Data protection
Data protection
Privacy Policy
A. Responsible for data processing
Responsible for the processing of personal data within the scope of this website in accordance with the provisions of the General Data Protection Regulation (GDPR) is:
GDV Mouldservice GmbH
Zankeltrad 9
92693 Eslarn
represented by the managing director Marko Römer
Telephone: 09653/657989-0
Email: info@goatsmoke.de
With this privacy policy we inform you about the scope of the processing of your personal data (hereinafter referred to as "data").
B. Data processing
We process data in the course of operating our website. The processing of data also includes disclosure by transmission.
For data transfers to the USA, there is an adequacy decision of the EU Commission, the EU-US Privacy Shield. In this, the Commission has certified that the guarantees for the transfer of data to the USA on the basis of the EU-US Privacy Shield correspond to the data protection standards in the EU. To the extent that we transfer data to the USA, we have marked the participation of our service providers in the EU-US Privacy Shield.
The data concerned, processing purposes, legal bases, recipients and transfers to third countries are listed in the following table:
a) Log file
We log your visit to our websites. The following data is processed: name of the website accessed, date and time of access, volume of data transferred, browser type and version, operating system you use, referrer URL (the previously visited website), your IP address and the requesting provider. This is necessary to ensure the security of the website. We process the data accordingly on the basis of our legitimate interests in accordance with Art. 6 Para. 1 f) GDPR . The log file is deleted after seven days, unless it is required to clarify or prove specific violations of law that became known within the retention period.
b) Hosting
As part of the hosting, all data to be processed in connection with the operation of this website is stored. This is necessary to enable the operation of the website. We process the data accordingly on the basis of our legitimate interests in accordance with Art. 6 Para. 1 f) GDPR . To provide our online presence, we use services from web hosting providers to whom we transmit the above-mentioned data.
c) Contact
If you contact us, your data (name, contact details, if provided by you) and your message will be processed exclusively for the purpose of processing and handling your request. We process this data on the basis of Art. 6 Para. 1 b) GDPR or Art. 6 Para. 1 f) GDPR to process your request.
d) Newsletter
In order to be able to send you regular information about our company and our offers, we offer to send you a newsletter. When you register for the newsletter, we process the data you enter (email address and other voluntary information).
The newsletter will be sent to you upon registration based on your consent in accordance with Art. 6 (1) (a) GDPR .
Registration for the newsletter is carried out using the so-called double opt-in procedure. To prevent misuse, after you register we will send you an email asking you to confirm your registration. In order to be able to prove the registration process in accordance with legal requirements, your registration will be logged. This includes the storage of the registration and confirmation time as well as your IP address. We use service providers to send the newsletter, to whom we transmit the above-mentioned data.
The data is transmitted to the servers of the following service providers in the USA:
Mailchimp: Rocket Science Group, LLC, 675 Ponce De Leon Ave NE #5000, Atlanta, GA 30308
Certification under:
https://www.privacyshield.gov/participant?id=a2zt0000000TO6hAAG&status=Active
Further information on data protection can be found at:
https://mailchimp.com/legal/privacy/
e) Customer account
If you open a customer account, you agree that your inventory data (name, address, email address, bank details) and your usage data (user name, password) will be saved. This allows us to identify you as a customer and gives you the opportunity to manage your orders.
Your data will be processed on the basis of your consent in accordance with Art. 6 Para. 1 a) GDPR .
f) Purchase processing
We process your order data to process the purchase contract. The data is processed accordingly on the basis of Art. 6 Para. 1 b) GDPR .
We will send your address details to the company responsible for the delivery. If this is necessary to process the contract, we will also send your email address or telephone number to the company responsible for the delivery in order to coordinate a delivery date (advice).
We transmit your transaction data (name, date of order, payment method, shipping and/or receipt date, amount and payment recipient, if applicable bank details or credit card details) to the payment service provider commissioned to process the payment.
g) Cookies, website analysis and marketing
To enable the use of certain functions, we use so-called cookies. These are short data packets that are stored on your device and exchanged with other providers. Some of the cookies we use are deleted immediately after you close your browser (so-called session cookies). Other cookies remain on your device and enable your browser to be recognized the next time you visit (persistent cookies).
You can delete all cookies stored on your device and set the common browsers to prevent the storage of cookies.
In this case, you may have to re-adjust some settings each time you visit this website and accept that some functions may be impaired.
