Privacy policy

Data protection declaration

Unless stated otherwise below, the provision of your personal data is neither legally nor contractually obligatory, nor required for conclusion of a contract. You are not obliged to provide your data. Not providing it will have no consequences. This only applies as long as the processing procedures below do not state otherwise.
“Personal data” is any information relating to an identified or identifiable natural person.


Server log files
You can use our websites without submitting personal data. 
Every time our website is accessed, user data is transferred to us or our web hosts/IT service providers by your internet browser and stored in server log files. This stored data includes for example the name of the site called up, date and time of the request, the IP address, amount of data transferred and the provider making the request. The processing is carried out on the basis of Article 6(1) f) GDPR due to our legitimate interests in ensuring the smooth operation of our website as well as improving our services.
 

Your data may be transferred to third countries outside the EU, in particular to Canada and the USA, and processed there. The EU Commission has issued an adequacy decision for Canada. For the USA, there is an adequacy decision of the EU Commission, the Trans-Atlantic Data Privacy Framework (TADPF). Shopify is not certified under the TADPF. This data transfer takes place on the basis of contractual obligations that are comparable to those of the EU Commission's standard contractual clauses.

Contact

Responsible person
Contact us at any time. The person responsible for data processing is: 
Hasan Almeslem, Wiesecker Weg 91, 35396 Gießen Deutschland, +49 15755897545, info@limorista.com


Proactive contact of the customer by e-mail
If you make contact with us proactively via email, we shall collect your personal data (name, email address, message text) only to the extent provided by you. The purpose of the data processing is to handle and respond to your contact request.
If the initial contact serves to implement pre-contractual measures (e.g. consultation in the case of purchase interest, order creation) or concerns an agreement already concluded between you and us, this data processing takes place on the basis of Article 6(1)(b) GDPR.
If the initial contact occurs for other reasons, this data processing takes place on the basis of Article 6(1)(f) GDPR for the purposes of our overriding, legitimate interest in handling and responding to your request. In this case, on grounds relating to your particular situation, you have the right to object at any time to this processing of personal data concerning you and carried out on the basis of Article 6(1)(f) GDPR.
We will only use your email address to process your request. Your data will subsequently be deleted in compliance with statutory retention periods, unless you have agreed to further processing and use.
 

Use of address validation from Google Maps API
We use the address validation of the provider Google (Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland "Google") on our website.
The purpose of data processing is to check your entries in our address forms in real time for input and spelling errors and to complete any missing data. If data is entered incorrectly, alternative suggestions for correcting the data are displayed. For this purpose, the address data you enter is transmitted to the provider, where it is stored and analysed.
Among other things, the following information may be transmitted to Google and processed there: postal addresses (country, city, postcode, street, house number), e-mail address, telephone number.
Your data may also be transmitted to the USA. For the USA, there is an adequacy decision of the EU Commission, the Trans-Atlantic Data Privacy Framework (TADPF). Google has certified itself in accordance with the TADPF and has thus undertaken to comply with European data protection principles.
Your personal data is processed on the basis of Art. 6 para. 1 lit. f GDPR due to our overriding legitimate interest in a correct data basis for the fulfilment of our contractual obligations. On grounds relating to your particular situation, you have the right to object at any time to this processing of personal data concerning you.
The data is processed separately by the provider and is not merged with other data. It is deleted by the provider as soon as the status of the data entered has been determined, but at the latest after 30 days.
For more information on terms of use and data protection at Google, please visit: https://cloud.google.com/maps-platform/terms or at https://www.google.de/policies/privacy/.


