data protection
We, Bübchen Skincare GmbH, take the protection of your personal data very seriously and strictly adhere to the rules of applicable data protection laws.
The following information provides you with an overview of what type of personal data we collect from website visitors and for what purpose, what we use the data collected in this way, how we ensure the protection of this data and how you can always obtain information about the information in question and revoke your consent to the use of data.
You can generally use our online services without revealing your identity. If we request personal data on our website, e.g., as part of contact forms or orders, this is done on a voluntary basis or as part of the necessary transmission of data for the order. We use this information for our own business purposes (such as providing requested information or shipping our products).
When ordering from the online shop, we will process your data solely to process the order. You can place orders via our website. In order to process the order, the corresponding fields are marked as mandatory. Data processing within the scope of orders from the online shop is carried out in accordance with Art. 6 (1) (a) and Art. 6 (1) (f) GDPR.
If you have any questions, you can contact us using a form provided on our website. The data marked as mandatory is required to assign the inquiry and adequately answer it. Additional information can be provided voluntarily. Data processing for the purpose of contacting us is carried out in accordance with Art. 6 (1) (a) of the General Data Protection Regulation (GDPR) and based on your voluntarily granted consent.
The personal data collected by us for the use of the contact form or the order in the online shop will be deleted after the query or comment you have made has been dealt with (in the absence of special circumstances, usually after 3 months) or alternatively after the expiry of the relevant tax and commercial retention periods.
You can revoke your consent at any time without giving reasons, with effect for the future. To do so, you can send an email to "shop@buebchen.de" or contact us:
Responsible body:
Bübchen Skincare GmbH
Johannes-Gutenberg-Straße 12–14
65719 Hofheim am Taunus
Email: shop@buebchen.de
Data collection on this website
Our website uses Shopify and several tools provided by Shopify, a tool for building and hosting websites. When you visit our website, Shopify collects your IP address, as well as information about the device you use and your browser.
For more information about how Shopify handles customer data, visit https://www.shopify.de/legal/datenschutz .
Collection, storage, use and duration of use of personal data
We collect, process and use the following personal data:
(a) in the context of mere website use: anonymized or pseudonymized IP address, type and scope of the website elements accessed by you, date and time of access and (in the case of website access via a link) the last visited URL, in accordance with Art. 6 (1) (f) GDPR;
(b) when using the contact form or when ordering the newsletter: your first and last name, your email address and your address, in accordance with Art. 6 (1) (a) GDPR;
(c) when ordering from the online shop via the existing ordering system: your name, first name, email address, address (street, house number, postal code, city), telephone number, bank details / credit card details, physical address, geolocations, IP address of the browser, product data
(d) for the occasional conduct of competitions via our social media (in particular on Facebook and Instagram; the privacy policies of Facebook and Instagram apply).
We use the data listed under (a), (b), and (d) solely to process your inquiries and administer the competitions (the data will then be deleted; it will not be passed on to third parties). The duration of data storage for the purpose of processing inquiries or competitions complies with the statutory retention periods. Your personal data will be deleted after this period, or at the latest after three months.
We use the data collected under (c) to process and execute orders from the online shop. As part of the order process in our online shop, the data is further processed and stored in accordance with statutory retention periods. The data is transferred to: Dallmann's Pharma Candy GmbH, DataJet.
We use Google Analytics for statistical purposes. Further information can be found in the "Analysis and Advertising Tools" section.
SHARING OF DATA
Disclosure to third parties, for commercial or non-commercial purposes, will generally not occur without your express consent. We will only disclose your personal data to third parties if this is required by law (Art. 6 (1) (c) GDPR), if you have consented to this (Art. 6 (1) (a) GDPR), or if it is necessary in the context of product orders (Art. 6 (1) (f) GDPR). The necessary data (your last name, first name, email address, address (street, house number, postal code, city), telephone number, bank details/credit card details, physical address, geolocations, IP address of the browser, product data) will be forwarded to Dallmann's Pharma Candy GmbH via the DataJet system in order to be able to deliver the ordered items (Art. 6 (1) (b) and (f)).
