Datenschutzerklärung

This Privacy Policy explains how personal information may be collected, used, disclosed, retained and protected when individuals visit, use or make purchases through cathyprom.shop.

We take privacy seriously and seek to process personal information in accordance with applicable data-protection requirements, including the General Data Protection Regulation (GDPR) where it applies and relevant German privacy requirements.

For privacy-related enquiries:

Email: info@cathyprom.shop

Important Controller Information

cathyprom.shop is the store name and customer-facing contact used for this ecommerce website.

Privacy requests concerning the store may be submitted to:

info@cathyprom.shop

German and European privacy law may require the legally responsible operator or data controller to disclose its genuine legal identity and address. Those details cannot lawfully be invented and must correspond to the actual business operating cathyprom.shop.

Personal Information We May Collect

Depending on how customers interact with cathyprom.shop, we may process information including:

Identity and Contact Information

This may include:

  • Name;
  • Email address;
  • Telephone number;
  • Billing information;
  • Shipping information; and
  • Other contact details supplied by the customer.

Order and Transaction Information

This may include:

  • Products ordered;
  • Order number;
  • Order value;
  • Purchase history;
  • Returns;
  • Refunds;
  • Shipping status;
  • Customer-service correspondence; and
  • Transaction-related records.

Payment Information

Payments may be processed through Shopify-supported or other third-party payment processors.

We may receive limited information regarding payment authorization, payment status or transaction identifiers.

Full payment-card information may be processed directly by authorized payment providers rather than stored directly by cathyprom.shop.

Device and Technical Information

When a visitor accesses our website, technical information may be collected, such as:

  • IP address;
  • Browser type;
  • Device type;
  • Operating system;
  • Language;
  • Time zone;
  • Referral information;
  • Website activity;
  • Session information; and
  • Cookie or similar-technology identifiers where legally permitted.

Shopping Activity

We may process information regarding how users interact with our store, including:

  • Products viewed;
  • Cart activity;
  • Searches;
  • Checkout activity;
  • Purchases;
  • Returns; and
  • Other interactions with our ecommerce services.

Communications

If a customer contacts us, we may retain the communication and related information in order to provide support, resolve disputes, maintain records and improve customer service.

Sources of Information

Personal information may be obtained:

  • Directly from customers;
  • Through orders and checkout;
  • Through customer accounts;
  • Through customer-service communications;
  • Automatically through website technologies;
  • From Shopify;
  • From payment providers;
  • From fulfilment and delivery providers;
  • From fraud-prevention providers;
  • From analytics or marketing providers where lawful; and
  • From applications and integrations used to operate the store.

Why We Process Personal Information

We may process personal information for purposes including:

Processing Orders

Information may be used to:

  • Confirm purchases;
  • Receive and verify payment;
  • Process orders;
  • Arrange fulfilment;
  • Arrange delivery;
  • Provide tracking information;
  • Manage returns; and
  • Issue refunds.

The relevant GDPR legal basis may include processing necessary for performance of a contract or taking steps at the customer's request before entering into a contract.

Compliance With Legal Obligations

Information may be processed where necessary to comply with:

  • Accounting obligations;
  • Tax obligations;
  • Consumer-protection requirements;
  • Fraud-prevention obligations;
  • Regulatory requirements;
  • Legal claims; and
  • Other applicable laws.

Customer Service

We may use customer information to respond to enquiries, investigate issues and provide assistance.

Fraud Prevention and Security

Information may be used to detect, investigate and prevent:

  • Fraud;
  • Unauthorized transactions;
  • Abuse;
  • Cybersecurity incidents;
  • Malicious activity; and
  • Other threats to customers or our services.

Where applicable, processing may be based on legitimate interests, legal obligations or other lawful grounds.

Website Improvement

Where legally permitted, information may be used to understand website performance and improve functionality, customer experience, security and ecommerce operations.

Marketing

We may send marketing communications when a lawful basis exists.

Where consent is legally required, marketing will be based on valid consent.

Customers may withdraw consent or unsubscribe using available functionality or by contacting:

info@cathyprom.shop

GDPR Legal Bases

Where GDPR applies, personal information will be processed only where a lawful basis exists.

Depending on the circumstances, such legal bases may include:

  • Consent;
  • Performance of a contract;
  • Steps taken before entering into a contract;
  • Compliance with a legal obligation;
  • Legitimate interests that are not overridden by the individual's rights and freedoms; or
  • Another basis recognized by applicable law.

Cookies and Similar Technologies

cathyprom.shop may use cookies, pixels, local storage and related technologies.

