Privacy Policy

Privacy Policy

Unless otherwise stated below, the provision of your personal data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide the data. Failure to provide it has no consequences. This only applies if no other information is provided in the following processing operations.
"Personal data" means any information relating to an identified or identifiable natural person.


Server Log Files
You can visit our website without providing any personal information. 
Every time you access our website, usage data is transmitted to us or our web host / IT service provider by your Internet browser and stored in log data (so-called server log files). This stored data includes, for example, the name of the page accessed, the date and time of access, the IP address, the amount of data transferred and the requesting provider.
The processing is carried out on the basis of Art. 6 para. 1 lit. f GDPR out of our overriding legitimate interest in ensuring the trouble-free operation of our website and improving our offer. 

 
Your data may be transferred to third countries outside the EU, in particular to Canada and the USA, and processed there. The EU Commission has issued an adequacy decision for Canada. For the USA, there is an adequacy decision by the EU Commission, the Trans-Atlantic Data Privacy Framework (TADPF). Shopify is not certified under the TADPF. This data transfer takes place on the basis of contractual obligations that are comparable to those of the EU Commission's standard contractual clauses.

Contact

Person responsible
Please contact us if you wish. The person responsible for data processing is Kevin Ramezan Shirazi, Nikolaj Waruschkin, Arsterdamm 94B, 28277  Bremen Germany, +491733973160, info@everstack.de Proactive contact by the customer by e-mail
If you contact us by e-mail on your own initiative, we will only collect your personal data (name, e-mail address, message text) to the extent provided by you. The purpose of data processing is to process and respond to your contact request.
If the purpose of the contact is to carry out pre-contractual measures (e.g. advice in the event of an interest in purchasing, preparation of an offer) or concerns a contract already concluded between you and us, this data processing is carried out on the basis of Art. 6 para. 1 lit. b GDPR.
If contact is made for other reasons, this data processing is carried out on the basis of Art. 6 para. 1 lit. f GDPR due to our overriding legitimate interest in processing and responding to your inquiry. In this case, you have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you based on Art. 6 (1) (f) GDPR.
We will only use your e-mail address to process your request. Your data will then be deleted in compliance with statutory retention periods, unless you have consented to further processing and use.


Collection and processing when using the contact form
When you use the contact form, we collect your personal data (name, e-mail address, message text) only to the extent that you provide. The data processing serves the purpose of establishing contact.

If the contact is made for the purpose of implementing pre-contractual measures (e.g. advice in the event of an interest in purchasing, preparation of an offer) or concerns a contract already concluded between you and us, this data processing is carried out on the basis of Art. 6 para. 1 lit. b GDPR.
If contact is made for other reasons, this data processing is carried out on the basis of Art. 6 para. 1 lit. f GDPR due to our overriding legitimate interest in processing and responding to your request. In this case, you have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on Article 6(1)(f) GDPR.
We will only use your e-mail address to process your request. Your data will then be deleted in compliance with statutory retention periods, unless you have consented to further processing and use.

Use of the address validation of Google Maps API
We use the address validation of the provider Google (Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland "Google") on our website.
The purpose of data processing is to check your entries in our address forms in real time for input and spelling errors and to complete any missing data. In the event of incorrectly entered data, alternative suggestions for correcting the data are displayed. For this purpose, the address data you enter is transmitted to the provider, where it is stored and analyzed.
Among other things, the following information may be transmitted to Google and processed there: postal addresses (country, city, zip code, street, house number), e-mail address, telephone number.
Your data may also be transferred to the USA. The EU Commission has issued an adequacy decision for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). Google has certified itself in accordance with the TADPF and has therefore undertaken to comply with European data protection principles.
The processing of your personal data takes place on the basis of Art. 6 para. 1 lit. f GDPR out of our overriding legitimate interest in a correct data basis for the fulfillment of our contractual obligations. You have the right to object to this processing of your personal data at any time for reasons arising from your particular situation.
The data will be processed separately by the provider and will not be merged with other data. They will be deleted by the provider as soon as the status of the data entered has been determined, but after 30 days at the latest.
You can find more information on Google's terms of use and data protection at: https://cloud.google.com/maps-platform/terms or at https://www.google.de/policies/privacy/.

 
Collection and processing of applications by e-mail 
Site visitors can apply for vacancies advertised on our website by e-mail if they are interested. We only collect your personal data to the extent provided by you. This includes your contact details (e.g. name, e-mail address, telephone number), details of your professional qualifications and training, details of further professional training and performance-related certificates.
The data processing serves the purpose of establishing contact and deciding on the establishment of an employment relationship with you. The provision of the data is necessary in order to carry out the application process. The processing of your personal data takes place on the basis of Art. 6 para. 1 lit. b GDPR in conjunction with. § Section 26 (1) BDSG for the implementation of pre-contractual measures (going through the application process as an employment contract initiation).
If you have given us your consent to the processing of personal data for inclusion in our applicant pool, e.g. by ticking a checkbox, the processing is carried out on the basis of Art. 6 para. 1 lit. a GDPR. You can withdraw your consent to us at any time without affecting the lawfulness of processing based on consent before its withdrawal.
If special categories of personal data within the meaning of Art. 9 para. 1 GDPR are requested from applicants as part of the application process, such as information on the degree of severe disability, this is done on the basis of Art. 9 para. 2 lit. b. GDPR. GDPR, so that we can exercise the rights arising from labor law and social security and social protection law and fulfill our obligations in this regard.
We store your personal data for as long as is necessary to make a decision about your application. Your data will then be deleted after six months at the latest, unless you have consented to further processing and use. If an employment relationship is established following the application process, the data provided will be further processed on the basis of Art. 6 para. 1 lit. b GDPR in conjunction with Section 26 para. 1 BDSG for the purposes of implementing the employment relationship and then transferred to the personnel file.
 
