Privacy Policy
- INFORMATION ABOUT THE COLLECTION OF PERSONAL DATA AND CONTACT DETAILS OF THE DATA CONTROLLER
1.1 We are pleased that you are visiting our website and thank you for your interest. Below, we provide information about how we handle your personal data when you use our website. Personal data refers to all information that can be used to personally identify you.
1.2 The data controller for processing personal data on this website within the meaning of the General Data Protection Regulation (GDPR) is [SweetLunaBelle.com]. The data controller is the natural or legal person who determines, alone or jointly with others, the purposes and means of processing personal data.
1.3 For security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries directed to the data controller), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the string "https://" and the lock icon in your browser’s address bar.
- DATA COLLECTION WHEN VISITING OUR WEBSITE
When you visit our website purely for informational purposes (i.e., without registering or providing us with any information), we only collect the data that your browser automatically transmits to our server (so-called "server log files"). When you access our website, we collect the following data, which is technically necessary for us to display the website:
The specific webpage visited on our website
Date and time of access
Amount of data transferred in bytes
Source/reference from which you arrived at the page
Browser used
Operating system used
IP address used (if applicable: in anonymized form)
This data is processed in accordance with Art. 6(1)(f) GDPR based on our legitimate interest in improving the stability and functionality of our website. The data is not shared or used for other purposes. However, we reserve the right to review the server log files retrospectively if there are concrete indications of unlawful use.
- COOKIES
To make visiting our website more appealing and to enable the use of certain functions, we use so-called cookies on various pages. These are small text files that are stored on your device. Some of the cookies we use are deleted at the end of your browser session, i.e., when you close your browser (so-called session cookies). Other cookies remain on your device and allow us or our partner companies (third-party cookies) to recognize your browser on your next visit (persistent cookies).
Cookies may collect and process specific user information, such as browser and location data or IP address values, depending on their functionality. Persistent cookies are automatically deleted after a predefined period, which may vary depending on the cookie.
Some cookies serve to simplify the order process by storing settings (e.g., remembering the contents of a virtual shopping cart for a later visit). If personal data is also processed by individual cookies implemented by us, this processing is based either on Art. 6(1)(b) GDPR for the execution of a contract or on Art. 6(1)(f) GDPR to safeguard our legitimate interests in providing the best possible functionality of the website and a customer-friendly and effective browsing experience.
We may also work with advertising partners to make our online offer more interesting for you. In this case, cookies from partner companies (third-party cookies) may also be stored on your hard drive when you visit our website. If we collaborate with such advertising partners, you will be informed separately and in detail about the use of these cookies and the scope of the data collected in the corresponding sections below.
Please note that you can configure your browser to inform you about the setting of cookies, allow them on a case-by-case basis, exclude the acceptance of cookies for certain cases, or generally disable them. Every browser manages cookie settings differently. The help menu of your browser provides explanations on how to adjust your cookie settings. You can find instructions for the respective browsers at the following links:
Internet Explorer: Instructions
Firefox: Instructions
Chrome: Instructions
Safari: Instructions
Opera: Instructions
Please note that disabling cookies may limit the functionality of our website.
- CONTACT
When contacting us (e.g., via a contact form or email), personal data is collected. The specific data collected through a contact form is evident from the respective contact form itself. This data is stored and used exclusively for the purpose of responding to your inquiry or for establishing contact and the associated technical administration.
The legal basis for processing this data is our legitimate interest in responding to your request in accordance with Art. 6(1)(f) GDPR. If your contact aims to conclude a contract, an additional legal basis for processing is Art. 6(1)(b) GDPR.
Your data will be deleted once your request has been fully processed, provided that there are no statutory retention requirements and it can be inferred from the circumstances that the matter has been conclusively resolved.
- DATA PROCESSING WHEN CREATING A CUSTOMER ACCOUNT AND FOR CONTRACT EXECUTION
In accordance with Art. 6(1)(b) GDPR, personal data is collected and processed if you provide it to us for the execution of a contract or when opening a customer account. The specific data collected is indicated in the respective input forms. You may delete your customer account at any time by sending a message to the data controller’s address provided above.
We store and use the data you provide for contract processing. After the contract has been fully executed or your customer account deleted, your data will be restricted for further use and deleted after the retention periods required under tax and commercial law, unless you have explicitly consented to further use of your data or we are legally permitted to continue using the data, as outlined in this privacy policy.
