Skip to content

End of Season Sale

shop now

Cart

Your cart is empty

Cookie settings

Choose which cookies and similar technologies you consent to. You can change or withdraw your choice at any time via the “Cookie settings” link at the bottom of every page.

More in our privacy policy

Privacy policy

This English translation is provided for your information. Only the German version is legally binding.

Last updated: 30 September 2026

Protecting your personal data is important to us. In this privacy policy, we explain which data we process when you visit our website wstnd.com, shop with us or contact us in any other way, for what purposes and on what legal basis we do so, to whom we pass on data, how long we store it and what rights you have. Personal data is any information relating to an identified or identifiable natural person, such as your name, your address, your e-mail address or your IP address.

Overview

  1. Controller and contact
  2. Legal bases
  3. Visiting our website and hosting (Shopify)
  4. Encryption
  5. Cookies, local storage and consent
  6. Customer account
  7. Orders and contract processing
  8. Payment and fraud prevention
  9. Shipping and logistics
  10. Order tracking, returns and withdrawal function
  11. Back-in-stock notification
  12. Contact form, e-mail, telephone and AI-assisted support tool
  13. Customer reviews
  14. Newsletter
  15. Web push notifications
  16. Analytics and marketing (only with consent)
  17. Protection against spam and abuse
  18. Job applications
  19. Partner, press and cooperation enquiries
  20. Our profiles on social networks
  21. Shopify as an independent controller (Shop Pay, Shop app)
  22. Recipients at a glance
  23. Transfers to third countries
  24. Storage period
  25. Obligation to provide data and automated decision-making
  26. Your rights
  27. Data security
  28. Children and young people
  29. Changes to this privacy policy

1. Controller and contact

The controller responsible for data processing on this website and in our online shop within the meaning of the General Data Protection Regulation (GDPR) is:

WSTND GmbH i. G.
represented by its managing director Nuray Kahraman
Brehmstr. 3
40239 Düsseldorf
Germany
E-mail: info@wstnd.com

You can reach us using these contact details for all questions about data protection and for exercising your rights, most easily by e-mail. We have not appointed a data protection officer, as we are not legally required to do so.

2. Legal bases

We only process personal data if a legal basis permits it. In this privacy policy, we state the relevant legal basis for each processing operation:

  • Consent (Art. 6(1)(a) GDPR): You have given us your consent for a specific purpose, e.g. for the newsletter or for analytics and marketing cookies. You can withdraw your consent at any time with effect for the future.
  • Contract and pre-contractual measures (Art. 6(1)(b) GDPR): The processing is necessary to perform a contract with you or to take steps at your request prior to entering into a contract, e.g. to deliver your order.
  • Legal obligation (Art. 6(1)(c) GDPR): We are legally obliged to process data, e.g. to retain invoices or to confirm a withdrawal.
  • Legitimate interests (Art. 6(1)(f) GDPR): The processing is necessary for the purposes of our legitimate interests or those of a third party, and your interests do not override them, e.g. in the secure operation of our website. We state the interest we pursue in each case.
  • Access to your device (Section 25 of the German Telecommunications Digital Services Data Protection Act, TDDDG): Storing information on your device (e.g. cookies) and reading such information is only permitted without consent if it is strictly necessary to provide a service you have expressly requested (Section 25(2) No. 2 TDDDG). In all other cases, we obtain your consent (Section 25(1) TDDDG).

3. Visiting our website and hosting (Shopify)

Our online shop runs on the Shopify platform. The provider is Shopify International Limited, Victoria Buildings, 2nd Floor, 1–2 Haddington Road, Dublin 4, D04 XN32, Ireland (“Shopify”). Shopify provides the servers, software and security infrastructure for our shop and processes on our behalf all data generated when you visit the website, place orders and use the customer account.

Each time you access our website, Shopify automatically processes technically necessary connection data transmitted by your browser:

  • IP address and the approximate location derived from it (country, region)
  • date and time of access
  • page or file accessed and amount of data transferred
  • the website from which you came to us (referrer)
  • browser type and version, operating system, device type and language setting

This data is required to deliver the website to you, to ensure the stability and security of the shop and to detect and prevent attacks and misuse (e.g. bot access or fraud attempts). Shopify also uses content delivery networks for this purpose, which deliver content via servers close to you. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the secure and error-free operation of our online shop. The log data is only stored for as long as necessary for these purposes.