WhatsApp Business
If you contact us via WhatsApp, we use the WhatsApp Business version of WhatsApp Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; "WhatsApp"). If you are located outside the European Economic Area, this service is provided by WhatsApp Inc. (1601 Willow Road, Menlo Park, CA 94025, USA).
The purpose of data processing is to process and respond to your contact request. For this purpose, we collect and process your mobile phone number stored with WhatsApp, your name if provided and other data to the extent provided by you. We use a mobile device for the service, the address book of which only contains data from users who have contacted us via WhatsApp. Personal data will not be passed on to WhatsApp without your prior consent.
Your data will be transmitted by WhatsApp to servers of Meta Platforms Inc. in the USA. The EU Commission has issued an adequacy decision for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). Meta Platforms Inc. has certified itself in accordance with the TADPF and has therefore undertaken to comply with European data protection principles. If the contact serves the implementation of pre-contractual measures (e.g. advice on purchase interest, preparation of an offer) or concerns a contract already concluded between you and us, this data processing is carried out on the basis of Art. 6 para. 1 lit. b GDPR.

If contact is made for other reasons, this data processing is carried out on the basis of Art. 6 para. 1 lit. f GDPR out of our overriding legitimate interest in providing a quick and easy way to contact you and in answering your inquiry. In this case, you have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you based on Art. 6 (1) (f) GDPR.
We only use your personal data to process your request. Your data will then be deleted in compliance with statutory retention periods, unless you have consented to further processing and use.
You can find more information on terms of use and data protection when using WhatsApp at https://www.whatsapp.com/legal/#terms-of-service and https://www.whatsapp.com/legal/#privacy-policy.


Customer account Orders      

Customer account
When you open a customer account, we collect your personal data to the extent specified there. The purpose of data processing is to improve your shopping experience and simplify order processing. The processing is carried out on the basis of Art. 6 para. 1 lit. a GDPR with your consent. You can revoke your consent at any time by notifying us without affecting the legality of the processing carried out on the basis of the consent until revocation. Your customer account will then be deleted.


Collection, processing and disclosure of personal data for orders
When you place an order, we collect and process your personal data only to the extent necessary to fulfill and process your order and to handle your inquiries. The provision of data is necessary for the conclusion of the contract. Failure to provide it will result in no contract being able to be concluded. Processing is carried out on the basis of Art. 6 Para. 1 lit. b GDPR and is necessary for the performance of a contract with you. 
Your data will be passed on, for example, to shipping companies, dropshipping or fulfillment providers, payment service providers, service providers for order processing and IT service providers. In all cases, we strictly observe the legal requirements. The scope of data transfer is kept to a minimum.
 
Your data may be transferred to third countries outside the EU, in particular to Canada and the USA, and processed there. The EU Commission has issued an adequacy decision for Canada. For the USA, there is an adequacy decision by the EU Commission, the Trans-Atlantic Data Privacy Framework (TADPF). Shopify is not certified under the TADPF. This data transfer takes place on the basis of contractual obligations that are comparable to those of the EU Commission's standard contractual clauses.

Reviews       Advertising      


Data collection when writing a comment or rating
When you comment/rate an article or a contribution, we only collect your personal data (name, e-mail address, comment text) to the extent that you provide. The processing serves the purpose of enabling a comment/rating and displaying comments/ratings. 


We also collect the following data for the purpose of verifying your rating/comment: Order number, Customer number, Invoice number, .

By submitting the comment/review, you consent to the processing of the transmitted data. The processing is carried out on the basis of Art. 6 para. 1 lit. a GDPR with your consent. You can revoke your consent at any time by notifying us without affecting the legality of the processing carried out on the basis of the consent until revocation. Your personal data will then be deleted.

When your comment/rating is published the name you have provided and the e-mail address you have provided published.

Use of the e-mail address for sending newsletters
We use your e-mail address to send you information and offers by newsletter, provided you have expressly consented to this. The data processing serves the sole purpose of advertising. For this purpose, we process your e-mail address and any other data that you have voluntarily provided when registering for our newsletter.
The processing is carried out on the basis of Art. 6 para. 1 lit. a GDPR with your consent. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
You can unsubscribe from the newsletter at any time by using the corresponding link in the newsletter or by notifying us. Your e-mail address will then be removed from the mailing list. Despite removal from the mailing list, we may continue to store your e-mail address in a so-called blacklist to prevent you from receiving future newsletter e-mails from us. This storage takes place on the basis of Art. 6 para. 1 lit. f GDPR out of our and your legitimate interest in preventing the reuse of your e-mail address for sending our newsletter. You have the right to object to this processing of your personal data at any time for reasons arising from your particular situation.


Use of the e-mail address for sending direct advertising
We use your e-mail address, which we have received as part of the sale of goods or services, to send you electronic advertising for our own goods or services that are similar to those that you have already purchased from us, unless you have objected to this use. The provision of the e-mail address is necessary for the conclusion of the contract. Failure to provide it means that no contract can be concluded. The processing is carried out on the basis of Art. 6 para. 1 lit. f GDPR out of our overriding legitimate interest in direct advertising. You can object to this use of your e-mail address at any time by notifying us. You can find the contact details for exercising your objection in the legal notice. You can also use the link provided for this purpose in the advertising email. This will not incur any costs other than the transmission costs according to the basic rates.


