General Data Protection Regulation (GDPR)
Privacy Policy
1) Introduction and contact details of the responsible party
1.1 We are pleased that you are visiting our website and thank you for your interest. Below, we inform you about how we handle your personal data when you use our website. Personal data is any data that can be used to personally identify you.
1.2 The data controller for this website within the meaning of the General Data Protection Regulation (GDPR) is YANG HENGSHENG LOGISTICS LTD. // NORSKY LOGISTICS LTD., Suite C, Level 7, World Trust Tower, 50 Stanley Street, Central, Hong Kong, Email : info@norsky.de. The data controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.
1.3 This website uses SSL or TLS encryption for security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the data controller). You can recognize an encrypted connection by the "https://" prefix and the padlock symbol in your browser's address bar.
2) Data collection when visiting our website
When you simply use our website for informational purposes, i.e., if you do not register or otherwise provide us with information, we only collect data that your browser transmits to our server (so-called "server log files"). When you access our website, we collect the following data, which is technically necessary for us to display the website to you:
- Our visited website
- Date and time of access
- Amount of data sent in bytes
- Source/referrer from which you accessed this page
- Browser used
- Operating system used
- IP address used (possibly in anonymized form)
The processing is carried out in accordance with Article 6(1)(f) GDPR on the basis of our legitimate interest in improving the stability and functionality of our website. The data will not be disclosed or used for any other purpose. However, we reserve the right to subsequently review the server log files should there be concrete indications of unlawful use.
3) Hosting & Content Delivery Network
- Shopify
We use the system of the following provider for hosting our website and displaying the page content: Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland (“Shopify”)
Data will also be transferred to: Shopify Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada, Shopify Data Processing (USA) Inc., Shopify Payments (USA) Inc. or Shopify (USA) Inc.
All data collected on our website is processed on the provider's servers. We have concluded a data processing agreement with the provider, which ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.
When data is transferred to Canada, an adequate level of data protection is ensured by an adequacy decision of the European Commission.
For the transfer of data to the USA, the provider relies on standard contractual clauses of the European Commission, which are intended to ensure compliance with the European level of data protection.
4) Cookies
To make your visit to our website more enjoyable and to enable the use of certain features, we use cookies, which are small text files that are stored on your device. Some of these cookies are automatically deleted after you close your browser (so-called "session cookies"), while others remain on your device for a longer period and allow us to save your website settings (so-called "persistent cookies"). In the latter case, you can find information about the storage duration in your web browser's cookie settings.
If any of the cookies we use process personal data, this processing is carried out in accordance with Art. 6 para. 1 lit. b GDPR either for the performance of the contract, in accordance with Art. 6 para. 1 lit. a GDPR in the case of consent given, or in accordance with Art. 6 para. 1 lit. f GDPR to safeguard our legitimate interests in the best possible functionality of the website and a customer-friendly and effective design of the website visit.
You can configure your browser to notify you when cookies are set and allow you to decide whether to accept them individually, or to exclude the acceptance of cookies in certain cases or entirely.
Please note that if you do not accept cookies, the functionality of our website may be limited.
5) Making contact
When you contact us (e.g., via contact form or email), we process your personal data solely for the purpose of handling and responding to your inquiry and only to the extent necessary. The legal basis for processing this data is our legitimate interest in responding to your inquiry, pursuant to Article 6(1)(f) GDPR. If your contact relates to a contract, the additional legal basis for processing is Article 6(1)(b) GDPR. Your data will be deleted when it is clear from the circumstances that the matter has been resolved and provided that no statutory retention obligations apply.
6) Comment function
When you use the comment function on this website, your comment, the date and time it was posted, and your chosen username will be stored and published on this website. For security reasons, your IP address will also be stored to allow us to identify the author of any unlawful comments. Your email address will be stored so we can contact you if a third party objects to your published content as being unlawful.
7) Use of customer data for direct marketing
7.1 - Klaviyo
Our email newsletters are sent via this provider: Klaviyo, 225 Franklin St, Boston, MA 02110, USA
Based on our legitimate interest in effective and user-friendly newsletter marketing, we pass on the data you provided when registering for the newsletter to this provider in accordance with Art. 6 para. 1 lit. f GDPR, so that they can take over the newsletter distribution on our behalf.
Subject to your explicit consent pursuant to Art. 6 para. 1 lit. a GDPR, the provider also conducts statistical performance analysis of newsletter campaigns using web beacons or tracking pixels in the sent emails, which can measure open rates and specific interactions with the newsletter content. Device information (e.g., time of access, IP address, browser type, and operating system) is also collected and analyzed, but not combined with other data sets.
You can revoke your consent to newsletter tracking at any time with effect for the future.