We have concluded a data processing agreement with Shopify (Art. 28 GDPR). Shopify may transfer data to affiliated companies and sub-processors outside the EU, in particular to Shopify Inc. in Canada and Shopify (USA) Inc. in the USA. For Canada, there is an adequacy decision of the EU Commission; transfers to the USA are based on the EU-US Data Privacy Framework and, in addition, on standard contractual clauses (see section 23).

4. Encryption

For security reasons, our website and all applications we operate can only be accessed via an encrypted connection (TLS). You can recognise it by “https://” and the lock symbol in your browser’s address bar. Data that you transmit to us – for example when placing an order or via a form – therefore cannot be read by third parties.

5. Cookies, local storage and consent

5.1 What we store

We and the services we use store information on your device or read it from there, for example in the form of cookies (small text files) or in your browser’s local storage (local storage and session storage). We distinguish between the following categories:

  • Strictly necessary (without consent, Section 25(2) No. 2 TDDDG, Art. 6(1)(b) and (f) GDPR): for the cart, the checkout, logging in to the customer account, your country, language and currency selection, the security of the shop and the storage of your cookie choice. The shop does not work without these.
  • Preferences (only with consent): features that remember your selection and make use more convenient, such as the display of recently viewed items.
  • Analytics (only with consent): measuring the use of our shop in order to improve it (section 16).
  • Marketing (only with consent): measuring the success of our advertising and showing relevant advertising on other platforms (section 16).

You can find a current list of the cookies used by Shopify, including their purpose and storage period, at shopify.com/legal/cookies.

5.2 Features that only store data in your browser

Some features of our shop store information exclusively in your browser’s local storage. This data remains on your device and is not transmitted to us:

  • Wishlist (“wstnd_wishlist”): the items you save with the heart symbol.
  • Newsletter notice (“theme:popup-filled”): so that the newsletter sign-up window does not appear again on every visit.
  • WSTND game (“wstnd_game_plays”): the number of your attempts on this device.
  • Withdrawal form (“wstnd-widerruf”, only for the duration of the session): so that your acknowledgement of receipt can be displayed after submission.

These storage operations serve features that you use yourself and are based on Section 25(2) No. 2 TDDDG. Only if you have consented to the “Preferences” category do we also remember in local storage (“theme:recently-viewed-products”) which items you have recently viewed, in order to show them to you again (Section 25(1) TDDDG, Art. 6(1)(a) GDPR); if you withdraw your consent, we delete this list. You can remove all of this data yourself at any time by deleting the website data in your browser; your wishlist will then be lost.

5.3 Giving, changing and withdrawing consent

On your first visit, we ask you via our cookie banner whether you consent to preference, analytics and marketing cookies. You can accept all categories, reject all or select them individually. Without consent, we only use strictly necessary storage. Consent management is provided by Shopify; your choice is stored in a cookie (“_tracking_consent”) for up to twelve months so that we do not have to ask you again on every visit. The legal basis for this is Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR (proof of consent).

Your consent is voluntary. You can change or withdraw it at any time via the “Cookie settings” link in the footer of every page. The withdrawal takes effect for the future; the lawfulness of the processing carried out until then remains unaffected. You can also block or delete cookies in your browser; our shop may then only work to a limited extent.

6. Customer account

You can order from us as a guest or create a customer account. You log in with your e-mail address and a one-time code that we send you by e-mail each time you log in; we do not store a password. In the customer account, we process your name, your e-mail address, your saved addresses, your telephone number if applicable and your order history so that you can view orders and complete future purchases more quickly. The customer account is operated by Shopify on our behalf and can be accessed at account.wstnd.com.

The legal basis is Art. 6(1)(b) GDPR. You can request the deletion of your customer account at any time by e-mail to us. Data that we must continue to store due to statutory retention obligations is restricted until the respective period expires (section 24). If you log in with Shop (“Sign in with Shop”), section 21 also applies.

