Mix and Match
Privacy policy
1) INFORMATION ON THE COLLECTION OF PERSONAL DATA AND CONTACT DETAILS OF THE CONTROLLER
1.1 We are pleased that you are visiting our website and thank you for your interest. Below we inform you about the handling of your personal data when using our website. Personal data refers to all data by which you can be personally identified.
1.2 The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is Shop Name. The controller is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data.
1.3 For security reasons and to protect the transmission of personal data and other confidential content (e.g. orders or inquiries to the controller), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the "https://" string and the lock symbol in your browser bar.
2) DATA COLLECTION WHEN VISITING OUR WEBSITE
When you use our website purely for informational purposes — i.e. if you do not register or otherwise provide us with information — we only collect data that your browser transmits to our server (so-called "server log files"). When you access our website, we collect the following data that is technically necessary to display the website to you:
- Our visited website
- Date and time of access
- Amount of data sent in bytes
- Source/referral from which you reached the page
- Browser used
- Operating system used
- IP address used (possibly in anonymized form)
Processing is carried out pursuant to Art. 6(1)(f) GDPR on the basis of our legitimate interest in improving the stability and functionality of our website. The data is not passed on or used for any other purpose. We do, however, reserve the right to review the server log files retrospectively if there are concrete indications of unlawful use.
3) COOKIES
To make visiting our website attractive and to enable the use of certain functions, we use so-called cookies on various pages. These are small text files stored on your device. Some of the cookies we use are deleted after the end of the browser session, i.e. after closing your browser (so-called session cookies). Other cookies remain on your device and allow us or our partner companies (third-party cookies) to recognize your browser on your next visit (persistent cookies). When cookies are set, they collect and process certain user information such as browser and location data as well as IP address values. Persistent cookies are automatically deleted after a specified period, which may vary depending on the cookie.
Some cookies serve to simplify the ordering process by saving settings (e.g. remembering the contents of a virtual shopping cart for a later visit to the website). Where cookies implemented by us also process personal data, this is carried out pursuant to Art. 6(1)(b) GDPR either for the performance of a contract or pursuant to Art. 6(1)(f) GDPR to safeguard our legitimate interests in the best possible functionality of the website and a customer-friendly and effective design of the page visit.
We may work with advertising partners who help us make our online offering more interesting for you. For this purpose, cookies from partner companies will also be stored on your hard drive when you visit our website (third-party cookies). If we work with the aforementioned advertising partners, you will be informed individually and separately about the use of such cookies and the scope of the information collected in the paragraphs below.
Please note that you can set your browser to inform you about the placement of cookies and to decide individually whether to accept them, or to exclude the acceptance of cookies for certain cases or in general. Each browser differs in how it manages cookie settings. This is described in the help menu of each browser, which explains how you can change your cookie settings. You can find these for the respective browsers at the following links:
- Internet Explorer: https://support.microsoft.com/en-us/help/17442
- Firefox: https://support.mozilla.org/en-US/kb/enable-and-disable-cookies
- Chrome: https://support.google.com/chrome/answer/95647
- Safari: https://support.apple.com/kb/ph21411
- Opera: https://help.opera.com/en/latest/web-preferences/#cookies
Please note that if you do not accept cookies, the functionality of our website may be restricted.
4) CONTACT
When you contact us (e.g. via contact form or email), personal data is collected. The data collected in the case of a contact form can be seen from the respective contact form. This data is stored and used exclusively for the purpose of responding to your request or for contacting you and the associated technical administration. The legal basis for processing the data is our legitimate interest in responding to your request pursuant to Art. 6(1)(f) GDPR. If your contact is aimed at concluding a contract, the additional legal basis for processing is Art. 6(1)(b) GDPR. Your data will be deleted after final processing of your inquiry, which is the case when it can be inferred from the circumstances that the matter in question has been conclusively resolved, provided there are no statutory retention obligations to the contrary.
5) DATA PROCESSING FOR OPENING A CUSTOMER ACCOUNT AND CONTRACT PROCESSING
Pursuant to Art. 6(1)(b) GDPR, personal data is further collected and processed when you provide it to us for the performance of a contract or when opening a customer account. The data collected can be seen from the respective input forms. Deletion of your customer account is possible at any time and can be carried out by sending a message to the controller's address mentioned above. We store and use the data you provide for contract processing. After the contract has been fully processed or your customer account has been deleted, your data will be blocked in compliance with commercial and tax law retention periods and deleted after these periods have expired, unless you have expressly consented to further use of your data or we have reserved the right to use your data beyond this in a manner permitted by law, about which we will inform you accordingly below.
