Privacy Statement

27 July 2018
Privacy Statement

Privacy Statement

Thank you for your interest in our website. The protection of your privacy is very important to us. Below we inform you in detail about the handling of your data.

 

  • Access data and hosting
  • You can visit our website without providing any personal information. With every visit of the website, the web server automatically saves a so-called server log file which, for example, contains the name of the requested file, your IP address, date and time of the call, the amount of data transmitted and the requesting provider (access data) and documents the call.

These access data are evaluated exclusively for the purpose of ensuring trouble-free operation of the site and improving our services. This serves according to art. 6 para. 1 sentence 1 litf GDPR the protection of our legitimate interests in the proper presentation of our offer that are overriding in the process of balancing of interests. All access data will be deleted no later than seven days after the end of your visit to the site.

Third-party hosting services

Within the framework of processing on our behalf, third party providers provide us with hosting and presentation services for our websites. If a service provider is based in the USA, it is certified under the EU-US Privacy Shield. A current certificate can be viewed here. As a result of this agreement between the US and the European Commission, the latter has established an adequate level of data protection for companies certified under the Privacy Shield. Further, we have agreed the application of EU standard data protection clauses with other service providers based in a country outside the EU or the EEA in order to provide suitable guarantees pursuant to art. 46 para. 2 lit. c GDPR.

All data collected in the context of the use of these web pages or in forms provided for the purposes as described below are processed on the servers of the respective service provider. Processing on other servers only takes place as described within this privacy statement.

  • Data collection and use for the use of IBUYGOU
  • We collect personal data if you voluntarily provide it when contacting us (e.g. via contact form or e-mail). Mandatory fields are marked as such, since in these cases we require the data for processing your contact or opening of the customer account in accordance with art. 6 para. 1 sentence 1 lit. b GDPR and you cannot send the contact without this information. Which data is collected can be seen from the respective input forms. We use the data provided by you to process your enquiries.

We have engaged service providers for the technical processing of your inquiries on our behalf. These service providers are based in the USA / EUROPE and are certified under the EU-US Privacy Shield. As a result of this agreement between the US and the European Commission, the latter has established an adequate level of data protection for companies certified under the Privacy Shield.

After complete processing of the inquiry, your data will be restricted for further processing and deleted after expiry of the storage periods under tax and commercial law, unless you have expressly consented to further use of your data or we reserve the right to use data beyond this, which is permitted by law and about which we inform you in this declaration.

Live Chat Tool Userlike

If you use the live chat tool to make contact, the data you voluntarily enter there (name, e-mail address, message) will be stored on our behalf at our service provider Userlike on servers within Germany. They will be processed there for the purpose of answering the inquiry by us and subsequently deleted in accordance with art. 6 para. 1 sentence 1 lit. b GDPR.

Registration for IBUYGOU buyer protection

When subscribing for IBUYGOU buyer protection, we need your e-mail address, the total purchase price, the selected payment method, purchase order number, your customer number (if you have one) and the name of the online shop from which you ordered the product.

Your data will be used within the scope of contract processing in accordance with art. 6 para. 1 sentence 1 lit. b GDPR for the purpose of providing the IBUYGOU buyer protection to you.

Only in the event of a claim under the buyer protection we require additional information and personal data from you to review and process your claim for reimbursement. When registering a refund claim, your name, address, telephone number and bank account will be charged for the refund.

With the buyer protection you also get access to the IBUYGOU customer login (IBUYGOU). In the IBUYGOU customer login you can see your active and concluded buyer protection contracts, submit refund applications and submit or change ratings for your orders. Your e-mail address serves as identification and user name for access to IBUYGOU. You have the possibility to personalize your membership account by voluntarily entering further personal data such as your name, place of residence and/or a profile picture in the IBUYGOU customer login or when submitting a rating.

Your submitted ratings can then be displayed with these additional details, although some details to protect your privacy are always only displayed in abridged form. Similarly, a summary of all assessments submitted can then be publicly retrieved. Your email address will not be publicly displayed. You can change or remove your personal data at any time in IBUYGOU. You can also deactivate the public display of your profile there.

After complete processing of the contract or deactivation of your customer account, your data will be restricted for further processing and deleted after expiry of the storage periods under tax and commercial law, unless you have expressly consented to further use of your data or we reserve the right to use data beyond this, which is permitted by law and about which we inform you in this declaration. You can deactivate your customer account at any time and either by sending a message to the contact option described below or using the function provided for this purpose in the customer account.

