Privacy policy
Last updated: 25 September 2026
This privacy notice applies to the Designeria online shop on Shopify and the associated handling of enquiries and orders.
Version dated: 10 September 2026
1. Data controller and contact
Designeria e.U., owner Theresa Thaler, Erdbrustgasse 7/9, 1160 Vienna, Austria.
For questions about data protection or to exercise your rights, please contact:
Email: contact@designeria.at
Telephone: +43 676 432 6606
2. Visiting the shop and technical operation
When you visit the shop, we process, in particular, your IP address, the time of access, pages visited, device and browser information, and technically necessary cookie and session data. This is required to provide the website, shopping cart and checkout, and to maintain security and troubleshoot errors.
The legal bases are Article 6(1)(b) GDPR for contractual functions you request and Article 6(1)(f) GDPR for our legitimate interest in operating a secure and functional shop. Where required by law, access to your device for purposes that are not strictly necessary requires your consent under Section 165(3) of the Austrian Telecommunications Act 2021 (TKG 2021).
3. Enquiries, custom work and orders
We process the name, contact, billing and delivery details you provide; information about products, orders, payments and deliveries; and the contents of your messages. If you send us images, sketches or motifs for a custom piece, we use them to assess and handle your enquiry. Please do not send unnecessary personal data relating to other people.
We process this information to take steps at your request before entering into a contract and to perform the contract, under Article 6(1)(b) GDPR. Accounting and statutory record-keeping are based on Article 6(1)(c) GDPR. We rely on Article 6(1)(f) GDPR to prevent misuse and to establish, exercise or defend legal claims.
We cannot process an order without the information required to fulfil and deliver it. Additional information is voluntary and is not required for this purpose.
4. Shopify and customer accounts
We use Shopify for hosting, the online shop, checkout, order management and, where available, customer accounts. Shopify International Limited, Ireland, is particularly relevant for merchants in the European region.
Shopify processes some data on our behalf and is an independent controller for certain services it provides. Technical security checks and payment or fraud checks may also take place.
You can find details of Shopify’s own processing and your rights in its consumer privacy notice:
https://www.shopify.com/legal/privacy/consumers
Information about processing on our behalf is available in Shopify’s Data Processing Addendum:
https://www.shopify.com/legal/dpa
If you use a customer account, the identification and contact details required for the account are linked to your orders. Please keep your password and login codes confidential.
5. Payment processing and shipping
Depending on the payment method you choose at checkout, the information required for payment, contact, order and technical processing is shared with the relevant payment service provider.
Where available, these providers include Shopify Payments and its payment partners, PayPal, and the wallet and card providers involved in Apple Pay or Google Pay. For bank transfers, we process the payment reference, sender and transaction details supplied by the banks involved. We do not receive full credit card details.
The legal basis is performance of the contract under Article 6(1)(b) GDPR. Any independent statutory checks carried out by payment providers remain their responsibility.
We use Sendcloud B.V., Stadhuisplein 10, 5611 EM Eindhoven, the Netherlands, as a processor for shipping fulfilment, shipping labels and tracking. The order, contact and address details required for delivery are processed and passed on to the carrier handling the shipment.
The legal basis is Article 6(1)(b) GDPR.
Further information:
Sendcloud privacy notice:
https://account.sendcloud.com/privacy/
PayPal privacy notice:
https://www.paypal.com/at/legalhub/paypal/privacy-full
6. Withdrawal, returns and warranty claims
If you withdraw from a contract or make a complaint, we process your identification and contact details, contract and item information, your statement, any photos you choose to provide, and information about receipt, handling status and refunds.
The legal bases are Article 6(1)(b) and (c) GDPR. Where necessary to establish, exercise or defend legal claims, we process records under Article 6(1)(f) GDPR. We do not use this information for newsletters or advertising solely because you have withdrawn from a contract.
7. Newsletters, reviews and optional services
Signing up for marketing is voluntary and is not a condition of placing an order. If a newsletter is offered and you subscribe, we process your email address and the details of your subscription, confirmation and cancellation to send the newsletter and document your consent.
The legal basis is Article 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future by using the unsubscribe link or emailing us. Necessary order and contract messages are unaffected.
The footer contains a Trustpilot review counter provided by Trustpilot A/S, Pilestræde 58, 5th floor, 1112 Copenhagen K, Denmark. When the widget loads, it may transmit your IP address, browser and device information, the page visited and the time of access to Trustpilot.
We rely on our legitimate interest under Article 6(1)(f) GDPR to display independent reviews. If Trustpilot uses non-essential cookies or similar technologies, this will only take place with your consent under Article 6(1)(a) GDPR and Section 165(3) TKG 2021. You can withdraw consent through the cookie settings.
For the online withdrawal form, we use the “Revoq EU Withdrawal Button” app integrated with Shopify. If you submit the form, we process, in particular, your name, email address, order and item details, and any message you choose to include, so that we can handle and document your withdrawal.
The legal bases are Article 6(1)(b) and (c) GDPR. The technical service provider is engaged as a processor to the extent required.
A link to a social network only takes you to that network’s website when you open it. Such a link does not subscribe you to review invitations. For any other embedded analytics, advertising or review services, the information and choices provided in the consent management tool apply.
8. Recipients and data transfers
Where necessary, recipients include our shop, IT, communications, payment and shipping providers; our appointed tax and legal advisers; and public authorities where disclosure is required by law. Processors are engaged under Article 28 GDPR.
Shopify and other service providers may process data outside the European Economic Area. Transfers are made in accordance with Articles 44 et seq. GDPR, in particular on the basis of an applicable adequacy decision or appropriate safeguards such as EU Standard Contractual Clauses and, where necessary, supplementary protective measures.
Information about Shopify’s recipients and safeguards is available in the data processing agreement linked above. Please contact us if you need further information or a copy of the relevant safeguards.
9. How long we keep your data
We keep data only for as long as it is needed for the relevant purpose.
Accounting and invoice records are generally retained for seven years. Longer statutory periods may apply to ongoing proceedings.
Enquiries that do not result in a contract are deleted once they are no longer needed for their purpose or for necessary legal records. Contract, complaint and withdrawal records are retained in line with statutory record-keeping duties and the applicable limitation periods.
Records of consent may be retained after you unsubscribe for as long as necessary to demonstrate that consent was given or withdrawn. Service providers may also retain technical data for the periods required for security and operation.
10. Your rights
Subject to the legal requirements, you have the right to:
- access your personal data
- have it corrected
- have it erased
- restrict its processing
- data portability
You may withdraw consent at any time with effect for the future. This does not affect the lawfulness of processing carried out before withdrawal.
Right to object: If we process data on the basis of Article 6(1)(f) GDPR, you may object on grounds relating to your particular situation. You may object at any time to processing for direct marketing, including profiling related to that marketing.
You may lodge a complaint with a data protection supervisory authority, in particular the Austrian Data Protection Authority:
Please send requests to contact@designeria.at. To prevent unauthorised disclosure, we may ask you for reasonable proof of identity.
11. Automated decisions and changes
Information about any automated decisions made by a payment service provider you select is available in that provider’s privacy notice. If you have questions about an automated refusal, please contact us and the relevant provider.
We will update this notice if the services we use or our processing activities change.