Collection and processing in case of applications via e-mail
In case of interest, website visitors may apply to vacancies advertised on our website by e-mail. We only collect your personal data to the extent provided by you. This includes your contact details (e.g., name, e-mail address, telephone number), details of your professional qualifications and training, details of further professional training and performance-specific evidence.
The purpose of this data processing is to contact you and to decide on the establishment of an employment relationship with you. The provision of the data is necessary to carry out the application procedure. The processing of your personal data takes place on the basis of Art. 6 para. 1(b) GDPR in conjunction with Art. 26 para. 1 Federal Data Protection Act (BDSG) for the implementation of pre-contractual measures (undergoing the application procedure as an initiation of the employment contract).
If you have given us permission for the processing of personal data for the inclusion in our pool of applicants, e.g., by checking a checkbox, the processing takes place on the basis of Art. 6 par. 1(a) GDPR. You can revoke your consent at any time without affecting the legality of the processing carried out on the basis of your consent until the revocation.
If specific categories of personal data within the meaning of Art. 9 para. 1 of the GDPR are requested from the applicants, such as information on the degree of severe disability, this is carried out on the basis of Art. 9 para. 2(b) GDPR, so that we can exercise the rights arising from labor law and the social security and social protection legislation and fulfill our obligations in this regard.
We will store your personal data as long as this is necessary for the decision about your application. Your data will then be deleted after six months at the latest, provided that you have not consented to further processing and use. If an employment relationship is established following the application procedure, the data provided will be further processed and then transferred to the personnel file for the purposes of implementing the employment relationship pursuant to Art. 6 para. 1 (b) GDPR in conjunction with Art. 26 Para. 1 of the Federal Data Protection Act (BDSG).


Customer account      Orders      

Customer account
When you open a customer account, we will collect your personal data in the scope given there. The data processing is for the purpose of improving your shopping experience and simplifying order processing. The processing will be carried out on the basis of art. 6 (1) lit. a GDPR with your consent. You can withdraw your consent at any time by contacting us without affecting the legality of the processing carried out with your consent up to the withdrawal. Your customer account will then be deleted.
 
Collection, processing, and transfer of personal data in orders
When you submit an order we only collect and use your personal data insofar as this is necessary for the fulfilment and handling of your order as well as processing of your queries. The provision of data is necessary for conclusion of a contract. Failure to provide it will prevent the conclusion of any contract. The processing will occur on the basis of Article 6(1) b) GDPR and is required for the fulfilment of a contract with you. 
Your data will be shared, for example, with shipping companies, dropshipping or fulfillment providers, payment service providers, service providers for order processing, and IT service providers. We will comply strictly with legal requirements in every case. The scope of data transmission is restricted to a minimum.
 

Your data may be transferred to third countries outside the EU, in particular to Canada and the USA, and processed there. The EU Commission has issued an adequacy decision for Canada. For the USA, there is an adequacy decision of the EU Commission, the Trans-Atlantic Data Privacy Framework (TADPF). Shopify is not certified under the TADPF. This data transfer takes place on the basis of contractual obligations that are comparable to those of the EU Commission's standard contractual clauses.


Evaluations       Advertising      

Data collection when you post a comment or a review
When you comment on/review an article or post, we collect your personal data (name, email address, comment text) only in the scope provided by you. The processing serves to allow you to comment/review and to display comments/reviews.


By submitting the comment/review, you agree to the processing of the transmitted data. The processing is carried out on the basis of Art. 6 para. 1 lit. a GDPR with your consent. You can withdraw your consent at any time by contacting us without affecting the legality of the processing carried out with your consent up to the withdrawal. Your personal data will then be deleted.

When your comment/review is published only the name you have entered will be published.

Shopauskunft customer review
We use the "shopauskunft.de" evaluation tool for our website, from 
Händlerbund Management AG (Kohlgartenstraße 11 - 13, 04315 Leipzig; "Shopauskunft").
Following your order, we would like to ask you to evaluate and comment on your purchase with us. For this reason, we will contact you via email. When doing so, we will make use of a technical system known as “Rechtssichere Bewertungsanfrage (a type of evaluation request that is legally sound, RBA)”. As part of this procedure, we will process the data pertaining to your order (order number/invoice number, value of purchases and shipping costs) as well as your e-mail address. Processing is carried out on the basis of Article 6(1)(a) GDPR with your consent, insofar as you have expressly consented to disclose your data and receive feedback requests.
You can withdraw your consent at any time using the corresponding link in the email or by sending us a message, without affecting the legality of the processing carried out with your consent up to the withdrawal.

For more information about data protection when using Shopauskunft, please visit: https://www.shopauskunft.de/datenschutz.
 
