Privacy Policy

PRIVACY POLICY

1) INFORMATION ABOUT THE COLLECTION OF PERSONAL DATA AND CONTACT DETAILS OF THE CONTROLLER

1.1

We are pleased that you are visiting our website and thank you for your interest. Below, we inform you about how we handle your personal data when you use our website. Personal data refers to any data that can personally identify you.

1.2

The controller responsible for data processing on this website, within the meaning of the General Data Protection Regulation (GDPR), is Bayside Boutique. The controller for processing personal data is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data.

1.3

This website uses SSL or TLS encryption for security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the controller). You can recognize an encrypted connection by the character sequence “https://” and the lock symbol in your browser’s address bar.


2) DATA COLLECTION WHEN VISITING OUR WEBSITE

If you use our website for informational purposes only, meaning that you do not register or otherwise provide us with information, we only collect the data that your browser transmits to our server (so-called “server log files”). When you visit our website, we collect the following data, which is technically necessary for us to display the website to you:

  • Our visited website
  • Date and time of access
  • Amount of data sent in bytes
  • Source/reference from which you reached the page
  • Used browser
  • Used operating system
  • Used IP address (if applicable, in anonymized form)

The processing is carried out in accordance with Art. 6(1)(f) GDPR based on our legitimate interest in improving the stability and functionality of our website. The data is not disclosed or otherwise used. However, we reserve the right to check the server log files retrospectively if there are concrete indications of unlawful use.


3) COOKIES

To make visiting our website attractive and enable the use of certain functions, we use so-called cookies on various pages. These are small text files that are stored on your device. Some of the cookies we use are deleted after your browser session ends (so-called session cookies). Other cookies remain on your device and allow us or our partner companies (third-party cookies) to recognize your browser during your next visit (persistent cookies).

When cookies are set, they collect and process specific user information such as browser and location data, as well as IP address values. Persistent cookies are automatically deleted after a specified period, which may vary depending on the cookie.

Some cookies serve to simplify the ordering process by saving settings (e.g., remembering the contents of a virtual shopping cart for a later visit to the website). If personal data is also processed through individual cookies implemented by us, the processing is carried out either in accordance with Art. 6(1)(b) GDPR for contract execution or in accordance with Art. 6(1)(f) GDPR to protect our legitimate interests in the best possible functionality of the website and a customer-friendly and effective website experience.

We may work with advertising partners who help us make our website more interesting for you. In this case, cookies from partner companies may also be stored on your device when you visit our website (third-party cookies). If we cooperate with such advertising partners, you will be informed individually and separately about the use of such cookies and the scope of the collected data.

You can configure your browser to notify you when cookies are set and decide individually whether to accept them, accept cookies only in certain cases, or generally exclude them. Each browser differs in how it manages cookie settings. This is described in the help menu of each browser, which explains how to change your cookie settings. You can find these settings for the respective browsers at the following links:

Please note that if you do not accept cookies, the functionality of our website may be limited.


4) CONTACTING US

When you contact us (e.g., via contact form or email), personal data is collected. The specific data collected depends on the respective contact form. This data is stored and used exclusively for the purpose of responding to your inquiry and the associated technical administration.

The legal basis for processing this data is our legitimate interest in responding to your inquiry in accordance with Art. 6(1)(f) GDPR. If your contact aims at concluding a contract, an additional legal basis for processing is Art. 6(1)(b) GDPR. Your data will be deleted once your inquiry has been fully processed, provided that no statutory retention obligations prevent this.


5) DATA PROCESSING WHEN OPENING A CUSTOMER ACCOUNT AND FOR CONTRACT PROCESSING

In accordance with Art. 6(1)(b) GDPR, personal data is collected and processed when you provide it to us for contract execution or when opening a customer account. The specific data collected is evident from the respective input forms.

You can delete your customer account at any time by sending a message to the above-mentioned controller. We store and use the data you provide for contract processing. After the contract is fully executed or your customer account is deleted, your data will be restricted with respect to tax and commercial retention periods and deleted after these periods expire, unless you have expressly consented to further use of your data or we are legally permitted to retain and use it beyond this period.


