Privacy policy
Last updated: September 04, 2026
1. Controller
This Privacy Policy applies to the official website and online store of the band Mental Cruelty.
The controller responsible for the processing of personal data within the meaning of the General Data Protection Regulation (“GDPR”) is:
Blasphemous Arts Entertainment GbR
Hohbergstraße 17
76337 Waldbronn
Germany
Email: shop@mentalcrueltyofficial.com
Blasphemous Arts Entertainment GbR operates the official Mental Cruelty website and online store. In this Privacy Policy, Blasphemous Arts Entertainment GbR is also referred to as “we”, “us” or “our”.
2. General Information and Legal Bases
This Privacy Policy explains how we process personal data when you visit our website, use our online store, communicate with us, subscribe to marketing communications, interact with our advertising, begin a checkout or place an order.
Personal data means any information relating to an identified or identifiable natural person. This includes, for example, your name, postal address, email address, telephone number, IP address, device identifiers, online identifiers, marketing preferences and information concerning your orders or interactions with our store.
We process personal data only where a legal basis permits us to do so. Depending on the relevant processing activity, the legal bases are primarily:
-
Article 6(1)(a) GDPR where you have given consent;
-
Article 6(1)(b) GDPR where processing is necessary to take steps at your request before entering into a contract or to perform a contract;
-
Article 6(1)(c) GDPR where processing is necessary to comply with a legal obligation; and
-
Article 6(1)(f) GDPR where processing is necessary for our legitimate interests or those of a third party and those interests are not overridden by your interests, rights or freedoms.
Where information is stored on, or accessed from, your device, Sections 25(1) and 25(2) of the German Telecommunications and Digital Services Data Protection Act (“TDDDG”) may also apply.
3. Shopify: Store Operation, Hosting and Enhanced Services
Our online store is operated using Shopify’s e-commerce platform. The Shopify entity generally responsible for merchants established in the European Economic Area is:
Shopify International Limited
2nd Floor, Victoria Buildings
1–2 Haddington Road
Dublin 4, D04 XN32
Ireland
Shopify provides the technical infrastructure required to host and operate our website, display products, provide shopping-cart and checkout functions, maintain customer accounts, process and manage orders, send store communications, provide analytics and marketing functionality, and protect the store against fraud, misuse and security threats.
When you interact with our store, Shopify may process:
-
contact and identification information, including your name, email address and telephone number;
-
billing and delivery addresses;
-
IP address, browser, operating system, device and network information;
-
pages and products viewed, searches and other interactions with our store;
-
cookie identifiers, client identifiers and other online identifiers;
-
shopping-cart and checkout information;
-
order, transaction, payment-status, shipping, return and refund information;
-
customer-account and marketing-preference information; and
-
technical log, security, fraud and diagnostic data.
This processing is based on Article 6(1)(b) GDPR where necessary to enter into or perform a contract and otherwise on Article 6(1)(f) GDPR. Our legitimate interests are the secure, reliable and efficient operation of our store, customer service, fraud prevention and the protection of our systems and customers.
For most store services, Shopify processes personal data on our behalf. For certain services that customers use directly with Shopify, and for certain Enhanced Services, Shopify may process personal data as an independent controller.
Shopify Network Intelligence and Enhanced Services
We have enabled Shopify Network Intelligence. Shopify may therefore use certain customer and interaction data from our store together with information arising from your interactions with Shopify and other Shopify merchants to provide Enhanced Services. These services may include improved fraud prevention, analytics, measurement, advertising, product recommendations and personalisation.
Depending on the particular service, Shopify may process personal data on our behalf or as an independent controller.
Where required in the European Economic Area, the United Kingdom or Switzerland, non-essential processing for advertising or personalisation based on your activity in our store, with Shopify or with other Shopify merchants is activated only after you have given the relevant consent through the privacy controls available on our website.
You may withdraw your consent at any time with effect for the future by reopening the privacy settings on our website.
