Privacy Policy
1. Controller
The controller responsible for data processing on this website is:
Phillip Nägele
Karl-Bröger-Straße 5
90765 Fürth
Germany
Email: info@neonframe.de
Phone: +49 178 7567467
2. Hosting and Shop System (Shopify)
This website is operated via Shopify Inc., 151 O’Connor Street, Ground Floor, Ottawa, Ontario K2P 2L8, Canada.
Shopify provides the e-commerce platform through which we offer our products.
In the course of using Shopify, personal data (e.g., IP address, order data, contact details) is processed.
Processing is based on:
-
Art. 6(1)(b) GDPR (performance of a contract)
-
Art. 6(1)(f) GDPR (legitimate interest in the secure and efficient operation of the website)
A data processing agreement pursuant to Art. 28 GDPR has been concluded with Shopify.
Data transfers to third countries (in particular the USA) are carried out on the basis of:
-
EU Standard Contractual Clauses pursuant to Art. 46 GDPR
-
where applicable, the EU-US Data Privacy Framework
Further information:
https://www.shopify.com/legal/privacy
3. Server Log Files
When accessing this website, information is automatically collected:
-
IP address
-
Date and time
-
Browser type
-
Operating system
-
Referrer URL
These data serve the technical security and stability of the website.
Legal basis: Art. 6(1)(f) GDPR.
Legitimate interest: Ensuring trouble-free operation and protection against attacks.
Storage period: generally a maximum of 14 days.
4. Contract Processing and Customer Account
In the context of an order, we process:
-
First and last name
-
Address
-
Email address
-
Payment data
-
Order details
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
Retention periods:
Due to commercial and tax law requirements, data is stored for 6 or 10 years.
5. Payment Service Providers
For payment processing, payment data is transmitted to the following providers:
PayPal
PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg
Legal basis: Art. 6(1)(b) GDPR
https://www.paypal.com/de/webapps/mpp/ua/privacy-full
Klarna
Klarna Bank AB (publ), Sweden
Legal basis: Art. 6(1)(b) GDPR
https://www.klarna.com/de/datenschutz/
Credit Card / Shopify Payments
Payment processing is carried out via Shopify Payments.
Legal basis: Art. 6(1)(b) GDPR.
Data processing agreements or independent data protection responsibilities exist with the payment service providers.
6. Cookies and Consent Management
Our website uses cookies.
Non-essential cookies are only set after your explicit consent in accordance with Art. 6(1)(a) GDPR.
Consent is obtained via a cookie consent tool and can be revoked at any time with effect for the future.
7. Google Analytics (GA4)
This website uses Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics uses cookies that enable an analysis of the use of the website.
IP anonymization is activated.
Legal basis: Art. 6(1)(a) GDPR (consent).
A data processing agreement pursuant to Art. 28 GDPR has been concluded with Google.
Data may be transferred to the USA.
The transfer takes place on the basis of:
-
EU Standard Contractual Clauses
-
where applicable, the EU-US Data Privacy Framework
Retention period of user data: 2 months (unless individually configured otherwise).
Consent can be withdrawn at any time via the cookie banner.
8. Meta Pixel (Facebook / Instagram)
This website uses the Meta Pixel of Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
This allows user behavior to be analyzed after users click on a Meta advertisement.
Legal basis: Art. 6(1)(a) GDPR (consent).
For the processing of certain data within the framework of the Meta Pixel, we are jointly responsible with Meta Platforms Ireland Ltd. pursuant to Art. 26 GDPR.
The joint controller agreement can be viewed here:
https://www.facebook.com/legal/controller_addendum
Data may be transferred to the USA.
The transfer is based on Standard Contractual Clauses or the EU-US Data Privacy Framework.
Consent can be withdrawn at any time via the cookie consent tool.
9. Storage Period
Personal data is stored only as long as:
-
it is necessary for contract fulfillment
-
statutory retention periods apply
-
granted consent has not been withdrawn
10. Rights of Data Subjects
You have the right to:
-
Access (Art. 15 GDPR)
-
Rectification (Art. 16 GDPR)
-
Erasure (Art. 17 GDPR)
-
Restriction of processing (Art. 18 GDPR)
-
Data portability (Art. 20 GDPR)
-
Object (Art. 21 GDPR)
-
Withdraw granted consent (Art. 7(3) GDPR)
If processing is based on Art. 6(1)(f) GDPR, you have the right to object at any time, on grounds relating to your particular situation.
11. Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority.
Competent authority:
Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18
91522 Ansbach
Germany