Privacy policy
Privacy policy
Last updated: 12 August 2026
1. Data controller
The controller responsible for processing personal data in this online shop is:
Danis Drip
Owner: Daniella Anders
Fährstraße 18
47495 Rheinberg
Germany
Phone: 0176 41195485
Email: info@danisdrip.de
Website: https://www.danisdrip.de
There is currently no statutory obligation to appoint a data protection officer.
2. General information and legal bases
We process personal data only insofar as necessary to provide and secure the online shop, take steps prior to entering into a contract and fulfil orders, provide digital content, communicate, comply with legal obligations or on the basis of consent. The legal bases are, in particular, Article 6(1)(a) GDPR (consent), Article 6(1)(b) GDPR (contract and steps prior to entering into a contract), Article 6(1)(c) GDPR (legal obligation) and Article 6(1)(f) GDPR (legitimate interests). Legitimate interests include, in particular, the secure and economical operation of the shop, fraud prevention, customer service, quality assurance and the establishment or defence of legal claims.
3. Hosting and shop operation by Shopify
Our online shop is provided through Shopify. The contracting party for merchants in the EMEA region is Shopify International Limited, Victoria Buildings, 2nd Floor, 1–2 Haddington Road, Dublin 4, D04 XN32, Ireland. To operate the shop, Shopify processes, in particular, IP addresses, device and browser data, log data, cookie and consent data, contact and customer account data, order, shipping and payment information, and communication with the shop. Processing is carried out for the performance of a contract under Article 6(1)(b) GDPR and to ensure a secure and functioning shop under Article 6(1)(f) GDPR.
Shopify may use affiliates and subprocessors outside the European Economic Area. Where necessary, transfers are based on an adequacy decision, particularly the EU-US Data Privacy Framework, or standard contractual clauses. Further information: Shopify privacy policy and Shopify privacy for consumers.
4. Website visits and log data
When you visit the shop, technically necessary data is processed, particularly your IP address, date and time, page or file accessed, volume of data transferred, referrer URL, browser, operating system, device information, and error and security data. Processing serves website delivery, stability, security and the prevention of misuse. The legal basis is Article 6(1)(f) GDPR. Security logs are retained only for as long as required for these purposes or to investigate a specific incident.
5. Orders, personalisation and customer accounts
When you place an order, we process, in particular, your name, billing and delivery address, email address, telephone number, products and variants ordered, personalisation details, payment and shipping status, order number and order-related communication. This serves to process and fulfil the order, manufacture personalised goods, communicate with customers and handle warranty and withdrawal cases. The legal basis is Article 6(1)(b) GDPR. We retain information required under tax and commercial law under Article 6(1)(c) GDPR.
When a customer account is created, the necessary account, access and order data is processed to provide and manage the account. Customers may request deletion of their account unless statutory retention obligations prevent this.
6. Contacting us
If you contact us by email, telephone or contact form, we process the contact details provided and the content of your enquiry. If the enquiry relates to a contract or steps prior to entering into a contract, the legal basis is Article 6(1)(b) GDPR; in other cases it is Article 6(1)(f) GDPR, based on our interest in appropriate communication and customer support. The data is deleted once the enquiry has been fully dealt with, unless statutory retention or evidence obligations require otherwise.
7. Payment processing
For payment processing, we transmit the necessary order, contact, billing and payment data to the payment provider selected at checkout. The legal basis is Article 6(1)(b) GDPR. Checks to prevent fraud and misuse may additionally be based on Article 6(1)(f) GDPR. Payment providers may process data as independent data controllers.
Shopify Payments: Payments are processed through Shopify International Limited and affiliated payment companies. Depending on your selection, Shop Pay, Visa, Mastercard, American Express, Maestro, Apple Pay, Google Pay, Klarna and other payment methods displayed at checkout may be available. For certain payment methods, data is also transmitted to their operators, card-issuing banks, card networks and, where applicable, identity or credit checking services. The privacy information of the selected payment service also applies.
PayPal: If you select PayPal, the necessary data is transmitted to PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg. PayPal may process additional data for payment processing, identity verification, fraud prevention and risk assessment. Further information: PayPal privacy policy.
