1. Data protection at a glance
General notes
The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data is any data with which you can be personally identified. Detailed information on data protection can be found in our privacy policy listed below this text.
Data collection on this website
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. You can find their contact details in the imprint of this website.
How do we collect your data?
Your data is collected partly by you providing it to us. This can be, for example, data you enter into a contact form.
Other data is automatically collected or collected with your consent when visiting the website by our IT systems. These are mainly technical data (e.g., internet browser, operating system, or time of page access). The collection of this data takes place automatically as soon as you enter this website.
What do we use your data for?
Some of the data is collected to ensure error-free provision of the website. Other data may be used to analyze your user behavior.
What rights do you have regarding your data?
You have the right at any time to receive free information about the origin, recipients, and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can revoke this consent at any time for the future. Furthermore, you have the right, under certain circumstances, to request the restriction of the processing of your personal data. Additionally, you have the right to lodge a complaint with the competent supervisory authority.
For this and other questions regarding data protection, you can contact us at any time at the address provided in the imprint.
Analytics tools and third-party tools
When visiting this website, your browsing behavior may be statistically analyzed. This is mainly done using cookies and so-called analytics programs.
Detailed information about these analytics programs can be found in the following privacy policy.
2. Hosting and Content Delivery Networks (CDN)
External Hosting
This website is hosted by an external service provider (host). The personal data collected on this website are stored on the host's servers. These may include, in particular, IP addresses, contact inquiries, meta and communication data, contract data, contact details, names, website accesses, and other data generated through a website.
The use of the host is for the purpose of fulfilling the contract with our potential and existing customers (Art. 6 para. 1 lit. b GDPR) and in the interest of a secure, fast, and efficient provision of our online offer by a professional provider (Art. 6 para. 1 lit. f GDPR).
Our host will only process your data to the extent necessary to fulfill its service obligations and will follow our instructions regarding this data.
Conclusion of a contract for order processing
To ensure data protection-compliant processing, we have concluded a contract for order processing with our host.
3. General information and mandatory disclosures
Data protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the legal data protection regulations as well as this privacy policy.
When you use this website, various personal data are collected. Personal data are data with which you can be personally identified. This privacy policy explains which data we collect and what we use them for. It also explains how and for what purpose this happens.
We point out that data transmission over the Internet (e.g., when communicating by email) can have security vulnerabilities. Complete protection of data from access by third parties is not possible.
Note on the responsible party
The responsible party for data processing on this website is:
Bernhard Endlmaier
Klosterweg 1a
85445 Oberding
Germany
Phone: +49 (0)8122 – 22 78 241
Email: info@lashes-and-more.shop
The responsible party is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data (e.g., names, email addresses, or similar).
Revocation of your consent to data processing
Many data processing operations are only possible with your explicit consent. You can revoke a consent you have already given at any time. A simple notification by email to us is sufficient. The legality of the data processing carried out until the revocation remains unaffected by the revocation.
Right to object to data collection in special cases and to direct marketing (Art. 21 GDPR)
IF THE DATA PROCESSING IS BASED ON ART. 6 PARA. 1 LIT. E OR F GDPR, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION TO THE PROCESSING OF YOUR PERSONAL DATA; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS, AND FREEDOMS OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE, OR DEFENSE OF LEGAL CLAIMS (OBJECTION ACCORDING TO ART. 21 PARA. 1 GDPR).
IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR SUCH MARKETING; THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION ACCORDING TO ART. 21 PARA. 2 GDPR).
Right to complain to the competent supervisory authority
In case of violations of the GDPR, affected individuals have the right to lodge a complaint with a supervisory authority, especially in the member state of their habitual residence, workplace, or the location of the alleged violation. This right to complain exists without prejudice to other administrative or judicial remedies.
Right to data portability
You have the right to receive data that we process automatically based on your consent or to fulfill a contract, either to yourself or to a third party, in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done if technically feasible.
SSL or TLS encryption
For security reasons and to protect the transmission of confidential content, such as orders or inquiries you send to us as the site operator, this site uses SSL or TLS encryption. You can recognize an encrypted connection by the browser's address bar changing from "http://" to "https://" and by the lock icon in your browser bar.
When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
Encrypted payment transactions on this website
If, after concluding a paid contract, there is an obligation to provide us with your payment data (e.g., account number for direct debit authorization), this data is required for payment processing.
Payment transactions via common payment methods (Visa/MasterCard, direct debit) are carried out exclusively via an encrypted SSL or TLS connection. You can recognize an encrypted connection by the browser's address line changing from "http://" to "https://" and by the lock symbol in your browser bar.
With encrypted communication, your payment data that you transmit to us cannot be read by third parties.
Information, deletion, and correction
Within the scope of applicable legal provisions, you have the right at any time to free information about your stored personal data, their origin and recipients, and the purpose of data processing, and, if applicable, a right to correction or deletion of this data. For this and other questions regarding personal data, you can contact us at any time at the address provided in the imprint.
