Skip to content
CardmasterCardmaster

Privacy Policy

What personal data we process, why, on what legal basis and for how long, plus the rights you have while we do it.

Controller

The controller for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:

Controller
Cardmaster GmbH
Address
Bahnhofstraße 4, 53783 Eitorf, Deutschland
Email
contact@cardmasterstore.de
Phone
+49 1573 1172797

We have not appointed a data protection officer; the thresholds in sec. 38 BDSG do not apply to us. Please send data protection requests to the email address above. They are handled by management directly.

What we deliberately don't do

This site runs without ad networks, without audience measurement and without profiling. Several things other shops have to explain at length simply do not happen here:

  • No Google Analytics, no Meta pixel, no other analytics or tracking tool.
  • No advertising cookies and no consent banner: we use strictly necessary cookies only, which are exempt from consent under sec. 25(2) no. 2 TDDDG.
  • No fonts loaded from third-party servers. All fonts ship with the site; no connection to Google Fonts is made.
  • No sale or disclosure of your data for advertising, neither to third parties nor to affiliated companies.
  • No newsletter without an explicit double opt-in sign-up.

Visiting the site (server logs)

Every page request causes your browser to send technical data that our server logs briefly: IP address, date and time, the address requested, the amount of data transferred, the status code, the referring page, and browser and operating system identifiers.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is keeping the service stable, narrowing down faults and fending off attacks. These logs are not combined with other data and are not used to analyse visitor behaviour. We delete them after seven days unless a security incident requires longer retention.

Cookies

We use four cookies. All four are needed to run the shop; none is used to recognise you across websites:

CookiePurposeStorage period
cm_localeRemembers the language you selected.12 months
cm_cartLinks your browser to its basket. Holds a random identifier only, no contents.30 days
cm_themeRemembers the light or dark appearance.12 months
cm_adminSession identifier for shop administration. Set for staff only, never for customers.7 days

Storing this information on your device is based on sec. 25(2) no. 2 TDDDG; the processing that follows is based on Art. 6(1)(b) and (f) GDPR. You may delete cookies in your browser at any time: your basket will be lost, the rest of the site keeps working.

Basket and reservation

When you add an item to the basket, its contents are stored in our database together with the identifier from the cookie. No name is needed: at that point we do not know who you are.

Because nearly every item is one of a kind, goods are reserved for 45 minutes from the moment checkout begins. If no payment arrives within that window, the reservation lapses automatically and the item is released to everyone again. Legal basis: Art. 6(1)(b) GDPR. Unfinished baskets are deleted no later than 30 days after their last change; we send no abandoned-basket reminder emails.

Orders and performance of the contract

An order requires: email address, first and last name, delivery address and, optionally, company, phone number and a delivery note. Added to that are the order details themselves: items, prices, time, order number, chosen language and payment status.

The legal basis is Art. 6(1)(b) GDPR: without this data we cannot perform the contract of sale. Your phone number is passed to the carrier so they can reach you if delivery runs into trouble; it stays optional. You can view your order through the link in the confirmation email. We do not create a password-protected customer account.

Payment processing via Stripe

Payments are handled by Stripe Payments Europe, Limited, The One Building, 1 Grand Canal Street Lower, Dublin 2, Ireland. You enter your payment details on a page operated by Stripe. Card numbers, PayPal credentials and bank details never reach our servers and are not stored by us.

We send Stripe the order number, amount, currency, email address and item names. Stripe returns whether the payment succeeded, along with the type and last digits of the payment method used. Stripe also processes this data as an independent controller for fraud prevention and to meet its own legal obligations.

Legal basis: Art. 6(1)(b) GDPR. Transfers to Stripe, Inc. in the United States may occur; they are covered by the European Commission's standard contractual clauses and Stripe's certification under the EU-US Data Privacy Framework. Details are in Stripe's privacy policy at stripe.com/privacy.

Shipping

To deliver your order we pass your name, delivery address and (where provided) phone number and email address to the carrier engaged. The carrier used is named in the dispatch confirmation. Legal basis: Art. 6(1)(b) GDPR. The email address serves tracking only; we do not release it for the carrier's own marketing.