6) USE OF YOUR DATA FOR DIRECT MARKETING
6.1 Subscribing to our email newsletter
If you subscribe to our email newsletter, we will regularly send you information about our offers. The only mandatory information required for sending the newsletter is your email address. Providing additional optional data is voluntary and will be used to address you personally. For sending the newsletter, we use the so-called double opt-in procedure. This means we will only send you an email newsletter once you have expressly confirmed that you consent to receiving newsletters. We will then send you a confirmation email asking you to confirm by clicking a link that you wish to receive newsletters in the future.
By activating the confirmation link, you give us your consent for the use of your personal data pursuant to Art. 6(1)(a) GDPR. When registering for the newsletter, we store your IP address registered by the Internet Service Provider (ISP) as well as the date and time of registration in order to be able to trace any possible misuse of your email address at a later point in time. The data collected by us when registering for the newsletter is used exclusively for promotional contact via the newsletter. You can unsubscribe from the newsletter at any time via the link provided in the newsletter or by sending a corresponding message to the controller mentioned at the beginning. Upon unsubscribing, your email address will be deleted from our newsletter distribution list immediately, unless you have expressly consented to further use of your data or we reserve the right to use data beyond this in a manner that is legally permitted and about which we inform you in this declaration.
6.2 Sending the email newsletter to existing customers
If you have provided us with your email address when purchasing goods or services, we reserve the right to regularly send you offers for similar goods or services from our range by email. For this purpose, we do not need to obtain separate consent from you. Data processing is carried out solely on the basis of our legitimate interest in personalized direct advertising pursuant to Art. 6(1)(f) GDPR. If you initially objected to the use of your email address for this purpose, we will not send you any emails. You are entitled to object to the use of your email address for the aforementioned advertising purpose at any time with effect for the future by notifying the controller mentioned at the beginning. You will only incur transmission costs at basic rates for this. After receipt of your objection, the use of your email address for advertising purposes will be stopped immediately.
7) DATA PROCESSING FOR ORDER FULFILLMENT
7.1 The personal data we collect will be passed on to the transport company responsible for delivery as part of contract processing, insofar as this is necessary for the delivery of goods. Your payment data will be passed on to the commissioned credit institution as part of payment processing, insofar as this is necessary for payment processing. Where payment service providers are used, we inform you explicitly below. The legal basis for passing on the data is Art. 6(1)(b) GDPR.
7.2 Use of payment service providers
PayPal For payments via PayPal, credit card via PayPal, direct debit via PayPal, or — where offered — "purchase on account" or "installment payment" via PayPal, we pass on your payment data to PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg ("PayPal") as part of payment processing. The transfer is made pursuant to Art. 6(1)(b) GDPR and only to the extent necessary for payment processing.
For the payment methods credit card via PayPal, direct debit via PayPal, or — where offered — "purchase on account" or "installment payment" via PayPal, PayPal reserves the right to carry out a credit check. For this purpose, your payment data may be passed on to credit agencies pursuant to Art. 6(1)(f) GDPR based on PayPal's legitimate interest in determining your creditworthiness. The result of the credit check regarding the statistical probability of payment default is used by PayPal to decide on the provision of the respective payment method. The credit report may contain probability values (so-called score values). Where score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical method. Address data, among other things, are included in the calculation of score values. For further data protection information, including the credit agencies used, please refer to PayPal's privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full
You can object to this processing of your data at any time by notifying PayPal. However, PayPal may still be entitled to process your personal data if this is necessary for contractual payment processing.
SOFORT If you select the payment method "SOFORT," payment processing is carried out via the payment service provider SOFORT GmbH, Theresienhöhe 12, 80339 Munich, Germany ("SOFORT"), to whom we pass on the information provided during the order process along with information about your order pursuant to Art. 6(1)(b) GDPR. SOFORT GmbH is part of the Klarna Group (Klarna Bank AB (publ), Sveavägen 46, 11134 Stockholm, Sweden). Your data is only passed on for the purpose of payment processing with the payment service provider SOFORT and only to the extent necessary for this purpose. Further information on SOFORT's data protection provisions can be found at: https://www.klarna.com/sofort/datenschutz
8) CONTACT FOR REVIEW REMINDERS
Own review reminder (not sent by a customer review system)
We use your email address for a one-time reminder to submit a review of your order for the review system we use, provided you have given us your explicit consent during or after your order pursuant to Art. 6(1)(a) GDPR. You can withdraw your consent at any time by sending a message to the data processing controller.
