Currency
1. Scope
This Privacy Policy explains the personal information used in connection with visiting https://includo.shop, placing orders and contacting our store. It covers the store's handling of customer information and describes choices and rights available to individuals in Germany and the European Economic Area.
For questions about our handling of personal information, or to exercise privacy rights, email info@includo.shop. References to includo.shop identify the store. Shopify and certain payment or other service providers may also process information under their own notices and responsibilities, depending on the service used.
2. Information You Provide
When you order, we process information such as your name, billing and shipping addresses, email address, selected goods, purchase amounts, order references and payment status. A telephone number may be processed where supplied for delivery or a feature requiring it. Payment details are handled through the payment services used at checkout; do not send full card details by email.
When you contact us, we process the message content, contact details and information you provide about the purchase or issue. This can include photographs of a product, return requests and delivery information. Please avoid supplying health information, identity documents or other sensitive data unless reasonably necessary for a specific request.
If an account feature is used, account identification, authentication information, purchase history and the preferences stored through that feature may also be processed. Information you choose to submit through a review or other public feature may become visible to other visitors as indicated when submitting it.
3. Technical and Usage Information
Operating an online storefront involves technical information such as IP addresses, browser and device characteristics, language settings, approximate location derived from IP data, page requests, timestamps and diagnostic or security records. This information can help deliver pages correctly, protect the checkout and investigate errors.
Cookies and similar technologies can store or access information on your device. The purposes and legal requirements for those technologies are distinct from the subsequent use of any personal data. Optional analytics and advertising technologies, if enabled, require the appropriate consent before storage or access where the law requires it.
4. Information Received from Providers
We may receive payment confirmations, fraud-risk indicators, shipment updates, delivery confirmations and return information from providers assisting with transactions and fulfilment. The information received depends on the payment and delivery services involved in your order.
We use that information to connect a payment or shipment to the relevant purchase, answer enquiries and resolve problems. It is not a general permission to obtain unrelated information about you from other sources.
5. Purposes and Legal Bases
Order administration, processing the purchase, organising delivery and handling requests necessary for the contract are based on Article 6(1)(b) GDPR. Information needed before a purchase in response to your request may also be processed under that basis.
Accounting, tax obligations, legally required records and compliance with enforceable legal duties are based on Article 6(1)(c) GDPR. Where a claim or security issue requires processing outside a contractual or legal obligation, Article 6(1)(f) may apply to a proportionate legitimate interest, such as preventing fraud, maintaining reliable services or defending legal claims. We assess your interests and rights against that purpose.
Optional marketing and optional analytics or advertising processing are based on consent under Article 6(1)(a) where required. Consent is not inferred merely from visiting the website, placing an order or accepting terms of sale. Withdrawal of consent does not affect processing that was lawful before withdrawal.
6. Required and Optional Information
Certain information is necessary to complete a purchase, including an appropriate delivery address, contact information and payment authorisation. If information needed to perform the purchase is not provided, we may be unable to accept or fulfil the order.
Optional account features, marketing subscriptions and consent to nonessential technologies are separate choices. Refusing optional marketing does not prevent you from receiving the service messages needed for an existing order or obtaining customer support.
7. Shopify
Our store uses Shopify for its ecommerce infrastructure. Shopify processes information needed to host the storefront, support checkout and provide associated services. For certain activities it acts as a service provider processing information for merchants; for other activities, including certain consumer services, it may act under its own responsibilities.
If you choose a Shopify consumer service such as Shop or Shop Pay where offered, additional processing may take place under the notice applicable to that service. Shopify's privacy information is available at https://www.shopify.com/legal/privacy and its merchant data-processing terms at https://www.shopify.com/legal/dpa. These notices supplement the store's notice for the relevant services.
8. Other Recipients
Information may be disclosed to payment providers for payment authorisation and reimbursement; carriers and fulfilment providers for delivery and returns; and technical providers for hosting, communications and operational support. Only information appropriate to the particular task should be shared.
Professional advisers, accounting providers and competent public authorities may receive information where necessary for legal obligations, advice, auditing or legal claims. A service provider acting on our behalf must be subject to an appropriate agreement and confidentiality requirements where the GDPR requires them.
If optional analytics or advertising integrations are used, relevant providers and their purposes must be described through the applicable consent information before consent is requested. This conditional description does not establish that a particular advertising provider or app is installed.
9. Cookies and Similar Technologies
Strictly necessary technologies can support the basket, checkout, security and a consent choice you have made. Under Section 25 TDDDG, the necessity exception is limited to the legally specified circumstances, including a service you expressly requested. A technology is not necessary simply because it is commercially useful to the store.
