privacy policy

Last: 2018-10-28


Privacy policy

1. An overview of data protection

General

The following gives a simple overview of what happens to your personal information when you visit our website. Personal information is any data with which you could be personally identified. Detailed information on the subject of data protection can be found in our privacy policy found below.

Data collection on our website

Who is responsible for the data collection on this website?

The data collected on this website are processed by the website operator. The operator’s contact details can be found in the website’s required legal notice.

How do we collect your data?

Some data are collected when you provide it to us. This could, for example, be data you enter on a contact form.

Other data are collected automatically by our IT systems when you visit the website. These data are primarily technical data such as the browser and operating system you are using or when you accessed the page. These data are collected automatically as soon as you enter our website.

What do we use your data for?

Part of the data is collected to ensure the proper functioning of the website. Other data can be used to analyze how visitors use the site.

What rights do you have regarding your data?

You always have the right to request information about your stored data, its origin, its recipients, and the purpose of its collection at no charge. You also have the right to request that it be corrected, blocked, or deleted. You can contact us at any time using the address given in the legal notice if you have further questions about the issue of privacy and data protection. You may also, of course, file a complaint with the competent regulatory authorities.

2. General information and mandatory information

Data protection

The operators of this website take the protection of your personal data very seriously. We treat your personal data as confidential and in accordance with the statutory data protection regulations and this privacy policy.

If you use this website, various pieces of personal data will be collected. Personal information is any data with which you could be personally identified. This privacy policy explains what information we collect and what we use it for. It also explains how and for what purpose this happens.

Please note that data transmitted via the internet (e.g. via email communication) may be subject to security breaches. Complete protection of your data from third-party access is not possible.

Notice concerning the party responsible for this website

The party responsible for processing data on this website is:

420 Store
Oliver Steinwede
Ohechaussee 208
22848 Norderstedt
Germany

Telephone: +4915234039851
Email: privacy@420-store.de

The responsible party is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data (names, email addresses, etc.).

Revocation of your consent to the processing of your data

Many data processing operations are only possible with your express consent. You may revoke your consent at any time with future effect. An informal email making this request is sufficient. The data processed before we receive your request may still be legally processed.

Right to file complaints with regulatory authorities

If there has been a breach of data protection legislation, the person affected may file a complaint with the competent regulatory authorities. The competent regulatory authority for matters related to data protection legislation is the data protection officer of the German state in which our company is headquartered. A list of data protection officers and their contact details can be found at the following link: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html.

Right to data portability

You have the right to have data which we process based on your consent or in fulfillment of a contract automatically delivered to yourself or to a third party in a standard, machine-readable format. If you require the direct transfer of data to another responsible party, this will only be done to the extent technically feasible.

SSL or TLS encryption

This site uses SSL or TLS encryption for security reasons and for the protection of the transmission of confidential content, such as the inquiries you send to us as the site operator. You can recognize an encrypted connection in your browser’s address line when it changes from “http://” to “https://” and the lock icon is displayed in your browser’s address bar.

If SSL or TLS encryption is activated, the data you transfer to us cannot be read by third parties.

Encrypted payments on this website

If you enter into a contract which requires you to send us your payment information (e.g. account number for direct debits), we will require this data to process your payment.

Payment transactions using common means of payment (Visa/MasterCard, direct debit) are only made via encrypted SSL or TLS connections. You can recognize an encrypted connection in your browser’s address line when it changes from “http://” to “https://” and the lock icon in your browser line is visible.

In the case of encrypted communication, any payment details you submit to us cannot be read by third parties.

Information, blocking, deletion

As permitted by law, you have the right to be provided at any time with information free of charge about any of your personal data that is stored as well as its origin, the recipient and the purpose for which it has been processed. You also have the right to have this data corrected, blocked or deleted. However, in case of excessive amounts of such requests within a short time we´ll reserve the right to charge a suitable fee for our efforts. You can contact us at any time using the address given in our legal notice if you have further questions on the topic of personal data.

Opposition to promotional emails

We hereby expressly prohibit the use of contact data published in the context of website legal notice requirements with regard to sending promotional and informational materials not expressly requested. The website operator reserves the right to take specific legal action if unsolicited advertising material, such as email spam, is received.

3. Data collection on our website

Cookies

Some of our web pages use cookies. Cookies do not harm your computer and do not contain any viruses. Cookies help make our website more user-friendly, efficient, and secure. Cookies are small text files that are stored on your computer and saved by your browser.

Most of the cookies we use are so-called “session cookies.” They are automatically deleted after your visit. Other cookies remain in your device’s memory until you delete them. These cookies make it possible to recognize your browser when you next visit the site.

