Privacy Policy

1. Data Controller

Parfinity GmbH Holtenauer Straße 83 24105 Kiel Germany
Represented by: Sven Efftinge, Managing Director Email: info@parfinity.com Phone: +49 (0) 431 6489 2216

2. Overview of Processing Activities

This privacy policy informs you about the type, scope, and purpose of processing personal data on our website www.parfinity.com. We use various services to optimize our offering, some of which transfer data to countries outside the EU.

3. Hosting

Our website is hosted by Vercel Inc.:
Vercel Inc. 340 S Lemon Ave #4133 Walnut, CA 91789, USA
The servers are located in the EU. When you visit our website, Vercel processes technical data such as IP addresses, access times, and transferred data volumes. This processing is based on our legitimate interests in the secure and efficient provision of our website (Art. 6(1)(f) GDPR).
More information: https://vercel.com/legal/privacy-policy

4. SSL Encryption

This website uses SSL encryption for security reasons. This means that transmitted data is encrypted and cannot be read by third parties.

5. Cookies and Consent Management

5.1 What are Cookies?

Cookies are small text files that are stored on your device when you visit our website. They make it possible to recognize your browser and store information.

5.2 Cookie Categories

We use the following cookie categories:
Necessary Cookies (no consent required)
  • Session cookies for shopping cart functionality
  • Saving cookie settings
  • Shopify functionalities
Analytics Cookies (consent required)
  • Google Analytics
  • Microsoft Clarity
  • Facebook Pixel
  • TikTok Pixel
Marketing Cookies (consent required)
  • Google Ads Remarketing
  • Facebook Custom Audiences
  • TikTok Ads

5.3 Managing Your Cookie Settings

When you first visit our website, a cookie banner appears where you can make your settings. You can revoke your consent at any time with effect for the future by visiting cookie settings.

6. Data Collection on Our Website

6.1 Automatically Collected Data

The following data is automatically collected each time you access our website:
  • IP address
  • Date and time of request
  • Time zone difference to GMT
  • Content of the request
  • HTTP status code
  • Amount of data transferred
  • Website from which the request comes
  • Browser, operating system and their interface
  • Language and version of browser software
This data is collected based on Art. 6(1)(f) GDPR. The data is deleted as soon as it is no longer necessary to achieve the purpose of its collection.

6.2 Contact Form

When using our contact form, we collect:
  • Name
  • Email address
  • Your message
  • Time of request
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in responding to inquiries) or Art. 6(1)(b) GDPR (pre-contractual measures).

6.3 Customer Account

You can create a customer account. We collect:
  • First name, last name
  • Email address
  • Password (encrypted)
  • Delivery address
  • Billing address
  • Phone number (optional)
  • Date of birth (optional)
  • Order history
Processing is based on Art. 6(1)(b) GDPR (contract fulfillment) and Art. 6(1)(f) GDPR (legitimate interests in customer retention).

6.4 Order Processing

For orders, we collect:
  • All data from 6.3
  • Payment information
  • Order details
  • IP address
The legal basis is Art. 6(1)(b) GDPR (contract fulfillment) and Art. 6(1)(c) GDPR (legal obligations, e.g., tax law).

7. Analytics Tools and Advertising

7.1 Google Analytics 4

We use Google Analytics 4 from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Processed data:
  • Anonymized IP addresses
  • Device information
  • User behavior (pages visited, time spent, clicks)
  • Demographic characteristics (approximate location, language)
Purpose: Analysis of user behavior to improve our website Legal basis: Art. 6(1)(a) GDPR (consent) Storage period: 14 months
You can prevent collection by Google Analytics:
  • Adjust cookie settings
  • Install browser add-on: https://tools.google.com/dlpage/gaoptout

7.2 Google Ads

We use Google Ads for remarketing and conversion tracking.
Processed data:
  • Cookie ID
  • IP address
  • Device information
  • Pages visited
  • Actions performed (e.g., purchases)
Purpose: Display of personalized advertising, success measurement Legal basis: Art. 6(1)(a) GDPR (consent) Opt-out: https://adssettings.google.com

7.3 Google Tag Manager

Google Tag Manager is a tool for managing website tags. The Tag Manager itself does not store cookies or collect personal data but triggers other tags.