Subscribing to rating reminder

If, during or after placing your order, you grant an express consent according to art. 6 par. 1 sentence 1 lit. a GDPR to receiving email reminders, your email address will be transferred to IBUYGOU for the purpose of sending you email reminders about rating your purchase order using the Trusted Shops customer rating service. If you subscribe to the automated rating reminder service, you will be automatically receiving email reminders about rating a transaction after every purchase from the IBUYGOU members. On your every visit, you will be recognised based on anonymised data. You may withdraw your consent to receiving email reminders at any time, with effect on your future orders.

If you submit an evaluation via the IBUYGOU evaluation system, we require your e-mail address within the framework of our user contract in accordance with art. 6 para. 1 sentence 1 lit. b GDPR in order to ensure the validity and trustworthiness of the evaluation. The e-mail address will be stored for this purpose together with the order number and the evaluation submitted. When you submit a product review, the URL of the product and the product image, the product name, the product SKU, GTIN and MPN, and the manufacturer are also saved.

In order to make the rating system secure, to prevent incorrect or falsified ratings and to ensure proper operation of the rating system, we also collect your IP address when you submit a rating. This serves to safeguard our legitimate interests in the prevention of misuse and the protection of our systems that are overriding in the process of balancing of interests in accordance with art. 6 para. 1 sentence 1 lit. f GDPR. The IP address is stored for a maximum of 7 days for the evaluation and then deleted.

Social login via Facebook or Google

You can link your IBUYGOU buyers account to your Facebook or Google account.

Facebook, Inc. and Google LLC are based in the USA. They are certified under the EU-US Privacy Shield. A current certificate can be viewed here. As a result of this agreement between the US and the European Commission, the latter has established an adequate level of data protection for companies certified under the Privacy Shield.

In case of a link between the accounts, you will only need to authenticate to Facebook or Google using your login information to be logged into your Trusted Shops customer account for buyers. For this purpose, you will be asked to consent to the transmission of the following data to IBUYGOU the first time you create a link:

Facebook: E-mail address, name, profile photo, age range (e.g. 35-39), language, country and other data that you have set to public on your Facebook profile.

Google: E-mail address, name, profile photo and other data that you have posted on your Google profile as publicly available.

The data IBUYGOU receives from Facebook or Google will be used to help you design your shopper profile on the basis of your consent pursuant to art. 6 para. 1 sentence 1 lit. a GDPR. Facebook receives the e-mail address from IBUYGOU the first time it is linked in order to identify you as a user, and afterwards only the ID that has been set as an authentication feature for you between the two systems. Facebook or Google does not receive any further data. You can unlink the accounts at any time and revoke the transfer of data with future effect by changing your settings on Facebook (here) or Google (here).

Registration for IBUYGOU membership for online merchants

An application for membership for online merchants is only offered to persons acting in the exercise of their commercial or self-employed professional activity. Personal data is collected for the purpose of contract processing in accordance with art. 6 para. 1 sentence 1 lit. b GDPR if you voluntarily provide it to us when contacting us or registering for our services.

After complete processing of the contract, your data will be restricted for further processing and deleted after expiry of the storage periods under tax and commercial law, unless you have expressly consented to further use of your data or we reserve the right to use data beyond this, which is permitted by law and about which we inform you in this declaration.

Application for a job at IBUYGOU

If you apply for a position at IBUYGOU via this website, personal data will be collected in our application portal for the purpose of handling the evaluation process in accordance with art. 6 para. 1 sentence 1 lit. b GDPR.

This portal is operated by a service provider who processes the data collected on its servers on our behalf.

The data you provide in our application portal will be used exclusively for the purpose of filling the advertised position and checking and processing your application submitted in this context. After completion of the application process, this data will be blocked for further use and deleted upon expiry of any storage obligations, unless you expressly consent to any other processing.

 

  • Data transfer
  • If you have ordered goods which we will send to you by post, we will pass on the data required for the fulfilment of the contract in accordance with art. 6 para. 1 sentence 1 lit. b GDPR to the shipping company commissioned with the delivery if this is necessary for the delivery of ordered goods. Depending on which payment service provider you select in the order process, we pass on the payment data collected for the processing of payments to the credit institution commissioned with the payment and, if applicable, to payment service providers commissioned by us or to the selected payment service. In some cases, the selected payment service providers also collect this data themselves if you create an account there. In this case, you must log in to the payment service provider with your access data during the ordering process. The data protection declaration of the respective payment service provider applies in this respect.

We use a payment service provider based in a country outside the European Union. The transmission of personal data to this company only takes place within the scope of the necessity to fulfil the contract.