We have concluded a data processing agreement with the provider, which protects the data of our website visitors and prohibits its transfer to third parties.
For the transfer of data to the USA, the provider relies on standard contractual clauses of the European Commission, which are intended to ensure compliance with the European level of data protection.
7.2 If you cancel your purchase with us before completing the order, you have the option of receiving a one-time email reminder about the contents of your virtual shopping cart.
The only mandatory information required to send you this reminder is your email address. Providing further information is voluntary and may be used to personalize our communications with you. We use a double opt-in procedure for sending emails, which ensures that you only receive a notification after you have explicitly confirmed your consent by clicking a verification link sent to the specified email address.
By activating the confirmation link, you give us your consent to use your personal data in accordance with Article 6 Paragraph 1 Letter a of the GDPR for sending you shopping cart reminders. We store your IP address, registered by your Internet Service Provider (ISP), as well as the date and time of registration, in order to be able to trace any potential misuse of your email address at a later date. The data we collect when you register for our email notification service is used strictly for this purpose. You can unsubscribe from shopping cart reminders at any time by sending a message to the data controller named above. After you unsubscribe, your email address will be immediately deleted from our mailing list, unless you have expressly consented to further use of your data or we reserve the right to use your data for other purposes permitted by law, about which we inform you in this statement.
8) Data processing for order processing
8.1 Insofar as necessary for the processing of the contract for delivery and payment purposes, the personal data we collect will be passed on to the commissioned transport company and the commissioned credit institution in accordance with Art. 6 para. 1 lit. b GDPR.
If we owe you updates for goods with digital elements or for digital products based on a corresponding contract, we process the contact details you provided during the ordering process (name, address, email address) in order to personally inform you about upcoming updates within the legally prescribed period, in accordance with our legal information obligations pursuant to Art. 6 para. 1 lit. c GDPR, via a suitable communication channel (e.g., by post or email). Your contact details will be used strictly for the purpose of notifying you about updates we owe you and will only be processed by us to the extent necessary for the respective information.
To process your order, we also work with the following service provider(s), who support us in whole or in part in fulfilling concluded contracts. Certain personal data will be transmitted to these service providers in accordance with the following information.
8.2 To fulfill our contractual obligations to our customers, we work with external shipping partners. We will pass on your name, delivery address, and, if necessary for delivery, your telephone number, exclusively for the purpose of delivering the goods (Art. 6 para. 1 lit. b GDPR) to a shipping partner selected by us.
8.3 Use of specialized service providers for order processing and fulfillment
- Order processing is handled by YIWU CUJIA TRADE CO., LTD, F2, Building 8, No. 89, Siyuan Road, Yidong Industrial Zone, Niansanli St, China. Your name, address, and any other personal data will be shared in accordance with Article 6 Paragraph 1 Letter b of the GDPR solely for the purpose of processing your online order. Your data will only be shared to the extent that it is actually necessary for processing the order.
8.4 Use of payment service providers (payment services)
- Amazon Pay
When you select "Amazon Pay" as your payment method, payment processing is handled by the payment service provider Amazon Payments Europe sca, 38 avenue JF Kennedy, L-1855 Luxembourg (hereinafter: "Amazon Payments"), to whom we transfer the information you provided during the ordering process, along with information about your order, in accordance with Article 6 Paragraph 1 Letter b GDPR. Your data is transferred exclusively for the purpose of payment processing with the payment service provider Amazon Payments and only to the extent necessary for this purpose. If cookies, i.e., small text files that are stored on your device, are set when using Amazon Pay, this is done exclusively on the basis of your explicit consent in accordance with Article 6 Paragraph 1 Letter a GDPR. This consent can be revoked at any time via the "Cookie Consent Tool" implemented on the website. You can find further information about Amazon Payments' privacy policy at the following web address: https://pay.amazon.de /help /82974
- Apple Pay
If you choose the "Apple Pay" payment method from Apple Distribution International (Apple), Hollyhill Industrial Estate, Hollyhill, Cork, Ireland, payment processing is handled via the "Apple Pay" function on your iOS, watchOS, or macOS device by charging a payment card stored with "Apple Pay." Apple Pay uses security features integrated into your device's hardware and software to protect your transactions. Authorizing a payment requires entering a code you previously set and verifying your identity using your device's "Face ID" or "Touch ID" function.
For payment processing purposes, the information you provide during the ordering process, along with details of your order, will be transmitted to Apple in encrypted form. Apple then re-encrypts this data with a developer-specific key before transmitting it to the payment service provider of the payment card stored in Apple Pay. This encryption ensures that only the website where the purchase was made can access the payment information. After the payment has been processed, Apple sends your device account number and a transaction-specific, dynamic security code to the originating website to confirm the successful payment.