6) USE OF YOUR DATA FOR DIRECT MARKETING

6.1 Subscription to Our Email Newsletter

If you subscribe to our email newsletter, we will regularly send you information about our offers. The only mandatory information required for sending the newsletter is your email address. Any additional data is voluntary and used to address you personally.

For newsletter distribution, we use the so-called double opt-in procedure, meaning we will only send you an email newsletter if you have expressly confirmed your consent. You will receive a confirmation email asking you to click on a confirmation link to verify that you want to receive the newsletter.

By activating the confirmation link, you grant us your consent to use your personal data in accordance with Art. 6(1)(a) GDPR. Your email address is stored for newsletter distribution. You can unsubscribe at any time via the link in the newsletter or by notifying the controller. After unsubscribing, your email address will be deleted unless you have expressly consented to further use or we retain the data for legally permitted purposes.

6.2 Email Newsletter to Existing Customers

If you provide your email address when purchasing goods or services, we may send you promotional emails for similar products or services. This processing is based on our legitimate interest in personalized direct marketing under Art. 6(1)(f) GDPR. You can object to this use at any time by notifying the controller.

7) DATA PROCESSING FOR ORDER PROCESSING

7.1 The personal data we collect will be passed on to the transport company commissioned with the delivery as part of contract execution, insofar as this is necessary for the delivery of the goods. We pass on your payment data to the commissioned credit institution as part of payment processing, provided this is necessary for payment processing. If payment service providers are used, we explicitly inform you about this below. The legal basis for data transmission is Art. 6 (1) lit. b GDPR.

7.2 Use of Payment Service Providers (Payment Processors)

  • PayPal
    When paying via PayPal, credit card via PayPal, direct debit via PayPal, or – if offered – "purchase on account" or "installment payment" via PayPal, we pass on your payment data to PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg ("PayPal"), as part of payment processing. The transfer is based on Art. 6 (1) lit. b GDPR and only to the extent necessary for payment processing.

PayPal reserves the right to conduct a credit check for the payment methods credit card via PayPal, direct debit via PayPal, or – if offered – "purchase on account" or "installment payment" via PayPal. For this purpose, your payment data may be passed on to credit agencies in accordance with Art. 6 (1) lit. f GDPR, based on PayPal's legitimate interest in determining your ability to pay. The result of the credit check concerning the statistical probability of non-payment is used by PayPal to decide on the provision of the respective payment method. The credit report may contain probability values (so-called score values). If score values are included in the credit report result, they are based on a scientifically recognized mathematical-statistical procedure. Address data, among other things, is included in the calculation of score values.

For further data protection information, including the credit agencies used, please refer to PayPal's privacy policy:
https://www.paypal.com/de/webapps/mpp/ua/privacy-full

You can object to this processing of your data at any time by notifying PayPal. However, PayPal remains entitled to process your personal data if necessary for contractual payment processing.

  • SOFORT
    If you choose the "SOFORT" payment method, payment processing will be carried out by the payment service provider SOFORT GmbH, Theresienhöhe 12, 80339 Munich, Germany ("SOFORT"), to whom we transmit your information provided during the order process, along with information about your order, in accordance with Art. 6 (1) lit. b GDPR. SOFORT GmbH is part of the Klarna Group (Klarna Bank AB (publ), Sveavägen 46, 11134 Stockholm, Sweden). Your data will only be passed on for payment processing with the payment service provider SOFORT and only to the extent necessary.

For further information about SOFORT's privacy policy, please visit:
https://www.klarna.com/sofort/datenschutz


8) CONTACT FOR REVIEW REMINDERS

Own Review Reminder (No dispatch by a customer review system)

We use your email address to send a one-time reminder to submit a review of your order for our review system, provided you have given us your explicit consent in accordance with Art. 6 (1) lit. a GDPR during or after your order.

You can revoke your consent at any time by notifying the data controller.


9) USE OF SOCIAL MEDIA: SOCIAL PLUGINS

9.1 Facebook Plugins with Shariff Solution
Our website uses social plugins ("plugins") of the social network Facebook, operated by Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA ("Facebook").

