Privacy policy
Last updated: 24 July 2026
1. Data Controller
The controller responsible for the processing of personal data on this website is:
cool down germany
Owner: Michael Senn
Graubergen 9
21218 Seevetal
Germany
Phone: +49 151 540 78 990
Email: m.senn@cool-down.online
2. General Information on Data Processing
We process personal data only to the extent necessary to operate our online shop, process orders, communicate with customers, comply with legal obligations or carry out the analytics and marketing activities described below.
Depending on the relevant processing activity, we rely in particular on the following legal bases:
– Article 6(1)(a) GDPR: consent
– Article 6(1)(b) GDPR: taking steps prior to entering into a contract or performance of a contract
– Article 6(1)(c) GDPR: compliance with a legal obligation
– Article 6(1)(f) GDPR: pursuit of legitimate interests
Our legitimate interests include, in particular, the secure, functional and commercially efficient operation of our online shop, the prevention of fraud and misuse, the processing of customer enquiries and the improvement of our services.
Where cookies or similar technologies store information on your device or access information already stored on your device, the provisions of the German Telecommunications Digital Services Data Protection Act (TDDDG) also apply.
3. Categories of Personal Data
Depending on how you use our online shop, we may process the following categories of personal data:
– first and last name
– billing and delivery address
– email address
– telephone number, where provided
– company and business customer information
– customer account and login details
– order, contract, payment and return information
– communications and customer support content
– product, batch and complaint information
– IP address and technical connection information
– browser, device and operating system information
– pages viewed and functions used
– product views, shopping cart, checkout and purchase events
– cookie, consent and marketing information
– newsletter subscriptions and interaction data
4. Sources of Personal Data
We receive personal data in particular:
– directly from you, for example when you place an order, register or contact us,
– automatically when you use our online shop,
– from payment, shipping and other service providers,
– from advertising and analytics platforms,
– from publicly accessible sources, where legally permitted and necessary for the relevant purpose.
5. Technical Provision of the Website and Server Logs
When you access our website, technically necessary data is processed so that the website can be displayed and operated securely, reliably and properly.
This may include:
– IP address
– date and time of access
– page or file accessed
– amount of data transferred
– browser type and browser version
– operating system used
– referring URL
– device information
– technical error and security information
The processing is based on Article 6(1)(f) GDPR. Our legitimate interest is the secure, functional and uninterrupted operation of our online shop and the prevention of misuse and cyberattacks.
Technically essential storage and access operations on your device are carried out on the basis of Section 25(2) TDDDG.
6. Shopify
Our online shop is operated using the Shopify e-commerce platform.
The contracting entity for merchants in the European Economic Area is:
Shopify International Limited
Victoria Buildings, 2nd Floor
1–2 Haddington Road
Dublin 4, D04 XN32
Ireland
Shopify processes personal data in particular for:
– providing and displaying the online shop
– managing products, customer accounts and shopping carts
– processing and documenting orders
– carrying out security and fraud checks
– providing payment, analytics, communication and marketing functions
– technical maintenance, troubleshooting and further development of the platform
This may include the processing of contact, order, payment, transaction, usage, device, cookie and consent data.
Where Shopify processes data on our behalf for the provision of the online shop, the processing is carried out on the basis of a data processing agreement.
Shopify may also process certain data under its own responsibility in connection with its own consumer services, enhanced services, security functions or other independently controlled functions.
Further information:
https://www.shopify.com/de/legal/datenschutz
Shopify Privacy Policy for Consumers:
https://www.shopify.com/de/legal/privacy/customers
Shopify Privacy Portal:
https://privacy.shopify.com/de
7. Shopify Network Intelligence
Shopify Network Intelligence is enabled for the use of certain Shopify functions, particularly Shopify Messaging.
Shopify may use information from interactions with our shop, Shopify and other Shopify-powered shops to provide enhanced services.
This processing may serve the following purposes in particular:
– improving and personalising Shopify services
– improving the performance and analysis of our shop
– detecting fraud, risk and misuse
– measuring and improving marketing activities
– improving audience selection and advertising functions
Depending on the relevant function, contact, customer, order, usage, device, cookie and interaction data may be processed.
Other Shopify merchants do not receive direct access to our customer data.
Where consent is required for a particular processing activity, the processing will only take place in accordance with your selection in the cookie banner or privacy settings.