Other device storage or access, including optional analytics and advertising technologies, requires informed consent where applicable. The consent interface should identify purposes and providers, provide relevant duration information and allow you to reject optional categories. Relevant information about actual technologies belongs in that interface and the associated disclosures.
You can change choices through the site's cookie preferences where available and can also contact info@includo.shop. Browser controls can delete or block cookies, although blocking necessary technologies may affect the basket or checkout. Deleting cookies may also remove a stored consent preference and cause a consent request to appear again.
10. Marketing Choices
If you subscribe to marketing offered by the store, we use the contact details and preferences needed for that subscription. You may unsubscribe through the link in a marketing email or by emailing info@includo.shop. We keep service communications, such as order confirmations and refund messages, separate from optional marketing.
If personalised advertising is used, it may involve information about visits, interactions and purchases being processed for the disclosed advertising purposes after any required consent. You can refuse or withdraw that consent. An objection to direct marketing also applies to profiling related to that marketing.
11. International Processing
Shopify and other relevant providers can operate systems outside Germany and outside the EEA. Where personal data is transferred to a country without an applicable adequacy decision, an appropriate transfer mechanism, such as European Commission standard contractual clauses and any necessary supplementary measures, is required.
An adequacy decision or certification framework can be relied on only where it applies to the actual recipient and transfer. We do not assume every provider or country is automatically covered. You may request information about the safeguards relevant to your data, including how to obtain a copy, by emailing info@includo.shop. Confidential or unrelated third-party information may be redacted where appropriate.
12. Retention
We retain information for the purpose that justified collecting it and for legally required periods. Transaction records may need to be kept for accounting or tax duties after an order is complete. Enquiry and complaint information may remain necessary while an issue or legal claim is unresolved.
Account information is retained while the account is used and thereafter only to the extent justified by other purposes. Marketing subscription information is retained until withdrawal or until it is otherwise no longer needed. A minimal suppression record may remain necessary to respect an opt-out.
Technical records should be retained only for the period needed for operational reliability, security and investigation. The duration of a particular cookie or similar identifier is disclosed in the relevant consent information. Where a fixed period cannot be stated generally, retention is determined by applicable legal duties, the purpose, the status of the matter and whether less identifying information is sufficient.
13. Security
Appropriate technical and organisational measures are required to protect personal information against unauthorised disclosure, alteration, loss and access. Security depends on the systems used and includes limiting access to people and providers who need the information for their tasks.
No online service can promise absolute security. Please protect account credentials and contact us if you suspect an unauthorised purchase or data exposure. We assess personal-data breaches and make legally required notifications where the applicable conditions are met.
14. Your Rights
Subject to the GDPR's conditions, you may request access to your personal data and information about processing, correction of inaccurate information, erasure, restriction and portability. Erasure is not absolute where information must be retained to comply with a legal duty or establish, exercise or defend legal claims.
You may object to processing based on legitimate interests for reasons related to your particular situation. We then assess whether legally sufficient grounds justify continuing the processing. You may object to direct marketing at any time, including associated profiling.
You may withdraw consent at any time without affecting earlier lawful processing. You also have protection against decisions based solely on automated processing that have legal or similarly significant effects, subject to the GDPR's exceptions and safeguards.
15. Requests and Complaints
Send requests to info@includo.shop. We may ask for proportionate information to verify identity, particularly if responding would disclose personal information or change an account. We do not routinely require excessive identity documents.
We ordinarily respond within one month. Where permitted because of complexity or number of requests, the period may be extended by up to two further months, with notice and reasons within the initial month. Requests are generally free; the GDPR permits a reasonable fee or refusal in limited circumstances, such as manifestly unfounded or excessive requests.
You may complain to a data-protection supervisory authority, especially in the EEA country of your habitual residence, work or the alleged infringement. You do not need to contact us first. Germany's competent authority depends on the relevant responsibilities and location; authority information can be found through https://www.datenschutzkonferenz-online.de/datenschutzaufsichtsbehoerden.html.
16. Automated Checks
Payment and security providers may use automated risk checks. Their particular role and processes depend on the service used. If a transaction is declined or challenged and you wish to question the outcome, contact us and, where appropriate, the provider involved. Mandatory GDPR safeguards apply to any solely automated decision with the relevant legal or similarly significant effects.
17. Children and External Links
The store's purchasing facilities are intended for people with legal capacity to enter into the purchase or acting with appropriate authorisation. We do not seek children's personal data for optional marketing. If you believe a child has supplied information that should not have been processed, contact us.
External links take you to services governed by their own notices. Review those notices before submitting information. This does not remove our responsibility for disclosures or integrations that we control.
18. Updates and Contact
We may update this policy to explain changes to actual processing or legal requirements. A new notice does not itself authorise a new purpose or substitute for consent. Material changes are communicated as required.
Thanks for subscribing!
This email has been registered!