Data protection
Data protection
Privacy Policy
A. Responsible for data processing
The entity responsible for the processing of personal data within the scope of this website in accordance with the provisions of the General Data Protection Regulation (GDPR) is:
GDV-German Design Variations GmbH
Zankeltrad 9
92693 Eslarn
represented by Managing Director Georg Kneißl
Email: info@goatsmoke.de
This privacy policy informs you about the scope of the processing of your personal data (hereinafter referred to as "data").
B. Data processing
We process data as part of operating our website. This data processing also includes disclosure through transmission.
For data transfers to the USA, there is an adequacy decision by the EU Commission, the EU-US Privacy Shield. In this decision, the Commission has certified that the guarantees for the transfer of data to the USA based on the EU-US Privacy Shield correspond to the data protection standards in the EU. Where we transfer data to the USA, we have indicated that our service providers participate in the EU-US Privacy Shield.
The specific data affected, processing purposes, legal bases, recipients and transfers to third countries are listed below:
a) Log file
We log your visit to our websites. The following data is processed: the name of the accessed website, the date and time of access, the amount of data transferred, the browser type and version, the operating system you are using, the referrer URL (the previously visited website), your IP address, and the requesting provider. This is necessary to ensure the security of the website. We process this data based on our legitimate interests pursuant to Art. 6 para. 1 f) GDPR . The log file is deleted after seven days, unless it is required for the investigation or proof of specific legal violations that became known within the retention period.
b) Hosting
As part of the hosting process, all data processed in connection with the operation of this website is stored. This is necessary to enable the website to function. We process this data accordingly based on our legitimate interests pursuant to Art. 6 para. 1 f) GDPR . To provide our online presence, we use services from web hosting providers, to whom we transmit the aforementioned data.
c) Making contact
If you contact us, your data (name, contact details, if provided by you) and your message will be processed solely for the purpose of handling and processing your request. We process this data on the basis of Article 6 Paragraph 1 b) GDPR or Article 6 Paragraph 1 f) GDPR for the purpose of processing your request.
d) Newsletter
To keep you regularly informed about our company and our offers, we offer a newsletter subscription. By subscribing to the newsletter, you consent to the processing of the data you provide (email address and any other voluntary information).
The newsletter is sent via registration based on your consent in accordance with Art. 6 para. 1 a) GDPR .
Newsletter registration uses a double opt-in process. To prevent misuse, we will send you an email after you register, asking you to confirm your subscription. To document the registration process in accordance with legal requirements, your registration is logged. This includes recording the registration and confirmation times, as well as your IP address. We use service providers to send the newsletter, and we transmit the aforementioned data to them.
The data will be transferred to the servers of the following service providers in the USA:
Mailchimp: Rocket Science Group, LLC, 675 Ponce De Leon Ave NE #5000, Atlanta, GA 30308
Certification under:
https://www.privacyshield.gov/participant?id=a2zt0000000TO6hAAG&status=Active
Further information on data protection can be found at:
https://mailchimp.com/legal/privacy/
e) Customer account
By creating a customer account, you consent to the storage of your personal data (name, address, email address, bank details) and your usage data (username, password). This allows us to identify you as a customer and enables you to manage your orders.
Your data will be processed on the basis of your consent in accordance with Art. 6 para. 1 a) GDPR .
f) Purchase processing
We process your order data to fulfill the purchase contract. This data processing is based on Article 6 Paragraph 1 b) GDPR .
We will forward your address details to the company commissioned with the delivery. If necessary for processing the contract, we will also forward your email address or telephone number to the delivery company for the purpose of coordinating a delivery date (notification).
We transmit your transaction data (name, date of order, payment method, shipping and/or receipt date, amount and payee, if applicable bank details or credit card details) to the payment service provider commissioned with processing the payment.
g) Cookies, website analytics and marketing
To enable the use of certain functions, we use cookies. These are small data packets that are stored on your device and exchanged with other providers. Some of the cookies we use are deleted immediately after you close your browser (session cookies). Other cookies remain on your device and allow us to recognize your browser on your next visit (persistent cookies).
You can delete all cookies stored on your device and configure common browsers to prevent the storage of cookies.
In this case, you may have to readjust some settings each time you visit this website and accept the impairment of some functions.
We use cookies in connection with the following functionalities:
aa) Google Analytics
We use “Google Analytics”, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, for website analysis.