9) USE OF SOCIAL MEDIA: SOCIAL PLUGINS
9.1 Facebook plugins with Shariff solution
Our website uses so-called social plugins ("plugins") of the social network Facebook, operated by Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA ("Facebook").
To increase the protection of your data when visiting our website, these buttons are not integrated as unrestricted plugins, but only using an HTML link. This type of integration ensures that when you access a page on our website that contains such buttons, no connection is yet established with Facebook's servers. When you click the button, a new browser window opens and calls up the Facebook page where you can interact with the plugins (if necessary after entering your login details).
Facebook Inc., based in the USA, is certified under the US-European data protection agreement "Privacy Shield," which guarantees compliance with the level of data protection applicable in the EU. For the purpose and scope of data collection and the further processing and use of data by Facebook, as well as your related rights and settings options to protect your privacy, please refer to Facebook's privacy notice: https://www.facebook.com/policy.php
9.2 Google+ plugins as Shariff solution
Our website uses so-called social plugins ("plugins") of the social network Google+, operated by Google LLC., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google").
To increase the protection of your data when visiting our website, these buttons are not integrated as unrestricted plugins, but only using an HTML link. This ensures that when you access a page on our website that contains such buttons, no connection is yet established with Google+'s servers. When you click the button, a new browser window opens and calls up the Google+ page where you can interact with the plugins (if necessary after entering your login details).
Google LLC, based in the USA, is certified under the Privacy Shield agreement. For further information, please refer to Google's privacy notices: https://www.google.com/intl/en/policies/privacy/
9.3 Instagram plugin as Shariff solution
Our website uses so-called social plugins ("plugins") of the online service Instagram, operated by Instagram LLC., 1601 Willow Rd, Menlo Park, CA 94025, USA ("Instagram").
To increase the protection of your data, these buttons are not integrated as unrestricted plugins, but only via an HTML link, ensuring no connection is established with Instagram's servers until you click the button. A new browser window will then open and load Instagram's page. Instagram LLC., based in the USA, is certified under the Privacy Shield agreement. For further information, please refer to Instagram's privacy notices: https://help.instagram.com/155833707900388/
10) ONLINE MARKETING
10.1 DoubleClick by Google
This website uses the online marketing tool DoubleClick by Google, operated by Google LLC., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("DoubleClick").
DoubleClick uses cookies to serve relevant ads to users, improve campaign performance reports, or prevent a user from seeing the same ads multiple times. Via a cookie ID, Google records which ads are displayed in which browser and can thus prevent them from being shown multiple times. Processing is carried out on the basis of our legitimate interest in the optimal marketing of our website pursuant to Art. 6(1)(f) GDPR.
In addition, DoubleClick can use cookie IDs to record so-called conversions related to ad requests — for example, when a user sees a DoubleClick ad and later visits the advertiser's website with the same browser and makes a purchase there. According to Google, DoubleClick cookies do not contain personal information.
Due to the marketing tools used, your browser automatically establishes a direct connection with Google's server. We have no influence over the scope and further use of the data collected by Google through the use of this tool and therefore inform you to the best of our knowledge: through the integration of DoubleClick, Google receives the information that you have accessed the relevant part of our website or clicked on one of our ads. If you are registered with a Google service, Google can associate the visit with your account. Even if you are not registered with Google or are not logged in, it is possible that the provider will obtain and store your IP address.
If you wish to object to participation in this tracking procedure, you can disable cookies for conversion tracking by setting your browser to block cookies from the domain www.googleadservices.com. This setting will be deleted if you delete your cookies. Alternatively, you can find out about the setting of cookies and make settings at the Digital Advertising Alliance at www.aboutads.info. Finally, you can set your browser so that you are informed about the setting of cookies and decide individually whether to accept them, or exclude the acceptance of cookies for certain cases or in general. If cookies are not accepted, the functionality of our website may be restricted.
Further information about DoubleClick by Google's privacy policy can be found at: https://www.google.de/policies/privacy/
10.2 Use of Google AdWords Conversion Tracking
This website uses the online advertising program "Google AdWords" and, within Google AdWords, the conversion tracking of Google LLC., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"). We use Google AdWords to draw attention to our attractive offers on external websites with the help of advertising media (so-called Google AdWords). We can determine how successful the individual advertising measures are in relation to the data from the advertising campaigns. Our goal is to show you advertising that is relevant to you, to make our website more interesting for you, and to achieve a fair calculation of advertising costs.
