Privacy policy

The data controller is:

DriveDressy GmbH, Karl-Schmid-Straße 11, 81829 Munich, Germany, Email: info@drivedressy.com

We appreciate your interest in our online store. Protecting your privacy is very important to us. Below, we provide detailed information about how we handle your data.

1. Access Data and Hosting

You can visit our website without providing any personal information. Each time you access a webpage, the web server automatically saves a so-called server log file that contains, for example, the name of the requested file, your IP address, the date and time of the request, the amount of data transferred, and the requesting provider (access data), and documents the request.

This access data is analyzed solely for the purpose of ensuring the smooth operation of the website and improving our services. In accordance with Article 6(1)(f) of the GDPR, this serves to protect our legitimate interests—which, following a balancing of interests, are deemed to prevail—in the proper presentation of our services. All access data is deleted no later than seven days after the end of your visit to the website.

Hosting services provided by a third-party provider
As part of processing carried out on our behalf, a third-party provider provides us with website hosting and display services. All data collected through the use of this website or via the forms provided in the online store, as described below, is processed on its servers. Processing on other servers takes place only within the scope described here.

This service provider is located within a country of Europa or the European Economic Area.

2. Collection and use of data for contract processing, establishing contact, and opening a customer account

We collect personal data when you voluntarily provide it to us as part of your order or when you contact us (e.g., via the contact form, seat form check form, or email). Required fields are marked as such because, in these cases, we absolutely need the data to process the contract or your inquiry, and you cannot submit the order or inquiry without providing this information. The data collected is indicated on the respective input forms.

We use the data you provide in accordance with Article 6(1)(b) of the GDPR to fulfill our contractual obligations and process your inquiries. If you have given your consent for this purpose in accordance with Article 6(1)(a) of the GDPR by choosing to open a customer account, we will use your data for the purpose of opening that account.

Once the contract has been fully fulfilled or your customer account has been deleted, your data will be restricted from further processing and deleted after the retention periods required by tax and commercial law have expired, unless you have expressly consented to the continued use of your data or we reserve the right to use your data beyond these periods in a manner permitted by law, about which we will inform you in this statement. You may delete your customer account at any time by either sending a message using the contact information provided below or by using the function provided for this purpose in your customer account.

3. Data Sharing

To fulfill the contract in accordance with Article 6(1)(b) of the GDPR, we share your data with the shipping company responsible for delivery, to the extent necessary to deliver the ordered goods. Depending on which payment service provider you select during the ordering process, we will transfer the payment data collected for this purpose to the financial institution responsible for processing the payment and, if applicable, to payment service providers commissioned by us or to the selected payment service. In some cases, the selected payment service providers also collect this data themselves if you create an account with them. In this case, you must log in to the payment service provider using your login credentials during the ordering process. In this regard, the privacy policy of the respective payment service provider applies.

Sharing of data with shipping service providers
If you have given us your express consent to do so during or after placing your order, we will share your email address and phone number with the selected shipping provider in accordance with Article 6(1)(a) of the GDPR so that the provider can contact you prior to delivery to notify you of the shipment or coordinate delivery details.

You may revoke your consent at any time by sending a message to the contact information provided below or by contacting the shipping service provider directly at the contact address listed. Upon revocation, we will delete the data you provided for this purpose, unless you have expressly consented to further use of your data or we reserve the right to use your data for other purposes that are permitted by law and about which we inform you in this statement.
Deutsche Post AG, 20 Charles-de-Gaulle-Str., 53113 Bonn, Germany, Email: impressum.paket@dhl.com

4. Email newsletter

Email marketing with newsletter sign-up
When you subscribe to our newsletter, we use the data required for this purpose or the data you have provided separately to send you our email newsletter on a regular basis, based on your consent in accordance with Article 6(1)(a) of the GDPR.

You can unsubscribe from the newsletter at any time by either sending a message using the contact information provided below or by clicking the link provided in the newsletter. Once you unsubscribe, we will remove your email address from the mailing list, unless you have expressly consented to the continued use of your data or we reserve the right to use your data for other purposes that are permitted by law and about which we inform you in this statement.