Google Analytics uses so-called "cookies", text files that are stored on your computer and enable an analysis of your use of the website.
The information generated by the cookie about your use of this website (including your IP address) is transmitted to and stored on a Google server in the USA. We use the stored information to evaluate your use of the website, to compile reports on website activity for website operators, and to provide other services related to website activity. We process the data obtained in this way based on our legitimate interest in the optimal marketing of our online services pursuant to Art. 6 para. 1 f) GDPR. Google will under no circumstances associate your IP address with other data held by Google.
Please note that this website uses Google Analytics with the extension "anonymizeIp()". This shortens IP addresses before they are transmitted to a server in the USA. This generally prevents any direct link to an individual from being established through the stored data. Only in exceptional cases will the full IP address be transmitted to a server in the USA and shortened there.
You can object to data collection at any time with effect for the future by installing the Google Analytics browser deactivation add-on at [link to Google Analytics deactivation add-on].
Use http://tools.google.com/dlpage/gaoptout?hl=de .
Please also note the information on the use of data from Google in the Google Partner Network at:
http://www.google.com/intl/de/policies/privacy/partners/
www.google.de/privacy_ads.html
Google is certified under:
https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active
Further information on data protection can be found at: https://policies.google.com/privacy?hl=de&gl=de
bb) Facebook Remarketing/Retargeting: Facebook Custom Audiences (Pixels/Cookies)
We use a tracking pixel on our website. When you visit certain pages, a cookie is stored on your device. These cookies remain permanently on your computer. They allow us to track which ads and third-party websites lead users to our website. This process helps us optimize our advertising by analyzing the statistical data we obtain through these cookies. We process this data based on our legitimate interest in the optimal marketing of our online services, in accordance with Article 6(1)(f) of the GDPR.
The cookies are not used to personally identify you. The data is anonymous to us and does not allow us to draw any conclusions about the user. The information generated by the cookie about your use of this website (including your IP address) is transmitted to and stored on a Facebook server in the USA.
Facebook is certified under:
https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active
Further information on data protection can be found at:
https://www.facebook.com/help/568137493302217
You can object to data collection at any time with effect for the future by [insert opt-out option]
Consent to the use of cookies.
To ensure our website functions correctly, we use cookies. To obtain and properly document your valid consent to the use and storage of cookies in the browser you use to access our website, we use a consent management platform: CookieFirst. This technology is provided by Digital Data Solutions BV, Plantage Middenlaan 42a, 1018 DH, Amsterdam, Netherlands. Website: https://cookiefirst.com , referred to as CookieFirst.
When you access our website, a connection is established with CookieFirst's server to allow us to obtain your valid consent for the use of certain cookies. CookieFirst then stores a cookie in your browser to activate only the cookies you have consented to and to properly document this consent. The processed data is stored until the specified retention period expires or you request its deletion. Certain statutory retention periods may apply in deviation from this.
CookieFirst is used to obtain the legally required consent for the use of cookies. The legal basis for this is Article 6 Paragraph 1 Letter c of the General Data Protection Regulation (GDPR).
Data processing agreement
We have concluded a data processing agreement with CookieFirst. This is a legally required agreement under data protection law, which ensures that the data of our website visitors is processed only according to our instructions and in compliance with the GDPR.
Server log files
Our website and CookieFirst automatically collect and store information in so-called server log files, which your browser automatically transmits to us. The following data is collected:
- Your consent status or the revocation of your consent
- Your anonymized IP address
- Information about your browser
- Information about your device
- The date and time of your visit to our website
- The URL of the website where you saved or updated your consent settings.
- The approximate location of the user who has saved their consent preferences.
- A universally unique identifier (UUID) of the website visitor who clicked the cookie banner.
