Privacy Policy (GDPR compliant)

Last updated: February 2026

This Privacy Policy explains how HAUS.JACOB (hereinafter 'we', 'us', or 'our') collects, uses, discloses, and protects your personal data when you visit or make a purchase from https://hausjacob.com (the 'Site'). It is drafted in accordance with the General Data Protection Regulation (EU) 2016/679 ('GDPR') and the German Federal Data Protection Act (BDSG).

1. Controller

HAUS.JACOB GmbH
Wolfratshauser Str. 52
81379 Munich
Germany

Email: support@hausjacob.com

2. Categories of Personal Data We Process

We may process the following categories of personal data:

When browsing the Site

  • IP address

  • Device and browser type

  • Date and time of access

  • Referring URL

  • Pages visited
    (Server log files)

When placing an order

  • Name

  • Billing and shipping address

  • Email address

  • Phone number (if provided)

  • Ordered products

  • Payment method

  • Transaction ID

When contacting us

  • Name

  • Email address

  • Message content

Newsletter (if subscribed)

  • Email address

  • Consent timestamp

Cookies & similar technologies

  • Unique cookie ID

  • Consent preferences

  • Usage behaviour (if analytics enabled)

Payment details (e.g. card numbers, PayPal credentials) are processed exclusively by the respective payment provider and are not stored by us.

3. Purposes and Legal Bases (Art. 6 GDPR)

We process personal data for the following purposes:

Display and secure the website

→ Art. 6 (1)(f) GDPR (legitimate interest)

Process orders and payments

→ Art. 6 (1)(b) GDPR (contract performance)

Shipping and logistics

→ Art. 6 (1)(b) GDPR

Respond to enquiries

→ Art. 6 (1)(b) or (f) GDPR

Send marketing newsletters (if applicable)

→ Art. 6 (1)(a) GDPR (consent)

Comply with tax and commercial law obligations

→ Art. 6 (1)(c) GDPR

4. Hosting & E-Commerce Platform

Our website is hosted and operated via Shopify Inc., 151 O’Connor Street, Ottawa, Ontario K2P 2L8, Canada.

Shopify provides the online e-commerce platform that allows us to sell our products.

Data may be stored through Shopify’s data storage, databases and applications. Shopify processes data on secure servers.

Canada benefits from an adequacy decision by the European Commission pursuant to Art. 45 GDPR.

Further information: https://www.shopify.com/legal/privacy

5. Payment Providers

Payments are processed via Shopify Payments and its integrated payment providers, which may include:

  • Stripe Payments Europe Ltd.

  • PayPal (Europe) S.à r.l. et Cie, S.C.A.

  • Klarna Bank AB

  • Apple Pay

The respective payment provider processes payment data independently as data controller.

6. Shipping Providers

For delivery of goods, we share necessary data (name, address, email if required) with:

  • DHL Paket GmbH

  • Freight or specialized art courier services (where applicable)

Processing is based on Art. 6 (1)(b) GDPR.

7. Analytics & Cookies

We may use cookies to ensure website functionality.

Non-essential cookies (e.g. analytics or marketing cookies) are only set based on user consent (Art. 6 (1)(a) GDPR).

You may withdraw consent at any time via the cookie banner.

8. International Data Transfers

Where data is transferred outside the European Economic Area (EEA), we rely on:

  • An adequacy decision (e.g. Canada), or

  • EU Standard Contractual Clauses pursuant to Art. 46 GDPR.

9. Retention Periods

We store personal data only as long as necessary:

  • Server logs: 14 days

  • Order and accounting data: 10 years (statutory retention)

  • Contact enquiries: 12 months

  • Newsletter data: until withdrawal of consent

10. Your Rights

Under GDPR you have the right to:

  • Access your personal data (Art. 15)

  • Rectification (Art. 16)

  • Erasure (Art. 17)

  • Restriction of processing (Art. 18)

  • Data portability (Art. 20)

  • Object to processing (Art. 21)

  • Withdraw consent at any time (Art. 7 (3))

To exercise your rights, contact: support@hausjacob.com

You also have the right to lodge a complaint with a supervisory authority, for example the Bavarian Data Protection Authority (BayLDA).

11. Security Measures

We implement appropriate technical and organisational measures, including:

  • HTTPS / TLS encryption

  • Access controls

  • Regular backups

  • Restricted data access

12. Automated Decision-Making

No automated decision-making or profiling with legal or significant effects takes place.

13. Changes to This Policy

We may update this Privacy Policy where necessary. The version valid at the time of your visit applies.