You can configure your browser to inform you about the use of cookies so that you can decide on a case-by-case basis whether to accept or reject a cookie. Alternatively, your browser can be configured to automatically accept cookies under certain conditions or to always reject them, or to automatically delete cookies when closing your browser. Disabling cookies may limit the functionality of this website.

Cookies which are necessary to allow electronic communications or to provide certain functions you wish to use (such as the shopping cart) are stored pursuant to Art. 6 paragraph 1, letter f of DSGVO. The website operator has a legitimate interest in the storage of cookies to ensure an optimized service provided free of technical errors. If other cookies (such as those used to analyze your surfing behavior) are also stored, they will be treated separately in this privacy policy.

If you write comments on our website, your name, email address and website will be stored in cookies. This is to automatically fill in the stored data in case you write another comment. Those cookies expire after one year. If you have an account on our website and log in, a temporarily cookie will be set which checks if your browser allows cookies. This cookie does not deal with personal data and expires when you close your browser.

Wenn you log in, your log in data will be stored in cookies that expire after two days. If you choose the option “keep logged in”, those cookies remain active for two weeks; however, they will be deleted if you log out from your account. Furthermore, we use cookies for the storage of your displaying options; those cookies expire after one year.

If you edit an article, a cookie will be stored that only links to the ID of that specific article and does not deal with personal data. This cookie expires after one day.

WooCommerce Multilingual and WPML Translation

WooCommerce Multilingual and WPML use Cookies to identify the visitor’s current language, the last visited language and the language of users who have logged in.

WPML will share data regarding the site through Installer. No data from the user itself will be shared.

WooCommerce Multilingual will use cookies to understand the basket info when using languages in domains and to transfer data between the domains.

WooCommerce Multilingual will also use cookies to identify the language and currency of each customer’s order as well as the language and currency of the reports (like invoices) created by WooCommerce. WooCommerce Multilingual extends these reports by adding the currency’s information.

Server log files

The website provider automatically collects and stores information that your browser automatically transmits to us in “server log files”. These are:

  • Browser type and browser version
  • Operating system used
  • Referrer URL (the website visited before)
  • requested website or file
  • device type
  • Host name of the accessing computer
  • Time of the server request
  • IP address in anonymous type (used to point out the enchroachment location)

These data will not be combined with data from other sources.

The basis for data processing is Art. 6 (1) (f) DSGVO, which allows the processing of data to fulfill a contract or for measures preliminary to a contract.

Contact form

Should you send us questions via the contact form, we will collect the data entered on the form, including the contact details you provide, to answer your question and any follow-up questions. We do not share this information without your permission.

We will, therefore, process any data you enter onto the contact form only with your consent per Art. 6 (1)(a) DSGVO. You may revoke your consent at any time. An informal email making this request is sufficient. The data processed before we receive your request may still be legally processed.

We will retain the data you provide on the contact form until you request its deletion, revoke your consent for its storage, or the purpose for its storage no longer pertains (e.g. after fulfilling your request). Any mandatory statutory provisions, especially those regarding mandatory data retention periods, remain unaffected by this provision.

Registration on this website

You can register on our website in order to access additional functions offered here. The input data will only be used for the purpose of using the respective site or service for which you have registered. The mandatory information requested during registration must be provided in full. Otherwise, we will reject your registration.

To inform you about important changes such as those within the scope of our site or technical changes, we will use the email address specified during registration.

We will process the data provided during registration only based on your consent per Art. 6 (1)(a) DSGVO. You may revoke your consent at any time with future effect. An informal email making this request is sufficient. The data processed before we receive your request may still be legally processed.

We will continue to store the data collected during registration for as long as you remain registered on our website. Statutory retention periods remain unaffected.

Leaving comments/ratings on this website

If you use the comment/rating function on this site, the time at which you created the comment/rating and your email address will be stored along with your comment/rating, as well as your username, unless you are posting anonymously.

It is possible that an anonymous token (“hash”) is generated out of your email address and hand it out to the Gravatar service, to check if the email address uses the Gravatar service. After the comment or rating got published, the profile picture (if existing) that belongst to the email address, can be seen in public, in context with the comment/rating. You can find more information in the privacy policy of Gravatar here: https://automattic.com/privacy.

Storage of the IP address

Our comment/rating function stores the IP addresses of those users who post comments. Since we do not check comments on our site before they go live, we need this information to be able to pursue action for illegal or slanderous content.

How long comments/ratings are stored

The comments/ratings and the associated data (e.g. IP address) are stored and remain on our website until the content commented upon has been completely deleted or the comments are required to be removed for legal reasons (slander, etc.).

Legal basis

The comments and ratings are stored based on your consent per Art. 6 (1) (a) DSGVO. You may revoke your consent at any time with future effect. An informal email making this request is sufficient. The data processed before we receive your request may still be legally processed.