7.4 Meta Pixel (Facebook/Instagram)

We use the Meta Pixel from Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland.
Processed data:
  • Cookie ID
  • IP address
  • Browser information
  • Page views
  • Actions performed
  • Facebook ID (if logged in)
Purpose: Remarketing, conversion tracking, audience building Legal basis: Art. 6(1)(a) GDPR (consent) Opt-out: https://www.facebook.com/settings?tab=ads

7.5 TikTok Pixel

We use the TikTok Pixel from TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland.
Processed data:
  • IP address
  • Browser information
  • Website activities
  • Cookie ID
Purpose: Ad performance measurement, remarketing Legal basis: Art. 6(1)(a) GDPR (consent)

7.6 Microsoft Clarity

We use Microsoft Clarity from Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA.
Processed data:
  • Anonymized IP address
  • Device information
  • Mouse movements, clicks, scrolling behavior
  • Session recordings (anonymized)
Purpose: Improvement of user-friendliness Legal basis: Art. 6(1)(a) GDPR (consent) Privacy: https://privacy.microsoft.com/privacystatement

8. Email Marketing

8.1 Newsletter

We use Klaviyo (Klaviyo, Inc., 125 Summer Street, Boston, MA 02110, USA) for our newsletter distribution.
Processed data:
  • Email address
  • Name (optional)
  • Sign-up time
  • IP address at sign-up
  • Opening and click behavior
Purpose: Sending advertising, information about new products Legal basis: Art. 6(1)(a) GDPR (consent) Unsubscribe: Via the link in each email

8.2 Transactional Emails

We also send order confirmations and service emails via Klaviyo based on Art. 6(1)(b) GDPR (contract fulfillment).

9. Payment Service Providers

9.1 Shopify Payments

Provider: Shopify International Limited, Victoria Buildings, 2nd floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland
Processed data: Name, address, bank details, credit card details, transaction amounts

9.2 PayPal

Provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg
Processed data: Name, address, email, transaction data

9.3 Stripe

Provider: Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland
Processed data: Name, address, credit card details, transaction data

9.4 Klarna

Provider: Klarna Bank AB, Sveavägen 46, 111 34 Stockholm, Sweden
Processed data: Name, address, date of birth, gender, email, phone number, IP address
For all payment service providers, processing is based on Art. 6(1)(b) GDPR (contract fulfillment).

10. Embedded Content

10.1 Google Fonts

We embed Google Fonts locally. No connection to Google servers is made.

10.2 YouTube Videos

If embedded, we use YouTube's enhanced privacy mode. Data is only transmitted to YouTube when the video is played.

11. Data Transfer to Third Countries

Some of our service providers are based in the USA. The transfer is based on:
  • Your consent (Art. 49(1)(a) GDPR)
  • Standard contractual clauses of the EU Commission
  • Adequacy decision (where available)
We would like to point out that the USA does not have a level of data protection comparable to the EU and that US authorities may access your data under certain circumstances.

12. Storage Period

We only store personal data for as long as necessary for the respective purposes:
  • Customer data: During the business relationship and thereafter in accordance with legal retention periods (usually 10 years for tax-relevant data, 6 years for business correspondence)
  • Cookie data: Depending on the cookie, between session end and 2 years
  • Newsletter data: Until consent is revoked
  • Log files: Maximum 30 days

13. Your Rights

13.1 Overview

You have the following rights:
  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)
  • Right to withdraw consent (Art. 7(3) GDPR)

13.2 Right to Object

You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on Art. 6(1)(e) or (f) GDPR. We will no longer process the personal data unless we can demonstrate compelling legitimate grounds.

13.3 Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority. In Schleswig-Holstein:
Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein Holstenstraße 98, 24103 Kiel Phone: 0431 988-1200 Email: mail@datenschutzzentrum.de

14. Data Security

We take technical and organizational security measures to protect your data against accidental or intentional manipulation, loss, destruction, or access by unauthorized persons:
  • SSL encryption
  • Firewalls
  • Access controls
  • Regular security updates
  • Encrypted passwords

15. Currency and Changes to this Privacy Policy

This privacy policy is currently valid and has the status of 1. Juli 2025.
Due to the further development of our website and offers or due to changed legal or official requirements, it may become necessary to change this privacy policy.

16. Contact for Data Protection

For questions about data protection, you can reach us at:
Email: datenschutz@parfinity.com Postal: Parfinity GmbH, Holtenauer Straße 83, 24105 Kiel

Version 1.0 - Status: 1. Juli 2025