Datenschutz

Datenschutz ist wichtig. Deswegen versuchen wir so offen und klar wie möglich zu kommunizieren, wie Deine Daten verarbeitet und genutzt werden.

Data Protection

Privacy Policy

1. Data protection at a glance

General information

The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to personally identify you. Detailed information on data protection can be found in our privacy policy, which is linked below.

Data collection on this website

Who is responsible for data collection on this website?

Data processing on this website is carried out by the website operator. Their contact details can be found in the section "Information on the responsible body" in this privacy policy.

How do we collect your data?

Your data is collected, firstly, because you provide it to us. This could include, for example, data that you enter into a contact form.

Other data is collected automatically or with your consent by our IT systems when you visit the website. This is primarily technical data (e.g., internet browser, operating system, or time of page access). This data is collected automatically as soon as you access this website.

What do we use your data for?

Some data is collected to ensure the website functions correctly. Other data may be used to analyze your user behavior. If contracts can be concluded or initiated via the website, the transmitted data will also be processed for contract offers, orders, or other inquiries.

What rights do you have regarding your data?

You have the right to obtain information free of charge at any time regarding the origin, recipients, and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given your consent to data processing, you can revoke this consent at any time for the future. Furthermore, you have the right, under certain circumstances, to request the restriction of the processing of your personal data. You also have the right to lodge a complaint with the competent supervisory authority.

You can contact us at any time with regard to this and other questions concerning data protection.

Analytics tools and third-party tools

When you visit this website, your browsing behavior may be statistically analyzed. This is done primarily using so-called analytics programs.

Detailed information about these analytics programs can be found in the following privacy policy.

2. Hosting and Content Delivery Networks (CDN)

We host the content of our website with the following providers:

Shopify

The provider is Shopify International Limited, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland (hereinafter referred to as “Shopify”).

Shopify is a tool for building and hosting websites. When you visit our website, Shopify collects your IP address and information about the device and browser you are using. Shopify also analyzes visitor numbers, visitor sources, and customer behavior, and generates user statistics. If you make a purchase on our website, Shopify also collects your name, email address, shipping and billing addresses, payment information, and other data related to the purchase (e.g., phone number, sales volume, etc.). Shopify stores cookies in your browser for these analyses.

For details, please refer to Shopify's privacy policy: https://www.shopify.de/legal/datenschutz .

The use of Shopify is based on Article 6(1)(f) GDPR. We have a legitimate interest in ensuring the most reliable presentation of our website. If consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) of the German Telemedia Act (TMG), insofar as the consent includes the storage of cookies or access to information on the user's device (e.g., device fingerprinting) within the meaning of the TDDG. Consent can be withdrawn at any time.

Order processing

We have concluded a data processing agreement (DPA) for the use of the aforementioned service. This is a legally required contract under data protection law, which ensures that the service provider processes the personal data of our website visitors only according to our instructions and in compliance with the GDPR.

Strato

The provider is Strato AG, Otto-Ostrowski-Straße 7, 10249 Berlin (hereinafter "Strato"). When you visit our website, Strato collects various log files, including your IP address.

For further information, please refer to Strato's privacy policy: https://www.strato.de/datenschutz/ .

The use of Strato is based on Article 6(1)(f) GDPR. We have a legitimate interest in ensuring the most reliable presentation of our website possible. If corresponding consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user's device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be withdrawn at any time.

Order processing

We have concluded a data processing agreement (DPA) for the use of the aforementioned service. This is a legally required contract under data protection law, which ensures that the service provider processes the personal data of our website visitors only according to our instructions and in compliance with the GDPR.

Cloudflare

By using Shopify and the review tool Judge.me (see below), we use the service "Cloudflare". The provider is Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA (hereinafter "Cloudflare").

Cloudflare offers a globally distributed Content Delivery Network (CDN) with DNS. Technically, the transfer of information between your browser and our website is routed through the Cloudflare network. This enables Cloudflare to analyze the traffic between your browser and our website and to act as a filter between our servers and potentially malicious traffic from the internet. Cloudflare may also use cookies or other technologies to recognize internet users, but these are used solely for the purpose described here.

The use of Cloudflare is based on our legitimate interest in providing our website in the most error-free and secure way possible (Art. 6 para. 1 lit. f GDPR).

Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details and further information on security and data protection at Cloudflare can be found here: https://www.cloudflare.com/privacypolicy/ .

The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/5666 .

3. General information and mandatory disclosures

Data protection

The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.

When you use this website, various personal data are collected. Personal data is data that can be used to identify you personally. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done.

Please note that data transmission over the internet (e.g., when communicating via email) can have security vulnerabilities. Complete protection of data against access by third parties is not possible.

Note regarding the responsible body

The responsible body for data processing on this website is:

Matthias Schempf
Herrenalber Straße 48
75334 Straubenhardt

Telephone: +49 (0)7082 60422
Email: mail@driver13.de

The responsible entity is the natural or legal person who, alone or jointly with others, decides on the purposes and means of processing personal data (e.g. names, email addresses, etc.).

Storage duration

Unless a more specific retention period is stated within this privacy policy, your personal data will remain with us until the purpose for processing the data no longer applies. If you submit a legitimate request for erasure or withdraw your consent to data processing, your data will be deleted, provided we have no other legally permissible grounds for storing your personal data (e.g., tax or commercial law retention periods); in the latter case, the data will be deleted once these grounds cease to apply.