7. Orders and contract processing

When you order from us, we process the data required to conclude and perform the purchase contract:

  • first and last name, billing and delivery address
  • e-mail address and, if provided or required for delivery, telephone number
  • ordered items, sizes, prices, shipping method, redeemed discount codes and gift cards
  • payment method and payment status (details in section 8)
  • order number, order date, shipping and delivery status and communication about the order
  • technical data of the order, in particular IP address and browser information, for fraud prevention

We use this data to process your order, ship the goods, inform you about the status of your order (order and shipping confirmation by e-mail), handle payments, returns, withdrawals, exchanges and warranty cases, and to issue invoices. The legal bases are Art. 6(1)(b) GDPR and, where we fulfil retention obligations under commercial and tax law, Art. 6(1)(c) GDPR. Fraud prevention and the enforcement of our claims are based on Art. 6(1)(f) GDPR.

For inventory management, invoicing and shipping preparation, we use the ERP system Xentral. The provider is Xentral ERP Software GmbH, Fuggerstraße 11, 86150 Augsburg, Germany. Xentral processes the order data on our behalf (Art. 28 GDPR). Our tax advisor and, where applicable, tax authorities receive the necessary data for our accounting and the fulfilment of tax obligations.

If you abandon a checkout, Shopify stores the data entered up to that point. We only send you reminder e-mails about an uncompleted purchase if you have consented to receiving advertising e-mails (section 14).

8. Payment and fraud prevention

To process payments, we pass on the necessary data to the payment service provider you select in the checkout. The legal basis is Art. 6(1)(b) GDPR. The payment service providers partly process your data under their own responsibility, for example to fulfil legal obligations to prevent money laundering or to prevent fraud; their own privacy notices apply to this.

8.1 Shopify Payments (credit and debit cards, Apple Pay, Google Pay, Shop Pay)

We process card and wallet payments via Shopify Payments. The payment service provider is Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland. In particular, name, billing address, e-mail address, card details (card number, expiry date, security code), amount, currency, order number and device and connection data are processed. We do not receive full card details ourselves, only information such as the card type, the last four digits and the payment status. Your bank may additionally require the payment to be confirmed via 3-D Secure. Stripe may also process data in the USA; this is based on the EU-US Data Privacy Framework and standard contractual clauses.

If you pay with Apple Pay or Google Pay, Apple (Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland) or Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) also process your data in accordance with their own privacy policies. For Shop Pay, see section 21.

8.2 Klarna

If you choose a Klarna payment method, we transmit your contact details (name, address, e-mail address, telephone number if applicable), the order details (items, amount, order number) and device and connection data to Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden. To check the selected payment method, in particular for purchases on invoice or in instalments, Klarna may carry out an identity and credit check and obtain information from credit agencies for this purpose. Klarna is itself responsible for this check and the further processing. You can find details in Klarna’s privacy notice.

8.3 PayPal

If you choose PayPal, you will be redirected to PayPal. The provider is PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg. We transmit your name, address, e-mail address, amount, currency, order number and the items ordered. PayPal is itself responsible for processing the payment and may carry out a credit check, for example for “Pay Later”. PayPal may also process data outside the EU. You can find details in PayPal’s privacy statement.

8.4 Fraud prevention

To protect us and our customers from payment fraud, Shopify and the payment service providers automatically assess orders for fraud risks. For example, IP address, device information, delivery and billing address and payment data are compared. We then review conspicuous orders ourselves before making a decision. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in preventing fraud and payment defaults.

9. Shipping and logistics

To deliver your order, we pass on your name, your delivery address, the order number and the parcel weight to the carrier. This is usually DHL Paket GmbH, Sträßchensweg 10, 53113 Bonn, Germany (DHL Group). For shipments abroad, DHL may hand over the parcel to partner companies in the destination country for delivery, which receive the delivery data for this purpose. The legal basis is Art. 6(1)(b) GDPR.

We only pass on your e-mail address or telephone number to the carrier insofar as this is necessary for delivery – for example for shipments to Switzerland or the United Kingdom for customs clearance and delivery notification – or insofar as you have consented to this. For deliveries to Switzerland and the United Kingdom, we also transmit the information required for the customs declaration (contents, value of goods, tariff number and country of origin); the competent customs authorities also receive this information (Art. 6(1)(b) and (c) GDPR). There are adequacy decisions of the EU Commission for Switzerland and the United Kingdom.

Insofar as logistics or delivery partners store, pack or ship goods or process returns on our behalf, they receive the necessary data (name, delivery address, order number, items ordered) as our processors.