We use cookies in connection with the following functionalities:
a) Google Analytics
For website analysis, we use “Google Analytics”, a web analysis service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics uses so-called “cookies”, text files that are stored on your computer and enable an analysis of your use of the website
The information generated by the cookie about your use of this website (including your IP address) is transmitted to a Google server in the USA and stored there. We use the stored information to evaluate your use of the website, to compile reports on website activity for website operators and to provide other services related to website activity. We process the data obtained in this way due to our overriding interest in the optimal marketing of our online offering in accordance with Art. 6 Para. 1 f) GDPR. Google will under no circumstances associate your IP address with other Google data.
We would like to point out that this website uses Google Analytics with the extension "anonymizeIp()". This means that IP addresses are shortened before being transmitted to a server in the USA. A direct personal reference in connection with the stored data is therefore generally excluded. Only in exceptional cases is the full IP address transmitted to a server in the USA and shortened there.
You can object to the collection of data at any time with effect for the future by downloading the Google Analytics browser deactivation add-on at
Use http://tools.google.com/dlpage/gaoptout?hl=de .
Please also note the information on the use of data by Google in the Google Partner Network at:
http://www.google.com/intl/de/policies/privacy/partners/
www.google.de/privacy_ads.html
Google is certified under:
https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active
Further information on data protection can be found at: https://policies.google.com/privacy?hl=de&gl=de
bb) Facebook Remarketing/Retargeting: Facebook Custom Audiences (Pixels/Cookies)
We use a so-called tracking pixel on our website. When you visit certain pages, a cookie is stored on your device. The cookies remain permanently on your PC. The cookies are used to track which third-party ads and pages users use to access our website. The process is used to optimize our advertising by evaluating the statistical data we receive using the cookies. We process the data obtained in this way based on our overriding interest in the optimal marketing of our online offering in accordance with Art. 6 Para. 1 f) GDPR.
The cookies do not identify you personally. The data is anonymous to us and does not allow us to draw any conclusions about the user. The information generated by the cookie about your use of this website (including your IP address) is transferred to a Facebook server in the USA and stored there.
Facebook is certified under:
https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active
Further information on data protection can be found at:
https://www.facebook.com/help/568137493302217
You can object to the data collection at any time with effect for the future by [insert opt-out option]
Consent to the use of cookies.
In order for our website to function properly, we use cookies. In order to obtain your valid consent to the use and storage of cookies in the browser you use to access our website and to properly document this, we use a consent management platform: CookieFirst. This technology is provided by Digital Data Solutions BV, Plantage Middenlaan 42a, 1018 DH, Amsterdam, the Netherlands. Website: https://cookiefirst.com referred to as CookieFirst.
When you access our website, a connection is established with the CookieFirst server to give us the opportunity to obtain valid consent from you to use certain cookies. CookieFirst then stores a cookie in your browser to enable only the cookies you have consented to and to properly document this. The processed data is stored until the specified storage period expires or you request that the data be deleted. Deviating from this, certain statutory retention periods may apply.
CookieFirst is used to obtain the legally required consent to use cookies. The legal basis for this is Article 6 paragraph 1 letter c of the General Data Protection Regulation (GDPR).
Data processing agreement
We have concluded a data processing agreement with CookieFirst. This is a contract required under data protection law that ensures that the data of our website visitors is only processed in accordance with our instructions and in compliance with the GDPR.