If personal data is processed during the described transfers, the processing is carried out exclusively for the purpose of payment processing in accordance with Art. 6 para. 1 lit. b GDPR.
Apple retains anonymized transaction data, including the approximate purchase amount, date, and time, as well as whether the transaction was successful. Anonymization completely eliminates any possibility of identifying individuals. Apple uses this anonymized data to improve Apple Pay and other Apple products and services.
When you use Apple Pay on your iPhone or Apple Watch to complete a purchase you made through Safari on your Mac, your Mac and the authorizing device communicate over an encrypted channel on Apple's servers. Apple does not process or store any of this information in a format that can identify you personally. You can disable the ability to use Apple Pay on your Mac in your iPhone's settings. Go to "Wallet & Apple Pay" and turn off "Allow Payments on Mac."
Further information on data protection with Apple Pay can be found at the following web address: https://support.apple.com /de-de /HT203027
- EPS transfer
When selecting the payment method "EPS transfer," payment processing is handled by the payment service provider PSA Payment Services Austria GmbH, Handelskai 92, Gate 2, 1200 Vienna, Austria, to whom we transfer the information you provided during the ordering process, along with information about your order, in accordance with Article 6 Paragraph 1 Letter b GDPR. Your data is transferred exclusively for the purpose of payment processing with the aforementioned payment service provider and only to the extent necessary for this purpose. Further information about the relevant data protection regulations of PSA Payment Services Austria GmbH can be found at the following web address: https://eservice.psa.at /de/datenschutzerklaerung.html
- Google Pay
If you choose the payment method "Google Pay" from Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), payment processing is handled via the "Google Pay" application on your mobile device, which must be running at least Android 4.4 ("KitKat") and have NFC capability. The payment will be processed by charging a payment card stored in Google Pay or a payment system verified there (e.g., PayPal). To authorize a payment via Google Pay exceeding €25, you must first unlock your mobile device using the configured verification method (e.g., facial recognition, password, fingerprint, or pattern).
For payment processing purposes, the information you provide during the ordering process, along with information about your order, will be shared with Google. Google will then transmit your payment information stored in Google Pay to the originating website in the form of a unique transaction number, which is used to verify the payment. This transaction number contains no information about the actual payment details of your payment method stored in Google Pay, but is created and transmitted as a unique numerical token. In all transactions via Google Pay, Google acts solely as an intermediary for processing the payment. The transaction is executed exclusively between the user and the originating website by debiting the payment method stored in Google Pay.
If personal data is processed during the described transfers, the processing is carried out exclusively for the purpose of payment processing in accordance with Art. 6 para. 1 lit. b GDPR.
Google reserves the right to collect, store, and analyze certain transaction-specific information for each transaction made through Google Pay. This includes the date, time, and amount of the transaction; the merchant's location and description; a description of the purchased goods or services provided by the merchant; photos you attached to the transaction; the name and email address of the seller and buyer or sender and recipient; the payment method used; your description of the reason for the transaction; and, if applicable, the offer associated with the transaction.
According to Google, this processing is carried out exclusively in accordance with Art. 6 para. 1 lit. f GDPR on the basis of the legitimate interest in proper accounting, verification of transaction data and the optimization and maintenance of the Google Pay service.
Google also reserves the right to combine the processed transaction data with other information collected and stored by Google when you use other Google services.
The Google Pay terms of service can be found here:
https://payments.google.com /payments /apis-secure /u /0 /get_legal_document ?ldo=0 &ldt=googlepaytos &ldl=de
Further information on data protection at Google Pay can be found at the following web address:
https://payments.google.com /payments /apis-secure /get_legal_document ?ldo=0 &ldt=privacynotice &ldl=de
- Klarna
When selecting a Klarna payment service, payment processing is handled by Klarna Bank AB (publ), https://www.klarna.com/de/ Sveavägen 46, 111 34 Stockholm, Sweden (hereinafter "Klarna"). To process your payment, your personal data (first and last name, street, house number, postal code, city, gender, email address, telephone number and IP address, and, if applicable, your date of birth and bank details) as well as data related to your order (e.g., invoice amount, items, delivery method) will be forwarded to Klarna for identity and credit checks, provided you have expressly consented to this in accordance with Art. 6 Para. 1 lit. a GDPR during the ordering process. You can see which credit agencies your data may be forwarded to here:
https://cdn.klarna.com /1.0 /shared /content /legal /terms /0 /de_de /credit_rating_agencies
The credit report may contain probability values (so-called score values). If score values are included in the credit report, they are based on a scientifically recognized mathematical-statistical method. Address data is among the factors, but not the only one, used in calculating the score values. Klarna uses the information obtained about the statistical probability of a payment default to make a balanced decision regarding the establishment, execution, or termination of the contractual relationship.
