Privacy policy

Privacy Policy

Person responsible for data processing is:
Sophie Mahlo
Prager Str. 5
10779 Berlin

mail@gluckigluck.com

Phone: 01787236447

We appreciate your interest in our online shop. Protecting your privacy is very important to us. Below we provide detailed information about how we handle your data.


1. ACCESS DATA AND HOSTING

You can visit our websites without providing personal information. Each time a webpage is accessed, the web server automatically stores a so-called server log file, which contains, for example, the name of the requested file, your IP address, date and time of access, amount of data transferred, and the requesting provider (access data) and documents the access. These access data are evaluated exclusively to ensure the smooth operation of the site and to improve our offer. This serves to safeguard our overriding legitimate interests in a correct presentation of our offer within the framework of a balancing of interests according to Art. 6 para. 1 sentence 1 lit. f GDPR. All access data are deleted no later than seven days after the end of your visit to the site.


HOSTING

The services for hosting and displaying the website are partly provided by our service providers within the framework of processing on our behalf. Unless otherwise explained in this privacy policy, all access data as well as all data collected in designated forms on this website are processed on their servers. If you have questions about our service providers and the basis of our cooperation with them, please contact the contact option described in this privacy policy.

Our service providers are located and/or use servers in the USA and other countries outside the EU and EEA. There is no adequacy decision by the European Commission for these countries. Our cooperation with them is based on standard data protection clauses of the European Commission.

Our service providers are located and/or use servers in the following countries for which the European Commission has determined an adequate level of data protection by decision: Canada


2. DATA PROCESSING FOR CONTRACT EXECUTION, CONTACT, AND NEWSLETTER SHIPPING

2.0 NEWSLETTER

Email advertising with newsletter subscription If you subscribe to our newsletter, we use the data required for this or separately provided by you to regularly send you our email newsletter based on your consent according to Art. 6 para. 1 sentence 1 lit. a GDPR. You can unsubscribe from the newsletter at any time either by sending a message to the contact option described below or via a designated link in the newsletter. After unsubscribing, we delete your email address unless you have explicitly consented to further use of your data or we reserve the right to further data use permitted by law and about which we inform you in this declaration.


2.1 DATA PROCESSING FOR CONTRACT EXECUTION

For the purpose of contract execution according to Art. 6 para. 1 sentence 1 lit. b GDPR, we collect personal data if you voluntarily provide it to us during your order. Mandatory fields are marked as such because we need the data for contract execution and cannot process the order without them. Which data is collected is evident from the respective input forms.

Further information on the processing of your data, especially on the transfer to our service providers for order, payment, and shipping processing, can be found in the following sections of this privacy policy. After complete contract execution, your data will be restricted for further processing and deleted after the expiration of tax and commercial retention periods according to Art. 6 para. 1 sentence 1 lit. c GDPR, unless you have explicitly consented to further use of your data according to Art. 6 para. 1 sentence 1 lit. a GDPR or we reserve the right to further data use permitted by law and about which we inform you in this declaration.

Inventory management system

For order and contract processing, we use inventory management systems of external service providers. Our service providers act as processors on our behalf. If you have questions about our service providers and the basis of our cooperation with them, please contact the contact option described in this privacy policy.

Our service providers are located and/or use servers in countries outside the EU and EEA. There is no adequacy decision by the European Commission for these countries. Our cooperation with them is based on standard data protection clauses of the European Commission.


2.2 CUSTOMER ACCOUNT

If you have given your consent according to Art. 6 para. 1 sentence 1 lit. a GDPR by choosing to open a customer account, we use your data for the purpose of opening the customer account and storing your data for future orders on our website. Deleting your customer account is possible at any time either by sending a message to the contact option described in this privacy policy or via a designated function in the customer account. After deletion of your customer account, your data will be deleted unless you have explicitly consented to further use of your data according to Art. 6 para. 1 sentence 1 lit. a GDPR or we reserve the right to further data use permitted by law and about which we inform you in this declaration.


