+3110 - 747 00 00

LIMITED TIME OFFER: 20% OFF SITEWIDE

Privacy and Cookie Policy

Last updated: Aug 14, 2026

DiamondsByMe takes the protection of personal information seriously. This policy explains what personal information we handle when you visit our United States website, use our services or visit our premises, why we handle it, who receives it, how long we keep it and how you can exercise available privacy choices and rights.

Who we are and how we use information

DiamondsByMe B.V. is responsible for personal information handled through www.diamondsbyme.com.

DiamondsByMe B.V.

Dienstenstraat 25

3161 GN Rhoon

The Netherlands

Dutch Chamber of Commerce: 24376433

Email: [email protected]

Telephone: +31 10 747 0000

This policy applies to customers and visitors in the United States. Our services are not directed to children under 13, and we do not knowingly collect personal information from children under 13 without legally required parental consent.

Depending on how you use our website and services, we may process:

  • name, address, town or city, email address and telephone number;
  • account, order, delivery and invoice information;
  • product specifications such as ring size, metal, stone, engraving and configuration choices;
  • payment method, payment status and data needed for payment or refund; we do not normally receive full payment-card details;
  • customer service, chat, complaint, return, warranty, repair and service information, including photographs you send;
  • newsletter subscription, marketing preferences and consent records;
  • technical information such as IP address, device, browser, cookies and website use;
  • fraud prevention, security and misuse information;
  • CCTV images at our premises; and
  • recruitment information such as contact details, CV and correspondence.

We do not request more information than reasonably necessary. Without required information, we may be unable to fulfill an order, payment, delivery or service request.

We handle personal information where reasonably necessary for our functions and activities, for the purposes described below and as permitted or required by applicable law:

  • to create accounts, make and deliver orders, take payment, and handle returns, warranties, repairs and services;
  • to comply with accounting, tax, consumer-law, product-safety and other legal obligations and lawful requests from authorities;
  • for customer service, security, fraud prevention, quality improvement, statistics, business operations and establishing or defending legal claims; and
  • for newsletters and analytical, personalization or marketing technologies where consent is required or has been requested. Consent can be withdrawn at any time.

CCTV protects staff, visitors, jewelry, goods and premises and helps prevent or investigate incidents. We use signs at the premises, restrict access and retain footage only as reasonably necessary.

We use information to record and make the configured jewelry, communicate about the order, process payment and arrange delivery.

Payments may be handled by Adyen, Pay.nl, Klarna or PayPal. Delivery details may be shared with carriers including DHL and FedEx.

Payment partners may independently conduct payment, fraud, credit or risk checks under their own notices and terms.

When you contact us, we use contact information, messages, order details and submitted photographs to deal with the request.

Freshdesk/Freshchat and Minimal AI may support chat, information retrieval, drafting and conversation summaries. Important decisions on orders, complaints, warranty or fraud are not made solely by AI where meaningful human review is needed.

Marketing, cookies and recipients

We send commercial emails in accordance with the CAN-SPAM Act and other applicable law. Messages identify the sender, include our valid postal address and provide a clear unsubscribe option. We act on unsubscribe requests within five working days.

We may retain a minimal suppression record to respect an opt-out.

Messages necessary for an order, payment, delivery, return, warranty, repair, security or requested service are service communications rather than newsletters.

CookieHub manages preferences. Essential storage and access technologies support the website and services.

The United States does not have one nationwide cookie-consent rule for all websites. We use CookieHub to provide transparency and choice and obtain consent or provide opt-out mechanisms where required by applicable federal or state law or by our selected operating standard.

Personalization, remarketing and advertising technologies are used according to the preferences selected through CookieHub. You can accept, refuse or later change non-essential technology preferences through the cookie settings.

The CookieHub notice provides the current technical list of technologies, providers, purposes and durations.

With consent where required, services may include Google, Meta, Microsoft, TikTok and Pinterest for analytics, measurement, personalization and remarketing.

We disclose information only as needed for the purposes above, with consent, or where legally required. Recipients may include:

  • Afosto for webshop, account and order management;
  • Adyen, Pay.nl, Klarna, PayPal and financial institutions;
  • DHL and FedEx;
  • Freshdesk/Freshchat, Minimal AI, Klaviyo and Typeform;
  • Trustpilot;
  • Cloudflare, CookieHub, Make.com and BigQuery;
  • Google, Meta, Microsoft, TikTok and Pinterest;
  • professional advisers, insurers, accountants and competent authorities.