You can withdraw your consent at any time by sending a message to the data controller or to Klarna. However, Klarna may still be entitled to process your personal data if this is necessary for processing payments in accordance with the contract.
Your personal data will be processed in accordance with applicable data protection regulations and as described in Klarna's privacy policy for data subjects residing in Germany. https://cdn.klarna.com /1.0 /shared /content /legal /terms /0 /de_de /privacy
or for those affected who are based in Austria https://cdn.klarna.com /1.0 /shared /content /legal /terms /0 /de_at /privacy
treated.
- Paypal
When paying via PayPal, credit card via PayPal, direct debit via PayPal, or – if offered – "purchase on account" or "installment payment" via PayPal, we forward your payment data to PayPal (Europe) Sarl et Cie, SCA, 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter "PayPal") for payment processing. This transfer is carried out in accordance with Art. 6 para. 1 lit. b GDPR and only to the extent necessary for payment processing.
For the payment methods credit card via PayPal, direct debit via PayPal, or – if offered – "purchase on account" or "installment payment" via PayPal, PayPal reserves the right to conduct a credit check. For this purpose, your payment data may be transferred to credit agencies in accordance with Art. 6 Para. 1 lit. f GDPR based on PayPal's legitimate interest in determining your creditworthiness. PayPal uses the result of the credit check regarding the statistical probability of payment default to decide whether to offer the respective payment method. The credit check may contain probability values (so-called score values). If score values are included in the result of the credit check, they are based on a scientifically recognized mathematical-statistical procedure. Address data is among the data used, but not the only data, in the calculation of the score values. For further information on data protection, including the credit agencies used, please refer to PayPal's Privacy Statement. https://www.paypal.com /de /webapps /mpp /ua /privacy-full
You can object to this processing of your data at any time by sending a message to PayPal. However, PayPal may still be entitled to process your personal data if this is necessary for the contractual processing of payments.
- Paypal Checkout
This website uses PayPal Checkout, an online payment system from PayPal, which consists of PayPal's own payment methods and local payment methods from third-party providers.
When paying via PayPal, credit card via PayPal, direct debit via PayPal, or – if offered – "Pay Later" via PayPal, we forward your payment data to PayPal (Europe) Sarl et Cie, SCA, 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter "PayPal") for payment processing. This transfer is carried out in accordance with Art. 6 para. 1 lit. b GDPR and only to the extent necessary for payment processing.
For the payment methods credit card via PayPal, direct debit via PayPal, or – if offered – "Pay later" via PayPal, PayPal reserves the right to conduct a credit check. For this purpose, your payment data may be forwarded to credit agencies in accordance with Art. 6 Para. 1 lit. f GDPR, based on PayPal's legitimate interest in assessing your creditworthiness. PayPal uses the result of the credit check regarding the statistical probability of payment default to decide whether to offer the respective payment method. The credit check may include probability values (so-called score values). If score values are included in the result of the credit check, they are based on a scientifically recognized mathematical-statistical procedure. Address data is among the data used to calculate the score values, but is not the only factor. You can object to this processing of your data at any time by sending a message to PayPal. However, PayPal may still be entitled to process your personal data if this is necessary for the contractual processing of payments.
When you select the PayPal payment method "purchase on account," your payment data will first be transmitted to PayPal to prepare the payment. PayPal will then forward this data to Ratepay GmbH, Franklinstrasse 28-29, 10587 Berlin ("Ratepay") for payment processing. The legal basis for this is Article 6(1)(b) GDPR. In this case, Ratepay conducts an identity and credit check on its own behalf to determine your creditworthiness, in accordance with the principle already mentioned above, and forwards your payment data to credit agencies based on its legitimate interest in determining creditworthiness pursuant to Article 6(1)(f) GDPR. A list of the credit agencies that Ratepay may consult can be found here: https://www.ratepay.com/legal-payment-creditagencies/
When using a payment method from a local third-party provider, your payment data will first be forwarded to PayPal in accordance with Article 6(1)(b) GDPR to prepare the payment. Depending on your selection of an available local payment method, PayPal will then transmit your payment data to the respective provider in accordance with Article 6(1)(b) GDPR to process the payment.
