Privacy Policy
1) Responsible person
See imprint
2) What data we process (and for what purpose)
a) Website access (technically required)
When you visit the website, we process technical data (e.g. IP address, device/browser data, time, pages visited) to provide and secure the website.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest: operation/security).
b) Ordering & Contract Processing
When you place an order, we process data such as name, address, email, telephone number (if applicable), and order and payment information (payment data is usually processed via payment providers).
Purpose: Contract processing, invoicing, communication regarding the order.
Legal basis: Art. 6 para. 1 lit. b GDPR (contract) and lit. c GDPR (legal obligations).
c) Contact
When you contact us, we process the data you provide (e.g., name, email, message) in order to handle your request.
Legal basis: Art. 6 para. 1 lit. b GDPR (pre-contractual/contractual) or lit. f GDPR (legitimate interest: processing of inquiries).
3) Recipient / Service Provider
We use Shopify as our shop platform (hosting, checkout, shop functions). In doing so, personal data is processed by Shopify and/or within its infrastructure.
Other recipients may include, depending on usage:
-
Payment service provider (displayed at checkout)
-
IT/Hosting service provider
-
Possibly an email service provider (for order emails)
4) Cookies & Consent
We use technically necessary cookies to ensure the shop functions correctly (e.g., shopping cart/checkout).
If we use analytics/marketing cookies, this will only happen after you have given your consent via the cookie banner; you can withdraw your consent at any time via the cookie settings.
5) Storage duration
We only store personal data for as long as it is necessary for the aforementioned purposes or as long as we are legally obligated to do so (e.g., commercial and tax law retention).
6) Your rights
Depending on the circumstances, you have the right to information, rectification, erasure, restriction of processing, data portability, and the right to object. If you have given your consent, you can withdraw it at any time with effect for the future.
You also have the right to lodge a complaint with a data protection supervisory authority.
7) Data transfer to third countries
Using Shopify may involve the transfer of data to third countries (e.g., USA/Canada). Shopify uses appropriate safeguards for this in accordance with Articles 44 et seq. of the GDPR (e.g., standard contractual clauses/adequacy decisions).
8) Changes
We may update this privacy policy if legal requirements or our processes change.