Privacy Policy
Note: This privacy policy is a template. Enter your company details in the [square brackets] and adapt the list of third-party providers used (Klarna, PayPal, Google Analytics, etc.). We expressly recommend a review by a German lawyer or a specialised service (Händlerbund / Trusted Shops / IT-Recht Kanzlei).
1. Privacy at a glance
General information
The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to personally identify you. For detailed information on the subject of data protection, please refer to our privacy policy set out below this text.
Data collection on this website
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. You can find their contact details in the legal notice (Impressum) of this website.
How do we collect your data?
Your data is collected on the one hand by you providing it to us. This may be, for example, data you enter in a contact form or that you need for placing an order (name, delivery address, email, payment data).
Other data is collected automatically or after your consent when you visit the website by our IT systems. This is mainly technical data (e.g. internet browser, operating system or time of page access).
What do we use your data for?
Part of the data is collected to ensure error-free provision of the website and the processing of your order. Other data may be used to analyse your user behaviour.
What rights do you have regarding your data?
You have the right at any time to receive information free of charge about the origin, recipients and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. For this and for further questions on the subject of data protection, you can contact us at any time at the address given in the legal notice.
2. Hosting and external services
Shopify
We host our online shop with Shopify. The provider is Shopify International Limited, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland (hereinafter “Shopify”). When you access our online shop, all data required for this (e.g. IP address, browser data, order data) is processed on Shopify's servers.
The use of Shopify is based on Art. 6 (1) (b) and (f) GDPR. We have concluded a data processing agreement (DPA) with Shopify.
For more information, please see Shopify's privacy policy: https://www.shopify.com/legal/privacy
3. General information and mandatory information
Data protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.
Information about the responsible party
The party responsible for data processing on this website is:
[FULL COMPANY NAME]
[Street and house number]
[Postal code and city]
Phone: [Phone number]
Email: [E-MAIL]
The responsible party is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data (e.g. names, email addresses, etc.).
Data protection officer
[If you have a data protection officer: “We have appointed a data protection officer. Name and contact details: …”]
[If not: “We are not obliged to appoint a data protection officer. For questions about data protection, please contact the address given above.”]
Storage period
Unless a more specific storage period has been stated within this privacy policy, your personal data will remain with us until the purpose for the data processing no longer applies. If you assert a legitimate request for deletion or revoke consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data (e.g. tax or commercial law retention periods).
Withdrawal of your consent to data processing
Many data processing operations are only possible with your express consent. You can revoke consent you have already given at any time. The lawfulness of the data processing carried out up to the revocation remains unaffected by the revocation.
Right to lodge a complaint with the competent supervisory authority
In the event of breaches of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority. The right to complain exists without prejudice to other administrative or judicial remedies.
Information, deletion and correction
Within the framework of the applicable legal provisions, you have the right at any time to free information about your stored personal data, its origin and recipients and the purpose of the data processing and, if applicable, a right to correction or deletion of this data.
4. Data collection on this website
Cookies
Our website uses so-called “cookies”. Cookies are small text files and do not cause any damage to your device. They are stored either temporarily for the duration of a session (session cookies) or permanently (permanent cookies) on your device.
Cookies that are necessary to carry out the electronic communication process, to provide certain functions you have requested (e.g. shopping cart function) or to optimise the website (e.g. cookies to measure the web audience) (necessary cookies) are stored on the basis of Art. 6 (1) (f) GDPR. Where consent to the storage of cookies and comparable recognition technologies has been requested, processing takes place exclusively on the basis of this consent (Art. 6 (1) (a) GDPR).
Server log files
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are: browser type and browser version, operating system used, referrer URL, host name of the accessing computer, time of the server request, IP address.
Contact form & email enquiries
If you send us enquiries via the contact form or email, your details from the enquiry form, including the contact details you provide there, will be stored by us for the purpose of processing the enquiry and in case of follow-up questions. We do not pass on this data without your consent.
5. Order processing and shipping
Data transfer to shipping service providers
As part of contract processing, we transfer your address data to the shipping service provider commissioned by us (e.g. DHL), insofar as this is necessary for the delivery of the goods. The legal basis is Art. 6 (1) (b) GDPR.
Payment processing
Klarna — We offer payments via Klarna in our shop. The provider is Klarna Bank AB (publ), Sveavägen 46, 11134 Stockholm, Sweden. Klarna offers various payment options (e.g. purchase on account, instant transfer, instalment purchase). If you choose a Klarna payment, the data necessary for this (name, address, bank details, etc.) as well as data relating to your order will be transmitted to Klarna. More information on data processing by Klarna: https://www.klarna.com/de/datenschutz/. The data transfer is based on Art. 6 (1) (b) GDPR.
PayPal — On our website we offer, among other things, payment via PayPal. The provider of this payment service is PayPal (Europe) S.à.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg. When paying via PayPal, your entered payment data is forwarded to PayPal. More information: https://www.paypal.com/de/webapps/mpp/ua/privacy-full.
Shop Pay / Apple Pay / Google Pay — Express payment services provided by Shopify and the respective providers. When using them, your payment data is processed in encrypted form.
6. Plugins and tools
Google Web Fonts (or Shopify Fonts) — if used
This page uses so-called web fonts for the uniform display of fonts. The web fonts are loaded via the respective provider. When a page is accessed, fonts and related data (e.g. IP address) may be loaded from the provider's servers. The use is based on Art. 6 (1) (f) GDPR.
Newsletter
If you would like to receive the newsletter offered on the website, we require an email address from you as well as information that allows us to verify that you are the owner of the email address provided and that you agree to receive the newsletter. No further data is collected, or only on a voluntary basis. For the handling of the newsletter, we use newsletter service providers, which are described below.
7. Review apps and other third-party providers
The following third-party apps may be integrated on the website. Please supplement this list according to the apps you actually use:
- Air Product Reviews (Air Apps Ltd.) — storage of product reviews
- Wishlist Plus (Swym Corporation) — wishlist
- Krtbite Restock Alerts — back-in-stock notifications
- Bundler — product bundles
- Translate & Adapt (Shopify) — translations
The following applies to each of these services: data is only processed insofar as this is necessary for the respective purpose. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest) or Art. 6 (1) (a) GDPR (consent).
As of: [enter date]