We retain full responsibility for data processing. Furthermore, we will not transfer the data directly to third countries.
Note on data transfer to the USA and other third countries
Our website includes tools from companies based in the USA or other third countries that do not have secure data protection laws. If these tools are active, your personal data may be transferred to these third countries and processed there. We would like to point out that a level of data protection comparable to that in the EU cannot be guaranteed in these countries. For example, US companies are obliged to release personal data to security authorities without you as the data subject being able to take legal action. It cannot therefore be ruled out that US authorities (e.g. secret services) may process, evaluate and permanently store your data located on US servers for surveillance purposes. We have no influence over these processing activities.
YOUR RIGHTS AS A DATA SUBJECT
We hereby inform you that according to Articles 15 et seq. of the GDPR, you have the right to transfer your personal data to us under the conditions defined therein.
- the right to information under Article 15;
- the right to rectification under Article 16;
- the right to erasure under Article 17;
- the right to restriction of processing pursuant to Article 18;
- the right to object to processing under Article 21; and
- have the right to data portability under Article 20.
According to Art. 77 GDPR, you also have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of personal data concerning you violates this regulation.
If the processing is based on Art. 6 (1) (a) GDPR (consent), you also have the right to withdraw your consent at any time without affecting the legality of the processing carried out on the basis of your consent until the withdrawal.
INFORMATION ON DATA USE, DELETION OF DATA, REVOCATION OF CONSENT
Upon request, we will be happy to provide you with information about how we collect and use your data and what data we have stored about you as a result of your website use. Please contact us at shop@buebchen.de . We will be happy to correct or delete this data upon your request.
Cookies
Our website uses so-called "cookies." Cookies are small text files that do not cause any damage to your device. They are stored either temporarily for the duration of a session (session cookies) or permanently (permanent cookies) on your device. Session cookies are automatically deleted after your visit. Permanent cookies remain stored on your device until you delete them yourself or until they are automatically deleted by your web browser.
In some cases, cookies from third-party companies may also be stored on your device when you visit our website (third-party cookies). These enable us or you to use certain services provided by the third-party company (e.g., cookies for processing payment services).
Cookies serve various functions. Many cookies are technically necessary, as certain website functions would not work without them (e.g., the shopping cart function or the display of videos). Other cookies are used to evaluate user behavior or display advertising.
Cookies that are required to carry out electronic communication (necessary cookies) or to provide certain functions you have requested (functional cookies, e.g. for the shopping cart function) or to optimize the website (e.g. cookies to measure web audience) are stored on the basis of Art. 6 (1) (f) GDPR, unless another legal basis is specified. The website operator has a legitimate interest in storing cookies to ensure the technically error-free and optimized provision of its services. If consent to the storage of cookies has been requested, the cookies in question will be stored exclusively on the basis of this consent (Art. 6 (1) (a) GDPR); this consent can be revoked at any time.
You can configure your browser to inform you about the use of cookies and to only accept cookies on a case-by-case basis, to exclude cookies for specific cases or in general, and to automatically delete cookies when you close your browser. Disabling cookies may limit the functionality of this website.
If cookies are used by third-party companies or for analysis purposes, we will inform you separately about this within the framework of this data protection declaration and, if necessary, request your consent.
Server log files
The website provider automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These include:
- Browser type and version
- operating system used
- Referrer URL
- Hostname of the accessing computer
- Time of server request
- IP address
This data will not be merged with other data sources.
This data is collected on the basis of Art. 6 (1) (f) GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimization of its website – for this purpose, the server log files must be collected.
Analysis and advertising tools
Google Analytics
This website uses Google Analytics, a web analysis service provided by Google Inc. ("Google"). Google Analytics uses so-called "cookies", text files that are stored on your computer and that enable an analysis of your use of the website. The information generated by the cookie about your use of the website is usually transferred to a Google server in the USA and stored there. However, if IP anonymization is activated on this website, your IP address will be shortened beforehand by Google within member states of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity and to provide the website operator with other services relating to website activity and internet usage.
The IP address transmitted by your browser as part of Google Analytics will not be merged with other data held by Google.
