PRIVACY POLICY

Last updated: 6 September 2026

1. Controller

The controller responsible for processing personal data on this website is:

PHILINI
Owner: Natalia Brunner
Professional name: Nataly Brunner
Austr. 8
83646 Bad Tölz
Germany

Atelier and showroom:
Nockhergasse 6
83646 Bad Tölz
Germany

Telephone: +49 176 24080649
Email: info@philini.com

2. General information and legal bases

We process personal data only where this is necessary to operate our website and online shop, respond to enquiries, fulfil orders, comply with legal obligations, protect our legitimate interests or where you have given your consent.

Depending on the purpose, processing is based in particular on:

  • Article 6(1)(a) GDPR: consent;

  • Article 6(1)(b) GDPR: performance of a contract or steps taken before entering into a contract;

  • Article 6(1)(c) GDPR: compliance with a legal obligation;

  • Article 6(1)(f) GDPR: our legitimate interests, such as operating a secure and functional online shop, preventing fraud and protecting legal claims.

Where information is stored on or accessed from your device, Section 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG) also applies. Technologies that are not strictly necessary are used only with your consent.

3. Technical provision, server data and Shopify

Our online shop is operated using the Shopify platform.

Service provider:

Shopify International Limited
2nd Floor, Victoria Buildings
1–2 Haddington Road
Dublin 4, D04 XN32
Ireland

Shopify International Limited is affiliated with Shopify Inc., 151 O’Connor Street, Ground Floor, Ottawa, Ontario K2P 2L8, Canada.

When you visit the website, technical data may be processed automatically. This can include:

  • IP address;

  • date and time of access;

  • requested page or file;

  • referrer URL;

  • browser type, operating system and device information;

  • language and regional settings;

  • connection, security and error information;

  • information concerning interactions with the website.

This processing is necessary to display the website, provide the shopping cart and checkout, maintain security, detect technical problems and prevent misuse. The legal basis is Article 6(1)(f) GDPR. Where processing is required to initiate or perform an order, Article 6(1)(b) GDPR also applies.

Shopify processes customer data partly as our processor. For certain services, such as fraud prevention or selected payment functions, Shopify may also process data for its own purposes under its applicable privacy information.

Shopify and its service providers may process data outside the European Economic Area, including in Canada and the United States. Shopify states that such transfers are protected through recognised transfer mechanisms, including adequacy decisions, Binding Corporate Rules and Standard Contractual Clauses.

Further information:

https://www.shopify.com/legal/privacy/consumers
https://www.shopify.com/legal/dpa

Technical and security data is retained only for as long as required to operate and protect the service, unless longer retention is required by law or necessary for the establishment, exercise or defence of legal claims.

4. Cookies, similar technologies and consent management

Our website uses cookies and similar technologies. These may store or access information on your device.

Strictly necessary technologies are used to provide functions expressly requested by you, including:

  • website security;

  • language and regional settings;

  • shopping-cart functions;

  • checkout and payment preparation;

  • customer-account functions;

  • consent management.

The use of strictly necessary technologies is based on Section 25(2) TDDDG. The associated processing of personal data is based on Article 6(1)(b), (c) or (f) GDPR, depending on the purpose.

Optional technologies for statistics, analytics, advertising or marketing are used only after your consent under Section 25(1) TDDDG and Article 6(1)(a) GDPR.

Consentmo consent management

We use the Consentmo GDPR Compliance App by iSenseLabs to obtain, manage and document cookie and tracking preferences.

Provider:

iSenseLabs / Consentmo
Prof. Georgi Bradistilov Street No. 4
1700 Sofia
Bulgaria
EU registration number: 112660079
Email: support@consentmo.com

Consentmo may process the date and time of your choice, browser and device information, an anonymised IP address and records of consent, rejection or withdrawal.

The processing is necessary to comply with our legal obligations and to document your privacy choices. The legal basis is Article 6(1)(c) GDPR and Article 6(1)(f) GDPR. Necessary storage on your device is based on Section 25(2) TDDDG.