These technologies may support:

  • Shopping-cart operation;
  • Secure checkout;
  • Login functionality;
  • Website security;
  • Fraud prevention;
  • Language settings;
  • Essential ecommerce functionality;
  • Analytics;
  • Advertising; and
  • Personalization.

Under German TDDDG requirements, storing information on or accessing information from a user's device generally requires appropriate consent unless the activity is strictly necessary for transmitting a communication or providing a digital service expressly requested by the user.

Accordingly, non-essential analytics, advertising or personalization technologies should be activated only where an appropriate legal basis exists.

Cookie Consent

Where legally required, visitors may be presented with a cookie-consent mechanism.

Customers may be able to:

  • Accept non-essential technologies;
  • Reject non-essential technologies;
  • Select preferences; and
  • Change previously selected preferences.

Strictly necessary technologies may operate without optional consent when permitted by law because they are necessary to provide functions requested by the user.

Shopify

Our website may use Shopify to provide ecommerce infrastructure.

Shopify may process information in connection with:

  • Store hosting;
  • Checkout;
  • Transactions;
  • Security;
  • Fraud prevention;
  • Customer accounts;
  • Analytics;
  • Store operations; and
  • Other Shopify functionality.

Shopify's role regarding particular information may depend on the relevant processing activity and applicable contractual arrangements.

Third-Party Service Providers

We may disclose information to service providers where reasonably necessary to operate our business.

Such providers may include:

  • Shopify;
  • Payment processors;
  • Shipping companies;
  • Fulfilment providers;
  • Customer-support providers;
  • Cloud-service providers;
  • Security providers;
  • Fraud-prevention services;
  • Analytics services;
  • Marketing services;
  • Professional advisers; and
  • Other ecommerce applications.

We do not authorize processors acting on our behalf to use personal information for unrelated purposes except as lawfully permitted.

International Data Transfers

Some service providers may process personal information outside Germany or outside the European Economic Area.

Where GDPR applies to such transfers, appropriate transfer mechanisms and safeguards will be used where required.

Depending on the circumstances, safeguards may include:

  • European Commission adequacy decisions;
  • Standard Contractual Clauses;
  • Supplementary safeguards; or
  • Other legally recognized mechanisms.

Retention

Personal information will not be retained longer than reasonably necessary for the relevant purposes, subject to legal requirements.

Retention periods may depend on:

  • Contractual obligations;
  • Tax requirements;
  • Accounting requirements;
  • Consumer claims;
  • Fraud prevention;
  • Dispute resolution;
  • Legal limitation periods; and
  • Other applicable regulatory requirements.

Information may therefore be retained after an order has been completed where legally required or reasonably necessary.

Data Security

We use reasonable administrative, organizational and technical safeguards intended to protect personal information.

However, no internet transmission, computer system or storage method can be guaranteed to be completely secure.

Customers should protect account credentials and contact us if they suspect unauthorized use.

GDPR Rights

Where GDPR applies, individuals may have rights including:

  • The right to obtain information about processing;
  • The right of access;
  • The right to correction;
  • The right to erasure where applicable;
  • The right to restriction of processing;
  • The right to data portability where applicable;
  • The right to object to certain processing;
  • The right to object to direct marketing;
  • The right to withdraw consent where processing is based on consent; and
  • The right to lodge a complaint with a competent data-protection supervisory authority.

Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.

Direct Marketing Objection

Where personal information is processed for direct marketing, individuals have the right to object to that processing.

After a valid objection, personal information will no longer be processed for the relevant direct-marketing purpose.

Automated Decision-Making

Fraud-prevention or payment systems may use automated processes to assess transactions.

Where GDPR restrictions relating to solely automated decisions producing legal or similarly significant effects apply, such processing will be conducted only where legally permitted and with required safeguards.

Children's Privacy

cathyprom.shop is intended for customers who have legal capacity to make purchases or who use the website with appropriate parental or guardian authorization.

We do not intentionally seek to collect personal information from children in violation of applicable law.

Legal Disclosure

Personal information may be disclosed where reasonably necessary to:

  • Comply with applicable law;
  • Respond to lawful governmental requests;
  • Establish, exercise or defend legal claims;
  • Investigate fraud;
  • Protect customers;
  • Protect the security of our services; or
  • Enforce legal rights.

Business Transfers

If the operation of cathyprom.shop is reorganized, transferred, merged or sold, personal information may be transferred as part of that transaction where permitted by applicable law and subject to appropriate safeguards.

Changes to This Privacy Policy

We may update this Privacy Policy when our services, technology, legal obligations or processing practices change.

The current version will be published on cathyprom.shop with an updated revision date where appropriate.

Contact

Privacy requests and questions may be submitted to:

cathyprom.shop
Email: info@cathyprom.shop