Server log files
Our website and CookieFirst automatically collect and store information in so-called server log files, which your browser automatically transmits to us. The following data is collected:
- Your consent status or withdrawal of your consent
- Your anonymized IP address
- Information about your browser
- Information about your device
- The date and time of your visit to our website
- The URL of the website where you saved or updated your consent settings
- The approximate location of the user who has stored their consent preferences
- A universally unique identifier (UUID) of the website visitor who clicked on the banner cookie
The cookies we use on our website are
Updated: 9.9.2024, 9:00
Necessary |
|||||
name |
Purpose |
Domain name |
Sequence |
Provider |
type |
__csrf_token-**** |
A CSRF token is a secret, unique, and unpredictable value generated by a server-side application to protect vulnerable CSRF resources. |
www.shisha-world.com |
session |
Cookies |
|
cookiefirst-consent |
This cookie stores your cookie settings for this website. You can change these or withdraw your consent at any time. |
shisha-world.com |
a year |
Cookies |
|
cookiefirst-consent |
This cookie stores your cookie settings for this website. You can change these or withdraw your consent at any time. |
shisha-world.com |
Persistent |
Local Storage |
|
cookiefirst-id |
This cookie contains your unique ID so that CookieFirst can identify unique visitors to this website. |
shisha-world.com |
Persistent |
Local Storage |
|
nocache |
This cookie tells the browser not to create a cache on the affected page. |
www.shisha-world.com |
session |
Cookies |
|
permanentlyBasketRefreshed |
Used to ensure the correct functioning of the shopping cart and to store the shopping cart contents. |
www.shisha-world.com |
session |
Cookies |
|
permanentBasketSession |
This cookie ensures the correct functioning of the shopping cart and the storage of the shopping cart contents. |
www.shisha-world.com |
a month |
Cookies |
|
session-1 |
This cookie is set when you visit Shopware online shops for the first time to save your login data. |
www.shisha-world.com |
session |
Cookies |
|
x-ua-device |
This cookie is used to determine what type of device or browser software the visitor is using. This allows the website to be displayed correctly. |
www.shisha-world.com |
session |
Cookies |
|
performance |
|||||
name |
Purpose |
Domain name |
Sequence |
Provider |
type |
_ga |
Registers a unique ID for a website visitor to track how the visitor uses the website. The data is used for statistics. Data transfer to third countries: USA. Google LLC. is certified according to the Data Privacy Framework, which means that your rights as a data subject can be guaranteed. |
.shisha-world.com |
2 years |
Cookies |
|
_ga_******** |
This cookie stores a unique ID for a website visitor and tracks how the visitor uses the website. The data is used for statistics. Data transfer. to third countries: USA. Google LLC. is certified according to the Data Privacy Framework, which means that your rights as a data subject can be guaranteed. |
.shisha-world.com |
2 years |
Cookies |
|
_ga_******** |
This cookie stores a unique ID for a website visitor and tracks how the visitor uses the website. The data is used for statistics. Data transfer. to third countries: USA. Google LLC. is certified according to the Data Privacy Framework, which means that your rights as a data subject can be guaranteed. |
.shisha-world.com |
2 years |
Cookies |
|
_gat_UA-**** |
The _gat_UA cookie is a variation of the Google Analytics _gat cookie. It is used to limit the collection of data on high traffic websites. The cookie is set by the Google Analytics tracking code and contains the unique ID of the tracking account or website it relates to. The _gat_UA cookie is typically used to throttle the request rate, which means it limits the amount of data Google Analytics can collect from the website. |
.shisha-world.com |
a few seconds |
Cookies |
|
_gid |
Registers a unique ID for a website visitor to track how the visitor uses the website. The data is used for statistics. Data transfer to third countries: USA. Google LLC. is certified according to the Data Privacy Framework, which means that your rights as a data subject can be guaranteed. |
.shisha-world.com |
a day |
Cookies |
|
_hjSession_****** |
A cookie that contains the current session data. This means that subsequent requests within the session window are associated with the same Hotjar session. |
.shisha-world.com |
30 minutes |
Cookies |
|
_hjSessionUser_****** |
Hotjar cookie that is set when a user first lands on a page containing the Hotjar script. It is used to maintain the Hotjar user ID, unique to that site, in the browser. This ensures that behavior on subsequent visits to the same site is attributed to the same user ID. |
.shisha-world.com |
a year |
Cookies |
|
hjActiveViewportIds |
This element is set by Hotjar for performance and analytics purposes. |
shisha-world.com |
Persistent |
Local Storage |
|
klaviyoOnsite |
This cookie is set by Klaviyo in relation to our order notification system. It manages, among other things, tracking and shipping updates. |
shisha-world.com |
Persistent |
Local Storage |
|
Functional |
|||||
name |
Purpose |
Domain name |
Sequence |
Provider |
type |
__kla_id |
This cookie is set by Klaviyo in relation to our order notification system. It manages, among other things, tracking and shipping updates. |
www.shisha-world.com |
2 years |
Cookies |
|
fblo_1770124373294723 |
Social Login |
shisha-world.com |
session |
--- |
Cookies |
VISITOR_INFO1_LIVE |
This cookie allows YouTube to monitor bandwidth usage. |
.youtube.com |
6 months |
Cookies |
|
YSC |
Register unique IDs and keep statistics on what videos users have watched on YouTube. |
.youtube.com |
session |
Cookies |
|
Advertising |
|||||
name |
Purpose |
Domain name |
Sequence |
Provider |
type |
VISITOR_PRIVACY_METADATA |
This cookie is used to track and enhance the user's privacy settings on YouTube. |
.youtube.com |
6 months |
Cookies |
|
Unclassified |
|||||
name |
Purpose |
Domain name |
Sequence |
Provider |
type |
subscriberUUID |
This cookie does not have a description yet. Our team is working on providing more information. |
shisha-world.com |
Persistent |
Local Storage |
This cookie table was created and updated by Cookie Consent - CookieFirst .