2.3 CONTACT

In the context of customer communication, we collect personal data to process your inquiries according to Art. 6 para. 1 sentence 1 lit. b GDPR if you voluntarily provide it to us when contacting us (e.g., via contact form or email). Mandatory fields are marked as such because we need the data to process your contact. Which data is collected is evident from the respective input forms. After complete processing of your inquiry, your data will be deleted unless you have explicitly consented to further use of your data according to Art. 6 para. 1 sentence 1 lit. a GDPR or we reserve the right to further data use permitted by law and about which we inform you in this declaration.


3. DATA PROCESSING FOR SHIPPING PROCESSING

For contract fulfillment according to Art. 6 para. 1 sentence 1 lit. b GDPR, we pass your data to the shipping service provider commissioned with delivery, insofar as this is necessary for the delivery of ordered goods.


DATA TRANSFER TO SHIPPING SERVICE PROVIDERS FOR SHIPPING NOTIFICATION

If you have given us your explicit consent during or after your order, we pass your email address and phone number to the selected shipping service provider based on this consent according to Art. 6 para. 1 sentence 1 lit. a GDPR so that they can contact you before delivery for the purpose of delivery notification or coordination.
The consent can be revoked at any time by sending a message to the contact option described in this privacy policy or directly to the shipping service provider at the contact address listed below. After revocation, we delete your data provided for this purpose unless you have explicitly consented to further use of your data or we reserve the right to further data use permitted by law and about which we inform you in this declaration.

Amazon Fulfilment Center
Kaltbandstrasse 4
44145 Dortmund
Germany

DHL Paket GmbH
Sträßchensweg 10
53113 Bonn
Germany

United Parcel Service Deutschland S.à r.l. & Co. OHG
Görlitzer Straße 1
41460 Neuss
Germany


4. DATA PROCESSING FOR PAYMENT PROCESSING

For payment processing in our online shop, we cooperate with the following partners: technical service providers, credit institutions, payment service providers.


4.1 DATA PROCESSING FOR TRANSACTION PROCESSING

Depending on the selected payment method, we pass the data necessary for processing the payment transaction to our technical service providers, who act as processors on our behalf, or to the commissioned credit institutions or the selected payment service provider, insofar as this is necessary for payment processing. This serves contract fulfillment according to Art. 6 para. 1 sentence 1 lit. b GDPR. In part, the payment service providers collect the data necessary for payment processing themselves, e.g., on their own website or via technical integration in the ordering process. The privacy policy of the respective payment service provider applies in this regard.
If you have questions about our partners for payment processing and the basis of our cooperation with them, please contact the contact option described in this privacy policy.


4.2 DATA PROCESSING FOR FRAUD PREVENTION AND OPTIMIZATION OF OUR PAYMENT PROCESSES

We may provide our service providers with additional data, which they use together with the data necessary for payment processing as our processors for fraud prevention and optimization of our payment processes (e.g., invoicing, handling disputed payments, supporting accounting). This serves our overriding legitimate interests in protecting against fraud and efficient payment management within the framework of a balancing of interests according to Art. 6 para. 1 sentence 1 lit. f GDPR.


5. COOKIES AND OTHER TECHNOLOGIES


5.1 GENERAL INFORMATION

To make visiting our website attractive and to enable the use of certain functions, we use technologies including so-called cookies on various pages. Cookies are small text files that are automatically stored on your device. Some of the cookies we use are deleted after the end of the browser session, i.e., after closing your browser (so-called session cookies). Other cookies remain on your device and allow us to recognize your browser on your next visit (persistent cookies).
We use such technologies that are strictly necessary for the use of certain functions of our website (e.g., shopping cart function). These technologies collect and process IP address, time of visit, device and browser information, and information about your use of our website (e.g., information about the contents of the shopping cart). This serves our overriding legitimate interests in an optimized presentation of our offer within the framework of a balancing of interests according to Art. 6 para. 1 sentence 1 lit. f GDPR.