8. Shipping and collection
For physical orders, we transmit the data required for delivery, particularly the name, delivery address and, where applicable, contact details, to the shipping provider used, particularly DHL or Deutsche Post. The legal basis is Article 6(1)(b) GDPR. An email address or telephone number is transmitted only where necessary for delivery or where corresponding consent has been given. For collection, we process order and contact data to prepare and hand over the goods.
9. Digital content and LDT Digital Downloads
To provide and manage digital content, particularly STL files, we use the Shopify app LDT Digital Downloads from LDT Team, Thanh Tri, Hanoi 100000, Vietnam. This may involve processing, in particular, names, email addresses, telephone numbers, order numbers, products and variants ordered, IP addresses, geolocation, browser and operating system data, and access and download activity. The app can store files, generate download links, send download emails, manage access limits and process evidence of consent to the immediate supply of digital content.
The legal basis is Article 6(1)(b) GDPR; where an express declaration regarding the early start of contract performance is recorded and documented, Article 6(1)(a) and (c) GDPR also apply. Due to the provider’s location, data may be transferred to a third country. Such transfers are based on the data protection safeguards agreed with the provider. Only data required for provision, evidence and protection against misuse is transmitted.
10. Withdrawal function
To provide the electronic withdrawal function, we use the EU Widerruf Button service via the domain euwiderrufsbutton.de. When the form is used, the data processed includes, in particular, the name, email address, order number, details of the items concerned, content and time of the withdrawal statement, and technical log data. The purpose is to receive, document and confirm withdrawal and comply with legal obligations. The legal bases are Article 6(1)(c) GDPR and, insofar as processing serves to administer the contract, Article 6(1)(b) GDPR. Data is retained only for as long as necessary for processing and statutory evidence and retention obligations.
11. Product reviews with Judge.me
We use Judge.me to display and collect product and shop reviews. The provider is Judge.me Ltd, c/o Buckworths, 1–3 Worship Street, London EC2A 2AB, United Kingdom; EU data protection representative: Buckworths (Ireland) Limited, c/o Workhub, 77 Lower Camden Street, Dublin, Ireland. This may involve processing names or display names, email addresses, order and product references, reviews, uploaded images or other content, and technical usage data.
The display of voluntarily submitted reviews and purchase verification are based on Article 6(1)(f) GDPR, reflecting our interest in authentic customer feedback and transparent product presentation. Review requests are sent by email only where the necessary consent has been given or all legal conditions for permitted communication with existing customers are met. The legal basis is then Article 6(1)(a) GDPR or the relevant statutory permission. You may object or withdraw consent at any time. The European Commission’s adequacy decision applies to transfers to the United Kingdom. Further information: Judge.me Privacy Policy.
12. Newsletter and promotional communication
If you subscribe to the newsletter, we process your email address and any additional voluntarily provided information based on your consent under Article 6(1)(a) GDPR. Where used, we document registration and confirmation to provide evidence of consent. Consent may be withdrawn at any time with future effect through the unsubscribe link or by emailing info@danisdrip.de. You may object at any time to legally permitted advertising to existing customers. After unsubscribing, data may remain stored with restricted access to the extent necessary to provide evidence of earlier consent.
13. Cookies, local storage and TinyCookie
We use technically necessary cookies and similar technologies to enable the shop, cart, customer account, security and checkout to function. Such storage or access is based on Section 25(2) TDDDG; subsequent data processing is based on Article 6(1)(b) or (f) GDPR.
For non-essential technologies, we use the TinyCookie consent management service provided by Tobi AI Ltd. TinyCookie stores and manages your choices and may process a consent identifier, time, categories, language, device data and technical log data for this purpose. The legal basis is Article 6(1)(c) and (f) GDPR. Non-essential analytics or marketing technologies are activated only after consent under Section 25(1) TDDDG and Article 6(1)(a) GDPR. Consent may be changed or withdrawn at any time with future effect through the cookie settings. Further information: TinyCookie Privacy Policy.