- Sofort (SOFORT GmbH, Theresienhöhe 12, 80339 Munich, Germany)
- iDeal (Currence Holding BV, Beethovenstraat 300 Amsterdam, Netherlands)
- giropay (Paydirekt GmbH, Stephanstr. 14-16, 60313 Frankfurt am Main
- bancontact (Bancontact Payconiq Company, Rue d'Arlon 82, 1040 Brussels, Belgium)
- blik (Polski Standard Płatności sp. z oo, ul. Czerniakowska 87A, 00-718 Warsaw, Poland)
- eps (PSA Payment Services Austria GmbH, Handelskai 92, Gate 2
1200 Vienna, Austria)
- MyBank (PRETA SAS, 40 Rue de Courcelles, F-75008 Paris, France)
- Przelewy24 (PayPro SA, Kanclerska 15A, 60-326 Poznań, Poland)
For further information regarding data protection, please refer to PayPal's privacy policy: https://www.paypal.com /de /webapps /mpp /ua /privacy-full
- Shopify Payments
We use the payment service provider "Shopify Payments", 3rd Floor, Europa House, Harcourt Building, Harcourt Street, Dublin 2. If you choose a payment method offered via Shopify Payments, payment processing is handled by the technical service provider Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland, to whom we transfer the information you provided during the ordering process, along with information about your order (name, address, account number, bank code, possibly credit card number, invoice amount, currency, and transaction number) in accordance with Article 6 Paragraph 1 Letter b GDPR. Your data is transferred exclusively for the purpose of payment processing with Stripe Payments Europe Ltd. and only to the extent necessary for this purpose. Further information on Shopify Payments' data protection practices can be found at the following web address: https://www.shopify.com/legal/privacy .
You can find information on data protection regarding Stripe Payments Europe Ltd. here: https://stripe.com /de /privacy
- IMMEDIATELY
When selecting the payment method "SOFORT," payment processing is handled by the payment service provider SOFORT GmbH, Theresienhöhe 12, 80339 Munich, Germany (hereinafter "SOFORT"), to whom we transfer the information you provided during the ordering process, along with information about your order, in accordance with Article 6 Paragraph 1 Letter b GDPR. SOFORT GmbH is part of the Klarna Group (Klarna Bank AB (publ), Sveavägen 46, 11134 Stockholm, Sweden). Your data is transferred exclusively for the purpose of payment processing with the payment service provider SOFORT and only to the extent necessary for this purpose. You can find further information about SOFORT's data protection policy at the following web address: https://www.klarna.com/sofort/datenschutz .
- bancontact
If you choose the "Bancontact" payment method, payment processing will be handled by Bancontact Payconiq Company, Rue d'Arlon 82, 1040 Brussels, Belgium, to whom we will transfer the information you provided during the ordering process, along with information about your order (name, address, account number, sort code, credit card number (if applicable), invoice amount, currency, and transaction number). Your data will be transferred solely for the purpose of payment processing and only to the extent necessary for this purpose.
9) Online Marketing
Facebook Pixel for creating Custom Audiences with advanced data matching (with cookie consent tool)
Within our online service, the so-called "Facebook pixel" of the social network Facebook is used in the mode of extended data matching, which is operated by Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland ("Facebook").
Based on the user's explicit consent, when a user clicks on an advertisement we have placed on Facebook, the Facebook Pixel adds a parameter to the URL of our linked page. This URL parameter is then stored in the user's browser via a cookie set by our linked page itself. This cookie also collects specific customer data, such as the email address, which we collect on our website linked to the Facebook ad during processes like purchases, account logins, or registrations (extended matching). The Facebook Pixel then reads this cookie and transmits the data, including the specific customer data, to Facebook.
With the help of the Facebook pixel with advanced matching, Facebook can precisely identify visitors to our website as a target audience for displaying advertisements (so-called "Facebook Ads"). Accordingly, we use the Facebook pixel with advanced matching to ensure that the Facebook Ads we place are only shown to Facebook users who have demonstrated an interest in our website or who exhibit certain characteristics (e.g., interests in specific topics or products, determined based on the websites they visit) that we transmit to Facebook (so-called "Custom Audiences"). We also use the Facebook pixel with advanced matching to ensure that our Facebook Ads correspond to the potential interests of users and are not perceived as intrusive. Furthermore, we can evaluate the effectiveness of Facebook ads for statistical and market research purposes by tracking whether users were redirected to our website after clicking on a Facebook ad (so-called "conversion"). Compared to the standard version of Facebook Pixel, the enhanced matching feature helps us to better measure the effectiveness of our advertising campaigns by capturing more attributed conversions.
All transmitted data is stored and processed by Facebook, so that a connection to the respective user profile is possible and Facebook uses the data for its own advertising purposes, in accordance with the Facebook Data Policy ( https://www.facebook.com/about/privacy/). ) can use the data. This data can enable Facebook and its partners to display advertisements on and off Facebook.
These processing operations are carried out exclusively with the express consent given in accordance with Art. 6 para. 1 lit. a GDPR.
The information generated by Facebook is generally transmitted to and stored on a Facebook server. This may also involve transmission to the servers of Meta Platforms Inc. in the USA. You can revoke your consent at any time with effect for the future by deactivating this service in the "cookie consent tool" provided on the website.