10. Order tracking, returns and withdrawal function

We operate our own application for the pages Track your order, Start a return and Withdraw from contract. It runs on the Cloudflare Workers platform of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, which acts as our processor. Cloudflare processes requests in the nearest data centre of its global network, i.e. possibly also outside the EU; this is based on the EU-US Data Privacy Framework and standard contractual clauses.

  • Track your order: You enter your order number and your e-mail address. The application compares this information with the order at Shopify and queries the shipment status from DHL using the tracking number. The legal basis is Art. 6(1)(b) GDPR.
  • Start a return: We process your order number, your e-mail address, the selected items and quantities, the reason for the return, your optional description, your choice between refund and exchange including the requested size, the selected shipping method and the processing status of the return. If you book a DHL return label, we transmit your name and your sender address to DHL to create the label. The legal basis is Art. 6(1)(b) GDPR.
  • Withdraw from contract: We process your name, your order number, your e-mail address, where applicable the information about which items you are withdrawing from, and the date and time of receipt. We send you the legally required acknowledgement of receipt by e-mail, file a copy in our mailbox and note the withdrawal on your order in Shopify. The legal basis is Art. 6(1)(c) GDPR in conjunction with Section 356a BGB and Art. 6(1)(b) GDPR.

We send e-mails from this application (e.g. return label, return confirmation and acknowledgement of receipt of your withdrawal) via Brevo. The provider is Sendinblue SAS, 17 rue de Salneuve, 75017 Paris, France, which acts as our processor. To protect against misuse, we limit the number of requests; for this purpose, your IP address is processed briefly (Art. 6(1)(f) GDPR). We retain data on returns and withdrawals as long as it is needed for processing and as proof, and otherwise in accordance with the statutory retention periods (section 24).

11. Back-in-stock notification

If a size is sold out, you can be notified by e-mail as soon as it is available again. For this purpose, we store your e-mail address, the desired item and size, your language and the time of sign-up. As soon as the item is available again, we send you exactly one e-mail and then delete your address, but no later than twelve months after sign-up. You do not receive a newsletter as a result. We store the waiting list in our application at Cloudflare (section 10) and send the e-mail via Brevo.

The legal basis is your consent, which you give by submitting the form (Art. 6(1)(a) GDPR). You can withdraw it at any time, for example by e-mail to us; we will then delete your address immediately.

12. Contact form, e-mail, telephone and AI-assisted support tool

12.1 Your enquiry

If you contact us via the contact form or by e-mail, we process your name, your e-mail address, the subject, your order number if applicable and the content of your message in order to answer your enquiry. The contact form is transmitted via Shopify. The legal basis is Art. 6(1)(b) GDPR if your enquiry concerns an order or a contract, and otherwise Art. 6(1)(f) GDPR; our legitimate interest lies in answering your enquiry.

Our e-mail mailboxes are operated on our behalf by STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. We delete enquiries once they have been dealt with and no retention obligations prevent this. We retain messages concerning a contract as business letters for up to six years.

12.2 Our support tool

We process enquiries in our own support tool, which runs on a server of STRATO GmbH in Germany. It assigns your message to the relevant order and shows us the associated order data from Shopify so that we can answer you quickly and completely.

To prepare replies, the tool transmits the content of your message and the associated order information (e.g. order number, items, shipping status) to Anthropic. The provider is Anthropic PBC, 548 Market Street, PMB 90375, San Francisco, CA 94104, USA. Its AI model Claude creates a suggested reply from this. Every reply is checked by a member of staff, adjusted if necessary and sent by them; no automated decision-making takes place. Anthropic acts as our processor, does not use the transmitted data to train its AI models under its contractual terms and generally deletes it within 30 days, unless longer storage is required by law or becomes necessary to investigate violations of its usage policies. The transfer to the USA is based on the standard contractual clauses of the EU Commission (Art. 46(2)(c) GDPR).

The legal basis for using the support tool is Art. 6(1)(f) GDPR; our legitimate interest lies in answering customer enquiries quickly, completely and consistently. You can object to this at any time: simply write in your message that your enquiry should be processed without AI support – we will then answer it without the AI model. Please do not send us particularly sensitive data (e.g. health data) if it is not necessary for your enquiry.

