Skip to content
Legal

Privacy

Privacy Policy

1. Controller Ilia Isakov Leuningerstr. 10 56410 Montabaur Email: [email protected]

2. Overview of the processing activities We process personal data only to the extent necessary to provide our online shop and our services. Processing is based on the GDPR, in particular:

  • Art. 6(1)(b) GDPR (performance of a contract): processing to handle orders, payment and delivery.
  • Art. 6(1)(f) GDPR (legitimate interest): operation and security of the shop, advertising measurement, bot protection.
  • Art. 6(1)(a) GDPR (consent): where consent is obtained separately.

3. Data we collect When you use our shop, we process the following data:

  • Master data: name, address, email address (when you place an order)
  • Payment data: processed directly by Stripe (see section 5)
  • Usage data: IP address, browser type, access times, pages viewed
  • Design data: the categories and designs you select and the designs generated for you
  • Device ID: anonymized visitor ID used to assign guest designs

4. Hosting and content delivery Our shop is hosted on servers in Germany. For the delivery of static content and for DDoS protection we use Cloudflare Inc. (USA). In doing so, Cloudflare processes technically necessary connection data. The transfer of data to the USA is based on EU standard contractual clauses. (Legal basis: Art. 6(1)(f) GDPR) More information: https://www.cloudflare.com/privacypolicy/

5. Payment processing Payments are processed by Stripe Payments Europe Ltd. (Ireland). When you pay, your payment data is transmitted directly to Stripe. We do not store complete credit card data ourselves. Stripe processes your data in accordance with its own privacy policy: https://stripe.com/privacy (Legal basis: Art. 6(1)(b) GDPR)

6. Order fulfillment and production For the production and shipping of your order we work with Printful Inc. (USA/Latvia). Printful receives the data required to fulfill the order (name, delivery address, product details). The transfer of data is based on EU standard contractual clauses. (Legal basis: Art. 6(1)(b) GDPR) Privacy policy of Printful: https://www.printful.com/policies/privacy

7. AI design generation We use AI based image generation to create individual designs. Only your design selection (category, designs, style) is transmitted to the AI service as a text description. No personal data such as name, email or payment information is passed on to the AI service. The generated design images are stored on our servers in Germany. The rights of use in the generated designs lie with the operator. (Legal basis: Art. 6(1)(b) GDPR)

7a. Use of Google API Services (Google Ads) We use Google Ads (Google LLC, USA) to advertise our shop and the Google Ads API for the automated transmission of conversion data. Our use of Google API Services complies with the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy). (Legal basis: Art. 6(1)(f) GDPR, legitimate interest in measuring and optimizing our advertising campaigns)

Data collection and use (Data Usage): We transmit only anonymized conversion events (for example that a purchase took place, order value, currency) to Google Ads. No personal data (name, email address, delivery address, payment information) is transmitted to Google. The data is used solely to measure and optimize our advertising campaigns.

Data sharing (Data Sharing): The conversion data transmitted to Google is anonymized and contains no personal information. Google user data is not passed on to any other third parties. Google user data is not sold or passed on to advertising platforms, data brokers or information resellers. Google processes the data in accordance with its own privacy policy (https://policies.google.com/privacy) and the API terms of use.

Data storage and protection (Data Storage & Protection): Conversion data is processed on our servers in Germany and transmitted to Google exclusively over encrypted HTTPS connections. We do not store Google user data permanently on our systems. Access to the Google Ads API is protected by OAuth 2.0 and limited to authorized systems.

AI training: We do not use any data received through Google API Services or transmitted to Google to train AI or ML models.

8. Database and authentication We use Supabase Inc. (USA) for data storage and user sign in. Supabase stores your account data (email, encrypted password) and your order data in a PostgreSQL database. The transfer of data is based on EU standard contractual clauses. (Legal basis: Art. 6(1)(b) GDPR) Privacy policy of Supabase: https://supabase.com/privacy

9. Email communication We use Brevo (Sendinblue, France) to send confirmation and information emails. Brevo processes your email address and your name for the purpose of email delivery. (Legal basis: Art. 6(1)(b) GDPR) Privacy policy of Brevo: https://www.brevo.com/legal/privacypolicy/

10. Bot protection To protect against automated requests we use Cloudflare Turnstile. In doing so, technical data (IP address, browser information) is transmitted to Cloudflare in order to distinguish human users from bots. No cookies are set for tracking purposes. (Legal basis: Art. 6(1)(f) GDPR)

11. Cookies and local storage Our shop uses only technically necessary cookies and local storage (localStorage) for the shopping cart, session management and the visitor ID. We do not use tracking cookies or analytics tools that require consent.

12. Disclosure of data to third parties We disclose personal data only where this is necessary for the performance of the contract or required by law. Data is disclosed to the following categories of recipients:

  • Payment service provider: Stripe (payment processing, payment data)
  • Production partner: Printful (name, delivery address, product details for printing and shipping)
  • Hosting/CDN: Cloudflare (technical connection data, DDoS protection)
  • Email service provider: Brevo (email address, name for confirmation emails)
  • AI service provider: anonymized text descriptions for design generation (no personal data)
  • Advertising measurement: Google Ads (anonymized conversion data for campaign optimization, no personal data)

Personal data is not sold and is not passed on to data brokers or information resellers. Transfers of data to third countries (USA) are based on EU standard contractual clauses.

13. Data security and protective measures We use appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, destruction or alteration. These include:

  • Encryption: all data is transmitted via HTTPS/TLS. Stored passwords are hashed and salted.
  • Access control: access to personal data is limited to authorized staff who need it to process orders.
  • Server location: our servers are located in Germany and are subject to German and European data protection law.
  • Regular backups: regular encrypted backups protect against data loss.
  • Payment data: complete credit card and bank details are processed exclusively by Stripe and are never stored on our servers.

14. Retention period Personal data is deleted as soon as the purpose of storing it no longer applies. Order data is stored for the duration of the statutory retention periods (as a rule 6 or 10 years under the German Commercial Code (HGB) and the German Fiscal Code (AO)). Generated design images remain on our servers as the intellectual property of the operator. Account data is removed when you delete your account, unless statutory retention obligations apply.

15. Your rights As a data subject you have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)
  • Right to withdraw consent you have given (Art. 7(3) GDPR)

To exercise your rights, please contact: [email protected]

16. Right to lodge a complaint You have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data. The authority responsible for us is: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz Hintere Bleiche 34 55116 Mainz https://www.datenschutz.rlp.de

Last updated: February 2026

This English version is provided for convenience. In case of doubt, the German version prevails.

Newsletter · rarely, never spam

When a new piece arrives at the studio.

A few editions a month. We email you as soon as they arrive, and not otherwise.