BitLabelz

Privacy Policy

Thank you very much for your interest in our shop. Data protection is a high priority for us. You can generally use our website without providing any personal data. If you want to place an order, create a customer account or write to us, we process the personal data needed for this. Where processing is necessary and there is no legal basis for it, we ask for your consent.

Personal data, such as your name, address or email address, is always processed in accordance with the General Data Protection Regulation (GDPR) and the data protection provisions applicable in Germany. This privacy policy informs you about the nature, scope and purpose of the personal data we process and about the rights you have.

We have implemented numerous technical and organisational measures to protect the personal data processed through this website as completely as possible. All pages are transmitted in encrypted form (HTTPS). Nevertheless, data transmission over the internet can in principle have security gaps, so absolute protection cannot be guaranteed. You are therefore free to send us personal data by other means, for example by post.

This is a translation for your convenience. In case of doubt, the German version applies.

1. Definitions

This privacy policy is based on the terms used in the General Data Protection Regulation (GDPR). It is meant to be easy to read and understand for everyone. We therefore explain the most important terms first:

  • Personal data means any information relating to an identified or identifiable natural person (the "data subject"), for example name, address, email address, identification number or online identifier.
  • Data subject means any identified or identifiable natural person whose personal data is processed by the controller.
  • Processing means any operation performed on personal data, such as collection, recording, storage, alteration, retrieval, use, disclosure by transmission, erasure or destruction.
  • Restriction of processing means marking stored personal data with the aim of limiting its processing in the future.
  • Profiling means any automated processing of personal data to evaluate or predict personal aspects of a natural person.
  • Pseudonymisation means processing personal data in such a way that it can no longer be attributed to a specific person without additional information that is kept separately.
  • Controller means the natural or legal person which, alone or jointly with others, determines the purposes and means of the processing of personal data.
  • Processor means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
  • Recipient means a natural or legal person, public authority, agency or other body to which personal data is disclosed, whether a third party or not.
  • Third party means any person or body other than the data subject, the controller, the processor and the persons who, under their direct authority, are authorised to process the data.
  • Consent means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which they signify agreement to the processing of personal data relating to them.

2. Name and address of the controller

The controller within the meaning of the GDPR is:

BitCases & BitLabelz
Owner Heidi Püttner
Egerstraße 14
95126 Foerbau
Germany
Email: info@bitlabelz.com
Website: bitlabelz.com

We have not appointed a data protection officer, as we are not legally required to do so. For any questions about data protection, please contact us at the email address above.

3. Hosting

Our shop runs on a server of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The server is located in Germany. Hetzner processes all data arising from visiting and using the shop (see sections 5 to 9) exclusively on our behalf and according to our instructions. We have concluded a data processing agreement with Hetzner in accordance with Art. 28 GDPR. The legal basis is our legitimate interest in a secure and reliable operation of the shop (Art. 6(1)(f) GDPR) and, where orders are concerned, Art. 6(1)(b) GDPR.

We load all content of the shop, including fonts and images, from our own server. We do not embed content of other providers that would transfer data to them when a page is loaded.

4. Cookies

Our shop uses cookies. Cookies are small text files stored on your device by your web browser. We use only technically necessary cookies without which the shop would not work. We do not use cookies for analytics, advertising or marketing, and we do not use any services that track your behaviour across websites. Consent is not required for these cookies (Section 25(2) no. 2 of the German TDDDG). The legal basis for the related processing is Art. 6(1)(b) and (f) GDPR.

  • BLSESS: session. Keeps you signed in, keeps your entries in the checkout and protects forms against misuse. Deleted when you close the browser.
  • BLKORB: shopping cart. Makes sure your cart is still there on your next visit. Valid for 60 days.
  • BLSPRACHE: last selected language (German or English). Valid for 1 year.
  • BLMERK: wishlist. Only set when you save an item with the heart without a customer account, and contains nothing but a random number we use to find your wishlist. Valid for 1 year. When you sign in, the wishlist moves to your account and the cookie is deleted. We keep the wishlist itself (which items) for up to 13 months.

You can prevent cookies from being set at any time in your browser settings and delete cookies that have already been set. Without cookies, however, the shopping cart, checkout and customer account cannot be used.

If you choose PayPal or a payment method via Stripe, you are taken to their payment page. There, these providers set their own cookies according to their own privacy policies (see section 11).

5. Server log files

Each time our website is accessed, the server automatically records general data and information and stores it in log files. This includes (1) browser type and version, (2) the operating system used, (3) the page from which you came to us (referrer), (4) the page accessed, (5) date and time of access, (6) the IP address and (7) the amount of data transferred and the status code.

