Privacy Policy
Personal data (hereinafter referred to as “data”) is processed by us only to the extent necessary and for the purpose of providing a functional and user-friendly website, including its contents and the services offered therein.
According to Article 4(1) of Regulation (EU) 2016/679, the General Data Protection Regulation (hereinafter “GDPR”), “processing” refers to any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment or combination, restriction, erasure, or destruction.
This privacy policy informs you particularly about the type, scope, purpose, duration, and legal basis of the processing of personal data when we alone or jointly with others decide on the purposes and means of such processing. We also inform you about third-party components we use for optimization and usability purposes, which may process data under their own responsibility.
I. Information About the Controller
The responsible provider of this website under data protection law is:
Lea Mellin
Bernadottestr. 154c
22605 Hamburg
Germany
Tax Number: 42/158/04114
Contact
Email: leamellin.creative@web.de
Phone: +49 175 4289992
II. Rights of Users and Data Subjects
Users and data subjects have the following rights:
- To confirm whether data concerning them is being processed, to information about the data being processed, further details about the data processing, and copies of the data (Art. 15 GDPR);
- To correct or complete inaccurate or incomplete data (Art. 16 GDPR);
- To the immediate erasure of their data (Art. 17 GDPR), or, if further processing is necessary as per Art. 17(3) GDPR, to the restriction of processing (Art. 18 GDPR);
- To receive the data concerning them and provided by them and to transmit this data to other providers/controllers (Art. 20 GDPR);
- To lodge a complaint with the supervisory authority if they believe that their data is being processed in violation of data protection laws (Art. 77 GDPR).
Additionally, the controller is obligated to inform all recipients to whom data has been disclosed about any correction or deletion of data or restriction of processing under Art. 16, 17(1), and 18 GDPR, unless this proves impossible or involves disproportionate effort. Users also have the right to information about these recipients.
According to Art. 21 GDPR, users and data subjects also have the right to object to future processing of their data, provided the data is processed under Art. 6(1)(f) GDPR. In particular, an objection to data processing for direct marketing purposes is permissible.
III. Information on Data Processing
Your data processed when using our website will be deleted or blocked as soon as the purpose for storing it ceases to apply, unless there are legal retention obligations, or unless otherwise specified below.
Server Data
For technical reasons, especially to ensure a secure and stable website, data is transmitted by your internet browser to us or our web host. These server log files include: browser type and version, operating system, referrer URL, pages visited, date and time of access, and IP address.
These data are stored temporarily and not combined with other data.
Legal basis: Art. 6(1)(f) GDPR – legitimate interest in improving stability, functionality, and security of the website.
Storage duration: Max. 7 days unless required for evidence purposes.
Cookies
a) Session Cookies
We use cookies to make our website more user-friendly, effective, and secure. These may include storing preferences, language settings, or cart contents.
Legal basis:
- Art. 6(1)(b) GDPR if related to contract initiation or performance
- Art. 6(1)(f) GDPR for general website optimization
These cookies are deleted when your browser is closed.
b) Third-Party Cookies
We may also use third-party cookies for analytics, advertising, or embedded functionalities. Details can be found in the respective providers' privacy policies.
c) Managing Cookies
You can restrict or prevent cookie installation through your browser settings and delete stored cookies anytime. Refer to your browser’s help function for exact steps.
Note: Blocking cookies may limit website functionality.
Cookies on our site are used only in accordance with legal regulations. Where required, we obtain your prior consent.
Contract Processing
Data provided by you for ordering our products/services is processed for contract fulfillment. Without this data, we cannot complete the contract.
Legal basis: Art. 6(1)(b) GDPR.
We retain data for legal storage periods even after contract conclusion.
We may transfer data to delivery services or payment providers for order processing.
Payhip
Our shop is hosted and operated via Payhip. Payhip Limited is a company incorporated in England and Wales with registration no 08386910. They own and operate www.payhip.com. They registered office is Payhip, 85 Great Portland Street, First Floor, London, United Kingdom, W1W 7LT.
Payhip processes on our behalf: name, billing/shipping address, email, payment details, IP, order info, and device/browser data.
Payhip's privacy policy: https://payhip.com/privacy
We have a data processing agreement with Payhip.
PayPal
We use PayPal (Europe) S.à.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg for payment processing.
PayPal is integrated into our checkout process.
Legal basis:
- Art. 6(1)(b) GDPR (contract)
- Art. 6(1)(f) GDPR (secure & efficient payments)
Loading the PayPal checkout page transmits OS, browser, referrer, timestamp, and IP address to PayPal, even without user interaction.
PayPal processes any entered data independently.
PayPal’s privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full
Stripe
We also use Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland for payment processing.
Supported methods: credit card, Klarna, Apple Pay, Google Pay, SEPA, and others.
Stripe is integrated into the final checkout page.
Legal basis:
- Art. 6(1)(b) GDPR (contract)
- Art. 6(1)(f) GDPR (secure payments)
Loading Stripe’s checkout transfers system/browser data and IP address to Stripe.
Stripe processes the entered data independently to handle the payment.
Stripe’s privacy policy: https://stripe.com/de/privacy
Based on the model privacy policy by Anwaltskanzlei Weiß & Partner