Privacy Policy

The controller within the meaning of data protection laws, in particular the EU General Data Protection Regulation (GDPR), is:

Ecom Brands GmbH
Jonas Tank
Rödingsmarkt 31-33
20459 Hamburg
Telephone: 040-716 68 954
Email: support@ecom-brands.de

We appreciate your interest in our website. Protecting your privacy is very important to us. Below, we provide detailed information about how we handle your data on our website.

1. Storage of access data in server log files and hosting

You can visit our websites without providing any personal information. Each time a webpage is accessed, the web server automatically saves a so-called server log file, which contains, for example, the name of the requested file, your IP address, the date and time of access, the amount of data transferred, and the requesting provider (access data), and documents the access.
This access data is evaluated solely for the purpose of ensuring the smooth operation of the website and improving our services. This serves our legitimate interests, which, in accordance with Art. 6 Para. 1 Sentence 1 lit. f GDPR, override any conflicting interests, in ensuring the correct presentation of our services. All access data is deleted no later than seven days after the end of your visit to the website.

Hosting services provided by a third-party provider

As part of processing on our behalf, a third-party provider hosts and displays our website. This serves our legitimate interest in the correct presentation of our offerings, which outweighs any conflicting interests. All data collected through the use of this website or via forms provided in the online shop, as described below, is processed on their servers. Processing on other servers only takes place within the scope described herein.
This service provider is located within a country of the European Union or the European Economic Area.

2. Data collection and use for contract processing and when opening a customer account

We collect personal data when you voluntarily provide it to us in connection with your order, when contacting us (e.g., via contact form or email), or when opening a customer account. Required fields are marked as such because we need this data to process your order, your inquiry, or to open your customer account. Without this information, you cannot complete your order, open an account, or send your inquiry. The specific data collected is evident from the respective input forms. We use the data you provide in accordance with Article 6 Paragraph 1 Sentence 1 Letter b of the GDPR for contract processing and handling your inquiries. After complete contract fulfillment or deletion of your customer account, your data will be restricted from further processing and deleted after the statutory retention periods under tax and commercial law have expired, unless you have expressly consented to further use of your data or we reserve the right to use your data beyond this scope, which is permitted by law and about which we inform you in this privacy policy. You can delete your customer account at any time, either by sending a message to the contact option described below or via a designated function in your customer account.

3. Data transfer for contract fulfillment

For the purpose of fulfilling the contract pursuant to Art. 6 para. 1 sentence 1 lit. b GDPR, we forward your data to the shipping company commissioned with the delivery, insofar as this is necessary for the delivery of ordered goods. We use Ohl Connect GmbH & Co. KG as our logistics service provider. Ohl Connect GmbH & Co. KG provides logistics services on our behalf. For this purpose, we transmit your data to them. Ohl Connect GmbH & Co. KG will receive your name and recipient address, your email address, telephone number, customer reference number, the name of the invoice recipient, and the invoice address. Ohl Connect GmbH & Co. KG is contractually obligated to use this data only for the purpose described above and according to our instructions. Depending on which payment service provider you select during the ordering process, we will forward the payment data collected for this purpose to the bank commissioned with processing the payment and, if applicable, to payment service providers commissioned by us, or to the selected payment service. In some cases, the selected payment service providers also collect this data themselves if you create an account with them. In this case, you must log in to the payment service provider with your access data during the ordering process. The data privacy policy of the respective payment service provider applies in this respect.
For customer support purposes, we use Software-as-a-Service (SaaS) solutions from companies located outside the European Union. In this context, data is not transferred to the companies themselves, but is processed within the respective software solutions exclusively by our employees. Personal data is only transferred to these companies to the extent necessary for the performance of the contract. We use solutions from the providers Zendesk, Inc., 1019 Market Street, 6th Floor, San Francisco, California 94103, and Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (www.google.de), both of which are headquartered in the USA and certified under the EU-US Privacy Shield. Current certificates can be viewedHERE . Based on this agreement between the USA and the European Commission, the latter has determined that companies certified under the Privacy Shield provide an adequate level of data protection.

4. Email newsletter

When you subscribe to our newsletter, we use the data required for this purpose or data you have separately provided to send you our email newsletter regularly based on your consent in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR.
You can unsubscribe from the newsletter at any time, either by sending a message to the contact address provided below or by using the unsubscribe link in the newsletter. After unsubscribing, we will delete your email address unless you have expressly consented to further use of your data or we reserve the right to use your data for other purposes permitted by law, as described in this privacy policy.
The newsletter is sent by a service provider as part of processing on our behalf, to whom we pass on your email address for this purpose.
This service provider is located within a country of the European Union or the European Economic Area.