Further information about Shopify’s processing, privacy choices and data-subject rights is available in Shopify’s Consumer Privacy Policy and privacy portal:
Shopify Consumer Privacy Policy
Information about Shopify’s subprocessors is available at:
4. Website Access and Technical Log Data
When you visit our website, technical information is processed so that the website can be delivered to your device and operated securely.
This information may include:
-
IP address;
-
date and time of access;
-
requested page or file;
-
volume of data transferred;
-
browser type and browser version;
-
operating system;
-
referring URL;
-
device and network information;
-
error reports; and
-
security events.
The processing is based on Article 6(1)(f) GDPR. Our legitimate interests are the technical availability, stability and security of the website and the detection and prevention of misuse, fraud and attacks.
Technical log and security data is deleted or anonymised when it is no longer required for these purposes, unless statutory retention obligations apply or continued storage is necessary to investigate a specific incident.
5. Cookies, Pixels and Similar Technologies
Our website uses cookies, pixels and similar technologies. These technologies can store information on, or read information from, your device.
Strictly Necessary Technologies
Strictly necessary technologies are used to provide functions expressly requested by you. These functions include:
-
shopping-cart and checkout functions;
-
session management;
-
storage of your privacy preferences;
-
load balancing;
-
account and login functions;
-
security and fraud prevention; and
-
protection against unauthorised access.
These technologies are used on the basis of Section 25(2) TDDDG. Related processing of personal data is based on Article 6(1)(b) GDPR where necessary to enter into or perform a contract and otherwise on Article 6(1)(f) GDPR. Our legitimate interests are the secure and functional operation of the online store.
Optional Analytics, Advertising and Personalisation Technologies
Optional technologies may include Shopify analytics functions, Shopify Enhanced Services and Meta advertising technologies such as the Meta Pixel, Advanced Matching and the Conversions API.
In regions where consent is required, these technologies are activated only after you have made the relevant choice through our cookie banner or privacy settings.
The legal bases are your consent under Section 25(1) TDDDG and Article 6(1)(a) GDPR.
You may withdraw your consent at any time with effect for the future by reopening the privacy settings on our website. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Rejecting optional technologies does not prevent you from using the essential shopping and checkout functions of our store. However, certain optional analytics, advertising or personalisation functions may not be available.
6. Orders, Shopping Carts and Checkouts
When you place products in your shopping cart, begin a checkout or place an order, we process the information required to prepare, conclude and fulfil the purchase contract.
This may include:
-
first and last name;
-
billing and delivery address;
-
email address;
-
telephone number;
-
products, quantities and variants selected;
-
shopping-cart and checkout information;
-
order value;
-
order and transaction numbers;
-
date and time of the order;
-
payment method and payment status;
-
shipping, delivery and customs information;
-
return, cancellation and refund information; and
-
communications relating to the order.
Required information is marked accordingly during checkout. Without this information, we will generally be unable to enter into or perform the purchase contract.
The processing is based on Article 6(1)(b) GDPR.
Where retention is required under tax, commercial or other law, the additional legal basis is Article 6(1)(c) GDPR.
Order and technical information may also be processed to prevent fraudulent, abusive or harmful transactions. This processing is based on Article 6(1)(f) GDPR. Our legitimate interests are fraud prevention and the protection of our customers, payment processes and online store.
7. Payment Using PayPal
We offer PayPal as a payment method through our online store. The provider is:
PayPal (Europe) S.à r.l. et Cie, S.C.A.
22–24 Boulevard Royal
L-2449 Luxembourg
When you select PayPal, the information required to process the payment is transmitted to PayPal.
This may include:
-
name;
-
email address;
-
billing and delivery address;
-
order number;
-
order value;
-
currency;
-
information about the products ordered; and
-
payment and transaction status.
We do not receive your PayPal login credentials or complete bank or payment-card details. PayPal provides us with the information required to confirm, allocate, refund or reject the payment.