Credit check when registering for IBUYGOU membership for online merchants

Only if you act in the exercise of your commercial or self-employed professional activity, we transmit your address data to credit agencies when concluding a membership contract for online merchants for the purpose of assessing the liability risk and for credit assessment if necessary. This serves to settle the contractual relationship pursuant to art. 6 para. 1 sentence 1 lit. b GDPR.

Appropriate measures to protect your rights, freedoms and legitimate interests will be taken into account. You have the opportunity to make your views known and to challenge the decision by contacting the contact person described below.

 

  • E-mail newsletter and postal advertising
  • E-mail advertising with registration for the newsletter

If you register for one of our newsletters or provide your data in order to download a document free of charge from our website or our Facebook or LinkedIn presence, we use the data required for this or separately provided by you in order to regularly send you our e-mail newsletter on the basis of your consent in accordance with art. 6 para. 1 sentence 1 lit. a GDPR.

The newsletter is sent on our behalf by service providers to whom we pass on your e-mail address for this purpose.

If the newsletter is sent via a service provider based in the USA / EUROPE, it is certified under the EU-US Privacy Shield. As a result of this agreement between the US and the European Commission, the latter has established an adequate level of data protection for companies certified under the Privacy Shield.

You can unsubscribe from the newsletter at any time and either by sending a message to the contact option described below or via a link provided for this purpose in the newsletter. After deregistration, we delete your e-mail address unless you have expressly consented to further use of your data or we reserve the right to use data beyond this, which is permitted by law and about which we inform you in this declaration.

E-mail advertising without registration for the newsletter and your right of objection

If we receive your e-mail address in connection with the sale of a product or service and you have not objected to this, we reserve the right to regularly send you offers for similar products, such as those already purchased, from our range by e-mail in accordance with Section 7 (3) UWG. This serves to safeguard our legitimate interests in an advertising approach to our customers that are overriding in the process of balancing of interests in accordance with art. 6 para. 1 sentence 1 lit. f GDPR.

The newsletter is sent on our behalf by service providers to whom we pass on your e-mail address for this purpose.

If the newsletter is sent via a service provider based in the USA / EUROPE, it is certified under the EU-US Privacy Shield. As a result of this agreement between the US and the European Commission, the latter has established an adequate level of data protection for companies certified under the Privacy Shield.

You can object to this use of your e-mail address at any time by sending a message to the contact option described below or via a link provided for this purpose in the advertising e-mail.

Postal advertising and your right of objection

Furthermore, we reserve the right to use your first and last name as well as your postal address for our own advertising purposes, e.g. to send interesting offers and information about our products by post. This serves to safeguard our legitimate interests in an advertising approach to our customers that are overriding in the process of balancing of interests in accordance with art. 6 para. 1 sentence 1 lit. f GDPR.

The advertising mailings are processed on our behalf by a service provider to whom we pass on your data.

You can object to the storage and use of your data for these purposes at any time by sending a message to the contact option described below.

 

  • Integration of the IBUYGOU
  • To display our ratings collected, the IBUYGOU is integrated on some of our websites.

Pursuant to art. 6 para. 1 sentence 1 lit. f GDPR, this serves to safeguard our legitimate interests in the optimal marketing of our offer that are overriding in the process of balancing of interests.

When the IBUYGOU is called, the web server automatically saves a so-called server log file, which contains e.g. your IP address, date and time of the call, transferred data volume and the requesting provider (access data) and documents the call. This access data is not evaluated and is automatically overwritten at the latest seven days after the end of your page visit.

 

  • Cookies
  • To improve the user experience on our website and enable you to use its certain features in order to show suitable products or conduct market research, some pages of this website use the so-called cookies. This serves the protection of our legitimate interests in the optimised presentation of our offer according to art. 6 para. 1 sentence 1 lit f GDPR that are overriding in the process of balancing of interests. A cookie is a small text file which is stored automatically on your end device. Some of the cookies we use are deleted after you close the browser session, i.e. when you close the browser (that’s the so-called session cookies). Other cookies are stored in your end-user device and enable us to recognise your browser when you visit us again (persistent cookies). To check the cookie storage period, you can use the Overview function in the cookie settings of your web browser. You can configure your browser for it to inform you whenever a page uses cookies and decide on a case-by-case basis whether to accept or reject the cookies on a given website or generally. Every browser has a different policy for managing the cookie settings. The browser’s policy is described in the Help menu of every browser and explains how you can change your cookie settings. To find out how to change the settings in your browser, see the lin