General information on the legal basis for data processing on this website

If you have consented to data processing, we process your personal data on the basis of Article 6(1)(a) GDPR or Article 9(2)(a) GDPR if special categories of data pursuant to Article 9(1) GDPR are processed. In the case of explicit consent to the transfer of personal data to third countries, data processing also takes place on the basis of Article 49(1)(a) GDPR. If you have consented to the storage of cookies or to access to information on your device (e.g., via device fingerprinting), data processing additionally takes place on the basis of Section 25(1) of the German Telemedia Act (TMG). You can withdraw your consent at any time. If your data is required for the performance of a contract or for taking steps prior to entering into a contract, we process your data on the basis of Article 6(1)(b) GDPR. Furthermore, we process your data if it is necessary for compliance with a legal obligation, on the basis of Article 6(1)(c) GDPR. Data processing may also be based on our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR. Information on the applicable legal bases in each individual case is provided in the following paragraphs of this privacy policy.

Recipients of personal data

As part of our business activities, we collaborate with various external parties. This sometimes requires the transfer of personal data to these external parties. We only disclose personal data to external parties if this is necessary for the performance of a contract, if we are legally obligated to do so (e.g., disclosure of data to tax authorities), if we have a legitimate interest in the disclosure pursuant to Article 6(1)(f) GDPR, or if another legal basis permits the data transfer. When using data processors, we only transfer our customers' personal data on the basis of a valid data processing agreement. In the case of joint processing, a joint processing agreement is concluded.

Revocation of your consent to data processing

Many data processing operations are only possible with your explicit consent. You can revoke your consent at any time. The legality of data processing carried out before the revocation remains unaffected by the revocation.

Right to object to data processing in special cases and to direct marketing (Art. 21 GDPR)

If data processing is based on Article 6(1)(e) or (f) of the GDPR, you have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you; this also applies to profiling based on these provisions. The specific legal basis for each processing operation can be found in this privacy policy. If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or the processing serves the purpose of establishing, exercising or defending legal claims (objection pursuant to Art. 21 para. 1 GDPR).

If your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such marketing; this also applies to profiling insofar as it is related to such direct marketing. If you object, your personal data will subsequently no longer be processed for direct marketing purposes (objection pursuant to Article 21(2) GDPR).

Right to lodge a complaint with the competent supervisory authority

In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, their place of work, or the place of the alleged infringement. This right to lodge a complaint is without prejudice to any other administrative or judicial remedy.

Right to data portability

You have the right to receive the data that we process automatically based on your consent or in fulfillment of a contract, either for yourself or for a third party, in a commonly used, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done if technically feasible.

Information, correction and deletion

Under applicable law, you have the right to request information, free of charge, about your stored personal data, its origin and recipients, and the purpose of the data processing, as well as the right to rectification or erasure of this data. You can contact us at any time with regard to this and any other questions concerning personal data.

Right to restriction of processing

You have the right to request the restriction of the processing of your personal data. You can contact us at any time to do so. The right to restrict processing exists in the following cases:

  • If you dispute the accuracy of your personal data stored with us, we generally need time to verify this. For the duration of the verification process, you have the right to request the restriction of the processing of your personal data.
  • If the processing of your personal data was/is unlawful, you can request the restriction of data processing instead of deletion.
  • If we no longer need your personal data, but you require it for the establishment, exercise or defense of legal claims, you have the right to request restriction of processing of your personal data instead of erasure.
  • If you have objected to processing pursuant to Article 21(1) GDPR, a balancing of interests between your interests and ours must be carried out. Until it is determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.

If you have restricted the processing of your personal data, this data – apart from being stored – may only be processed with your consent or for the establishment, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the European Union or of a Member State.

SSL or TLS encryption

This site uses SSL/TLS encryption for security reasons and to protect the transmission of confidential information, such as orders or inquiries that you send to us as the site operator. You can recognize an encrypted connection by the fact that the browser's address bar changes from "http://" to "https://" and by the lock symbol in your browser's address bar.

When SSL or TLS encryption is enabled, the data you send to us cannot be read by third parties.

Encrypted payment transactions on this website

If, after concluding a paid contract, you are obligated to provide us with your payment details (e.g., account number for direct debit), this data is required for payment processing.

Payments via common payment methods (Visa/MasterCard, direct debit) are processed exclusively via an encrypted SSL or TLS connection. You can recognize an encrypted connection by the fact that the browser's address bar changes from "http://" to "https://" and by the padlock symbol in your browser's address bar.

With encrypted communication, your payment details that you transmit to us cannot be read by third parties.

Objection to advertising emails

The use of contact details published as part of the legal notice for sending unsolicited advertising and informational materials is hereby prohibited. The operators of these pages expressly reserve the right to take legal action in the event of unsolicited advertising, such as spam emails.

4. Data collection on this website

Cookies

Our website uses so-called "cookies." Cookies are small data packets and do not harm your device. They are stored on your device either temporarily for the duration of a session (session cookies) or permanently (persistent cookies). Session cookies are automatically deleted after you leave our website. Persistent cookies remain stored on your device until you delete them yourself or until they are automatically deleted by your web browser.