Trustami customer ratings
To display collected ratings and feedback from social media, the Trustami trust seal is embedded on this website. This serves to implement our legitimate interests in the optimal marketing of our offer on our website in accordance with Article 6(1)(1)(f) GDPR. When the Trustami trust seal is called up, the web server automatically stores data (access data) in the form of a server log file containing the name of the website accessed, the file, the date and time of access, your IP address in truncated form, the amount of data transferred, the notification of successful retrieval, the browser type, the user's operating system, the referrer URL (of the previously visited site) and the requesting provider. This access data is not analysed and is automatically overwritten no later than seven days after the end of your visit to our website. The Trustami trust seal and the services advertised with it are provided by Trustami GmbH, Schröderstraße 5, 10115 Berlin. For the processing of data collected by Trustami, Trustami's Data Protection Policy at https://www.trustami.com/privacy/ applies.
 

Website logo for Google customer reviews 
The website logo for Google Customer Reviews of Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; "Google") is integrated into our website.
The integration serves to display the number and results of our reviews previously received from Google and to advertise participation in this program. In order to display the logo on our website and to show you personalised advertisements on Google, Google uses cookies. In so doing, among other things your IP address is processed and transmitted to Google. Your data may be transmitted to the USA. For the USA, there is an adequacy decision of the EU Commission, the Trans-Atlantic Data Privacy Framework (TADPF). Google has certified itself in accordance with the TADPF and has thus undertaken to comply with European data protection principles.
The use of cookies or comparable technologies is carried out with your consent on the basis of Art. 25 para. 1 p. 1 TDDDG in conjunction with Art. 6 para. 1 lit. a GDPR. The processing of your personal data is carried out with your consent on the basis of Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the legality of the processing carried out with your consent up to the withdrawal.
For more information on terms of service and privacy when using Google customer reviews, please visit https://www.google.com/shopping/customerreviews/static/tos/de/1_01_tos.html and https://policies.google.com/privacy?hl=de


Use of the Trusted Shops rating system (Trustbadge)
We use the rating system of Trusted Shops SE, Subbelrather Str. 15C, 50823 Cologne, Germany (‘Trusted Shops’) on our website.
Trusted Shops and we are jointly responsible for the collection of your data when using the service and the transmission of this data to Trusted Shops. The basis for this is an agreement between us and Trusted Shops on the joint processing of personal data.
Accordingly, we and Trusted Shops are equally responsible for the fulfilment of the obligations under the GDPR, in particular for the fulfilment of the information obligations pursuant to Art. 13, 14 GDPR and for the granting of the rights of data subjects pursuant to Art. 15 - 21 GDPR. You can find more information on this at https://help.etrusted.com/hc/de/article_attachments/4422901015569.
Trusted Shops enables us to obtain customer reviews and display them on our website via the ‘Trustbadge’ in order to provide you with an insight into the quality of our services.
After placing an order, you can receive an invitation to submit a review from us or Trusted Shops and then submit a review. The following data will be processed by us or Trusted Shops: E-mail address, order information (order total, order number, product purchased if applicable). This data may also be used for the purpose of verifying your rating.
When you visit our website and display the Trustbadge, the following data is also processed by us or Trusted Shops: Your IP address, date and time of access, amount of data transferred and the requesting provider.
The processing is carried out on the basis of Art. 6 para. 1 lit. a GDPR with your consent, provided that you have expressly consented to the transfer of your data and the receipt of the evaluation request. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
Further information on data protection at Trusted Shops can be found at: https://www.trustedshops.de/impressum-datenschutz/#datenschutz.


Review reminder
Following your order, we would like to ask you to review your purchase with us.
For this purpose, we use your personal data (name, e-mail address, order information) independently of the contract processing in order to send you a review reminder by e-mail after an order has been placed, provided you have expressly consented to this.
Processing will be carried out on the basis of Art. 6 para. 1 lit. a GDPR with your consent. You can withdraw your consent at any time using the corresponding link in the email or by sending us a message, without affecting the legality of the processing carried out with your consent up to the withdrawal.


Use of your email address for mailing of direct marketing 
We use your email address, which we obtained in the course of selling a good or service, for the electronic transmission of marketing for our own goods or services which are similar to those you have already purchased from us, unless you have objected to this use. You must provide your email address in order to conclude a contract. Failure to provide it will prevent the conclusion of any contract. The processing will be carried out on the basis of art. 6 (1) lit. f GDPR due to our justified interest in direct marketing. You can object to this use of your email address at any time by contacting us. You will find the contact details for exercising your right to object in our imprint. You can also use the link provided in the marketing email. This will not involve any costs other than transmission costs at basic tariffs.
 