- USE OF YOUR DATA FOR DIRECT MARKETING
6.1 Subscription to our Email Newsletter
If you subscribe to our email newsletter, we will regularly send you information about our offers. The only mandatory information required to send the newsletter is your email address. Providing additional data is voluntary and is used to address you personally. We use the so-called double opt-in procedure to send the newsletter. This means we will only send you an email newsletter if you have explicitly confirmed your consent to receive newsletters.
After subscribing, you will receive a confirmation email asking you to confirm your subscription by clicking a corresponding link. By activating the confirmation link, you consent to the use of your personal data in accordance with Art. 6(1)(a) GDPR.
When you subscribe to the newsletter, we save your IP address, as entered by your Internet Service Provider (ISP), as well as the date and time of subscription to prevent misuse of your email address. The data collected during the newsletter subscription is used exclusively for promotional purposes via the newsletter.
You may unsubscribe from the newsletter at any time by clicking the link provided in the newsletter or by notifying the data controller at the address mentioned earlier. After unsubscribing, your email address will be promptly removed from our mailing list, unless you have explicitly consented to further use of your data or we reserve the right to use your data in a manner permitted by law, about which we inform you in this policy.
6.2 Sending the Email Newsletter to Existing Customers
If you have provided your email address when purchasing goods or services, we reserve the right to send you regular offers for similar goods or services from our range via email. For this purpose, we do not require separate consent from you. The data processing is carried out solely on the basis of our legitimate interest in personalized direct marketing, in accordance with Art. 6(1)(f) GDPR.
If you initially objected to the use of your email address for this purpose, we will not send you any emails. You have the right to object to the use of your email address for promotional purposes at any time with effect for the future by notifying the data controller mentioned above. Only transmission costs in accordance with basic rates will apply. Once your objection is received, the use of your email address for advertising purposes will cease immediately.
- DATA PROCESSING FOR ORDER PROCESSING
7.1 Transfer of Personal Data for Delivery and Payment Processing
Personal data collected by us is shared with the delivery company assigned to ship the goods, as far as it is necessary for the delivery. Similarly, your payment details are shared with the financial institution responsible for processing the payment, as required for the payment process. If we use payment service providers, you will be explicitly informed below. The legal basis for this data transfer is Art. 6(1)(b) GDPR.
7.2 Use of Payment Service Providers
PayPal
If you select PayPal as your payment method, your payment details will be transferred to PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg, for payment processing. This transfer is in accordance with Art. 6(1)(b) GDPR and is strictly limited to what is necessary for payment processing.
For certain payment methods (credit card via PayPal, direct debit via PayPal, "purchase on account," or "installment payment"), PayPal may conduct a credit check. To do so, PayPal may forward your payment data to credit agencies in line with Art. 6(1)(f) GDPR, based on its legitimate interest in assessing your creditworthiness.
The credit check result (e.g., statistical probability of payment default) may influence the availability of specific payment methods. This process may involve "score values" calculated using scientifically recognized mathematical-statistical procedures, which may include address data.
More details, including the credit agencies involved, can be found in PayPal's privacy policy: PayPal Privacy Policy.
You may object to this data processing at any time by contacting PayPal. However, PayPal may still process your data as required for contractual payment processing.
SOFORT
If you choose "SOFORT" as your payment method, payment processing will be conducted via SOFORT GmbH, Theresienhöhe 12, 80339 Munich, Germany. SOFORT GmbH is part of the Klarna Group (Klarna Bank AB, Sveavägen 46, 11134 Stockholm, Sweden). Your payment and order data will be shared with SOFORT under Art. 6(1)(b) GDPR, solely for payment processing.
For more details, please refer to SOFORT's privacy policy: SOFORT Privacy Policy.
- CONTACT FOR REVIEW REMINDERS
We may use your email address to send you a one-time reminder to submit a review of your order on our review system, provided you have given your explicit consent during or after your order, in accordance with Art. 6(1)(a) GDPR.
You can revoke your consent at any time by notifying the data controller mentioned above.
- USE OF SOCIAL MEDIA: SOCIAL PLUGINS
9.1 Facebook Plugins with Shariff Solution
Our website uses social plugins ("plugins") from the Facebook platform operated by Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA.