Order emails

We send an order confirmation, a dispatch confirmation and, for pre-orders, the request for the outstanding balance. These are contractual messages, not marketing; they cannot be unsubscribed from while the contract is running. Legal basis: Art. 6(1)(b) GDPR.

Sending goes through our provider's mail server. Our emails contain no tracking pixels: we do not learn whether or when you opened a message.

Getting in touch

If you write or call, we process what you tell us in order to answer. The legal basis is Art. 6(1)(b) GDPR where a contract or its preparation is involved, otherwise Art. 6(1)(f) GDPR.

Enquiries unrelated to an order are deleted no later than six months after they are dealt with. Enquiries about an order become part of that record and follow the retention periods below.

Map on the contact page

The map showing our shop comes from OpenStreetMap and only loads when you explicitly ask for it. Until then, no request leaves your browser. When you click the button, your browser sends your IP address to the OpenStreetMap Foundation, St John's Innovation Centre, Cowley Road, Cambridge CB4 0WS, United Kingdom.

The legal basis is your consent under Art. 6(1)(a) GDPR and sec. 25(1) TDDDG, given by that click and withdrawn by reloading the page. The United Kingdom is covered by an adequacy decision of the European Commission. Our address also appears in plain text on the same page. The map is a convenience, not a detour you have to take.

Pre-orders

For a pre-order we additionally store the quantity reserved, the deposit paid, the balance outstanding and the expected dispatch date. We need this to assign your allocation and to request the balance before shipping. Legal basis: Art. 6(1)(b) GDPR.

Retention periods

DataRetention
Server logs7 days
Unfinished baskets30 days after the last change
Expired reservationsLapse after 45 minutes, deleted with the basket
Orders, invoices, payment records10 years (sec. 147 AO); commercial correspondence 6 years (sec. 257 HGB)
Enquiries unrelated to an order6 months after they are dealt with
Shop administration sessions7 days

The tax and commercial retention periods are duties, not choices: we may not delete an invoice even if you ask us to. In that case we block the data concerned from any further use and delete it once the period expires.

Who receives your data

  • Our hosting and database provider, which runs the website and the shop (processor under Art. 28 GDPR).
  • Stripe as payment service provider.
  • The carrier engaged for the shipment.
  • Our email provider, for sending contractual messages.
  • Our tax adviser and, in the event of an audit, the tax authorities.
  • Lawyers, courts and public authorities, where necessary to pursue legal claims or required by law.

Every processor is bound by a contract under Art. 28 GDPR. Beyond the cases listed, we pass your data to no one.

Your rights

You have the following rights against us:

  • Access to the data we hold about you (Art. 15 GDPR).
  • Rectification of inaccurate data and completion of incomplete data (Art. 16).
  • Erasure, unless a statutory retention duty stands in the way (Art. 17).
  • Restriction of processing (Art. 18).
  • Portability of your data in a common, machine-readable format (Art. 20).
  • Objection to processing we base on a legitimate interest (Art. 21).
  • Withdrawal of a consent you gave, with effect for the future (Art. 7(3)).

An informal email to the address above is enough. We reply within one month and charge nothing for it. Where we have reasonable doubts about your identity we may ask for one more detail, such as the order number the data is stored under.

No automated decision-making

There is no automated decision-making, including profiling, within the meaning of Art. 22 GDPR. We run no credit checks and score no behaviour. Fraud screening of your payment is carried out by Stripe; a rejection there means only that the payment does not go through.

Data security

The connection to this site is encrypted end to end with TLS, as the padlock in your browser shows. Access to shop administration is limited to staff, passwords are stored only as hashes, and every change to an order or to stock is logged. The only personal identifier in those logs is the order number.

Changes to this policy

We update this policy when our processing or the law changes. The version published here applies; the date at the top of the page shows how current it is. For an order already placed, the version in force when the contract was concluded remains decisive.

Privacy Policy · Cardmaster