Privacy Policy
The protection of your personal data is of particular concern to us. We therefore process your data exclusively on the basis of legal regulations. In this data protection information we inform you about the most important aspects of data processing within the framework of our online shop. The legal basis for data protection can be found in the Basic Data Protection Regulation (Regulation (EU) 2016/679), the General Data Protection Regulation (GDPR) and the Austrian Telecommunications Act (TKG).
Contact
If you contact us via the form on the website or via e-mail, your data will be stored for six months for the purpose of processing your inquiry and in case of follow-up questions. We will not pass on this data without your consent.
Processed data types
Announced by the customer
- Name(s)/Company
- Email address
- Address
- Bank, payment and credit card data
- Telephone and fax number
- Password (encrypted)
- VAT registration number (If you are an entrepreneur in the sense of § 1 UGB (Austrian Corporate Code))
- Username
- Order data
- Refunds
- Return of goods
- Contents of news or reviews of the customer
- Information about the seller
Additionally charged by the responsible person
- IP addresses (log files)
- User ID, Push ID, Device ID
- Browser used
- Communication protocol
- Information on account usage (e.g. date of creation, number of logins, date of last request)
- Information about the purchased products
- User behavior data (View, Fav, Rate, Add to Cart, Buy)
Data storage
We would like to point out that for the purpose of an easier shopping process and for the later contract processing, the IP data of the connection owner is stored by the online shop operator within the framework of cookies, as well as the name, address and credit card number of the customer.
The data provided by you is necessary for the fulfilment of the contract or for the implementation of pre-contractual measures. Without this data we cannot conclude the contract with you. No data will be transferred to third parties, with the exception of the transfer of credit card data to the processing bank institutes/payment service providers for the purpose of debiting the purchase price, to the transport company/forwarding agent commissioned by us for the delivery of the goods and to our tax advisor for the fulfilment of our tax obligations.
After cancellation of the purchase process, the data stored by us will be deleted. In the case of a contract conclusion, all data from the contractual relationship will be stored until the end of the tax law retention period (7 years). In addition, the data name, address, purchased goods and date of purchase are stored until the expiry of the product liability period (10 years). The data processing is based on the legal provisions of § 96 (3) TKG (Austrian Telecommunications Act) and Art 6 (1) lit a (consent) and/or lit b (necessary for the performance of the contract) of the GDPR.
Cookies
Our website uses so-called cookies. These are small text files that are stored on your end device with the help of the browser. They do not cause any damage.
We use cookies to make our offer user-friendly. Some cookies remain stored on your terminal device until you delete them. They enable us to recognize your browser on your next visit. If you do not wish this, you can set up your browser to inform you about the setting of cookies and to allow this only in individual cases.
If you deactivate cookies, the functionality of our website may be limited.
Analysis tools and advertising
Google Tag Manager
We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Tag Manager is a tool that allows us to integrate tracking or statistical tools and other technologies on our website. Google Tag Manager itself does not create any user profiles, does not store cookies and does not perform any independent analysis. It only serves to manage and play out the tools it integrates. However, Google Tag Manager does collect your IP address, which may also be transferred to Google’s parent company in the USA.
The use of Google Tag Manager is based on Art. 6 (1) lit. f GDPR. The website operator has a legitimate interest in a fast and uncomplicated integration and administration of various tools on his website. If a corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 (1) lit. a GDPR; the consent can be revoked at any time.
Google Analytics
This website uses functions of the web analysis service Google Analytics. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics enables the website operator to analyze the behavior of website visitors. In doing so, the website operator receives various usage data, such as page impressions, length of stay, operating systems used and the origin of the user. This data may be summarized by Google in a profile which is assigned to the respective user or his terminal device.
Google Analytics uses technologies that enable the recognition of the user for the purpose of analyzing user behavior (e.g. cookies or device fingerprinting). The information collected by Google on the use of this website is usually transferred to a Google server in the USA and stored there.
The use of this analysis tool is based on Art. 6 (1) lit. f GDPR. The website operator has a legitimate interest in the analysis of user behavior in order to optimize both his website and his advertising. If a corresponding consent has been requested (e.g. consent to the storage of cookies), the processing is carried out exclusively on the basis of Art. 6 (1) lit. a GDPR; the consent can be revoked at any time.
Data transmission to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here:
https://privacy.google.com/businesses/controllerterms/mccs/.
