← Back home

Privacy policy

1. Controller and contact

The controller responsible for processing personal data in this shop is:

MONATLICH. · Joshua Calle Moser
Sole proprietorship
Pilotystr. 51
90408 Nürnberg
Germany

For privacy questions or to exercise your rights, contact info@monatlich-store.com.

2. Visiting and operating the shop

When you visit our shop, technically necessary connection data is processed. This includes, in particular, your IP address, the time of access, the requested page or file, browser and operating system information, and technical status and error messages. We need this data to deliver the website, protect it from attacks and resolve technical problems. The legal basis is our legitimate interest in a secure and functioning shop under Article 6(1)(f) GDPR.

The shop is provided through Kotao GmbH, Hohenzollernring 57, 50672 Köln, Germany. Kotao processes shop data on our behalf and uses infrastructure and communications providers for this purpose, including hosting, databases, secure content delivery and transactional emails. Details of the subprocessors and their processing locations are available in Kotao’s list of subprocessors. Platform operations use, among other services, Cloudflare for content delivery and security, and Neon for databases.

The platform provider generally retains technical server logs for up to 90 days. In the event of a specific security incident, data needed for investigation or legal proceedings may be retained longer. Further information is available in Kotao’s privacy policy.

3. Shopping bag, necessary storage and page counts

Cookies or similar storage technologies may be used to make the shopping bag, sign-in, security and checkout work. Where these are necessary for a function you have expressly requested, access to your device takes place under section 25(2)(2) of the German Telecommunications Digital Services Data Protection Act (TDDDG). Subsequent processing of personal data is based on Article 6(1)(b) or (f) GDPR, depending on the function. This information is needed only for as long as the relevant session, shopping bag or security function requires it. You can also remove it through your browser settings, which may limit individual shop functions.

Optional personal usage analytics, advertising pixels and remarketing are disabled in this version of the shop. A basic technical page counter may still process the address of the page visited without query parameters. Search terms, campaign parameters, referrers and shopping bag identifiers are not passed to this counter. It supports an aggregate assessment of shop operations based on Article 6(1)(f) GDPR. Connection data that necessarily arises with each connection is described in the preceding section.

No newsletter sign-up or advertising integrations from Meta, TikTok, Google or Pinterest are currently configured. Before introducing services that require consent, we will add the relevant information and choices.

4. Orders and customer service

When you place an order, we process information required for the contract: your name, contact and delivery details, billing address, ordered items, amounts, order and payment status, and messages about the order. The legal basis is Article 6(1)(b) GDPR. We also process legally required invoicing and accounting data under Article 6(1)(c) GDPR. We cannot fulfil your order without the details marked as required during checkout.

For delivery, we share your name and delivery address with the appointed shipping provider. Additional contact information is shared only if it is required for the agreed delivery or you have consented. The shipping provider is identified in the shipping notification. Providers for shop operations, payment processing and transactional emails receive only the data required for their respective tasks.

If you contact us by email, we use your email address and message to respond. Contract-related enquiries are processed under Article 6(1)(b) GDPR; other enquiries are processed on the basis of our legitimate interest in answering them under Article 6(1)(f) GDPR. Please do not send payment details such as full card numbers by email.

5. Payment processing

Our shop platform uses Stripe for the online payments offered at checkout. To carry out and secure a payment, it processes, in particular, the transaction amount, currency, order reference, billing and contact details, and the payment information you enter with the payment provider. Sensitive card details are entered in the provider’s payment component. We receive payment status information and payment references, but not your full card number.

Sharing data to execute the payment is based on Article 6(1)(b) GDPR. Stripe also processes data as an independent controller, for example to prevent fraud and comply with legal obligations. Information about the responsible Stripe entity, legal bases, data transfers and your rights is available in Stripe’s privacy policy. Available payment methods are displayed before you complete your order.

6. Recipients and processing outside the EEA

Depending on the infrastructure or payment service used, data may also be processed outside the European Union or European Economic Area, particularly in the United States. Such transfers must meet the requirements of Articles 44 onwards GDPR, for example through an applicable adequacy decision or appropriate safeguards such as EU Standard Contractual Clauses. Details of individual services are available in the provider information linked above. You can request information about the safeguards applicable to your data and a copy of them from us.

7. How long we keep data

We retain personal data only for as long as we need it for the relevant purpose or are required to do so by law. Resolved enquiries are deleted unless contractual, evidentiary or retention obligations require otherwise. Contract-related documents may be retained until the relevant limitation periods expire. Tax and commercial records are subject to statutory retention periods depending on the document, particularly six, eight or ten years. Data is deleted once its purpose no longer applies and the relevant periods have expired.

8. Your rights

Subject to the applicable legal requirements, you have rights of access, rectification, erasure, restriction of processing and data portability. You can withdraw consent at any time with effect for the future. This does not affect the lawfulness of processing carried out before withdrawal.

Right to object: Where we process data on the basis of legitimate interests under Article 6(1)(f) GDPR, you can object on grounds relating to your particular situation. You can object to processing for direct marketing at any time without giving particular reasons.

You may also lodge a complaint with a data protection supervisory authority, particularly in your place of habitual residence, place of work or the place of a suspected infringement. The Bavarian State Office for Data Protection Supervision generally supervises businesses based in Bavaria.

To exercise your rights, email info@monatlich-store.com. We request only the information needed to identify the relevant data and, where necessary, verify your identity.

9. Changes

We will update this information when our shop’s functions or services change.

Last updated: 25 September 2026