Privacy policy
Privacy Policy
This privacy policy describes how and when information is collected, used, and shared when you purchase an item from me, contact me, or otherwise use my services through getthewave.de or related websites and services.
This privacy policy does not apply to third-party practices that are not owned or controlled by me, including Shopify and any third-party services you access through my website.
Information Collected
To process your order, you must provide me with certain information, including your name, email address, mailing address, payment details, and details of the product you are ordering. You may also choose to provide me with additional personal information (for example, for a custom order) when you contact me directly.
Why I Need This Information and How I Use It
I rely on a number of legal bases to collect, use, and share your information, including:
- As necessary to provide my services, such as processing your order, resolving disputes, or providing customer support.
- To comply with a legal obligation or court order, or in connection with legal claims, such as retaining information about your purchases for tax purposes.
- As necessary for my legitimate interests, if those legitimate interests are not overridden by your rights or interests, such as providing and improving my services. I use your information to provide the services you requested and in my legitimate interest to improve my services.
Sharing and Disclosure of Information
I only share your personal data for specific reasons and under very limited circumstances, as follows:
- Service providers: I engage certain trusted third parties to perform functions and provide services for my shop, such as shipping companies. I share your personal information with these third parties, but only to the extent necessary to perform these services.
- Business transfers: If I sell or merge my business, I may disclose your information as part of that transaction, only to the extent permitted by law.
-
Compliance with laws: I may collect, use, retain, and share your information if I have a good faith belief that doing so is necessary to:
- (a) Respond to legal processes or governmental requests
- (b) Enforce my agreements, terms, and policies
- (c) Prevent, investigate, and address fraud, illegal activities, security, or technical issues
- (d) Protect the rights, property, and safety of my customers or others
Data Retention
I retain your personal information only for as long as necessary to provide you with my services and as described in this privacy policy. However, I may also be required to retain this information to comply with legal obligations, resolve disputes, and enforce my agreements.
Transfer of Personal Data Outside the EU
I may store and process your information through third-party hosting services in the United States and other countries. As a result, I may transfer your personal data to countries whose data protection and government surveillance laws differ from those in your country. If I transfer information about you outside the EU, I rely on the EU-U.S. Privacy Shield as the legal basis for the transfer, as Google Cloud is certified under the EU-U.S. Privacy Shield.
Your Rights
If you reside in certain regions, including the EU, you have a number of rights regarding your personal data. Some of these rights apply generally, and some apply only in certain cases. These rights include:
- Access: You may have the right to access and receive a copy of the personal data I hold about you by contacting me via the information below.
- Change, Restrict, Delete: You may also have the right to change, restrict my use of, or delete your personal data. Except for exceptional circumstances (such as when I am required to store data for legal reasons), I will delete your personal data upon request.
-
Object:
- You can object to my processing of some of your data based on my legitimate interests.
- You can also object to receiving marketing messages from me after you have explicitly consented to them.
In such cases, I will delete your personal data unless I can demonstrate compelling legitimate grounds for its continued use or if it is legally required.
- Complaint: If you reside in the EU and wish to raise concerns about my use of your data (without prejudice to any other rights you may have), you have the right to do so with your local data protection authority.
How to Contact Me
For purposes of EU data protection law, I, Lena Hermisch, am the data controller of your personal information. If you have any questions or concerns, you can contact me at lena@getthewave.de.