Privacy Policy

Privacy Policy

1) INFORMATION ABOUT THE COLLECTION OF PERSONAL DATA AND CONTACT DETAILS OF THE CONTROLLER

1.1 
We are pleased that you are visiting our website and thank you for your interest. In the following, we inform you about how we handle your personal data when you use our website. Personal data refers to all data with which you can be personally identified.

1.2
The controller responsible for data processing on this website under the General Data Protection Regulation (GDPR) is Noah Toronto. The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data.

1.3  
For security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the controller), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the character sequence "https://" and the lock symbol in your browser's address bar.

2) DATA COLLECTION WHEN VISITING OUR WEBSITE

When you visit our website purely for informational purposes, i.e., without registering or providing us with other information, we collect only the data that your browser transmits to our server (so-called "server log files"). This data is technically necessary for us to display the website, and includes:

- The website you visited  
- The date and time of access  
- The amount of data sent in bytes  
- The source/reference from which you accessed the page  
- The browser used  
- The operating system used  
- The IP address used (if applicable: anonymized)

The processing of this data is conducted in accordance with Article 6(1)(f) GDPR, based on our legitimate interest in improving the stability and functionality of our website. The data will not be passed on or used in any other way. However, we reserve the right to check the server log files retrospectively if there are specific indications of illegal use.

3) COOKIES

To make our website more attractive and to enable the use of certain functions, we use cookies on various pages. Cookies are small text files stored on your device. Some cookies are deleted after the end of your browser session (session cookies), while others remain on your device and allow us or our partner companies to recognize your browser on your next visit (persistent cookies).  

When cookies are set, they collect and process specific user information, such as browser and location data and IP address values. Persistent cookies are automatically deleted after a predefined period, which may differ depending on the cookie.

Some cookies are used to simplify the ordering process by saving settings (e.g., remembering the contents of a shopping cart for a later visit). If personal data is also processed via cookies, this processing is based on Article 6(1)(b) GDPR (performance of a contract) or Article 6(1)(f) GDPR (legitimate interest in the best functionality of the website and a user-friendly experience).

We may also collaborate with advertising partners who help us make our website more interesting for you. In such cases, cookies from these partner companies may also be stored on your device. You will be informed about the use of such cookies and the information collected within the respective sections below.

You can configure your browser settings to be informed about the setting of cookies, decide on a case-by-case basis whether to accept cookies, or generally exclude the acceptance of cookies. Please note that disabling cookies may limit the functionality of our website.

4) CONTACTING US

When contacting us (e.g., via contact form or email), personal data is collected. The specific data collected can be seen from the respective input form. This data is stored and used solely for the purpose of responding to your inquiry and for the related technical administration. The legal basis for processing this data is Article 6(1)(f) GDPR. If your inquiry aims to conclude a contract, Article 6(1)(b) GDPR provides an additional legal basis. Once your inquiry has been fully resolved, your data will be deleted unless statutory retention obligations prevent this.

5) DATA PROCESSING FOR ACCOUNT CREATION AND CONTRACT EXECUTION

Personal data is collected and processed in accordance with Article 6(1)(b) GDPR when you provide it to us for the execution of a contract or the creation of a customer account. The specific data collected is evident from the input forms. You can delete your customer account at any time by notifying us. Once a contract has been fully executed or your account has been deleted, your data will be locked in compliance with retention periods required by tax and commercial law and deleted after these periods, unless you have explicitly consented to further use or we are legally allowed to continue processing it.

6) USE OF YOUR DATA FOR DIRECT MARKETING

6.1 Subscription to our Email Newsletter
When you subscribe to our email newsletter, we send you regular updates about our offers. Providing your email address is sufficient for receiving the newsletter. Any additional information is voluntary and used to personalize the communication.  
The newsletter is sent using a double opt-in process. This means we will only send you a newsletter after you confirm your consent by clicking a verification link in an email sent to you. By activating the confirmation link, you agree to the use of your personal data under Article 6(1)(a) GDPR.