Use of the e-mail address for availability notifications
We offer an availability notification service on our website. If an item is temporarily unavailable, you have the option of entering your e-mail address on the item in question and being informed by e-mail when it becomes available, provided you have given your consent. You will receive a one-time e-mail notification about the availability of the respective item when the goods are available. The processing is carried out on the basis of Art. 6 para. 1 lit. a GDPR with your consent. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal. You can unsubscribe from the availability notification at any time by notifying us. Your e-mail address will then be removed from the mailing list.



Payment service providers      

The use of PayPal Check-Out
We use the PayPal Check-Out payment service of PayPal (Europe) S.à.r.l. et Cie, S.C.A. (22-24 Boulevard Royal L-2449, Luxembourg; "PayPal") on our website. The data processing serves the purpose of being able to offer you payment via the payment service. With the selection and use of payment via PayPal, credit card via PayPal, direct debit via PayPal or "Pay Later" via PayPal, the data required for payment processing is transmitted to PayPal in order to be able to fulfill the contract with you with the selected payment method. This processing is based on Art. 6 para. 1 lit. b DSGVO.

Cookies may be stored that enable your browser to be recognised. The resulting data processing is carried out on the basis of Art. 6 para. 1 lit. f GDPR due to our legitimate interest in a customer-oriented range of varying payment methods. On grounds relating to your particular situation, you have the right to object at any time to this processing of personal data concerning you.

Credit card via PayPal, direct debit via PayPal & "Pay later" via PayPal.
For individual payment methods such as credit card via PayPal, direct debit via PayPal or "Pay later" via PayPal, PayPal reserves the right, if necessary, to obtain credit information on the basis of mathematical-statistical methods using credit agencies. For this purpose, PayPal transmits the personal data required for a credit check to a credit agency and uses the information received about the statistical probability of a payment default for a weighed decision on the establishment, implementation or termination of the contractual relationship. The credit information may include probability values (score values), which are calculated on the basis of scientifically recognized mathematical-statistical methods and in the calculation of which, among other things, address data are included. Your interests worthy of protection are taken into account in accordance with the statutory provisions. The data processing serves the purpose of credit assessment for a contract initiation. The processing is carried out on the basis of Art. 6 (1) lit. f DSGVO for our overriding legitimate interest in protecting against payment default when PayPal makes advance payments.
You have the right to object at any time to this processing of personal data relating to you based on Art. 6 (1) (f) DSGVO for reasons arising from your particular situation by notifying PayPal. The provision of the data is necessary for the conclusion of the contract with the payment method requested by you. Failure to provide it will result in the contract not being concluded with the payment method you have chosen.

Local third-party providers
When paying via the payment method of a local third-party provider, the data required for payment processing is transmitted to PayPal. This processing takes place on the basis of Art. 6 para. 1 lit. b DSGVO.  For the execution of this payment method, the data may then be forwarded by PayPal to the respective provider. This processing takes place on the basis of Art. 6 para. 1 lit. b DSGVO. Local third-party providers may be, for example:

  • Apple Pay (Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland)
  • Google Pay (Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland)


Purchase on account via PayPal
When paying via the payment method purchase on account, the data required to process the payment is first transmitted to PayPal. For the execution of this payment method, the data is then transmitted by PayPal to Ratepay GmbH (Franklinstraße 28-29, 10587 Berlin; "Ratepay") in order to be able to fulfill the contract with you with the selected payment method. This processing is based on Art. 6 para. 1 lit. b DSGVO. Ratepay may conduct a credit check on the basis of mathematical-statistical methods using credit agencies according to the procedure already described above. The data processing serves the purpose of credit assessment for contract initiation. The processing is carried out on the basis of Art. 6 (1) lit. f DSGVO from our overriding legitimate interest in protecting against payment default when Ratepay makes advance payments. For more information on data protection and which credit agencies Ratpay uses, please visit https://www.ratepay.com/legal-payment-dataprivacy/ and https://www.ratepay.com/legal-payment-creditagencies/.

For more information on data processing when using PayPal, please see the associated privacy policy at https://www.paypal.com/de/webapps/mpp/ua/privacy-full.