13. Customer reviews

13.1 Invitation to review

About seven days after your order has been delivered, we ask you by e-mail to review the items you purchased. We send a maximum of one invitation per order and, where applicable, one reminder. Orders that you have withdrawn from or returned do not receive an invitation. For this purpose, we process your name, your e-mail address, your order number, the items ordered, your language and the shipping and delivery date. We query the delivery date from DHL using the tracking number. We also store when you first open the personal review link; we do not evaluate whether you open the e-mail itself.

The invitation is advertising for our own goods. We send it to you if you have consented to receiving advertising e-mails (Art. 6(1)(a) GDPR, Section 7(2) No. 2 of the German Act against Unfair Competition, UWG) or – without consent – as an existing customer to the e-mail address you gave us when purchasing, provided that we informed you of your right to object when you placed your order (Section 7(3) UWG). In this case, the legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in receiving feedback on our products and helping other customers with their choice. You can object to the use of your e-mail address for review invitations at any time without incurring any costs other than the transmission costs at the basic rates – via the unsubscribe link in every invitation or by e-mail to info@wstnd.com. We will then add your e-mail address to a blocklist so that you do not receive any further invitations.

13.2 Submission and publication of your review

If you write a review, we store the star rating, the title, the text, your information on the fit, the display name you have chosen, the date, the reference to the item and to your order, and the “verified purchase” note. The star rating, the title, the text, the fit information, the display name, the date and the “verified purchase” note are published on the product page. Your e-mail address and your order data are never published. The reviews, together with the display name, may also appear in the structured data of the product page that search engines such as Google read (e.g. for stars in search results). The legal basis for publication is your consent, which you give by submitting the review (Art. 6(1)(a) GDPR). You can request at any time that we delete your review.

13.3 Technology and service providers

We operate the review tool ourselves at bewertungen.wstnd.com on a server of STRATO GmbH in Germany (processor). When accessed, the server processes technically necessary connection data such as IP address and time in order to deliver the page and protect it against misuse (Art. 6(1)(f) GDPR). We also store published reviews in our shop at Shopify. We send the e-mails via Brevo (Sendinblue SAS, France, section 10).

13.4 Imported reviews

We have transferred reviews that customers previously submitted via the review service Judge.me to our own system, with display name, star rating, title, text, date, customer photos where applicable and verification status, so that they can continue to be displayed. We store customer photos in our shop at Shopify for this purpose. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in preserving the published reviews when changing service. If you would like us to delete an imported review or photo, an e-mail to us is sufficient.

13.5 Storage period

We anonymise data on review invitations after twelve months. Published reviews remain stored until you request their deletion. We keep entries on the blocklist permanently so that we can continue to respect your objection in future (Art. 6(1)(c) and (f) GDPR).

14. Newsletter

With our newsletter, we inform you about new drops, restocks, promotions and offers. We only need your e-mail address to sign up. After signing up, we send you an e-mail in which you confirm your subscription (double opt-in); only then will you receive the newsletter. We store your e-mail address, the time of sign-up and confirmation and the source of the sign-up (e.g. newsletter form or checkout) in order to be able to prove your consent.

We send the newsletter via Shopify’s e-mail function (Shopify Messaging), which works on our behalf. It is evaluated whether a newsletter has been opened and which links have been clicked. This evaluation helps us to improve the content; it is part of the newsletter you have agreed to. You will also only receive reminder e-mails about an uncompleted purchase with this consent.

The legal basis is your consent (Art. 6(1)(a) GDPR, Section 7(2) No. 2 UWG). You can unsubscribe from the newsletter at any time – via the unsubscribe link in every issue or by e-mail to us. After unsubscribing, we remove your address from the mailing list. We retain proof of your previous consent for up to three years in order to be able to defend ourselves against any claims (Art. 6(1)(f) GDPR).

15. Web push notifications

If you agree in your browser, we send you push notifications, e.g. about new drops, restocks, price changes or a cart you have not completed. For this we use the PushOwl service by Brevo (Sendinblue SAS, 17 rue de Salneuve, 75017 Paris, France). An identifier of your push subscription, browser and device information, your language, your approximate location (country) and – insofar as necessary for the notifications – your activity in the shop, such as items viewed or items in the cart, are processed. The notifications are delivered via the push service of your browser manufacturer (e.g. Google for Chrome, Apple for Safari, Mozilla for Firefox, Microsoft for Edge); data may also be processed in the USA in this context.