Right to restriction of processing
You have the right to request the restriction of the processing of your personal data. You can contact us at any time at the address provided in the imprint. The right to restriction of processing applies in the following cases:
- If you dispute the accuracy of your personal data stored with us, we usually need time to verify this. During the verification period, you have the right to request the restriction of the processing of your personal data.
- If the processing of your personal data was/is unlawful, you can request the restriction of data processing instead of deletion.
- If we no longer need your personal data, but you require it to exercise, defend, or assert legal claims, you have the right to request the restriction of the processing of your personal data instead of deletion.
- If you have lodged an objection under Art. 21 para. 1 GDPR, a balance must be struck between your interests and ours. As long as it is not yet clear whose interests prevail, you have the right to request the restriction of the processing of your personal data.
If you have restricted the processing of your personal data, these data – apart from their storage – may only be processed with your consent or for asserting, exercising, or defending legal claims or to protect the rights of another natural or legal person or for reasons of important public interest of the European Union or a member state.
Objection to advertising emails
The use of contact data published within the scope of the imprint obligation for sending unsolicited advertising and informational materials is hereby objected to. The operators of the pages expressly reserve the right to take legal action in the event of unsolicited sending of advertising information, such as spam emails.
4. Data collection on this website
Cookies
Our websites use so-called "cookies." Cookies are small text files and do not cause any damage to your device. They are either temporarily stored for the duration of a session (session cookies) or permanently (permanent cookies) on your device. Session cookies are automatically deleted after your visit ends. Permanent cookies remain stored on your device until you delete them yourself or an automatic deletion occurs through your web browser.
In some cases, cookies from third-party companies may also be stored on your device when you visit our site (third-party cookies). These allow us or you to use certain services of the third-party company (e.g., cookies for processing payment services).
Cookies have various functions. Many cookies are technically necessary because certain website functions would not work without them (e.g., the shopping cart function or video display). Other cookies are used to analyze user behavior or display advertising.
Cookies that are necessary for carrying out the electronic communication process (necessary cookies) or for providing certain functions you desire (functional cookies, e.g., for the shopping cart function) or for optimizing the website (e.g., cookies for measuring web traffic) are stored based on Art. 6 para. 1 lit. f GDPR, unless another legal basis is specified. The website operator has a legitimate interest in storing cookies for the technically error-free and optimized provision of its services. If consent to the storage of cookies has been requested, the storage of the respective cookies takes place exclusively based on this consent (Art. 6 para. 1 lit. a GDPR); consent can be revoked at any time.
You can set your browser to inform you about the setting of cookies and to allow cookies only in individual cases, to exclude the acceptance of cookies for certain cases or in general, and to activate the automatic deletion of cookies when closing the browser. Disabling cookies may restrict the functionality of this website.
If cookies from third parties or for analysis purposes are used, we will inform you separately about this within the scope of this privacy policy and, if necessary, request your consent.
Cookie consent with Borlabs Cookie
Our website uses the cookie consent technology from Borlabs Cookie to obtain your consent to store certain cookies in your browser and to document this in compliance with data protection regulations. The provider of this technology is Borlabs – Benjamin A. Bornschein, Georg-Wilhelm-Str. 17, 21107 Hamburg (hereinafter Borlabs).
When you enter our website, a Borlabs cookie is stored in your browser in which the consents you have given or the revocation of these consents are stored. This data is not passed on to the provider of Borlabs Cookie.
The collected data is stored until you request deletion from us, delete the Borlabs cookie yourself, or the purpose for data storage no longer applies. Mandatory statutory retention periods remain unaffected. Details on data processing by Borlabs Cookie can be found at https://de.borlabs.io/kb/welche-daten-speichert-borlabs-cookie/
The use of the Borlabs Cookie Consent technology is to obtain the legally required consents for the use of cookies. The legal basis for this is Art. 6 para. 1 sentence 1 lit. c GDPR.
Server log files
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
- Browser type and browser version
- Operating system used
- Referrer URL
- Hostname of the accessing computer
- Time of the server request
- IP address
A merging of this data with other data sources does not take place.
The collection of this data is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimization of its website – for this purpose, server log files must be recorded.
Contact form
If you send us inquiries via the contact form, your details from the inquiry form, including the contact information you provide there, will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. We do not share this data without your consent.
The processing of this data is based on Art. 6 para. 1 lit. b GDPR if your inquiry is related to the fulfillment of a contract or is necessary for pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of inquiries addressed to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR) if this was requested.
The data you enter in the contact form remains with us until you request deletion, revoke your consent to storage, or the purpose for data storage no longer applies (e.g., after your inquiry has been fully processed). Mandatory legal provisions – especially retention periods – remain unaffected.
