Privacy policy
Name and contact details of the responsible
Controller:
Gotcha Matcha GmbH
Hegestraße 48
20251 Hamburg
E-mail: info@gotchamatcha.de
2. collection and storage of personal data and the nature and purpose of their use
a) When you visit the website
When you visit our website, the browser used on your device automatically sends information to the server of our website. This information is temporarily stored in a so-called log file. The following information is collected without any action on your part and stored until it is automatically deleted
- IP address of the requesting computer,
- Date and time of access,
- Name and URL of the accessed file,
- the website from which access was made (referrer URL)
- browser used and, if applicable, the operating system of your computer and the name of your access provider.
The aforementioned data is processed by us for the following purposes
- Ensuring a smooth connection to the website,
- Ensuring a comfortable use of our website,
- evaluating system security and stability and
- for other administrative purposes.
The legal basis for data processing is Art. 6 para. 1 sentence 1 lit. f GDPR. Our legitimate interest follows from the purposes for data collection listed above. Under no circumstances do we use the data collected for the purpose of drawing conclusions about your person. We do not use cookies or analysis services when you visit our website.
b) When registering for our newsletter
If you have expressly consented in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR, we will use your email address to send you our newsletter on a regular basis. It is sufficient to provide an email address to receive the newsletter. You can unsubscribe at any time, for example via a link at the end of each newsletter. Alternatively, you can also send your unsubscribe request at any time to info@gotchamatcha.de by e-mail.
3. Transfer of Data
Your personal data will not be transferred to third parties for purposes other than those listed below. We only pass on your personal data to third parties if:
- you have given your express consent to this in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR,
- the disclosure pursuant to Art. 6 para. 1 sentence 1 lit. f GDPR is necessary for the assertion, exercise or defense of legal claims and there is no reason to assume that you have an overriding interest worthy of protection in not disclosing your data,
- in the event that there is a legal obligation for the disclosure pursuant to Art. 6 para. 1 sentence 1 lit. c GDPR, and
- this is legally permissible and necessary for the processing of contractual relationships with you in accordance with Art. 6 para. 1 sentence 1 lit. b GDPR.
Depending on the payment method, payment processing may be carried out by the payment service provider
Shopify International Limited
Victoria Buildings, 2nd floor
1-2 Haddington Road
Dublin 4, D04 XN32, Ireland
Managing Director: Tobias Lütke
Email: hilfe@shopify.de
or through
PayPal (Europe) S.à r.l. et Cie, S.C.A., Société en Commandite par Actions
22-24 Boulevard Royal, L-2449 Luxembourg, RCS Luxembourg
Managing Director: Daniel Schulman
Phone: +49 69 945189832
E-mail: impressum@paypal.com
Your data relevant for payment processing will be used by Shopify or PayPal exclusively for processing the payment transaction.
4. Collection of personal data when visiting our website, cookies
(1) When using our website for purely informational purposes, i.e. if you do not register or otherwise provide us with information, we only collect the personal data that the browser you are using transmits to our server and that is technically necessary for the operation of our website and to ensure stability, functionality and security. The data is collected in this context in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR on the basis of our legitimate interest and includes in particular: the following data IP address (possibly in anonymized form), date and time at the time of access to our website, content of the request (specific page), access status/http status code, amount of data transferred in each case, the browser used, the operating system used.
(2) In addition to the aforementioned data, cookies are stored on your computer when you use our website. Cookies are small text files that are stored on your hard disk by the browser you use and through which certain information flows to us. Cookies cannot execute programs or transfer viruses to your computer. They are used to make our website more user-friendly and effective overall and to simplify your visit to our website (e.g. displaying the contents of your shopping cart the next time you visit our website).
Our website uses transient and persistent cookies in particular. Transient cookies are automatically deleted when you close the browser. These include session cookies in particular. These store a so-called session ID, with which various requests from your browser can be assigned to the joint session. This allows your computer to be recognized when you visit our website again. The session cookies are deleted when you log out or close the browser. Persistent cookies are automatically deleted after a specified period, which may vary depending on the cookie. You can delete these cookies at any time in the security settings.
If the use of these cookies results in the processing of personal data, the legal basis for this is Art. 6 para. 1 lit. b GDPR (performance of the contract), Art. 6 para. 1 lit. a (consent given) or Art. 6 para. 1 lit. f GDPR (protection of our legitimate interests).
(3) You can configure the security settings of your browser according to your preferences regarding the storage of cookies and, for example, refuse to accept third-party cookies or all cookies. To do this, please use the help menu of the browser you are using. If you reject all or some cookies, you may not be able to use all the functions of our website.
