Privacy policy
PRIVACY POLICY
1. Controller and Scope
The controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws as well as other data protection regulations is:
Nayif Abdirabo
Rothmundstraße 3
80337 Munich, Germany
Email: hello@anothercomb.com
This Privacy Policy informs you about the collection and processing of your personal data when you visit or shop on our website and online store, as well as about your rights as a data subject.
2. Hosting via Shopify
2.1 Hosting & Platform
Our online store is operated via the Shopify service, provided by Shopify International Limited, Victoria Buildings, 2nd Floor, 1–2 Haddington Road, Dublin 4, D04 XN32, Ireland (hereinafter “Shopify”).
Shopify provides us with the e-commerce platform on which we offer our products.
All data you enter on our website is stored on Shopify’s servers.
We have concluded a data processing agreement with Shopify pursuant to Art. 28 GDPR, under which Shopify is obliged to comply with the GDPR and protect your data. For more information, please see Shopify’s Privacy Policy.
3. Collection and Storage of Personal Data, Type and Purpose of Their Use
3.1 Server Log Files
Each time our website is accessed, our hosting provider (Shopify) automatically collects data and information from the computer system of the accessing device. This includes:
- Name of the accessed page/file (URL)
- Date and time of access
- Amount of data transferred
- Browser type and version
- Operating system used
- Referrer URL (previously visited page)
- Hostname (IP address in anonymized form)
This data is processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR) to enable the delivery of our website and ensure the stability and security of our service. The log files are generally automatically deleted after 2 weeks, unless there is a legal obligation to retain them for a longer period.
4. Contact
4.1 Email Contact
If you contact us by email (e.g., at hello@anothercomb.com), the personal data you transmit will be stored to process your inquiry. The legal bases are either Art. 6(1)(b) GDPR (pre-contractual or contractual communication) or Art. 6(1)(f) GDPR (legitimate interest in answering inquiries).
4.2 Contact Form (if used)
If you use a contact form on our website, we collect the data entered there (e.g., name, email address, message) for the purpose of handling your request. The legal bases match those in section 4.1.
Your data will be deleted once processing is no longer required for the contact request and there are no statutory retention requirements preventing deletion.
5. Newsletter via Klaviyo
5.1 General Information
You have the option to subscribe to our newsletter, which provides you with regular information about offers and news concerning our online store. For newsletter management and delivery, we use Klaviyo, provided by Klaviyo, Inc., 125 Summer St., Floor 6, Boston, MA 02110, USA (“Klaviyo”).
5.2 Registration and Double Opt-In
Registration for our newsletter proceeds via the double opt-in method. After signing up, you will receive an email in which you must confirm your subscription.
When you register for the newsletter, we store your email address as well as the registration time and IP address to provide proof of lawful consent.
5.3 Data Processing by Klaviyo
Your data is stored on Klaviyo’s servers and used exclusively on our behalf for sending the newsletter as well as for statistical analysis. We have concluded a data processing agreement with Klaviyo pursuant to Art. 28 GDPR.
5.4 Performance Measurement
Our newsletters may contain what is known as a “web beacon” (tracking pixel) that is retrieved when the email is opened. In doing so, technical information (e.g., IP address, browser, time) is collected. It is also recorded whether the newsletter was opened and which links were clicked. This data is not intended to personally identify you but serves solely to improve and optimize our newsletter offerings.
5.5 Withdrawal of Consent
The legal basis for sending the newsletter is your consent (Art. 6(1)(a) GDPR).
You can withdraw your consent at any time, for example, via the “unsubscribe” link in each newsletter or by emailing hello@anothercomb.com.
For more information on data processing by Klaviyo, please refer to Klaviyo’s Privacy Policy.
6. Cookies and Tracking Technologies
6.1 General Information About Cookies
We use cookies on our website to make our services more user-friendly, effective, and secure. Cookies are small text files that are stored on your device.
- Strictly Necessary (Essential) Cookies: Necessary to enable basic functions (e.g., shopping cart, checkout).
- Analytics/Performance Cookies: Used to statistically evaluate the use of our website in order to optimize it.
- Marketing/Targeting Cookies: Allow interest-based advertising to be shown to you.
6.2 Legal Basis
- For strictly necessary cookies, we rely on our legitimate interest (Art. 6(1)(f) GDPR).