We need this data to (1) deliver the content of our website correctly, (2) ensure the permanent functionality and security of our systems, (3) detect and fend off attacks (repeated attacks from one IP address are automatically blocked for a while) and (4) provide law enforcement authorities with the necessary information in the event of an attack. We do not draw any conclusions about you and do not combine the log files with other data. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the purposes mentioned.

The log files are automatically deleted after 14 days.

To protect sign in and forms against mass guessing, we also briefly count attempts per sender. For this we store only an irreversible hash of the IP address, which is deleted after 24 hours at the latest.

Visitor statistics

To see which pages and items are in demand, we count page views and visits ourselves, without cookies and without external services. A visit is the first page view on a given day. To recognise repeated page views on the same day, we create an irreversible hash from the IP address, the browser identifier and a random value that changes every day; the IP address itself is not stored for this. The random value is replaced daily and the hashes are deleted after two days at the latest. We only keep totals per day and page and the origin of visits as totals (for example search engine, social network, direct). This does not allow any conclusions about you. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is to shape our offer according to what our customers need.

6. Orders and customer account

When you order from us, we process the data you enter at checkout: name, delivery and, if applicable, billing address, email address, optionally phone number, company and a note on the order, as well as the items ordered, prices, the payment method chosen and the payment and shipping status. We use this data to accept, collect payment for and ship your order and to keep you informed about its status (order confirmation, payment received, shipping confirmation). The legal basis is Art. 6(1)(b) GDPR. Without this information we cannot conclude a contract with you.

Together with the order we store the IP address from which the order was placed, so that we can detect and investigate fraud and misuse (Art. 6(1)(f) GDPR). It is deleted after six months.

You can order as a guest or create a customer account. In the customer account we store your name, email address, an encrypted password, your addresses and your orders, so that you can view them at any time and order again more quickly (Art. 6(1)(b) GDPR). You can change your details in the account at any time and request deletion of your account by email. We keep orders and invoicing data even after the account has been deleted for as long as statutory retention periods apply (Art. 6(1)(c) GDPR in conjunction with Section 147 of the German Fiscal Code and Section 257 of the German Commercial Code, up to ten years).

For shipping, we pass your name and delivery address on to the shipping provider (see section 10), and for payment the necessary data to the payment provider you choose (see section 11).

Sign in with Google

Instead of using your email address and password, you can also register and sign in with your Google account. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. When you click "Sign in with Google", you are redirected to Google and sign in there. Google then sends us your name, your email address and an identification number of your Google account. We store this number in your customer account so that we can recognise you the next time you sign in. If a customer account already exists for your email address, it is linked to your Google account. We never receive your Google password, and we do not send Google any data about your orders. The legal basis is Art. 6(1)(b) GDPR (creating and using the customer account at your request). Signing in with Google is voluntary; you can always order without Google.

Google may also transfer data to Google LLC in the USA; Google LLC is certified under the EU US Data Privacy Framework. How Google processes your data is described in Google's privacy policy: policies.google.com/privacy. You can remove the connection between your Google account and our shop at any time at myaccount.google.com/connections.

7. Contact form and email

Due to legal requirements, our website contains information that allows you to contact us quickly by electronic means, including our email address and a contact form. If you write to us by email or through the contact form, we store the data you send (in the contact form: name, email address, optionally order number, and your message) solely to process and answer your request. We keep messages from the contact form and emails sent to us in our database so that we can see the course of a request in one place; messages from the contact form are additionally delivered to us by email. To prevent misuse, we also store the IP address. The data is not passed on to third parties.

If you write to us in a language other than German, we have your message translated into German automatically, and our reply into your language. For this, only the text of the message concerned is sent to the Google Cloud Translation service (Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland). Google processes the text as our processor solely for the translation and does not use it for its own purposes. Processing by Google LLC in the USA is possible; Google LLC is certified under the EU US Data Privacy Framework. The legal basis is Art. 6(1)(b) GDPR if your request relates to an order, otherwise Art. 6(1)(f) GDPR (our interest in understanding your request and answering it in your language).

The legal basis is Art. 6(1)(b) GDPR if your request relates to a contract or an order, otherwise Art. 6(1)(f) GDPR (our interest in answering requests). The IP address is deleted after six months, messages from the contact form and by email twelve months after the last message, unless they must be kept for an order.

8. Withdrawal through our form

You can withdraw from a contract using the "Vertrag widerrufen" (withdraw from contract) function on our website. In doing so, we process your name, your email address, the order number, the scope of the withdrawal, a reason you may give voluntarily, and the date, time and IP address of receipt. You immediately receive an acknowledgement of receipt by email. We need this data to process the withdrawal and to be able to prove it (Art. 6(1)(b) and (c) GDPR). The IP address is deleted after six months; otherwise the same retention periods apply as for orders.