We store your IP address and the date/time of registration to track potential misuse of your email address. You can unsubscribe from the newsletter at any time via the unsubscribe link provided in every newsletter or by contacting us directly. Upon unsubscribing, your email address will be deleted unless you have explicitly consented to its further use or if legally permitted processing is necessary.

6.2 Sending Email Newsletters to Existing Customers  
If you have provided your email address during a purchase, we reserve the right to send you emails with offers on similar products or services, as permitted under Article 6(1)(f) GDPR. You may object to this at any time by contacting us or using the unsubscribe link in the emails.

7) DATA PROCESSING FOR ORDER HANDLING

7.1 Transmission to Shipping Providers  
Personal data is shared with the shipping company for the purpose of delivering goods. Payment data is also shared with the financial institution or payment service provider responsible for processing the payment. The legal basis is Article 6(1)(b) GDPR.

7.2 Payment Services  
- PayPal: For payments processed via PayPal, your data is shared with PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg, as required for processing payments.  
- SOFORT: For SOFORT payments, your data is shared with SOFORT GmbH, a Klarna Group subsidiary, to process the transaction.  

8) CONTACT FOR REVIEW REMINDERS  
We may use your email address to remind you to review your purchase if you have provided explicit consent during or after your order under Article 6(1)(a) GDPR. You can withdraw your consent at any time.

9) USE OF SOCIAL MEDIA PLUGINS

9.1 Facebook Plugins with Shariff Solution
Our website uses Facebook plugins in a way that protects your privacy. Interaction with Facebook occurs only when you click the plugin. For more details, see Facebook's Privacy Policy: [https://www.facebook.com/policy.php](https://www.facebook.com/policy.php).

9.2 Instagram Plugins
Similarly, Instagram plugins are embedded using a privacy-enhanced method. Data transfer occurs only when you click the plugin. See Instagram's Privacy Policy: [https://help.instagram.com/155833707900388/](https://help.instagram.com/155833707900388/).

10) ONLINE MARKETING

10.1 Google DoubleClick
This service is used to display relevant ads and track performance. It uses cookies to personalize ads based on user activity. See Google’s Privacy Policy: [https://www.google.com/policies/privacy/](https://www.google.com/policies/privacy/).

10.2 Google AdWords Conversion Tracking
This allows us to track the success of ad campaigns. Cookies are used to evaluate actions such as clicks on ads. You can opt out via browser settings or plugins.

11) WEB ANALYTICS SERVICES

Google Analytics* 
We use Google Analytics to analyze user behavior on our website. Data is anonymized and processed under Article 6(1)(f) GDPR. You can opt out using browser plugins or settings. See: [https://tools.google.com/dlpage/gaoptout?hl=en](https://tools.google.com/dlpage/gaoptout?hl=en).

12) RETARGETING/REMARKETING

Facebook Pixel
This tool tracks user actions after interacting with Facebook ads, helping optimize future campaigns. Processing occurs only with explicit consent under Article 6(1)(a) GDPR.

13) DATA SUBJECT RIGHTS

13.1 Your Rights
You have the right to:  
- Access your data (Article 15 GDPR).  
- Rectification of incorrect data (Article 16 GDPR).  
- Erasure of your data (Article 17 GDPR).  
- Restriction of processing (Article 18 GDPR).  
- Data portability (Article 20 GDPR).  
- Withdraw consent (Article 7(3) GDPR).  
- Lodge a complaint with a supervisory authority (Article 77 GDPR).  

13.2 Right to Object 
You may object to processing based on legitimate interests at any time if there are reasons relating to your particular situation (Article 21 GDPR). If the data is used for direct marketing, you may object at any time without providing a reason.

14) DATA RETENTION
Personal data is stored only as long as required by legal retention periods or necessary for the purposes for which it was collected.