Inquiry by email, telephone, or fax
If you contact us by email, telephone, or fax, your inquiry including all personal data arising from it (name, inquiry) will be stored and processed by us for the purpose of handling your request. We do not pass on this data without your consent.
The processing of this data is based on Art. 6 para. 1 lit. b GDPR if your inquiry is related to the fulfillment of a contract or is necessary for pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of inquiries addressed to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR) if this was requested.
The data you send to us via contact inquiries remains with us until you request deletion, revoke your consent to storage, or the purpose for data storage no longer applies (e.g., after your request has been fully processed). Mandatory legal provisions – especially statutory retention periods – remain unaffected.
Registration on this website
You can register on this website to use additional features on the site. The data entered for this purpose is used only for the purpose of using the respective offer or service for which you have registered. The mandatory information requested during registration must be provided completely. Otherwise, we will reject the registration.
For important changes, such as changes in the scope of the offer or technically necessary changes, we use the email address provided during registration to inform you in this way.
The processing of the data entered during registration is carried out for the purpose of executing the user relationship established by the registration and, if applicable, to initiate further contracts (Art. 6 para. 1 lit. b GDPR).
The data collected during registration is stored by us as long as you are registered on this website and is then deleted. Statutory retention periods remain unaffected.
5. Analysis Tools and Advertising
Google Analytics
This website uses features of the web analytics service Google Analytics. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics uses so-called "cookies." These are text files stored on your computer that enable an analysis of your use of the website. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there.
The storage of Google Analytics cookies and the use of this analysis tool are based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in analyzing user behavior to optimize both its web offering and its advertising. If a corresponding consent has been requested (e.g., consent to the storage of cookies), processing takes place exclusively on the basis of Art. 6 para. 1 lit. a GDPR; consent can be revoked at any time.
IP Anonymization
We have activated the IP anonymization function on this website. This means your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before being transmitted to the USA. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, compile reports on website activity, and provide other services related to website and internet usage to the website operator. The IP address transmitted by your browser within Google Analytics will not be merged with other data from Google.
Browser Plugin
You can prevent the storage of cookies by adjusting the settings of your browser software; however, we point out that in this case you may not be able to use all the functions of this website fully. Furthermore, you can prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) by Google, as well as the processing of this data by Google, by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de.
Objection to data collection
You can prevent the collection of your data by Google Analytics by clicking on the following link. An opt-out cookie will be set that prevents the collection of your data during future visits to this website: Disable Google Analytics.
More information about handling user data with Google Analytics can be found in Google's privacy policy: https://support.google.com/analytics/answer/6004245?hl=de.
Order processing
We have concluded a contract for order processing with Google and fully implement the strict requirements of the German data protection authorities when using Google Analytics.
Storage duration
Data stored by Google at the user and event level, linked with cookies, user IDs (e.g., User ID), or advertising IDs (e.g., DoubleClick cookies, Android advertising ID), is anonymized or deleted after 14 months. Details can be found at the following link: https://support.google.com/analytics/answer/7667196?hl=de
Google Analytics Remarketing
This website uses the functions of Google Analytics Remarketing in conjunction with the cross-device functions of Google Ads and Google DoubleClick. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
This function allows the advertising audiences created with Google Analytics Remarketing to be linked with the cross-device functions of Google Ads and Google DoubleClick. This way, interest-based, personalized advertising messages tailored to you based on your previous usage and browsing behavior on one device (e.g., mobile phone) can also be shown on another of your devices (e.g., tablet or PC).
If you have given the corresponding consent, Google links your web and app browsing history with your Google account for this purpose. This way, the same personalized advertising messages can be displayed on every device where you sign in with your Google account.
To support this function, Google Analytics collects Google-authenticated user IDs, which are temporarily linked to our Google Analytics data to define and create audiences for cross-device advertising.
You can permanently object to cross-device remarketing/targeting by disabling personalized advertising; please follow this link: https://www.google.com/settings/ads/onweb/.
The summary of the data collected in your Google account is based solely on your consent, which you can give or withdraw at Google (Art. 6 para. 1 lit. a GDPR). For data collection processes that are not merged in your Google account (e.g., because you do not have a Google account or have objected to the merging), the data collection is based on Art. 6 para. 1 lit. f GDPR. The legitimate interest arises from the fact that the website operator has an interest in the anonymized analysis of website visitors for advertising purposes.
Further information and the privacy policy can be found in Google's privacy statement at: https://policies.google.com/technologies/ads?hl=de.
Google Ads and Google Conversion Tracking
This website uses Google Ads. Google Ads is an online advertising program by Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
As part of Google Ads, we use so-called conversion tracking. When you click on an ad placed by Google, a cookie for conversion tracking is set. Cookies are small text files that the internet browser stores on the user's computer. These cookies expire after 30 days and are not used for personal identification of users. If the user visits certain pages of this website and the cookie has not yet expired, Google and we can recognize that the user clicked on the ad and was redirected to this page.
