The controller responsible for processing your personal data on this website is:
[COMPANY NAME]
[STREET AND NUMBER]
[POSTCODE] [CITY]
Germany
Email: [PRIVACY EMAIL]
Phone: [PHONE NUMBER]
Data protection officer: [NAME AND CONTACT, or delete this line].
A data protection officer is mandatory only in the cases set out in § 38 BDSG — as a rule from 20 people permanently processing personal data. A small shop usually does not need one. Delete the line rather than writing “none appointed”.
When you open this site your browser automatically transmits data that our hosting provider records in log files: IP address, date and time of the request, the page requested, referrer URL, browser type and version, and operating system.
Purpose: delivering the site, security, and troubleshooting.
Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest is the technically
error-free presentation and the security of this site.
Retention: [XX] days, then deleted or anonymised.
Hosting is provided by [HOSTING PROVIDER, LEGAL NAME AND ADDRESS] on our behalf as a processor under Art. 28 GDPR.
To process an order we collect your name, delivery and billing address, email address, the items ordered, and, where you provide it, your phone number.
Purpose: performing the purchase contract, shipping, invoicing, and handling
returns and warranty claims.
Legal basis: Art. 6 (1) (b) GDPR (performance of a contract). For the retention
of invoices: Art. 6 (1) (c) GDPR together with the commercial and tax record-keeping duties in
§ 257 HGB and § 147 AO.
Retention: invoice data is kept for ten years from the end of the calendar year
in which the invoice was issued. Data not subject to a retention duty is deleted once the
contract has been fully performed and all warranty periods have expired.
We pass your delivery address to the shipping company carrying the parcel: [CARRIER, LEGAL NAME AND ADDRESS].
Card, Klarna and SEPA payments are processed by Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. We never see or store your full card number. The data you enter in the payment form goes directly to Stripe. Stripe acts as an independent controller for parts of this processing; see stripe.com/privacy.
Legal basis: Art. 6 (1) (b) GDPR.
Cryptocurrency payments. If you pay in crypto, the transaction is processed by [CRYPTO PAYMENT PROVIDER, LEGAL NAME AND ADDRESS]. We receive the payment confirmation and the amount, not your wallet’s transaction history. Note that entries on a public blockchain cannot be erased by us or by anyone else — a request for erasure under Art. 17 GDPR cannot extend to the blockchain record itself.
If you sign up for the drop alert we store your email address and the time of your sign-up. We use the double opt-in procedure: your address is only added once you have confirmed it via the link in our confirmation email.
Legal basis: Art. 6 (1) (a) GDPR (consent). You can withdraw your consent at any time using the unsubscribe link in every email, with effect for the future. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
Email delivery runs through [EMAIL SERVICE PROVIDER, LEGAL NAME AND ADDRESS] as a processor.
This site stores only what is technically necessary to run the shop: your cart, your selected shipping region and currency, and the session needed at checkout. These are strictly necessary and are set on the basis of § 25 (2) no. 2 TDDDG; they do not require consent.
[We do not use any analytics, tracking or advertising cookies.] If you add analytics, a pixel or any marketing tag later, you must add a consent banner that blocks those tools until the visitor actively agrees, and list each one here with its provider, purpose and retention.
Some of the providers listed above process data in or from third countries, in particular the United States. Such transfers take place on the basis of the European Commission’s standard contractual clauses under Art. 46 (2) (c) GDPR and, where the provider is certified, the EU–US Data Privacy Framework under Art. 45 GDPR.
List the concrete providers here once you have picked them. A generic sentence is not enough if a supervisory authority asks.
You have the right to:
To exercise any of these, write to [PRIVACY EMAIL].
Where we process your data on the basis of Art. 6 (1) (f) GDPR, you have the right to object at any time, on grounds relating to your particular situation, to that processing (Art. 21 (1) GDPR). If we process your data for direct marketing, you have the right to object at any time without giving reasons (Art. 21 (2) GDPR); we will then stop that processing.
You have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, place of work or the place of the alleged infringement (Art. 77 GDPR). The authority responsible for us is:
[COMPETENT SUPERVISORY AUTHORITY — the data protection authority of the federal state in which your company is registered]
We update this policy when the way we process data changes, for example when we add a payment method or an analytics tool. The version in force is always the one published here.
Last updated: 21 September 2026.