To protect your data, these plugins are integrated into our website via an HTML link. This ensures that no connection to Facebook servers is made when you visit a page on our site containing these buttons. Only when you click the button, a new browser window will open, taking you to Facebook, where you can interact with the plugin after logging in.
Facebook is certified under the EU-US Privacy Shield Framework, ensuring compliance with European data protection standards.
For more information on data collection and use by Facebook, please visit their privacy policy: Facebook Privacy Policy.
9.2 Google+ Plugins with Shariff Solution
Our website uses plugins from the Google+ platform, operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
As with Facebook, these plugins are integrated via HTML links to prevent immediate connection with Google's servers. You can interact with Google+ plugins only by clicking on the link, which will open a new browser window.
Google LLC is certified under the EU-US Privacy Shield. For more information, refer to Google's privacy policy: Google Privacy Policy.
9.3 Instagram Plugins with Shariff Solution
Our website includes plugins for Instagram, operated by Instagram LLC, 1601 Willow Rd, Menlo Park, CA 94025, USA.
These plugins are also integrated using HTML links to protect your data. Interaction with Instagram plugins occurs only after clicking the link, which opens a new browser window.
Instagram LLC is certified under the EU-US Privacy Shield. Further details can be found in Instagram's privacy policy: Instagram Privacy Policy.
10) ONLINE MARKETING
10.1 DoubleClick by Google
This website uses the online marketing tool DoubleClick by Google, operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("DoubleClick").
DoubleClick uses cookies to display relevant advertisements to users, improve campaign performance reports, or prevent a user from seeing the same ad multiple times. Using a cookie ID, Google tracks which ads are displayed in which browser and can thus prevent them from being shown multiple times. The processing is based on our legitimate interest in the optimal marketing of our website in accordance with Art. 6(1)(f) GDPR.
Additionally, DoubleClick can use cookie IDs to record so-called conversions related to ad requests. For example, this happens when a user sees a DoubleClick ad and later visits the advertiser’s website using the same browser and makes a purchase. According to Google, DoubleClick cookies do not contain personal data.
Due to the marketing tools used, your browser automatically establishes a direct connection to Google’s server. We have no control over the extent and further use of the data collected by Google through this tool and therefore inform you to the best of our knowledge: Through the integration of DoubleClick, Google receives information that you have accessed a particular part of our website or clicked on an ad from us. If you are registered with a Google service, Google can associate the visit with your account. Even if you are not registered with Google or not logged in, it is possible for the provider to obtain and store your IP address.
If you wish to opt out of this tracking process, you can disable cookies for conversion tracking by setting your browser to block cookies from the domain www.googleadservices.com. You can also configure your browser to notify you about the setting of cookies and individually decide whether to accept them or block cookies in specific cases or in general. Please note that the functionality of our website may be limited if cookies are not accepted.
Google LLC, based in the USA, is certified under the EU-US Privacy Shield, which ensures compliance with the level of data protection applicable in the EU.
For more information about the privacy policies of DoubleClick by Google, visit: https://www.google.de/policies/privacy/.
10.2 Use of Google AdWords Conversion Tracking
This website uses the online advertising program "Google AdWords" and, within the framework of Google AdWords, the conversion tracking of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"). We use Google AdWords to draw attention to our attractive offers on external websites through advertising materials (so-called Google AdWords). We can evaluate the success of individual advertising campaigns in relation to the data from the campaigns. Our aim is to show you advertising that is of interest to you, make our website more interesting for you, and ensure a fair calculation of advertising costs.
The conversion tracking cookie is set when a user clicks on an ad served by Google. Cookies are small text files stored on your computer system. These cookies generally expire after 30 days and are not used to personally identify users. If the user visits certain pages of this website and the cookie has not yet expired, Google and we can recognize that the user clicked on the ad and was redirected to this page. Each Google AdWords customer receives a different cookie, so cookies cannot be tracked across the websites of AdWords customers.
The information collected using the conversion cookie is used to create conversion statistics for AdWords customers who have opted for conversion tracking. Customers are informed about the total number of users who clicked on their ad and were redirected to a page with a conversion tracking tag. However, they do not receive information that personally identifies users.