Your consent is voluntary and may be withdrawn or changed at any time through the cookie settings available on the website. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Further information:

https://www.consentmo.com/legal/privacy-policy

5. Orders, customer accounts and contract performance

When you place an order, create or use a customer account or communicate with us concerning a possible order, we process the information required for the transaction. This may include:

  • name and contact details;

  • billing and delivery address;

  • email address and telephone number;

  • products ordered and order value;

  • payment status and selected payment method;

  • customer-account information;

  • order, production, delivery and return information;

  • communications relating to the order;

  • information required for bespoke or personalised products.

Mandatory information is required to conclude or perform the contract. Without this information, we may be unable to accept or fulfil the order.

Processing is based on Article 6(1)(b) GDPR. Data required for accounting, tax, consumer-law or other legal documentation is also processed under Article 6(1)(c) GDPR.

We may process order and technical information to prevent fraud, misuse and payment defaults. This is based on our legitimate interest under Article 6(1)(f) GDPR.

Contract and accounting records are retained for the applicable statutory retention periods, generally between six and ten years depending on the type of document. Customer-account information is retained until the account is deleted, unless statutory obligations or unresolved contractual or legal matters require longer retention.

You may request deletion of your customer account by contacting info@philini.com. This does not affect information that must continue to be retained by law.

6. Contact requests and appointments

If you contact us by email, telephone, post or through a contact form, we process the information you provide, such as your name, contact details and the content of your message.

Where your enquiry concerns an order, a possible contract, an appointment or a bespoke product, processing is based on Article 6(1)(b) GDPR. For general enquiries, processing is based on Article 6(1)(f) GDPR and our legitimate interest in responding to communications addressed to us.

Appointment information may include your name, email address, telephone number, preferred date and time and details concerning the requested consultation. Where a Shopify-integrated appointment function is made available, the relevant technical booking provider may process this information as a service provider.

Enquiry and appointment data is deleted when the matter has been completed and no further retention is necessary. Information relevant to an order or contractual relationship may be retained with the corresponding contract documentation.

7. Electronic withdrawal function

We provide an electronic function through which customers can notify us of their withdrawal from a contract.

For this function, we use the Shopify application Revoq, operated by:

Jonas Busch, sole proprietor
Cologne, Germany
Email: contact@revoq.buschbytes.com
Website: https://www.consumer-withdrawal.eu/en

Depending on the information entered, the following data may be processed:

  • name;

  • email address;

  • order number;

  • company name, if provided;

  • products or items concerned;

  • withdrawal details;

  • information entered in optional text fields;

  • date and time of submission;

  • technical delivery and confirmation data.

The data is processed to receive, confirm, document and handle the withdrawal. The legal basis is Article 6(1)(b) and Article 6(1)(c) GDPR.

Revoq processes end-customer data as our processor under Article 28 GDPR and states that the service is hosted in Europe.

Withdrawal information is retained for as long as necessary to handle and document the withdrawal. Where it forms part of contractual, accounting or legal documentation, the applicable statutory retention periods apply.

Further information:

https://www.consumer-withdrawal.eu/terms

8. Shipping and delivery

To fulfil an order, we provide the shipping service provider commissioned with the delivery with the information necessary to deliver the goods. This generally includes the recipient’s name, delivery address and, where required for delivery coordination, email address or telephone number.

Processing is based on Article 6(1)(b) GDPR.

Where a shipping provider offers optional delivery notifications or delivery preferences requiring separate consent, the relevant information and consent will be obtained separately.

9. Payments and fraud prevention

The payment methods available for a particular order are displayed during checkout. Payment processing may involve Shopify Payments, banks, card organisations, wallet providers or other payment-service providers.

Depending on the method selected, recipients may include:

  • Shopify International Limited and the Shopify Payments service;

  • PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg;

  • Klarna Bank AB (publ), Stockholm, Sweden;

  • Apple Distribution International Limited for Apple Pay;

  • Google Ireland Limited for Google Pay;

  • Shop Pay;

  • card schemes and providers of local payment methods displayed during checkout;

  • the banks involved in a bank transfer.

Payment providers may receive information such as your name, billing address, email address, order amount, currency, order number, payment information, device data and information required for fraud prevention or authentication.

