Privacy Policy
1) Information on the Collection of Personal Data and Contact Details of the Controller
1.1
We are pleased that you are visiting our website and thank you for your interest. The following provides information on how your personal data is handled when you use our website. Personal data includes all data by which you can be personally identified.
1.2
The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is Shop Name. The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.
1.3
For security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the controller), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the string “https://” and the padlock icon in your browser’s address bar.
2) Data Collection When Visiting Our Website
When you use our website for informational purposes only — that is, if you do not register or otherwise transmit information to us — we collect only the data that your browser transmits to our server (so-called “server log files”). When you access our website, we collect the following data, which are technically necessary for us to display the website to you:
-
Our visited website
-
Date and time of access
-
Amount of data sent in bytes
-
Source/referrer from which you came to the site
-
Browser used
-
Operating system used
-
IP address used (possibly in anonymized form)
Processing takes place in accordance with Article 6(1)(f) GDPR on the basis of our legitimate interest in improving the stability and functionality of our website. The data are neither passed on nor used in any other way. However, we reserve the right to subsequently review server log files if there are specific indications of unlawful use.
3) Cookies
In order to make visiting our website attractive and to enable the use of certain functions, we use so-called cookies on various pages. Cookies are small text files stored on your device. Some of the cookies we use are deleted after the end of your browser session, i.e., after closing your browser (so-called session cookies). Other cookies remain on your device and allow us or our partner companies (third-party cookies) to recognize your browser the next time you visit (persistent cookies).
When cookies are set, they collect and process certain user information such as browser and location data and IP address values to varying degrees. Persistent cookies are automatically deleted after a specified duration, which may differ depending on the cookie.
In part, cookies are used to simplify the ordering process (e.g., remembering the contents of a virtual shopping cart for a later visit). If personal data are also processed through cookies implemented by us, such processing occurs either in accordance with Article 6(1)(b) GDPR for contract execution or in accordance with Article 6(1)(f) GDPR to safeguard our legitimate interests in ensuring the best possible functionality of the website and a customer-friendly and effective website experience.
We may also cooperate with advertising partners who help us make our online offering more interesting for you. For this purpose, cookies from partner companies (third-party cookies) may be stored on your hard drive when you visit our website. If we work with such advertising partners, you will be individually informed about the use of such cookies and the scope of the collected information in the following paragraphs.
Please note that you can configure your browser to inform you about the setting of cookies and to allow you to decide individually whether to accept them, or to exclude the acceptance of cookies for specific cases or in general. Each browser differs in the way it manages cookie settings. This is described in the help menu of each browser, which explains how to change your cookie settings. You can find these instructions for the respective browsers at the following links:
-
Internet Explorer: https://support.microsoft.com/de-de/help/17442/windows-internet-explorer-delete-manage-cookies
-
Firefox: https://support.mozilla.org/de/kb/cookies-erlauben-und-ablehnen
-
Chrome: https://support.google.com/chrome/answer/95647?hl=de&hlrm=en
-
Opera: https://help.opera.com/en/latest/web-preferences/#cookies
Please note that if you do not accept cookies, the functionality of our website may be restricted.
4) Contact
When you contact us (e.g., via contact form or e-mail), personal data is collected. The data collected through the contact form can be seen in the respective input form.
This data is stored and used exclusively for the purpose of responding to your request or for contacting you, and for the associated technical administration.
The legal basis for processing this data is our legitimate interest in responding to your request in accordance with Article 6(1)(f) GDPR.
If your contact is aimed at concluding a contract, the additional legal basis for processing is Article 6(1)(b) GDPR.
Your data will be deleted once your inquiry has been fully processed, provided that it can be inferred from the circumstances that the matter concerned has been conclusively resolved, and there are no statutory retention obligations preventing deletion.
5) Data Processing When Opening a Customer Account and for Contract Execution
Personal data is collected and processed when you open a customer account and/or conclude a contract.
The data collected can be seen from the respective input forms.
Data processing takes place for the purpose of performing a contract in accordance with Article 6(1)(b) GDPR.
Your data may be passed on to payment service providers or shipping companies, insofar as this is necessary for processing your order.
After completion of the contract or deletion of your customer account, your data will be blocked for further use and deleted after expiry of the statutory retention periods, unless you have expressly consented to further use of your data or a further legally permissible data use is reserved by us in this declaration.
You can delete your customer account at any time, either by sending a message to the controller’s contact address or by using a function provided for this purpose in the customer account.
6) Use of Your Data for Direct Advertising
6.1 Subscription to Our E-mail Newsletter
If you subscribe to our e-mail newsletter, we will regularly send you information about our offers.
The only mandatory information for sending the newsletter is your e-mail address.
The provision of any additional data is voluntary and used to address you personally.
For the newsletter dispatch we use the so-called double-opt-in procedure. This means that we will only send you a newsletter by e-mail once you have expressly confirmed that you consent to receiving newsletters.
We will then send you a confirmation e-mail asking you to confirm that you wish to receive newsletters by clicking a corresponding link.