Use of Klaviyo
We use the service of Klaviyo Inc. (125 Summer St Floor 7, Boston, MA 02111, USA; "Klaviyo") to send newsletters as part of order processing.
We pass on the information you provide during the newsletter registration process (e-mail address, first and last name if applicable) to Klaviyo. The data processing serves the purpose of sending the newsletter and its statistical evaluation.
In order to evaluate newsletter campaigns, the newsletters sent contain a 1x1 pixel graphic (tracking pixel) or a tracking link. This enables us to determine whether you have opened the newsletter and whether you have clicked on any integrated links. In this context, we collect your personal data such as IP address, browser type and device as well as the time. This data can be used to create user profiles under a pseudonym. The data collected will not be used to identify you personally. The data collected is only used for statistical analysis to improve newsletter campaigns.
Your data is generally transmitted to Klaviyo servers in the USA and stored there. An adequacy decision by the EU Commission is in place for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). Klaviyo has certified itself in accordance with the TADPF and is therefore committed to complying with European data protection principles.
Your personal data is processed on the basis of Art. 6 para. 1 lit. f GDPR due to our overriding legitimate interest in a targeted, effective advertising and user-friendly newsletter system. You have the right to object to this processing of your personal data at any time on grounds relating to your particular situation.

You can find more information on data protection at Klaviyo at https://www.klaviyo.com/legal/privacy-notice and at https://www.klaviyo.com/legal/data-processing-agreement

Use of the e-mail address for availability notifications
We offer the service of product availability notification on our website. If an item is temporarily unavailable, you have the option of entering your e-mail address on the respective item and being informed by us by e-mail when it becomes available, provided you have agreed to this. You will receive a one-time notification by e-mail about the availability of the respective item. The processing is carried out on the basis of Art. 6 para. 1 lit. a GDPR with your consent. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal. You can unsubscribe from the availability notification at any time by notifying us. Your e-mail address will then be removed from the mailing list.

 
Shipping service provider      

Forwarding the e-mail address to shipping companies for information about the shipping status
We will pass on your e-mail address to the shipping company as part of the contract processing if you have expressly consented to this during the ordering process. The purpose of this disclosure is to inform you by e-mail about the shipping status. The processing is carried out on the basis of Art. 6 para. 1 lit. a GDPR with your consent. You can withdraw your consent at any time by notifying us or the transport company without affecting the lawfulness of processing based on consent before its withdrawal.


Payment service provider      

Use of PayPal
We use the PayPal payment service of PayPal (Europe) S.à.r.l. et Cie, S.C.A. (22-24 Boulevard Royal L-2449, Luxembourg; "PayPal") on our website. The purpose of data processing is to be able to offer you payment via the payment service. By selecting and using payment via PayPal, the data required for payment processing will be transmitted to PayPal in order to fulfill the contract with you using the selected payment method. This processing is carried out on the basis of Art. 6 para. 1 lit. b GDPR.

All PayPal transactions are subject to the PayPal privacy policy. You can find this at https://www.paypal.com/de/webapps/mpp/ua/privacy-full


Use of PayPal Express
We use the PayPal Express payment service of PayPal (Europe) S.à.r.l. et Cie, S.C.A. (22-24 Boulevard Royal L-2449, Luxembourg; "PayPal") on our website. The purpose of data processing is to be able to offer you payment via the PayPal Express payment service.
To integrate this payment service, it is necessary for PayPal to collect, store and analyze data (e.g. IP address, device type, operating system, browser type, location of your device) when you access the website. Cookies may also be used for this purpose. Cookies make it possible to recognize your browser.
The use of cookies or comparable technologies takes place with your consent on the basis of Section 25 (1) sentence 1 TDDDG
  i.V.m. Art. 6 para. 1 lit. a GDPR. Your personal data is processed with your consent on the basis of Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
By selecting and using PayPal Express, the data required for payment processing will be transmitted to PayPal in order to fulfill the contract with you with the selected payment method. This processing is carried out on the basis of Art. 6 para. 1 lit. b GDPR.
Further information on data processing when using the PayPal Express payment service can be found in the associated privacy policy at https://www.paypal.com/de/webapps/mpp/ua/privacy-full?locale.x=de_DE#Updated_PS


Use of PayPal Check-Out
We use the PayPal Check-Out payment service from PayPal (Europe) S.à.r.l. et Cie, S.C.A. (22-24 Boulevard Royal L-2449, Luxembourg; "PayPal") on our website. The purpose of data processing is to be able to offer you payment via the payment service. By selecting and using payment via PayPal, credit card via PayPal, direct debit via PayPal or "Pay later" via PayPal, the data required for payment processing will be transmitted to PayPal in order to fulfill the contract with you with the selected payment method. This processing is carried out on the basis of Art. 6 para. 1 lit. b GDPR.

Cookies may be stored that enable your browser to be recognized. The resulting data processing takes place on the basis of Art. 6 para. 1 lit. f GDPR from our overriding legitimate interest in a customer-oriented offer of different payment methods. You have the right to object to this processing of your personal data at any time on grounds relating to your particular situation.