The transfer is necessary to process your payment and perform the purchase contract and is based on Article 6(1)(b) GDPR.
PayPal processes certain information under its own responsibility, including for authentication, payment processing, fraud prevention and compliance with legal obligations.
Further information is available in PayPal’s Privacy Statement:
8. Shipping and Delivery
We use the following companies for shipping and delivery:
DPD Deutschland GmbH
Wailandtstraße 1
63741 Aschaffenburg
Germany
DHL Paket GmbH
Charles-de-Gaulle-Straße 20
53113 Bonn
Germany
Deutsche Post AG
Charles-de-Gaulle-Straße 20
53113 Bonn
Germany
The carrier used depends on the shipment’s type, size, destination and selected delivery method.
For shipping, customs clearance and delivery, we may transmit:
-
your name;
-
delivery address;
-
order, reference or shipment number;
-
shipment information required for transportation and delivery;
-
information about the contents, quantity, weight, value, country of origin or customs classification where required for customs clearance; and
-
email address or telephone number where required for customs clearance, delivery communication or delivery.
The processing is based on Article 6(1)(b) GDPR where necessary to perform the purchase contract and Article 6(1)(c) GDPR where necessary to comply with customs, export or other legal obligations.
Where optional delivery notifications are based on our legitimate interests, processing is based on Article 6(1)(f) GDPR. Our legitimate interest is reliable and customer-friendly delivery. You may object to this processing on grounds relating to your particular situation.
For international shipments, required recipient, shipment and customs information may be transmitted to affiliated companies, foreign postal services, customs agents, delivery partners and competent authorities in destination or transit countries.
These recipients may be located outside the European Union or European Economic Area. International transfers are made under an applicable adequacy decision, appropriate safeguards under Article 46 GDPR or, where necessary to deliver an order, an applicable derogation under Article 49 GDPR.
Further information is available at:
9. Shipping Rates & Rules App
We use the Shopify app “Shipping Rates & Rules” to calculate, display and apply shipping and delivery rules.
For this purpose, the app may access information required to determine the available shipping method or rate, including:
-
products and product information;
-
shopping-cart and order information;
-
delivery destination;
-
customer address;
-
name, email address or telephone number where technically required;
-
IP address;
-
browser and operating-system information; and
-
approximate location or device information.
The processing is based on Article 6(1)(b) GDPR where required to provide a requested shipping option and otherwise on Article 6(1)(f) GDPR. Our legitimate interests are accurate shipping calculations and the reliable operation of our checkout and delivery processes.
The app provider processes personal data on our behalf to the extent agreed with us.
10. Customer Accounts
Where customer accounts are offered and used, we process the information required to create, secure and administer the account, display order history, manage addresses and preferences and provide requested account functions.
This may include:
-
name and contact information;
-
authentication and account information;
-
billing and delivery addresses;
-
order history;
-
account preferences; and
-
account activity.
The processing is based on Article 6(1)(b) GDPR and, for account security and misuse prevention, Article 6(1)(f) GDPR. Our legitimate interests are providing secure customer-account functions and preventing unauthorised access.
11. Contacting Us
If you contact us by email, through a contact form, social media or by other means, we process the information you provide.
This may include:
-
your name;
-
email address;
-
telephone number;
-
social-media username;
-
content of your message; and
-
information relating to an order.
Where your enquiry relates to a contract or potential order, the processing is based on Article 6(1)(b) GDPR.
Other enquiries are processed on the basis of Article 6(1)(f) GDPR. Our legitimate interests are responding to your enquiry and maintaining customer and business relationships.
Enquiries are deleted when they have been conclusively dealt with and no statutory retention obligation or other legitimate ground for continued storage applies.
12. Transactional and Service Communications
We and Shopify send communications required to operate customer accounts, handle checkouts and orders and provide requested services.