The conversion tracking cookie is set when a user clicks on a Google-placed AdWords ad. These cookies typically expire after 30 days and are not used for personal identification. When the user visits certain pages of this website and the cookie has not yet expired, Google and we can recognize that the user clicked on the ad and was directed to this page. Each Google AdWords customer receives a different cookie. Cookies therefore cannot be tracked across AdWords customers' websites. The information obtained using the conversion cookie is used to create conversion statistics for AdWords customers who have opted for conversion tracking. Customers learn the total number of users who clicked on their ad and were directed to a page tagged with a conversion tracking tag. However, they do not receive any information that can be used to personally identify users.
If you do not wish to participate in tracking, you can block this use by disabling the Google Conversion Tracking cookie via your browser settings under user preferences. You will then not be included in the conversion tracking statistics. We use Google AdWords on the basis of our legitimate interest in targeted advertising pursuant to Art. 6(1)(f) GDPR.
You can permanently disable cookies for ad preferences by downloading and installing the browser plug-in available at: https://www.google.com/settings/ads/plugin?hl=en
11) WEB ANALYTICS SERVICES
Google (Universal) Analytics
This website uses Google Analytics, a web analytics service of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"). Google Analytics uses "cookies" — text files stored on your computer that enable analysis of your use of the website. The information generated by the cookie about your use of this website (including the shortened IP address) is generally transmitted to a Google server in the USA and stored there.
This website uses Google Analytics exclusively with the extension "_anonymizeIp()", which ensures anonymization of the IP address through truncation and excludes any direct personal reference. Through this extension, your IP address is truncated by Google within member states of the European Union or in other contracting states to the Agreement on the European Economic Area beforehand. Only in exceptional cases will the full IP address be transferred to a Google server in the USA and truncated there. In these exceptional cases, processing is carried out pursuant to Art. 6(1)(f) GDPR on the basis of our legitimate interest in the statistical analysis of user behavior for optimization and marketing purposes.
On our behalf, Google will use this information to evaluate your use of the website, to compile reports on website activity, and to provide us with other services related to website and internet use. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.
You can prevent the storage of cookies through a corresponding setting in your browser software; however, we point out that in this case you may not be able to use all functions of this website to their full extent. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) to Google, and the processing of this data by Google, by downloading and installing the browser plugin available at: https://tools.google.com/dlpage/gaoptout?hl=en
This website also uses Google Analytics for cross-device analysis of visitor flows, which is carried out via a User ID. On the first visit to a page, the user is assigned a unique, permanent, and anonymized ID that is set across devices. This makes it possible to assign interaction data from different devices and different sessions to a single user. The User ID does not contain personal data and does not transmit such data to Google. You can object to the collection and storage of data via the User ID at any time with effect for the future.
12) RETARGETING / REMARKETING / REFERRAL ADVERTISING
Facebook Custom Audience via the Pixel method
This website uses the "Facebook Pixel" of Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA ("Facebook"). With explicit consent, user behavior can be tracked after users have seen or clicked on a Facebook advertisement. This process is used to evaluate the effectiveness of Facebook ads for statistical and market research purposes and can help optimize future advertising measures.
The data collected is anonymous to us, meaning it does not allow us to draw conclusions about the identity of users. However, the data is stored and processed by Facebook, so that a connection to the respective user profile is possible and Facebook can use the data for its own advertising purposes in accordance with the Facebook data use policy (https://www.facebook.com/about/privacy/).
Consent to the use of the Facebook Pixel may only be given by users over the age of 13. If you are younger, please ask your parent or guardian for permission. These processing operations are carried out exclusively with explicit consent pursuant to Art. 6(1)(a) GDPR.
Google AdWords Remarketing
Our website uses the functions of Google AdWords Remarketing to advertise this website in Google search results and on third-party websites. The provider is Google LLC., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"). For this purpose, Google places a cookie in your device's browser, which automatically enables interest-based advertising using a pseudonymous cookie ID based on the pages you have visited. Processing is carried out on the basis of our legitimate interest in the optimal marketing of our website pursuant to Art. 6(1)(f) GDPR.
Further data processing only takes place if you have agreed with Google that your internet and app browser history is linked to your Google account and information from your Google account is used to personalize ads that you view on the web. If in this case you are logged into Google during your visit to our website, Google uses your data together with Google Analytics data to create and define audience lists for cross-device remarketing.
