Copenhagen Closet ApS · CVR 46358538

Privacy policy

This policy explains how we collect, use, share and delete your personal data when you visit our website, apply for membership or are a member of Copenhagen Closet.

Last updated 16 September 2026

This English version is provided for convenience and is awaiting final legal review. The Danish version remains authoritative. Open the Danish source.

1. Who is the data controller?

Copenhagen Closet ApS is the data controller for the processing described in this policy.

Copenhagen Closet ApS, Danish CVR no. 46358538, Rådmandsgade 40D, st. tv., 2200 København N, Denmark. Email: info@copenhagencloset.dk. Telephone: +45 42 44 55 25.

2. Who does this policy apply to?

This policy applies to visitors to copenhagencloset.dk, membership applicants, members, newsletter recipients, ambassadors and people who contact us. Membership is only offered to people aged 18 or over.

3. What data do we process?

Depending on your relationship with us, we may process:

  • Name, date of birth, email address, telephone number and login details.
  • Address and delivery details.
  • Information from your membership application, including your Instagram and TikTok profiles, how you heard about us, and any referral code.
  • Profile photo, wishlist, membership status, and membership and rental history.
  • Payment and invoice data, transaction status, and customer and subscription identifiers from Stripe. We do not receive your full card details.
  • Status and results from Stripe Identity, including whether photo ID and selfie were approved and whether name and date of birth match the application. Stripe processes the document and selfie images; we do not store those images in our own database.
  • Evidence of your electronic acceptance of the terms and permission for later automatic payment.
  • For older membership journeys, we may continue to retain signed agreements and historical signing information from Nextsign.
  • Delivery, tracking and return information.
  • Information about damage, including descriptions, photos, assessments, correspondence, and any claims or invoices.
  • Customer service enquiries and necessary internal notes and administrative logs.
  • Newsletter consent and information about sends, opens and clicks where you have consented.
  • Technical information such as IP address, device, browser, cookie ID, page views and campaign data where permitted by your cookie choices.
  • Please do not send sensitive personal data unless we have specifically requested it and there is a lawful and necessary purpose.

4. Purposes and lawful bases

  • Application and membership assessment: to create and process your application, check the age requirement and conduct a manual assessment. The lawful bases are steps before entering into a possible contract and our legitimate interest in administering a private members’ club, under Article 6(1)(b) and (f) GDPR.
  • Identity verification: to verify identity and age and prevent misuse in connection with access to valuable bags. The lawful bases are steps before entering into the contract and our legitimate interest in security and loss prevention under Article 6(1)(b) and (f). Differences are reviewed manually and are not decided solely by automated processing.
  • Membership and rentals: to administer your account, payments, subscription, rentals, returns, support and membership benefits. The lawful basis is performance of our contract under Article 6(1)(b).
  • Payments and accounting: to collect payment, issue invoices, and comply with bookkeeping and tax requirements. The lawful bases are our contract and legal obligations under Article 6(1)(b) and (c).
  • Delivery: to send and receive bags and provide delivery information to GLS. The lawful basis is performance of the membership agreement under Article 6(1)(b).
  • Damage and claims: to document and handle damage, determine liability, and establish, exercise or defend legal claims. The lawful bases are our contract and legitimate interests under Article 6(1)(b) and (f).
  • Security and prevention of misuse: to protect members, bags, systems and our business, and to keep necessary administrative and security logs. The lawful basis is our legitimate interest under Article 6(1)(f).
  • Newsletter: to send news and marketing through Klaviyo when you actively subscribe. The lawful basis is your consent under Article 6(1)(a). You can unsubscribe at any time.
  • Statistics and digital marketing: to understand use of the website, measure campaigns and show relevant advertising through Google, Meta and TikTok. The lawful basis is your consent under Article 6(1)(a).
  • Referral programme: to record an ambassador referral, calculate membership credit and measure the programme’s effectiveness. Cookie-based storage and analysis only take place with the relevant consent.

5. Manual membership assessment

Every membership application is assessed manually. We may consider the information in your application and the social media profiles you provide. We do not make membership decisions based solely on automated processing or profiling.

6. Where do we obtain the data?

We mainly receive information directly from you. We may also receive identity and payment status from Stripe, delivery status from GLS, and technical campaign or usage data from services to which you have consented. When assessing membership, we may view the social media profiles you provided. For older journeys, we may continue to receive or retain historical signing status from Nextsign.

7. Recipients and service providers

We only disclose or entrust data where necessary and lawful.

We do not sell your personal data.

  • Vercel for hosting and technical operations.
  • Supabase for the database, login, file storage and backend functions. The project’s primary region is Central Europe.
  • Stripe for Identity, saved payment methods, payments, subscriptions, invoices and payment-related customer service.
  • Nextsign only for retaining historical electronic signatures and membership agreements from the previous flow.
  • One.com for email. One.com states that EU customer data is stored in Denmark.
  • Klaviyo for newsletters and marketing communications.
  • GLS as an independent recipient of name, address, email and telephone number for transport and delivery.
  • Google, Meta and TikTok for statistics and marketing, but only to the extent permitted by your consent.
  • Auditors, advisers, authorities or courts where necessary or legally required.

8. Transfers outside the EU/EEA

Some providers or their subprocessors may process data outside the EU/EEA, including in the United States. When this happens, we ensure that a valid transfer mechanism is in place, such as an adequacy decision or the European Commission’s Standard Contractual Clauses, and assess whether supplementary safeguards are required. Contact us if you would like more information about the basis for a particular transfer.

9. How long do we retain data?

These periods may be extended if the law requires longer retention or if the data is necessary for a specific ongoing matter. The data is then deleted or anonymised.

  • Rejected and incomplete applications are generally deleted after 7 days.
  • Data about active members is retained while the membership is administered.
  • Ordinary profile data and rental history are generally deleted or anonymised 2 years after the most recent activity.
  • Accounting and invoice records are retained for 5 years from the end of the financial year to which they relate.
  • Damage photos and details are generally deleted 12 months after the case is closed.
  • For a specific dispute or legal claim, relevant data may be retained until the matter has been finally resolved.
  • Signed membership agreements are generally deleted 12 months after the membership and all associated obligations have ended.
  • Newsletter data is processed until you unsubscribe. Limited evidence of consent may be retained for up to 2 years after the last marketing communication.
  • Security and administrative logs are generally retained for no more than 12 months unless a specific security incident requires longer retention.
  • Cookie lifetimes are set out in our cookie policy.

10. Your rights

You can exercise your rights by emailing info@copenhagencloset.dk. We may ask for information needed to confirm your identity.

  • Access the data we process about you.
  • Have inaccurate data corrected.
  • Have data erased or processing restricted.
  • Object to processing based on legitimate interests.
  • Receive certain data in a structured format and have it transferred.
  • Withdraw consent without affecting the lawfulness of earlier processing.

11. Complaints

Please contact us first if you are unhappy with our processing. You also have the right to complain to the Danish Data Protection Agency, Carl Jacobsens Vej 35, 2500 Valby, Denmark, via datatilsynet.dk.

12. Changes

We update this policy when our processing, providers or the rules change. The date above shows when it was last updated. We will provide appropriate notice of material changes.