The newsletter is sent by a service provider acting on our behalf, to whom we provide your email address for this purpose.

Newsletter distribution via Klaviyo

This website uses Klaviyo’s services to send newsletters. The provider is Klaviyo, Inc., 125 Summer St, Floor 6, Boston, MA 02110, USA. Klaviyo is a service that allows, among other things, the sending of newsletters to be organized and analyzed. If you enter data for the purpose of subscribing to the newsletter (e.g., email address), this data is stored on Klaviyo’s servers in the United States.

Klaviyo has mechanisms in place to ensure an adequate level of data protection in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

We use Klaviyo to analyze our newsletter campaigns. When you open an email sent via Klaviyo, a file contained in the email (known as a web beacon) connects to Klaviyo’s servers in the United States. This allows us to determine whether a newsletter message has been opened and, if so, which links were clicked. In addition, technical information is collected (e.g., time of access, IP address, browser type, and operating system). This information cannot be linked to the specific newsletter recipient. It is used exclusively for the statistical analysis of newsletter campaigns. The results of these analyses can be used to better tailor future newsletters to the interests of the recipients.

If you do not wish to have your data analyzed by Klaviyo, you can unsubscribe from the newsletter. We provide a link for this purpose in every newsletter message. Click here to unsubscribe directly: http://manage.kmail-lists.com/subscriptions/unsubscribe?cy=VXmNm5

Data processing is based on your consent (Art. 6(1)(a) of the GDPR). You may withdraw this consent at any time by unsubscribing from the newsletter unsubscribe. The lawfulness of data processing operations that have already taken place remains unaffected by the withdrawal.

The data you have provided to us for the purpose of subscribing to our newsletter will be stored by us until you unsubscribe from the newsletter and will be deleted from both our servers and Klaviyo’s servers after you unsubscribe. Data stored by us for other purposes (e.g., email addresses for the members’ area) remains unaffected by this.

For more information, please refer to Klaviyo’s Privacy Policy at: https://www.klaviyo.com/privacy.

5. Cookies and Web Analytics

We use cookies on various pages to enhance your experience on our website, enable certain features, display relevant products, and conduct market research. This serves to protect our legitimate interests—which, following a balancing of interests, take precedence—in optimizing the presentation of our offerings, in accordance with Article 6(1)(f) of the GDPR.

Cookies are small text files that are stored on your computer and saved by your browser. Cookies do not cause any damage to your computer and do not contain viruses. Cookies are used to make our website more user-friendly, effective, and secure. Some cookies contain a so-called cookie ID. A cookie ID is a unique identifier for the respective cookie. The identifier consists of a string of characters that allows websites and servers to associate the specific web browser in which the cookie was stored. This enables the visited websites and servers to distinguish the individual browser of the data subject from other web browsers that contain different cookies. The respective browser can thus be recognized and identified via the unique cookie ID.

Some of the cookies we use are deleted at the end of the browser session, i.e., when you close your browser (so-called session cookies). Other cookies remain on your device and allow us to recognize your browser the next time you visit (persistent cookies). You can find the storage duration in the overview of your web browser’s cookie settings. You can configure your browser to notify you when cookies are set and decide individually whether to accept them, or to block the acceptance of cookies in specific cases or generally. Additionally, you can select the option to automatically delete cookies when you close your browser. Each browser differs in how it manages cookie settings. This is described in the help menu of each browser, which explains how you can change your cookie settings. You can find these for the respective browsers under the following links:

Internet Explorer™
Safari™
Chrome™
Firefox™
Opera™

Please note that rejecting or blocking cookies may affect the functionality of our website.

Use of Google (Universal) Analytics for Web Analytics
If you have given your consent in accordance with Article 6(1)(a) of the GDPR, this website uses Google (Universal) Analytics for the purpose of web analytics. The web analytics service is provided by Google Ireland Limited, a company incorporated and operating under Irish law, with its registered office at Gordon House, Barrow Street, Dublin 4, Ireland. (www.google.de). Google (Universal) Analytics uses methods that enable an analysis of your use of the website, such as cookies. The information automatically collected about your use of this website is generally transmitted to a Google server in the United States and stored there. By activating IP anonymization on this website, the IP address is truncated within the member states of the European Union or in other signatory states to the Agreement on the European Economic Area prior to transmission. Only in exceptional cases is the full IP address transmitted to a Google server in the United States and truncated there. The anonymized IP address transmitted by your browser as part of Google Analytics is generally not merged with other Google data. Once the purpose has been fulfilled and we have ceased using Google Analytics, the data collected in this context will be deleted.