Cookies can originate from us (first-party cookies) or from third-party companies (so-called third-party cookies). Third-party cookies enable the integration of certain services from third-party companies within websites (e.g., cookies for processing payment services).

Cookies serve various functions. Many cookies are technically necessary, as certain website functions would not work without them (e.g., the shopping cart function or the display of videos). Other cookies can be used to analyze user behavior or for advertising purposes.

Cookies that are necessary for carrying out electronic communication, for providing certain functions you have requested (e.g., for the shopping cart function), or for optimizing the website (e.g., cookies for measuring website traffic) (necessary cookies) are stored on the basis of Article 6(1)(f) GDPR, unless another legal basis is specified. The website operator has a legitimate interest in storing necessary cookies to ensure the technically flawless and optimized provision of its services. If consent to the storage of cookies and similar recognition technologies has been requested, processing is carried out exclusively on the basis of this consent (Article 6(1)(a) GDPR and Section 25(1) TDDDG); this consent can be revoked at any time.

You can configure your browser to notify you when cookies are set and to allow cookies only in individual cases, to accept cookies in certain cases or to generally reject them, and to automatically delete cookies when you close your browser. Disabling cookies may limit the functionality of this website.

If further cookies and services are used on this website, you can find this information in this privacy policy.

Shopify cookie banner

Our website uses the cookie banner integrated into Shopify to obtain your consent to the storage of certain cookies on your device or the use of certain technologies and to document this in accordance with data protection regulations. The provider is Shopify International Limited, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland (hereinafter referred to as “Shopify”).

When you visit our website, a connection is established with the servers of the provider Shopify. Shopify receives personal data in this way, such as the browser used, the IP address, and a timestamp. A cookie is then stored in your browser to associate your consents with you or their revocation. The data collected in this way is stored until you request its deletion, delete the cookie yourself, or the purpose for data storage no longer applies. Mandatory legal retention obligations remain unaffected. For details, please refer to Shopify's privacy policy: https://www.shopify.de/legal/datenschutz .

The Shopify cookie banner is used to obtain the legally required consent for the use of cookies. The legal basis for this is Article 6(1)(c) GDPR.

Order processing

In connection with our use of Shopify, we have entered into a data processing agreement (DPA) for the use of the aforementioned service. This is a legally required agreement under data protection law, which ensures that Shopify processes the personal data of our website visitors only according to our instructions and in compliance with the GDPR.

Server log files

The website provider automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. This information includes:

  • Browser type and browser version
  • Operating system used
  • Referrer URL
  • Hostname of the accessing computer
  • Time of server request
  • IP address

This data will not be combined with other data sources.

This data is collected on the basis of Article 6(1)(f) GDPR. The website operator has a legitimate interest in the technically flawless presentation and optimization of its website – for this purpose, the server log files must be recorded.

Contact form

If you send us inquiries via the contact form, your information from the inquiry form, including the contact details you provided, will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. We will not share this data without your consent.

The processing of this data is based on Article 6(1)(b) GDPR if your request is related to the performance of a contract or is necessary for taking steps prior to entering into a contract. In all other cases, processing is based on our legitimate interest in the effective handling of inquiries addressed to us (Article 6(1)(f) GDPR) or on your consent (Article 6(1)(a) GDPR), if such consent has been obtained; you may withdraw your consent at any time.

The data you enter in the contact form will remain with us until you request its deletion, revoke your consent to its storage, or the purpose for data storage no longer applies (e.g., after your inquiry has been processed). Mandatory legal provisions – in particular, retention periods – remain unaffected.

B2B contact form

For B2B contact requests, we use the tool "Formful". The provider is HerculesApps, Eduard-Heis-Str. 3, 51061 Cologne, Germany.

For this app to function, it needs access to the following data:

  • Customers
    Name, email address, phone number, physical address, geolocation, IP address, browser and operating system
  • Content provider
    Email address, IP address, browser and operating system
  • Shop owner
    Name, email address, phone number, physical address
  • Customers process
    Customer data
  • Processing orders
    All order data for the last 60 days
  • Show other data
    regional schemes
  • View products
    Product listings or collections
  • View your online shop
    Pages in your online shop

For more information about data protection regarding the "Formful" app and the developer HerculesApps, please visit the HerculesApps privacy policy page at: https://herculesapps.com/formful/privacy-policy

The same applies here: If you send us inquiries via the contact form, your information from the inquiry form, including the contact details you provide there, will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. We will not share this data without your consent.

The processing of this data is based on Article 6(1)(b) GDPR if your request is related to the performance of a contract or is necessary for taking steps prior to entering into a contract. In all other cases, processing is based on our legitimate interest in the effective handling of inquiries addressed to us (Article 6(1)(f) GDPR) or on your consent (Article 6(1)(a) GDPR), if such consent has been obtained; you may withdraw your consent at any time.

The data you enter in the contact form will remain with us until you request its deletion, revoke your consent to its storage, or the purpose for data storage no longer applies (e.g., after your inquiry has been processed). Mandatory legal provisions – in particular, retention periods – remain unaffected.