You can manage your privacy settings in relation to Shopify through the following portal:
https://privacy.shopify.com/de
8. Orders and Contract Processing
When you place an order with us, we process the information required to process and perform the order.
This includes in particular:
– first and last name
– billing and delivery address
– email address
– telephone number, where provided
– company information for business customers
– products and quantities ordered
– order number and order date
– payment method and payment status
– shipping, return and refund information
The processing is carried out for the purpose of taking steps prior to entering into a contract and performing the purchase contract in accordance with Article 6(1)(b) GDPR.
Order, invoice, payment and accounting information is also processed to comply with tax, commercial and other statutory documentation and retention obligations on the basis of Article 6(1)(c) GDPR.
Without the information marked as mandatory, we may be unable to process your order or may be unable to process it properly.
9. Customer Account
If you create or use a customer account, we process in particular:
– name and contact details
– login and authentication information
– saved addresses
– order history
– return and account settings
The processing is carried out to provide and manage the customer account on the basis of Article 6(1)(b) GDPR.
You may request the deletion of your customer account. Order, invoice, payment and contract data that must be retained by law will remain unaffected.
10. Payment Processing
To process payments, we transfer the necessary information to the payment service provider selected by you.
Depending on the payment methods displayed and selected during checkout, the following services may be involved:
– Shopify Payments
– PayPal
– credit and debit card providers
– Apple Pay
– Google Pay
– Shop Pay
– other payment service providers displayed during checkout
The following data may be processed in particular:
– name
– billing address
– email address
– order amount and currency
– order and transaction number
– payment method and payment status
– device, IP and security information
– account, card or payment information, depending on the payment method
Complete payment instrument details are generally processed directly by the relevant payment service provider and are not normally fully visible to us.
The processing is carried out to perform the purchase contract in accordance with Article 6(1)(b) GDPR and for secure payment processing and fraud prevention in accordance with Article 6(1)(f) GDPR.
Payment service providers may process personal data under their own responsibility for payment processing, identity verification, fraud prevention, credit checks and compliance with their own legal obligations.
Shopify Payments may carry out automated security and risk assessments. These may take into account the IP address, device information, address verification, payment information and unusual ordering patterns.
Further information about Shopify:
https://www.shopify.com/de/legal/datenschutz
Further information about PayPal:
https://www.paypal.com/de/legalhub/paypal/privacy-full
11. Shipping with DHL
For delivery of your order, we transfer the necessary information to:
DHL Paket GmbH
Charles-de-Gaulle-Straße 20
53113 Bonn
Germany
The following data may be transferred:
– recipient’s name
– delivery address
– order and shipment information
– email address, where required for shipment notifications
– telephone number, where required for delivery or provided by you
The transfer is carried out for the performance of the purchase contract in accordance with Article 6(1)(b) GDPR.
Where an email address or telephone number is used exclusively for optional shipment notifications or additional delivery options, the processing is based, depending on the specific function, on your consent or our legitimate interest in reliable and customer-friendly delivery.
Further information:
https://www.dhl.de/de/toolbar/footer/datenschutz.html
12. Contact, Customer Service and Returns
If you contact us by email, telephone, contact form or by another method, we process the information you provide in order to handle your enquiry.
This may include:
– name
– email address
– telephone number
– order number
– content of the message
– information relating to products, deliveries, returns or complaints
– photographs and other attachments
Where your enquiry relates to an order, a contract or pre-contractual measures, the processing is carried out on the basis of Article 6(1)(b) GDPR.
General enquiries are processed on the basis of Article 6(1)(f) GDPR. Our legitimate interest is the proper handling and documentation of your enquiry.
13. Health Data and Reports Concerning Medical Devices
Enquiries, complaints or reports concerning medical devices may contain information about symptoms, injuries, illnesses, side effects or other health-related circumstances.
Health data constitutes a special category of personal data and is subject to a higher level of protection.
Please provide only the health information that is actually necessary to process your enquiry or a possible product incident.
Where no other statutory exception applies, we obtain your explicit consent before processing health data in accordance with Article 9(2)(a) GDPR.
Processing may also be permitted where it is:
– necessary for the establishment, exercise or defence of legal claims,
– necessary to comply with statutory product or medical device obligations, or
– necessary to process and report a safety-related incident.
Where required by law, relevant information may be shared with manufacturers, authorised representatives, competent authorities, insurers, legal advisers or other legally designated bodies.