Updated: 9.9.2024, 9:00
What are cookies?
Cookies and similar technologies are very small text documents or pieces of code that often contain a unique identification code. When you visit a website or use a mobile application, a computer asks your computer or mobile device for permission to store that file on your computer or mobile device and to access information. Information collected through cookies and similar technologies may include the date and time of the visit and how you use a particular website or mobile application.
Why do we use cookies?
Cookies ensure that you remain logged in during your visit to our online store, that all items in your shopping cart are saved, that you can shop safely and that the website continues to function smoothly. The cookies also ensure that we can see how our website is used and how we can improve it. In addition, depending on your preferences, our own cookies may be used to present you with targeted advertising that matches your personal interests.
What type of cookies do we use?
Necessary cookies
These cookies are necessary for the website to function properly. Some of the following actions can be performed using these cookies.
- Save items in a shopping cart for online purchases
- Save your cookie settings for this website
- Saving language settings
- Log in to our portal. We need to verify that you are logged in.
Performance cookies
These cookies are used to collect statistical information about the use of our website, also known as analytics cookies. We use this data to improve performance and optimize the website.
Functional cookies
These cookies enable more functionality for our website visitors. These cookies may be set by our third party service providers or our own website. The following functionalities may or may not be enabled if you accept this category.
- Live chat services
- Watch online videos
- Social media sharing buttons
- Log in to our website using social media.
Advertising / Tracking Cookies
These cookies are set by third-party advertising partners and are used for profiling and tracking data across multiple websites. If you accept these cookies, we can display our advertising on other websites based on your user profile and preferences.
These cookies also store data on how many visitors have seen or clicked on our advertisements in order to optimize advertising campaigns.
Unclassified
These cookies are still in the classification process. They appear in one of the following categories: Necessary, Performance, Functional or Advertising.
How can I disable or remove cookies?
You can opt-out of all but essential cookies. You can change your browser settings to block cookies. Most browsers have an explanation of how to do this in the "help" function. However, if you block cookies, you may not be able to use all the technical features of our website and this may have a negative impact on your user experience.
a) Integration of external content
We use external dynamic content to optimize the presentation and offering of our website. When you visit the website, a request is automatically sent to the server of the respective content provider via API, in which certain log data (e.g. the user's IP address) is transmitted. The dynamic content is then sent to our website and displayed there.
We use external content in connection with the following functionalities:
b) Google Maps
We use the Google Maps map service to provide you with an interactive map. When the map is displayed, data, including your IP address and location, is transferred to Google servers in the USA and stored there. This processing is carried out based on our overriding legitimate interest in the optimal marketing of our offer in accordance with Art. 6 Para. 1 f) GDPR .
Google is certified under:
https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active
Further information on data protection can be found at: https://policies.google.com/privacy?hl=de&gl=de
c) Social plugins
We use third-party plug-ins on our websites. This allows you to inform your contacts whether you like our website, point out content or share content. The plug-ins are identified by the logo of the respective third-party provider.
When you visit our site, your data will be transferred to the respective third-party providers.
If you are also a user of a third-party provider, this data can be assigned to the corresponding user account with the provider.
This data may be transferred to the third-party provider even if you are not registered as a user with the third-party provider and do not click on the plug-in on our website.
However, if data is transmitted without simultaneous registration with the third-party provider, it is not immediately possible to establish a direct personal reference to you, e.g. via the IP address; this would only be possible with information from your provider.
The purpose and scope of data processing by the third-party provider can be found in the data protection information of the respective provider.
This data is processed based on our overriding legitimate interest in the optimal marketing of our online offering in accordance with Art. 6 (1) (f) GDPR .
Our website uses plugins from the following providers:
- Facebook Connect, Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland.