Use of Amazon Payments
We use Amazon Payments payment service on our website, from Amazon Payments Europe s.c.a. (38 avenue John F. Kennedy, L-1855 Luxembourg; "Amazon Payments").
The processing of data enables you to pay using the Amazon Payments payment service.
To integrate this payment service it is essential that Amazon Payments collects, stores, and analyses data when accessing the website (e.g. IP address, device type, operating system, browser type, device location). Cookies may be used for this purpose. Cookies allow your internet browser to be recognised.
The use of cookies or comparable technologies is based on § 15 para. 3 p. 1 TMG. The processing of your personal data is based on Art. 6 para. 1 lit. f GDPR out of our overriding legitimate interest in a customer-oriented offer of different payment methods. On grounds relating to your particular situation, you have the right to object at any time to this processing of personal data concerning you.
By selecting and using "Amazon Payments", the data required for payment processing will be submitted to Amazon Payments to execute the agreement with you using the selected payment method. The data is processed on the basis of Article 6(1)(b) GDPR.
Further information on data processing when using the Amazon Payments payment service can be found in the associated data privacy policy at: https://pay.amazon.com/de/help/201212490


Use of Shopify Payments
We use the payment service "Shopify Payments" from Shopify International Limited (2nd Floor Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland; "Shopify") on our website. In this case, payment processing is carried out by the payment service provider Stripe Payments Europe, Ltd. (1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland; "Stripe"). The purpose of data processing is to enable us to offer you payment via the Shopify Payments payment service. When you select and use a corresponding "Shopify Payments" payment method, the data required for payment processing is transmitted to Stripe in order to fulfil the contract with you using the selected payment method. This processing is carried out on the basis of Art. 6 (1) lit. b GDPR.
Stripe reserves the right to obtain credit information based on mathematical-statistical methods using credit agencies. To this end, Stripe transmits the personal data required for a credit check to a credit agency and uses the information obtained about the statistical probability of a payment default to make a balanced decision about the establishment, execution or termination of the contractual relationship. The credit report may contain probability values (score values) that are calculated on the basis of scientifically recognised mathematical-statistical methods and which include address data, among other things, in their calculation. Your interests worthy of protection will be taken into account in accordance with the statutory provisions. The purpose of data processing is to check creditworthiness for the initiation of a contract. Processing is carried out on the basis of Art. 6 (1) lit. f GDPR due to our overriding legitimate interest in protection against payment default when Stripe makes advance payments.
You have the right to object at any time to the processing of your personal data based on Art. 6 (1) (f) GDPR for reasons arising from your particular situation by notifying Stripe. The provision of data is necessary for the conclusion of the contract with your desired payment method. Failure to provide data will result in the contract not being concluded with your chosen payment method.
For more information on data processing when using the Shopify Payments payment service, please refer to Shopify's privacy policy at: 
https://www.shopify.com/de/legal/datenschutz.
For more information on data processing when processing payments via the payment service provider Stripe, please refer to Stripe's privacy policy at: https://stripe.com/de/privacy.


Cookies 

Our website uses cookies. Cookies are small text files which are saved in a user’s internet browser or by the user’s internet browser on their computer system. When a user calls up a website, a cookie may be saved on the user’s operating system. This cookie contains a characteristic character string which allows the browser to be clearly identified when the website is called up again.


Cookies will be stored on your computer. You therefore have full control over the use of cookies. By choosing corresponding technical settings in your internet browser, you can be notified before the setting of cookies and you can decide whether to accept this setting in each individual case as well as prevent the storage of cookies and transmission of the data they contain. Cookies which have already been saved may be deleted at any time. We would, however, like to point out that this may prevent you from making full use of all the functions of this website.
Using the links below, you can find out how to manage cookies (or deactivate them, among other things) in major browsers:
Chrome Browser: https://support.google.com/accounts/answer/61416?hl=en
Microsoft Edge: https://support.microsoft.com/de-de/microsoft-edge/cookies-in-microsoft-edge-lB6schen-63947406-40ac-c3b8-57b9-2a946a29ae09
Mozilla Firefox: https://support.mozilla.org/en-US/kb/enable-and-disable-cookies-website-preferences
Safari: https://support.apple.com/de-de/guide/safari/manage-cookies-and-website-data-sfri11471/mac


technically necessary cookies
Insofar as no other information is given in the data protection declaration below we use only these technically necessary cookies cookies to make our offering more user-friendly, effective and secure. Cookies also allow our systems to recognise your browser after a page change and to offer you services. Some functions of our website cannot be offered without the use of cookies. These services require the browser to be recognised again after a page change.