5. Contact requests & contact options

If you contact us via contact form or email, the data you provide will be used to process your request. Providing this data is necessary for processing and responding to your request; without it, we cannot respond to your request, or can only do so to a limited extent.
The legal basis for this processing is Article 6(1)(b) GDPR.

Contact form

If you send us inquiries via the contact form, your information from the inquiry form, including the contact details you provide, will be stored by us for the purpose of processing the request and in case of follow-up questions. We will not share this data without your further consent.
Your data will be deleted once your request has been fully answered and there are no legal retention obligations preventing deletion, such as in the case of any subsequent contract processing.

6. Data usage during payment processing

We use external payment service providers through whose platforms users and we can process payment transactions (e.g., each with a link to their privacy policy: PayPal ( https://www.paypal.com/de/webapps/mpp/ua/privacy-full ), Klarna ( https://www.klarna.com/de/datenschutz/ ), Giropay ( https://www.giropay.de/rechtliches/datenschutz-agb/ ), Visa ( https://www.visa.de/datenschutz ), Mastercard ( https://www.mastercard.de/de-de/datenschutz.html ), American Express ( https://www.americanexpress.com/de/content/privacy-policy-statement.html )).

We use payment service providers for the performance of contracts on the basis of Art. 6 para. 1 lit. b GDPR. Furthermore, we use external payment service providers on the basis of our legitimate interests pursuant to Art. 6 para. 1 lit. f GDPR in order to offer our users effective and secure payment options.

The data processed by payment service providers includes master data such as name and address, bank details such as account numbers or credit card numbers, passwords, TANs and checksums, as well as contract, amount, and recipient-related information. This information is required to process the transactions. However, the entered data is processed and stored only by the payment service providers. This means we do not receive any account or credit card information, but only confirmation or rejection of the payment. The payment service providers may transmit the data to credit reference agencies for identity and creditworthiness verification. Please refer to the terms and conditions and privacy policies of the payment service providers for further information.

The terms and conditions and privacy policies of the respective payment service providers apply to payment transactions and can be accessed on their respective websites or transaction applications. We also refer you to these for further information and to exercise your rights of withdrawal, access, and other data subject rights.

7. Cookies and web analytics

To make your visit to our website more attractive and to enable the use of certain functions, to display suitable products, or for market research, we use so-called cookies on various pages. This serves our legitimate interests, which outweigh your interests, in an optimized presentation of our offerings in accordance with Art. 6 Para. 1 Sentence 1 lit. f GDPR. Cookies are small text files that are automatically stored on your device. Some of the cookies we use are deleted after the end of your browser session, i.e., after you close your browser (session cookies). Other cookies remain on your device and allow us to recognize your browser on your next visit (persistent cookies). You can find information about the storage duration in the overview in your web browser's cookie settings. You can configure your browser to inform you about the setting of cookies and decide individually whether to accept them, or to exclude the acceptance of cookies in certain cases or in general. Each browser differs in how it manages cookie settings. This is described in the help menu of each browser, which explains how you can change your cookie settings.
You can find these for the respective browsers at the following links:
Cookie settings in Internet Explorer™
Cookie settings in Safari™
Cookie settings in Chrome™
Cookie settings in Firefox™
Cookie settings in Opera™
If you do not accept cookies, the functionality of our website may be limited.

8. SSL encryption

This site uses SSL encryption for security reasons and to protect the transmission of confidential information, such as inquiries you send to us as the site operator. You can recognize an encrypted connection by the fact that the browser's address bar changes from "http://" to "https://" and by the padlock icon in your browser's address bar. When SSL encryption is activated, the data you transmit to us cannot be read by third parties.