These communications may include:
-
account verification and password-reset messages;
-
order and payment confirmations;
-
invoices and payment receipts;
-
shipping and delivery updates;
-
return, cancellation and refund communications;
-
payment-error notifications; and
-
responses to customer enquiries.
These communications are not sent for independent advertising purposes.
Processing is based on Article 6(1)(b) GDPR where necessary to enter into or perform a contract, Article 6(1)(c) GDPR where required by law and otherwise Article 6(1)(f) GDPR.
Our legitimate interests are providing customer service, documenting transactions and ensuring reliable order processing.
13. Email, SMS and WhatsApp Marketing
If you separately subscribe to marketing by email, SMS or WhatsApp, we process the contact details and consent information required for the selected communication channel.
Depending on the consent you provide, communications may include:
-
news about Mental Cruelty;
-
music and release announcements;
-
merchandise and product announcements;
-
pre-order information;
-
special offers;
-
event or band-related updates;
-
back-in-stock or price-change notifications; and
-
reminders about products left in your shopping cart or checkout.
Marketing communications are based on your consent under Article 6(1)(a) GDPR and the applicable requirements of Section 7 of the German Act Against Unfair Competition (“UWG”).
Consent is voluntary and is not required to place an order. Each channel is used only where the consent recorded for that channel covers the intended communication.
Consent Records and Double Opt-in
To document your consent, we may store:
-
the wording of the consent;
-
selected communication channel;
-
date and time of registration;
-
source of registration;
-
confirmation status;
-
IP address or other technical log data; and
-
the date and time of a double opt-in confirmation.
Where double opt-in is used, marketing communications are not sent until the subscription has been confirmed.
Withdrawal and Opt-out
You may withdraw your marketing consent at any time with effect for the future.
You can withdraw consent by:
-
using the unsubscribe link included in an email;
-
using the opt-out method stated in an SMS or WhatsApp message; or
-
contacting shop@mentalcrueltyofficial.com.
Withdrawal for one channel does not automatically withdraw a separate consent for another channel unless you request this.
Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
After an opt-out, the relevant email address or telephone number may be retained on a suppression list to ensure that the request continues to be respected.
This processing is based on Article 6(1)(f) GDPR. Our legitimate interests are complying with opt-out requests, preventing unwanted advertising and documenting compliance.
14. OnPitch
We use the OnPitch app, operated by OnPitch Holdings Inc., to synchronise marketing preferences, manage subscribers, create audience segments, send email, SMS and WhatsApp communications, process opt-outs and attribute purchases to marketing campaigns.
Depending on the services and campaigns used, OnPitch may process:
-
name;
-
email address;
-
telephone number;
-
postal address or country;
-
email, SMS and WhatsApp marketing-consent status;
-
products and product interests;
-
complete or partial order history;
-
total spend;
-
purchase frequency;
-
campaign delivery status;
-
opening and click information;
-
replies and opt-outs;
-
campaign conversion information;
-
IP address;
-
browser and operating-system information;
-
approximate location information; and
-
technical identifiers and app authentication information.
OnPitch processes this information on our behalf for subscriber synchronisation, audience segmentation, campaign delivery, consent management and campaign measurement.
Audience segments may be based on location, purchase history, purchase frequency, product interests or customer value. Segmentation is used to select relevant recipients for communications. We do not use it to make decisions that produce legal effects or similarly significantly affect you.
Marketing communications sent through OnPitch are based on your consent under Article 6(1)(a) GDPR and Section 7 UWG.
OnPitch is instructed to respect the marketing preferences recorded for the relevant channel and to process opt-outs. You may withdraw your consent as described in Section 13.
Further information about OnPitch is available at:
15. Abandoned Checkout and Cart Reminders
If you have expressly consented to receive marketing communications that include checkout or shopping-cart reminders, Shopify Messaging or OnPitch may use your email address or telephone number together with information about products placed in your shopping cart or checkout.
The purpose is to remind you that the checkout was not completed and to provide a link allowing you to continue it.