If you do not wish to participate in tracking, you can block this use by disabling the Google conversion tracking cookie through your browser settings under "User Preferences." You will then not be included in the conversion tracking statistics.
We use Google AdWords based on our legitimate interest in targeted advertising in accordance with Art. 6(1)(f) GDPR.
Google LLC, based in the USA, is certified under the EU-US Privacy Shield, ensuring compliance with the level of data protection applicable in the EU.
For more information on Google's privacy policies, visit: https://www.google.de/policies/privacy/.
You can permanently disable cookies for ad preferences by adjusting your browser settings or downloading and installing the browser plug-in available at: https://www.google.com/settings/ads/plugin?hl=en.
Please note that certain functions of this website may not be fully available if cookies are disabled.
11) WEB ANALYSIS SERVICES
Google (Universal) Analytics
Function: This website uses Google Analytics, a web analytics service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google").
Google Analytics uses "cookies," which are text files placed on your computer, to help analyze how users use the website. The information generated by the cookie about your use of this website (including the shortened IP address) is generally transmitted to and stored by Google on servers in the USA.
Anonymization: This website exclusively uses Google Analytics with the extension "_anonymizeIp()," which ensures anonymization of the IP address by truncation and excludes direct personal identification.
Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. In such exceptional cases, this processing is carried out under Art. 6(1)(f) GDPR based on our legitimate interest in statistical analysis of user behavior for optimization and marketing purposes.
Google uses this information on our behalf to evaluate your use of the website, compile reports on website activity, and provide other services related to website and internet usage. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.
Opt-out:
You can prevent cookies from being stored by adjusting your browser settings. However, please note that in this case, you may not be able to use all the website’s features fully. You can also prevent the data generated by the cookie (including your IP address) from being collected and processed by Google by downloading and installing the browser plug-in available at: https://tools.google.com/dlpage/gaoptout?hl=en.
Alternatively, you can click the following link to set an opt-out cookie, which prevents future collection of your data by Google Analytics within this website (this opt-out cookie works only in this browser and for this domain; if you delete your cookies in this browser, you must click the link again): Disable Google Analytics.
Cross-device tracking: This website also uses Google Analytics for cross-device analysis of visitor flows, conducted using a user ID. Upon the first visit to a page, the user is assigned a unique, permanent, and anonymized ID that is used across devices. This allows interaction data from various devices and sessions to be assigned to a single user. The user ID does not contain personal data and does not transmit such data to Google.
You can object to the collection and storage of data via the user ID at any time with effect for the future. To do this, you must disable Google Analytics on all systems you use, such as in another browser or on your mobile device.
For additional information on Universal Analytics, visit: https://support.google.com/analytics/answer/2838718?hl=en&ref_topic=6010376.
12) RETARGETING/REMARKETING/RECOMMENDATION ADVERTISING
Facebook Custom Audience via the Pixel Method
This website uses the "Facebook Pixel" from Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA ("Facebook"). With explicit consent, this tool allows user behavior to be tracked after they have viewed or clicked on a Facebook ad. This process helps evaluate the effectiveness of Facebook ads for statistical and market research purposes and can assist in optimizing future advertising efforts.
The data collected is anonymous to us, meaning it does not allow us to identify users. However, Facebook stores and processes the data, making it possible to associate it with the respective user profile, which Facebook may use for its own advertising purposes in accordance with Facebook’s Data Use Policy (https://www.facebook.com/about/privacy/).
This allows Facebook and its partners to display ads both on and off Facebook. A cookie may also be stored on your computer for this purpose.
These processing activities occur only with your explicit consent, in accordance with Art. 6(1)(a) GDPR.
Consent for using the Facebook Pixel may only be given by users who are 13 years or older. If you are younger, please ask your legal guardian for permission.
Facebook Inc., based in the USA, is certified under the EU-US Privacy Shield, ensuring compliance with the data protection standards applicable in the EU.
To deactivate the use of cookies on your computer, you can adjust your browser settings to prevent future cookies from being stored or to delete already stored cookies. Disabling all cookies may result in limited functionality on our website. You can also deactivate the use of cookies by third parties, such as Facebook, on the Digital Advertising Alliance website: https://www.aboutads.info/choices/.
Google AdWords Remarketing
Our website uses the features of Google AdWords Remarketing, which enables us to advertise this website in Google search results and on third-party websites.