9. Use of Google (Universal) Analytics for web analytics

This website uses Google (Universal) Analytics, a web analytics service provided by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (www.google.de), for website analysis. This serves our legitimate interest in optimizing the presentation of our website, which outweighs any potential impact on your privacy, pursuant to Art. 6 Para. 1 Sentence 1 lit. f GDPR. Google (Universal) Analytics uses methods that enable analysis of your website usage, such as cookies. The information automatically collected about your use of this website is generally transmitted to and stored on a Google server in the USA. By activating IP anonymization on this website, your IP address is shortened before transmission within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. The anonymized IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data. Once the purpose for which Google Analytics was used has ceased and we have ended its use, the data collected in this context will be deleted.
Google Inc. is headquartered in the USA and is certified under the EU-US Privacy Shield. A current certificate can be found here: List of companies in the EU-US Privacy Shield . You can prevent Google Analytics from collecting your data by clicking the following link. This will set an opt-out cookie that prevents the collection of your data on future visits to this website: Disable Google Analytics
This website uses the "demographic characteristics" feature of Google Analytics. This allows reports to be generated that contain information about the age, gender, and interests of website visitors. This data comes from Google's interest-based advertising and from third-party visitor data. This data cannot be attributed to any specific individual. You can deactivate this feature at any time via the ad settings in your Google account or generally prohibit the collection of your data by Google Analytics as described in the section "Objection to data collection".
We have concluded a data processing agreement with Google and fully implement the strict requirements of the German data protection authorities when using Google Analytics.
For more information on how Google Analytics handles user data, please see Google's privacy policy: Google's privacy policies

10. Google reCAPTCHA

To protect our web forms from misuse and spam, we use the Google reCAPTCHA service in some forms on this website. Google reCAPTCHA is a service provided by Google Ireland Limited, a company incorporated and operating under Irish law, located at Gordon House, Barrow Street, Dublin 4, Ireland ( www.google.de ). By verifying manual input, this service prevents automated software (bots) from carrying out abusive activities on the website. This serves our legitimate interests, which, in accordance with Article 6(1)(f) GDPR, override any conflicting interests, in protecting our website from misuse and ensuring the smooth operation of our online presence.

Google reCAPTCHA uses methods, such as cookies, to analyze your website usage. These methods are implemented through a code embedded in the website, a so-called JavaScript. The automatically collected information about your use of this website, including your IP address, is generally transmitted to and stored on a Google server in the USA. Google reCAPTCHA also evaluates other cookies stored in your browser by Google services. No personal data from the input fields of the respective form is read or stored.

To the extent that information is transferred to and stored on Google servers in the USA, the American company Google LLC is certified under the EU-US Privacy Shield. A current certificate can be viewed [here/at this link]. This can be viewed here . Based on this agreement between the USA and the European Commission, the latter has determined that companies certified under the Privacy Shield provide an adequate level of data protection.

You can prevent Google from collecting and processing data generated by JavaScript or cookies relating to your use of the website (including your IP address) by disabling JavaScript or cookies in your browser settings. Please note that this may limit the functionality of our website for your use. Further information about Google's privacy policy can be found here .

11. Use of Google Webfonts

To ensure our content is displayed correctly and attractively across different browsers, we use "Google Web Fonts" from Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; hereinafter "Google") on this website to display fonts.

Further information about Google Web Fonts can be found at https://developers.google.com/fonts/faq and in Google's privacy policy: https://www.google.com/policies/privacy/ .

12. Using Google Maps

This website uses Google Maps. Google Maps is operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter "Google"). This allows us to display interactive maps directly on the website and enables you to conveniently use the map function.
Further information about data processing by Google can be found in Google's privacy policy: https://policies.google.com/privacy . There you can also change your personal privacy settings in the Privacy Center.

Detailed instructions on managing your data in connection with Google products can be found here: https://www.dataliberation.org

By visiting our website, Google receives information that you have accessed the corresponding subpage of our website. This occurs regardless of whether Google provides a user account that you are logged into, or whether no user account exists. If you are logged into Google, your data will be directly associated with your account.

If you do not wish to have your activity associated with your Google profile, you must log out of Google before activating the button. Google stores your data as user profiles and uses it for advertising, market research, and/or to tailor its websites to user needs. This analysis is carried out in particular (even for users who are not logged in) to provide targeted advertising and to inform other users of the social network about your activities on our website. You have the right to object to the creation of these user profiles, and to exercise this right, you must contact Google.

The provider currently offers no simple opt-out option or way to block data transfer. If you wish to prevent tracking of your activity on our website, please revoke your consent in the cookie consent tool for the relevant cookie category or for all cookies and data transfers that are not technically necessary. In this case, however, you may not be able to use our website at all or only to a limited extent.