We do not use health data to create advertising profiles and do not transfer health data to Google or Meta for advertising purposes.
14. Email Marketing with Shopify Messaging
We use Shopify Messaging to send email marketing communications, including newsletters, product information, offers and marketing automations.
The following data may be processed in particular:
– name
– email address
– subscription status
– date, time and source of subscription
– proof of consent
– sending and delivery status
– email opens and clicks, depending on the selected tracking setting
– orders and sessions attributed to a campaign
– unsubscribes
– undeliverable emails
– spam complaints
– responses to marketing campaigns
Personalised emails may include existing customer information, such as the recipient’s name or place of residence.
Marketing emails are generally sent only where you have previously provided your express consent. The legal basis is Article 6(1)(a) GDPR. The requirements of Section 7 of the German Unfair Competition Act (UWG) also apply.
Where the statutory requirements for advertising to existing customers are met, emails may exceptionally be sent on the basis of Section 7(3) UWG. In that case, we use your email address only to advertise our own similar products and inform you, when collecting and whenever using the address, of your right to object at any time.
You may withdraw your consent or object to the use of your email address for advertising purposes at any time with effect for the future:
– by using the unsubscribe link in the relevant email, or
– by sending a message to m.senn@cool-down.online.
The withdrawal or objection does not affect the lawfulness of processing carried out before that time.
Following an unsubscribe request, we may store your email address on a suppression list where necessary to ensure that no further marketing emails are sent to that address.
Emails are sent and analysed using Shopify Messaging and the technical service providers used by Shopify for this purpose.
Further information:
https://www.shopify.com/de/legal/datenschutz
15. Cookies and Similar Technologies
Our website uses cookies and comparable technologies such as pixels, local storage technologies, tags and server-side event transfers.
Cookies are small files or pieces of information that may be stored on or read from your device.
We distinguish in particular between:
– technically necessary cookies and technologies
– functional cookies and technologies
– analytics and statistics technologies
– marketing and advertising technologies
Technically necessary technologies are used to provide functions expressly requested by you, including the shopping cart, checkout, language settings, login, security and payment processing.
For technically necessary operations, storage or access is carried out on the basis of Section 25(2) TDDDG. The subsequent processing of personal data is carried out, depending on the purpose, in particular on the basis of Article 6(1)(b) or Article 6(1)(f) GDPR.
Non-essential analytics, marketing and advertising technologies are generally used only with your consent. The legal bases are Section 25(1) TDDDG and Article 6(1)(a) GDPR.
You may change or withdraw your selection at any time through the cookie banner or the “Privacy Settings” link provided on our website.
16. Google Consent Mode
We use Google Consent Mode to communicate your consent choices to the Google services used on our website.
The following consent signals may be used:
– analytics_storage
– ad_storage
– ad_user_data
– ad_personalization
These signals inform Google whether:
– analytics-related information may be stored,
– advertising-related information may be stored,
– advertising-related user data may be transferred to Google, and
– data may be used for personalised advertising.
Where the relevant consent has been refused, the corresponding analytics or advertising cookies may not be stored or read.
Depending on the technical implementation of Consent Mode, limited cookieless signals may be transmitted to Google where consent has been refused. These may include the consent status and technical information and may be used for aggregated or modelled measurement.
You may change your consent choices at any time through our website’s privacy settings.
17. Google Analytics 4
We use Google Analytics 4 to analyse the use of our online shop.
The provider is:
Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland
Google Analytics may process the following information in particular:
– cookie and online identifiers
– randomly generated client IDs
– device and browser information
– operating system and screen resolution
– approximate geographical region
– pages viewed and referral sources
– time and duration of visits
– product views
– search, shopping cart and checkout events
– purchases, order values and transaction identifiers
– consent signals
IP addresses are technically transmitted when a connection is established. Google states that IP addresses are not logged or stored in Google Analytics 4. For access from the European Union, IP addresses are used to derive approximate location information and are then discarded.
Google Analytics is used to evaluate the use of our website, prepare reports, identify errors and usage patterns and improve our online shop.
Google Analytics and the associated non-essential cookies are used only with your consent in accordance with Section 25(1) TDDDG and Article 6(1)(a) GDPR.
The retention period for user-level and event-level data in our Google Analytics property is set to 14 months. This setting does not necessarily apply to all aggregated standard reports.