Processing of data (customer and contract data)

We collect, process, and use personal data only insofar as it is necessary to establish, or modify legal relationships with us (master data). This is done based on Art. 6 (1) (b) DSGVO, which allows the processing of data to fulfill a contract or for measures preliminary to a contract. We collect, process and use your personal data when accessing our website (usage data) only to the extent required to enable you to access our service or to bill you for the same.

Collected customer data shall be deleted after completion of the order or termination of the business relationship. Legal retention periods remain unaffected.

Data transmitted when entering into a contract with online shops, retailers, and mail order

We transmit personally identifiable data to third parties only to the extent required to fulfill the terms of your contract, for example, to companies entrusted to deliver goods to your location or banks entrusted to process your payments. Your data will not be transmitted for any other purpose unless you have given your express permission to do so. Your data will not be disclosed to third parties for advertising purposes without your express consent.

The basis for data processing is Art. 6 (1) (b) DSGVO, which allows the processing of data to fulfill a contract or for measures preliminary to a contract.

Data transferred when signing up for services and digital content

We transmit personally identifiable data to third parties only to the extent required to fulfill the terms of your contract with us, for example, to banks entrusted to process your payments.

Your data will not be transmitted for any other purpose unless you have given your express permission to do so. Your data will not be disclosed to third parties for advertising purposes without your express consent.

The basis for data processing is Art. 6 (1) (b) DSGVO, which allows the processing of data to fulfill a contract or for measures preliminary to a contract.

4. Plugins and tools

Google Web Fonts

For uniform representation of fonts, this page uses web fonts provided by Google. When you open a page, your browser loads the required web fonts into your browser cache to display texts and fonts correctly.

For this purpose your browser has to establish a direct connection to Google servers. Google thus becomes aware that our web page was accessed via your IP address. The use of Google Web fonts is done in the interest of a uniform and attractive presentation of our website. This constitutes a justified interest pursuant to Art. 6 (1) (f) DSGVO.

If your browser does not support web fonts, a standard font is used by your computer.

Further information about handling user data, can be found at https://developers.google.com/fonts/faq and in Google’s privacy policy at https://www.google.com/policies/privacy/.

5. Online Store

WooCommerce

During your visit on our website we collect the following data:

  • visited products: the products you recently watched
  • Location, IP Address and browser type: we use these information to generate information about taxes and delivery costs.
  • Shipping address: we need this to generate information about delivery costs and to ship your order to you.

We use cookies to keep information about your shopping cart updated. Fore more information about cookies, see paragraph 3 of this privacy policy.

If you purchase something in our store, we will ask you to provide informations like your name, your sending- and/or billing address, your email-address and your telephone number as well as information about your credit card and/or payment details. Furthermore, as an option we might ask you to provide information about your customer-account like username and password (note: neither any of the members of our team nor any third party will get to know your password or ask you directly for your password).

We us these informations to:

  • provide information about your orders and your customer-account
  • respond to your questions, refunds/revokes and requests
  • process your payments as well as prevent fraud
  • observe terms of law like tax calculation
  • improve our service
  • provide marketing messages and/or newsletters (if requested by you)
  • set up your customer-account

If you set up a customer-account, we keep your name, email-address, sending- and billing-address as well as your telephone number. We´ll use these informations to fill out your payment details for your next orders.

We´ll keep these personal data as long as they are necessary for the purpose they were provided for or we are obliged by law to keep them. For exsample, due to tax law we keep these personal data for ten years.

6. Payment service providers

PayPal

Our website accepts payments via PayPal. The provider of this service is PayPal (Europe) S.à.r.l & Cie, S.C.A. (22-24 Boulevard Royal, L-2449 Luxembourg).

If you select payment via PayPal, the payment data you provide will be supplied to PayPal based on Art. 6 (1) (a) (Consent) and Art. 6 (1) (b) DSGVO (Processing for contract purposes). You have the option to revoke your consent at any time with future effect. It does not affect the processing of data previously collected.

You can watch the PayPal privacy policy here.

7. Translation into different languages

WPML

If you log in to your account on this website and if you have access to the translation system WPML to translate content and/or “strings” (like button captions), as well as media captions into different languages, WPML Translation Management will send your name and email-address and the attached content itself to the Advanced Translation Editor and to the external translation service(s).

However, this website doesn´t use any external translation services; therefore, no personal data is sent out of this website. If you log in to your account on this website as a customer of the online store, you don´t get access to WPML translation management.

8. Who has access to your data?

Members of the 420 Store team have access to your provided data. Both system administrators and shop managers have access to:

  • Information about your order like purchased products, time of the purchase and shipping address
  • Customer information like name and email-address as well as billing and shipping information.

Our team members use your data to fullfill your orders and requirements and/or refunds and to suppurt you as a visitor or customer.

 

— End of privacy policy —