← Back to home

Privacy Policy

Last updated: 5 August 2026

This Privacy Policy explains how Floroo ("we", "us", "our") collects and processes your personal data when you visit floroo.be or order bouquets through our service. It is provided in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and Belgian data protection law.

1. Data controller

The data controller for the processing described in this policy is Floroo, based in Ghent, Belgium. For any privacy-related question or to exercise your rights, contact: florooflowers@gmail.com.

2. Personal data we process

  • Account data: name, email address, password hash.
  • Order data: bouquet content, delivery address, recipient name and message, requested delivery date.
  • Payment data: transaction identifiers and confirmation status. Card details are processed directly by our payment provider; we do not store them.
  • Communication data: messages you send us and our replies.
  • Technical data: IP address, device and browser information, and minimal usage data needed to operate and secure the site.

3. Purposes and legal bases

  • Performance of a contract (Art. 6(1)(b) GDPR): creating your account, processing orders, arranging delivery, handling refunds.
  • Legal obligation (Art. 6(1)(c) GDPR): accounting, tax and consumer protection obligations.
  • Legitimate interests (Art. 6(1)(f) GDPR): securing the site, preventing fraud, improving our service. We balance these interests against your rights and freedoms.
  • Consent (Art. 6(1)(a) GDPR): non-essential cookies and any marketing emails. You can withdraw your consent at any time.

4. Recipients of your data

We share personal data only with parties that need it to deliver the service:

  • The local florist fulfilling your order.
  • Our payment provider (Stripe) to process payments.
  • Our hosting and platform providers (including Cloudflare and Supabase) acting as processors under a data processing agreement.
  • Google Maps Platform for delivery address autocomplete.
  • Public authorities where we are required to do so by law. We do not sell your personal data.

5. International transfers

Some of our processors are established outside the European Economic Area (notably in the United States). Where this is the case, transfers are protected by appropriate safeguards under Chapter V GDPR, such as the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

6. Retention

We keep personal data only as long as necessary for the purposes set out above. Order and invoicing records are kept for 7 years to meet Belgian accounting obligations. Account data is kept until you delete your account. Technical logs are kept for a short period needed for security and debugging.

7. Your rights

Under the GDPR you have the right to:

  • access your personal data and obtain a copy;
  • have inaccurate data corrected;
  • have your data deleted, where the conditions of Art. 17 GDPR apply;
  • restrict or object to certain processing;
  • data portability for data you provided to us;
  • withdraw any consent at any time, without affecting prior processing;
  • lodge a complaint with the Belgian Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit), Rue de la Presse 35, 1000 Brussels — dataprotectionauthority.be.

To exercise any of these rights, email florooflowers@gmail.com. We respond within one month.

8. Security

We apply appropriate technical and organisational measures to protect your data, including encryption in transit (HTTPS), access controls, and processor agreements with our service providers.

9. Automated decision-making

We do not take decisions about you based solely on automated processing that produce legal or similarly significant effects.

10. Changes to this policy

We may update this policy from time to time. The "Last updated" date above always reflects the current version. Material changes will be communicated through the site.