You can permanently disable the setting of cookies for ad preferences by downloading and installing the browser plug-in available at: https://www.google.com/settings/ads/onweb/
13) RIGHTS OF THE DATA SUBJECT
13.1 The applicable data protection law grants you comprehensive rights (rights of access and intervention) vis-à-vis the controller with regard to the processing of your personal data, about which we inform you below:
-
Right of access pursuant to Art. 15 GDPR: You have in particular a right to information about your personal data processed by us, the purposes of processing, the categories of personal data processed, the recipients or categories of recipients to whom your data has been or will be disclosed, the planned storage period or the criteria for determining the storage period, the existence of a right to rectification, erasure, restriction of processing, objection to processing, complaint to a supervisory authority, the origin of your data if it was not collected directly from you, the existence of automated decision-making including profiling and, where applicable, meaningful information about the logic involved and the scope and intended effects of such processing for you, as well as your right to be informed of the guarantees pursuant to Art. 46 GDPR for transfers of your data to third countries.
-
Right to rectification pursuant to Art. 16 GDPR: You have the right to immediate rectification of inaccurate data concerning you and/or completion of your incomplete data stored by us.
-
Right to erasure pursuant to Art. 17 GDPR: You have the right to demand the erasure of your personal data if the requirements of Art. 17(1) GDPR are met. However, this right does not exist in particular if processing is necessary for exercising the right to freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise, or defense of legal claims.
-
Right to restriction of processing pursuant to Art. 18 GDPR: You have the right to demand the restriction of processing of your personal data as long as the accuracy of your data that you dispute is being verified, if you refuse erasure of your data due to unlawful data processing and instead request restriction of the processing of your data, if you need your data for the establishment, exercise, or defense of legal claims after we no longer need this data after fulfillment of the purpose, or if you have lodged an objection based on your particular situation, as long as it has not yet been determined whether our legitimate grounds outweigh yours.
-
Right to notification pursuant to Art. 19 GDPR: If you have asserted the right to rectification, erasure, or restriction of processing against the controller, the controller is obliged to communicate this rectification or erasure of data or restriction of processing to all recipients to whom the data concerning you has been disclosed, unless this proves impossible or involves a disproportionate effort. You have the right to be informed about these recipients.
-
Right to data portability pursuant to Art. 20 GDPR: You have the right to receive your personal data that you have provided to us in a structured, commonly used and machine-readable format, or to request its transfer to another controller, insofar as this is technically feasible.
-
Right to withdraw consent pursuant to Art. 7(3) GDPR: You have the right to withdraw consent to data processing at any time with effect for the future. In the event of withdrawal, we will delete the affected data immediately, insofar as further processing cannot be based on a legal basis for processing without consent. The withdrawal of consent does not affect the lawfulness of processing carried out on the basis of the consent prior to withdrawal.
-
Right to lodge a complaint pursuant to Art. 77 GDPR: If you believe that the processing of personal data concerning you violates the GDPR, you have — without prejudice to any other administrative or judicial remedy — the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, place of work, or place of the alleged infringement.
13.2 RIGHT TO OBJECT
IF WE PROCESS YOUR PERSONAL DATA ON THE BASIS OF A BALANCING OF INTERESTS DUE TO OUR OVERRIDING LEGITIMATE INTEREST, YOU HAVE THE RIGHT TO OBJECT TO THIS PROCESSING AT ANY TIME WITH EFFECT FOR THE FUTURE ON GROUNDS ARISING FROM YOUR PARTICULAR SITUATION.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE DATA IN QUESTION. HOWEVER, FURTHER PROCESSING REMAINS RESERVED IF WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR PROCESSING THAT OUTWEIGH YOUR INTERESTS, FUNDAMENTAL RIGHTS, AND FREEDOMS, OR IF PROCESSING SERVES THE ESTABLISHMENT, EXERCISE, OR DEFENSE OF LEGAL CLAIMS.
IF YOUR PERSONAL DATA IS PROCESSED BY US FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF SUCH MARKETING. YOU CAN EXERCISE THE OBJECTION AS DESCRIBED ABOVE.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE DATA IN QUESTION FOR DIRECT MARKETING PURPOSES.
14) DURATION OF STORAGE OF PERSONAL DATA
The duration of storage of personal data is determined by the respective statutory retention period (e.g. commercial and tax law retention periods). After expiry of the period, the corresponding data is routinely deleted, provided it is no longer necessary for the performance or initiation of a contract and/or there is no longer a legitimate interest on our part in continued storage.