The processing is based on Article 6(1)(b) GDPR. Legal compliance by payment providers may be based on Article 6(1)(c) GDPR. Fraud and risk checks may also be based on Article 6(1)(f) GDPR.

Certain payment providers, particularly Klarna or PayPal, may carry out identity, risk or credit assessments under their own responsibility. Their respective privacy information applies to this processing.

PHILINI does not receive or store your complete card number or complete payment-account credentials.

10. Newsletter

If you subscribe to our newsletter, we process your email address to send you PHILINI news, collection information and other promotional communications.

The legal basis is your consent under Article 6(1)(a) GDPR in conjunction with Section 7(2) of the German Unfair Competition Act (UWG).

To document consent, registration data and, where applicable, confirmation information such as the date, time and technical log data may be retained. Newsletter registration and recipient information is managed through Shopify and may be processed using Shopify’s email or marketing functions.

You may withdraw your consent at any time by using the unsubscribe link in a newsletter or by writing to info@philini.com. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

After unsubscribing, your address is removed from the active newsletter list. We may retain limited proof of the previous consent and withdrawal for the applicable limitation period to establish, exercise or defend legal claims. This information will not be used to send further advertising.

11. hCaptcha protection

Shopify uses hCaptcha on forms to protect our website, customer accounts, checkout and communication functions from automated access, spam, fraud and misuse.

Provider:

Intuition Machines, Inc.
1065 SW 8th Street, No. 704
Miami, Florida 33130
USA

hCaptcha may process:

  • IP address and other network identifiers;

  • device and browser information;

  • date and time;

  • mouse movements, scrolling, key presses and touch events;

  • information required to determine whether an interaction was made by a person or an automated system.

Processing is based on Article 6(1)(f) GDPR and our legitimate interest in protecting the website and its forms. Necessary access to the device is based on Section 25(2) TDDDG.

Data may be processed in the United States. Intuition Machines states that it participates in the EU–US Data Privacy Framework and also uses contractual safeguards for relevant transfers.

Further information:

https://www.hcaptcha.com/privacy

12. Google Tag Manager, Google Analytics, Google Ads and Stape

With your consent, we use Google tools to understand how visitors use our shop, measure the effectiveness of advertising and improve our website and campaigns.

The services include:

  • Google Tag Manager, container ID GTM-MJDDDZJ;

  • Google Analytics 4, measurement ID G-L2WSKJR5NC;

  • Google Ads and conversion measurement, ID AW-941165254.

Provider for users in the European Economic Area:

Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland

Google may also involve Google LLC and service providers in the United States and other countries.

The information processed may include:

  • IP address;

  • device, browser and operating-system information;

  • page views and interactions;

  • referrer and campaign information;

  • approximate location;

  • cookie and online identifiers;

  • shopping-cart, purchase and conversion events.

Google Tag Manager manages the delivery of tags. Google Analytics helps us create usage statistics. Google Ads helps measure whether an advertisement resulted in a visit, enquiry or purchase.

We also use Stape server-side tagging technology provided by Stape Inc. Stape may receive and forward pseudonymous technical, analytics and conversion information to the services configured by us. Server-side tagging is not used to bypass your privacy choice.

These analytics and advertising services are used only on the basis of consent under Article 6(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw or change your consent at any time through the website’s cookie settings.

Retention is governed by our configurations and the relevant service settings. We retain personal or pseudonymous analytics data only for as long as required for analysis and campaign measurement and then delete or anonymise it. Google and Stape may retain information under their own applicable policies where they act for their own purposes.

Data may be transferred outside the European Economic Area. Depending on the recipient, transfers are protected by an adequacy decision, the EU–US Data Privacy Framework or Standard Contractual Clauses.

Further information:

https://policies.google.com/privacy
https://stape.io/privacy-notice

13. Trusted Shops

The Trusted Shops Trustbadge is integrated into our website to display the trustmark and reviews and, where applicable, to offer buyer-protection or review services after an order.

Provider:

Trusted Shops SE
Subbelrather Straße 15c
50823 Cologne
Germany

When the Trustbadge is loaded, technical information such as the IP address, date and time, requested content, browser information and referrer may be processed.