Credit card via PayPal, direct debit via PayPal & "Pay later" via PayPal
For individual payment methods such as credit card via PayPal, direct debit via PayPal or "Pay later" via PayPal, PayPal reserves the right to obtain credit information on the basis of mathematical-statistical procedures using credit agencies. For this purpose, PayPal transmits the personal data required for a credit check to a credit agency and uses the information received on the statistical probability of a payment default for a balanced decision on the establishment, execution or termination of the contractual relationship. The credit report may contain probability values (score values) that are calculated on the basis of scientifically recognized mathematical-statistical procedures and whose calculation includes address data, among other things. Your legitimate interests are taken into account in accordance with the statutory provisions. The data processing serves the purpose of credit assessment for the initiation of a contract. The processing is carried out on the basis of Art. 6 para. 1 lit. f GDPR out of our overriding legitimate interest in protection against payment default if PayPal makes advance payments.
You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you based on Article 6(1)(f) GDPR by notifying PayPal. The provision of the data is necessary for the conclusion of the contract with the payment method you have requested. Failure to provide the data means that the contract cannot be concluded with the payment method you have selected.

Third-party providers
When paying via the payment method of a third-party provider, the data required for payment processing is transmitted to PayPal. This processing takes place on the basis of Art. 6 para. 1 lit. b GDPR. To process this payment method, the data may then be forwarded by PayPal to the respective provider. This processing is carried out on the basis of Art. 6 para. 1 lit. b GDPR. Local third-party providers may be, for example

  • Apple Pay (Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland)
  • Google Pay (Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland)

Purchase on account via PayPal
When paying via the payment method purchase on account, the data required for payment processing is first transmitted to PayPal. In order to process this payment method, the data is then transmitted by PayPal to Ratepay GmbH (Franklinstraße 28-29, 10587 Berlin; "Ratepay") in order to fulfill the contract with you with the selected payment method. This processing is carried out on the basis of Art. 6 para. 1 lit. b GDPR. Ratepay may carry out a credit check on the basis of mathematical-statistical procedures (probability or score values) using credit agencies in accordance with the procedure described above. The data processing serves the purpose of credit assessment for the initiation of a contract. The processing is carried out on the basis of Art. 6 para. 1 lit. f GDPR out of our overriding legitimate interest in protection against payment default if Ratepay makes advance payments. Further information on data protection and which credit agencies Ratpay uses can be found at https://www.ratepay.com/legal-payment-dataprivacy/ and https://www.ratepay.com/legal-payment-creditagencies/.

Further information on data processing when using PayPal can be found in the associated privacy policy at https://www.paypal.com/de/webapps/mpp/ua/privacy-full.


Use of the payment service provider Stripe
We use the payment service Stripe on our website, provided by Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. The data processing serves the purpose of offering you payment via the payment service. By selecting and using Stripe, the data required for payment processing is transmitted to Stripe in order to fulfill the contract with you using the selected payment method. This processing is based on Art. 6 Para. 1 lit. b GDPR. 
Stripe reserves the right to obtain a credit report based on mathematical-statistical methods, using credit agencies if necessary. For this purpose, Stripe transmits the personal data required for a credit check to a credit agency and uses the information received about the statistical probability of payment default for a balanced decision on the establishment, implementation, or termination of the contractual relationship. The credit report may include probability values (score values) that are calculated on the basis of scientifically recognized mathematical-statistical methods and include address data, among other things, in their calculation. Your legitimate interests are taken into account in accordance with the legal provisions. The data processing serves the purpose of the credit check for the initiation of a contract. The processing is based on Art. 6 Para. 1 lit. f GDPR due to our overriding legitimate interest in protection against payment default if Stripe makes advance payments. 
You have the right to object, at any time, to this processing of your personal data based on Art. 6 Para. 1 lit. f GDPR by notifying Stripe, for reasons arising from your particular situation. The provision of data is required for the conclusion of the contract with your desired payment method. Failure to provide data will result in the contract not being able to be concluded with your chosen payment method.
All Stripe transactions are subject to the Stripe Privacy Policy. You can find these at https://stripe.com/de/privacy 
 

cookies

Our website uses cookies. Cookies are small text files that are stored in the Internet browser or by the Internet browser on the user's computer system. When a user accesses a website, a cookie may be stored on the user's operating system. This cookie contains a characteristic string of characters that enables the browser to be uniquely identified when the website is called up again.
 
Cookies are stored on your computer. Therefore, you have full control over the use of cookies. By selecting the appropriate technical settings in your internet browser, you can be notified before cookies are set and decide individually whether to accept them, as well as prevent the storage of cookies and the transmission of the data they contain. Cookies that have already been saved can be deleted at any time. However, we would like to point out that you may then not be able to use all the functions of this website to their full extent.
 
You can find out how to manage (including deactivating) cookies for the most important browsers under the following links:
 
Technically necessary cookies
Unless otherwise stated in the privacy policy below, we only use these technically necessary cookies for the purpose of making our website more user-friendly, effective and secure. Furthermore, cookies enable our systems to recognize your browser even after a page change and to offer you services. Some functions of our website cannot be offered without the use of cookies. For these, it is necessary that the browser is recognized even after a page change.
 
The use of cookies or comparable technologies is based on Section 25 (2) TDDDG. Your personal data is processed on the basis of Art. 6 para. 1 lit. f GDPR due to our overriding legitimate interest in ensuring the optimal functionality of the website and a user-friendly and effective design of our offer.
You have the right to object, at any time, to this processing of your personal data for reasons arising from your particular situation.
 

Advertising tracking analysis      


Use of Google Analytics 4
We use the web analysis service Google Analytics from Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; "Google") on our website.
The data processing serves the purpose of analyzing this website and its visitors as well as for marketing and advertising purposes. For this purpose, Google will use the information obtained on behalf of the operator of this website to evaluate your use of the website, to compile reports on website activity and to provide the website operator with other services relating to website activity and internet usage. 
The following information may be collected in the process: IP address, date and time of the page view, click path, information about the browser you are using and the device you are using, pages visited, referrer URL (website from which you accessed our website), location data, purchase activities. Your data may be linked by Google with other data, such as your search history, your personal accounts, your usage data from other devices and all other data that Google has about you.