IP Anonymization
We have activated the IP anonymization function on this website. This means that your IP address will be truncated by Google within member states of the European Union or in other signatory states to the Agreement on the European Economic Area before it is transmitted to the USA. Only in exceptional cases will the full IP address be transferred to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on the website activities and to provide further services to the website operator in connection with the use of the website and the Internet. The IP address transmitted by your browser within the scope of Google Analytics is not combined with other data from Google.
Browser Plugin
You can prevent the collection and processing of your data by Google by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de. You can find more information on how Google Analytics handles user data in the Google privacy policy: https://support.google.com/analytics/answer/6004245?hl=de.
Order processing
We have a contract with Google for order processing and fully implement the strict requirements of the data protection authorities when using Google Analytics.
Demographic characteristics in Google Analytics
This website uses the “demographic characteristics” feature of Google Analytics to help the website visitors find appropriate ads within the Google advertising network. This allows reports to be generated that contain statements about the age, gender and interests of the site visitors. This data is derived from Google’s interest-based advertising and from third-party visitor data. This data cannot be associated with any particular person. You can disable this feature at any time in the ad settings in your Google Account or generally prohibit the collection of your data by Google Analytics as described in the “Opting out of data collection” section.
Storage
User and event-level data stored at Google that is linked to cookies, user IDs (e.g., User ID) or advertising IDs (e.g., DoubleClick cookies, Android advertising ID) is anonymized or deleted after 14 months. Details are found under the following link:
https://support.google.com/analytics/answer/7667196?hl=de
Hotjar
This website uses Hotjar. The provider is Hotjar Ltd, Level 2, St Julians Business Centre, 3, Elia Zammit Street, St Julians STJ 1000, Malta, Europe (Website: https://www.hotjar.com).
Hotjar is a tool to analyze your user behavior on this website. With Hotjar we can, among other things, record your mouse and scroll movements and clicks. Hotjar is also able to determine how long you stayed with the mouse pointer in a certain position. Hotjar uses this information to create so-called heat maps, which can be used to determine which areas of the website the website visitor prefers to view.
We can also determine how long you stayed on a page and when you left it. We can also determine at which point you have interrupted your entries in a contact form (so-called conversion-funnels). In addition, Hotjar can be used to obtain direct feedback from website visitors. This function serves to improve the operator’s web offerings.
Hotjar uses technologies that enable the recognition of the user for the purpose of analyzing user behavior (e.g. cookies or the use of device fingerprinting). The use of this analysis tool is based on Art. 6 (1) lit. f GDPR. The website operator has a legitimate interest in the analysis of user behavior in order to optimize both his website and his advertising. If a corresponding consent has been requested (e.g. consent to the storage of cookies), the processing is carried out exclusively on the basis of Art. 6 (1) lit. a GDPR; the consent can be revoked at any time.
Deactivating Hotjar
If you want to disable data collection by Hotjar, click on the following link and follow the instructions there: https://www.hotjar.com/opt-out
Please note that Hotjar must be deactivated separately for each browser or end device. For more information about Hotjar and the data collected, please refer to Hotjar’s privacy policy under the following link: https://www.hotjar.com/privacy
Contract on order processing
We have entered into a contract for order processing with Hotjar to implement the strict EU data protection regulations.
Facebook Pixel
This website uses Facebook’s visitor action pixels to measure conversion. This service is provided by Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. However, according to Facebook, the data collected is also transferred to the United States and other third countries.
This allows the behavior of site visitors to be tracked after they have clicked on a Facebook advertisement to be redirected to the provider’s website. This allows the effectiveness of Facebook Ads to be evaluated for statistical and market research purposes and to optimize future advertising efforts.
The collected data is anonymous to us as the operator of this website, we cannot draw any conclusions about the identity of the users. However, the data is stored and processed by Facebook so that a connection to the respective user profile is possible and Facebook can use the data for its own advertising purposes, in accordance with the Facebook Data Usage Policy. This allows Facebook to enable the placement of advertisements on pages of Facebook and outside of Facebook. This use of the data cannot be influenced by us as a site operator.
The use of Facebook pixels is based on Art. 6 (1) lit. f GDPR. The website operator has a legitimate interest in effective advertising measures, including social media. If a corresponding consent has been requested (e.g. consent to the storage of cookies), the processing is carried out exclusively on the basis of Art. 6 (1) lit. a GDPR; the consent can be revoked at any time.
