchase to an affiliate is placed only with the visitor's consent; see our Cookie Policy.
Legal basis: Contract performance and legal obligation (Article 6(1)(b) and 6(1)(c) GDPR).
2.10 Analytics and Tracking
With your consent, we use the following analytics and tracking tools:
- Google Analytics 4 (via Google Tag Manager) – to understand how visitors use the Platform. Data is processed by Google LLC. Google Privacy Policy.
- Meta Pixel – to measure the effectiveness of advertising on Meta platforms (Facebook/Instagram) and for retargeting. Data is processed by Meta Platforms Ireland Ltd. Meta Privacy Policy.
- Google Tag Manager – to manage and deploy the above tools. No data is collected by GTM itself.
Analytics and tracking cookies are only placed with your explicit consent via our cookie banner. You can withdraw consent at any time via the cookie settings link in the footer.
Legal basis: Consent (Article 6(1)(a) GDPR).
2.11 Joint Controllership with Meta (Meta Pixel)
If you accept marketing cookies, the Meta Pixel transmits data about your visit to Meta Platforms Ireland Ltd., such as your IP address, browser and device information, and the pages you viewed or actions you took on the Platform. For this specific processing, Colrs.io and Meta act as joint controllers within the meaning of Article 26 GDPR, on the basis of the Meta Controller Addendum that forms part of the Meta Business Tools terms.
The essence of that arrangement is as follows:
- Colrs.io is responsible for obtaining your consent before the pixel is loaded, and for informing you about this processing through this Privacy Policy and our Cookie Policy.
- Meta is responsible for the processing that takes place after the data has been transmitted, including the security of that processing, and for enabling you to exercise your rights in respect of the data Meta holds.
You may exercise your rights under the GDPR against either party. For requests about data held by Meta, you can contact Meta directly through the tools and contact details in the Meta Privacy Policy; we will pass on requests we receive where it is appropriate for us to do so. You can withdraw your consent at any time via the Cookie Settings link in the footer, after which no further data is sent to Meta.
Legal basis: Consent (Article 6(1)(a) GDPR).
2.12 Technical Data
We automatically collect IP addresses, browser type, and basic usage data when you visit the Platform. This is used for security, error monitoring, and the prevention of abuse. This data is processed on our hosting infrastructure at SiteGround. Where you complete a Cloudflare Turnstile check on a form, login, or at checkout, Cloudflare additionally processes your IP address and technical connection data for that check; see section 3.
Legal basis: Legitimate interest.
2.13 Transfer to a Creator if the Platform Closes
We share your name and email address with the Creator of a product you bought in three situations only: when you contact that Creator about your order, when the Creator delivers a licence key to you by hand, and, if Colrs.io ever stops operating the Platform, so that the Creator can keep giving you the access and support you were promised. In that last case we rely on our and your legitimate interest in honouring that promise (Article 6(1)(f) GDPR), we will tell you before it happens, and the Creator then becomes independently responsible for your data under their own privacy notice. The Creator is contractually bound to use it only for that purpose and to delete it once the availability period for your order has ended.
2.14 Cookies
See our Cookie Policy for details on how we use cookies.
3. Who We Share Your Data With
We share data only where necessary:
- Stripe – payment processing for purchases, as our processor. Stripe Privacy Policy. Separately, where you choose to sign up for Stripe Link, Stripe acts as an independent controller for that service; see section 2.3 and the Link Privacy Policy.
- Bunq – our business bank, used to make SEPA payouts to Creators and Affiliates. Data is processed in the EU.
- PayPal – used to make payouts to Creators and Affiliates who choose PayPal. PayPal acts as an independent controller for its own services.
- Brevo – email delivery and newsletter. Data is primarily processed in the EU, with appropriate safeguards for any international transfers.
- Cloudflare – bot and spam protection through Cloudflare Turnstile on our forms, login pages, and checkout. Processes IP addresses and technical connection data for the purpose of that check. Data may be processed outside the EU under the EU-US Data Privacy Framework, with Standard Contractual Clauses as a fallback.
- Creators – when you contact a Creator about your order, and where a Creator delivers a licence key manually, we share your name and email address with that Creator so they can provide Product support or issue your credential. Creators are contractually bound to use this data only for that support or delivery and may not add Buyers to marketing lists, share data with third parties, or use the data for any other purpose. Product update notifications are sent through the Platform; the Creator does not receive the Buyer list. If Colrs.io ceases operation of the Platform, see section 2.13.