Inquiries via email, telephone or fax

When you contact us by email, telephone, or fax, your inquiry, including all resulting personal data (name, inquiry), will be stored and processed by us for the purpose of handling your request. We will not share this data without your consent.

The processing of this data is based on Article 6(1)(b) GDPR if your request is related to the performance of a contract or is necessary for taking steps prior to entering into a contract. In all other cases, processing is based on our legitimate interest in the effective handling of inquiries addressed to us (Article 6(1)(f) GDPR) or on your consent (Article 6(1)(a) GDPR), if such consent has been obtained; you may withdraw your consent at any time.

The data you send us via contact requests will remain with us until you request its deletion, revoke your consent to its storage, or the purpose for data storage no longer applies (e.g., after your request has been processed). Mandatory legal provisions – in particular, statutory retention periods – remain unaffected.

Communication via WhatsApp

We use the instant messaging service WhatsApp, among other methods, to communicate with our customers and other third parties. The provider is WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.

Communication is end-to-end encrypted (peer-to-peer), preventing WhatsApp or other third parties from accessing the content of the communication. However, WhatsApp does have access to metadata generated during the communication process (e.g., sender, recipient, and time). We would also like to point out that, according to WhatsApp, it shares its users' personal data with its US-based parent company, Meta. Further details on data processing can be found in WhatsApp's privacy policy at: https://www.whatsapp.com/legal/#privacy-policy .

The use of WhatsApp is based on our legitimate interest in communicating with customers, prospective customers, and other business and contractual partners as quickly and effectively as possible (Art. 6 para. 1 lit. f GDPR). If corresponding consent has been requested, data processing is carried out exclusively on the basis of this consent; this consent can be revoked at any time with effect for the future.

The content of communications exchanged between you and us on WhatsApp will remain with us until you request its deletion, revoke your consent to its storage, or the purpose for data storage no longer applies (e.g., after your request has been processed). Mandatory legal provisions – in particular, retention periods – remain unaffected.

The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/7735 .

We use WhatsApp in the "WhatsApp Business" version.

Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://www.whatsapp.com/legal/business-data-transfer-addendum

We have configured our WhatsApp accounts so that there is no automatic data synchronization with the address book on the smartphones in use.

Registration on this website

You can register on this website to use additional features. We will only use the data you provide for the purpose of providing the specific offer or service for which you registered. All required information requested during registration must be provided in full. Otherwise, we will reject your registration.

For important changes, such as changes to the scope of services or technically necessary changes, we will use the email address you provided during registration to inform you.

The data entered during registration is processed for the purpose of carrying out the user relationship established by the registration and, if applicable, for initiating further contracts (Art. 6 para. 1 lit. b GDPR).

The data collected during registration will be stored by us for as long as you are registered on this website and will then be deleted. Statutory retention periods remain unaffected.

5. Analytics tools and advertising

Google Tag Manager

We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

The Google Tag Manager is a tool that allows us to integrate tracking and analytics tools and other technologies into our website. The Google Tag Manager itself does not create user profiles, store cookies, or perform independent analyses. It serves solely to manage and deploy the tools integrated through it. However, the Google Tag Manager does collect your IP address, which may also be transferred to Google's parent company in the United States.

The use of Google Tag Manager is based on Article 6(1)(f) GDPR. The website operator has a legitimate interest in the quick and easy integration and management of various tools on their website. If corresponding consent has been obtained, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent includes the storage of cookies or access to information on the user's device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be withdrawn at any time.

The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780 .

Google Analytics

This website uses functions of the web analytics service Google Analytics. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics allows website operators to analyze the behavior of website visitors. The website operator receives various usage data, such as page views, time spent on the site, operating systems used, and the user's origin. This data is aggregated into a user ID and assigned to the respective device of the website visitor.

Furthermore, we can use Google Analytics to record your mouse movements, scrolling, and clicks, among other things. Google Analytics also uses various modeling approaches to supplement the collected data and employs machine learning technologies for data analysis.

Google Analytics uses technologies that enable user recognition for the purpose of analyzing user behavior (e.g., cookies or device fingerprinting). The information collected by Google about the use of this website is generally transmitted to and stored on a Google server in the USA.

The use of this service is based on your consent pursuant to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. This consent can be revoked at any time.

Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://business.safety.google/adscontrollerterms/sccs/ .

The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780 .

IP anonymization

Google Analytics IP anonymization is activated. This means that your IP address is shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before being transmitted to the USA. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity, and to provide other services relating to website activity and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.

Browser Plugin

You can prevent Google from collecting and processing your data by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de .

For more information on how Google Analytics handles user data, please see Google's privacy policy: https://support.google.com/analytics/answer/6004245?hl=de .

Google Signals

We use Google Signals. When you visit our website, Google Analytics collects, among other things, your location, search history, YouTube history, and demographic data (visitor data). This data can be used for personalized advertising with the help of Google Signals. If you have a Google account, the visitor data from Google Signals will be linked to your Google account and used for personalized advertising messages. The data is also used to create anonymized statistics on the user behavior of our users.

Order processing

We have concluded a data processing agreement with Google and fully comply with the strict requirements of the German data protection authorities when using Google Analytics.

