Privacy policy
Privacy Policy
Unless otherwise stated below, the provision of your personal data is neither legally nor contractually required, nor is it necessary for the conclusion of a contract. You are not obliged to provide the data. Failure to provide the data has no consequences. This only applies insofar as no other information is provided in the following processing operations.
"Personal data" means any information relating to an identified or identifiable natural person.
Server Log Files
You may visit our website without providing any personal information.
Each time you access our website, usage data is transmitted by your internet browser to us or our web host / IT service provider and stored in log data (so-called server log files). This stored data includes, for example, the name of the page accessed, the date and time of access, the IP address, the amount of data transferred and the requesting provider.
The processing is carried out on the basis of Article 6(1)(f) GDPR due to our overriding legitimate interest in ensuring the smooth operation of our website and improving our services.
Your data may also be transferred to Canada. An adequacy decision of the European Commission exists for data transfers to Canada.
Contact
Data Controller
You may contact us at any time.
The controller responsible for data processing is:
Kevin Maiwald
Sperberstraße 7
84051 Essenbach
Germany
Phone: +49 15168164837
Email: maiwald1kevin@gmail.com
Customer-Initiated Contact by Email
If you contact us by email on your own initiative, we collect your personal data (name, email address, message text) only to the extent provided by you. The data processing serves the purpose of handling and responding to your inquiry.
If the contact serves the implementation of pre-contractual measures (e.g. consultation in the event of purchase interest, preparation of an offer) or concerns a contract already concluded between you and us, this data processing is carried out on the basis of Article 6(1)(b) GDPR.
If the contact is made for other reasons, this data processing is carried out on the basis of Article 6(1)(f) GDPR due to our overriding legitimate interest in processing and responding to your inquiry.
In this case, you have the right, for reasons arising from your particular situation, to object at any time to the processing of your personal data based on Article 6(1)(f) GDPR.
We use your email address solely for processing your inquiry. Your data will subsequently be deleted in compliance with statutory retention periods unless you have consented to further processing and use.
Collection and Processing When Using the Contact Form
When using the contact form, we collect your personal data (name, email address, message text) only to the extent provided by you. The data processing serves the purpose of establishing contact.
If the contact serves the implementation of pre-contractual measures (e.g. consultation in the event of purchase interest, preparation of an offer) or concerns a contract already concluded between you and us, this data processing is carried out on the basis of Article 6(1)(b) GDPR.
If the contact is made for other reasons, this data processing is carried out on the basis of Article 6(1)(f) GDPR due to our overriding legitimate interest in processing and responding to your inquiry.
In this case, you have the right, for reasons arising from your particular situation, to object at any time to the processing of your personal data based on Article 6(1)(f) GDPR.
We use your email address solely for processing your inquiry. Your data will subsequently be deleted in compliance with statutory retention periods unless you have consented to further processing and use.
Customer Account
When opening a customer account, we collect your personal data to the extent specified therein. The data processing serves the purpose of improving your shopping experience and simplifying order processing.
The processing is carried out on the basis of Article 6(1)(a) GDPR with your consent.
You may revoke your consent at any time by notifying us, without affecting the lawfulness of the processing carried out on the basis of the consent until the revocation.
Your customer account will then be deleted.
Collection, Processing and Transfer of Personal Data for Orders
When placing an order, we collect and process your personal data only insofar as this is necessary for the fulfilment and processing of your order and for handling your inquiries.
The provision of the data is necessary for the conclusion of the contract. Failure to provide the data means that no contract can be concluded.
The processing is carried out on the basis of Article 6(1)(b) GDPR and is necessary for the performance of a contract with you.
Your data may be passed on, for example, to the shipping companies and dropshipping providers selected by you, payment service providers, service providers for order processing and IT service providers.
In all cases, we strictly observe the legal requirements. The scope of the data transfer is limited to the minimum necessary.
Your data may also be transferred to Canada. An adequacy decision of the European Commission exists for data transfers to Canada.
Reviews and Advertising
Data Collection When Submitting a Comment or Review
When submitting a comment or review on an item or post, we collect your personal data (name, email address, comment text) only to the extent provided by you. The processing serves the purpose of enabling comments/reviews and displaying comments/reviews.
For the purpose of verifying your review, we also collect the following data:
-
Order number
-
Invoice number
By submitting the comment/review, you consent to the processing of the transmitted data. Processing is carried out on the basis of Article 6(1)(a) GDPR with your consent.
You may revoke your consent at any time by notifying us, without affecting the lawfulness of the processing carried out on the basis of the consent until revocation.