Your IP address will first be shortened by us on our own servers. Google thus only receives pseudonymized data.

Google uses technologies such as cookies, web storage in the browser and tracking pixels that enable your use of the website to be analyzed. The use of cookies or comparable technologies takes place with your consent on the basis of § 25 para. 1 sentence 1 TDDDG i.V.m. Art. 6 para. 1 lit. a GDPR. 

Your personal data is processed with your consent on the basis of Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

We use the extended implementation of the consent mode (Advanced Consent Mode). In this case, user data is transmitted to Google in the form of "pings" even if consent has not been granted. These pings may contain the following information, among others IP address to derive the IP country (no logging of the IP address takes place), date and time of the page view, URL of the pages visited, user agent, referrer URL (website from which our website was accessed) or information about the triggering of website events such as a conversion. On the basis of this information, Google models user data in order to be able to carry out a comprehensive usage analysis despite the refusal of consent.

The information generated about your use of this website is usually transferred to a Google server in the USA and stored there. An adequacy decision of the EU Commission is in place for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). Google has certified itself in accordance with the TADPF and has therefore undertaken to comply with European data protection principles. Both Google and US government authorities have access to your data.

Further information on terms of use and data protection can be found at https://policies.google.com/technologies/partner-sites and under https://policies.google.com/privacy?hl=de&gl=de.

Use of HeatMap 
We use the analysis tool from HeatMap Inc. (6724 Monroe Ave, Eldersburg, Maryland 21784, USA, “HeatMap”) on our website as part of commissioned processing. The data processing serves the purpose of the needs-based design, optimization and analysis of our website. 
The tool records the movements of website visitors on the website. This creates a log of mouse movements, scrolling behavior, dwell time and clicks on the website (so-called heatmap). For this purpose, HeatMap uses cookies, among other things. The following information may be collected, among other things: Information about the device you are using (screen size, devices, unique device identifier), information about the browser you are using, location data (exclusively to the country). User profiles can be created from this data under a pseudonym. The data is not used to personally identify the visitor to the website and is not merged with personal data of the bearer of the pseudonym. 
Your data may be transferred to third countries, such as the USA. An adequacy decision by the EU Commission exists for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). Heatmap is not certified according to the TADPF.
The use of cookies or comparable technologies takes place with your consent on the basis of § 25 para. 1 sentence 1 TDDDG i.V.m. Art. 6 para. 1 lit. a GDPR. The processing of your personal data is carried out with your consent on the basis of Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal. 
Further information on the collection and use of your data by HeatMap can be found at: https://heatmap.com/privacy.
 
Use of Shopify statistics
We use the statistics and analysis functions of Shopify International Ltd. on our website (Victoria Buildings, 
2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland; "Shopify") in the context of order processing. Shopify is a company affiliated with Shopify Inc (151 O'Connor Street, Ground Floor, Ottawa, Ontario, K2P 2L8, Canada).
The purpose of data processing is to analyze this website and its visitors. For this purpose, data is stored for marketing and optimization purposes and provided in reports, analyses and statistics. Among other things, the following device information is collected and processed: Web browser information, IP address, time zone and some of the cookies installed on your device. When you navigate the website, information is also collected about the web pages or products you have accessed, the referrer URL (the website from which you accessed our website) and information about how you interact with the website. Technologies such as cookies, web beacons, tags and pixels (electronic files used to collect information about how you navigate the website) are used for this purpose.

Your data may be transferred to third countries outside the EU, in particular to Canada and the USA, and processed there. The EU Commission has issued an adequacy decision for Canada. For the USA, there is an adequacy decision by the EU Commission, the Trans-Atlantic Data Privacy Framework (TADPF). Shopify is not certified under the TADPF. This data transfer takes place on the basis of contractual obligations that are comparable to those of the EU Commission's standard contractual clauses.
The use of cookies or comparable technologies takes place with your consent on the basis of § 25 para. 1 sentence 1 TDDDG i.V.m. Art. 6 para. 1 lit. a GDPR. The processing of your personal data is carried out with your consent on the basis of Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
You can find more information on data protection at Shopify at https://www.shopify.com/de/legal/datenschutz, information on the order processing contract at https://www.shopify.com/de/legal/dpa and information on the cookies used at https://www.shopify.com/de/legal/cookies.


Use of the Meta Pixel
We use the Meta Pixel from Meta Platforms Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; "Meta") on our website.
Meta and we are jointly responsible for the collection of your data and the transmission of this data to Meta when the service is integrated. The basis for this is an agreement between us and Meta on the joint processing of personal data, in which the respective responsibilities are defined. The agreement is available at https://de-de.facebook.com/legal/terms/businesstools. According to this agreement, we are responsible in particular for fulfilling the information obligations pursuant to Art. 13, 14 GDPR, for compliance with the security requirements of Art. 32 GDPR with regard to the correct technical implementation and configuration of the service and for compliance with the obligations pursuant to Art. 33, 34 GDPR, insofar as a breach of the protection of personal data affects our obligations under the joint processing agreement. Meta is responsible for enabling the rights of data subjects pursuant to Art. 15 - 20 GDPR, complying with the security requirements of Art. 32 GDPR with regard to the security of the Service and the obligations under Art. 33, 34 GDPR to the extent that a personal data breach affects Meta's obligations under the Joint Processing Agreement.
The purpose of the application is to target visitors to the website with interest-based advertising on the social networks Facebook and Instagram. The Meta remarketing tag has been implemented on the website for this purpose. This tag establishes a direct connection to the Meta servers when you visit the website. This tells the Meta server which of our pages you have visited. Meta assigns this information to your personal Facebook and/or Instagram user account. When you visit the Facebook or Instagram social networks, you will then be shown personalized, interest-based ads.
The application also serves the purpose of creating conversion statistics. This tells us the total number of users who have clicked on one of our ads and been redirected to a page with a conversion tracking tag and what actions are taken after being redirected to this website. However, we do not receive any information with which users can be personally identified.
Your data may be transferred to the USA. An adequacy decision by the EU Commission, the Trans-Atlantic Data Privacy Framework (TADPF), is in place for the USA. Meta has certified itself in accordance with the TADPF and is therefore committed to complying with European data protection principles.
Your personal data is processed with your consent on the basis of Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
You can deactivate the remarketing function "Custom Audiences" here. For more information on the collection and use of data by Meta, your rights in this regard and ways to protect your privacy, please refer to Meta's privacy policy at https://www.facebook.com/about/privacy/.