The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). You can withdraw it at any time by deactivating notifications for wstnd.com in your browser or device settings. We store the data until you withdraw your consent or your push subscription becomes invalid.

16. Analytics and marketing (only with consent)

We only use the following services if you have consented to the respective category via our cookie banner (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). Without consent, they are not loaded. You can withdraw your consent at any time via “Cookie settings” in the footer.

16.1 Shopify analytics (analytics)

Shopify records for us how our shop is used: for example pages visited, time spent, search terms, cart and checkout activity, the source of the visit (e.g. search engine or campaign), device type, browser and approximate location. Cookies with pseudonymous identifiers are set for this purpose. We receive aggregated evaluations and use them to improve the range, presentation and usability of our shop.

16.2 Google Analytics 4 (analytics)

We use Google Analytics 4, a web analytics service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). Using cookies and a pseudonymous identifier, Google Analytics records how you use our shop, e.g. pages visited, items viewed, cart and purchase events with order value, source of the visit, device, browser and approximate location. IP addresses are not stored in Google Analytics 4. The usage data is deleted after 14 months at the latest. We use Google’s consent mode, which transmits your choice in the cookie banner to Google so that Google’s services act accordingly.

16.3 Google Ads (marketing)

With Google Ads, we measure the success of our ads (conversion tracking) and can show you ads on Google services and partner websites that match your visits to our shop (remarketing). For this purpose, cookies or identifiers are set and information about ad clicks, visits, items viewed and purchases with order value is transmitted to Google. For more accurate measurement, your e-mail address may also be transmitted in encrypted (hashed) form (enhanced conversions).

Google is certified under the EU-US Data Privacy Framework for Google Analytics and Google Ads and additionally uses standard contractual clauses. You can find more information in Google’s privacy policy.

16.4 Meta Pixel and Conversions API (marketing)

We use the Meta Pixel and the Conversions API of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland (“Meta”). This allows us to transmit information about your activity in our shop – such as pages visited, items viewed, items in the cart, checkouts started and purchases with order value – together with browser and device information, your IP address and cookie identifiers to Meta. Via the Conversions API, we also send these events directly from our shop to Meta; your e-mail address, telephone number, name and address may also be transmitted in encrypted (hashed) form so that Meta can match the events to user accounts on Facebook and Instagram. We use this to measure the success of our ads and to show you relevant ads on Facebook and Instagram.

We are jointly responsible with Meta for the collection and transmission of this data to Meta (Art. 26 GDPR). The details are set out in Meta’s Controller Addendum; under it, Meta in particular assumes responsibility for fulfilling data subjects’ rights for the jointly controlled processing. Meta is solely responsible for further processing. Meta is certified under the EU-US Data Privacy Framework. You can find more information in Meta’s privacy policy.

16.5 TikTok Pixel and Events API (marketing)

We use the TikTok Pixel and the Events API of TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland (“TikTok”). This allows us to transmit information about your activity in our shop – such as items viewed, items in the cart and purchases with order value – together with browser and device information, your IP address, cookie identifiers and, where applicable, your e-mail address or telephone number in encrypted (hashed) form to TikTok. We use this to measure the success of our ads on TikTok and to show you relevant ads there.

We are jointly responsible with TikTok for the collection and transmission of this data (Art. 26 GDPR); the details are set out in TikTok’s joint controller terms. TikTok is solely responsible for further processing. TikTok states that data may also be processed in or accessed from countries outside the EU, such as the USA, Singapore, Malaysia or China. For some of these countries, there is no adequacy decision of the EU Commission; TikTok bases transfers on standard contractual clauses. You can find more information in TikTok’s privacy policy.

17. Protection against spam and abuse

To protect our forms (e.g. contact form, newsletter sign-up and customer account) against spam and automated attacks, Shopify may use the hCaptcha service of Intuition Machines, Inc., USA. hCaptcha uses technical characteristics such as IP address, browser and device information and your interaction with the page to check whether an input comes from a human, and may store or read information on your device for this purpose. The legal bases are Art. 6(1)(f) GDPR and Section 25(2) No. 2 TDDDG; our legitimate interest lies in protecting our shop against misuse. hCaptcha is used by Shopify as a sub-processor; the transfer to the USA is secured by the contractual agreements between Shopify and the provider.

