Privacy Policy
Revised Privacy Policy (Kinuaya 01.01.2026)
1. Controller
The data controller for this website is:
KINUAYA
Owner: Gloria Todorovic
Hermann-Metzger-Straße 19
88045 Friedrichshafen
Germany
Email: gloriatodorovic@kinuaya.com
2. General information on data processing
We take the protection of your personal data very seriously. Your data will be processed exclusively on the basis of legal provisions (in particular the GDPR and the BDSG). In this privacy policy, we inform you about the nature, scope and purpose of the collection and use of personal data when visiting our online shop.
3. Hosting
Our online shop is operated via Shopify. Shopify is a service of Shopify Inc., 151 O’Connor Street, Ground Floor, Ottawa, ON K2P 2L8, Canada. Shopify provides us with the e-commerce platform through which we offer our products.
The data is stored on servers in Canada and possibly in other countries. Canada is recognized by the EU Commission as a country with an adequate level of data protection. A data processing agreement exists with Shopify in accordance with Art. 28 GDPR.
4. Webhosting
Our domain hosting is provided by GoDaddy.com, LLC, 2155 E GoDaddy Way, Tempe, AZ 85284, USA. Personal data is only transferred to the USA on the basis of appropriate guarantees in accordance with Art. 46 GDPR, e.g., through standard contractual clauses.
5. Collection and processing of personal data
The following data may be processed during the order process or when using our shop:
-
Name, address, email address, phone number
-
Payment data (via third-party providers)
-
IP address
-
Device and browser information
-
Order data
-
Newsletter subscription data
Processing is based on:
-
Art. 6 para. 1 lit. b GDPR (contract fulfillment / order processing)
-
Art. 6 para. 1 lit. f GDPR (legitimate interest in the secure, stable and economic provision of our online offer)
6. Payment service providers
We use the following service providers for payment processing:
-
PayPal (PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg)
-
Klarna (Klarna Bank AB, Sweden)
-
Stripe (Stripe Payments Europe Ltd., Ireland)
-
Apple Pay (Apple Inc., USA)
Payment processing takes place directly through the respective providers. We do not receive complete payment data (e.g., credit card numbers), but only information for transaction approval.
7. Newsletter
We send our newsletter via Seguno (Seguno Software, Inc., USA). Registration takes place via the double opt-in procedure.
Data processing is based on your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time, e.g., via the unsubscribe link in the newsletter.
8. Web analysis with Google Analytics
This website uses Google Analytics, a web analysis service of Google Ireland Ltd. The collected data (e.g., IP address, user behavior, device type) is used to evaluate and improve our offer. The IP address is anonymized.
The use takes place only with your consent in accordance with Art. 6 para. 1 lit. a GDPR in conjunction with Section 25 para. 1 TTDSG (if cookies/tracking technologies are used).
You can revoke or adjust your consent at any time via the cookie settings.
9. Social Media and Communication
Our website may include functions from the following third-party providers:
-
Instagram (Meta Platforms Ireland Ltd.)
-
WhatsApp (Meta Platforms Ireland Ltd.)
If you interact with these platforms or share our content via corresponding plugins, personal data may be transferred to these providers.
10. International Data Transfer
Since some of our service providers (e.g., Shopify, Google, Seguno, Meta, Apple) are located in third countries (especially the USA), data transfers outside the European Economic Area may occur. This only happens in compliance with the GDPR and with suitable safeguards such as standard contractual clauses according to Art. 46 GDPR.
11. Your Rights
You have the right at any time:
-
to information about your stored data (Art. 15 GDPR)
-
to rectification of inaccurate data (Art. 16 GDPR)
-
to erasure of your data (Art. 17 GDPR)
-
to restriction of processing (Art. 18 GDPR)
-
to data portability (Art. 20 GDPR)
-
to object to processing (Art. 21 GDPR)
-
to withdraw granted consent (Art. 7 para. 3 GDPR)
To exercise your rights, please contact: gloriatodorovic@kinuaya.com
(or alternatively: datenschutz@kinuaya.com, if you wish to use a separate data protection email address)
12. Data Retention Period
Personal data will only be stored for as long as necessary to fulfill the respective purposes or as required by statutory retention periods.
13. Changes to this Privacy Policy
We reserve the right to adapt this Privacy Policy to changed legal requirements or new functions of our online shop. The current version can always be found on this page.