To enhance the protection of your data when visiting our website, these buttons are not fully integrated as plugins but only embedded as an HTML link. This ensures that no connection to Facebook’s servers is established when accessing a page on our website that contains such buttons. If you click the button, a new browser window opens, directing you to Facebook, where you can interact with the plugins (possibly after logging in).

Facebook Inc. is certified under the EU-U.S. "Privacy Shield" framework, ensuring compliance with EU data protection standards.

For details on data collection and further processing by Facebook, as well as your rights and privacy settings, please refer to Facebook's privacy policy:
https://www.facebook.com/policy.php

9.2 Google+ Plugins with Shariff Solution
Our website uses social plugins ("plugins") of the social network Google+, operated by Google LLC., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google").

To enhance data protection, these buttons are embedded only as HTML links, ensuring no automatic connection to Google+ servers when visiting our site. Clicking the button opens a new browser window leading to Google+, where you can interact with the plugins (after logging in, if necessary).

Google LLC is certified under the "Privacy Shield" framework.

For more information on data collection and processing by Google, please refer to Google's privacy policy:
https://www.google.com/intl/de/policies/privacy/

9.3 Instagram Plugin with Shariff Solution
Our website uses social plugins ("plugins") of the online service Instagram, operated by Instagram LLC, 1601 Willow Rd, Menlo Park, CA 94025, USA ("Instagram").

These buttons are embedded only as HTML links to prevent an automatic connection to Instagram servers when visiting our site. Clicking the button opens a new browser window leading to Instagram, where you can interact with the plugins.

Instagram LLC is certified under the "Privacy Shield" framework.

For further details on data collection and usage by Instagram, please refer to their privacy policy:
https://help.instagram.com/155833707900388/


10) ONLINE MARKETING

10.1 DoubleClick by Google
This website uses the online marketing tool DoubleClick by Google, operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("DoubleClick").

DoubleClick uses cookies to show relevant ads to users, improve campaign performance reports, or prevent users from seeing the same ads multiple times. A cookie ID allows Google to track which ads have been displayed in which browser, preventing duplicate display. Processing is based on our legitimate interest in optimizing our website marketing (Art. 6 (1) lit. f GDPR).

Further details on DoubleClick’s privacy policy:
https://www.google.de/policies/privacy/

10.2 Use of Google AdWords Conversion Tracking
This website uses the online advertising program "Google AdWords" and its conversion tracking feature provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google").

Conversion tracking cookies are set when a user clicks on a Google AdWords ad. They typically expire after 30 days and do not personally identify users. If the user visits specific pages on this website before the cookie expires, Google and we can track that the user clicked the ad and was redirected to the page.

For details on Google's privacy policy:
https://www.google.de/policies/privacy/

You can permanently disable cookies for ad preferences by adjusting your browser settings or installing the plugin:
https://www.google.com/settings/ads/plugin?hl=de

Please note that disabling cookies may limit website functionality.

  1. WEB ANALYSIS SERVICES Google (Universal) Analytics
  • Google Universal Analytics

This website uses Google Analytics, a web analysis service of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"). Google Analytics uses so-called "cookies," text files that are stored on your computer and allow an analysis of your use of the website. The information generated by the cookie about your use of this website (including the shortened IP address) is generally transmitted to a Google server in the USA and stored there.

This website uses Google Analytics exclusively with the "_anonymizeIp()" extension, which ensures anonymization of the IP address by shortening it and excludes direct personal reference. Through this extension, your IP address is shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before transmission. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. In these exceptional cases, this processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interest in the statistical analysis of user behavior for optimization and marketing purposes.

On our behalf, Google will use this information to evaluate your use of the website, compile reports on website activities, and provide further services related to website and internet use to us. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.