18. Job applications

You can send us applications by e-mail to jobs@wstnd.com. We process the data you send us – such as contact details, CV, references and cover letter – exclusively to decide on your application. The legal basis is Art. 6(1)(b) GDPR (initiation of an employment relationship). If you voluntarily provide special categories of personal data (e.g. information about a severe disability), we process it on the basis of Art. 9(2)(b) GDPR.

If an employment relationship is established, we transfer the data to the personnel file. Otherwise, we delete your application documents six months after the end of the procedure so that we can defend ourselves against any claims, for example under the German General Equal Treatment Act (Art. 6(1)(f) GDPR). If you would like us to keep your documents for future positions, we will ask for your consent. Please note that e-mails are transmitted in encrypted form but are not end-to-end encrypted.

19. Partner, press and cooperation enquiries

If you contact us about a partnership or cooperation (partner@wstnd.com) or as a member of the press (presse@wstnd.com), we process your contact details and the content of your message in order to deal with your enquiry and initiate cooperation. The legal bases are Art. 6(1)(b) GDPR and otherwise Art. 6(1)(f) GDPR; our legitimate interest lies in communicating with business partners and the media. We delete the data once the enquiry has been dealt with and there are no retention obligations.

20. Our profiles on social networks

On our website, we link to our profiles on Instagram and TikTok. These are simple links: only when you click on them are you redirected to the respective platform, and only then does the provider receive data from you. The sharing function on our product pages also consists of simple links without embedded content from the platforms.

When you visit our profiles, the operators of the platforms process your data in accordance with their own privacy policies. We receive aggregated statistics from Meta (Instagram) and TikTok on the use of our profiles, such as reach and interactions, without being able to identify individual persons. We are jointly responsible with Meta for creating the statistics on our Instagram profile (Art. 26 GDPR); the details are set out in the Page Insights Controller Addendum. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in communicating with our customers and presenting our brand. You can most effectively assert your rights directly with the platforms, as only they have access to the user data; we will be happy to support you.

21. Shopify as an independent controller (Shop Pay, Shop app)

For certain features, Shopify processes personal data not on our behalf but under its own responsibility. This concerns in particular Shop Pay and signing in with Shop, the Shop app as well as cross-merchant fraud prevention and the improvement of Shopify’s services. If you use Shop Pay, Shopify stores your contact, delivery and payment details in your Shop account so that you can pay more quickly in all shops that offer Shop Pay. Shopify’s Consumer Privacy Policy applies to this. You can exercise your rights vis-à-vis Shopify via Shopify’s privacy portal.

22. Recipients at a glance

Your data is received – in each case only to the extent described above – by the following recipients:

  • Processors: Shopify (shop system, customer account, newsletter), Cloudflare (application for order tracking, returns, withdrawal and waiting list), Brevo (e-mail delivery, web push), STRATO (e-mail mailboxes, support tool, review tool), Xentral (inventory management and invoices), Anthropic (suggested replies in support) and, where applicable, logistics and delivery partners. We have concluded contracts under Art. 28 GDPR with all processors.
  • Independent controllers: carriers (DHL and its partners in the destination country), payment service providers (Stripe, Klarna, PayPal, Apple, Google), Shopify for Shop Pay and the Shop app, customs authorities for deliveries to Switzerland and the United Kingdom, our tax advisor and authorities and courts insofar as we are legally obliged to do so.
  • Joint controllers: Meta and TikTok for the collection and transmission of data via pixels and interfaces (only with your consent) and Meta for the statistics on our Instagram profile.
  • Only with your consent: Google (Analytics and Ads), Meta and TikTok.

We do not sell your personal data.

23. Transfers to third countries

Some of the recipients mentioned process data outside the European Union or the European Economic Area, in particular in the USA. We only transfer data to such third countries if the statutory requirements of Art. 44 et seq. GDPR are met:

  • Adequacy decision: The EU Commission has determined an adequate level of data protection for Canada, Switzerland and the United Kingdom. For the USA, this applies to companies certified under the EU-US Data Privacy Framework (adequacy decision of 10 July 2023), such as Google, Meta, Cloudflare and Shopify.
  • Standard contractual clauses: Otherwise – for example with Anthropic and TikTok – transfers are based on the standard contractual clauses of the EU Commission (Art. 46(2)(c) GDPR), supplemented by additional safeguards where necessary. You can request a copy from us.