Each recipient receives only what is necessary. We do not sell personal information.

After a purchase, we may provide name, email address and order number to Trustpilot to send a review invitation. Trustpilot acts under its own responsibility when you create an account or publish a review.

We work with NDBM Thailand Co., Ltd. and our own craftspeople in Thailand. Necessary order and product information may be accessed there for manufacture, engraving, planning, quality control, repair and service.

Access is limited. Payment information, marketing preferences, browsing behavior and unrelated customer information are not made available for production.

We use contractual, organizational and technical safeguards.

DiamondsByMe is established in the Netherlands. Personal information collected from customers in the United States is therefore transferred to and processed in the Netherlands.

Necessary order and product information may also be disclosed to NDBM Thailand Co., Ltd. and our craftspeople in Thailand for manufacture, engraving, planning, quality control, repair and service.

We use contractual, organizational and technical safeguards for overseas processing and require service providers to protect personal information consistently with this policy and applicable law.

Service providers may also use systems or subprocessors in other countries. Where practicable, we identify the countries in which overseas recipients are likely to be located and review material changes to these arrangements.

Retention, security and your rights

We keep information only as long as needed for its purpose, legal obligations, disputes and legitimate business needs. Broadly:

  • tax and financial records: generally seven years after the relevant financial year;
  • order, product, warranty and service records: as required for the contract, statutory rights, claims and the additional lifetime warranty; essential records may be kept longer to assess a lifetime-warranty claim;
  • ordinary customer service conversations: generally up to two years; records forming part of an order, return, complaint, warranty or service case generally up to five years, unless a legal duty, active dispute or warranty administration requires longer;
  • account information: while active or reasonably needed, subject to legal retention duties;
  • newsletter data: until opt-out, with a minimal suppression or evidence record retained as needed;
  • fraud and security information: generally no more than two years after no incident or dispute remains;
  • recruitment information: generally four weeks after the process, or up to one year with consent;
  • CCTV: up to four weeks unless needed for an incident, report or legal proceedings;
  • Custom Design requests through Typeform, Make.com and Google Sheets: up to two years if no order follows; necessary data becomes part of the order file if one does;
  • pseudonymized analytics and server-tracking data in BigQuery: up to 25 months;
  • Trustpilot invitation data: up to three years; BCC messages processed for the invitation service up to 30 days; and
  • cookie and analytics information: according to CookieHub and the selected preferences.

We use appropriate technical and organizational measures, including access controls, secure connections, supplier agreements, logging, back-ups and periodic reviews.

No system is risk-free. We investigate suspected data breaches and comply with applicable federal and state breach-notification requirements. Where notification is legally required, we notify affected individuals and the relevant authorities within the applicable time.

Depending on where you live and subject to applicable exceptions, you may have rights to request access to, correction or deletion of personal information, obtain a copy of certain information, or opt out of certain sales, sharing, targeted advertising or profiling. We will honor verified requests to the extent required by applicable law.

You may withdraw marketing consent or unsubscribe from direct marketing at any time. A minimal suppression record may be retained so that we continue to respect the request.

Send requests to [email protected]. We may request proportionate information to verify your identity and, where permitted, may accept a request from an authorized agent.

We respond within the period required by applicable law. If an extension is permitted and reasonably necessary, we will notify you.

If you believe we have mishandled your personal information, email [email protected] with enough information for us to investigate. No specific form is required.

We investigate the complaint and respond within a reasonable period, generally within 30 days. We will keep you informed where further time is reasonably required.

If you are not satisfied with our response, you may contact your state attorney general or other applicable state privacy regulator. You may also report concerns about unfair or deceptive practices to the Federal Trade Commission.

Federal Trade Commission

reportfraud.ftc.gov

You can find your state attorney general through the National Association of Attorneys General at naag.org.

Regulators determine whether and how they can assist with a complaint.

We may update this policy when our services, systems or the law change. The latest version is published on www.diamondsbyme.com. We provide additional notice of significant changes where reasonably appropriate.