5 Use of Google Analytics
(1) This website uses Google Analytics, a web analysis service of Google Inc (“Google”). Google Analytics uses “cookies”, which are text files placed on your computer, to help the website analyze how users use the site. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there. However, due to the IP anonymization on this website, your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and truncated there. Google will use this information on behalf of the operator of this website for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage to the website operator.
(2) The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.
(3) You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. You can also prevent Google from collecting the data generated by the cookie and relating to your use of the website (including your IP address) and from processing this data by Google by downloading and installing the browser plug-in available at the following link: http://tools.google.com/dlpage/gaoptout?hl=de.
As an alternative to this plug-in, in particular when accessing our website via mobile devices, it is necessary to click on the following link (opt-out cookie) to prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) to Google and the processing of this data by Google. Google Analytics Opt-out
(4) This website uses Google Analytics with the extension “_anonymizeIp()”. This means that IP addresses are further processed in abbreviated form, so that they cannot be linked to a specific person. If the data collected about you is personally identifiable, it will be excluded immediately and the personal data will be deleted immediately.
(5) We use Google Analytics to analyze and regularly improve the use of our website. We can use the statistics obtained to improve our offer and make it more interesting for you as a user. For the exceptional cases in which personal data is transferred to the USA, Google has submitted to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework. The legal basis for the use of Google Analytics is Art. 6 para. 1 sentence 1 lit. f GDPR.
(6) Information from the third-party provider: Google Dublin, Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland, Fax: +353 (1) 436 1001. Terms of use: http://www.google.com/analytics/terms/de.html, overview of data protection: http://www.google.com/intl/de
/analytics/learn/privacy.html, as well as the privacy policy: http://www.google.de/intl
/en/policies/privacy.
(7) This website also uses Google Analytics for a cross-device analysis of visitor flows, which is carried out via a user ID. You can deactivate the cross-device analysis of your usage in your customer account under “My data”, “Personal data”.
6. Social Media Plugins
We do not use any social media plugins
7. rights of data subjects
You have the right to
- to request information about your personal data processed by us in accordance with Art. 15 GDPR. In particular, you can request information about the purposes of processing, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right of appeal, the origin of your data if it was not collected by us, as well as the existence of automated decision-making including profiling and, if applicable, meaningful information on its details;
- in accordance with Art. 16 GDPR, to immediately request the correction of incorrect or incomplete personal data stored by us
- in accordance with Art. 17 GDPR, to request the erasure of your personal data stored by us, unless the processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest or for the establishment, exercise or defense of legal claims;
- in accordance with Art. 18 GDPR, to demand the restriction of the processing of your personal data if the accuracy of the data is disputed by you, the processing is unlawful but you refuse to delete it and we no longer need the data, but you need it to assert, exercise or defend legal claims or you have lodged an objection to the processing in accordance with Art. 21 GDPR
- in accordance with Art. 20 GDPR, to receive your personal data that you have provided to us in a structured, commonly used and machine-readable format or to request that it be transmitted to another controller
- in accordance with Art. 7 para. 3 GDPR, to revoke your consent to us at any time. As a result, we may no longer continue the data processing that was based on this consent in the future and
- to lodge a complaint with a supervisory authority in accordance with Art. 77 GDPR. As a rule, you can contact the supervisory authority of your usual place of residence or workplace or our company headquarters.
8. right to object
If your personal data are processed on the basis of legitimate interests in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR, you have the right to object to the processing of your personal data in accordance with Art. 21 GDPR, provided that there are reasons for this arising from your particular situation or the objection is directed against direct advertising. In the latter case, you have a general right to object, which will be implemented by us without specifying a particular situation. If you wish to exercise your right of revocation or objection, simply send an e-mail to info@gotcha-matcha.de .
9. data security
We use the widespread SSL (Secure Socket Layer) method in conjunction with the highest level of encryption supported by your browser when you visit our website. You can tell whether an individual page of our website is transmitted in encrypted form by the closed display of the key or lock symbol in the address bar or footer of your browser. We also use suitable technical and organizational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction or unauthorized access by third parties. Our security measures are continuously improved in line with technological developments.
10. topicality and amendment of this data protection declaration
This data protection declaration is currently valid and is dated January 2024. Due to the further development of our website and offers on it or due to changed legal or official requirements, it may become necessary to change this data protection declaration. You can view, access and print out the current privacy policy at any time on this website.