10) Web analytics services
Google (Universal) Analytics
This website uses Google (Universal) Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"). Google (Universal) Analytics uses "cookies," which are text files placed on your computer, to help the website analyze how users use the site. The information generated by the cookie about your use of the website (including your truncated IP address) will generally be transmitted to and stored by Google on servers in the United States.
This website uses Google (Universal) Analytics exclusively with the extension "_anonymizeIp()", which ensures anonymization of the IP address by truncation and prevents direct identification of individuals. With this extension, your IP address is truncated by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before being transmitted. Only in exceptional cases will the full IP address be transmitted to a Google LLC server in the USA and truncated there. On our behalf, Google will use this information to evaluate your use of the website, to compile reports on website activity, and to provide us with other services relating to website activity and internet usage. The IP address transmitted by your browser as part of Google (Universal) Analytics will not be merged with other Google data.
Google Analytics offers a special feature called "demographics," which allows for the creation of statistics about the age, gender, and interests of website visitors based on an analysis of interest-based advertising and third-party information. This enables the definition and differentiation of website user groups for the purpose of targeted marketing efforts. However, data collected via "demographics" cannot be attributed to any specific individual.
Details about the processing initiated by Google Analytics and how Google handles website data can be found here: https://policies.google.com/technologies/partner-sites
All processing described above, in particular the setting of Google Analytics cookies for reading information on your device, will only be carried out if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. Without this consent, Google Analytics will not be used during your visit to our website.
You can withdraw your consent at any time with effect for the future. To exercise your right of withdrawal, please deactivate this service in the "Cookie Consent Tool" provided on the website.
This website may also use the "Google Signals" service as an extension of Google Analytics. Google Signals allows Google to generate cross-device reports (so-called "cross-device tracking"). If you have activated "personalized ads" in your Google account settings and have linked your internet-enabled devices to your Google account, Google can analyze user behavior across devices and create database models based on this analysis, provided you have given your consent to the use of Google Analytics in accordance with Art. 6 Para. 1 lit. a GDPR. This analysis takes into account the logins and device types of all website visitors who were logged into a Google account and completed a conversion. The data shows, among other things, on which device you first clicked on an ad and on which device the corresponding conversion took place. When Google Signals is used, we do not receive any personal data from Google, but only statistics generated based on Google Signals. You have the option to deactivate the "personalized ads" function in your Google account settings and thus disable cross-device analysis. Follow the instructions on this page: https://support.google.com /ads /answer /2662922 ?hl=de
Further information can be found here: https://support.google.com /analytics /answer /7532985 ?hl=de
As an extension of Google Analytics, this website may also use the "UserIDs" function. By assigning individual UserIDs, we can have Google generate cross-device reports (so-called "cross-device tracking"). This means that, with your consent to the use of Google Analytics in accordance with Art. 6 Para. 1 lit. a GDPR, your usage behavior can also be analyzed across devices if you have created a personal account by registering on this website and are logged into your account on different devices using your login credentials. The data collected in this way shows, among other things, on which device you first clicked on an ad and on which device the corresponding conversion took place.
We have entered into a data processing agreement with Google for the use of Google Analytics, which obliges Google to protect the data of our website visitors and not to pass it on to third parties.
For the transfer of data from the EU to the USA, Google relies on so-called standard data protection clauses of the European Commission, which are intended to ensure compliance with the European level of data protection in the USA.
Further information about Google (Universal) Analytics can be found here: https://policies.google.com/privacy ?hl=de &gl=de
11) Retargeting/ Remarketing/ Referral Advertising
TikTok Pixel
This website uses the “TikTok Pixel”, a tracking technology of the social network “TikTok” by TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland (“TikTok”).
Cookies (small text files stored on your device) are used to collect pseudonymized information about your browsing behavior on our website, transmit it to TikTok, where it is stored and analyzed to enable the display of interest-based and personalized product recommendations on TikTok. The information collected and processed in this pseudonymized form generally includes the device ID, device type, timestamp, operating system, and IP address. This information can be linked to the user by using other information that TikTok has stored about the user, for example, due to their account on the social network "TikTok." TikTok can also combine the information collected via the pixel with other information that TikTok has collected from other websites and/or in connection with the use of the social network "TikTok" to create pseudonymized user profiles. Under no circumstances can the collected information be used to personally identify visitors to this website.
The TikTok pixel allows us to track the effectiveness of ads on TikTok. If a user is redirected from a TikTok ad to pages on this website and the cookies have not yet expired, the pixel records and tracks certain user actions that we have predefined (e.g., completed transactions, leads, website searches, product page views). When such an action is performed, your browser sends an HTTP request from the cookie to TikTok's server via the TikTok pixel, transmitting certain information about the action. This transmission allows TikTok to compile statistics on user behavior on our website after redirection from a TikTok ad, which we use to optimize our offerings.