9. Sending emails

Emails to you (such as order and shipping confirmations or answers to your requests) and your emails to us run through the mail server of our email provider ALL-INKL.COM Neue Medien Münnich, owner René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany. ALL-INKL processes the data on our behalf on servers in Germany; we have concluded a data processing agreement with ALL-INKL in accordance with Art. 28 GDPR. The legal basis is Art. 6(1)(b) and (f) GDPR.

Newsletter. If you subscribe to our newsletter, we will occasionally inform you by email about new items and offers. For this we only need your email address; we also store the language (German or English) in which you receive the newsletter. We use the double opt in procedure: after signing up you receive an email with a confirmation link, and we only send you the newsletter once you have confirmed. To be able to prove your consent, we store the time and IP address of the sign up and of the confirmation. If you ticked the newsletter box in your customer account in our previous shop, this consent remains valid. The legal basis is your consent (Art. 6(1)(a) GDPR), and our legitimate interest in being able to prove that consent (Art. 6(1)(f) GDPR). You can unsubscribe at any time using the link at the end of every newsletter email, in your customer account or with a short message to us. We delete unconfirmed sign ups after 30 days. After you unsubscribe, we keep your email address together with the time of unsubscribing for up to three years, in order to be able to prove the earlier consent and to make sure you do not receive any more newsletters. We do not track whether you open a newsletter or click on links in it. The newsletter is sent through ALL-INKL like all of our emails.

10. Shipping of goods

To deliver your order, we pass your name and delivery address on to the commissioned shipping provider: Deutsche Post AG or DHL Paket GmbH, Charles de Gaulle Straße 20, 53113 Bonn, Germany. The legal basis is Art. 6(1)(b) GDPR.

If your shipment has a tracking number, we query the delivery status from DHL to show it to you in your customer account. In doing so, we only transmit the tracking number.

11. Payment methods

Depending on the payment method you choose, we transmit the data required for payment to the respective payment provider. The legal basis is Art. 6(1)(b) GDPR. Some of the payment providers process your data as independent controllers according to their own privacy policies, for example for fraud prevention or to comply with legal obligations.

a) PayPal

If you choose "PayPal", you are redirected to the PayPal payment page. The operator is PayPal (Europe) S.à r.l. et Cie, S.C.A., 22 to 24 Boulevard Royal, L 2449 Luxembourg. PayPal is an online payment provider; payment is made through a PayPal account or, depending on what PayPal offers, by card or "Pay Later". We transmit the order number, the amount, the items ordered and the delivery address to PayPal. PayPal receives the data you enter at PayPal directly. The transmission serves payment processing and fraud prevention. PayPal may transmit data to credit agencies for identity and credit checks and may pass it on to affiliated companies and service providers where necessary to fulfil its contractual obligations. More information: PayPal privacy statement.

b) Stripe (card, Apple Pay, Google Pay, Klarna and more)

If you choose "Card, Klarna and more", you are redirected to the Stripe payment page. The operator is Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland. You enter your card details directly at Stripe; we never receive them. We transmit your email address, the order number, the amount and a description of the items ordered to Stripe. From Stripe we receive confirmation of the payment and the payment method used. Stripe may also transfer data to Stripe, Inc. in the USA; Stripe is certified under the EU US Data Privacy Framework, and standard contractual clauses of the EU Commission are in place as well. More information: Stripe privacy policy.

Through Stripe we offer, among others, the following payment methods. The respective providers receive the data required for payment from Stripe or directly from you:

  • Apple Pay: Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland (privacy).
  • Google Pay: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (privacy).
  • Klarna: Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden. Klarna allows, among other things, paying later, in instalments or immediately. If you choose Klarna, Stripe transmits the data required for this to Klarna, usually name, address, email address, phone number, IP address and details of the order and amount. Klarna checks your identity and creditworthiness; for this, Klarna may transmit data to credit agencies and calculate probability values for your payment behaviour (scoring). Klarna makes this decision as an independent controller, not us. More information: Klarna privacy notice.
  • iDEAL | Wero (Netherlands), Bancontact (Belgium), eps (Austria) and other payment methods that Stripe shows depending on your country: the payment is processed through your bank or the respective provider, which receives the data required for this.

c) Prepayment (bank transfer)

If you choose prepayment, you transfer the amount to our bank account. In doing so, we receive the usual transfer data from your bank (name, IBAN, amount, reference). We use this data to match the payment to your order.

12. Backups

To make sure that no orders or customer data are lost, we back up the database every night and the images once a week. The backups are stored on our server at Hetzner in Germany and are deleted automatically: database backups after 14 days, image backups after four weeks. Occasionally we store a copy on our own computer, which we treat just as confidentially. The legal basis is Art. 6(1)(f) GDPR (protection against data loss) and Art. 32 GDPR.

13. Links to social networks

On our website we link to our profile on Instagram. This is a simple link, not an embedded plugin: no data is transferred to Instagram when you visit our pages. Only when you click the link are you taken to Instagram (Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland), where the Instagram privacy policy applies.

