PRIVACY POLICY
We take the protection of your personal data seriously. Here you'll find what data we collect, why, and how to exercise your rights.
1. Responsible party
Responsible party within the meaning of Art. 4 No. 7 GDPR is:
Sent by Heaven — Paul Welther
Siebenbürgenstr. 20, 74321 Bietigheim-Bissingen
Email: info@sentbyheaven.de
2. General information
Personal data is any information relating to an identified or identifiable natural person (Art. 4 No. 1 GDPR). We process your data exclusively on the basis of statutory provisions (GDPR, BDSG, TTDSG).
3. Data collection when visiting the website
(1) When you access our website, information is automatically stored in so-called server log files: IP address, date/time, transferred data volume, browser type, operating system, referrer URL.
(2) Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in stable provision). Storage period: 30 days, then anonymization.
4. Cookies & Tracking
(1) We use cookies and similar technologies. For non-essential cookies, we obtain your consent in advance pursuant to § 25 (1) TTDSG in conjunction with Art. 6 (1) lit. a GDPR via our consent banner.
(2) You can adjust or revoke your selection at any time at Cookie settings.
Tools used:
- Shopify — Shop system (Provider: Shopify International Ltd., Ireland). Technically necessary cookies, legal basis: Art. 6 (1) lit. b GDPR (contract performance).
- Klaviyo — Newsletter delivery & personalization (Provider: Klaviyo Inc., USA). Processing based on consent (Art. 6 (1) lit. a GDPR). Third country transfer secured via EU standard contractual clauses + Data Privacy Framework.
- Meta Pixel — Conversion tracking & re-targeting (Provider: Meta Platforms Ireland Ltd., Ireland). Processing only with consent.
- TikTok Pixel — Conversion tracking & re-targeting (Provider: TikTok Technology Ltd., Ireland). Processing only with consent.
5. Orders in the shop
(1) For an order we process the following data: Name, address, email, payment data, phone number if applicable.
(2) Legal basis: Art. 6 (1) lit. b GDPR (contract performance) and Art. 6 (1) lit. c GDPR (commercial and tax retention obligations).
(3) Recipients: Shipping service providers (DHL), payment service providers (Klarna, PayPal, Stripe), tax consultancy. Storage period: 10 years pursuant to § 147 AO.
6. Newsletter
(1) Newsletter registration is done via double opt-in through Klaviyo. We store your email address, registration time and IP address to verify consent.
(2) Legal basis: Art. 6 (1) lit. a GDPR (consent).
(3) You can unsubscribe at any time — via the link in each newsletter or by emailing info@sentbyheaven.de.
7. Data processing & third country transfer
We use data processors pursuant to Art. 28 GDPR. Where data is transferred to third countries (especially USA), this is done on the basis of EU standard contractual clauses (Art. 46 (2) lit. c GDPR) or an adequacy decision (Data Privacy Framework).
8. Your rights
You have the right at any time to:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Object to processing (Art. 21 GDPR)
- Withdraw consent given (Art. 7 (3) GDPR)
- Complain to a supervisory authority (Art. 77 GDPR)
9. Privacy contact
For questions or to exercise your rights, you can reach us at info@sentbyheaven.de.