14. Shopify analytics, Shop channel and Agentic Storefronts
Shopify provides us with aggregated statistics on shop visits, orders, searches and usage. Where personal or pseudonymous data is used for this purpose and the processing is not technically necessary, it takes place only with your consent. The legal basis is Article 6(1)(a) GDPR; strictly operational, necessary analysis may be based on Article 6(1)(f) GDPR.
Products may be made available through Shopify sales channels such as Shop, Agentic Storefronts and connected AI or shopping services. Primarily product, merchant, price, inventory and offer data is transmitted. Where a specific customer enquiry, referral or order includes personal data, processing is governed by Article 6(1)(b) GDPR and the privacy information of the service used.
15. Facebook and Instagram / Meta
We maintain a presence on Facebook and Instagram and use the Shopify Facebook & Instagram sales channel. The provider for users in the EEA is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. When you visit our social media pages, interact, send messages or make purchases through Meta services, Meta processes data as an independent controller. We process messages and interactions received for communication, customer support and public relations under Article 6(1)(b) or (f) GDPR.
Where Meta Pixel, Conversions API, personalised advertising or comparable marketing functions are activated, non-essential usage, device, event and purchase data is processed only after your consent under Section 25(1) TDDDG and Article 6(1)(a) GDPR. Consent may be withdrawn in the cookie settings. Meta may link data to existing accounts and process it in third countries. Transfer mechanisms may include, in particular, adequacy decisions or standard contractual clauses. Further information: Meta privacy policy.
16. External links and embedded content
The shop contains links to external websites and social networks. Merely displaying an ordinary link generally does not transmit data to its destination; when you click it, the destination provider’s privacy information applies. If external videos, maps, fonts or other content that transmits data upon loading is embedded, it is activated only after any required consent or integrated locally or in a way that minimises data use.
17. Recipients and categories of recipients
Where necessary for the respective purpose, recipients of personal data may include Shopify and its subprocessors, payment providers and financial institutions, shipping providers, LDT Digital Downloads, EU Widerruf Button, Judge.me, TinyCookie, Meta, IT, hosting and communication providers, tax and legal advisers, and competent authorities. Data is disclosed only on a legal basis, for contract performance, based on consent or where a legitimate interest exists and is not overridden by the data subject’s rights.
18. Transfers to third countries
Some providers or their subprocessors are located outside the European Economic Area. Where no adequacy decision exists, we base transfers in particular on the European Commission’s standard contractual clauses and assess supplementary safeguards. Despite these safeguards, a residual risk may exist in certain third countries that authorities access data under local law and European data subject rights are enforceable only to a limited extent.
19. Retention periods
We retain personal data only for as long as required for the respective purpose or by legal obligations. Contract, order and invoice data relevant under commercial and tax law is generally retained in accordance with statutory retention periods. Communication, consent, withdrawal, warranty and security data is retained for as long as required for processing, evidence, legal defence or legal obligations. Data is then deleted or its processing restricted. Where processing is based on consent, this is subject to earlier withdrawal of that consent.
20. Your data protection rights
Subject to the statutory conditions, you have the right of access, rectification, erasure, restriction of processing and data portability. Consent given may be withdrawn at any time with future effect. Where processing is based on Article 6(1)(f) GDPR, you may object on grounds relating to your particular situation. You may object to direct marketing at any time without giving reasons.
To exercise your rights, contact info@danisdrip.de or use the contact details above. You also have the right to lodge a complaint with a data protection supervisory authority. The authority particularly responsible for our location is: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf, https://www.ldi.nrw.de.
21. Required data and automated decisions
Providing the contract and order data marked as mandatory is necessary to conclude the contract. Without this data, we cannot process the order. We do not carry out solely automated decision-making with legal or similarly significant effects. Payment or platform providers may conduct their own automated risk and fraud checks; their privacy information explains these.
22. Data security and changes
We implement appropriate technical and organisational measures to protect personal data against loss, manipulation, unauthorised access and unauthorised disclosure. We update this privacy policy when the legal situation, services used or data processing activities change. The version published in the shop at the relevant time applies.