All processing described above, in particular the setting of cookies for reading information on the device used, will only be carried out if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future by deactivating this service in the "Cookie Consent Tool" provided on the website. We have concluded a data processing agreement with TikTok for the use of the TikTok Pixel, which obliges TikTok to protect the data of our website visitors and not to pass it on to third parties. TikTok generally transfers collected information outside the European Economic Area and relies on so-called standard contractual clauses of the European Commission, which are intended to ensure compliance with the European level of data protection.
12) Page functionalities
12.1 Facebook Plugins with 2-click solution
Our website uses so-called social plugins ("plugins") from the social network Facebook, which is operated by Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland ("Facebook").
To enhance the protection of your data when visiting our website, the plugins are initially deactivated and integrated using a so-called "2-click" solution. You can recognize deactivated plugins by their gray background. This integration ensures that no connection to Facebook's servers is established when you access a page on our website containing such plugins. Only when you activate the plugins and thereby give your consent to the data transfer in accordance with Art. 6 Para. 1 lit. a GDPR, does your browser establish a direct connection to Facebook's servers. The content of the respective plugin is then transmitted directly to your browser and integrated into the page. The plugin then transmits data (including your IP address) to Facebook. We have no influence on the scope of the data that Facebook collects using the plugins. To our knowledge, Facebook receives information about which of our websites you are currently and previously visiting. By integrating these plugins, Facebook receives information that your browser has accessed the corresponding page of our website, even if you do not have a Facebook profile or are not currently logged in. The collected information (including your IP address) is transmitted directly from your browser to a server of Meta Platforms Inc. in the USA and stored there. When you interact with the plugins, the corresponding information is also transmitted directly to a Facebook server and stored there. This information is also published on Facebook and displayed to your contacts.
You can withdraw your consent at any time by deactivating the plugin by clicking it again. However, this withdrawal does not affect data that has already been transferred to Facebook.
For information on the purpose and scope of data collection and the further processing and use of data by Facebook, as well as your related rights and privacy settings, please refer to Facebook's privacy policy: https://www.facebook.com/policy.php
12.2 Instagram plugin as a Shariff solution
Our website uses so-called social plugins (“plugins”) from the online service Instagram, which is operated by Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2 Ireland (“Facebook”).
To enhance the protection of your data when visiting our website, these buttons are not fully integrated as plugins, but rather embedded using an HTML link. This method ensures that no connection to Instagram's servers is established when you access a page on our website containing these buttons. When you click the button, a new browser window opens and takes you to the Instagram page, where you can interact with the plugins there (after entering your login details, if necessary).
For information on the purpose and scope of data collection and the further processing and use of data by Instagram, as well as your related rights and privacy settings, please refer to Instagram's privacy policy: https://help.instagram.com/155833707900388/
12.3 Use of YouTube videos
This website uses the YouTube embedding function to display and play videos from the provider "YouTube", which belongs to Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google").
This uses enhanced privacy mode, which, according to the provider, only initiates the storage of user information when the video(s) are played. When embedded YouTube videos are played, the provider "YouTube" sets cookies to collect information about user behavior. According to YouTube, this information is used, among other things, to collect video statistics, improve user-friendliness, and prevent misuse. If you are logged into Google, your data will be directly associated with your account when you click on a video. If you do not want this association with your YouTube profile, you must log out before activating the button. You have the right to object to the creation of these user profiles, and to exercise this right, you must contact YouTube. When using YouTube, personal data may also be transferred to the servers of Google LLC in the USA.
Regardless of whether the embedded videos are played, a connection to the Google network is established every time this website is accessed, which may trigger further data processing operations beyond our control.
All processing described above, in particular the reading of information on the device used via the tracking pixel, will only be carried out if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. Without this consent, YouTube videos will not be used during your visit to our website.
You can withdraw your consent at any time with effect for the future. To exercise your right of withdrawal, please deactivate this service in the "Cookie Consent Tool" provided on the website, using the alternative methods explained to you on the website.
Further information on data protection at "YouTube" can be found in the YouTube Terms of Service at https://www.youtube.com/static ?template=terms as well as in Google's privacy policy at https://www.google.de /intl /de /policies /privacy
12.4 Shopsync for Shopify
This website uses the Shopify app “Shopsync” by ShopSync LLC, PO Box 252, Jefferson City, TN 37760, USA.
ShopSync synchronizes the newsletter service "Mailchimp" with our Shopify account so that, on the one hand, updates in Mailchimp email lists (such as a newsletter recipient opting out) are automatically stored on Shopify, and on the other hand, new contact details generated through contracts concluded on Shopify are automatically transferred to Mailchimp's email lists.