The cookies we use on our website are
Updated: September 9, 2024, 9:00 AM
|
Necessary |
|||||
|
name |
Purpose |
Domain name |
Sequence |
Provider |
type |
|
__csrf_token-**** |
A CSRF token is a secret, unique, and unpredictable value generated by a server-side application to protect vulnerable CSRF resources. |
www.goatsmoke.de |
session |
Cookie |
|
|
cookiefirst-consent |
This cookie stores your cookie settings for this website. You can change these settings or withdraw your consent at any time. |
www.goatsmoke.de |
a year |
Cookie |
|
|
cookiefirst-consent |
This cookie stores your cookie settings for this website. You can change these settings or withdraw your consent at any time. |
www.goatsmoke.de |
Persistent |
Local Storage |
|
|
cookiefirst-id |
This cookie contains your unique ID so that CookieFirst can identify unique visitors to this website. |
www.goatsmoke.de |
Persistent |
Local Storage |
|
|
nocache |
This cookie tells the browser that no cache should be created on the affected page. |
www.goatsmoke.de |
session |
Cookie |
|
|
permanentBasketRefreshed |
Used to ensure the shopping cart functions correctly and to save the shopping cart contents. |
www.goatsmoke.de |
session |
Cookie |
|
|
permanentBasketSession |
This cookie ensures the correct functioning of the shopping cart and the storage of the shopping cart contents. |
www.goatsmoke.de |
a month |
Cookie |
|
|
session-1 |
This cookie is set when you visit Shopware online shops for the first time to save your login details. |
www.goatsmoke.de |
session |
Cookie |
|
|
x-ua-device |
This cookie determines the type of device or browser software used by the visitor. This ensures the website is displayed correctly. |
www.goatsmoke.de |
session |
Cookie |
|
|
performance |
|||||
|
name |
Purpose |
Domain name |
Sequence |
Provider |
type |
|
_ga |
Registers a unique ID for each website visitor to track their website usage. The data is used for statistical purposes. Data is transferred to the USA. Google LLC is certified under the Data Privacy Framework, which means your rights as a data subject are guaranteed. |
www.goatsmoke.de |
2 years |
Cookie |
|
|
_ga_******** |
This cookie stores a unique ID for a website visitor and tracks how the visitor uses the website. The data is used for statistical purposes. Data transfer to third countries: USA. Google LLC is certified under the Data Privacy Framework, which means that your rights as a data subject are guaranteed. |
www.goatsmoke.de |
2 years |
Cookie |
|
|
_ga_******** |
This cookie stores a unique ID for a website visitor and tracks how the visitor uses the website. The data is used for statistical purposes. Data transfer to third countries: USA. Google LLC is certified under the Data Privacy Framework, which means that your rights as a data subject are guaranteed. |
www.goatsmoke.de |
2 years |
Cookie |
|
|
_gat_UA-**** |
The _gat_UA cookie is a variation of the Google Analytics _gat cookie. It is used to limit data collection on high-traffic websites. Set by the Google Analytics tracking code, this cookie contains the unique ID of the tracking account or website it relates to. The _gat_UA cookie is typically used to throttle the request rate, meaning it limits the amount of data Google Analytics can collect from the website. |
www.goatsmoke.de |
a few seconds |
Cookie |
|
|
_gid |
Registers a unique ID for each website visitor to track their website usage. The data is used for statistical purposes. Data is transferred to the USA. Google LLC is certified under the Data Privacy Framework, which means your rights as a data subject are guaranteed. |
www.goatsmoke.de |
a day |
Cookie |
|
|
_hjSession_****** |
A cookie containing the current session data. This means that subsequent requests within the session window are associated with the same Hotjar session. |
www.goatsmoke.de |
30 minutes |
Cookie |
|
|
_hjSessionUser_****** |
A Hotjar cookie that is set when a user first lands on a page containing the Hotjar script. It is used to maintain the Hotjar user ID, which is unique to that site, in the browser. This ensures that subsequent visits to the same site are associated with the same user ID. |
www.goatsmoke.de |
a year |
Cookie |
|
|
hjActiveViewportIds |
This element is set by Hotjar for performance and analysis purposes. |
www.goatsmoke.de |
Persistent |
Local Storage |
|
|
klaviyoOnsite |
This cookie is set by Klaviyo in connection with our order notification system. Among other things, it manages tracking and shipping updates. |
www.goatsmoke.de |
Persistent |
Local Storage |
|
|
Functional |
|||||
|
name |
Purpose |
Domain name |
Sequence |
Provider |
type |
|
__kla_id |
This cookie is set by Klaviyo in connection with our order notification system. Among other things, it manages tracking and shipping updates. |
www.goatsmoke.de |
2 years |
Cookie |
|
|
fblo_1770124373294723 |
Social Login |
www.goatsmoke.de |
session |
--- |
Cookie |
|
VISITOR_INFO1_LIVE |
This cookie allows YouTube to check bandwidth usage. |
.youtube.com |
6 months |
Cookie |
|
|
YSC |
Register unique IDs and compile statistics on which videos users have watched on YouTube. |
.youtube.com |
session |
Cookie |
|
|
Advertising |
|||||
|
name |
Purpose |
Domain name |
Sequence |
Provider |
type |
|
VISITOR_PRIVACY_METADATA |
This cookie is used to track and enhance the user's privacy settings on YouTube. |
.youtube.com |
6 months |
Cookie |
|
|
Unclassified |
|||||
|
name |
Purpose |
Domain name |
Sequence |
Provider |
type |
|
subscriberUUID |
This cookie has not yet been described. Our team is working on providing more information. |
www.goatsmoke.de |
Persistent |
Local Storage |
|
This cookie table was created and updated by Cookie Consent - CookieFirst .