By activating the confirmation link, you give us your consent to use your personal data in accordance with Article 6(1)(a) GDPR.
When you register for the newsletter, we store the IP address entered by your Internet service provider (ISP) and the date and time of registration to enable us to trace any possible misuse of your e-mail address at a later date.
The data collected by us when you register for the newsletter will be used exclusively for advertising purposes via the newsletter.
You can unsubscribe from the newsletter at any time via the link provided in each newsletter or by sending a message to the controller named above.
After unsubscribing, your e-mail address will be immediately deleted from our newsletter distribution list, unless you have expressly consented to further use of your data or such use is otherwise legally permitted.
6.2 Sending the Newsletter to Existing Customers
If you have provided us with your e-mail address when purchasing goods or services, we reserve the right to regularly send you offers on similar goods or services from our range via e-mail.
According to Section 7(3) of the German Unfair Competition Act (UWG), we do not require separate consent for this.
Data processing takes place solely on the basis of our legitimate interest in personalized direct advertising in accordance with Article 6(1)(f) GDPR.
If you initially objected to the use of your e-mail address for this purpose, we will not send you such e-mails.
You have the right to object to the use of your e-mail address for the aforementioned advertising purpose at any time with future effect by notifying the controller.
There are no costs for this other than the transmission costs according to the basic rates.
Upon receipt of your objection, the use of your e-mail address for advertising purposes will be immediately discontinued.
6.3 Newsletter Dispatch via Third-Party Providers
If newsletter distribution takes place via an external service provider, we will inform you about the provider used and the associated data processing in the respective section below.
7) Data Processing for Order Handling
7.1 Disclosure of Data to Shipping Service Providers
In order to deliver your order, we work with shipping service providers who support us in fulfilling contracts.
Certain personal data (such as name and delivery address) are passed on to the shipping company selected for delivery as necessary in accordance with Article 6(1)(b) GDPR.
If you have given your explicit consent during or after your order, we will pass on your e-mail address and/or phone number to the shipping service provider in accordance with Article 6(1)(a) GDPR so that they can contact you before delivery for notification or coordination purposes.
You can withdraw your consent at any time by sending a message to the controller or directly to the shipping service provider.
7.2 Use of Payment Service Providers (Payment Processors)
Depending on the payment method selected, payment data may be transmitted to the payment service providers we use for the purpose of processing payments.
The legal basis for this transmission is Article 6(1)(b) GDPR.
In some cases, the payment service providers also independently collect data, e.g., via their own websites or technical systems when payment is made.
In this respect, the privacy policy of the respective payment service provider applies.
Below are the most common payment providers and related notices:
PayPal
If you choose payment via PayPal, your payment data will be transferred to:
PayPal (Europe) S.à r.l. et Cie, S.C.A.,
22–24 Boulevard Royal, L-2449 Luxembourg
Transmission takes place in accordance with Article 6(1)(b) GDPR.
For further information, please refer to PayPal’s privacy policy:
👉 https://www.paypal.com/webapps/mpp/ua/privacy-full
Klarna
If you select Klarna payment services, your personal data (name, address, e-mail, phone number, IP address, and possibly bank details) will be shared with Klarna AB for identity and credit checks.
This occurs in accordance with Article 6(1)(b) GDPR for contract fulfillment and Article 6(1)(f) GDPR for fraud prevention.
More details can be found in Klarna’s privacy statement:
👉 https://www.klarna.com/international/privacy-policy/
Stripe
When you pay via Stripe, your payment details are transmitted to:
Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland
Data transfer takes place in accordance with Article 6(1)(b) GDPR.
Stripe may transfer data to the USA; in such cases, safeguards such as EU Standard Contractual Clauses are applied.
Details can be found here:
👉 https://stripe.com/privacy
8) Contact via WhatsApp
If the user contacts us via WhatsApp to initiate a transaction (e.g., an order or inquiry), the communication takes place via:
WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland
The data you provide (telephone number, message content, and any attachments) are processed exclusively for communication and contract processing.
The legal basis for this is Article 6(1)(b) GDPR.
We do not pass data to third parties without your consent.
WhatsApp Business messages are end-to-end encrypted. Nevertheless, WhatsApp gains access to metadata (e.g., sender, recipient, time).
More information can be found in WhatsApp’s privacy policy:
👉 https://www.whatsapp.com/legal/privacy-policy-eea
9) Use of Social Media: Social Plugins
9.1 Facebook Plugins (Like & Share Buttons)
Our website integrates plugins from the social network Facebook (Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland).
These can be recognized by the Facebook logo or the “Like” button.
When you visit a page with such a plugin, your browser establishes a direct connection with Facebook servers.
Facebook thus receives the information that you have visited our site, even if you do not have a Facebook account or are not logged in.
If you are logged into Facebook, your visit can be directly assigned to your account.
Interactions (e.g., pressing “Like”) are transmitted directly to Facebook and stored there.
Data processing takes place in accordance with Article 6(1)(f) GDPR due to our legitimate interest in marketing and improving our online presence.
