Data protection

Privacy Policy

1. Who we are (Controller)

The controller responsible for data processing on this website, in the sense of the General Data Protection Regulation (GDPR), is:

WATCHES JEWELRY AND MORE Porzellangasse 27/6 1090 Vienna Austria Phone: 06767526004 Email: buero.zafir@gmail.com

2. Automatic Data Collection (Website Provision)

If you use our website for informational purposes only (i.e., without registering or placing an order), we only collect the data that your web browser automatically transmits to our server. These so-called server log files include:

  • IP address of the requesting device

  • Date and time of access

  • Name and URL of the retrieved file

  • Website from which access is made (referrer URL)

  • Browser used and, if applicable, the operating system of your computer

Legal basis: Processing is carried out in accordance with Art. 6 Para. 1 lit. f GDPR on the basis of our legitimate interest in improving the stability, security, and functionality of our website. Storage duration: This data is stored for a maximum of 14 days for security reasons and then automatically deleted.

3. Data Processing during Order Fulfillment

If you order goods in our online shop, we process the personal data you enter to fulfill the purchase contract. This includes:

  • First and last name

  • Billing and shipping address

  • Email address and phone number

  • Payment information

Legal basis: Processing is necessary for the performance of a contract with you or for the implementation of pre-contractual measures (Art. 6 Para. 1 lit. b GDPR). Storage duration: After complete execution of the contract, your data will be blocked for further use and deleted after the expiry of tax and commercial law retention periods. In Austria, this retention period is generally 7 years in accordance with § 212 UGB and § 132 BAO.

4. Disclosure of Data to Third Parties

For contract fulfillment, we pass on your data to selected service providers who support us in operating the shop.

A. Hosting Platform (Shopify)

Our website is hosted on Shopify's servers. The provider is Shopify International Limited, 2nd Floor, 1-2 Waterloo Road, Dublin 4, D04 E5W7, Ireland. Shopify processes your data (e.g., order and device data) to ensure the technical operation of the online shop.

Note on third-country transfer: Data may be transferred to the parent company Shopify Inc. in Canada or the USA. Shopify uses standard contractual clauses approved by the EU Commission to guarantee an adequate level of data protection.

B. Shipping Service Provider

For the purpose of delivering the ordered goods, we transmit your name and delivery address (and, if applicable, email/phone number for delivery notification) to the commissioned transport company (e.g., Österreichische Post AG, DHL, DPD). Legal basis: Art. 6 Para. 1 lit. b GDPR.

C. Payment Service Provider

Depending on the payment method you choose during the order process, we transmit the collected payment data to the credit institution commissioned with the payment or to the selected payment service provider (e.g., Stripe, PayPal, Klarna, Shopify Payments). The payment service providers sometimes process this data as independent controllers. The data protection regulations of the respective provider apply. Legal basis: Art. 6 Para. 1 lit. b GDPR.

5. Cookies and Web Analytics (Google Analytics)

This website uses cookies. These are small text files that are stored on your device. We differentiate between technically necessary cookies (without which the shop would not function, e.g., for the shopping cart) and marketing/analysis cookies.

Google Analytics

We use Google Analytics, a web analysis service of Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). Google Analytics uses cookies to analyze how visitors use our website. We use Google Analytics exclusively with activated IP anonymization, so that your IP address is truncated by Google within the EU.

Legal basis: The use of analysis and marketing cookies is based exclusively on your express consent via our cookie banner (Art. 6 Para. 1 lit. a GDPR). You can withdraw this consent at any time with effect for the future via the cookie settings on our website.

6. Social Media & Advertising Pixels

We use pixels and tracking technologies from third-party providers (e.g., Meta Pixel/Facebook, Google Ads, Bing Ads) on our website to measure the success of our advertising campaigns and to show you behavior-based, targeted advertising.

Legal basis: This processing also takes place exclusively after your active consent via the cookie banner (Art. 6 Para. 1 lit. a GDPR). You can also object to personalized advertising directly with the providers:

7. Your Rights under the GDPR

As a data subject, you have the following legal rights regarding the data stored with us:

  • Right to information (Art. 15 GDPR): You can find out what data we process about you.

  • Right to rectification (Art. 16 GDPR): You can request the correction of inaccurate data.

  • Right to erasure (Art. 17 GDPR): You can request the deletion of your data, provided that no legal retention obligations prevent this.

  • Right to restriction of processing (Art. 18 GDPR).

  • Right to data portability (Art. 20 GDPR).

  • Right to object (Art. 21 GDPR) to processing based on our legitimate interest.

If you wish to exercise any of these rights, simply send us an informal email to buero.zafir@gmail.com.

Right to lodge a complaint with the supervisory authority

If you believe that the processing of your data violates data protection law, you have the right to complain to the competent supervisory authority. In Austria, this is: Austrian Data Protection Authority (DSB) Barichgasse 40-42, 1030 Vienna Email: dsb@dsb.gv.at

8. Minors

Our offering is generally directed at adults. Persons under 18 years of age should not transmit personal data to us without the consent of their parents or guardians.

9. Changes to this Privacy Policy

We reserve the right to occasionally adapt this privacy policy so that it always complies with current legal requirements or to implement changes to our services (e.g., when introducing new payment methods or apps).

Important To-Dos for you to implement in the Shopify shop:

  1. Create a separate subpage: Copy this text and paste it into a separate subpage named "Privacy" in your Shopify admin area (under Online Store -> Pages). Link this page in the footer of your shop so that it is accessible with one click from every subpage.

  2. The cookie banner: Since you use Google Analytics and advertising pixels, make sure that the "Europe" region is activated in your Shopify store under Settings -> Customer Privacy. This will automatically block these tracking scripts until the customer clicks "Accept All" in the banner.

  3. Match additional apps: If you install new Shopify apps in the future (e.g., for product reviews, email marketing like Klaviyo, or dropshipping service providers), these must be added by name with a short paragraph in point 4 (Disclosure to third parties).