Cookie and privacy policy
Last updated: August 10, 2026
This policy describes what personal data Grade A Copenhagen processes about you, why we do it, the basis for our processing, who has access to the information, and what rights you have.
1. Data Controller
Grade A Copenhagen H.C. Ørsteds Vej 22D 1879 Frederiksberg C CVR-nr.: 44480271. E-mail:
You are always welcome to write to us if you have questions about this policy or wish to exercise one of your rights under section 9.
2. What information we process
We only process the information necessary for the purposes for which we use it:
Information you provide us with
- Name, email address, phone number, delivery and billing address
- Order history, returns, and complaints
- Login details if you create an account (password is stored encrypted and cannot be read by us)
- Messages you send us, e.g., customer service inquiries
- Information you enter for trade-ins and item appraisals
Information we collect automatically
- IP address, browser type, device type, and operating system
- Which pages you visit, what you search for, and what you add to your cart
- Approximate geographical location derived from the IP address
- Cookies and similar technologies, cf. section 6
Information we receive from others
- Payment status from our payment provider. We never receive or store your full card number
- Delivery status from the shipping company
- Email address and name if you sign up for our newsletter via an advertisement on Facebook or Instagram, cf. section 5
3. Purpose and Legal Basis
| Purpose | Information | Legal Basis |
|---|---|---|
| To complete your purchase, deliver the item, and handle returns | Contact, delivery, and order information | Fulfillment of the contract, GDPR Article 6(1)(b) |
| Customer service and complaints | Contact information and correspondence | Contract, Article 6(1)(b), and our legitimate interest in being able to respond to inquiries, Article 6(1)(f) |
| Bookkeeping and accounting | Invoice information | Legal obligation, Article 6(1)(c), cf. the Danish Bookkeeping Act |
| Newsletter and marketing emails | Name and email address | Your consent, Article 6(1)(a), cf. Section 10 of the Danish Marketing Practices Act |
| Statistics and site improvement | Usage data via cookies | Your consent, Article 6(1)(a), cf. the Danish Cookie Order |
| Targeted advertising | Usage data via cookies | Your consent, Article 6(1)(a) |
| Prevention of misuse and fraud | Technical logs | Legitimate interest in operating the site securely, Article 6(1)(f) |
Necessary cookies, which enable the site to function, are set without consent because they are a prerequisite for the service you have requested.
4. Newsletter
You can sign up for our newsletter in the footer of the site, when you create an account, or via an advertisement on Facebook or Instagram.
Subscription always happens actively and voluntarily. We use your email address to send news about products, sales, and consignments. You can unsubscribe at any time using the link at the bottom of any email or by writing to us – it costs nothing and requires no justification.
We retain documentation of your consent so that we can prove it was given. The documentation is deleted two years after you unsubscribe.
When we send you a newsletter, we record whether the email is opened and which links are clicked. We use this to see which content is relevant and to avoid sending to addresses that are no longer active. If you do not wish for this tracking, you can unsubscribe from the newsletter.
5. Registration via Facebook and Instagram
If you fill out a registration form in one of our ads on Facebook or Instagram, Meta sends us the information you entered in the form – typically your name and email address.
We use this information solely to register you as a recipient of our newsletter and send you a welcome email. It is not shared with others and is not used for other purposes. The legal basis is the consent you gave in the form.
Meta also processes the information as an independent data controller according to its own terms. You can read about this at facebook.com/privacy/policy.
6. Cookies
A cookie is a small text file stored in your browser. It cannot contain viruses or read other content on your device.
We use four types:
- Necessary — enables the cart, login, and payment to function. Cannot be deselected.
- Functional — remembers your choices, e.g., language and country.
- Statistical — shows us how the site is used so we can improve it.
- Marketing — used to show you relevant ads and measure their effectiveness.
The first time you visit the site, you will be asked what you want to allow. Only necessary cookies are set before you make a decision.
You can change or withdraw your consent at any time via the cookie settings on the site, and you can delete cookies in your browser's settings. If you delete them, parts of the site may stop working as expected.
7. Who gets access to the information
We never sell your information.
We use a number of suppliers who process information on our behalf and according to our instructions. They are not allowed to use it for their own purposes, and we have data processing agreements with them:
| Supplier | Purpose |
|---|---|
| Our hosting provider | Operation of webshop, database, and files |
| Frisbii | Payment processing |
| Shipmondo | Shipping agreements and consignment labels |
| Resend | Sending order confirmations and newsletters |
| Dinero (Visma) | Bookkeeping |
| Google Ireland | Statistics and advertising |
| Meta Platforms Ireland | Advertising and registration via lead ads |
| Klaviyo | Sending newsletters and marketing emails, as well as statistics on openings and clicks |
In addition, we disclose information when required to do so, for example, to the shipping company so the package can be delivered, or to authorities when required by law.
8. Transfer to third countries
Our suppliers are generally located in the EU/EEA.
Some of them, including Resend, Klaviyo, Google, and Meta, may process information in the USA. This occurs on the basis of the EU Commission's decision on an adequate level of protection for companies affiliated with the EU-U.S. Data Privacy Framework, or on the basis of the EU Commission's standard contractual clauses supplemented by technical and organizational measures.
You can obtain a copy of the basis for transfer by writing to us.
9. How long we store the information
| Information | Deleted |
|---|---|
| Orders and invoices | 5 years after the end of the financial year to which the order relates, cf. the Danish Bookkeeping Act |
| Customer account | When you delete the account, or after 3 years of inactivity |
| Newsletter recipient | Immediately upon unsubscription. Documentation of consent is stored for 2 years thereafter |
| Customer service correspondence | 2 years after the case is closed |
| Complaint and warranty cases | 3 years after the case is closed |
| Technical logs | 12 months |
| Cookies | From your session expires and up to 24 months, depending on the individual cookie |
10. Your Rights
Under the GDPR, you have the right to:
- Access — to know what information we process about you and to receive a copy
- Rectification — to have inaccurate information corrected
- Erasure — to have information deleted when we no longer have a basis for storing it
- Restriction — to have processing suspended while an objection is being handled
- Object — to object to processing that is based on our legitimate interests, and always to direct marketing
- Data Portability — to receive the information you have provided to us in a commonly used machine-readable format
- Withdraw Consent — to withdraw consent at any time. This does not affect the lawfulness of processing prior to withdrawal
Write to if you wish to exercise any of these rights. We will respond within one month.
11. Complaint
If you are dissatisfied with how we process your information, we would very much like to hear from you first. You can also file a complaint with:
Datatilsynet (Danish Data Protection Agency) Carl Jacobsens Vej 35 2500 Valby datatilsynet.dk
12. Security
We protect your information with technical and organizational measures, including traffic encryption, access restriction to employees who need the information, and continuous updating of our systems.
Should a personal data security breach occur that poses a high risk to your rights, we will notify you as soon as possible.
13. Changes
We update this policy when our processing of information changes or when required by law. The date at the top indicates when it was last amended. In case of significant changes, we will notify you on the site or by email.
