Privacy policy

Privacy Policy

The responsible party for data processing is:
Marlene Wandres
Dunckerstr. 90A
10437 Berlin
Germany
marlene.wandres@gmail.com

We appreciate your interest in our online store. Protecting your privacy is very important to us. Below, we provide detailed information about how we handle your data.


1. Access Data and Hosting

You can visit our websites without providing any personal information. Each time you access a website, the web server automatically stores a so-called server log file, which contains, for example, the name of the requested file, your IP address, the date and time of access, the amount of data transmitted, and the requesting provider (access data), and documents the access. This access data is evaluated solely for the purpose of ensuring the proper operation of the site and improving our offerings. This serves to safeguard our legitimate interests, as weighed against the interests of users, in the proper representation of our offerings in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR. All access data will be deleted no later than seven days after the end of your visit.


2. Data Processing for Contract Fulfillment and Contact

We collect personal data when you voluntarily provide it to us in the course of your order or when contacting us (e.g., via contact form or email). Mandatory fields are marked as such because we need the data for the fulfillment of the contract or to process your inquiry, and you cannot submit the order or contact us without providing this information. The data collected is visible in the respective input forms. We use the data you provide to fulfill the contract and process your inquiries in accordance with Art. 6 para. 1 sentence 1 lit. b GDPR.

For further information on the processing of your data, including the sharing of data with our service providers for the purpose of order, payment, and shipping processing, please refer to the subsequent sections of this privacy policy. After the contract has been fully processed, your data will be restricted for further processing and deleted after the expiration of the tax and commercial law retention periods according to Art. 6 para. 1 sentence 1 lit. c GDPR, unless you have expressly consented to further use of your data in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR, or we reserve the right to further use of the data that is legally permitted and about which we inform you in this policy.


3. Data Processing for Shipping Fulfillment

For the fulfillment of the contract in accordance with Art. 6 para. 1 sentence 1 lit. b GDPR, we share your data with the shipping service provider commissioned with the delivery, as far as this is necessary for the delivery of the ordered goods.

Data Sharing with Shipping Service Providers for Shipping Notifications
If you have expressly consented to this during or after your order, we will share your email address with the selected shipping service provider so that they can contact you prior to delivery for delivery announcements or coordination.
The consent can be revoked at any time by sending a message to the contact details provided in this privacy policy or directly to the shipping service provider at the contact address listed below. After revocation, we will delete your data provided for this purpose, unless you have expressly consented to further use of your data, or we reserve the right to further use of the data that is legally permitted and about which we inform you in this policy.

DHL Paket GmbH
Sträßchensweg 10
53113 Bonn
Germany


4. Data Processing for Payment Processing

When processing payments in our online store, we cooperate with the following partners: technical service providers, credit institutions, and payment service providers.

4.1 Data Processing for Transaction Processing
Depending on the selected payment method, we forward the necessary data for processing the payment transaction to our technical service providers, who work for us as processors, or to the commissioned credit institutions or selected payment service providers, as far as necessary for processing the payment. This serves to fulfill the contract according to Art. 6 para. 1 sentence 1 lit. b GDPR. In some cases, payment service providers collect the data required for processing the payment themselves, for example, on their own website or through technical integration in the order process. The privacy policy of the respective payment service provider applies in these cases.
If you have any questions about our partners for payment processing and the basis of our cooperation with them, please contact us using the contact details provided in this privacy policy.

4.2 Data Processing for Fraud Prevention and Optimization of Our Payment Processes
We may also provide our service providers with additional data, which they will use, together with the data necessary for processing the payment, as our processors for fraud prevention and optimization of our payment processes (e.g., invoicing, handling disputed payments, supporting accounting). This serves to safeguard our legitimate interests in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR, to protect us from fraud and ensure efficient payment management.

5. Advertising by Email

5.1 Email Newsletter with Registration
If you subscribe to our newsletter, we will use the required or separately provided data to send you our email newsletter regularly based on your consent according to Art. 6 (1) Sentence 1 lit. a GDPR. You can unsubscribe from the newsletter at any time, either by sending a message to the contact details described below or via a link provided in the newsletter. After unsubscribing, we will delete your email address from the recipient list unless you have explicitly consented to further use of your data according to Art. 6 (1) Sentence 1 lit. a GDPR or we reserve the right to use the data in ways that are legally permitted and which we inform you about in this declaration.