Each Google Ads customer receives a different cookie. The cookies cannot be tracked across the websites of Google Ads customers. The information collected using the conversion cookie is used to create conversion statistics for Google Ads customers who have opted for conversion tracking. Customers learn the total number of users who clicked on their ad and were redirected to a page tagged with conversion tracking. However, they do not receive any information that would allow users to be personally identified. If you do not want to participate in tracking, you can object to this use by easily disabling the Google Conversion Tracking cookie in your internet browser under user settings. You will then not be included in the conversion tracking statistics.
The storage of "conversion cookies" and the use of this tracking tool are based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in analyzing user behavior to optimize both its web offering and its advertising. If a corresponding consent has been obtained (e.g., consent to the storage of cookies), processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR; consent can be revoked at any time.
More information about Google Ads and Google Conversion Tracking can be found in Google's privacy policy: https://policies.google.com/privacy?hl=de.
You can set your browser to inform you about the setting of cookies and to allow cookies only in individual cases, to exclude the acceptance of cookies for certain cases or in general, and to activate the automatic deletion of cookies when closing the browser. Disabling cookies may restrict the functionality of this website.
6. Plugins and Tools
Google Web Fonts
This site uses so-called web fonts provided by Google for the uniform display of fonts. The Google Fonts are installed locally. No connection to Google servers takes place.
More information about Google Web Fonts can be found at https://developers.google.com/fonts/faq and in Google's privacy policy: https://policies.google.com/privacy?hl=de.
Google Maps
This site uses the Google Maps mapping service via an API. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
To use the functions of Google Maps, it is necessary to store your IP address. This information is usually transmitted to a Google server in the USA and stored there. The provider of this site has no influence on this data transmission.
The use of Google Maps is in the interest of an appealing presentation of our online offers and easy findability of the locations we specify on the website. This constitutes a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR. If a corresponding consent has been requested, processing takes place exclusively on the basis of Art. 6 para. 1 lit. a GDPR; the consent can be revoked at any time.
More information on handling user data can be found in Google's privacy policy: https://policies.google.com/privacy?hl=de.
Google reCAPTCHA
We use "Google reCAPTCHA" (hereinafter "reCAPTCHA") on this website. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
reCAPTCHA is used to verify whether the data entry on this website (e.g., in a contact form) is made by a human or by an automated program. For this purpose, reCAPTCHA analyzes the behavior of the website visitor based on various characteristics. This analysis starts automatically as soon as the website visitor enters the website. For the analysis, reCAPTCHA evaluates various information (e.g., IP address, the duration of the visitor's stay on the website, or mouse movements made by the user). The data collected during the analysis is forwarded to Google.
The reCAPTCHA analyses run completely in the background. Website visitors are not notified that an analysis is taking place.
The storage and analysis of data is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in protecting its web offerings from abusive automated data scraping and from SPAM. If corresponding consent has been requested (e.g., consent to the storage of cookies), processing takes place exclusively on the basis of Art. 6 para. 1 lit. a GDPR; consent can be revoked at any time.
Further information about Google reCAPTCHA can be found in the Google Privacy Policy and the Google Terms of Service at the following links: https://policies.google.com/privacy?hl=de and https://policies.google.com/terms?hl=de.
7. eCommerce and payment providers
Processing of data (customer and contract data)
We collect, process, and use personal data only to the extent necessary to establish, design, or change the legal relationship (master data). This is based on Art. 6 para. 1 lit. b GDPR, which permits the processing of data to fulfill a contract or pre-contractual measures. We collect, process, and use personal data about the use of this website (usage data) only to the extent necessary to enable or bill the user for the use of the service.
The collected customer data will be deleted after the order is completed or the business relationship ends. Statutory retention periods remain unaffected.
Data transmission upon conclusion of contract for online shops, merchants, and goods shipping
We only transmit personal data to third parties if this is necessary for contract processing, for example to companies responsible for delivering the goods or the credit institution responsible for payment processing. No further transmission of data takes place or only if you have expressly consented to the transmission. Your data will not be passed on to third parties without your explicit consent, for example for advertising purposes.
The basis for data processing is Art. 6 para. 1 lit. b GDPR, which permits the processing of data to fulfill a contract or pre-contractual measures.
PayPal
On this website, we offer, among other things, payment via PayPal. The provider of this payment service is PayPal (Europe) S.à.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter "PayPal").
If you choose to pay via PayPal, the payment data you enter will be transmitted to PayPal.
The transmission of your data to PayPal is based on Art. 6 para. 1 lit. a GDPR (consent) and Art. 6 para. 1 lit. b GDPR (processing to fulfill a contract). You have the option to revoke your consent to data processing at any time. A revocation does not affect the legality of data processing carried out in the past.