We also use technologies to fulfill legal obligations we are subject to (e.g., to prove consent to the processing of your personal data) as well as for web analysis and online marketing. Further information including the legal basis for data processing can be found in the following sections of this privacy policy.

Cookie settings for your browser can be found at the following links: Microsoft Edge™ [https://support.microsoft.com/de-de/help/4027947/microsoft-edge-delete-cookies] / Safari™ [https://support.apple.com/de-de/guide/safari/sfri11471/12.0/mac/10.14] / Chrome™ [https://support.google.com/chrome/answer/95647?hl=de&hlrm=en] / Firefox™ [https://support.mozilla.org/de/products/firefox/protect-your-privacy/cookies] / Opera™ [https://help.opera.com/de/latest/web-preferences/#cookies]

If you have consented to the use of technologies according to Art. 6 para. 1 sentence 1 lit. a GDPR, you can revoke your consent at any time by sending a message to the contact option described in the privacy policy. Alternatively, you can also visit the following link: https://gluckigluck.com. Not accepting cookies may limit the functionality of our website.


5.2 USE OF THE SHOPIFY CONSENT MANAGER TOOL TO MANAGE CONSENTS

On our website, we use the SHOPIFY Consent Manager Tool to inform you about the cookies and other technologies we use on our website and to obtain, manage, and document your possibly required consent to the processing of your personal data by these technologies. This is necessary according to Art. 6 para. 1 sentence 1 lit. c GDPR to fulfill our legal obligation according to Art. 7 para. 1 GDPR to be able to prove your consent to the processing of your personal data, to which we are subject. The Jimdo Consent Manager Tool is an offer of SHOPIFY Inc., 33 New Montgomery St #750, San Francisco, CA 94105 ("SHOPIFY"). After submitting your cookie declaration on our website, the SHOPIFY web server stores your IP address, date and time of your declaration, browser information, language, and URL from which the declaration was sent, as well as information about your consent behavior. In addition, a cookie is set that contains information about your consent behavior. Your data will be deleted after 365 days unless you have explicitly consented to further use of your data according to Art. 6 para. 1 sentence 1 lit. a GDPR or we reserve the right to further data use permitted by law and about which we inform you in this declaration.


6. USE OF COOKIES AND OTHER TECHNOLOGIES FOR WEB ANALYSIS AND ADVERTISING PURPOSES

If you have given your consent according to Art. 6 para. 1 sentence 1 lit. a GDPR, we use the following cookies and other technologies from third parties on our website. After the purpose ceases and the use of the respective technology ends, the data collected in this context will be deleted. You can revoke your consent at any time with effect for the future. Further information about your revocation options can be found in the section "Cookies and other technologies." Further information including the basis of our cooperation with the individual providers can be found with the individual technologies. If you have questions about the providers and the basis of our cooperation with them, please contact the contact option described in this privacy policy.


6.1 USE OF ADOBE SERVICES FOR WEB ANALYSIS AND ADVERTISING PURPOSES

We use the following technologies of Adobe Systems, Software Ireland Limited, Ireland, 4–6 Riverwalk, Citywest Business Campus, Dublin 24, Ireland ("Adobe"). The information automatically collected by Adobe technologies about your use of our website is usually transmitted to a server of Adobe, Inc., 345 Park Avenue San Jose, CA 95110-2704, USA and stored there. There is no adequacy decision by the European Commission for the USA. Our cooperation is based on standard data protection clauses of the European Commission. If your IP address is collected via Adobe technologies, it is shortened or completely replaced by a generic IP address before storage on Adobe's servers by activating appropriate settings.