You can find details about Facebook’s data policy at:
👉 https://www.facebook.com/about/privacy
9.2 Instagram Plugin
Our website may also use functions of Instagram (Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland).
When you visit a page that contains such a plugin, data about your interaction with the site is transmitted to Instagram.
If you are logged into your Instagram account, Instagram can associate your visit with your user profile.
You can prevent this by logging out of your Instagram account before visiting our website.
Further information is available at:
👉 https://help.instagram.com/519522125107875
10) Online Marketing
10.1 Google Ads (AdWords) Conversion Tracking
This website uses the online advertising program “Google Ads” and, within the scope of Google Ads, conversion tracking from:
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
If you click on an ad delivered by Google, a cookie is placed for conversion tracking.
Cookies of this kind lose validity after 30 days and do not serve to personally identify users.
If a user visits specific pages within the website and the cookie has not yet expired, Google and we can recognize that the user clicked on the ad and was redirected to that page.
Each Google Ads customer receives a different cookie.
Cookies cannot therefore be tracked across the websites of different Ads customers.
The information obtained through the conversion cookie is used to create conversion statistics for Ads customers who have opted for conversion tracking.
We learn the total number of users who clicked on our ad and were redirected to a page tagged with a conversion tracking tag.
However, we do not obtain any information by which users can be personally identified.
The use of Google Ads takes place on the basis of Article 6(1)(f) GDPR, representing our legitimate interest in targeted advertising and analyzing its effectiveness.
Further information on data protection at Google can be found here:
👉 https://policies.google.com/privacy
11) Web Analysis Services
11.1 Google Analytics
This website uses Google Analytics, a web analytics service provided by
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics uses cookies that enable analysis of your use of our website.
The information generated by the cookie about your use of this site (including your shortened IP address) is usually transmitted to a Google server and stored there.
This website uses Google Analytics exclusively with the extension “_anonymizeIp()”, ensuring that IP addresses are processed only in truncated form to rule out direct personal reference.
The processing takes place in accordance with Article 6(1)(f) GDPR, based on our legitimate interest in the statistical analysis of user behavior for optimization and marketing purposes.
You can prevent the storage of cookies by adjusting your browser software; however, this may limit functionality.
You can also prevent Google from collecting and processing the data generated by the cookie by downloading and installing the browser plug-in available here:
👉 https://tools.google.com/dlpage/gaoptout?hl=en
Further information on Google’s data use:
👉 https://policies.google.com/privacy
12) Tools and Miscellaneous
12.1 Google ReCAPTCHA
We use the “Google ReCAPTCHA” function from
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
This function is used to distinguish whether an input is made by a natural person or by automated processing (e.g., bots).
The service includes the transmission of the IP address and possibly other data required by Google for the ReCAPTCHA service.
The legal basis is Article 6(1)(f) GDPR, representing our legitimate interest in protecting our website against misuse and spam.
12.2 Google Maps
This site uses Google Maps (API) from Google Ireland Limited to display interactive maps.
By using Google Maps, information about your website use (including your IP address) may be transmitted to Google.
Google may transmit this information to servers outside the EU (e.g., USA) under the EU Standard Contractual Clauses.
The integration is based on Article 6(1)(f) GDPR, reflecting our legitimate interest in an appealing presentation of our online offers and easy location of our premises.
More information:
👉 https://policies.google.com/privacy
13) Rights of the Data Subject
Under the GDPR, you have the following rights regarding the processing of your personal data:
-
Right of Access (Article 15 GDPR) – You have the right to obtain confirmation of whether personal data concerning you are being processed and, if so, access to those data and detailed information.
-
Right to Rectification (Article 16 GDPR) – You have the right to request correction of inaccurate or completion of incomplete personal data.
-
Right to Erasure (Article 17 GDPR) – You may request deletion of your data if the processing is no longer necessary or unlawful.
-
Right to Restriction of Processing (Article 18 GDPR) – You may restrict processing of your data in specific circumstances.
-
Right to Data Portability (Article 20 GDPR) – You may receive your data in a structured, commonly used, and machine-readable format or request that it be transmitted to another controller.
-
Right to Object (Article 21 GDPR) – You may object at any time to processing based on legitimate interests or for direct marketing purposes.
-
Right to Withdraw Consent (Article 7(3) GDPR) – You may withdraw consent at any time with future effect.
-
Right to Lodge a Complaint (Article 77 GDPR) – You have the right to lodge a complaint with a supervisory authority if you believe your data have been processed unlawfully.
14) Duration of Storage of Personal Data
The duration of personal-data storage is based on the respective legal retention period (e.g., commercial and tax law).
After expiry of this period, the corresponding data are routinely deleted, provided they are no longer required for contract performance or initiation and there is no further legitimate interest in continued storage.
15) Updates and Amendments
We reserve the right to adapt this Privacy Policy so that it always complies with current legal requirements or to reflect changes in our services (e.g., introduction of new products or functionalities).
Your renewed visit will then be subject to the new Privacy Policy.