Privacy policy
We are pleased about your interest in our online shop. The protection of your privacy is very important to us. Below we inform you in detail about the handling of your data.
§ 1 Controller & Contact
The controller for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Capoyo GmbH
Rotwandweg 3
82024 Taufkirchen
Germany
Email: info@orbsmart.shop
Phone: +49 (89) 44 14 11 40
If you have any questions about the collection, processing, or use of your personal data, or for information, correction, blocking, or deletion of data, please contact us.
§ 2 Hosting, Server Log Files & Checkout by Shopify
We host our online shop with Shopify International Ltd., Gordon House, Barrow Street, Dublin 4, Ireland (“Shopify”). Shopify provides the e-commerce platform through which we sell our products, including checkout, payment processing, and hosting.
When you visit our website, Shopify automatically collects information in so-called server log files, which your browser transmits. These are:
- Your IP address
- Browser type and browser version
- Operating system used
- Referrer URL (the previously visited page)
- Hostname of the accessing computer
- Time of the server request
This data is processed to ensure the trouble-free operation of the site and to improve our offer (Legal basis: Art. 6(1)(f) GDPR). This data is not merged with other data sources.
For the transfer of data to the USA and other third countries, Shopify relies on the EU Commission's standard contractual clauses and/or the EU-US Data Privacy Framework (DPF) to ensure an adequate level of data protection.
§ 3 Data Collection upon Conclusion of Contract & Contact
We collect personal data when you voluntarily provide it to us as part of your order or when contacting us (e.g., via contact form or e-mail). Mandatory fields are marked as such because in these cases, we absolutely need the data to process the contract or your request.
Order Processing (Art. 6(1)(b) GDPR):
To fulfill the contract, we collect: Title, first name, last name, e-mail address, address (street, house number, postal code, city), and, if applicable, telephone number.
Customer Account (Art. 6(1)(a) GDPR):
If you voluntarily decide to open a customer account, we process your data based on your consent. You can have your customer account deleted at any time; an informal e-mail to us is sufficient.
Contacting Us (Art. 6(1)(b) or (f) GDPR):
Data that you send us via the contact form or e-mail will be stored to process your request. The processing takes place to carry out pre-contractual measures or to protect our legitimate interest in answering your query.
§ 4 Data Transfer to Third Parties (Service Providers)
To fulfill the contract (Art. 6(1)(b) GDPR), we pass on your data to service providers commissioned by us, insofar as this is necessary. This includes:
- Shipping Provider (DHL): We pass on your e-mail address and address to DHL Group AG (Charles-de-Gaulle-Straße 20, 53113 Bonn, Germany) so that they can inform you about the shipping status and deliver the shipment.
- ERP System (JTL): We use an enterprise resource planning system from JTL-Software-GmbH (Rheinstr. 7, 41836 Hückelhoven, Germany) for contract processing. Our ERP databases are also hosted by JTL. We have concluded a data processing agreement (DPA) with JTL in accordance with Art. 28 GDPR.
- Payment Service Providers: Depending on the payment method selected, we pass on the payment data collected for this purpose to the credit institution commissioned with the payment or to the payment service provider selected by us or you (e.g., PayPal, Amazon Payments, Shopify Payments, Klarna).
§ 5 Cookies, Analytics & Marketing
Our website uses cookies. Some of them are technically necessary to ensure the basic functions of the shop (e.g., the shopping cart) (Legal basis: Art. 6(1)(f) GDPR or § 25(2) TTDSG).
All other cookies, especially for analysis and marketing purposes (e.g., Google Analytics, Google Ads), are only used if you have given us your express consent via our cookie banner (Legal basis: Art. 6(1)(a) GDPR or § 25(1) TTDSG).
Without your consent, these tracking tools will not be activated.
Google Analytics
If you have given your consent, we use Google Analytics (Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). This service analyzes your user behavior on our website (e.g., clicks, duration of visit). The information generated by the cookies is usually transmitted to a Google server in the USA. We use the "IP anonymization" function, which shortens your IP address before transmission to the USA. Data transfer to the USA is based on the EU-US Data Privacy Framework (DPF).
Google Ads Conversion Tracking
If you have given your consent, we use Google Ads Conversion Tracking (Provider: Google Ireland Limited). If you click on a Google ad, a cookie is set. If you then visit our site, Google and we can recognize that you were redirected from the ad. This is used to measure the success of our advertising campaigns.
Google reCAPTCHA
To protect against misuse of our web forms (e.g., contact form) and against SPAM, we use the reCAPTCHA service (Provider: Google Ireland Limited). For this purpose, your IP address and, if applicable, other data required by Google for this service (e.g., mouse movements) are processed. This is done on the basis of our legitimate interest in the security of our website (Art. 6(1)(f) GDPR).
§ 6 Newsletter
If you subscribe to our newsletter (e.g., via the registration field in the shop), we use the data required for this or separately provided by you (your e-mail address) to send you our e-mail newsletter regularly based on your consent (Art. 6(1)(a) GDPR).
We use the so-called double opt-in procedure. After registering, you will receive an e-mail asking you to confirm your registration.
The newsletter is sent using the integrated e-mail marketing function of our shop platform Shopify (Provider: Shopify International Ltd., Gordon House, Barrow Street, Dublin 4, Ireland). Shopify acts as our data processor.
You can unsubscribe from the newsletter at any time, either by sending us a message or via the "Unsubscribe" link in the newsletter.
§ 7 Duration of Storage
We only store your data for as long as is necessary to fulfill the purpose (e.g., contract processing). After the contract has been fully processed, the data will be stored for the duration of the statutory warranty period (2 years) and then stored in accordance with statutory, in particular tax and commercial, retention periods (usually 10 years) and then deleted after the period has expired.
§ 8 Your Rights (Rights of the Data Subject)
Subject to the statutory requirements, you have the following rights:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure ("Right to be forgotten") (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to withdraw consent (Art. 7(3) GDPR)
- Right to object (Art. 21 GDPR)
Furthermore, you have the right to lodge a complaint with a data protection supervisory authority in accordance with Art. 77 GDPR.
§ 9 Dispute Resolution
We are not obligated and not willing to participate in a dispute resolution procedure before a consumer arbitration board.