To the extent that information is transferred to and stored on Google’s servers in the United States, the U.S. company Google LLC is certified under the EU-U.S. Privacy Shield. A current certificate canherecan be viewed. Based on this agreement between the United States and the European Commission, the latter has determined that companies certified under the Privacy Shield provide an adequate level of data protection.

You can withdraw your consent at any time with future effect by downloading and installing the browser plugin available at the following link:https://tools.google.com/dlpage/gaoptout?hl=de. This prevents the collection of data generated by the cookie and related to your use of the website (including your IP address), as well as the processing of this data by Google.

Use of Microsoft Clarity

We use Microsoft Clarity web analytics software for our website. The service provider is the American company Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA.

Microsoft Clarity is a tool that allows companies to assess the usability of their websites. To do this, Microsoft Clarity records selected user sessions. Companies can then analyze these sessions. The tool provides metrics that highlight potential usability issues.

Microsoft processes your data in the United States, among other places. Clarity and Microsoft are active participants in the EU-U.S. Data Privacy Framework, which governs the proper and secure transfer of personal data belonging to EU citizens to the United States. For more information, please visit: https://commission.europa.eu/document/download/77035a27-0a13-4d39-8b12-00630d3a6a94_en?filename=EU-US%20Data%20protection%20Umbrella%20Agreement.pdf&prefLang=de

In addition, Microsoft uses what are known as standard contractual clauses (Article 45(2) and (3) of the GDPR). Standard contractual clauses are model clauses provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through the EU-US Data Privacy Framework and the standard contractual clauses, Microsoft commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the US. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding standard contractual clauses here, among other places: https://eur-lex.europa.eu/legal-content/DE/TXT/PDF/?uri=CELEX:32021D0914

For more information about Microsoft's standard contractual clauses, visit: https://learn.microsoft.com/de-de/compliance/regulatory/offering-eu-model-clauses.

For more information about the data processed when using Microsoft, please see the Privacy Statement at: https://privacy.microsoft.com/de-de/privacystatement.

Use of Zigpoll

We use the Shopify app "Zigpoll" to create post-purchase or abandoned cart surveys. We then use these surveys to determine the platform where our customers first became aware of us and to track the overall distribution of sales across the respective platforms. Revenue distribution is always collected in aggregated form and is therefore anonymized. The app collects personal data such as the device’s IP address, names, email addresses, and sales details, provided the website visitor participates in the surveys. However, with the exception of sales details, we do not process any data. Furthermore, the data is used exclusively for the specified purpose and is not shared with third parties. We take appropriate technical and organizational measures to ensure the security and confidentiality of the data. Personal data can be requested at any time by sending an email to info@drivedressy.com be removed.

6. Online Marketing

Google Ads Remarketing
We use Google Ads to advertise this website in Google search results and on third-party websites. To this end, when you visit our website, Google sets a so-called remarketing cookie, which automatically enables interest-based advertising using a pseudonymous cookie ID and based on the pages you have visited. This serves to safeguard our legitimate interests, which prevail following a balancing of interests, in the optimal marketing of our website in accordance with Art. 6(1)(f) of the GDPR. Once the purpose has been fulfilled and we have ceased using Google Ads remarketing, the data collected in this context will be deleted.

Any further data processing will only take place if you have consented to Google linking your web and app browsing history to your Google Account and using information from your Google Account to personalize the ads you see on the web. In this case, if you are logged into Google while visiting our website, Google will use your data in conjunction with Google Analytics data to create and define audience lists for cross-device remarketing. To do this, Google will temporarily link your personal data with Google Analytics data to form audiences.

