Legal information
Privacy
How ALKA Group, trading through LegendMural, handles personal data when you use the storefront, place an order, contact us or exercise consumer rights.
Who is responsible for your data?
Alka Group, trading through the LegendMural storefront, is the controller for the personal data described on this page. Alka Group is registered with the Dutch Chamber of Commerce under KvK 95153756 at Schutkolk 4 d 1, 6582 DB Heumen, the Netherlands.
Privacy and customer-operations contact: info@legendmural.com.
Full seller and statutory contact details, including VAT and telephone information, are available on the Company Information page.
Data we process
For checkout and fulfilment we process the information you provide for your order: first name, last name, email address, street, optional address line 2, postal code, city and delivery country.
We also process order information such as selected products and variants, quantities, discounts, shipping zone and cost, order totals, currency, internal order reference, PayPal Order ID, payment state and timestamps needed to reconcile the order safely.
When an invoice PDF is requested through an authorized customer or dashboard download flow, we keep a limited security audit record containing the access time, access channel, trusted internal order reference, internal invoice identity where available, the access outcome and a general reason or error class. This audit record does not store the invoice PDF contents, Blob key or URL, service credentials or tokens, customer email solely for logging, full PayPal or checkout-session identifiers solely for logging, raw full IP address or raw full user-agent solely for logging.
If you contact us through the homepage contact form or by email, we process the name, email address, subject, message and follow-up correspondence you provide so we can answer your request and provide customer support.
If you use the online withdrawal function, we collect the name you enter, the Order ID and the order email address. The Order ID and order email are used to locate the purchase. Your name and confirmation email are used to create and send the statutory acknowledgement of your withdrawal. The immutable withdrawal record stores the link to the order, the server-side withdrawal timestamp and a confirmation code. A separate acknowledgement record stores the minimum statement snapshot and delivery information needed to provide, evidence and if necessary retry that acknowledgement: your name, confirmation email, Order ID/order reference, withdrawal declaration, confirmation code, receipt timestamp, delivery status, attempt timestamps, provider message identifier where available and a limited technical error code if delivery fails. The form does not ask you to provide a reason for withdrawal.
Why we process this data
We use order and contact data to create and perform the sales contract, calculate authoritative prices and shipping, process payment, deliver your order, provide order support and handle returns or withdrawal requests.
Limited invoice-download audit data is used to protect access to financial documents, investigate denied or failed access attempts, troubleshoot delivery problems and maintain an accountable security trail for customer and dashboard invoice access.
Contact and support messages are used to answer your request, take requested pre-contractual steps where relevant and maintain ordinary customer service. Depending on the request, this is based on steps connected with a contract or our legitimate interest in responding to customers and operating the storefront.
For the online withdrawal function, we process the statement data needed to register the withdrawal and provide and evidence the acknowledgement required for that consumer-right process. Limited delivery metadata is used to determine whether an acknowledgement succeeded and to support a controlled resend when delivery fails. This processing is based on our legal obligations relating to statutory withdrawal and, where relevant, the performance and administration of the sales contract.
We also retain limited order and payment-reconciliation data where necessary to meet legal obligations, maintain financial records, prevent duplicate financial processing, resolve disputes and protect the integrity of the payment flow.
The main legal bases are performance of a contract or requested pre-contractual steps, compliance with legal obligations and, where applicable, our legitimate interests in customer support, secure payment and invoice-access operations, fraud/error prevention and establishing or defending legal claims.
Payment, hosting and service providers
PayPal is used to provide the hosted payment experience and payment status. PayPal processes information under its own privacy terms when you use its service.
Netlify is used to host and run the storefront and server functions. Neon is used for durable order, payment-reconciliation, invoice-access audit, withdrawal and acknowledgement-delivery records.
Where LegendMural sends transactional email through Resend (Plus Five Five, Inc.), Resend receives the recipient email address, message content and technical delivery metadata needed to deliver and troubleshoot the message. Resend's primary processing operations and customer-data storage are in the United States. Its Data Processing Addendum includes safeguards for applicable international transfers, including the EU Standard Contractual Clauses.
The storefront loads Google Fonts from Google domains. Your browser may send technical request information such as your IP address and browser/request metadata when requesting those font files.
The homepage loads the Swiper interface library through jsDelivr. That CDN request can include technical information such as IP address, browser details, requested URL, referrer-domain information and request time.
We do not currently operate advertising pixels or behavioural analytics trackers in the tracked LegendMural storefront code.
Functional browser storage
The storefront uses functional browser storage to make the shopping and checkout experience work. localStorage is used for shopping-cart/version state, delivery-country selection and discount-code state. This information is stored in your browser and can remain there until it is replaced, cleared by the storefront or removed through your browser settings.
Temporary checkout and order-verification state can use sessionStorage. Session storage is designed for the browser session, and verified-paid checkout state is cleared where appropriate after the confirmed order flow completes.
This functional browser storage is not used by LegendMural for behavioural advertising or cross-site tracking.
How long we keep data
We apply different retention periods to different categories of data instead of keeping all personal data for one blanket period.
Sales, invoice and accounting information that forms part of our statutory business administration is normally retained for 7 years in line with Dutch tax record-keeping requirements. Where a transaction falls under an applicable One Stop Shop or Import One Stop Shop (OSS/IOSS) regime, the relevant records are retained for 10 years after the end of the year in which the supply took place.
Invoice-access audit records are normally retained for 90 days. Specific audit records may be kept longer where a documented security, dispute, legal or regulatory hold requires it.
Ordinary contact or support correspondence that is not part of an order, complaint, dispute, legal claim or statutory record is retained for up to 12 months after the request is resolved.
Withdrawal, complaint and other non-fiscal consumer-right or contractual evidence is kept only for as long as reasonably needed to administer the matter and establish, exercise or defend legal claims. Our retention limit for that evidence is generally up to 5 years where that period is needed, unless a shorter period is sufficient.
Specific information can be kept longer where a tax, legal, chargeback, fraud, security, warranty, dispute or regulatory hold requires it. A longer statutory record-keeping requirement also takes priority where it applies. These periods describe our retention policy; they do not imply that every category is currently subject to an automated deletion process.
Your privacy rights
Subject to the conditions in applicable data-protection law, you may ask for access to your personal data, correction, deletion, restriction of processing, data portability or object to certain processing.
You may contact us at info@legendmural.com. We may need to verify that a request concerns your own data before acting on it.
You also have the right to lodge a complaint with the competent data-protection supervisory authority.
Security and changes
LegendMural uses server-side authoritative pricing, server-side payment verification, restricted payment-provider URLs and durable payment reconciliation to reduce the risk of payment or order manipulation. Access to personal data is limited according to operational need and appropriate access controls.
We may update this notice when the storefront, providers or legal requirements change. Material changes will be reflected on this page.
Last updated: 7 September 2026.