Free carbon-neutral shipping over $75 · 60-night trial · Lifetime repairs

MILES Gear that goes the distance.

Privacy Policy

What we collect, why, and how to get it back.

Last updated 21 August 2026

Draft for review. This policy was prepared as part of the Miles site build and has not been reviewed by counsel. Confirm the entity details, retention periods and jurisdiction clauses with your lawyer before launch.

Miles Supply B.V. (“Miles”, “we”, “us”) runs the store at milesonlineshop.co. This policy explains what personal data we collect, why we collect it, how long we keep it and what you can do about it. It applies to the website, our email programme and our customer support channels.

1. Who is responsible

The data controller is Miles Supply B.V., Wilhelminakade 173, 3072 AP Rotterdam, Netherlands, registered with the Dutch Chamber of Commerce under KvK 84 129 337. Our privacy contact is [email protected].

2. What we collect

  • Order data. Name, shipping and billing address, email, phone number, order contents and order history.
  • Payment data. Handled by our payment processor. We receive the last four digits of the card, the card brand and the authorisation result — never the full card number.
  • Account data. Email address and a hashed password, if you create an account.
  • Support data. Messages you send us, plus any photos you attach to a warranty or repair claim.
  • Marketing data. Your email address and subscription status if you opt in to the newsletter, plus whether our emails were opened or clicked.
  • Technical data. IP address, browser and device type, referring page, and pages viewed. See our Cookie Policy for the detail.

3. Why we use it, and on what legal basis

Purpose Data used Legal basis (GDPR Art. 6)
Fulfilling and shipping your order Order, payment, account Performance of a contract
Returns, warranty and repairs Order, support Performance of a contract
Fraud and chargeback prevention Order, payment, technical Legitimate interest
Tax, customs and accounting records Order, payment Legal obligation
Newsletter and product announcements Marketing Consent
Measuring how the site is used Technical Consent (analytics cookies)

4. Who we share it with

We do not sell personal data. We share it only with processors who need it to run the store, under contract and only for the purpose we specify:

  • Payment processing and fraud screening.
  • Carriers and customs brokers, to deliver your order and clear it into your country.
  • Our email platform, for order confirmations and — if you opted in — the newsletter.
  • Our hosting and analytics providers.
  • Authorities, where we are legally required to disclose.

Where a processor is outside the EEA we rely on the European Commission’s Standard Contractual Clauses, or an adequacy decision where one exists.

5. How long we keep it

  • Order and invoice records: seven years, as required by Dutch tax law.
  • Account data: until you delete the account, then 30 days in backups.
  • Support conversations: three years from the last message.
  • Newsletter data: until you unsubscribe, plus a suppression record so we do not email you again.
  • Analytics data: 14 months.

6. Your rights

Wherever you live, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or send it to another provider in a portable format. If you are in the EEA or UK you can also lodge a complaint with your supervisory authority — in the Netherlands that is the Autoriteit Persoonsgegevens.

If you are a California resident, you have the right to know, delete, correct and opt out of “sharing” for cross-context behavioural advertising. We do not sell personal information as the CCPA defines it. We honour Global Privacy Control signals.

To exercise any right, email [email protected]. We respond within 30 days and will not charge you or degrade your service for asking.

7. Security

Traffic to and from the site is encrypted with TLS. Passwords are hashed. Access to customer records is limited to staff who need it, protected by multi-factor authentication and logged. If a breach affects your data and poses a risk to you, we notify you and the relevant authority within 72 hours of becoming aware.

8. Children

The store is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.

9. Changes

If we make a material change we will post the new version here and email subscribers at least 14 days before it takes effect. The date at the top of this page always reflects the current version.