- For all other (analytics/marketing) cookies, we obtain your consent (Art. 6(1)(a) GDPR). This consent is given via our cookie banner.
6.3 Withdrawal and Objection
You can withdraw your consent at any time via our cookie banner or delete/block cookies in your browser settings. Please note that this may limit the functionality of our website.
7. Order Processing in the Online Store (Shopify)
7.1 Data Categories and Purposes of Processing
When you place an order in our online store, we process the following data:
- First name, last name
- Billing and shipping address
- Email address
- Payment information (bank details, credit card data, PayPal account, etc.)
- Telephone number (optional)
Processing is for the purpose of contract fulfillment (Art. 6(1)(b) GDPR):
- To carry out your order
- For billing and delivery
- For customer communication (e.g., shipping status)
7.2 Data Sharing
- Shipping Service Providers: To deliver your goods, we share necessary data (name, shipping address, possibly email/phone) with shipping and logistics companies.
- Payment Service Providers: As part of payment processing, you submit your payment data directly to the respective provider (e.g., PayPal, Stripe, Apple Pay), which is responsible for processing your personal data.
- Tax and Legal Requirements: If legally required, we may be obligated to disclose data to tax authorities or other governmental agencies.
8. Integration of External Services & Content
8.1 Social Media Links / Plug-ins
Our website may contain links (and possibly plug-ins) to social networks such as Facebook, Instagram, or Pinterest. A connection to the servers of the respective provider is only established once you click such a link. Please note that we have no influence on the type and scope of data processing by these external providers.
Depending on implementation, the legal basis may be your consent (Art. 6(1)(a) GDPR) or our legitimate interest (Art. 6(1)(f) GDPR).
For more information, please refer to the providers’ respective privacy policies.
8.2 Analytics Tools
If we use analytics services (e.g., Google Analytics, internal Shopify analytics) to understand and optimize user behavior on our website, this is based on either your consent (Art. 6(1)(a) GDPR) or our legitimate interest (Art. 6(1)(f) GDPR). You can find more details in our cookie banner or a separate section on our website.
9. Storage Period and Erasure
Personal data is only stored for as long as is necessary for the stated purpose or as required by statutory (in particular commercial and tax) retention periods. After the purpose ceases to apply or these periods expire, the data will be deleted or blocked in accordance with legal requirements.
10. Your Rights as a Data Subject
- Right of Access (Art. 15 GDPR): You can request information at any time about the personal data we process about you.
- Right to Rectification (Art. 16 GDPR): You can request the correction of inaccurate data.
- Right to Erasure (Art. 17 GDPR): You have the right to request the deletion of your personal data, provided there are no legal retention obligations.
- Right to Restriction of Processing (Art. 18 GDPR): You can request the restriction of processing if certain conditions are met.
- Right to Data Portability (Art. 20 GDPR): You can ask us or a third party to provide you with a copy of your personal data in a structured, commonly used, and machine-readable format.
- Right to Object (Art. 21 GDPR): You can object to the processing of your data if it is based on our legitimate interest (e.g., direct marketing).
- Right to Withdraw Your Consent (Art. 7(3) GDPR): You can withdraw any consent you have given at any time with effect for the future.
- Right to Lodge a Complaint with a Supervisory Authority (Art. 77 GDPR): You can file a complaint with a relevant data protection authority if you believe that the processing of your data violates the GDPR. In Bavaria, for example, this is the Bavarian State Office for Data Protection Supervision.
You can exercise your rights by contacting us, for example by email at hello@anothercomb.com.
11. Data Security
We employ technical and organizational security measures (e.g., TLS encryption when accessing the website, access restrictions) to protect your data from manipulation, loss, destruction, or unauthorized access. Our security measures are continually improved in line with technological developments.
12. Changes and Updates to This Privacy Policy
We reserve the right to adapt this Privacy Policy if necessary, so that it always meets current legal requirements or to reflect changes to our services. The most current version is always available on our website.
13. Legal Notice (Imprint, Pursuant to § 5 TMG / § 55 RStV)
Nayif Abdirabo
Rothmundstraße 3
80337 Munich, Germany
Email: hello@anothercomb.com
Sole Proprietorship, Authorized Representative: Nayif Abdirao, VAT ID No. 143/500/00837
Date of this Privacy Policy: 01.03.2024