Updated: September 9, 2024, 9:00 AM
What are cookies?
Cookies and similar technologies are very small text files or pieces of code that often contain a unique identifier. When you visit a website or use a mobile application, a computer requests permission from your computer or mobile device to store this file and access information. Information collected through cookies and similar technologies may include the date and time of your visit, as well as how you use a particular website or mobile application.
Why do we use cookies?
Cookies ensure that you remain logged in during your visit to our online shop, that all items in your shopping cart are saved, that you can shop securely, and that the website continues to function smoothly. Cookies also allow us to see how our website is used and how we can improve it. Furthermore, depending on your preferences, our own cookies may be used to present you with targeted advertising that matches your personal interests.
What type of cookies do we use?
Necessary cookies
These cookies are necessary for the website to function properly. Some of the following actions can be performed with these cookies.
- Save items to a shopping cart for online purchases
- Save your cookie settings for this website
- Saving language settings
- Log in to our portal. We need to verify that you are logged in.
Performance cookies
These cookies are used to collect statistical information about the use of our website; they are also known as analytics cookies. We use this data to improve performance and optimize our website.
Functional cookies
These cookies enable enhanced functionality for our website visitors. These cookies may be set by our external service providers or by our own website. The following functionalities may or may not be activated depending on whether you accept this category.
- Live chat services
- Watch online videos
- Social media sharing buttons
- Log in to our website using social media.
Advertising / Tracking Cookies
These cookies are set by external advertising partners and are used for profiling and tracking data across multiple websites. If you accept these cookies, we can display our advertising on other websites based on your user profile and preferences.
These cookies also store data about how many visitors have seen or clicked on our advertisements, in order to optimize advertising campaigns.
Unclassified
These cookies are still being classified. They will be displayed in one of the following categories: Necessary, Performance, Functional, or Advertising.
How can I disable or remove cookies?
You can choose to accept all cookies except those that are essential. You can change your browser settings to block cookies. Most browsers have instructions on how to do this in their "Help" section. However, blocking cookies may prevent you from using all the technical features of our website and could negatively impact your user experience.
a) Integration of external content
We use external dynamic content to optimize the presentation and offerings of our website. When you visit our website, an API automatically sends a request to the server of the respective content provider, transmitting certain log data (e.g., the user's IP address). The dynamic content is then transmitted to our website and displayed there.
We use external content in connection with the following functionalities:
b) Google Maps
We use the "Google Maps" service from Google to provide you with an interactive map. When the map is displayed, data, including your IP address and location, is transferred to and stored on Google servers in the USA. This processing is based on our overriding legitimate interest in the optimal marketing of our services, pursuant to Art. 6 para. 1 f) GDPR .
Google is certified under:
https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active
Further information on data protection can be found at: https://policies.google.com/privacy?hl=de&gl=de
c) Social plugins
We use third-party plugins on our websites. These allow you to inform your contacts whether you like our website, draw attention to content, or share content. The plugins are identified by the logo of the respective third-party provider.
When you visit our site, your data will be transferred to the respective third-party providers.
If you are also a user of a third-party provider, this data can be assigned to the corresponding user account with the provider.
This data may also be transferred to the third-party provider even if you are not registered as a user with the third-party provider and do not click on the plugin on our pages.
However, if data is transmitted without simultaneous registration with the third-party provider, it is not immediately possible to establish a direct personal link to you via, for example, your IP address; this would only be possible by obtaining information from your provider.
The purpose and scope of data processing by the third-party provider can be found in the respective provider's privacy policy.
The processing of this data is based on our overriding legitimate interest in the optimal marketing of our online services in accordance with Art. 6 para. 1 f) GDPR .
