FAQs
On 1 August 2026, our logistics partner CEVA Logistics informed us that an unauthorised party had gained access to part of their systems, which are used to process Ace & Tate orders. We stopped sharing data with them the same day. CEVA blocked the access to those systems, took additional security measures and engaged external cybersecurity specialists to investigate the cause and impact. We also investigated whether our own systems were affected and we have no indications that this is the case - our website nd customer accounts were not accessed.
On 3 August 2026, CEVA informed us that it could not rule out that personal data was involved. As a precaution we notified the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), our lead supervisory authority in the EU, and the UK Information Commissioner's Office (ICO) on 5 August 2026. On 6 August 2026 we emailed the customers who at that time were known to be potentially involved.
On 10 September 2026, CEVA confirmed that personal data of Ace & Tate customers was in fact accessed and copied from their systems. On 14 September 2026 we started contacting the customers concerned again by email, to inform them of these new findings from CEVA's investigation.
The incident took place at CEVA Logistics, the provider that handles warehousing and shipping for part of our orders. CEVA works for many organisations across Europe, and a number of them were affected by the same incident. The incident occurred within CEVA's systems.
The incident took place in the systems of CEVA. We investigated immediately whether our own systems were affected and we have no indications that this is the case. Our website and customer accounts were not accessed.
Yes, we are still working with CEVA. CEVA acted on the requirements and recommendations of external cybersecurity specialists and took additional security measures. CEVA has confirmed to us that an independent party examined the security of the systems and established that they have been renewed and can be used safely again. On that basis we resumed our cooperation and their services restarted on 27 August 2026. We select our partners carefully and contractually require them to protect the personal data we entrust to them. That does not make an attack impossible.
We cannot yet say whether the incident could have been prevented. CEVA has since acted on the requirements and recommendations of external cybersecurity specialists and taken additional security measures. Protecting customer information is an important responsibility. We will use the findings of this investigation to strengthen our approach wherever improvements are identified.
Establishing exactly which data is involved in a security incident is a complex process: large volumes of data have to be examined and validated, and because these are another organisation's systems that work is carried out by CEVA.
CEVA has confirmed that the following data was accessed and copied from their systems: your name and contact details, including email address, delivery address, billing address and phone number; your order number and order date; delivery information, including the delivery method and the store your order was linked to; and details of the items ordered, including the product name and its price.
No payment details, bank account numbers (IBANs), credit card details, usernames or passwords are involved in this incident.
For business customers, company name and VAT number may also be involved.
No. Prescription and other medical data are not stored in the CEVA systems involved in this incident. CEVA receives this information only in hard copy.
We emailed the customers whose data may have been involved on 6 August 2026. On 14 September 2026, after receiving new information from CEVA, we started contacting the customers confirmed to be affected again by email, to inform them of these new findings. If you received that email, the data described above was involved. If you did not receive any email from us, we currently have no indication that your data was involved.
If you did not receive an email from us on 6 August 2026, then based on the information we had at that time, your data was not among the data identified as potentially involved. If CEVA's and our further investigation showed on 10 September 2026 that your data was in fact involved, we informed you as soon as reasonably possible after receiving those findings.
On the basis of the information known to us in August, we informed customers that their personal data might have been involved. CEVA has since confirmed that data was in fact accessed and copied from their systems. We said we would come back to you as soon as there were new and relevant developments, and that is why we have started contacting customers on 14 September 2026 to share these new findings from CEVA's investigation.
No. What we shared in August was correct on the basis of the information that was known and validated at that time. During an investigation of this size, findings emerge step by step. CEVA's further investigation established that more customers were affected than could be determined in August, and we informed those customers on 14 September 2026. We would rather be transparent and tell you as soon as findings have been validated than wait until every detail is final. We cannot say whether further information will follow.
Yes. Payment details, bank account numbers (IBANs) and credit card details are not shared with CEVA and are therefore not involved in this incident.
Your account credentials were not involved: usernames and passwords are not shared with CEVA, and our own systems were not accessed. You do not have to change your password. If you use the same password on other websites, changing it there is always sensible - not because of this incident, but because reused passwords are the most common cause of account takeovers.
The data was copied from CEVA's systems. CEVA monitors whether data from this incident is being offered or published online, including on the dark web, and to date no indications of this have been found. If that changes, we will update this page and inform the customers concerned.
CEVA prepares, ships and handles returns for part of our orders. To do that they need your name, address, contact details and order information. They receive only what is needed for those services, on our behalf and under a data processing agreement. We select our partners carefully and contractually require them to secure and protect the personal data we entrust to them.
We keep personal data for as long as we need it for the purpose it was collected for, or for as long as the law requires. Some order and invoice data has to be kept for tax and administrative purposes, and the same can apply to medical data. That is why data from older purchases may still be in our systems. CEVA processes only the data needed to prepare, deliver and return your order, on our behalf and under a data processing agreement.
We want to be as transparent as we can. In August we could not rule out that personal data had been viewed or copied, and we would rather have told you as a precaution than waited, so that you could be alert to phishing and other forms of misuse from the outset.
Because your name, contact details and order information were copied, there is an increased risk of phishing by email, message or telephone.
- Be extra alert to phishing messages. Check the sender, watch for typos, and look at what comes after the @ in an email address.
- Be alert to fake delivery or track & trace messages. Because order and delivery details are involved, you could receive messages that appear to come from our delivery partner about a parcel or order. Don't click links in unexpected delivery notifications - check the status of your order via your account on aceandtate.com instead.
- Don't share your password or payment details by email, phone or text.
- Not sure about a message? Don't click links or open attachments in messages from senders you don't know or trust, and see 'How do I recognise a genuine email from Ace & Tate?' below.
Our official email address is hello@aceandtate.com and newsletters are sent from hello@sending.aceandtate.com. Check the sender address: a fraudulent message can look almost identical. Not sure about a message? Do not click the links. Go to aceandtate.com, log in and check your order there.
Email hello@aceandtate.com and we will handle your request within one month. If your request is complex, or if we receive a large number of requests, we may extend that period by up to two further months and will tell you if that is the case. You can ask which personal data we hold about you, request corrections, or ask us to delete it. Some data - invoices and prescription details, for example - has to be kept for a period set by law, so it cannot always be deleted in full.
Yes. CEVA's services resumed on 27 August 2026 and online orders with home delivery are available again. You receive a shipping confirmation with a tracking link as soon as your order is on its way. Current delivery times are back to normal.
Yes. Our stores are open as usual and you are very welcome to visit, and you can book your eye test at your nearest store. Online orders are available again with home delivery as well as store pick-up.
Because you are a customer of Ace & Tate, not of CEVA. We are responsible for your personal data, so we inform you.
We update this page whenever there is new and relevant information, and we contact the customers concerned directly by email when CEVA's investigation produces findings that affect them. We did so on 6 August and again on 14 September 2026. If there are further relevant findings, we will do the same.
If your question is not answered on this page, you are always welcome to contact our customer service team at hello@aceandtate.com. We update this page and email the customers concerned as soon as more information is known.