Privacy Policy
1. Name and Address of the Controller
Buckle and Seam GmbH
Hannebach 30
96269 Großheirath
Germany
service@buckleandseam.com
2. Contact for Data Protection Inquiries
Please direct data protection inquiries to:
Buckle and Seam GmbH
Hannebach 30
96269 Großheirath
Germany
service@buckleandseam.com
3. General Information on Data Processing
We process personal data only to the extent necessary to provide a functional website and our services. Processing is carried out only based on consent or legal authorization.
4. Rights of the Data Subject
You have the right to access, rectification, erasure, restriction of processing, data portability, and objection, as well as the right to lodge a complaint with a supervisory authority.
5. Website Provision & Server Log Files
When accessing our website, technical data such as IP address, access time, browser type, and pages visited are automatically recorded. This data is processed to ensure the technical functionality and security of the website.
6. Use of Cookies
We use cookies to optimize the website and for statistical purposes. Processing is based on your consent (Art. 6 para. 1 lit. a GDPR) or, in the case of technically necessary cookies, on legitimate interests (Art. 6 para. 1 lit. f GDPR).
7. Consent Management with Pandectes GDPR
We use the Pandectes GDPR consent tool to obtain and manage consents. Your selection is saved and can be adjusted at any time. More information at: pandectes.io
8. Registration & Customer Account
When registering or placing an order, we process your personal data to create and manage your account. Processing is based on your consent or to fulfill a contract.
9. Online Store via Shopify
Our online store is operated via Shopify. Provider: Shopify Inc., 126 York Street, Suite 200, Ottawa, ON, Canada. Shopify acts as a data processor under Art. 28 GDPR. More info: shopify.com
10. Payment Processing
We offer various payment methods via third-party providers (e.g., Klarna, PayPal, Shopify Payments, Google Pay, Apple Pay, American Express, Visa). Payment processing is carried out according to Art. 6 para. 1 lit. b GDPR.
11. Shipping Providers
To deliver your order, we transmit relevant data to our shipping partners (e.g., DPD, DHL). This is based on your consent or to fulfill the contract.
12. Newsletter & Email Marketing (Klaviyo)
When subscribing to our newsletter, your email address and possibly other data will be processed. Sending is done via Klaviyo (USA). We use the double opt-in procedure. Legal basis: Consent according to Art. 6 para. 1 lit. a GDPR.
13. Contact Forms & Email Communication
When contacting us via forms or email, your information will be processed to handle your inquiry. The legal basis is your consent or contract initiation.
14. Web Analytics & Tracking
We use tools such as Google Analytics, Facebook Pixel and Google Tag Manager to analyze user behavior and optimize our website and advertising. Processing is only carried out with your consent in accordance with Art. 6 para. 1 lit. a GDPR.
15. Google Tag Manager
Google Tag Manager is used to manage website tags. It does not process any personal data itself.
16. Use of Social Media & Business Platforms
We maintain company profiles on platforms such as Instagram, Facebook, and YouTube. When you interact with us there, personal data may be processed. See the privacy policies of the respective platforms for details.
17. Plugins & Tools Used
Our website uses additional Shopify apps and plugins, including: Pandectes GDPR, Judge.me, Trusted Shops, Essential Upsell, AccessPro Accessibility, CartKing, Matrixify, Geos, Fivetran, Channable, Klaviyo, Google & YouTube, Facebook & Instagram, Progus Store Locator, Attrac, Translate & Adapt, Inbox Shopify, Shopify POS, Search & Discovery, Flow Shopify, DATEV Export Pro. Data processing depends on the function and is based on your consent or contract fulfillment.
18. Data Disclosure to Third Parties
Data will only be disclosed if legally required (Art. 6 para. 1 lit. c GDPR), contractually necessary (Art. 6 para. 1 lit. b GDPR), or based on your explicit consent (Art. 6 para. 1 lit. a GDPR). Possible recipients include shipping providers, payment processors, tax advisors, collection agencies, and auditors.
19. Data Transfers to Third Countries
When using Shopify, Klaviyo, Google, Meta, and other tools, data may be transferred to third countries. Such transfers are based on appropriate safeguards such as EU standard contractual clauses pursuant to Art. 46 GDPR.
20. Retention Period
We store personal data only as long as necessary for the respective processing purposes or as required by law. Once the purpose ceases or legal retention periods expire, data is routinely deleted.
Criteria for retention include legal retention periods (e.g., up to 10 years under tax and commercial law), duration of contractual relationships, consents, technical necessities, or legitimate interests.
21. Updates
This privacy policy is currently valid. We reserve the right to modify or update it as needed.