Your personal data will then be deleted.
Upon publication of your comment, the name you provided and the email address you provided will be published.
Use of Personal Data for Postal Advertising
We use your personal data (name and address), which we have received in connection with the sale of a product or service, to send you postal advertising, provided that you have not objected to such use.
The provision of this data is necessary for the conclusion of the contract. Failure to provide the data means that no contract can be concluded.
Processing is carried out on the basis of Article 6(1)(f) GDPR due to our overriding legitimate interest in direct marketing.
You may object to the use of your address data at any time by notifying us. The contact details for exercising your right of objection can be found in the Legal Notice (Imprint).
Use of the Email Address for Sending Newsletters
We use your email address, independently of contract processing, exclusively for our own advertising purposes in connection with newsletter distribution, provided that you have expressly consented to this.
Processing is carried out on the basis of Article 6(1)(a) GDPR with your consent.
You may revoke your consent at any time without affecting the lawfulness of the processing carried out on the basis of the consent until revocation.
You can unsubscribe from the newsletter at any time by using the corresponding link in the newsletter or by notifying us.
Your email address will then be removed from the mailing list.
Use of the Email Address for Direct Advertising
We use your email address, which we received in connection with the sale of a product or service, for the electronic transmission of advertising for our own products or services that are similar to those you have already purchased from us, unless you have objected to such use.
The provision of the email address is necessary for the conclusion of the contract. Failure to provide the email address means that no contract can be concluded.
Processing is carried out on the basis of Article 6(1)(f) GDPR due to our overriding legitimate interest in direct marketing.
You may object to the use of your email address at any time by notifying us.
The contact details for exercising your right of objection can be found in the Legal Notice (Imprint).
You may also use the designated unsubscribe link contained in the advertising email. No costs other than the transmission costs according to the basic rates will be incurred.
Shipping Service Providers
Transfer of Email Address to Shipping Companies for Shipment Status Information
We transfer your email address to the transport company as part of the contract processing, provided that you have expressly consented to this during the ordering process.
The transfer serves the purpose of informing you about the shipping status by email.
Processing is carried out on the basis of Article 6(1)(a) GDPR with your consent.
You may revoke your consent at any time by notifying us or the transport company, without affecting the lawfulness of the processing carried out on the basis of the consent until revocation.
Payment Service Providers and Credit Checks
Use of PayPal
We use the payment service PayPal provided by PayPal (Europe) S.à r.l. et Cie, S.C.A. (22-24 Boulevard Royal, L-2449 Luxembourg; "PayPal") on our website.
The purpose of data processing is to offer you payment via the payment service provider.
By selecting and using PayPal as a payment method, the data required for payment processing is transmitted to PayPal in order to fulfill the contract with you using the selected payment method.
This processing is carried out on the basis of Article 6(1)(b) GDPR.
All PayPal transactions are subject to the PayPal Privacy Policy, which can be found at:
https://www.paypal.com/privacy
Use of PayPal Plus
We use the PayPal Plus payment service of PayPal (Europe) S.à r.l. et Cie, S.C.A.
When selecting payment via PayPal, credit card via PayPal, or direct debit via PayPal, the data required for payment processing is transmitted to PayPal.
This processing is carried out on the basis of Article 6(1)(b) GDPR.
Credit Check by PayPal
For certain payment methods such as credit card via PayPal or direct debit via PayPal, PayPal reserves the right to obtain credit information based on mathematical-statistical procedures using credit agencies.
For this purpose, PayPal transmits the personal data required for a credit check to a credit agency and uses the information received regarding the statistical probability of a payment default for a balanced decision concerning the establishment, execution, or termination of the contractual relationship.
The credit report may contain probability values (score values) calculated on the basis of scientifically recognized mathematical-statistical procedures, including address data.
Processing is carried out on the basis of Article 6(1)(f) GDPR due to our legitimate interest in protection against payment defaults when PayPal provides services in advance.
You have the right to object to this processing at any time for reasons arising from your particular situation by notifying PayPal.
Failure to provide the required data means that the contract cannot be concluded using the selected payment method.
Use of PayPal Express
We use the PayPal Express payment service of PayPal (Europe) S.à r.l. et Cie, S.C.A.
For the integration of this payment service, PayPal collects, stores, and analyzes data when the website is accessed, including:
-
IP address
-
Device type
-
Operating system
-
Browser type
-
Device location
Cookies may also be used to recognize your browser.