Google Ads is a service provided by Google Ireland Limited, a company incorporated and operating under Irish law, with its registered office at Gordon House, Barrow Street, Dublin 4, Ireland (www.google.de). To the extent that information is transferred to and stored on Google’s servers in the United States, the U.S. company Google LLC is certified under the EU-U.S. Privacy Shield. A current certificate can beherecan be viewed. Based on this agreement between the United States and the European Commission, the latter has determined that companies certified under the Privacy Shield provide an adequate level of data protection.

You can disable the remarketing cookie via thisLinkdisable. You can alsoDigital Advertising AllianceLearn about the use of cookies and adjust your settings.

Google Maps
This website uses Google Maps to display geographic information. Google Maps is a service provided by Google Ireland Limited, a company incorporated and operating under Irish law, with its registered office at Gordon House, Barrow Street, Dublin 4, Ireland (www.google.de). This serves to protect our legitimate interests—which, following a balancing of interests, have been determined to prevail—in optimizing the presentation of our offerings and ensuring easy access to our locations, in accordance with Article 6(1)(f) of the GDPR.
When using Google Maps, Google transmits and processes data regarding website visitors’ use of Maps features, which may include, in particular, IP addresses and location data. We have no control over this data processing.
To the extent that information is transferred to and stored on Google’s servers in the United States, the U.S. company Google LLC is certified under the EU-U.S. Privacy Shield. A current certificate canherecan be viewed. Based on this agreement between the United States and the European Commission, the latter has determined that companies certified under the Privacy Shield provide an adequate level of data protection.
To disable the Google Maps service and prevent data from being sent to Google, you must disable JavaScript in your browser. In this case, Google Maps will not work or will only work with limited functionality.
For more information about Google's data processing practices, please see the privacy policy atGoogle. The Terms of Use forGoogle Mapsinclude detailed information about the map service.
Data processing is carried out on the basis of an agreement between joint controllers pursuant to Article 26 of the GDPR, which youherecan view.

Google reCAPTCHA
To protect against misuse of our web forms and to prevent spam, we use the Google reCAPTCHA service in connection with some forms on this website. Google reCAPTCHA is a service provided by Google Ireland Limited, a company incorporated and operating under Irish law, with its registered office at Gordon House, Barrow Street, Dublin 4, Ireland. (www.google.de). By verifying manual input, this service prevents automated software (so-called bots) from carrying out abusive activities on the website. In accordance with Article 6(1)(f) of the GDPR, this serves to safeguard our legitimate interests—which prevail following a balancing of interests—in protecting our website from abuse and ensuring the smooth operation of our online presence.

Google reCAPTCHA uses methods—such as cookies—to analyze your use of the website as part of the verification process, via a code embedded in the website known as JavaScript. The information automatically collected about your use of this website, including your IP address, is generally transmitted to a Google server in the United States and stored there. In addition, other cookies stored in your browser by Google services are evaluated by Google reCAPTCHA.
No personal data is read or saved from the input fields of the respective form.

To the extent that information is transferred to and stored on Google’s servers in the United States, the U.S. company Google LLC is certified under the EU-U.S. Privacy Shield. A current certificate canherecan be viewed. Based on this agreement between the United States and the European Commission, the latter has determined that companies certified under the Privacy Shield provide an adequate level of data protection.

You can prevent Google from collecting the data generated by JavaScript or cookies and related to your use of the website (including your IP address), as well as from processing this data, by disabling JavaScript or cookies in your browser settings. Please note that this may limit the functionality of our website for your use.

For more information about Google's privacy policy, please visithere.

7. Social Media

Our online presence on Facebook, YouTube, Instagram, Pinterest, Xing, and LinkedIn

Our presence on social media and other platforms is designed to facilitate better, more active communication with our customers and prospective clients. We use these channels to provide information about our products and current promotions.

When you visit our social media pages, your data may be automatically collected and stored for market research and advertising purposes. This data is used to create so-called user profiles using pseudonyms. These profiles may be used, for example, to display advertisements on and off the platforms that are presumed to match your interests. Cookies are generally used on your device for this purpose. These cookies store visitor behavior and user interests. In accordance with Art. 6(1)(f) of the GDPR, this serves to safeguard our legitimate interests—which prevail following a balancing of interests—in the optimized presentation of our offerings and effective communication with customers and prospective customers. If you are asked by the respective social media platform operators for consent to data processing, e.g., via a checkbox, the legal basis for the data processing is Article 6(1)(a) of the GDPR.