Verwendung von Google Ads Conversion-Tracking
Wir verwenden auf unserer Website das Online-Werbeprogramm „Google Ads“ und in diesem Rahmen Conversion-Tracking (Besuchsaktionsauswertung). Das Google Conversion Tracking ist ein Analysedienst der Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Irland; Google).
Wenn Sie auf eine von Google geschaltete Anzeige klicken, wird ein Cookie für das Conversion-Tracking auf Ihrem Rechner abgelegt. Diese Cookies haben eine begrenzte Gültigkeit, enthalten keine personenbezogenen Daten und dienen somit nicht der persönlichen Identifizierung. Wenn Sie bestimmte Seiten unserer Website besuchen und das Cookie noch nicht abgelaufen ist, können Google und wir erkennen, dass Sie auf die Anzeige geklickt haben und zu dieser Seite weitergeleitet wurden. Jeder Google Ads-Kunde erhält ein anderes Cookie. Somit besteht keine Möglichkeit, dass Cookies über die Websites von Ads-Kunden nachverfolgt werden können.
Die Informationen, die mit Hilfe des Conversion-Cookie eingeholt werden, dienen dem Zweck Conversion-Statistiken zu erstellen. Hierbei erfahren wir die Gesamtanzahl der Nutzer, die auf eine unserer Anzeigen geklickt haben und zu einer mit einem Conversion-Tracking-Tag versehenen Seite weitergeleitet wurden. Wir erhalten jedoch keine Informationen, mit denen sich Nutzer persönlich identifizieren lassen. 
Wir nutzen die erweiterte Implementierung des Einwilligungsmodus (Advanced Consent Mode). Hierbei werden auch bei nicht erteilter Einwilligung Nutzerdaten an Google in Form von “Pings” übermittelt. Diese Pings können u.a. folgende Informationen enthalten: IP-Adresse zum Ableiten des IP-Landes (eine Protokollierung der IP-Adresse findet nicht statt), Datum und Uhrzeit des Seitenaufrufs, URL der besuchte Seiten, User-Agent, Referrer-URL (Website, über die unsere Website aufgerufen wurde) oder Informationen über das Auslösen von Website-Ereignissen wie z.B. einer Conversion. Auf Grundlage dieser Informationen nimmt Google eine Modellierung von Nutzdaten vor, um eine umfassende Nutzungsanalyse trotz der Verweigerung der Einwilligung vornehmen zu können. 
Ihre Daten werden gegebenenfalls an die Server der Google LLC in die USA übermittelt. Für die USA ist ein Angemessenheitsbeschluss der EU-Kommission vorhanden, das Trans-Atlantic Data Privacy Framework (TADPF). Google hat sich nach dem TADPF zertifiziert und damit verpflichtet, europäische Datenschutzgrundsätze einzuhalten.
The use of cookies or comparable technologies takes place with your consent on the basis of § 25 para. 1 sentence 1 TDDDG i.V.m. Art. 6 para. 1 lit. a GDPR. The processing of your personal data is carried out with your consent on the basis of Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
You can find more information and Google's privacy policy at: https://www.google.de/policies/privacy/

 
Use of Google AdSense
We use the AdSense function of Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; "Google") on our website. The purpose of data processing is to rent out advertising space on the website and to target visitors to the website with interest-based advertising. This function is used to display personalized, interest-based advertisements from the Google Display Network to visitors to the provider's website. Google uses cookies that enable your use of the website to be analyzed. The information generated by the cookie about your use of this website is generally transmitted to a Google server in the USA and stored there. An adequacy decision of the EU Commission is in place for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). Google 
has certified itself in accordance with the TADPF and is therefore committed to complying with European data protection principles. Google may transfer this information to third parties where required to do so by law, or where such third parties process the information on Google's behalf. Google will not associate your IP address with any other data held by Google.
The use of cookies or comparable technologies takes place with your consent on the basis of § 25 para. 1 sentence 1 TDDDG i.V.m. Art. 6 para. 1 lit. a GDPR. The processing of your personal data is carried out with your consent on the basis of Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
You can find more information and Google's privacy policy at: https://www.google.com/policies/technologies/ads/ and https://www.google.de/policies/privacy/