Google Signals is disabled in our Google Analytics property.
You may withdraw your consent at any time through the privacy settings.
Further information:
https://policies.google.com/privacy?hl=en
18. Google Ads and Conversion Tracking
We use Google Ads to display advertisements and measure the effectiveness of our advertising activities.
The provider is:
Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland
Google Ads conversion tracking may record whether a visitor performed a particular action after clicking on or viewing an advertisement.
Such actions may include:
– viewing a product page
– searching for a product
– adding a product to the shopping cart
– beginning the checkout process
– completing a purchase
– order value and currency
The following data may be processed in particular:
– cookie and online identifiers
– information relating to advertising clicks
– device and browser information
– referral and page information
– time of conversion
– order value
– transaction identifier
– consent signals
Storage and processing for analytics and advertising purposes takes place only with your consent in accordance with Section 25(1) TDDDG and Article 6(1)(a) GDPR.
You may withdraw your consent at any time through the privacy settings.
Further information:
https://policies.google.com/privacy?hl=en
19. Enhanced Conversions for Google Ads
We use the “Enhanced Conversions” function in Google Ads.
This function may use data provided by you in connection with a purchase, including:
– email address
– first and last name
– telephone number, where provided
– address
Before transmission to Google, this data is normalised and converted into hash values using the one-way SHA-256 hashing algorithm.
Google uses these hash values to improve the matching of conversions with signed-in Google users and previous advertising interactions.
The processing is used to measure advertising campaigns more accurately, attribute purchases to advertising interactions and optimise our campaigns.
The data is transferred only where the necessary consent for the transfer of advertising-related user data has been granted. The legal basis is Article 6(1)(a) GDPR. Where information is stored on or accessed from your device, Section 25(1) TDDDG also applies.
You may withdraw your consent at any time through the privacy settings.
Further information:
https://policies.google.com/privacy?hl=en
20. Meta Pixel and Meta Conversions API
We use the Shopify sales channel “Facebook and Instagram by Meta”, including the Meta Pixel and Meta Conversions API.
The provider is:
Meta Platforms Ireland Limited
Merrion Road
Dublin 4
D04 X2K5
Ireland
The data-sharing setting is set to “Maximum”. Our shop therefore uses both the browser-based Meta Pixel and the server-side Meta Conversions API.
The following information may be processed and transferred to Meta:
– IP address
– cookie, browser and device identifiers
– browser and device information
– pages viewed
– searches
– product views
– shopping cart actions
– beginning of checkout
– payment and purchase events
– order value and currency
– name
– email address
– telephone number, where provided
– location and address information
Contact details may be transferred in hashed or encrypted form for matching with users of Meta services.
The processing is carried out in particular for:
– measuring advertising campaigns
– attributing purchases to advertisements
– preparing campaign reports
– improving audience selection
– displaying interest-based or personalised advertising
– creating and expanding advertising audiences
Where consent is required, the service is used only after you have given your consent in accordance with Section 25(1) TDDDG and Article 6(1)(a) GDPR.
We and Meta may be joint controllers for the collection and transfer of certain event data. Meta is generally independently responsible for the subsequent processing of data transferred to it.
You may withdraw your consent at any time through the privacy settings.
Further information:
https://www.facebook.com/privacy/policy/
21. Recipients of Personal Data
Depending on how our shop is used, personal data may be transferred in particular to the following recipients or categories of recipients:
– hosting and e-commerce providers
– payment service providers, banks and card companies
– shipping and logistics service providers
– IT, security, maintenance and support service providers
– newsletter and email service providers
– analytics, marketing and advertising platforms
– tax advisers, legal advisers, auditors and insurers
– manufacturers, authorised representatives and other parties involved in product or safety reports
– authorities, courts and other public bodies, where required by law
Personal data is transferred only where a legal basis exists.
22. Transfers to Third Countries
Some of our service providers, particularly Shopify, Google, Meta and certain payment service providers, may process personal data outside the European Union or European Economic Area.
Data transfers are carried out only in compliance with Articles 44 et seq. GDPR.
Depending on the recipient and destination country, the transfer may be based in particular on:
– an adequacy decision by the European Commission
– a valid certification under the EU-US Data Privacy Framework
– Standard Contractual Clauses issued by the European Commission
– binding corporate rules
– supplementary technical and organisational safeguards
– a statutory exception applicable to the individual case
Shopify may transfer data within its international group of companies and to subprocessors. Google, Meta and other service providers may process data in the United States and other countries.