13. Advertising via marketing networks

Use of Google Adwords Conversion

We use Google AdWords to advertise our attractive offers on external websites. The data from these advertising campaigns allows us to determine the success of individual advertising measures. Our aim is to show you relevant advertising, make our website more interesting for you, and ensure fair billing for advertising costs.
These advertisements are delivered by Google via so-called "ad servers." We use ad server cookies for this purpose, which allow us to measure certain parameters for success tracking, such as ad impressions or user clicks. If you access our website via a Google ad, Google AdWords will store a cookie on your computer. These cookies typically expire after 30 days and are not intended to personally identify you. The following data is generally stored in this cookie for analysis purposes: the unique cookie ID, the number of ad impressions per placement (frequency), the last impression (relevant for post-view conversions), and opt-out information (indicating that the user no longer wishes to be targeted).
These cookies allow Google to recognize your internet browser. If a user visits certain pages of an AdWords customer's website and the cookie stored on their computer has not yet expired, Google and the customer can recognize that the user clicked on the ad and was redirected to that page. Each AdWords customer is assigned a different cookie. Therefore, cookies cannot be tracked across the websites of different AdWords customers. We ourselves do not collect or process any personal data in the aforementioned advertising measures. We only receive statistical analyses from Google. These analyses allow us to identify which of the advertising measures used are particularly effective. We do not receive any further data from the use of these advertising tools, and in particular, we cannot identify users based on this information.
Due to the marketing tools used, your browser automatically establishes a direct connection to Google's server. We have no control over the scope and further use of the data collected by Google through the use of this tool and therefore inform you to the best of our knowledge: By integrating AdWords Conversion, Google receives the information that you have accessed the relevant part of our website or clicked on one of our ads. If you are registered with a Google service, Google can associate your visit with your account. Even if you are not registered with Google or are not logged in, it is possible that the provider will learn and store your IP address.

You can prevent participation in this tracking process in several ways:

- by adjusting your browser software settings accordingly, in particular by blocking third-party cookies, which will prevent you from receiving advertisements from third-party providers;

- by deactivating cookies for conversion tracking by configuring your browser to block cookies from the domain »www.googleadservices.com«, www.google.de/settings/ads, whereby this setting will be deleted if you delete your cookies;

- by deactivating interest-based ads from providers that are part of the self-regulatory campaign "About Ads" via the link www.aboutads.info/choices, whereby this setting will be deleted if you delete your cookies;

- by permanently disabling it in your Firefox, Internet Explorer, or Google Chrome browser via the link www.google.com/settings/ads/plugin. Please note that in this case, you may not be able to fully utilize all the features of this service.
The legal basis for processing your data is Art. 6 para. 1 sentence 1 lit. f GDPR.


Further information on data protection at Google can be found here: www.google.com/intl/de/policies/privacy and services.google.com/sitestats/de.html .
Alternatively, you can visit the Network Advertising Initiative (NAI) website at www.networkadvertising.org . Google has committed to the EU-US Privacy Shield, www.privacyshield.gov/EU-US-Framework .

Google AdWords Remarketing

We advertise this website in Google search results and on third-party websites using Google AdWords. When you visit our website, Google sets a so-called remarketing cookie, which automatically enables interest-based advertising using a pseudonymous cookie ID and based on the pages you have visited. This serves our legitimate interest in the optimal marketing of our website, which outweighs your interests in accordance with Art. 6 Para. 1 Sentence 1 lit. f GDPR. The data collected in this context will be deleted once the purpose for its collection has ceased and we have discontinued using Google AdWords Remarketing.
Further data processing only takes place if you have consented to Google linking your web and app browsing history to your Google account and using information from your Google account to personalize ads you see on the web. If you are logged into Google during your visit to our website, Google will use your data together with Google Analytics data to create and define target audience lists for cross-device remarketing. For this purpose, your personal data is temporarily linked by Google with Google Analytics data to create target audiences.
Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (www.google.de), is headquartered in the USA and is certified under the EU-US Privacy Shield. Current certificates can be viewed HERE . Based on this agreement between the USA and the European Commission, the latter has determined that companies certified under the Privacy Shield provide an adequate level of data protection.
You can deactivate the remarketing cookie via this link . You can also learn more about cookies and adjust your settings at the Digital Advertising Alliance .

14. Social Media Plugins

Use of social plugins from Facebook, Google, Twitter, Instagram, WhatsApp and Pinterest

Our website uses social plugins (“plugins”) from social networks. When you visit a page on our website that contains such a plugin, your browser establishes a direct connection to the servers of Facebook, Google, Twitter, or Instagram. The plugin content is transmitted directly from the respective provider to your browser and integrated into the page. By integrating the plugins, the providers receive information that your browser has accessed the corresponding page of our website, even if you do not have a profile or are not currently logged in. This information (including your IP address) is transmitted directly from your browser to a server of the respective provider (possibly in the USA) and stored there. If you are logged into one of the services, the providers can directly associate your visit to our website with your profile on the respective social network. If you interact with the plugins, for example, by clicking the “Like” or “Share” button, the corresponding information is also transmitted directly to a server of the provider and stored there. The information is also published on the social network and displayed to your contacts.
This serves to protect our overriding legitimate interests in the optimal marketing of our offer in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR.
For information on the purpose and scope of data collection, further processing and use of data by the providers, as well as contact options and your related rights and settings for protecting your privacy, please refer to the providers' privacy policies:

- Provider: Facebook Inc., 1 Hacker Way, Menlo Park, California 94025, USA. View Facebook's privacy policy.