ADOBE ANALYTICS

For the purpose of website analysis, data (IP address, time of visit, device and browser information, and information about your use of our website) are automatically collected and stored with Adobe Analytics, from which usage profiles are created using pseudonyms. Cookies and tags in page elements may be used for this purpose. If your IP address is collected via Adobe technologies, it is shortened or completely replaced by a generic IP address before storage on Adobe's servers by activating appropriate settings. The pseudonymized usage profiles are not merged with personal data about the pseudonym's bearer without a separate explicit consent. Adobe acts on our behalf.


6.2 USE OF GOOGLE SERVICES FOR WEB ANALYSIS AND ADVERTISING PURPOSES

We use the following technologies of Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). The information automatically collected by Google technologies about your use of our website is usually transmitted to a server of Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA and stored there. There is no adequacy decision by the European Commission for the USA. Our cooperation with them is based on standard data protection clauses of the European Commission. If your IP address is collected via Google technologies, it is shortened before storage on Google's servers by activating IP anonymization. Only in exceptional cases is the full IP address transmitted to a Google server and shortened there. Unless otherwise stated for the individual technologies, data processing is based on an agreement between joint controllers according to Art. 26 GDPR. Further information about data processing by Google can be found in Google's privacy policy [https://policies.google.com/privacy?hl=de].

GOOGLE ANALYTICS

For website analysis, data (IP address, time of visit, device and browser information, and information about your use of our website) are automatically collected and stored with Google Analytics, from which usage profiles are created using pseudonyms. Cookies may be used for this purpose. Your IP address is generally not merged with other data from Google. Data processing is based on an agreement on order processing by Google.

GOOGLE ADS

For advertising purposes in Google search results and on third-party websites, the so-called Google Remarketing Cookie is set when visiting our website, which automatically enables interest-based advertising through the collection and processing of data (IP address, time of visit, device and browser information, and information about your use of our website) and via a pseudonymous cookie ID based on the pages you visited. Further data processing only takes place if you have activated the "personalized advertising" setting in your Google account. If you are logged into Google during your visit to our website, Google uses your data together with Google Analytics data to create and define audience lists for cross-device remarketing.

For website analysis and event tracking, we measure your subsequent usage behavior via Google Ads Conversion Tracking if you have reached our website through a Google Ads advertisement. Cookies may be used for this purpose, and data (IP address, time of visit, device and browser information, and information about your use of our website based on events specified by us, such as visiting a website or newsletter registration) may be collected, from which usage profiles are created using pseudonyms.

GOOGLE MAPS

For visual representation of geographic information, Google Maps collects data about your use of the Maps functions, especially the IP address and location data, transmits it to Google, and then processes it. We have no influence on this subsequent data processing.

YOUTUBE VIDEO PLUGIN

To embed third-party content, the YouTube Video Plugin collects data (IP address, time of visit, device and browser information), transmits it to Google, and then processes it only if you play a video.


6.3 USE OF FACEBOOK SERVICES FOR WEB ANALYSIS AND ADVERTISING PURPOSES

FACEBOOK ANALYTICS

Within Facebook Analytics, statistics about visitor activities on our website are created from data collected with the Facebook Pixel about your use of our website. Data processing is based on an agreement on order processing by Facebook. Your analysis serves the optimal presentation and marketing of our website.

FACEBOOK ADS

We advertise this website on Facebook and other platforms via Facebook Ads. We determine the parameters of the respective advertising campaign. Facebook is responsible for the exact implementation, especially the decision about the placement of ads to individual users. Unless otherwise stated for the individual technologies, data processing is based on an agreement between joint controllers according to Art. 26 GDPR. The joint responsibility is limited to the collection of data and its transmission to Facebook Ireland. The subsequent data processing by Facebook Ireland is not covered by this.


7. INTEGRATION OF THE TRUSTED SHOPS TRUSTBADGE/OTHER WIDGETS

To display Trusted Shops services (e.g., quality seal, collected reviews) and to offer Trusted Shops products for buyers after an order, Trusted Shops widgets (e.g., Trusted Shops Trustbadge) are integrated on this website.