In the first case, data processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interest in the effective and system-wide maintenance of the files of advertising recipients and the efficient observance of legally significant status changes.
In the second case, only on the basis of the user's explicit consent in accordance with Art. 6 para. 1 lit. a GDPR, after a contract has been concluded on Shopify, will ShopSync transfer the user's first and last name, address and email address together with transaction-related information (purchase amount, time and date of purchase) to Mailchimp for inclusion in the Mailchimp list.
Data transferred in this way is not stored or retained by ShopSync after synchronization. All information synchronized between Shopify and Mailchimp is transmitted using SSL (Secure Socket Layer) technology, and all transmitted information remains encrypted during the synchronization process.
The synchronization process requires the transfer of information via a secure connection to servers hosted by Amazon Web Services in the USA.
Further information regarding data protection in relation to ShopSync can be found here: https://shopsync.io /privacy-policy
13) Tools and other items
Cookie consent tool
This website uses a "cookie consent tool" to obtain valid user consent for cookies and cookie-based applications that require consent. The cookie consent tool is displayed to users upon visiting the site as an interactive interface, where consent for specific cookies and/or cookie-based applications can be granted by ticking boxes. By using this tool, all cookies/services requiring consent are only loaded if the respective user grants the corresponding consent by ticking the boxes. This ensures that such cookies are only placed on the user's device if consent has been given.
This tool uses technically necessary cookies to store your cookie preferences. No personal user data is processed in this process.
If, in individual cases, personal data (such as the IP address) is processed for the purpose of storing, assigning or logging cookie settings, this is done in accordance with Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interest in a legally compliant, user-specific and user-friendly consent management for cookies and thus in a legally compliant design of our website.
A further legal basis for processing is Article 6(1)(c) GDPR. As data controllers, we are subject to the legal obligation to make the use of cookies that are not technically necessary dependent on the respective user's consent.
We have concluded a data processing agreement with the provider, which ensures the protection of the data of our website visitors and prohibits unauthorized disclosure to third parties.
Further information about the operator and the settings options of the cookie consent tool can be found directly in the corresponding user interface on our website.
14) Rights of the data subject
14.1 The applicable data protection law grants you the following rights as a data subject (rights of access and intervention) vis-à-vis the controller with regard to the processing of your personal data, whereby reference is made to the legal basis stated for the respective conditions for exercising these rights:
- Right of access pursuant to Art. 15 GDPR;
- Right to rectification pursuant to Article 16 GDPR;
- Right to erasure pursuant to Article 17 GDPR;
- Right to restriction of processing pursuant to Article 18 GDPR;
- Right to information pursuant to Article 19 GDPR;
- Right to data portability pursuant to Art. 20 GDPR;
- Right to withdraw consent pursuant to Art. 7 para. 3 GDPR;
- Right to lodge a complaint pursuant to Article 77 GDPR.
14.2 Right of objection
If we process your personal data based on our overriding legitimate interest as part of a balancing of interests, you have the right to object to this processing at any time, on grounds relating to your particular situation, with effect for the future.
If you exercise your right to object, we will cease processing the data in question. However, further processing remains possible if we can demonstrate compelling legitimate grounds for the processing which override your interests, fundamental rights and freedoms, or if the processing serves the purpose of establishing, exercising or defending legal claims.
If we process your personal data for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such marketing. You can exercise your right to object as described above.
If you exercise your right to object, we will cease processing the data in question for direct marketing purposes.
15) Duration of storage of personal data
The duration of the storage of personal data is determined by the respective legal basis, the purpose of processing and – if applicable – additionally by the respective statutory retention period (e.g. commercial and tax law retention periods).
When processing personal data on the basis of explicit consent pursuant to Art. 6 para. 1 lit. a GDPR, this data will be stored until the data subject withdraws his or her consent.
If statutory retention periods exist for data processed in the context of contractual or quasi-contractual obligations on the basis of Art. 6 para. 1 lit. b GDPR, this data will be routinely deleted after the expiry of the retention periods, provided that it is no longer required for the performance of a contract or for initiating a contract and/or we no longer have a legitimate interest in its continued storage.
When processing personal data on the basis of Article 6(1)(f) GDPR, this data will be stored until the data subject exercises their right to object pursuant to Article 21(1) GDPR, unless we can demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or the processing serves the purpose of establishing, exercising or defending legal claims.
When processing personal data for direct marketing purposes on the basis of Art. 6 para. 1 lit. f GDPR, this data will be stored until the data subject exercises his or her right to object pursuant to Art. 21 para. 2 GDPR.
Unless otherwise stated in the other information in this declaration regarding specific processing situations, stored personal data will be deleted when it is no longer necessary for the purposes for which it was collected or otherwise processed.