5.2 Newsletter Dispatch
The newsletter may also be sent by our service providers as part of a processing order on our behalf. If you have any questions about our service providers and the basis of our cooperation with them, please contact us using the contact details provided in this privacy policy.


6. Cookies and Other Technologies
General Information
In order to make your visit to our website more attractive and to enable the use of certain features, we use various technologies, including so-called cookies, on different pages. Cookies are small text files that are automatically stored on your device. Some of the cookies we use are deleted after the end of the browser session (so-called session cookies). Other cookies remain on your device and allow us to recognize your browser when you visit our website again (persistent cookies).
We use such technologies that are essential for the use of certain features of our website (e.g., the shopping cart function). These technologies collect and process data such as IP address, time of visit, device and browser information, and information about your use of our website (e.g., information about the contents of the shopping cart). This serves, as part of a balancing of interests, our overriding legitimate interests in the optimized presentation of our offerings according to Art. 6 (1) Sentence 1 lit. f GDPR.

In addition, we use technologies to fulfill the legal obligations we are subject to (e.g., to prove consents for processing your personal data) as well as for web analysis and online marketing. Further information on this, including the respective legal basis for data processing, can be found in the following sections of this privacy policy.

You can find cookie settings for your browser at the following links: Microsoft Edge™ / Safari™ / Chrome™ / Firefox™ / Opera™

If you have consented to the use of technologies in accordance with Art. 6 (1) Sentence 1 lit. a GDPR, you can withdraw your consent at any time by sending a message to the contact details described in the privacy policy.


7. Use of Cookies and Other Technologies for Web Analysis and Advertising Purposes
If you have consented to this according to Art. 6 (1) Sentence 1 lit. a GDPR, we use the following cookies and other technologies from third-party providers on our website. Once the purpose no longer applies and we stop using the respective technology, the data collected in this context will be deleted. You can withdraw your consent at any time with effect for the future. For further information on your withdrawal options, please refer to the "Cookies and Other Technologies" section. Further information, including the basis of our cooperation with the individual providers, can be found for each technology. If you have any questions about the providers and the basis of our cooperation with them, please contact us using the contact details described in this privacy policy.

7.1 Use of Google Services
We use the technologies listed below from Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). The information about your use of our website automatically collected through Google technologies is usually transmitted to a server of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, and stored there. There is no adequacy decision by the European Commission for the USA. Our cooperation is based on the Standard Contractual Clauses of the European Commission. If your IP address is collected via Google technologies, it will be anonymized before being stored on Google's servers. Only in exceptional cases will the full IP address be transmitted to a Google server and anonymized there. As far as nothing different is stated for the individual technologies, data processing is based on an agreement between joint controllers according to Art. 26 GDPR. Further information on data processing by Google can be found in Google's privacy policy.

Google Analytics
For the purpose of website analysis, data (IP address, time of visit, device and browser information, and information about your use of our website) are automatically collected and stored through Google Analytics, and pseudonymized user profiles are created. Cookies may be used for this. Your IP address is not generally combined with other data from Google. Data processing is based on an agreement for data processing between Google and us.

For the purpose of optimized marketing of our website, we have activated the data sharing settings for "Google Products and Services." This allows Google to access and use data collected and processed by Google Analytics to improve Google services. Data sharing with Google within these settings is based on an additional agreement between controllers. We have no influence over the subsequent data processing by Google.

To create and conduct tests, we also use the extension function of Google Analytics, Google Optimize.

Google Ads
For advertising purposes in Google search results and on third-party websites, the so-called Google Remarketing Cookie is set when visiting our website. This enables interest-based advertising through the collection and processing of data (IP address, time of visit, device and browser information, and information about your use of our website) and through the use of a pseudonymous cookie ID and based on the pages you visited. Further data processing only occurs if you have activated "personalized ads" in your Google account. In this case, if you are logged into Google during your visit to our website, Google uses your data along with Google Analytics data to create and define cross-device remarketing audience lists.