You can prevent the storage of cookies by setting your browser software accordingly; however, we point out that in this case, you may not be able to use all functions of this website to their full extent. Furthermore, you can prevent Google from collecting the data generated by the cookie related to your use of the website (including your IP address) and processing these data by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=en

Alternatively, instead of the browser plugin or within browsers on mobile devices, please click on the following link to set an opt-out cookie that will prevent future collection by Google Analytics within this website (this opt-out cookie only works in this browser and only for this domain; if you delete your cookies in this browser, you must click this link again): Disable Google Analytics

Google LLC, based in the USA, is certified under the US-European data protection agreement "Privacy Shield," which ensures compliance with the data protection level applicable in the EU.

This website also uses Google Analytics for cross-device analysis of visitor streams conducted via a user ID. When a page is first accessed, the user is assigned a unique, permanent, and anonymized ID that is set across devices. This allows interaction data from different devices and different sessions to be assigned to a single user. The user ID does not contain any personal data and does not transmit such data to Google.

The collection and storage of data via the user ID can be objected to at any time with effect for the future. To do so, you must disable Google Analytics on all systems you use, for example, in another browser or on your mobile device.

You can deactivate Google Analytics using a browser plugin from Google (https://tools.google.com/dlpage/gaoptout?hl=en). Alternatively, instead of the browser plugin or within browsers on mobile devices, please click on the following link to set an opt-out cookie that will prevent future collection by Google Analytics within this website (this opt-out cookie only works in this browser and only for this domain; if you delete your cookies in this browser, you must click this link again): Disable Google Analytics

Further information on Universal Analytics can be found here: https://support.google.com/analytics/answer/2838718?hl=en&ref_topic=6010376

  1. RETARGETING/ REMARKETING/ RECOMMENDATION ADVERTISING Facebook Custom Audience via the Pixel Method

This website uses the “Facebook Pixel” of Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA (“Facebook”). If explicit consent is given, this allows the behavior of users to be tracked after they have seen or clicked on a Facebook ad. This process is designed to evaluate the effectiveness of Facebook advertisements for statistical and market research purposes and can contribute to optimizing future advertising measures.

The collected data is anonymous for us and does not allow us to draw conclusions about the identity of users. However, Facebook stores and processes the data so that a connection to the respective user profile is possible and Facebook can use the data for its own advertising purposes in accordance with Facebook’s Data Usage Policy (https://www.facebook.com/about/privacy/).

You can allow Facebook and its partners to display advertisements on and outside of Facebook. For these purposes, a cookie may be stored on your computer. These processing operations are only carried out with explicit consent pursuant to Art. 6 para. 1 lit. a GDPR.

Consent to the use of the Facebook Pixel may only be given by users who are older than 13 years. If you are younger, please ask your legal guardians for permission.

Facebook Inc., based in the USA, is certified under the US-European “Privacy Shield” agreement, which ensures compliance with EU data protection levels.

To disable the use of cookies on your computer, you can set your internet browser to prevent future cookies from being placed or delete existing cookies. However, disabling all cookies may mean that some functions on our websites can no longer be executed. You can also disable the use of cookies by third-party providers such as Facebook on the following website of the Digital Advertising Alliance: https://www.aboutads.info/choices/

Google AdWords Remarketing

Our website uses the functions of Google AdWords Remarketing, with which we advertise for this website in Google search results and on third-party websites. The provider is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”). For this purpose, Google sets a cookie in your browser, which automatically enables interest-based advertising based on your visited pages. Processing is based on our legitimate interest in the optimal marketing of our website pursuant to Art. 6 para. 1 lit. f GDPR.

You can permanently disable the setting of cookies for ad preferences by downloading and installing the browser plugin available at the following link: https://www.google.com/settings/ads/onweb/

Further information and Google's privacy policy regarding advertising can be found here: https://www.google.com/policies/technologies/ads/

  1. RIGHTS OF THE DATA SUBJECT

(Provides detailed rights including access, rectification, deletion, restriction, objection, data portability, and complaint rights under GDPR.)

  1. DURATION OF STORAGE OF PERSONAL DATA

The duration of storage of personal data is based on the respective legal retention period (e.g., commercial and tax law retention periods). After the expiration of the period, the corresponding data are routinely deleted, provided that they are no longer required for contract fulfillment or initiation and/or no legitimate interest in further storage exists on our part.