Privacy Policy
Privacy Policy
SECTION 01Data Controller
The responsible party for data processing on this website is:
(haftungsbeschränkt)
85764 Oberschleissheim, Germany
SECTION 02Data Collection Overview
Automatically Collected Data
When you visit our website, certain data is automatically collected by our IT systems. This includes:
- Browser type and version
- Operating system used
- Referrer URL (previously visited page)
- Hostname of the accessing computer
- Time of the server request
- IP address (anonymized where possible)
This data is collected on the basis of Art. 6 (1) lit. f GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimization of the website.
Data You Provide
We also collect data that you voluntarily provide to us, for example when placing an order, creating an account, or contacting us. This may include:
- Name, email address, shipping and billing address
- Phone number (if provided)
- Payment information (processed securely via third-party providers)
- Order history and preferences
SECTION 03Purpose of Data Processing
We process your personal data for the following purposes:
- Processing and fulfilling your orders (Art. 6 (1) lit. b GDPR)
- Communicating with you regarding your orders or inquiries
- Providing and improving our website and services
- Sending marketing communications (only with your explicit consent, Art. 6 (1) lit. a GDPR)
- Complying with legal obligations (Art. 6 (1) lit. c GDPR)
- Fraud prevention and security
SECTION 04Cookies & Tracking
Our website uses cookies — small text files stored on your device. Some cookies are essential for the website to function (e.g., shopping cart), while others help us analyze website usage and improve your experience.
Essential Cookies
These are necessary for core site functionality, such as maintaining your session and shopping cart. They are set on the basis of Art. 6 (1) lit. f GDPR (legitimate interest).
Analytics & Marketing Cookies
We may use analytics tools (e.g., Shopify Analytics) to understand visitor behavior. Marketing cookies may be used to display relevant advertisements. These are only set with your explicit consent pursuant to Art. 6 (1) lit. a GDPR.
You can manage your cookie preferences through your browser settings at any time. Disabling certain cookies may limit site functionality.
SECTION 05Third-Party Services
We use the following third-party services that may process your data:
- Shopify — E-commerce platform (hosting, order processing)
- Payment Providers — Secure payment processing (e.g., PayPal, Stripe, Klarna)
- Shipping Partners — Order fulfillment and delivery
- Email Service Providers — Transactional and marketing emails
Each provider processes data according to their own privacy policies and data processing agreements in compliance with GDPR requirements.
SECTION 06Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes described in this policy, or as required by law. Specifically:
- Order data: Retained for the duration of legal retention periods (typically 6–10 years under German commercial and tax law)
- Account data: Retained until you request account deletion
- Marketing data: Retained until you withdraw consent
- Server logs: Automatically deleted after 30 days
SECTION 07Your Rights (GDPR)
Under the General Data Protection Regulation, you have the following rights:
- Right of Access (Art. 15 GDPR) — Obtain information about your stored data
- Right to Rectification (Art. 16 GDPR) — Correct inaccurate personal data
- Right to Erasure (Art. 17 GDPR) — Request deletion of your data
- Right to Restriction (Art. 18 GDPR) — Restrict the processing of your data
- Right to Data Portability (Art. 20 GDPR) — Receive your data in a machine-readable format
- Right to Object (Art. 21 GDPR) — Object to the processing of your data
- Right to Withdraw Consent (Art. 7 (3) GDPR) — Withdraw given consent at any time
To exercise any of these rights, please contact us at the address below. You also have the right to lodge a complaint with a supervisory authority (e.g., Bayerisches Landesamt für Datenschutzaufsicht).
SECTION 08Data Security
We use industry-standard SSL/TLS encryption for all data transmitted between your browser and our servers. Our website is hosted on Shopify’s secure infrastructure, which complies with PCI DSS standards for payment security. We regularly review and update our security measures to protect your data against unauthorized access, alteration, or destruction.