Processing is carried out on the basis of Article 6(1)(f) GDPR due to our legitimate interest in offering customer-oriented payment options.
You have the right to object to this processing at any time for reasons arising from your particular situation.
When selecting and using PayPal Express, the data required for payment processing is transmitted to PayPal to fulfill the contract using the selected payment method.
This processing is carried out on the basis of Article 6(1)(b) GDPR.
Further information can be found in PayPal's Privacy Policy.
Use of PayPal Checkout
We use the payment service PayPal Checkout provided by PayPal (Europe) S.à r.l. et Cie, S.C.A.
When selecting payment via PayPal, credit card via PayPal, direct debit via PayPal, or "Pay Later" via PayPal, the data required for payment processing is transmitted to PayPal.
This processing is carried out on the basis of Article 6(1)(b) GDPR.
Credit Card via PayPal, Direct Debit via PayPal and Pay Later
For these payment methods, PayPal may carry out credit checks based on mathematical-statistical procedures using credit agencies.
For this purpose, PayPal transmits personal data required for credit assessment and uses the information obtained to assess the probability of payment default.
Processing is carried out on the basis of Article 6(1)(f) GDPR due to the legitimate interest in preventing payment defaults.
You may object to this processing at any time by notifying PayPal.
Third-Party Providers
When using payment methods provided by third parties, the data required for payment processing is first transmitted to PayPal and may then be forwarded to the respective provider.
Examples include:
-
SOFORT GmbH, Theresienhöhe 12, 80339 Munich, Germany
-
giropay (Paydirekt GmbH, Stephanstraße 14-16, 60313 Frankfurt am Main, Germany)
Processing is carried out on the basis of Article 6(1)(b) GDPR.
Invoice Purchase via PayPal
When paying by invoice, the payment data is first transmitted to PayPal and subsequently forwarded to:
Ratepay GmbH
Franklinstraße 28-29
10587 Berlin
Germany
The transfer is necessary to fulfill the contract using the selected payment method.
Ratepay may conduct credit checks using recognized mathematical-statistical procedures and credit agencies.
Processing is carried out on the basis of Article 6(1)(f) GDPR due to the legitimate interest in protection against payment defaults.
Further information regarding Ratepay's privacy practices and credit agencies can be found on Ratepay's official websites.
Further information regarding PayPal's data processing can be found in PayPal's Privacy Policy.
Use of Klarna Payment Options
We use the payment service provided by Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden ("Klarna").
When selecting and using payment via Klarna, the data required for payment processing is transmitted to Klarna in order to fulfill the contract with you using the selected payment method.
This processing is carried out on the basis of Article 6(1)(b) GDPR.
Pay Later, Pay Now and Financing
For payment methods such as "Pay Later" (invoice), "Pay Now" (direct debit), and "Financing" (installment purchase), Klarna reserves the right to obtain credit information based on mathematical-statistical procedures using credit agencies.
For this purpose, Klarna transmits personal data required for credit assessment, such as:
-
First and last name
-
Address
-
Gender
-
Email address
-
IP address
-
Order-related information
Klarna uses the information received regarding the statistical probability of a payment default for a balanced decision concerning the establishment, execution, or termination of the contractual relationship.
The credit report may contain probability values (score values) calculated using scientifically recognized mathematical-statistical procedures and may include address data.
Processing is carried out on the basis of Article 6(1)(f) GDPR due to the legitimate interest in protection against payment defaults when Klarna provides services in advance.
You have the right to object to this processing at any time for reasons arising from your particular situation by notifying Klarna.
Failure to provide the required data means that the contract cannot be concluded using the selected payment method.
Further information regarding the credit agencies used by Klarna can be found on Klarna's official websites for Germany and Austria.
Your personal data will be processed by Klarna in accordance with applicable data protection regulations and Klarna's privacy policies.
Use of SOFORT
We use the payment service provider SOFORT GmbH, Theresienhöhe 12, 80339 Munich, Germany ("SOFORT").
SOFORT GmbH is part of the Klarna Group (Klarna Bank AB (publ), Sveavägen 46, 11134 Stockholm, Sweden).
The purpose of data processing is to offer various payment methods through the SOFORT payment service.
If you choose this payment option, the data required for payment processing is transmitted to SOFORT.
Processing is carried out on the basis of Article 6(1)(b) GDPR.
Further information regarding SOFORT's data processing practices can be found in SOFORT's and Klarna's privacy policies.
Use of Stripe
We use the payment service Stripe provided by Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland.
When selecting and using Stripe, the data required for payment processing is transmitted to Stripe in order to fulfill the contract with you using the selected payment method.