Google Analytics E-Commerce Measurement

This website uses the "E-commerce Measurement" feature of Google Analytics. E-commerce measurement allows the website operator to analyze the purchasing behavior of website visitors to improve their online marketing campaigns. Information such as orders placed, average order values, shipping costs, and the time from viewing to purchasing a product are collected. This data can be aggregated by Google under a transaction ID that is assigned to the respective user or their device.

Google Ads

The website operator uses Google Ads. Google Ads is an online advertising program of Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

Google Ads allows us to display advertisements in the Google search engine or on third-party websites when users enter specific search terms into Google (keyword targeting). Furthermore, targeted advertisements can be displayed based on user data available to Google (e.g., location data and interests) (audience targeting). As website operators, we can quantitatively evaluate this data by, for example, analyzing which search terms led to the display of our advertisements and how many advertisements resulted in clicks.

The use of this service is based on your consent pursuant to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. This consent can be revoked at any time.

Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://policies.google.com/privacy/frameworks andhttps://business.safety.google/controllerterms/ .

The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780 .

Google Conversion Tracking

This website uses Google Conversion Tracking. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

With the help of Google conversion tracking, Google and we can recognize whether a user has performed certain actions. For example, we can analyze which buttons on our website are clicked most frequently and which products are viewed or purchased most often. This information is used to create conversion statistics. We learn the total number of users who clicked on our ads and what actions they performed. We do not receive any information that allows us to personally identify the user. Google itself uses cookies or similar recognition technologies for identification.

The use of this service is based on your consent pursuant to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. This consent can be revoked at any time.

For more information about Google Conversion Tracking, please see Google's privacy policy: https://policies.google.com/privacy?hl=de .

The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780 .

Meta-Pixel (formerly Facebook Pixel)

This website uses the Meta pixel for conversion tracking. The provider of this service is Meta Platforms Ireland Limited, Merrion Road Dublin 4, Dublin, D04 X2K5, Ireland. According to Meta, the collected data is also transferred to the USA and other third countries.

This allows the behavior of website visitors to be tracked after they have been redirected to the provider's website by clicking on a meta ad. This enables the effectiveness of meta ads to be evaluated for statistical and market research purposes and future advertising campaigns to be optimized.

The data collected is anonymous for us as the operators of this website; we cannot draw any conclusions about the identity of the users. However, the data is stored and processed by Meta, so a connection to the respective user profile on Facebook or Instagram is possible, and Meta can use the data for its own advertising purposes in accordance with the Meta Data Policy ( https://de-de.facebook.com/about/privacy/ ). This allows Meta to display advertisements on Facebook or Instagram pages and other advertising channels. We, as the website operators, have no influence over this use of the data.

The use of this service is based on your consent pursuant to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. This consent can be revoked at any time.

We use the extended matching function within the meta-pixels.

Advanced matching allows us to send various types of data (e.g., city, state, postal code, hashed email addresses, names, gender, date of birth, or phone number) of our customers and prospects, which we collect through our website, to Meta. This enables us to tailor our advertising campaigns on Facebook and Instagram even more precisely to people who are interested in our offers. Furthermore, advanced matching improves the attribution of website conversions and expands Custom Audiences.

To the extent that personal data is collected on our website using the tool described here and forwarded to Meta, we and Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Dublin, D04 X2K5, Ireland, are jointly responsible for this data processing (Art. 26 GDPR). This joint responsibility is limited exclusively to the collection of the data and its transfer to Meta. The processing carried out by Meta after the transfer is not part of the joint responsibility. Our joint obligations are set out in a joint controllership agreement. You can find the text of the agreement at: https://www.facebook.com/legal/controller_addendum . According to this agreement, we are responsible for providing data protection information when using the Meta tool and for the data protection-compliant implementation of the tool on our website. Meta is responsible for the data security of Meta products. You can assert your data subject rights (e.g., requests for access) regarding data processed by Facebook or Instagram directly with Meta. If you assert your data subject rights with us, we are obligated to forward them to Meta.

Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum andhttps://de-de.facebook.com/help/566994660333381 .

You can find further information on protecting your privacy in Meta's privacy policy: https://de-de.facebook.com/about/privacy/ .

You can also deactivate the "Custom Audiences" remarketing feature in the ad settings at https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen . You must be logged in to Facebook to do this.

If you do not have an account with Facebook or Instagram, you can deactivate interest-based advertising from Meta on the website of the European Interactive Digital Advertising Alliance: http://www.youronlinechoices.com/de/praferenzmanagement/ .

The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/4452 .

Pinterest tag

We have integrated the Pinterest tag on this website. The provider is Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland.

The Pinterest tag is used to track certain actions you perform on our website. This data can then be used to display interest-based advertising to you on our website or on other sites within the Pinterest tag advertising network.

For this purpose, the Pinterest tag collects, among other things, a tag ID, your location, and the referrer URL. Furthermore, action-specific data such as order value, order quantity, order number, category of purchased items, and video views can be collected.

The Pinterest tag uses technologies that enable cross-site user recognition for the purpose of analyzing user behavior (e.g., cookies or device fingerprinting).

Where consent has been obtained, the aforementioned service is used exclusively on the basis of Article 6(1)(a) GDPR and Section 25 TDDDG. This consent can be revoked at any time. Where no consent has been obtained, this service is used on the basis of Article 6(1)(f) GDPR; the website operator has a legitimate interest in the most effective marketing measures possible.