The display of the Trustbadge is based on Article 6(1)(f) GDPR and our legitimate interest in presenting the trustworthiness of our shop and facilitating secure purchasing.

If you voluntarily use Trusted Shops buyer protection or review services after an order, additional order and contact information may be transferred to Trusted Shops. Trusted Shops processes this information according to its own contractual and privacy provisions.

Further information:

https://www.trustedshops.de/impressum-datenschutz/

14. Language selection and Langify

We use the langify Shopify application to provide and manage the German and English versions of our shop.

Provider:

langify GmbH & Co. KG
Im Robbenklee 29a
32052 Herford
Germany

The selected language and technical information required to provide the correct language version may be processed. A language preference may be stored on your device.

Processing is based on Article 6(1)(b) or Article 6(1)(f) GDPR and our legitimate interest in providing an understandable multilingual shop. Storage required to provide the language selected by the user is based on Section 25(2) TDDDG.

Further information is available through the provider’s privacy policy linked from:

https://apps.shopify.com/langify

15. External social-media links

Our website contains links to external social-media platforms, including Instagram, Facebook, Pinterest and LinkedIn.

These are external links. When you merely visit our website, no personal data is transferred to a social-media provider solely because such a link is displayed. A connection to the external platform is established when you click the relevant link.

The external provider is responsible for subsequent processing on its platform. Its respective privacy policy applies.

16. Recipients and international transfers

We disclose personal data only where necessary for the purposes described in this Privacy Policy. Recipients may include:

  • Shopify and Shopify service providers;

  • payment providers, banks and card organisations;

  • shipping and delivery providers;

  • IT, hosting, security and support providers;

  • consent, analytics and marketing providers;

  • Trusted Shops;

  • the provider of the electronic withdrawal function;

  • tax advisers, legal advisers and public authorities where legally required.

Some providers process information outside the European Economic Area. Where required, transfers are protected by an adequacy decision, Binding Corporate Rules, Standard Contractual Clauses or another legally recognised safeguard.

You may contact us for further information about applicable transfer safeguards.

17. Retention

Unless a specific retention period is stated in this Privacy Policy, we retain personal data only for as long as necessary for the respective purpose.

Data may be retained longer where required by commercial, tax, consumer-protection or other laws or where it is necessary for the establishment, exercise or defence of legal claims.

When the purpose no longer applies and no statutory or legal reason requires continued retention, the data is deleted or anonymised.

18. Your rights

Subject to the legal requirements, you have the right to:

  • obtain information about your personal data under Article 15 GDPR;

  • request correction of inaccurate data under Article 16 GDPR;

  • request erasure under Article 17 GDPR;

  • request restriction of processing under Article 18 GDPR;

  • receive data you provided in a portable format under Article 20 GDPR;

  • object to processing based on Article 6(1)(e) or (f) GDPR under Article 21 GDPR;

  • withdraw consent at any time with effect for the future;

  • lodge a complaint with a data-protection supervisory authority.

To exercise your rights, contact:

info@philini.com

You may also complain to the supervisory authority responsible for PHILINI:

Bavarian State Office for Data Protection Supervision
Bayerisches Landesamt für Datenschutzaufsicht – BayLDA
Promenade 18
91522 Ansbach
Germany

https://www.lda.bayern.de/

Right to object

Where we process your personal data on the basis of legitimate interests, you may object to this processing on grounds relating to your particular situation.

If personal data is processed for direct marketing, you may object at any time without giving reasons. Following such an objection, your data will no longer be processed for direct marketing.

19. Automated decisions

PHILINI does not make decisions producing legal or similarly significant effects solely through automated processing.

Selected payment providers may use automated fraud, identity, risk or credit checks under their own responsibility. Information about such processing is provided by the selected payment provider.

20. Security and changes to this Privacy Policy

We use appropriate technical and organisational security measures, including encrypted transmission through TLS/SSL, to protect personal data against loss, misuse and unauthorised access.

We may update this Privacy Policy if the website, its service providers or the legal requirements change. The current version published on this website applies.