This processing is carried out on the basis of Article 6(1)(b) GDPR.
Stripe may carry out credit checks based on mathematical-statistical procedures using credit agencies.
For this purpose, Stripe may transmit personal data required for credit assessment to credit agencies and use the information obtained regarding the statistical probability of a payment default.
The credit report may contain score values calculated on the basis of scientifically recognized mathematical-statistical procedures.
Processing is carried out on the basis of Article 6(1)(f) GDPR due to the legitimate interest in protection against payment defaults when Stripe provides services in advance.
You have the right to object to this processing at any time for reasons arising from your particular situation by notifying Stripe.
Failure to provide the required data means that the contract cannot be concluded using the selected payment method.
All Stripe transactions are subject to Stripe's Privacy Policy.
Use of Mollie
We use the payment service provider Mollie B.V., Keizersgracht 313, 1016 EE Amsterdam, Netherlands ("Mollie").
The purpose of data processing is to provide various payment methods through the Mollie payment platform.
If you choose one of Mollie's payment options, the data required for payment processing is transmitted to Mollie.
This includes, among other things:
-
Payment information (e.g. bank account number or credit card number)
-
IP address
-
Internet browser information
-
Device type
-
First and last name (where applicable)
-
Address information
-
Information regarding products or services purchased
Processing is carried out on the basis of Article 6(1)(b) GDPR.
Further information regarding Mollie's data processing practices can be found in Mollie's Privacy Policy.
Cookies
Our website uses cookies.
Cookies are small text files that are stored in the internet browser or by the internet browser on the user's computer system.
When a user accesses a website, a cookie may be stored on the user's operating system. This cookie contains a characteristic string that enables the browser to be uniquely identified when the website is accessed again.
Cookies are stored on your computer. Therefore, you have full control over the use of cookies.
By selecting the appropriate technical settings in your internet browser, you can:
-
Be notified before cookies are set
-
Decide individually whether to accept cookies
-
Prevent the storage of cookies
-
Prevent the transmission of data contained in cookies
Stored cookies can be deleted at any time.
Please note, however, that if cookies are disabled, you may not be able to use all functions of this website to their full extent.
Information on how to manage or disable cookies in common browsers can be found via the respective browser support pages.
Technically Necessary Cookies
Unless otherwise stated in this Privacy Policy, we use only technically necessary cookies for the purpose of making our website more user-friendly, effective, and secure.
Furthermore, cookies enable our systems to recognize your browser even after a page change and to offer you services.
Some functions of our website cannot be provided without the use of cookies. For these functions, it is necessary that the browser can be recognized even after a page change.
The use of cookies or comparable technologies is based on Section 25(2) TTDSG.
The processing of your personal data is carried out on the basis of Article 6(1)(f) GDPR due to our overriding legitimate interest in ensuring the optimal functionality of the website as well as a user-friendly and effective design of our services.
You have the right, for reasons arising from your particular situation, to object at any time to this processing of your personal data.
Data Subject Rights and Storage Period
Storage Duration
After complete contract processing, the data is initially stored for the duration of the statutory warranty period and thereafter in accordance with statutory retention periods, in particular under tax and commercial law.
The data will then be deleted after the expiration of these periods unless you have consented to further processing and use.
Rights of the Data Subject
If the legal requirements are met, you are entitled to the following rights pursuant to Articles 15 to 20 GDPR:
-
Right of access
-
Right to rectification
-
Right to erasure
-
Right to restriction of processing
-
Right to data portability
In addition, pursuant to Article 21(1) GDPR, you have the right to object to processing based on Article 6(1)(f) GDPR as well as to processing for direct marketing purposes.
Right to Lodge a Complaint with a Supervisory Authority
Pursuant to Article 77 GDPR, you have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data is not lawful.
You may lodge a complaint with, among others, the supervisory authority responsible for us:
Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18
91522 Ansbach
Germany
Phone: +49 981 1800930
Fax: +49 981 180093800
Email: poststelle@lda.bayern.de
Right to Object
If the personal data processing listed here is based on our legitimate interest pursuant to Article 6(1)(f) GDPR, you have the right to object to this processing at any time with future effect for reasons arising from your particular situation.
Once an objection has been made, processing of the affected data will cease unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or unless the processing serves the establishment, exercise, or defense of legal claims.
If personal data is processed for direct marketing purposes, you may object to this processing at any time by notifying us.
After an objection has been made, we will cease processing the affected data for direct marketing purposes.
Last updated: 29 November 2022