This serves our overriding legitimate interests in optimal marketing by enabling secure shopping according to Art. 6 para. 1 sentence 1 lit. f GDPR. The Trustbadge and the services advertised with it are an offer of Trusted Shops GmbH, Subbelrather Str. 15C, 50823 Cologne (Trusted Shops), with whom we are jointly responsible under Art. 26 GDPR for data protection. We inform you in this privacy notice below about the essential contractual contents according to Art. 26 para. 2 GDPR.

The Trustbadge is provided within a joint responsibility by a US-based CDN provider (Content Delivery Network). An adequate level of data protection is ensured by standard data protection clauses and other contractual measures. Further information on the data protection of Trusted Shops GmbH can be found here [https://www.trustedshops.de/impressum/#datenschutz].

When the Trustbadge is called up, the web server automatically stores a so-called server log file, which also contains your IP address, date and time of access, amount of data transferred, and the requesting provider (access data) and documents the access. The IP address is anonymized immediately after collection so that the stored data cannot be assigned to you personally. The server log file is stored in a security database for analyzing security anomalies and is automatically deleted or anonymized no later than 90 days after creation. This serves our and Trusted Shops' legitimate interests according to Art. 6 para. 1 sentence 1 lit. f GDPR for abuse and fraud prevention, offer and website optimization, and ensuring smooth operation of the website or the Trustbadge or other widgets from Trusted Shops.

Further personal data are transferred to Trusted Shops GmbH if you decide to use Trusted Shops products after completing an order or have already registered for use. This is done by automatic collection of personal data from the order data. Whether you as a buyer are already registered for product use is automatically checked based on a neutral parameter, the cryptographically one-way hashed email address. The email address is converted into this hash value, which cannot be decrypted by Trusted Shops, before transmission. After checking for a match, the parameter is automatically deleted.

This serves to verify whether you are already registered for services with Trusted Shops GmbH and is therefore necessary for fulfilling our and Trusted Shops' overriding legitimate interests in providing the buyer protection and transactional review services linked to the specific order according to Art. 6 para. 1 sentence 1 lit. f GDPR. If this is the case, further processing is carried out according to the contractual agreement between you and Trusted Shops. If you are not yet registered for the services, you will have the opportunity to do so for the first time afterwards. Further processing after registration is also governed by the contractual agreement with Trusted Shops. If you do not register, all transmitted data will be automatically deleted by Trusted Shops and no personal reference will be possible.

Within the joint responsibility between us and Trusted Shops GmbH, please preferably contact Trusted Shops GmbH for data protection questions and to assert your rights; their contact options can be found here [https://www.trustedshops.de/impressum/#datenschutz]. Further information on data protection can be found at the following link here [https://www.trustedshops.com/tsdocument/CONSUMER_MEMBERSHIP_TERMS_de.pdf]. Regardless, you can always contact us at the contact option described in this privacy policy. Your inquiry will then be forwarded to the other responsible party if necessary.


8. SOCIAL MEDIA


8.1 SOCIAL PLUGINS FROM FACEBOOK, INSTAGRAM, PINTEREST

Social buttons from social networks are used on our website. These are only embedded as HTML links in the page, so that no connection to the servers of the respective provider is established when our website is called up. If you click on one of the buttons, the website of the respective social network opens in a new window of your browser. There you can, for example, press the Like or Share button.


8.2 OUR ONLINE PRESENCE ON FACEBOOK, INSTAGRAM

If you have given your consent according to Art. 6 para. 1 sentence 1 lit. a GDPR to the respective social media operator, your data is automatically collected and stored for market research and advertising purposes when visiting our online presences on the above-mentioned social media, from which usage profiles are created using pseudonyms. These can be used, for example, to display advertisements within and outside the platforms that presumably correspond to your interests. Cookies are usually used for this purpose. Detailed information on the processing and use of data by the respective social media operator as well as a contact option and your rights and settings to protect your privacy can be found in the privacy notices of the providers linked below. If you still need help in this regard, you can contact us.