- Kynode (Nodemetrics), Republic of Korea – verification service, acting as our processor; forwards your registration data to the Korean National Tax Service where you request business verification for Korea.
- Google Ireland Ltd. (and Google LLC) – analytics and tag management, with your consent. Data may be processed in the US under the EU-US Data Privacy Framework, with Standard Contractual Clauses as a fallback.
- Meta Platforms Ireland Ltd. – advertising measurement and retargeting, with your consent. Meta acts as a joint controller for this processing rather than as a processor; see section 2.11. Meta Data Transfer Information.
- SiteGround – hosting provider and content delivery. We currently host the Platform on EU-based servers.
- Backblaze, Inc. – encrypted off-site backup of our invoices, order records and uploaded files, stored in a data centre in the EU (Amsterdam), as our processor.
- WordPress/WooCommerce – the software that powers our Platform, running on our own hosting. Certain optional services may involve processing by Automattic. Automattic Privacy Policy.
- Legal authorities – if required by law, court order, or to protect our legal rights.
We do not sell your personal data to third parties.
4. International Transfers
The Platform operates globally. Personal data may be transferred outside the EU/EEA in the following situations:
- Service providers (including Google, Meta, Stripe, and Cloudflare) processing data in the United States. Each of these is certified under the EU-US Data Privacy Framework, so the transfer rests on the European Commission's adequacy decision of 10 July 2023; Standard Contractual Clauses approved by the European Commission apply as a fallback where a certification lapses or does not cover a transfer.
- PayPal, where you receive payouts via PayPal, under its own terms and transfer mechanisms.
- Non-EU Creators receiving limited Buyer data for Product support or manual licence delivery, under the data protection obligations set out in our Vendor Agreement.
- Business verification for the Republic of Korea, where the registration number, opening date and representative's name are transferred to Kynode (Nodemetrics) in the Republic of Korea, our processor, which checks them against the records of the Korean National Tax Service. This happens only at your request. The European Commission has recognised the Republic of Korea as providing an adequate level of protection (Commission Implementing Decision (EU) 2022/254 of 17 December 2021), so no additional transfer safeguards are required. Verification for other countries does not involve any transfer outside the EU.
- Non-EU Buyers whose data is processed in the EU on Colrs.io infrastructure.
Where required, we rely on Standard Contractual Clauses, adequacy decisions, or other approved transfer mechanisms, as applicable, to ensure an adequate level of protection.
5. How Long We Retain Your Data
| Data | Retention period |
|---|---|
| Account data (no purchases) | Until account deletion, plus 1 year |
| Account data (with purchases) | Financial and transaction records: 7 years (Dutch tax law obligation); other account information only as long as necessary |
| Order and transaction records | 7 years (Dutch tax law obligation) |
| Self-billing invoices (Creators and Affiliates) | 7 years (Dutch tax law obligation) |
| Consent records (withdrawal) | 7 years (legal compliance) |
| Business verification data used for the check (opening date, representative's name, uploaded registration certificate) | Deleted 180 days after the decision on your request |
| Outcome of the check and the record that it took place (date, country, register consulted, evidence screenshot) | 7 years, as part of our tax records |
| Registration number and country on an order | 7 years, as part of the order and tax records (Dutch tax law obligation) |
| Registration number and country on your account | Until you delete your account or ask us to remove it; it remains on past orders for 7 years |
| Email address left to be notified about a restricted country | Until you ask us to remove it, or until we open or permanently close that country |
| Newsletter subscription | Until you unsubscribe |
| Support communications | 2 years after last contact, unless longer retention is required to resolve a dispute |
| Analytics data | 14 months (GA4 default) |
| Technical logs | 90 days |
6. Your Rights
Under GDPR, you have the right to:
- Access – request a copy of the personal data we hold about you.
- Rectification – request correction of inaccurate data.
- Erasure – request deletion of your data, where we are not legally obliged to retain it.
- Restriction – request that we restrict processing of your data.
- Portability – receive your data in a structured, machine-readable format.
- Object – object to processing based on legitimate interest.
- Withdraw consent – where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at privacy@colrs.io. We will respond without undue delay and at the latest within one month.
You also have the right to lodge a complaint with the Dutch data protection authority: Autoriteit Persoonsgegevens – autoriteitpersoonsgegevens.nl
7. Security
We implement appropriate technical and organisational measures to protect your personal data, including encrypted connections (HTTPS), one-way password hashing, restricted access controls, and regular software updates.
8. Changes to This Policy
We may update this policy from time to time. We will notify registered users of material changes by email. The date at the top of this page indicates when the policy was last updated.