14. Routine erasure and blocking of personal data

We process and store personal data only for as long as is necessary to achieve the respective purpose or as provided for by law. If the purpose no longer applies or a statutory retention period expires, the data is routinely blocked or erased in accordance with the law. The specific periods are stated in the individual sections above.

15. Rights of the data subject

You have the following rights. To exercise them, an informal message to info@bitlabelz.com or to our postal address is sufficient.

a) Right to confirmation and access (Art. 15 GDPR)

You have the right to obtain confirmation as to whether we process personal data concerning you and to receive information about this data and a copy free of charge. This includes in particular the purposes of processing, the categories of data, the recipients or categories of recipients (in particular in third countries), the planned storage period or the criteria for determining it, the existence of your rights to rectification, erasure, restriction and objection, the right to lodge a complaint with a supervisory authority, the source of the data if it was not collected from you, and the existence of automated decision making including profiling. If data is transferred to a third country, you can also request information about the appropriate safeguards.

b) Right to rectification (Art. 16 GDPR)

You have the right to have inaccurate personal data corrected without delay and incomplete personal data completed. You can change many details yourself in your customer account.

c) Right to erasure (Art. 17 GDPR)

You have the right to have your personal data erased without delay if one of the following applies and the processing is not necessary: the data is no longer needed for its purpose; you withdraw your consent and there is no other legal basis; you object and there are no overriding legitimate grounds; the data was processed unlawfully; erasure is required to comply with a legal obligation. Statutory retention obligations (for example for orders and invoices) remain unaffected; we block such data until the period expires.

d) Right to restriction of processing (Art. 18 GDPR)

You have the right to request restriction of processing if you contest the accuracy of the data (for the duration of the review), the processing is unlawful and you request restriction instead of erasure, we no longer need the data but you need it to establish, exercise or defend legal claims, or you have objected and it has not yet been determined whether our legitimate grounds override yours.

e) Right to data portability (Art. 20 GDPR)

You have the right to receive the data you have provided to us in a structured, commonly used and machine readable format and to transmit it to another controller or, where technically feasible, have it transmitted directly, provided the processing is based on consent or a contract and is carried out by automated means.

f) Right to object (Art. 21 GDPR)

You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on Art. 6(1)(e) or (f) GDPR. We will then no longer process the data unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims. We do not carry out direct marketing; if we did, you could object to it at any time without giving reasons.

g) Automated individual decisions including profiling (Art. 22 GDPR)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, unless the decision is necessary for entering into or performing a contract, is permitted by law or is based on your explicit consent. In these cases you have at least the right to human intervention, to express your point of view and to contest the decision.

h) Right to withdraw consent (Art. 7(3) GDPR)

You have the right to withdraw any consent given at any time with effect for the future. This does not affect the lawfulness of processing carried out before the withdrawal.

i) Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)

You have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, place of work or place of the alleged infringement. The authority responsible for us is the Bavarian State Office for Data Protection Supervision (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de.

16. Legal bases of processing

Art. 6(1)(a) GDPR is the legal basis for processing for which we obtain consent. If processing is necessary to perform a contract with you, for example to deliver goods, or to take steps prior to entering into a contract, for example for enquiries about our products, it is based on Art. 6(1)(b) GDPR. If we are subject to a legal obligation, for example tax retention obligations, processing is based on Art. 6(1)(c) GDPR. Processing not covered by any of these legal bases may be based on Art. 6(1)(f) GDPR if it is necessary to protect our legitimate interests or those of a third party and your interests, fundamental rights and freedoms do not override them.

17. Legitimate interests

Where processing is based on Art. 6(1)(f) GDPR, our legitimate interests are the secure, stable and economical operation of our shop, fending off attacks, fraud and misuse, protection against data loss, and answering enquiries.

18. Storage period

How long we store data is stated in the individual sections. Otherwise, the period depends on the statutory retention periods; after they expire, the data is routinely deleted unless it is still needed to perform or prepare a contract.

19. Obligation to provide data

Providing personal data is partly required by law (for example by tax regulations) or may result from contractual provisions (for example details of the contracting party). For an order we need the details marked as required at checkout; without them we cannot conclude the contract or deliver the goods. All other details are voluntary. We are happy to help if you have any questions about this.

20. Automated decision making

We ourselves do not use automated decision making or profiling. For the credit check by Klarna, see section 11 b.

21. Changes to this privacy policy

We update this privacy policy when the shop or the legal situation changes. The version published here applies.

Last updated: September 2026

This privacy policy was created with the privacy policy generator of DGD Deutsche Gesellschaft für Datenschutz GmbH, acting as external data protection officer in Nuremberg, in cooperation with the IT and data protection lawyer Christian Solmecke, and adapted by us to our shop.

0