The provider is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"). For this purpose, Google places a cookie in the browser of your end device, which automatically enables interest-based advertising using a pseudonymous cookie ID and based on the pages you have visited. Processing is carried out based on our legitimate interest in the optimal marketing of our website in accordance with Art. 6(1)(f) GDPR.
Further data processing occurs only if you have consented to Google linking your web and app browsing history to your Google account and using information from your Google account to personalize ads you view on the web. If you are logged into Google while visiting our website, Google uses your data together with Google Analytics data to create and define target audience lists for cross-device remarketing. To do this, Google temporarily links your personal data with Google Analytics data to form target groups.
You can permanently disable cookies for ad preferences by downloading and installing the browser plug-in available at: https://www.google.com/settings/ads/onweb/.
Alternatively, you can find information about the use of cookies and adjust your settings on the Digital Advertising Alliance website at: www.aboutads.info. Finally, you can configure your browser to notify you when cookies are set and decide individually whether to accept them or block cookies in certain cases or generally. Please note that the functionality of our website may be limited if cookies are not accepted.
Google LLC, based in the USA, is certified under the EU-US Privacy Shield, ensuring compliance with the EU data protection standards.
Further information and Google’s privacy policy regarding advertising can be found at: https://www.google.com/policies/technologies/ads/.
13) RIGHTS OF THE DATA SUBJECT
13.1 Rights under Data Protection Law
The applicable data protection law grants you comprehensive rights (rights of access and intervention) with respect to the processing of your personal data by the data controller. These include:
Right to Access (Art. 15 GDPR): You have the right to access your personal data processed by us, the purposes of processing, the categories of data processed, the recipients or categories of recipients to whom your data has been disclosed or will be disclosed, the planned retention period or criteria for determining the retention period, the existence of a right to rectification, deletion, restriction of processing, objection to processing, the right to lodge a complaint with a supervisory authority, the source of your data if not collected by us, the existence of automated decision-making including profiling, and meaningful information about the logic involved, significance, and potential consequences of such processing.
Right to Rectification (Art. 16 GDPR): You have the right to obtain the rectification of inaccurate personal data concerning you and to have incomplete data completed without delay.
Right to Deletion (Art. 17 GDPR): You have the right to request the deletion of your personal data under certain conditions, particularly if the processing is no longer necessary, you withdraw consent, or the processing is unlawful. Exceptions apply, such as when processing is necessary to exercise the right to freedom of expression, comply with legal obligations, serve the public interest, or establish, exercise, or defend legal claims.
Right to Restriction of Processing (Art. 18 GDPR): You have the right to request the restriction of processing of your personal data if you contest its accuracy, oppose its deletion in the case of unlawful processing, require it for legal claims, or have objected to processing and verification of legitimate grounds is pending.
Right to Notification (Art. 19 GDPR): If you have asserted your right to rectification, deletion, or restriction of processing, the controller is obligated to notify all recipients of your data unless this proves impossible or involves disproportionate effort.
Right to Data Portability (Art. 20 GDPR): You have the right to receive your personal data in a structured, commonly used, and machine-readable format or to have it transferred to another controller where technically feasible.
Right to Withdraw Consent (Art. 7(3) GDPR): You can withdraw your consent to data processing at any time with future effect. Data processed before withdrawal remains lawful.
Right to Lodge a Complaint (Art. 77 GDPR): If you believe the processing of your personal data violates the GDPR, you can lodge a complaint with a supervisory authority in the member state of your residence, workplace, or the alleged infringement.
13.2 Right to Object
If we process your personal data based on legitimate interests, you have the right to object to the processing at any time for reasons related to your particular situation.
If you exercise your right to object, we will cease processing the data unless we can demonstrate compelling legitimate grounds for processing that override your interests, rights, and freedoms, or if the processing serves the establishment, exercise, or defense of legal claims.
If your personal data is processed for direct marketing purposes, you have the right to object at any time to such processing. Once you exercise this right, we will stop processing your data for direct marketing purposes.
14) DURATION OF DATA STORAGE
The retention period for personal data depends on the respective statutory retention period (e.g., commercial and tax law retention periods). After the period expires, the corresponding data is routinely deleted unless it is still required for contract fulfillment or initiation, or if we have a legitimate interest in further storage.