You can log in to our site using Facebook Connect. In this case, no additional registration is necessary. To log in, you will be redirected to the Facebook site, where you can log in with your user data.
When you register via Facebook, our services are linked to your Facebook user profile. Through the link, the following information is automatically sent to us by the respective social media service provider:
- Username
- E-mail address
This information is essential for the conclusion of the contract in order to be able to identify you.
In addition, if you authenticate using these services, Facebook gives you the option of accessing your contacts. However, we do not make use of this.
We would like to point out that the use of the Facebook login may result in the collection and possible further use of personal data. However, this data collection and use is the responsibility of Facebook and cannot be influenced by us.
Certification at: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active
Further information at: https://www.facebook.com/privacy/explanation https://www.facebook.com/full_data_use_policy
d) Facebook Custom Audiences (customer list)
We use the Custom Audience services of Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA (Facebook). Customer data is transferred to Facebook in lists. The data is sent to Facebook servers in the USA. The data is used to analyze user behavior on the Internet and to personalize advertising and may be linked to an existing user account on Facebook.
Certification at: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active
Further information at: https://www.facebook.com/privacy/explanation
e) Payment processing by Klarna
In order to offer you Klarna's payment options, we will transfer personal data, such as contact details and order data, to Klarna. This enables Klarna to assess whether you can use the payment options offered through Klarna and to adapt the payment options to your needs. General information about Klarna can be found here . Your personal data will be treated by Klarna in accordance with the applicable data protection regulations and in accordance with the information in Klarna's privacy policy .
f) Credit card processing by VR-Payment
In order to offer you credit card payment, we will transmit personal data, such as contact details and order data, to VR Payment. This enables VR Payment to assess whether you can use the card payment processed via VR Payment and to adapt the payment options to your needs. General information about VR Payment can be found here . Your personal data will be treated by VR Payment in accordance with the applicable data protection regulations and in accordance with the information in VR Payment's data protection regulations .
g) Address data validation
On our website, we offer you the opportunity to check certain entries in address forms in our web shop for input errors in real time. This is intended to avoid problems with the delivery of the products you have ordered due to incorrect information.
We would also like to ensure that your contact details are valid for sending information about your order or for any necessary queries.
The legal basis for the transmission, processing and temporary storage of data by the service provider is Art. 6 Paragraph 1 Letter b of GDPR, as it is essential for the performance of the contract or for the implementation of pre-contractual measures that some of the data you enter into the input mask is checked for accuracy. The following data is processed by the service provider:
- Address (country, city, postal code, street, house number if applicable)
The data is processed separately by the service provider and is not merged. The requests are deleted by the service provider as soon as the status of the entered data has been determined and storage in the web shop has been completed, but no later than after 30 days.
C. Duration of data storage
We only store personal data for as long as it is necessary for the purposes for which it is processed or until you have withdrawn your consent. If statutory retention periods apply, the storage period for certain data may be up to 10 years, regardless of the processing purposes.
D. Your rights as a data subject
a) Information
Upon request, you can obtain information about all personal data that we have stored about you at any time and free of charge.
b) Correction, deletion, restriction of processing (blocking), objection
If you no longer agree to the storage of your personal data or if it has become incorrect, we will, upon your instruction, delete or block your data or make the necessary corrections (as far as this is possible under applicable law). The same applies if we are to process data only in a restricted manner in the future.
c) Data portability
Upon request, we will provide you with your data in a common, structured and machine-readable format so that you can transmit the data to another controller if you wish.
d) Right of appeal
You have the right to lodge a complaint with the competent supervisory authority:
https://www.bfdi.bund.de/DE/Infothek/Anschrift_Links/anschrift_links-node.html
e) Right of revocation for consents with effect for the future
You can revoke your consent at any time with effect for the future. Your revocation does not affect the legality of the processing up to the time of revocation.
f) Restrictions
Data for which we are unable to identify the person concerned, e.g. if it has been anonymized for analysis purposes, is not covered by the above rights. Information, deletion, blocking, correction or transfer to another company may be possible with regard to this data if you provide us with additional information that allows us to identify it.
g) Exercising your rights as a data subject
If you have any questions about the processing of your personal data, information, correction, blocking, objection or deletion of data or if you wish to transfer the data to another company, please contact
GDV Mouldservice GmbH
Zankeltrad 9
92693 Eslarn
Email: info@goatsmoke.de