For website analysis and event tracking, we measure your subsequent usage behavior via Google Ads Conversion Tracking if you arrived at our website through a Google Ads advertisement. Cookies may be used and data (IP address, time of visit, device and browser information, and information about your use of our website based on predefined events such as visiting a webpage or subscribing to a newsletter) is collected to create pseudonymized usage profiles.

7.2 Use of Facebook Services
Use of Facebook Pixel
We use Facebook Pixel as part of the following technologies provided by Facebook Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland ("Facebook"). The Facebook Pixel automatically collects and stores data (such as IP address, visit time, device and browser information, and information about your use of our website based on events we define, such as visiting a webpage or subscribing to a newsletter), from which usage profiles are created using pseudonyms. As part of the so-called extended data matching, additional information is collected and stored for matching purposes, which can identify individuals (e.g., names, email addresses, and phone numbers). To do this, a cookie is automatically set by the Facebook Pixel when you visit our website, which allows recognition of your browser when you visit other websites using a pseudonymous cookie ID. Facebook combines this information with other data from your Facebook account to generate reports about website activities and provide further web-related services, particularly personalized and group-based advertising.

The data automatically collected by Facebook technologies about your use of our website is usually transferred to a server of Facebook, Inc., 1601 Willow Road, Menlo Park, California 94025, USA, and stored there. There is no adequacy decision from the European Commission for the USA. If the data transfer to the USA falls under our responsibility, our cooperation is based on the standard contractual clauses of the European Commission. For further information about data processing by Facebook, please refer to Facebook’s privacy policy.

Facebook Analytics
As part of Facebook Analytics, statistics about visitor activities on our website are created from the data collected by the Facebook Pixel. The data processing is based on an agreement with Facebook for data processing. Your analysis is aimed at the optimal presentation and marketing of our website.

Facebook Ads
Through Facebook Ads, we advertise our website on Facebook and other platforms. We determine the parameters for each advertising campaign. Facebook is responsible for the exact implementation, including decisions regarding ad placement for individual users. Unless otherwise stated for specific technologies, the data processing is based on an agreement between joint controllers according to Article 26 GDPR. The joint responsibility is limited to the collection of the data and its transfer to Facebook Ireland. The subsequent data processing by Facebook Ireland is not included.

Based on the statistics about visitor activities on our website generated through Facebook Pixel, we run group-based advertising on Facebook through Facebook Custom Audiences by determining the characteristics of the respective target group. As part of the extended data matching (see above) for target group determination, Facebook acts as our data processor.

Based on the pseudonymous cookie ID set by Facebook Pixel and the data collected about your usage behavior on our website, we perform personalized advertising through Facebook Pixel Remarketing.

Through Facebook Pixel Conversions, we measure your subsequent behavior for web analysis and event tracking if you reached our website through a Facebook Ads advertisement. Data processing is based on an agreement for data processing with Facebook.

7.3 Other Web Analytics and Online Marketing Service Providers
Use of Pinterest Tag for Web Analysis and Advertising Purposes
For web analysis and advertising purposes on Pinterest and third-party websites, when visiting our website, technologies from Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland ("Pinterest") are automatically used to collect and process data (such as IP address, visit time, device and browser information, and information about your use of our website based on events we define, such as visiting a webpage or subscribing to a newsletter) and with a pseudonymous cookie ID. This allows interest-based advertising based on the pages you visit. Usage profiles are created from the collected data using pseudonyms. Pinterest combines this information with additional data from your Pinterest account to generate reports about website activities and provide additional web-related services. We have no control over Pinterest’s data processing and only receive statistics generated based on Pinterest Tag. Thus, we measure your subsequent behavior for web analysis and event tracking if you reached our website via a Pinterest advertisement.

The automatically collected information from Pinterest is typically transferred to a Pinterest server in the USA and stored there. The USA does not have an adequacy decision from the European Commission. Our cooperation relies on the standard contractual clauses of the European Commission. Data processing occurs based on an agreement between joint controllers under Article 26 GDPR.

