Privacy policy
Privacy Policy
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
GETPOPSTRAPS™
Mr. Omid Efazat
Gartenfelder Straße 52 | 13599 Berlin, Germany
E-Mail: help@getpopstraps.shop
2. General Information on Data Processing
(1) As a matter of principle, we process personal data of our users only to the extent necessary to provide a functional website along with our content and services. The processing of our users' personal data takes place regularly only with the user's consent or on one of the legal bases set out in Article 6(1) GDPR.
(2) Insofar as we obtain the data subject's consent for processing operations involving personal data, Article 6(1)(a) GDPR serves as the legal basis.
(3) For the processing of personal data necessary for the performance of a contract, Article 6(1)(b) GDPR serves as the legal basis.
(4) Insofar as processing of personal data is necessary to comply with a legal obligation, Article 6(1)(c) GDPR serves as the legal basis.
(5) Should processing be necessary to safeguard a legitimate interest of our company or a third party, and should the interests, fundamental rights, and fundamental freedoms of the data subject not override the former interest, Article 6(1)(f) GDPR serves as the legal basis.
3. Provision of the Website and Creation of Log Files
(1) Each time our website is accessed, our system automatically collects data and information from the computer system of the accessing device. The following data is collected:
- IP address of the user (anonymized)
- Date and time of access
- Content of the request (specific page)
- Access status / HTTP status code
- Amount of data transferred in each case
- Website from which the request originates
- Browser, operating system, and its interface
- Language and version of the browser software
(2) Storage in log files is carried out to ensure the functionality of the website. The data also serves to optimize the website and to ensure the security of our information technology systems. No evaluation of the data for marketing purposes takes place in this context.
(3) The legal basis for the temporary storage of the data and the log files is Article 6(1)(f) GDPR.
4. Use of Cookies
(1) Our website uses cookies. Cookies are text files that are stored in or by the internet browser on the user's computer system.
(2) We use the following types of cookies:
- Technically necessary cookies: These are essential for the operation of the website (e.g. shopping cart, login status). The legal basis is Article 6(1)(f) GDPR.
- Functional and performance cookies: These are used to improve usability and to analyze the performance of the website. The legal basis is Article 6(1)(a) GDPR (consent).
- Marketing cookies: These are used to display relevant advertising to you. The legal basis is Article 6(1)(a) GDPR (consent).
(3) You can prevent the storage of cookies by adjusting your browser settings accordingly; however, we point out that in this case you may not be able to use all functions of this website to their full extent.
5. Use of Shopify (Hosting Platform)
(1) Our online shop is hosted on the e-commerce platform Shopify, operated by Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland.
(2) When you visit our online shop, personal data is transmitted to and processed by Shopify, in particular:
- IP address
- Date and time of access
- Order data (name, address, email, telephone number, order contents)
- Payment information (see separate information on payment service providers)
(3) Shopify processes this data as a processor within the meaning of Article 28 GDPR. We have concluded a corresponding data processing agreement with Shopify.
(4) Data may be transferred to third countries (in particular the USA, where the parent company Shopify Inc. is based). Shopify has committed to complying with the EU Commission's Standard Contractual Clauses.
(5) Further information can be found in Shopify's privacy policy: https://www.shopify.com/legal/privacy
6. Payment Service Providers
(1) For orders placed in our online shop, the data required for payment processing is passed on to the respective payment service provider. We use:
- PayPal (PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg) — https://www.paypal.com/de/legalhub/privacy-full
- Klarna (Klarna Bank AB, Sveavägen 46, 11134 Stockholm, Sweden) — https://www.klarna.com/de/datenschutzbestimmungen/
- Shopify Payments (Shopify International Ltd., Dublin, Ireland) — https://www.shopify.com/legal/privacy
- Apple Pay (Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland)
- Google Pay (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland)
(2) Which data is specifically transmitted depends on the chosen payment method. The legal basis is Article 6(1)(b) GDPR (performance of a contract).
7. Shipping Service Providers
(1) To deliver your order, we transmit your required data (name, delivery address, and, where applicable, telephone number and email address for shipment notification) to:
- DHL (Deutsche Post AG, Charles-de-Gaulle-Straße 20, 53113 Bonn, Germany) — https://www.dhl.de/datenschutz
- For deliveries to the USA: additional international shipping partners where applicable (information provided in the respective shipping confirmation)
(2) The legal basis is Article 6(1)(b) GDPR (performance of a contract).
8. Contact Form and Email Contact
(1) A contact form is available on our website, which can be used to get in touch electronically. If you use this option, the data entered in the input mask is transmitted to us and stored.
(2) The following data is also stored at the time the message is sent:
- Name
- Email address
- Content of the message
- Date and time
(3) The legal basis for processing is Article 6(1)(f) GDPR. If the email contact is aimed at concluding a contract, Article 6(1)(b) GDPR additionally serves as the legal basis.
9. Newsletter (optional, where activated)
If you have subscribed to our newsletter, we process your email address and, where applicable, other voluntarily provided data for the purpose of sending the newsletter. The legal basis is your consent pursuant to Article 6(1)(a) GDPR. You can withdraw your consent at any time, for example via the unsubscribe link in every newsletter or by email to help@getpopstraps.shop.
10. Your Rights as a Data Subject
You have the right at any time to:
- Obtain information about the data stored about you (Article 15 GDPR)
- Request the rectification of inaccurate data (Article 16 GDPR)
- Request the erasure of your data (Article 17 GDPR)
- Request the restriction of processing (Article 18 GDPR)
- Object to processing (Article 21 GDPR)
- Request data portability (Article 20 GDPR)
- Lodge a complaint with a supervisory authority, in particular in the Member State of your residence, place of work, or the place of the alleged infringement (Article 77 GDPR)
To exercise your rights, contact us at help@getpopstraps.shop.
11. Competent Supervisory Authority
Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit) Friedrichstr. 219, 10969 Berlin, Germany Email: mailbox@datenschutz-berlin.de Web: https://www.datenschutz-berlin.de
12. Storage Period
Personal data is stored for as long as is necessary to fulfil the respective purpose or as required by statutory retention periods (e.g. 10 years for invoices pursuant to Section 147 of the German Fiscal Code (§ 147 AO)).
13. Currency of this Privacy Policy
This privacy policy may be amended at any time. The current version is available on our website.
Last updated: 17 May 2026