The use of cookies or comparable technologies is carried out on the basis of Art. 25 para. 2 TDDDG. Processing is carried out on the basis of art. 6 (1) lit. f GDPR due to our largely justified interest in ensuring the optimal functionality of the website as well as a user-friendly and effective design of our range of services.

You have the right to veto this processing of your personal data according to art. 6 (1) lit. f GDPR, for reasons relating to your personal situation.


Analysis      


Use of Google Analytics 4
We use the Google Analytics web analytics service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; "Google") on our website.
The data processing serves the purpose of analyzing this website and its visitors as well as for marketing and advertising purposes. To this end, Google will use the information obtained on behalf of the operator of this website for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage to the website operator. 
In this context, the following information may be collected, among others: IP address, date and time of page view, click path, information about the browser you are using and the device you are using (device), pages visited, referrer URL (website from which you accessed our website), location data, purchase activity. Your data may be linked by Google to other data, such as your search history, your personal accounts, your usage data from other devices, and any other data Google may have about you.
 

The IP address is shortened beforehand by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area.

The processing of your personal data is carried out with your consent on the basis of Art. 6 para. 1 lit. a DSGVO. You may revoke your consent at any time without affecting the lawfulness of the processing carried out on the basis of the consent until revocation.

We use the extended implementation of the consent mode (Advanced Consent Mode). In this case, user data is transmitted to Google in the form of "pings" even if consent has not been granted. These pings may contain the following information, among others: IP address to derive the IP country (the IP address is not logged), date and time of the page view, URL of the pages visited, user agent, referrer URL (website from which you accessed our website) or information about the triggering of website events such as a conversion. On the basis of this information, Google models user data in order to be able to carry out a comprehensive usage analysis despite the refusal of consent.


The information generated by this about your use of this website is usually transferred to a Google server in the USA and stored there. For the USA, there is an adequacy decision of the EU Commission, the Trans-Atlantic Data Privacy Framework (TADPF). Google has certified itself in accordance with the TADPF and has thus undertaken to comply with European data protection principles.
Both Google and US government agencies have access to your data.

For more information on terms of use and data protection, please visit https://policies.google.com/technologies/partner-sites and https://policies.google.com/privacy?hl=de&gl=de.

Use of Shopify Analytics
We use the statistical and analytical functions of Shopify International Ltd. (Victoria Buildings, 
2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland; "Shopify") on our website as part of an order processing. Shopify is an affiliated company of Shopify Inc. (151 O'Connor Street, Ground Floor, Ottawa, Ontario, K2P 2L8, Canada).
The processing of data serves to analyse this website and its visitors. For this purpose, data is stored for marketing and optimisation purposes and provided in reports, analyses and statistics. In the process, the following device information is collected and processed, among others: Web browser information, IP address, time zone and some of the cookies installed on your device. When you navigate the website, information is also collected on websites or products accessed, the referrer URL (website from which you accessed our website), and information on how you interact with the website. This is done using technologies such as cookies and web beacons, tags and pixels (electronic files that collect information about how you navigate the website).

Your data may be transferred to third countries outside the EU, in particular to Canada and the USA, and processed there. The EU Commission has issued an adequacy decision for Canada. For the USA, there is an adequacy decision of the EU Commission, the Trans-Atlantic Data Privacy Framework (TADPF). Shopify is not certified under the TADPF. This data transfer takes place on the basis of contractual obligations that are comparable to those of the EU Commission's standard contractual clauses.
The use of cookies or comparable technologies is carried out with your consent on the basis of Art. 25 Para. 1 Sentence 1 TDDDG in conjunction with Art. 6 Para. 1 Letter a GDPR. The processing of your personal data is carried out with your consent on the basis of Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the legality of the processing carried out with your consent up to the withdrawal.
You can find more detailed information on data protection at Shopify at https://www.shopify.com/de/legal/datenschutz, information on the order processing agreement at https://www.shopify.com/de/legal/dpa and information on the cookies used at https://www.shopify.com/de/legal/cookies.



Plug-ins

Use of Facebook Connect
Our website uses the single sign-on function Facebook Connect from Meta Platforms Ireland Ltd. (Grand Canal Harbour, Dublin, D02, Ireland; "Facebook").