The information processed may include:
-
email address or telephone number;
-
products, quantities and variants selected;
-
shopping-cart or checkout identifier;
-
date and time of the checkout;
-
checkout status; and
-
interactions with the reminder.
The processing and sending of these reminders is based on your consent under Article 6(1)(a) GDPR and the applicable requirements of Section 7 UWG.
You may withdraw your consent at any time as described in Section 13.
Entering an email address or telephone number during checkout does not, by itself, constitute consent to receive advertising reminders.
16. Facebook and Instagram by Meta
We use the Facebook & Instagram sales channel provided by:
Meta Platforms Ireland Limited
Merrion Road
Dublin 4, D04 X2K5
Ireland
We use this service to:
-
synchronise our product catalogue;
-
display or promote products on Facebook and Instagram;
-
measure advertising performance;
-
analyse conversions;
-
create advertising audiences; and
-
subject to your consent, show more relevant advertising.
Meta Pixel, Advanced Matching and Conversions API
Our current Meta data-sharing setting uses the Meta Pixel, Advanced Matching and the Conversions API.
If you give the relevant consent, these technologies may process or transmit to Meta:
-
IP address;
-
browser and device information;
-
cookie and client identifiers;
-
pages and products viewed;
-
search and browsing behaviour;
-
additions to a shopping cart;
-
checkout events;
-
purchases;
-
product identifiers;
-
order value and currency;
-
name;
-
email address;
-
telephone number; and
-
location or address information.
Contact or matching information may be normalised or cryptographically hashed before transmission. Hashing does not necessarily make the information anonymous because Meta may use it to match information to an existing Meta account.
The purposes are to measure advertisements and conversions, create or address advertising audiences, limit or optimise advertising delivery and display more relevant advertising on Meta services.
Optional storage or access on your device is based on your consent under Section 25(1) TDDDG. The related processing of personal data is based on Article 6(1)(a) GDPR.
You may withdraw your consent at any time with effect for the future through the privacy settings available on our website.
Joint Responsibility with Meta
For certain collection and transmission activities involving Meta Business Tools, we and Meta may act as joint controllers.
Meta’s Controller Addendum determines the allocation of responsibilities for these activities. For Meta’s subsequent processing, including matching information to Meta accounts, measurement, security and advertising on Meta services, Meta may act as an independent controller.
Product Catalogue
Our public product catalogue may be transmitted to Meta even where no advertising consent has been given.
Catalogue information normally concerns our publicly offered products and may include:
-
product names;
-
descriptions;
-
images;
-
variants;
-
prices;
-
availability; and
-
links to our store.
If you interact directly with Facebook or Instagram, Meta’s own privacy information applies.
Further information is available at:
17. Shopify Messaging and Shop Remarketing
We use Shopify Messaging to manage marketing communications and automations.
Depending on the settings enabled and choices made by a Shop user, Shopify’s Shop service may also send email or push notifications concerning:
-
a shopping cart that was not completed;
-
a previously viewed item that is back in stock;
-
a reduction in the price of a previously viewed item; or
-
repeated interest in products from our store.
These reminders may use:
-
Shopify or Shop account information;
-
email address;
-
push-notification identifiers;
-
interactions with our store;
-
product views;
-
shopping-cart activity;
-
checkout activity; and
-
order information.
Where we determine the purpose of a marketing communication, processing is based on consent under Article 6(1)(a) GDPR and Section 7 UWG.
Where Shopify or the Shop service independently determines the purposes and means of a Shop-account feature, Shopify’s Consumer Privacy Policy applies.
You can manage marketing subscriptions through the unsubscribe option included in a message. Shop users can also manage notifications and privacy choices through their Shop or Shopify settings.
18. Shopify Catalog and Agentic Storefronts
We allow Shopify Catalog to distribute our public store and product information to supported AI-powered discovery and shopping channels.