Use of the remarketing or "similar target groups" function of Google Inc.
We use the remarketing or "similar target groups" function of Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; "Google") on our website.
The application serves the purpose of analyzing visitor behavior and visitor interests. Google uses cookies to carry out the analysis of website usage, which forms the basis for the creation of interest-based advertisements. Cookies are used to record visits to the website and anonymized data on the use of the website. No personal data of visitors to the website is stored. If you subsequently visit another website in the Google Display Network, you will be shown advertisements that are highly likely to take into account previously accessed product and information areas.
Your data may be transmitted to servers of Google LLC in the USA. The EU Commission has issued an adequacy decision for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). Google
has certified itself in accordance with the TADPF and has thus undertaken to comply with European data protection principles.
The use of cookies or comparable technologies takes place with your consent on the basis of § 25 para. 1 sentence 1 TDDDG i.V.m. Art. 6 para. 1 lit. a GDPR. The processing of your personal data is carried out with your consent on the basis of Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
You can find more information about Google Remarketing and the associated privacy policy at: https://www.google.com/privacy/ads/

 
Use of the Pinterest tag
We use the Pinterest Tag of Pinterest Europe Limited (Palmerston House, 2nd, Fenian Street, Floor, Dublin 2, Ireland "Pinterest") on our website.
The purpose of the application is to target visitors to the website with interest-based advertising on the Pinterest social network. The Pinterest conversion tag has been implemented on the website for this purpose. This tag is used to establish a direct connection to the Pinterest servers when the website is visited. This tells the Pinterest server which of our pages you have visited. Pinterest assigns this information to your personal Pinterest user account if you are logged into the social network. When you visit Pinterest, you will then be shown personalized, interest-based Pinterest ads.
If you access our website via a pin on the Pinterest social network, a cookie for conversion tracking is stored on your computer. These cookies have a limited validity, do not contain any personal data and are therefore not used for personal identification. If you visit certain pages of our website and the cookie has not yet expired, Pinterest and we can recognize that you have clicked on the pin and have been redirected to this page. The information collected with the help of the conversion cookie is used to create conversion statistics and thus to optimize our website. Among other things, the following information can be processed: Total number of users who clicked on one of our pins and were redirected to our website, subpages visited on our website (e.g. category or product pages), search queries on our website, your shopping cart contents, completed transactions.
Your data may be transferred to the USA. An adequacy decision by the EU Commission is in place for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). Pinterest is not certified under the TADPF. Data is transferred on the basis of standard contractual clauses, among others, as suitable guarantees for the protection of personal data, which can be viewed at: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_de.
The use of cookies or comparable technologies takes place with your consent on the basis of Section 25 (1) sentence 1 TDDDG in conjunction with Art. 6 (1) lit. Art. 6 para. 1 lit. a GDPR. The processing of your personal data is carried out with your consent on the basis of Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
You can find more information on the collection and use of data by Pinterest, your rights in this regard and options for protecting your privacy in Pinterest's privacy policy at https://policy.pinterest.com/de/privacy-policy.

 
Use of TikTok Pixel
We use the TikTok Pixel of TikTok Technology Limited (10 Earlsfort Terrace, Dublin, D02 T380, Ireland; "TikTok Ireland") and TikTok Information Technologies UK Limited (6th Floor, One London Wall, London, EC2Y 5EB, United Kingdom; "TikTok UK") on our website. Both companies are the joint controllers for data processing (hereinafter "TikTok").
The purpose of data processing is to identify and analyze our customers' website access and to better address customers by placing targeted advertisements and evaluating the effectiveness of advertisements on TikTok. For this purpose, TikTok uses technologies such as cookies and pixels that enable your browser to be recognized. The following information may be collected and transmitted to TikTok: Date and time of the visit, information about the browser and device type you are using, screen resolution, IP address. TikTok can assign this information to your personal TikTok user account. The data collected in this way can be used to create user profiles using pseudonyms. However, it is not possible to identify users personally.
Your data may be transferred to third countries, such as the USA. The EU Commission has issued an adequacy decision for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). TikTok is not certified in accordance with the TADPF. The transfer of data to the USA and to third countries without an adequacy decision is based, among other things, on standard contractual clauses as suitable guarantees for the protection of personal data, which can be viewed at: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_de.
The use of cookies or comparable technologies takes place with your consent on the basis of Section 25 (1) sentence 1 TDDDG in conjunction with Art. 6 para. 1 lit. a GDPR. The processing of your personal data is carried out with your consent on the basis of Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
You can find more information on data protection at https://www.tiktok.com/legal/page/eea/privacy-policy/de and https://ads.tiktok.com/i18n/official/policy/controller-to-controller.



Plug-ins and miscellaneous


Use of the Google Tag Manager
We use the Google Tag Manager of Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; "Google") on our website.
This application is used to manage JavaScript tags and HTML tags that are used to implement tracking and analysis tools in particular. The data processing serves the purpose of designing and optimizing our website in line with requirements.
The Google Tag Manager itself neither stores cookies nor does it process personal data. However, it enables the triggering of other tags that can collect and process personal data.
Further information on terms of use and data protection can be found here.

 
Use of Google reCAPTCHA 
We use the reCAPTCHA service of Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; "Google") on our website. The query serves the purpose of differentiating whether the input is made by a human or by automated, machine processing. For this purpose, your input is transmitted to Google and used there. In addition, the IP address and, if applicable, other data required by Google for the reCAPTCHA service are transmitted to Google. This data is processed by Google within the European Union and, if necessary, also transmitted to servers of Google LLC in the USA. There is an adequacy decision by the EU Commission for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). Google has certified itself according to the TADPF and has thus committed itself to complying with European data protection principles.
The use of cookies or comparable technologies takes place with your consent on the basis of § 25 para. 1 sentence 1 TDDDG i.V.m. Art. 6 para. 1 lit. a GDPR. The processing of your personal data is carried out with your consent on the basis of Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
Further information on Google reCAPTCHA and the associated privacy policy can be found at: https://www.google.com/recaptcha/intro/android.html as well as https://www.google.com/privacy.
 