Insofar as the aforementioned social media platforms are headquartered in the United States, the following applies: The European Commission has issued an adequacy decision for the United States. This decision is based on the EU-U.S. Privacy Shield. A current certificate for the respective company canherecan be viewed.

For detailed information on how providers process and use data on their websites, as well as contact information, your rights in this regard, and settings to protect your privacy—including opt-out options—please refer to the providers’ privacy policies linked below. If you still need assistance with this, please feel free to contact us.

Facebook:https://www.facebook.com/about/privacy/
Data processing is carried out on the basis of an agreement between joint controllers pursuant to Article 26 of the GDPR, which youherecan view.
For more information on data processing when visiting a Facebook fan page (information on Insights data), please seehere.

Google/YouTube:https://policies.google.com/privacy?hl=de

Instagram:https://help.instagram.com/519522125107875

Pinterest:https://about.pinterest.com/de/privacy-policy

LinkedIn:https://www.linkedin.com/legal/privacy-policy

Xing:https://privacy.xing.com/de/datenschutzerklaerung

Right to opt out:

Facebook:https://www.facebook.com/settings?tab=ads

Google/YouTube:https://adssettings.google.com/authenticated?hl=de

Instagram:https://help.instagram.com/519522125107875

Pinterest:https://www.pinterest.de/settings

LinkedIn:https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out

Xing:https://privacy.xing.com/de/datenschutzerklaerung/welche-rechte-koennen-sie-geltend-machen/widerspruchsrecht

8. Sending review reminders via email

If you have given us your explicit consent in accordance with Article 6(1)(a) of the GDPR during or after placing your order, we will use your email address to send you a reminder to leave a review of your order via the review system we use. You may withdraw this consent at any time by contacting us using the contact information provided below.

9. How to Contact Us and Your Rights

As a data subject, you have the following rights:

  • pursuant to Article 15 of the GDPR, the right to request information about the personal data we process about you, to the extent specified therein;
  • pursuant to Article 16 of the GDPR, the right to request, without undue delay, the rectification of inaccurate personal data or the completion of incomplete personal data that we have stored;
  • pursuant to Article 17 of the GDPR, the right to request the erasure of your personal data stored by us, unless further processing
    • to exercise the right to freedom of expression and information;
    • to comply with a legal obligation;
    • for reasons of public interest or
    • is necessary for the assertion, exercise, or defense of legal claims;
  • pursuant to Article 18 of the GDPR, the right to request the restriction of the processing of your personal data, provided that
    • you dispute the accuracy of the data;
    • the processing is unlawful, but you object to its erasure;
    • we no longer need the data, but you need it to assert, exercise, or defend legal claims, or
    • you have objected to the processing pursuant to Article 21 of the GDPR;
  • pursuant to Article 20 of the GDPR, the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, or to request that it be transmitted to another controller;
  • In accordance with Article 77 of the GDPR, you have the right to lodge a complaint with a supervisory authority. As a general rule, you may contact the supervisory authority in your usual place of residence, your place of work, or where our company is headquartered.

If you have any questions regarding the collection, processing, or use of your personal data, or if you wish to request information, correct, restrict, or delete data, or withdraw your consent or object to a specific use of your data, please contact us directly using the contact information provided in our legal notice.


Right to object
To the extent that we process personal data as described above to protect our legitimate interests, which have been determined to prevail following a balancing of interests, you may object to such processing with effect for the future. If the processing is carried out for direct marketing purposes, you may exercise this right at any time as described above. To the extent that the processing is carried out for other purposes, you have a right to object only if there are grounds arising from your particular situation.

Once you have exercised your right to object, we will no longer process your personal data for these purposes, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or if the processing is necessary for the establishment, exercise, or defense of legal claims

This does not apply if the processing is carried out for direct marketing purposes. In that case, we will no longer process your personal data for that purpose.