⚠ Live prices unavailable — showing reference rates

Privacy & Security

This page is maintained by GoldMarc B.V. and describes how we handle your personal data and protect our website. It is editable project content and is not an independent certification.

Who we are

GoldMarc B.V., Bargelaan 200, 2333 CW Leiden, Netherlands. KvK 99855135, BTW/VAT NL005414790B54. Contact: sales@goldmarc.nl. We are a Wwft-registered Dutch dealer in physical gold and silver.

Data we collect

  • Contact details you submit (name, email, phone, address) when you place an order, request a quote, or contact us.
  • Order details (items, quantities, indicative prices at time of order).
  • For Wwft-regulated transactions: identification data required by Dutch anti-money-laundering law.
  • An essential cookie used only to remember that you dismissed the cookie banner. No analytics or tracking cookies.

How we use your data

  • To process quotes, orders, payments, and Brink's-insured delivery.
  • To meet our legal obligations under the Wwft and Dutch tax law.
  • To respond to your questions and provide customer service.

We do not sell your data, and we do not use it for advertising or profiling.

Sharing with third parties

We share data only with providers strictly necessary to deliver our service: our hosting and database provider, our email delivery provider, our payment processor, and our insured logistics partner (Brink's). Each acts as a processor under written agreement and is located in the EU or covered by an appropriate transfer mechanism.

Retention

Order and Wwft records are kept for the statutory retention period (currently seven years for tax and AML purposes). Quote requests and general correspondence are kept only as long as needed to handle your request.

Security controls

  • All traffic to this site is served over HTTPS.
  • Customer and admin data is stored in a managed Postgres database with row-level security; admin-only tables are restricted to verified admin accounts.
  • Administrative access requires authenticated sign-in; roles are stored server-side and enforced by database policies, not by client code.
  • Order confirmation emails are generated server-side with HTML escaping of all customer-provided fields.
  • Secrets and API keys are stored as server-side environment secrets and are never shipped to the browser.

Your rights (GDPR)

You can request access to, correction of, or deletion of your personal data, and you can object to or restrict certain processing. Email sales@goldmarc.nl and we will respond within 30 days. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

Reporting a security issue

If you believe you have found a security vulnerability affecting GoldMarc, please email sales@goldmarc.nl with details and steps to reproduce. Please do not publicly disclose the issue until we have had a reasonable chance to investigate and remediate.

See also our Terms of Trade.