This website uses Google Analytics with the extension "_anonymizeIp()." This shortens IP addresses for further processing, thus preventing them from being personally identifiable.
For the exceptional cases in which personal data is transferred to the USA, Google has submitted to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework. The legal basis for the use of Google Analytics is Art. 6 (1) (f) GDPR.
The legal basis for the processing of users’ personal data is Art. 6 (1) (f) GDPR.
Processing users' personal data enables us to analyze their surfing behavior. By evaluating the data obtained, we are able to compile information about the use of individual components of our website. This helps us to continuously improve our website and its user-friendliness. These purposes also constitute our legitimate interest in processing the data pursuant to Art. 6 (1) (f) GDPR. By anonymizing the IP address, the user's interest in the protection of their personal data is sufficiently taken into account.
Cookies are stored on the user's computer and transmitted from there to our website. Therefore, you as the user have full control over the use of cookies. You can deactivate or restrict the transmission of cookies by changing the settings in your internet browser. Cookies that have already been stored can be deleted at any time. This can also be done automatically.
However, please note that if you do this, you may not be able to use all of the features of this website to their full extent. You can also prevent Google from collecting the data generated by the cookie and relating to your use of the website (including your IP address) and from processing this data by downloading and installing the browser plug-in available at the following link: http://tools.google.com/dlpage/gaoptout?hl=de.
Google Dublin, Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland, Fax: +353 (1) 436 1001. User conditions: http://www.google.com/analytics/terms/de.html, overview of data protection: http://www.google.com/intl/de/analytics/learn/privacy.html, and the data protection declaration: http://www.google.de/intl/de/policies/privacy .
Google Analytics in Consent Mode
We use Google's "Consent Mode" (also called "consent mode"). In Consent Mode, users' personal data is processed by Google for measurement and advertising purposes, subject to the user's consent. Users' consent is obtained as part of our online services. Without the user's consent, the data is only processed in an aggregated manner (i.e., not assigned to individual users or summarized). Users' personal data will not be processed to display ads or measure advertising success if the consent only includes statistical measurement. Legal basis: Consent (Art. 6 (1) (a) GDPR); Website: https://support.google.com/analytics/answer/9976101?hl=de.
Google Ads
Our website uses Google Ads Conversion, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. This service allows us to place advertising material (so-called Google Ads) on external websites to draw attention to our offers and services. The data from the advertising campaigns allows us to determine the success of individual advertising measures.
These advertisements are delivered by Google via so-called "ad servers." For this purpose, we use ad server cookies (see above for information on cookies), which can be used to measure certain parameters for success, such as the display of ads or clicks by users. When you access our website via a Google ad, Google Ads stores a cookie on your device. These cookies usually expire after 30 days and are not intended to identify you personally. The analysis values for this cookie are usually the unique cookie ID, the number of ad impressions per display (frequency), the last impression (relevant for conversions after display), and the opt-out information (indication that the user no longer wishes to be contacted).
These cookies allow Google to recognize your internet browser. When a user visits certain pages of an advertiser's website and the cookie stored on their computer hasn't expired, Google and the advertiser can recognize that the user clicked on the ad and was redirected to that page. Each advertiser is assigned a different cookie. Therefore, cookies cannot be tracked across advertisers' websites.
When Google transfers personal data from the European Union (EU) to the United States, it does so in accordance with the Privacy Shield Framework between the U.S. Department of Commerce and the European Commission. For more information, please visit: https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active
For more information about how user data is handled, please see Google's privacy policy at: https://policies.google.com/privacy?hl=de&gl=de
Exchange data with Facebook (only applies to registered Facebook users)
We participate in a statistical program operated by Facebook, 1601 South California Avenue, Palo Alto, CA 94304, USA, which identifies Facebook users with a similar usage profile to our existing customers ("Facebook Custom Audiences - Statistical Twins"). As part of this program, customer email addresses are transferred to Facebook in an anonymized form (as a so-called "hash"). The email address can no longer be derived from the transmitted data. Facebook itself uses the same method to create a hash of its users' email addresses, compares this anonymized data, and determines whether one of our users is registered with Facebook with the same email address.