Despite these safeguards, it cannot be ruled out that authorities in third countries access data and that you do not have the same legal remedies against this as in the EU.

24. Storage period

We only store personal data for as long as is necessary for the respective purpose or as required by statutory retention obligations. After that, we delete it or restrict it until the retention period has expired. In detail:

  • Invoices and accounting records (e.g. invoices, credit notes, records of returns): eight years (Section 147 of the German Fiscal Code, Section 257 of the German Commercial Code).
  • Commercial and business letters (e.g. e-mails about orders, declarations of withdrawal): six years.
  • Books of account and records: ten years.
  • The periods begin at the end of the calendar year in which the documents were created.
  • Customer account: until you request deletion.
  • Contact enquiries: until they have been dealt with, unless there is a retention obligation.
  • Back-in-stock notification: until the notification is sent, for a maximum of twelve months.
  • Review invitations: anonymisation after twelve months; published reviews until deletion; blocklist permanently.
  • Newsletter: until you unsubscribe; proof of consent for up to three years afterwards.
  • Web push: until consent is withdrawn.
  • Cookie consent: up to twelve months.
  • Google Analytics: a maximum of 14 months.
  • Suggested replies at Anthropic: generally a maximum of 30 days.
  • Job applications: six months after the end of the procedure.

In individual cases, longer storage may be necessary to establish, exercise or defend legal claims.

25. Obligation to provide data and automated decision-making

For an order, we need the information marked as mandatory in the checkout; without it, we cannot conclude or perform the contract. All other information is voluntary. There is no legal obligation to provide us with data.

We do not engage in exclusively automated decision-making, including profiling, within the meaning of Art. 22 GDPR. Payment service providers such as Klarna or PayPal may carry out their own automated checks, for example of creditworthiness, for certain payment methods (section 8); you can obtain information on this and on your rights from the respective provider.

26. Your rights

You have the following rights vis-à-vis us with regard to your personal data:

  • Access to the data we process and a copy of this data (Art. 15 GDPR)
  • Rectification of inaccurate data or completion of incomplete data (Art. 16 GDPR)
  • Erasure of your data, insofar as no statutory retention obligation or other reason prevents this (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability, i.e. receiving your data in a structured, commonly used and machine-readable format (Art. 20 GDPR)
  • Withdrawal of consent given, with effect for the future (Art. 7(3) GDPR)
  • Objection to processing (Art. 21 GDPR, see below)

To exercise your rights, an informal message to info@wstnd.com is sufficient. Exercising your rights is free of charge. We will answer your request without undue delay, at the latest within one month. To prevent misuse, we may ask you to prove your identity, for example by sending a message from the e-mail address you used for your order.

Right to object under Art. 21 GDPR

If we process your data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you have the right to object to this processing at any time on grounds relating to your particular situation. We will then no longer process your data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

If we process your data for direct marketing purposes – including review invitations – you can object at any time without giving reasons. We will then no longer use your data for these purposes.

Right to lodge a complaint: You have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, your place of work or the place of the alleged infringement (Art. 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, www.ldi.nrw.de. However, we would be pleased if you contact us first with any questions or complaints.

27. Data security

We protect your data by means of technical and organisational measures that are appropriate to the state of the art and the risk of the processing – for example through encrypted transmission, access restrictions on a need-to-know basis, two-factor authentication where available, and the careful selection and contractual obligation of our service providers. No one can guarantee complete protection against all risks when transmitting data over the internet; please therefore use the most secure channels possible for transmitting particularly confidential information.

28. Children and young people

Our offer is aimed at adults. Persons under the age of 16 may not transmit personal data to us or give consent without the consent of their parents or legal guardians. If we learn that we have received such data without the necessary consent, we will delete it. Parents and legal guardians can contact us at any time for this purpose.

29. Changes to this privacy policy

We adapt this privacy policy if our data processing, the services we use or the legal situation change. The version published on this page applies; you can find the date of the last change at the top. In the event of material changes that require consent, we will obtain it again.