Despite the safeguards used, it cannot be completely ruled out that authorities outside the European Union may access personal data in accordance with their legal powers.
23. Data Retention
We store personal data only for as long as necessary for the relevant purpose or for as long as statutory retention, documentation or evidence obligations apply.
The following criteria apply in particular:
– Contract, invoice, payment and accounting data is generally retained for six, eight or ten years in accordance with tax and commercial law requirements.
– Customer account data is generally stored until the customer account is deleted, unless statutory retention obligations apply.
– Contact and support enquiries are deleted after they have been fully processed, unless they are required for contractual documentation, the establishment or defence of legal claims, or compliance with statutory obligations.
– Newsletter and marketing information is generally processed until consent is withdrawn, an objection is made or the subscription is cancelled.
– Evidence of consent and unsubscribe requests may be stored for longer where necessary to demonstrate compliance with legal obligations.
– User-level and event-level data in Google Analytics is generally retained for 14 months in accordance with our settings.
– Information relating to product defects, complaints, incidents or safety reports is retained in accordance with statutory product, medical device, documentation and limitation requirements.
– Cookie and consent information is retained for as long as necessary to demonstrate and implement your consent choices.
After the relevant retention period has expired, the data is deleted or anonymised unless another legal basis permits or requires continued storage.
24. Automated Decisions and Fraud Prevention
Shopify and payment service providers may use automated systems for fraud detection, identity verification and risk assessment.
These systems may take into account:
– payment and transaction information
– billing and delivery address
– IP address
– device information
– order value
– order frequency
– unusual or suspicious transaction patterns
Shopify may assign a risk rating to an order.
Based on such indicators, we may carry out an additional manual review of an order, request further information or take other measures permitted by law.
As a rule, we do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.
Payment service providers may carry out automated decisions under their own responsibility. Further information is available in the privacy policy of the payment service provider selected by you.
25. Your Data Protection Rights
Subject to the applicable statutory requirements, you have the following rights:
– right of access under Article 15 GDPR
– right to rectification under Article 16 GDPR
– right to erasure under Article 17 GDPR
– right to restriction of processing under Article 18 GDPR
– right to data portability under Article 20 GDPR
– right to object under Article 21 GDPR
– right to withdraw consent under Article 7(3) GDPR
– right to lodge a complaint with a supervisory authority under Article 77 GDPR
You may withdraw consent at any time with effect for the future. The withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
26. Right to Object
Where we process personal data on the basis of Article 6(1)(f) GDPR, you have the right to object to the processing at any time on grounds relating to your particular situation.
Where personal data is processed for direct marketing purposes, you may object to such processing at any time without providing reasons. This also applies to profiling related to direct marketing.
Following your objection, your personal data will no longer be processed for direct marketing purposes.
27. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority.
The authority generally responsible for our place of business is:
The State Commissioner for Data Protection of Lower Saxony
Prinzenstraße 5
30159 Hanover
Germany
Postal address:
Postfach 221
30002 Hanover
Germany
Phone: +49 511 120-4500
Email: poststelle@lfd.niedersachsen.de
28. Data Relating to Minors
Our online shop is not specifically directed at children.
We do not knowingly send marketing emails to minors unless valid consent or another legal basis exists.
If we become aware that a child’s personal data has been processed without a sufficient legal basis, we will delete the data unless a statutory retention obligation applies.
29. Data Security
We use appropriate technical and organisational measures to protect personal data against loss, alteration, unauthorised access, unlawful disclosure and other forms of misuse.
Depending on the relevant processing activity, these measures may include:
– encrypted data transmission
– access and authorisation controls
– security and fraud checks
– data backups
– technical updates
– organisational security measures
However, complete security during data transmission over the internet cannot be guaranteed.
30. Changes to this Privacy Policy
We may update this Privacy Policy where our processing activities, service providers or legal requirements change.
The current version is available on our website.
31. Contact for Data Protection Enquiries
For access requests, withdrawals of consent, objections or other data protection enquiries, please contact:
cool down germany
Owner: Michael Senn
Graubergen 9
21218 Seevetal
Germany
Email: m.senn@cool-down.online
Phone: +49 151 540 78 990