Privacy policy
Privacy Policy
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
SYNLESS WRLD
Franz-Hitze-Straße 29
33102 Paderborn
Germany
Phone: +49 (0) 152 190 81456
Email: info@synlesswrld.com
2. General Information
We operate our online store via the e-commerce platform Shopify. In this privacy policy, we inform you about how we collect, process, and use personal data when you visit our website, place an order, create a customer account, or otherwise contact us.
Personal data is any information relating to an identified or identifiable natural person.
3. Collection and Processing of Personal Data
In particular, we process the following categories of personal data:
Contact data: Name, billing and shipping address, telephone number, email address
Payment and transaction data: Payment method, payment status, order and transaction details
(Payment data such as credit card numbers are processed exclusively by payment service providers)
Customer data: User account, settings
Order data: Purchased products, shopping cart, order history
Communication data: Support inquiries, email communication
Technical data: IP address, browser type, device, operating system
Usage data: Interactions with the store
4. Sources of Data
Processing is carried out on the basis of data:
- that you provide to us directly
- that is collected automatically when you visit the website
- that is collected via service providers acting on our behalf
5. Legal Bases for Processing
The processing of personal data is carried out in accordance with Article 6 GDPR on the following legal bases:
- Art. 6(1)(b) GDPR – Performance of a contract (orders, shipping, payment)
- Art. 6(1)(c) GDPR – Legal obligations (tax and commercial law)
- Art. 6(1)(a) GDPR – Consent (newsletter, tracking, marketing)
- Art. 6(1)(f) GDPR – Legitimate interest (IT security, fraud prevention, shop optimization)
Consents may be revoked at any time with effect for the future.
6. Purpose of Data Processing
Processing is carried out in particular for the following purposes:
- Processing orders, payments, and shipping
- Managing customer accounts
- Customer communication and support
- Sending newsletters and marketing information
- Analysis and optimization of our online store
- Fraud prevention and security
7. Newsletter & Marketing (Klaviyo)
Newsletters are sent via Klaviyo.
- Newsletters are sent via Klaviyo.
- Newsletters are sent exclusively after explicit consent
- We use the double opt-in procedure
Legal basis: Art. 6(1)(a) GDPR
8. Cookies & Tracking Technologies
We use cookies and similar technologies.
- Technically necessary cookies pursuant to Section 25(2) TTDSG
- Analytics and marketing cookies only after consent
(Section 25(1) TTDSG in conjunction with Art. 6(1)(a) GDPR)
Consent management is handled via a cookie consent tool.
9. Payment Service Providers
For payment processing, we use the following providers:
- Shopify Payments (credit card)
- PayPal
- Klarna
- Apple Pay
- Google Pay
Processing is carried out by the respective payment service providers as independent controllers. Their respective privacy policies apply.
10. Shipping Service Provider
Shipping is carried out via DHL.
For this purpose, name and delivery address are transmitted to DHL.
Legal basis: Art. 6(1)(b) GDPR
11. Shopify & Data Processing Agreement
Our store is operated via Shopify Inc.
- Shopify processes data as a processor pursuant to Art. 28 GDPR
- In certain cases, Shopify processes data as an independent controller
Further information: https://privacy.shopify.com
12. Transfers to Third Countries
Data may be transferred to countries outside the EU/EEA.
This is carried out exclusively on the basis of the European Commission’s Standard Contractual Clauses or an adequacy decision.
13. Data Retention Period
Personal data is stored only for as long as necessary for the respective purposes or as required by statutory retention obligations.
14. Rights of Data Subjects
You have the right to:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to direct marketing (Art. 21 GDPR)
- Withdrawal of consent
Response period: maximum 1 month (Art. 12 GDPR)
15. Right to Lodge a Complaint
Competent supervisory authority:
State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (LDI NRW)
https://www.ldi.nrw.de
16. Data Security
We implement appropriate technical and organizational security measures. However, complete protection cannot be guaranteed.
17. Amendments
This privacy policy may be amended if necessary. The current version is available on our website.
18. Contact
For data protection inquiries, please contact:
SYNLESS WRLD
Franz-Hitze-Straße 29
33102 Paderborn
Germany
Phone: +49 (0) 152 190 81456
Email: info@synlesswrld.com