Depending on availability and our Shopify settings, these channels may include:
-
ChatGPT;
-
Google AI Mode or Gemini;
-
Microsoft Copilot; and
-
Meta.
The information distributed normally concerns our store and products and may include:
-
product title;
-
product description;
-
product images;
-
product options and variants;
-
price;
-
availability;
-
product category; and
-
other public catalogue attributes.
This allows users to find and compare our products and receive product recommendations through supported AI channels.
Shopify and the relevant AI channel may determine how products are ranked, described or presented within their respective services.
Shopify Catalog access does not, by itself, provide AI channels with our general customer database or complete order history.
If an AI channel offers a Shopify-powered direct checkout and we enable that feature, information required to complete the checkout and order may be processed by Shopify and the relevant channel. The processing described in Sections 3, 6, 7 and 8 applies accordingly, together with the privacy information provided by the relevant channel.
Where an AI channel only refers you to our online store, the checkout takes place through Shopify.
The distribution of public product information and operation of these discovery or sales channels is based on Article 6(1)(f) GDPR. Our legitimate interests are making our products discoverable and providing customers with additional ways to access our store.
When you interact directly with an external AI channel, the channel’s own privacy information also applies.
19. Recipients of Personal Data
We disclose personal data only where necessary to perform a contract, provide a requested service, comply with a legal obligation, protect a legitimate interest or where you have given consent.
Recipients or categories of recipients may include:
-
Shopify and companies or subprocessors within the Shopify group;
-
PayPal for payment processing;
-
DPD, DHL and Deutsche Post;
-
international postal, customs and delivery partners;
-
the provider of the Shipping Rates & Rules app;
-
OnPitch for subscriber management, segmentation and email, SMS or WhatsApp communications;
-
Meta for catalogue synchronisation, advertising and measurement;
-
providers involved in Shopify Messaging and Shop;
-
providers involved in Shopify Network Intelligence and Enhanced Services;
-
supported Shopify Catalog and agentic storefront channels;
-
IT, hosting, security and communications service providers;
-
tax advisers, accounting service providers, lawyers and other professional advisers;
-
banks and financial service providers; and
-
authorities, courts or other public bodies where disclosure is legally required.
We do not sell personal data to data brokers.
Data sharing for advertising or personalisation is carried out only as described in this Privacy Policy and subject to the consent and privacy controls required by applicable law.
20. International Data Transfers
Shopify, Meta, OnPitch, PayPal and their affiliated companies or subprocessors may process personal data outside the European Union or European Economic Area.
This can include countries whose data-protection laws do not provide the same level of protection as European Union law.
Where personal data is transferred to a third country, the transfer is made, as applicable, on the basis of:
-
an adequacy decision under Article 45 GDPR;
-
appropriate safeguards under Article 46 GDPR, such as the European Commission’s Standard Contractual Clauses; or
-
an applicable derogation under Article 49 GDPR.
Where required, supplementary measures and transfer-risk assessments are used.
You may contact us for further information about the safeguards used for a particular transfer and how to obtain a copy of them.
21. Retention Periods
We retain personal data only for as long as required for the relevant purpose or for as long as statutory retention obligations apply.
In particular:
-
order, invoice, accounting and payment records are retained for the applicable German statutory periods, generally six, eight or ten years depending on the type of document and legal requirement;
-
information required to establish, exercise or defend contractual claims may be retained until the relevant limitation periods expire;
-
customer enquiries are generally deleted when they have been conclusively resolved, unless a statutory obligation or legitimate reason requires longer retention;
-
active marketing-subscription data is retained until consent is withdrawn or the subscription otherwise ends;
-
consent records may be retained for the applicable accountability and limitation periods;
-
suppression-list entries may be retained for as long as necessary to ensure that an opt-out continues to be respected;
-
incomplete shopping-cart or checkout information is retained according to the configured Shopify retention and deletion settings and is deleted or anonymised when no longer required;
-
technical log and security data is deleted or anonymised when no longer required to provide and secure the store, unless a specific incident requires longer retention;
-
customer-account data is retained until the account is deleted or the underlying relationship ends, subject to statutory retention obligations; and
-
shipping information may be retained for as long as required to complete delivery, process returns or complaints and establish, exercise or defend legal claims.