Pinterest is a global company, so data may be transferred to the USA. According to Pinterest, this data transfer is based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://policy.pinterest.com/de/privacy-policy .

Further information about the Pinterest tag can be found here: https://help.pinterest.com/de/business/article/track-conversions-with-pinterest-tag .

The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/4203 .

Krtbite

We have integrated the Cartbite app into this website. The provider is Cartbite, plot no-84, gali no-8, ambika enclave, kakrola, New Delhi, DL, 110059, IN (hereinafter referred to as Cartbite).

Krtbite is a marketing automation tool for sending emails and SMS messages to inform customers and prospects about the restocking of products.

For this purpose, Krtbite stores consent for email marketing. In particular, the following data may be processed: name, telephone number, email address, address data, IP address, device identifiers, usage data (such as interactions between a user and Krtbite's online system, website or email, browser used, operating system used, referrer URL).

The use of Krtbite is based on Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDDG.

For further details, please refer to the provider's privacy policy at https://cartbite.staqlab.com/privacy .

Trusted Shops

Integration of the Trusted Shops Trustbadge / other widgets

To display Trusted Shops services (e.g., trustmarks, collected reviews) and to offer Trusted Shops products to buyers after an order, Trusted Shops widgets are integrated on this website. This serves our legitimate interests, which outweigh your interests, in optimal marketing by enabling secure shopping in accordance with Art. 6 Para. 1 Sentence 1 lit. f GDPR. The Trustbadge and the services advertised with it are offered by Trusted Shops AG, Subbelrather Str. 15C, 50823 Cologne, Germany ("Trusted Shops"), with whom we are jointly responsible for data protection in accordance with Art. 26 GDPR. In the following, we inform you about the essential contractual content in accordance with Art. 26 Para. 2 GDPR within the framework of this privacy notice.

Within the framework of the joint responsibility between us and Trusted Shops, please contact Trusted Shops preferably with any data protection questions and to assert your rights, using the contact options provided in their privacy policy . However, you are always free to contact the responsible party of your choice. If necessary, your inquiry will then be forwarded to the other responsible party for a response.

1. Data processing when integrating the Trustbadge / other widgets

The Trustbadge is provided by a US-based CDN (Content Delivery Network) provider.
An adequate level of data protection is ensured in each case by an adequacy decision of the EU Commission, which is available here for the USA. Service providers from the USA are generally certified under the EU-US Data Privacy Framework (DPF). Further information is available here . If service providers are not certified under the DPF, standard contractual clauses have been concluded as a suitable safeguard.

When the Trustbadge is accessed, the web server automatically saves a server log file containing your IP address, the date and time of access, the amount of data transferred, and the requesting provider (access data), thus documenting the access. The IP address is anonymized immediately after collection, so the stored data cannot be associated with you personally. The anonymized data is used primarily for statistical purposes and error analysis.

2. Data processing after order completion

After completing your order, order information (order total, order number, and, if applicable, the purchased product) as well as your email address, hashed using a cryptographic one-way function, will be transmitted to Trusted Shops. The legal basis for this is Article 6(1)(f) GDPR. This serves to verify whether you are already registered for services with Trusted Shops and is therefore necessary for the fulfillment of our and Trusted Shops' overriding legitimate interests in providing buyer protection and transactional review services linked to the specific order, in accordance with Article 6(1)(f) GDPR. If this is the case, further processing will take place in accordance with the contractual agreement between you and Trusted Shops. If you are not yet registered for the services, you will subsequently have the opportunity to do so for the first time. Further processing after successful registration is also governed by the contractual agreement with Trusted Shops. If you do not register, all transmitted data will be automatically deleted by Trusted Shops, and it will no longer be possible to identify you personally.

Trusted Shops uses service providers for hosting, monitoring, and logging. The legal basis for this is Article 6(1)(f) GDPR for the purpose of ensuring smooth operation. This may involve processing in third countries (USA and Israel).
An adequate level of data protection is ensured in each case by an adequacy decision of the EU Commission, which can be accessed here for the USA and here for Israel. Service providers from the USA are generally certified under the EU-US Data Privacy Framework. Further information is available here . Where service providers are not certified under the DPF, standard contractual clauses have been concluded as a suitable safeguard.

Judge.me

We have integrated the Judge.me app into this website. The provider is... Judge.me C/O Buckworths 2nd Floor, 1-3 Worship Street, London, ENG, EC2A 2AB, GB (hereinafter Judge.me).

Judge.me is used to collect and display customer reviews of our products and our shop. Customers are asked to submit product reviews via email, for example. When submitting a review, certain personal data is processed to verify the customer's rating. If you submit a review in our shop, your first and last name, email address, order date and number, name, and, if applicable, international references (GTIN/ISDN) are collected, transmitted to Judge.me, and evaluated there to determine the legitimacy of a customer review for a specific order. At the same time, customer data such as email address, first and last name, and order number are used to request a review from customers after they have placed an order.

The use of Judge.me is based on Article 6 Paragraph 1 Letter a GDPR and Section 25 Paragraph 1 TTDDG. Based on our legitimate interest in ensuring the authenticity of customer reviews by verifying their transactional relevance and preventing review abuse. After review review and approval are complete, the data is deleted by Judge.me .