Facebook [https://www.facebook.com/about/privacy/] is an offer of Facebook Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland ("Facebook Ireland"). The information automatically collected by Facebook Ireland about your use of our online presence on Facebook is usually transmitted to a server of Facebook, Inc., 1601 Willow Road, Menlo Park, California 94025, USA and stored there. There is no adequacy decision by the European Commission for the USA. Our cooperation with them is based on standard data protection clauses of the European Commission. Data processing during a visit to a Facebook fan page is based on an agreement between joint controllers according to Art. 26 GDPR. Further information (information about insights data) can be found here [https://www.facebook.com/legal/terms/information_about_page_insights_data].

Instagram [https://help.instagram.com/519522125107875] is an offer of Facebook Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland ("Facebook Ireland"). The information automatically collected by Facebook Ireland about your use of our online presence on Instagram is usually transmitted to a server of Facebook, Inc., 1601 Willow Road, Menlo Park, California 94025, USA and stored there. There is no adequacy decision by the European Commission for the USA. Our cooperation with them is based on standard data protection clauses of the European Commission. Data processing during a visit to an Instagram fan page is based on an agreement between joint controllers according to Art. 26 GDPR. Further information (information about insights data) can be found here [https://www.facebook.com/legal/terms/information_about_page_insights_data].


9. CONTACT OPTIONS AND YOUR RIGHTS


9.1 YOUR RIGHTS

As a data subject, you have the following rights:

* according to Art. 15 GDPR, the right to request information about your personal data processed by us to the extent specified there;
* according to Art. 16 GDPR, the right to request immediate correction of incorrect or completion of your personal data stored with us;
* according to Art. 17 GDPR, the right to request deletion of your personal data stored with us, unless further processing
* is necessary for exercising the right to freedom of expression and information;
* is necessary for compliance with a legal obligation;
* is necessary for reasons of public interest; or
* is necessary for the establishment, exercise, or defense of legal claims;
* according to Art. 18 GDPR, the right to request restriction of processing of your personal data, insofar as
* the accuracy of the data is contested by you;
* the processing is unlawful, but you oppose deletion;
* we no longer need the data, but you need them for the establishment, exercise, or defense of legal claims; or
* you have objected to processing according to Art. 21 GDPR;
* according to Art. 20 GDPR, the right to receive your personal data provided to us in a structured, commonly used, and machine-readable format or to request transmission to another controller;
* according to Art. 77 GDPR, the right to lodge a complaint with a supervisory authority. Usually, you can contact the supervisory authority of your usual place of residence or workplace or our company headquarters for this.

Right to object

If we process personal data as described above to safeguard our overriding legitimate interests within the framework of a balancing of interests, you can object to this processing with effect for the future. If the processing is for direct marketing purposes, you can exercise this right at any time as described above. If the processing is for other purposes, you only have a right to object if there are reasons arising from your particular situation.

After exercising your right to object, we will no longer process your personal data for these purposes unless we can demonstrate compelling legitimate grounds for processing that override your interests, rights, and freedoms, or if the processing serves the establishment, exercise, or defense of legal claims.

This does not apply if the processing is for direct marketing purposes. In that case, we will no longer process your personal data for this purpose.


9.2 CONTACT OPTIONS

If you have questions about the collection, processing, or use of your personal data, for information, correction, restriction, or deletion of data, as well as revocation of given consents or objection to a specific data use, please contact us directly via the contact details in our imprint.


Privacy policy created with the Trusted Shops [https://legal.trustedshops.com/] legal text generator in cooperation with FÖHLISCH Rechtsanwälte [https://foehlisch.com].

10. KLARNA

To offer you Klarna's payment methods, we may transmit your personal data in the form of contact and order data to Klarna at checkout so that Klarna can assess whether you qualify for their payment methods and to tailor these payment methods for you. Your transmitted personal data will be processed in accordance with Klarna's privacy policy,

Klarna’s own privacy notice.

en