Our website uses plugins from the following providers:
- Facebook Connect, Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland.
You can log in to our site using Facebook Connect. In this case, no additional registration is required. You will be redirected to Facebook's website, where you can log in with your Facebook credentials.
When you register via Facebook, our services are linked to your Facebook user profile. This link automatically transmits the following information to us from the respective social media service provider:
- Username
- E-mail address
This information is absolutely necessary for concluding the contract in order to identify you.
Furthermore, Facebook grants access to your contacts when authenticating via these services. However, we do not make use of this.
Please note that using Facebook Login may result in Facebook collecting and potentially further processing your personal data. However, this data collection and use is the responsibility of Facebook and cannot be influenced by us.
Certification under: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active
Further information can be found at: https://www.facebook.com/privacy/explanation and https://www.facebook.com/full_data_use_policy
d) Facebook Custom Audiences (customer list)
We use the Custom Audience services of Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA (Facebook). Customer data is transferred to Facebook in lists. The data is sent to Facebook servers in the USA. The data is used to analyze user behavior on the internet and to personalize advertising, and may be linked to an existing Facebook user account.
Certification under: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active
Further information can be found at: https://www.facebook.com/privacy/explanation
e) Payment processing by Klarna
To offer you Klarna's payment options, we will transmit personal data, such as contact and order details, to Klarna. This allows Klarna to assess whether you are eligible for the payment options offered by Klarna and to tailor these options to your needs. General information about Klarna can be found here . Your personal data will be processed by Klarna in accordance with applicable data protection regulations and as described in Klarna's privacy policy .
f) Credit card processing via VR-Payment
To offer you credit card payment, we will transmit personal data, such as contact and order details, to VR Payment. This allows VR Payment to assess whether you are eligible for card payments processed through VR Payment and to tailor the payment options to your needs. General information about VR Payment can be found here . Your personal data will be processed by VR Payment in accordance with applicable data protection regulations and as described in VR Payment's privacy policy .
g) Address data validation
On our website, we offer you the option of checking certain entries in address forms in our online shop for input errors in real time. This is intended to prevent problems with the delivery of your ordered products due to incorrect information.
Furthermore, we would like to ensure that your contact details are valid for sending you information about your order or for any necessary follow-up questions.
The legal basis for the transfer, processing, and temporary storage of data by the service provider is Article 6(1)(b) GDPR, as it is essential for the performance of the contract or for taking steps prior to entering into a contract that some of the data you enter into the input form is checked for accuracy. The following data is processed by the service provider:
- Address (country, city, postal code, street, house number if applicable)
The data is processed separately by the service provider and is not combined. The requests are deleted by the service provider as soon as the status of the entered data has been determined and storage in the webshop is complete, but no later than 30 days.
C. Duration of data storage
We only store personal data for as long as it is necessary for the purposes for which it is processed, or until you withdraw your consent. Where statutory retention obligations apply, the storage period for certain data may be up to 10 years, regardless of the processing purposes.
D. Your rights as a data subject
a) Information
Upon request, you will receive information free of charge at any time about all personal data we have stored about you.
b) Rectification, erasure, restriction of processing (blocking), objection
Should you no longer consent to the storage of your personal data, or should it have become inaccurate, we will, upon your request, delete or block your data or make the necessary corrections (to the extent permitted by applicable law). The same applies if you wish us to restrict the processing of your data in the future.
c) Data portability
Upon request, we will provide your data in a common, structured and machine-readable format so that you can transfer the data to another controller if you wish.
d) Right of appeal
There is a right to lodge a complaint with the competent supervisory authority:
https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html
e) Right of withdrawal for consents with effect for the future
You can withdraw your consent at any time with effect for the future. Your withdrawal does not affect the lawfulness of the processing carried out before the withdrawal.
f) Limitations
Data where we are unable to identify the data subject, for example, if it has been anonymized for analysis purposes, is not covered by the aforementioned rights. Access, erasure, restriction of processing, rectification, or data portability to another company may be possible with regard to this data if you provide us with additional information that allows us to identify you.
g) Exercising your data subject rights
If you have any questions about the processing of your personal data, or if you wish to request information, correction, blocking, objection or deletion of data, or to transfer your data to another company, please contact us.
GDV-German Design Variations GmbH
Zankeltrad 9
92693 Eslarn
Email: info@goatsmoke.de