Meta Platforms Ireland and we are jointly responsible for the collection of your data and the transfer of this data to Facebook when the service is integrated. The basis for this is an agreement between us and Meta Platforms Ireland on the joint processing of personal data, in which the respective responsibilities are defined. The agreement is available at https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible in particular for the fulfilment of the information obligations in accordance with Art. 13, 14 GDPR, for compliance with the security requirements of Art. 32 GDPR with regard to the correct technical implementation and configuration of the service, and for compliance with the obligations in accordance with Art. 33, 34 GDPR, insofar as a violation of the protection of personal data affects our obligations under the agreement on joint processing. Meta Platforms Ireland is responsible for enabling the rights of the data subject in accordance with articles 15-20 of the GDPR, for complying with the security requirements of article 32 of the GDPR with regard to the security of the service, and for complying with the obligations of articles 33, 34 of the GDPR, insofar as a breach of personal data protection concerns Meta Platforms Ireland's obligations under the joint processing agreement.
This function enables website visitors to log on to the website via their already existing Facebook account. The processing of data serves the purpose of verification during registration, personalisation and for interest-related advertising. To offer this function on the website a connection to the Facebook servers is established. Cookies are used for this purpose. In this process the following information, inter alia, can be collected and transmitted to Facebook: IP address, browser information, referrer URL (website via which you accessed our website), location data. This happens regardless of whether you are registered with or logged into the social network. The information is transferred even if users are not registered or logged in. Should you be connected simultaneously with one or more of your social network accounts, the collected information may also be assigned to your corresponding profiles. You can therefore prevent this assignment by logging yourself out before visiting our website and before activating the button for your social media accounts. Your data may be transmitted to the USA. For the USA, there is an adequacy decision of the EU Commission, the Trans-Atlantic Data Privacy Framework (TADPF). Meta has certified itself in accordance with the TADPF and has thus undertaken to comply with European data protection principles.
When using the single sign-on function the Facebook profile of the website visitor is connected with a customer account for this website. In this case we receive personal data of the user through Facebook, as stated in the login process. This can include the following information, inter alia: Name, address, public profile information (e,g, name profile picture, age, gender), email address, friends list, "Likes" information.
The use of cookies or comparable technologies is carried out with your consent on the basis of Art. 25 para. 1 p. 1 TDDDG in conjunction with Art. 6 para. 1 lit. a GDPR. The processing of your personal data is carried out with your consent on the basis of Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time without affecting the legality of the processing carried out with your consent up to the withdrawal. You can find more detailed information on the terms and conditions of use and data protection at https://www.facebook.com/about/privacy/.


Rights of persons affected and storage duration

Duration of storage 
After contractual processing has been completed, the data is initially stored for the duration of the warranty period, then in accordance with the retention periods prescribed by law, especially tax and commercial law, and then deleted after the period has elapsed, unless you have agreed to further processing and use.
 
Rights of the affected person
If the legal requirements are fulfilled, you have the following rights according to art. 15 to 20 GDPR: Right to information, correction, deletion, restriction of processing, data portability. You also have a right of objection against processing based on art. 6 (1) GDPR, and to processing for the purposes of direct marketing, according to art. 21 (1) GDPR.
 
Right to complain to the regulatory authority
You have the right to complain to the regulatory authority according to art. 77 GDPR if you believe that your data is not being processed legally.
 

You can lodge a complaint with, among others, the supervisory authority responsible for us, which you may reach at the following contact details:

Hessischer Beauftragter für Datenschutz und Informationsfreiheit
Postfach 3163
65021 Wiesbaden
Tel.: +49 611 14080
Fax: +49 611 1408900 oder +49 611 1408901
E-Mail: poststelle@datenschutz.hessen.de

Right to object
If the data processing outlined here is based on our legitimate interests in accordance with Article 6(1)f) GDPR, you have the right for reasons arising from your particular situation to object at any time to the processing of your data with future effect.
If the objection is successful, we will no longer process the personal data, unless we can demonstrate compelling legitimate grounds for the processing that outweigh your interests or rights and freedoms, or the processing is intended for the assertion, exercise or defence of legal claims.
 

If personal data is being processed for the purposes of direct advertising, you can object to this at any time by notifying us. If the objection is successful, we will no longer process the personal data for the purposes of direct advertising.

last update: 22.10.2024