8. Social Media
8.1 Social Plugins from Facebook, Instagram
Our website uses social buttons from social networks. These are only embedded as HTML links into the page, so no connection is established with the servers of the respective provider when visiting our website. When you click on one of the buttons, the website of the respective social network will open in a new window in your browser. There, you can, for example, click the Like or Share button.

8.2 Our Online Presence on Facebook, Instagram
If you have given your consent in accordance with Article 6(1) Sentence 1(a) of the GDPR to the respective social media operator, your data will be automatically collected and stored when you visit our online presence on the aforementioned social media platforms for market research and advertising purposes. Pseudonymous usage profiles are created from this data, which can be used, for example, to display ads within and outside of the platforms that are presumed to match your interests. Cookies are usually used for this purpose. For detailed information about the processing and use of the data by the respective social media operator, as well as contact information and your rights and privacy settings, please refer to the privacy policies linked below. If you need assistance, you can contact us.

Facebook is a service provided by Facebook Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland ("Facebook Ireland"). The information automatically collected by Facebook Ireland about your use of our online presence on Facebook is generally transferred to a server of Facebook, Inc., 1601 Willow Road, Menlo Park, California 94025, USA, and stored there. There is no adequacy decision from the European Commission for the USA. Our cooperation relies on the standard contractual clauses of the European Commission. Data processing in connection with visiting a Facebook Fanpage is based on an agreement between joint controllers according to Article 26 GDPR. Further information (including insights data) can be found here.

Instagram is a service provided by Facebook Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland ("Facebook Ireland"). The information automatically collected by Facebook Ireland about your use of our online presence on Instagram is generally transferred to a server of Facebook, Inc., 1601 Willow Road, Menlo Park, California 94025, USA, and stored there. There is no adequacy decision from the European Commission for the USA. Our cooperation relies on the standard contractual clauses of the European Commission. Data processing in connection with visiting an Instagram Fanpage is based on an agreement between joint controllers according to Article 26 GDPR. Further information (including insights data) can be found here.

9. Contact Options and Your Rights
As a data subject, you have the following rights:

  • Right to Access (Article 15 GDPR): The right to request information about the personal data we process about you to the extent defined therein.

  • Right to Rectification (Article 16 GDPR): The right to request the immediate correction of inaccurate or completion of your personal data stored with us.

  • Right to Erasure (Article 17 GDPR): The right to request the deletion of your personal data stored with us, unless further processing is required:

    • for the exercise of the right to freedom of expression and information;

    • to fulfill a legal obligation;

    • for reasons of public interest; or

    • for the assertion, exercise, or defense of legal claims.

  • Right to Restriction of Processing (Article 18 GDPR): The right to request the restriction of processing of your personal data if:

    • the accuracy of the data is disputed by you;

    • the processing is unlawful but you oppose the deletion;

    • we no longer need the data, but you need it for the assertion, exercise, or defense of legal claims; or

    • you have objected to processing under Article 21 GDPR.

  • Right to Data Portability (Article 20 GDPR): The right to receive your personal data that you have provided to us in a structured, commonly used, and machine-readable format or request its transmission to another controller.

  • Right to Lodge a Complaint (Article 77 GDPR): The right to file a complaint with a supervisory authority. Typically, you can contact the supervisory authority of your habitual residence, workplace, or the location of our company's headquarters.

For any questions regarding the collection, processing, or use of your personal data, or if you need information, correction, restriction, or deletion of data, or wish to withdraw consent or object to specific data processing, please contact us directly via the contact details in our Impressum.

Right to Object
If we process personal data based on our legitimate interests as part of a balancing of interests, you may object to this processing with effect for the future. If the processing is for direct marketing purposes, you can exercise this right at any time as described above. For other purposes, your right to object applies only if there are reasons arising from your particular situation.

Once you exercise your right to object, we will no longer process your personal data for these purposes unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or if the processing is necessary for the assertion, exercise, or defense of legal claims.

This does not apply if the processing is for direct marketing purposes. In that case, we will no longer process your personal data for this purpose.