All of the aforementioned processing activities may also involve the transfer of personal data to servers of Judge.me and associated service providers (e.g. Cloudflare) in the USA.

Judge.me's privacy policy can be found in the provider's privacy statement at https://judge.me/privacy .

UpPromote Affiliate Marketing

We have integrated the UpPromote Affiliate Marketing app (hereinafter referred to as UpPromote) into this website. The provider is the company UpPromote, located in [location omitted]. Me linh, Hanoi, 100000, VN.

UpPromote saves As part of its services, UpPromote places cookies on your device to document transactions (e.g., leads and sales) and records your use of our website (e.g., whether an order was placed in our online shop). These cookies serve the purpose of correctly attributing the success of an advertising campaign and the corresponding billing within the UpPromote affiliate program network. The cookies are used to record the origin of the request (UpPromote campaign) so that UpPromote can track sales to this publisher campaign for this session. This is used to identify the sales request between the UpPromote campaign and the program.

For UpPromote to function in our shop, the service requires access to customer data such as... Name, email address, phone number, physical address, Geolocation, IP address, browser and operating system, browsing behavior, client ID cookie. UpPromote also requires access to shop data regarding customer browsing behavior, orders and order history, as well as products and product offers.

The use of UpPromote is based on Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDDG.

All of the aforementioned processing activities may also involve the transfer of personal data to servers of UpPromote and associated service providers in the USA.

UpPromote's privacy policy can be found in the provider's privacy statement at https://docs.uppromote.com/privacy-policy/privacy-policy .

6. Newsletter

Newsletter data

If you wish to subscribe to the newsletter offered on this website, we require your email address and information that allows us to verify that you are the owner of the email address provided and that you agree to receive the newsletter. No further data is collected, or only on a voluntary basis. We use this data exclusively for sending the requested information and do not share it with third parties.

The processing of the data entered in the newsletter registration form is based solely on your consent (Art. 6 para. 1 lit. a GDPR). You can revoke your consent to the storage of your data, your email address, and its use for sending the newsletter at any time, for example, via the "Unsubscribe" link in the newsletter. The lawfulness of the data processing operations already carried out remains unaffected by the revocation.

The data you provide for the purpose of subscribing to our newsletter will be stored by us or our newsletter service provider until you unsubscribe. After you unsubscribe or the purpose for receiving the newsletter no longer applies, your data will be deleted from the newsletter distribution list. We reserve the right to delete or block email addresses from our newsletter distribution list at our own discretion, based on our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR.

Data that we have stored for other purposes remains unaffected.

After you unsubscribe from our newsletter mailing list, your email address may be stored on a blacklist by us or our newsletter service provider if this is necessary to prevent future mailings. The data on the blacklist will only be used for this purpose and will not be combined with other data. This serves both your interest and our interest in complying with legal requirements for sending newsletters (legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR). Storage on the blacklist is not time-limited. You can object to this storage if your interests outweigh our legitimate interest.

7. eCommerce and payment providers

Processing of customer and contract data

We collect, process, and use personal customer and contract data to establish, define the content of, and modify our contractual relationships. We collect, process, and use personal data relating to the use of this website (usage data) only to the extent necessary to enable the user to access the service or for billing purposes. The legal basis for this is Article 6(1)(b) GDPR.

The collected customer data will be deleted after completion of the order or termination of the business relationship and expiry of any applicable statutory retention periods. Statutory retention periods remain unaffected.

Data transfer during contract conclusion for online shops, retailers and shipping companies

When you order goods from us, we share your personal data with the transport company responsible for delivery and the payment service provider handling your payment. Only the data required by each service provider to fulfill their task will be shared. The legal basis for this is Article 6(1)(b) GDPR, which permits the processing of data for the performance of a contract or for taking steps prior to entering into a contract. If you have given your consent in accordance with Article 6(1)(a) GDPR, we will share your email address with the transport company responsible for delivery so that they can inform you about the shipping status of your order via email; you can withdraw this consent at any time.

Payment services

We integrate payment services from third-party companies on our website. When you make a purchase with us, your payment data (e.g., name, payment amount, bank account details, credit card number) is processed by the payment service provider for the purpose of payment processing. The respective terms and conditions and privacy policies of the respective providers apply to these transactions. The use of these payment service providers is based on Article 6(1)(b) GDPR (contractual necessity) and in the interest of ensuring the smoothest, most convenient, and most secure payment process possible (Article 6(1)(f) GDPR). Where your consent is requested for specific actions, Article 6(1)(a) GDPR serves as the legal basis for data processing; consent can be withdrawn at any time for the future.

We use the following payment services/payment providers on this website:

PayPal

The provider of this payment service is PayPal (Europe) S.à.rl et Cie, SCA, 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter referred to as “PayPal”).

Data transfers to the USA are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://www.paypal.com/de/webapps/mpp/ua/pocpsa-full .

For details, please refer to PayPal's privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full .

Apple Pay

The payment service provider is Apple Inc., Infinite Loop, Cupertino, CA 95014, USA. Apple's privacy policy can be found at: https://www.apple.com/legal/privacy/de-ww/ .

Google Pay

The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google's privacy policy can be found here: https://policies.google.com/privacy .

