Privacy Policy
Protecting your personal data matters to us. Below we inform you about the type, scope and purpose of processing personal data within our online services and related activities.
1.Controller
2.Overview of processing
We generally process our users' personal data only to the extent necessary to provide a functional website and our content and services. This includes in particular:
- Master data (e.g. names, addresses)
- Contact data (e.g. e-mail, phone numbers)
- Contract and order data (e.g. submitted cards, orders, status)
- Payment data (e.g. invoices, payment history)
- Usage and meta/communication data (e.g. IP addresses, access times)
3.Legal bases
We process personal data on the basis of the GDPR. The relevant grounds are in particular consent (Art. 6(1)(a)), performance of a contract and pre-contractual requests (Art. 6(1)(b)), compliance with legal obligations (Art. 6(1)(c)) and our legitimate interests (Art. 6(1)(f)).
4.Hosting & server log files
When you access our website, your browser automatically transmits information to our server, which is temporarily stored in log files (e.g. IP address, date and time of the request, file accessed, browser type). This serves to ensure trouble-free operation and the security of our systems (Art. 6(1)(f) GDPR).
5.Order processing & grading service
To process your order (receipt, examination, grading, sealing and return of your cards), we process the master, contract and payment data required for this purpose. Processing is carried out to perform the contract (Art. 6(1)(b) GDPR). Statutory retention obligations remain unaffected.
6.Customer account & portal
When you create a customer account, we process the data you provide to enable you to manage your orders, status updates and invoices. You can have your account deleted at any time.
7.Payment service providers
To process payments, we use external payment service providers, in particular Stripe (Stripe Payments Europe, Ltd., Ireland) and PayPal (PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg). The payment data entered is processed exclusively by the respective payment service provider; we ourselves do not store complete payment instrument data. The privacy notices of the respective provider apply in addition.
8.Contacting us
When you contact us (e.g. by e-mail or phone), your details are stored to process the request and in case of follow-up questions (Art. 6(1)(b) or (f) GDPR).
9.E-mail marketing & newsletter
Where you have consented or where legally permitted, we use your e-mail address to inform you about our own offers, promotions and news regarding our grading service.
10.Cookies
Our website uses technically necessary cookies to ensure operation (e.g. cart, login, language setting). Non-essential cookies and analytics services (see the “Consent management” and “Web analytics with Google Analytics” sections) are only loaded after your active consent via our cookie banner. You can withdraw or adjust your consent at any time with effect for the future and restrict or prevent the storage of cookies in your browser settings.
11.Storage period
We store personal data only as long as necessary for the respective purposes or as required by statutory retention periods (in particular under commercial and tax law). The data is then deleted or blocked.
12.Disclosure of data
Your data is only transferred to third parties if this is necessary to perform the contract (e.g. to shipping providers such as DHL or to payment service providers), you have expressly consented, or we are legally obliged to do so. Your contact data is not passed on for third-party advertising purposes.
13.Your rights
Under the GDPR you have the following rights: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). You can withdraw any consent given at any time with effect for the future.
14.Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, place of work or the place of the alleged infringement.
15.Data security
We take appropriate technical and organisational measures to protect your data against loss, manipulation and unauthorised access. Our website is transmitted via an encrypted SSL/TLS connection.
16.Consent management (cookie banner)
To manage consent for non-essential cookies and services, we use a consent management tool (Complianz). It stores your cookie consent so that your choice is taken into account on future visits. The legal basis is compliance with a legal obligation and our legitimate interest in legally compliant consent management (Art. 6(1)(c) and (f) GDPR).
17.Web analytics with Google Analytics
Where you have consented, we use Google Analytics, a web analytics service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). Google Analytics uses cookies to analyse the use of our website (e.g. pages visited, time spent, approximate location via the truncated IP address). This information is generally transmitted to and stored on Google servers; a transfer to the USA may occur. The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time via the cookie settings with effect for the future. Further information can be found in Google’s privacy policy.
This privacy policy is updated as needed to reflect changes in our processing or the legal situation.