Use of Google invisible reCAPTCHA
We use the invisible reCAPTCHA service of Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; "Google") on our website.
This serves the purpose of distinguishing the input by a human or by automated, machine processing. In the background, Google collects and analyzes usage data that is used by Invisible reCaptcha to distinguish regular users from bots. For this purpose, your input is transmitted to Google and used there. In addition, the IP address and any other data required by Google for the Invisible reCAPTCHA service are transmitted to Google.

This data is processed by Google within the European Union and may also be transmitted to servers of Google LLC in the USA. An adequacy decision by the EU Commission is in place for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). Google has certified itself in accordance with the TADPF and is therefore committed to complying with European data protection principles.
The use of cookies or comparable technologies takes place with your consent on the basis of § 25 para. 1 sentence 1 TDDDG i.V.m. Art. 6 para. 1 lit. a GDPR. The processing of your personal data is carried out with your consent on the basis of Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
Further information on Google reC
APTCHA and the associated privacy policy can be found at: https://www.google.com/recaptcha/intro/android.html and https://www.google.com/privacy

Use of YouTube
We use the function for embedding YouTube videos from Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; "YouTube") on our website.YouTube is a company affiliated with Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; "Google").
The function displays videos stored on YouTube in an iFrame on the website. The "Extended data protection mode" option is activated. This means that YouTube does not store any information about visitors to the website. Only when you watch a video is information about it transmitted to YouTube and stored there. Your data may be transmitted to the USA. There is an adequacy decision by the EU Commission for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). YouTube 
has certified itself in accordance with the TADPF and is therefore committed to complying with European data protection principles.
The use of cookies or comparable technologies takes place with your consent on the basis of § 25 para. 1 sentence 1 TDDDG i.V.m. Art. 6 para. 1 lit. a GDPR. The processing of your personal data is carried out with your consent on the basis of Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
For more information on the collection and use of data by YouTube and Google, your rights in this regard and ways to protect your privacy, please refer to YouTube's privacy policy at https://www.youtube.com/t/privacy.


Use of Google Fonts
We use Google Fonts from Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; "Google") on our website.
The purpose of data processing is the uniform display of fonts on our website. In order to load the fonts, a connection to Google's servers is established when the page is accessed. Cookies may be used for this purpose. Among other things, your IP address and information about the browser you are using are processed and transmitted to Google. This data is not linked to your Google account.

Your data may be transferred to the USA. The EU Commission has issued an adequacy decision for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). Google has certified itself in accordance with the TADPF and is therefore committed to complying with European data protection principles.
The use of cookies or comparable technologies takes place with your consent on the basis of § 25 para. 1 sentence 1 TDDDG i.V.m. Art. 6 para. 1 lit. a GDPR. The processing of your personal data is carried out with your consent on the basis of Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
Further information on data processing and data protection can be found at https://www.google.de/intl/de/policies/ and at https://developers.google.com/fonts/faq.

Use of Google Translate 
We use the translation service of 
Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) on our website via an API integration.
The purpose of data processing is to display the information provided on the website in another language. In order for the translation to be displayed automatically after you have selected a language, the browser you are using connects to Google's servers. Cookies may be used for this purpose. Among other things, the following information may be collected and processed: IP address, URL of the page visited, date and time.
Your data may be transmitted to the USA. The EU Commission has issued an adequacy decision for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). Google has certified itself in accordance with the TADPF and has therefore undertaken to comply with European data protection principles.
The use of cookies or comparable technologies takes place with your consent on the basis of § 25 para. 1 sentence 1 TDDDG i.V.m. Art. 6 para. 1 lit. a GDPR. The processing of your personal data is carried out with your consent on the basis of Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal. 
Further information on the collection and use of your data by Google can be found at: https://www.google.com/policies/privacy/.
 
Data subject rights and storage duration

Duration of storage
Once the contract has been fully processed, the data will initially be stored for the duration of the warranty period, then in accordance with statutory retention periods, in particular under tax and commercial law, and then deleted after expiry of the period, unless you have consented to further processing and use.


Rights of the data subject
If the legal requirements are met, you have the following rights under Art. 15 to 20 GDPR: right of access, right to rectification, right to erasure, right to restriction of processing, right to data portability.
You also have the right to object to processing based on Article 6(1)(f) GDPR and to processing for the purposes of direct marketing in accordance with Article 21(1) GDPR.


Right to lodge a complaint with the supervisory authority
In accordance with Art. 77 GDPR, you have the right to lodge a complaint with the supervisory authority if you believe that your personal data is being processed unlawfully.


You can lodge a complaint with the supervisory authority responsible for us, which you can reach using the following contact details:

State Commissioner for Data Protection of Lower Saxony
Prinzenstrasse 5
30159 Hanover
Phone: +49 511 1204500
Fax: +49 511 1204599
E-mail: poststelle@lfd.niedersachsen.de


Right to object
If the personal data processing listed here is based on our legitimate interest in accordance with Art. 6 para. 1 lit. f GDPR, you have the right to object to this processing at any time with effect for the future for reasons arising from your particular situation.
Once you have objected, the processing of the data concerned will be terminated unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or if the processing serves the establishment, exercise or defense of legal claims.


If personal data is processed for direct marketing purposes, you can object to this processing at any time by notifying us. Once you have objected, we will stop processing the data concerned for the purpose of direct marketing.

last update: 22.10.2024