Klarna

The provider is Klarna AB, Sveavägen 46, 111 34 Stockholm, Sweden (hereinafter "Klarna"). Klarna offers various payment options (e.g., installment payments). If you choose to pay with Klarna (Klarna Checkout solution), Klarna will collect various personal data from you. Klarna uses cookies to optimize the use of the Klarna Checkout solution. Details on the use of Klarna cookies can be found at the following link: https://cdn.klarna.com/1.0/shared/content/policy/cookie/de_de/checkout.pdf

You can find details about this in Klarna's privacy policy at the following link: https://www.klarna.com/de/datenschutz/ .

Amazon Pay

The provider of this payment service is Amazon Payments Europe SCA, 38 avenue JF Kennedy, L-1855 Luxembourg.

Details on how your data is handled can be found in the Amazon Pay privacy policy at the following link: https://pay.amazon.de/help/201212490?ld=APDELPADirect .

Shopify Payment

The provider of this payment service in the EU is Shopify International Limited, 2nd Floor Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland (hereinafter referred to as “Shopify Payment”).

For details, please refer to Shopify Payment's privacy policy: https://www.shopify.de/legal/datenschutz .

American Express

The provider of this payment service is American Express Europe SA, Theodor-Heuss-Allee 112, 60486 Frankfurt am Main, Germany (hereinafter referred to as "American Express").

American Express may transfer data to its parent company in the USA. This data transfer to the USA is based on the Binding Corporate Rules. Details can be found here: https://www.americanexpress.com/en-cz/company/legal/privacy-centre/binding-corporate-rules/

For further information, please refer to the American Express privacy policy: https://www.americanexpress.com/de-de/firma/legal/datenschutz-center/online-datenschutzerklarung/ .

Mastercard

The provider of this payment service is Mastercard Europe SA, Chaussée de Tervuren 198A, B-1410 Waterloo, Belgium (hereinafter referred to as “Mastercard”).

Mastercard may transfer data to its parent company in the USA. This data transfer to the USA is based on Mastercard's Binding Corporate Rules. Details can be found here: https://www.mastercard.de/de-de/datenschutz.html and https://www.mastercard.us/content/dam/mccom/global/documents/mastercard-bcrs.pdf

VISA

The provider of this payment service is Visa Europe Services Inc., London Branch, 1 Sheldon Square, London W2 6TT, United Kingdom (hereinafter referred to as “VISA”).

The UK is considered a safe third country with regard to data protection. This means that the UK has a level of data protection equivalent to that of the European Union.

VISA may transfer data to its parent company in the USA. This data transfer to the USA is based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://www.visa.de/nutzungsbedingungen/visa-globale-datenschutzmitteilung/mitteilung-zu-zustandigkeitsfragen-fur-den-ewr.html

For further information, please refer to VISA's privacy policy: https://www.visa.de/nutzungsbedingungen/visa-privacy-center.html .

8. Audio and video conferences

Data processing

We use online conferencing tools, among other methods, to communicate with our customers. The specific tools we use are listed below. When you communicate with us via video or audio conference over the internet, your personal data will be collected and processed by us and the provider of the respective conferencing tool.

The conference tools collect all data that you provide/use to access the tools (email address and/or your phone number). Furthermore, the conference tools process the duration of the conference, the start and end times of your participation, the number of participants, and other "contextual information" related to the communication process (metadata).

Furthermore, the tool provider processes all technical data necessary for handling online communication. This includes, in particular, IP addresses, MAC addresses, device IDs, device type, operating system type and version, client version, camera type, microphone or speaker, and the type of connection.

If content is exchanged, uploaded, or otherwise made available within the tool, it will also be stored on the tool provider's servers. Such content includes, in particular, cloud recordings, chat/instant messages, voicemails, uploaded photos and videos, files, whiteboards, and other information shared during the use of the service.

Please note that we do not have full control over the data processing operations of the tools used. Our options are largely determined by the respective provider's company policy. Further information on data processing by the conference tools can be found in the privacy policies of the respective tools, which we have listed below this text.

Purpose and legal basis

The conference tools are used to communicate with prospective or existing business partners or to offer certain services to our customers (Art. 6 para. 1 lit. b GDPR). Furthermore, the use of these tools serves to generally simplify and expedite communication with us or our company (legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR). Where consent has been requested, the use of the relevant tools is based on this consent; this consent can be revoked at any time with effect for the future.

Storage duration

The data we collect directly via video and conferencing tools will be deleted from our systems as soon as you request its deletion, withdraw your consent to its storage, or the purpose for data storage no longer applies. Stored cookies remain on your device until you delete them. Mandatory legal retention periods remain unaffected.

We have no control over how long your data is stored by the operators of the conference tools for their own purposes. For details, please contact the operators of the conference tools directly.

Conference tools used

We use the following conference tools:

Microsoft Teams

We use Microsoft Teams. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Details regarding data processing can be found in the Microsoft Teams privacy statement: https://privacy.microsoft.com/de-de/privacystatement .

The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. Further information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/6474 .

Order processing

We have concluded a data processing agreement (DPA) for the use of the aforementioned service. This is a legally required contract under data protection law, which ensures that the service provider processes the personal data of our website visitors only according to our instructions and in compliance with the GDPR.