- Twitter: Provider: Twitter Inc., 795 Folsom St., Suite 600, San Francisco, CA 94107, USA. View Twitter's privacy policy.

- Google+: Provider: Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. See Google's privacy policy.

- Instagram: Provider: Instagram Inc., 1601 Willow Road, Menlo Park, CA, 94025, USA. View Instagram's privacy policy.

- Pinterest: Provider: Pinterest Inc., 808 Brannan Street, San Francisco, CA 94103-490, USA. View Pinterest's privacy policy .

- TikTok: TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland. View TikTok's privacy policy: https://www.tiktok.com/legal/privacy-policy?lang=de

- WhatsApp: Provider: WhatsApp Inc., 1601 Willow Road, Menlo Park, California 94025, USA. View WhatsApp's privacy policy.

If you do not want social networks to directly associate the data collected via our website with your profile on the respective service, you must log out of the relevant service before visiting our website. You can also completely prevent the loading of plugins using browser add-ons, such as the script blocker "NoScript" ( http://noscript.net/ ).

15. YouTube Video Plugins

This website integrates content from third-party providers. This content is provided by Google Inc. ("Provider"). YouTube is operated by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google").
For YouTube videos embedded on our website, the enhanced privacy setting is activated. This means that no information about website visitors is collected and stored by YouTube unless they play the video. Embedding these videos serves our legitimate interest in the optimal marketing of our services, which outweighs any potential impact on your privacy, in accordance with Article 6(1)(f) GDPR.
For information on the purpose and scope of data collection and the further processing and use of data by the providers, as well as your related rights and settings options to protect your privacy, please refer to Google's privacy policy.

16. Contact options and your rights

You can exercise the following rights at any time using the contact details provided for our data protection officer:

- pursuant to Article 15 GDPR, the right to request information about your personal data processed by us to the extent specified therein;

- pursuant to Article 16 GDPR, the right to request the immediate rectification of inaccurate or incomplete personal data concerning you that we hold;

- pursuant to Article 17 GDPR, the right to request the erasure of your personal data stored by us, unless further processing is necessary: ​​for exercising the right of freedom of expression and information; for compliance with a legal obligation; for reasons of public interest; or for the establishment, exercise or defense of legal claims;

- pursuant to Article 18 GDPR, the right to request the restriction of the processing of your personal data insofar as: the accuracy of the data is contested by you; the processing is unlawful, but you object to its erasure; we no longer need the data, but you require it for the establishment, exercise or defense of legal claims; or you have objected to the processing pursuant to Article 21 GDPR;

- pursuant to Article 20 GDPR, the right to receive your personal data which you have provided to us in a structured, commonly used and machine-readable format or to request its transmission to another controller;

- In accordance with Article 77 of the GDPR, you have the right to lodge a complaint with a supervisory authority. You can usually contact the supervisory authority of your habitual residence, your place of work, or our company's registered office.


If you have any questions regarding the collection, processing, or use of your personal data, or if you wish to request information, correction, blocking, or deletion of data, or to revoke your consent or object to a specific use of your data, please contact us directly using the contact details provided in our legal notice. You can also request the necessary forms to exercise your rights as described above by contacting us using the contact details provided there.

You can lodge a complaint with a supervisory authority at any time, e.g., with the competent supervisory authority of the federal state where you live or with the authority responsible for us as the data controller.

A list of supervisory authorities (for the non-public sector) with addresses can be found here. here .

17. Right to object

To the extent that we process personal data as explained above to protect our overriding legitimate interests within the framework of a balancing of interests, you may object to this processing with effect for the future. If the processing is for direct marketing purposes, you may exercise this right at any time as described above. If the processing is for other purposes, you only have a right to object if there are grounds relating to your particular situation.
After you exercise your right to object, we will no longer process your personal data for these purposes unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defense of legal claims.
This does not apply if the processing is for direct marketing purposes. In that case, we will no longer process your personal data for this purpose.

If you have any questions about data protection, please send us an email or contact the person responsible for data protection directly:

Ecom Brands GmbH
Jonas Tank
Rödingsmarkt 31-33
20459 Hamburg
Telephone: 040-716 68 954
Email: support@ecom-brands.de