Service providers may retain information under their own legal obligations or documented retention schedules.
After the relevant retention period expires, personal data is deleted or anonymised unless another legal basis permits continued processing.
22. Sources of Personal Data
We generally receive personal data directly from you when you:
-
visit our website;
-
interact with our store;
-
interact with our advertising;
-
begin a checkout;
-
place an order;
-
create or use a customer account;
-
subscribe to communications; or
-
contact us.
We may also receive personal data:
-
from Shopify or Shop;
-
from PayPal;
-
from Meta;
-
from OnPitch;
-
from shipping, postal, customs and delivery partners; and
-
automatically through cookies, pixels, server logs and similar technologies.
23. Automated Decision-Making and Profiling
We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR.
Subject to consent where required, Shopify, Meta and OnPitch functions may analyse interactions, purchases, location, customer value, product interests or campaign engagement to create audience segments, measure advertising or personalise content.
This may constitute profiling for marketing purposes. We do not use this profiling to make decisions of the kind described in Article 22 GDPR.
Shopify, PayPal or other providers may also use automated systems to assess payment, security or fraud indicators.
Where a provider carries out such processing under its own responsibility, the provider’s own privacy information applies.
24. Your Rights
Subject to the applicable legal requirements, you have:
-
the right of access under Article 15 GDPR;
-
the right to rectification under Article 16 GDPR;
-
the right to erasure under Article 17 GDPR;
-
the right to restriction of processing under Article 18 GDPR;
-
the right to data portability under Article 20 GDPR;
-
the right to object under Article 21 GDPR;
-
the right to withdraw consent under Article 7(3) GDPR; and
-
the right to lodge a complaint with a supervisory authority under Article 77 GDPR.
You may exercise these rights by contacting us using the details provided in Section 1.
If we have reasonable doubts about your identity, we may request the additional information necessary to verify it.
Withdrawal of Consent
Where processing is based on consent, you may withdraw your consent at any time with effect for the future.
Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
Right to Object
Where personal data is processed on the basis of Article 6(1)(f) GDPR, you have the right to object at any time on grounds relating to your particular situation.
Where personal data is processed for direct marketing, you have the right to object at any time without giving reasons. This also applies to profiling to the extent that it is related to direct marketing.
Following your objection, your personal data will no longer be processed for direct-marketing purposes.
Where Shopify acts as an independent controller for Enhanced Services, you may also exercise applicable privacy rights through Shopify’s privacy portal:
25. Right to Lodge a Complaint
You have the right to lodge a complaint with a data-protection supervisory authority if you believe that the processing of your personal data infringes the GDPR.
The supervisory authority responsible for our registered place of business is:
The State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg
Heilbronner Straße 35
70191 Stuttgart
Germany
Postal address:
Postfach 10 29 32
70025 Stuttgart
Germany
Telephone: +49 711 615541-0
Email: poststelle@lfdi.bwl.de
State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg
You may also lodge a complaint with another competent supervisory authority, particularly in the EU Member State of your habitual residence, place of work or place of the alleged infringement.
26. Security
We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful loss, alteration, destruction, disclosure and unauthorised access.
No transmission or storage system can be guaranteed to be completely secure. You should therefore avoid sending particularly confidential information through unsecured communication channels.
27. External Links
Our website may contain links to websites and services operated by third parties.
The relevant third-party operator is responsible for processing personal data on its own website or service. Please review the privacy information provided by the relevant third party.
28. Changes to This Privacy Policy
We may update this Privacy Policy if our processing activities, services, providers or applicable legal requirements change.
The current version will be published on our website. The date shown at the beginning of this Privacy Policy indicates when it was last updated.