Data transmission to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here:
- https://www.facebook.com/legal/EU_data_transfer_addendum and
- https://de-de.facebook.com/help/566994660333381.
You will find further information on the protection of your privacy in the Facebook data protection information: https://de-de.facebook.com/about/privacy/.
You can also use the remarketing feature “Custom Audiences” in the Advertising Settings section at: https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen disable. You must be logged in to Facebook for this. If you do not have a Facebook account, you can deactivate usage-based advertising from Facebook on the European Interactive Digital Advertising Alliance website: http://www.youronlinechoices.com/de/praferenzmanagement/.
LinkedIn Insight Tag
This website uses the Insight tag from LinkedIn. This service is provided by LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland.
Data processing by LinkedIn Insight Tag
We use the LinkedIn Insight Tag to obtain information about visitors to our website. Once a site visitor is registered with LinkedIn, we can analyze, among other things, the key professional information (e.g., career level, company size, country, location, industry, and job title) of our site visitors to better tailor our site to their specific audiences. We can also use LinkedIn Insight Tags to measure whether visitors to our websites make a purchase or other action (conversion measurement). Conversion measurement can also be performed across devices (e.g. from PC to tablet). LinkedIn Insight Tag also offers a retargeting feature that allows us to display targeted advertising to visitors to our website outside of the website. According to LinkedIn, no identification of the advertising addressee takes place.
LinkedIn itself also collects log files (URL, referrer URL, IP address, device and browser characteristics, and time of access). IP addresses are shortened or (if used to reach LinkedIn members across devices) hashed (pseudonymized). The direct identifiers of LinkedIn members are deleted by LinkedIn after seven days. The remaining pseudonymized data will then be deleted within 180 days.
The data collected by LinkedIn cannot be assigned to specific individuals by us as website operator. LinkedIn will store the collected personal data of the website visitors on its servers in the USA and use it for its own promotional activities. Please see LinkedIn’s privacy policy for details: https://www.linkedin.com/legal/privacy-policy#choices-oblig.
Legal basis
The use of LinkedIn Insight is based on Art. 6 (1) lit. f GDPR. The website operator has a legitimate interest in effective advertising measures, including social media. If a corresponding consent has been requested (e.g. consent to the storage of cookies), the processing is carried out exclusively on the basis of Art. 6 (1) letter a GDPR; consent may be revoked at any time.
Data transmission to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://www.linkedin.com/legal/l/dpa and https://www.linkedin.com/legal/l/eu-sccs.
Objection to the usage of LinkedIn Insight Tag
Disagree with LinkedIn’s analysis of user behavior and targeted advertising at the following link:
https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
In addition, LinkedIn members may control the use of their personal information for promotional purposes in their account settings. To prevent LinkedIn from linking information collected on our site to your LinkedIn account, you must log out of your LinkedIn account before you visit our site.
Conclusion of an Order Processing Agreement
We have a contract for order processing with LinkedIn.
Newsletter
You have the possibility to subscribe to our newsletter via our website. To do so, we need your e-mail address and your declaration that you agree to receive the newsletter. In order to be able to inform you specifically, we also collect and process voluntarily provided information on areas of interest, birthday and postal code.
Once you have subscribed to the newsletter, you will receive a confirmation e-mail from us with a link to confirm your subscription.
The e-mail is sent via Mailchimp: The Rocket Science Group, LLC, 675 Ponce de Leon AveNE, Suite 5000, Atlanta, GA 30308, USA. For details please see the MailChimp privacy policy:
https://mailchimp.com/legal/privacy/
You can cancel the newsletter subscription at any time. Please send your cancellation to the following e-mail address: hello@love-a-duck.com. We will then immediately delete your data in connection with the newsletter dispatch. This revocation has no influence on the lawfulness of the processing, which was carried out on the basis of the consent given up to the revocation.
Your rights
With regard to your data stored with us, you have the rights to information, correction, deletion, blocking, transferability of data, revocation and objection. If you are of the opinion that the processing of your data violates data protection laws or your data protection rights have been violated in any other way, you can file a complaint with us at patrick@love-a-duck.com or with the data protection authority.
You can reach us for this purpose at the following contact details:
LOVE A DUCK e.U.
Dr. Patrick Bartos
Zeltgasse 11 / E2
A-1080 Vienna
Austria
patrick@love-a-duck.com