Facebook promises not to save this match or use it outside of this program. This will then be used to identify third parties who use Facebook in a similar way to the customer, allowing us to target these people. You will not receive any additional advertising or messages from us or Facebook.
If you are not registered with Facebook using the same email address as us, Facebook will not receive any information about you. We will never know whether you are registered with Facebook, nor will we receive any other data about you.
You hereby consent to the anonymized sharing of your email address in the manner described above. Although we have every reason to trust Facebook's assurances, we would like to point out that Facebook is not subject to German data protection law.
For further information about the purpose and scope of data collection and the further processing and use of the data by Facebook as well as your settings options for protecting your privacy, please refer to Facebook's privacy policy, which can be found at https://www.facebook.com/about/privacy/ .
Facebook Social Plugin
Our website uses social plugins ("plugins") from the social network facebook.com ("Facebook"). Facebook is operated by Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA.
When you visit a page on our website that contains such a plugin, your browser establishes a direct connection to the Facebook servers. The content of the plugin is transmitted directly from Facebook to your browser, which then integrates it into the website. By integrating the plugin, Facebook receives the information that you have accessed the corresponding page of our website. If you are logged in to Facebook, Facebook can associate the visit with your Facebook account.
For information about the purpose and scope of data collection, the further processing and use of data by Facebook, as well as your rights and settings options for protecting your privacy, please refer to Facebook's privacy policy: https://www.facebook.com/policy.php If you are a Facebook member and do not want Facebook to collect data about you via our website and link it to your member data stored on Facebook, you must log out of Facebook before visiting our website. It is also possible to block Facebook social plugins with add-ons for your browser, for example, with the "Facebook Blocker."
Pinterest Conversion Tag
We use Pinterest Conversion Tag from Pinterest Inc., 651 Brannan Street, San Francisco, CA 94107, United States, to create so-called custom audiences, i.e. to segment visitor groups of our online offering, determine conversion rates and then optimize them. This happens in particular when you interact with advertisements that we have placed with Pinterest Inc. We process your data with the help of Pinterest Conversion Tag for the purpose of optimizing our website and for marketing purposes on the basis of your consent in accordance with Art. 6 (1) (a) GDPR. The specific storage period of the processed data cannot be influenced by us; it is determined by Pinterest Inc. Further information can be found in the privacy policy for Pinterest Conversion Tag: https://policy.pinterest.com/de/privacy-policy .
Shopify
Our website uses Shopify, along with several tools provided by Shopify. This is an e-commerce platform we use to provide our customers with an exceptional online experience.
For more information about how Shopify handles customer data, visit https://www.shopify.com/legal/privacy/customers
DataJet
We use DataJet to transfer customer data from the online shop (Shopify).
For more information about how DataJet processes and protects data, please visit the following website: http://code57.pl/apps/datajet/privacy_policy.pdf
NEWSLETTER
In order to provide you with regular information about our company and our offers, we offer an email newsletter. When you subscribe to our newsletter, we process the data you entered during registration (email address and other voluntary information). To prevent misuse, we will send you an email after your registration asking you to confirm your registration (double opt-in procedure). To ensure that the registration process complies with legal requirements, your registration will be logged. This includes the time of registration and confirmation, as well as your IP address.
The legal basis for sending the newsletter is your consent in accordance with Art. 6 (1) (a) GDPR. Data processing in connection with sending the confirmation email for your registration and the associated data logging is carried out in accordance with Art. 6 (1) (f) GDPR based on our legitimate interest in proving your proper registration.
To send the newsletter, we use service providers to whom we transmit the specified data. The data is transmitted to the servers of the following service providers in the USA:
Klaviyo: Klaviyo, Inc., 60 South Street, Suite 910, Boston, Massachusetts, USA
Privacy Policy: https://www.klaviyo.com/privacy
You have the right to withdraw your consent at any time.
Updates to this notice
Technical and legal changes, as well as internal marketing strategy changes, may require us to supplement or correct this privacy policy. The most recent privacy policy will then apply to your next visit.
Please review these notices from time to time for any such changes.