Privacy policy

Data Protection Declaration

1) Who We Are and How to Reach Us

1.1 Thank you for visiting our website — we're glad you're here. The sections below explain how we handle your personal data while you use this site. "Personal data" means any information that could be used to identify you.

1.2 The data controller responsible for processing on this website, as defined by the General Data Protection Regulation (GDPR), is Paul Hochreiter-Grundnig, Höhenstraße 53, 8047 Kainbach, Austria, Phone: +43 664 9274505, email: office@scarccity.com. A "controller" is the person or entity that, alone or together with others, decides why and how personal data is processed.

2) Cookies

To make browsing our site more useful and to enable certain features, we use cookies — small text files stored on your device. Some are cleared automatically once you close your browser ("session cookies"); others stay on your device for a set period to remember your preferences ("persistent cookies"). You can find how long each one lasts in your browser's cookie settings.

Where a cookie we set processes personal data, we rely on one of the following legal bases: Art. 6(1)(b) GDPR when it's needed to fulfil a contract, Art. 6(1)(a) GDPR where you've given consent, or Art. 6(1)(f) GDPR where we have a legitimate interest in making the site work well and providing a smooth, customer-friendly browsing experience.

You can configure your browser to notify you when cookies are set, decide case-by-case whether to accept them, or block them entirely. Note that some site features may not work properly without cookies.

3) Hosting and Content Delivery

Shopify — Our website is hosted, and its content served, through: Shopify International Limited, Victoria Buildings, 2nd floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland. Data is also transferred to Shopify Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada.

All data collected through our site is processed on this provider's servers. We have a data processing agreement in place with them that protects visitor data and bars unauthorized sharing with third parties. Transfers to Canada are covered by an adequacy decision from the European Commission, which confirms an adequate level of data protection there.

4) What We Collect When You Simply Browse

4.1 If you're only viewing our site — not registering or submitting information — we still automatically receive data your browser sends to our server (known as "server log files"). This includes:

  • The page you visited on our site
  • Date and time of access
  • Volume of data transferred (in bytes)
  • The site or link that referred you to us
  • Your browser
  • Your operating system
  • Your IP address (anonymized where applicable)

We process this under Art. 6(1)(f) GDPR, based on our legitimate interest in keeping the site stable and functioning well. We don't share or otherwise use this data, though we may review server logs after the fact if we have concrete reason to suspect misuse.

4.2 For security, our site uses SSL/TLS encryption to protect personal data and other sensitive information (such as orders or inquiries) in transit. You'll recognize an encrypted connection by the "https://" prefix and the padlock icon in your browser's address bar.

5) Processing Data to Fulfill Your Order

5.1 Where necessary to fulfill and deliver your order, we share the relevant personal data with our shipping partner and payment provider under Art. 6(1)(b) GDPR.

If we're contractually obligated to provide updates for goods with digital elements or digital products, we'll use the contact details you gave us at checkout (name, address, email) to notify you about upcoming updates within the legally required timeframe, based on our statutory duty under Art. 6(1)(c) GDPR. We limit use of this contact information strictly to that purpose.

To fulfill your order, we also work with the service providers listed below, who assist with all or part of executing the contract. Certain personal data is shared with them as described.

5.2 Sharing Data with Delivery Partners

  • Austrian Post — Austrian Post Aktiengesellschaft, Rochusplatz 1, 1030 Vienna, Austria. If you've given express consent during checkout, we share your email and/or phone number with them under Art. 6(1)(a) GDPR so they can coordinate a delivery time or send delivery notifications. Otherwise, we only share the recipient's name and delivery address, as needed for delivery, under Art. 6(1)(b) GDPR — in that case, delivery-time coordination or notification isn't possible. You can withdraw consent at any time, effective going forward, by contacting us or the provider directly.

5.3 Payment Service Providers

  • Apple Pay — Apple Distribution International, Hollyhill Industrial Estate, Hollyhill, Cork, Ireland. Choosing Apple Pay processes your payment through your iOS/watchOS/macOS device by charging a card stored in Apple Pay, secured by your device's built-in hardware/software protections and confirmed via a passcode plus Face ID or Touch ID. Your order and checkout details are sent to Apple in encrypted form; Apple re-encrypts this with a developer-specific key before forwarding it to your card's payment processor, so only the originating site can read the payment data. After payment, Apple returns your device account number and a one-time security code to confirm the transaction. This is processed under Art. 6(1)(b) GDPR for payment purposes only.

    Apple keeps anonymized transaction records — approximate amount, date/time, and whether it succeeded — with no personal identifiers, and uses this to improve Apple Pay and other products. When completing an Apple Pay purchase from Safari on a Mac using your iPhone or Apple Watch as the authorizing device, the devices communicate over an encrypted Apple channel, and Apple does not store this exchange in a personally identifiable form; you can turn this off under Wallet & Apple Pay settings on your iPhone by disabling "Allow payments on Mac." More on Apple Pay privacy: https://support.apple.com/en-gb/HT203027

  • Google Pay — Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland. Choosing Google Pay processes payment via the Google Pay app on an Android 4.4+ NFC-enabled device, charging a stored card or linked payment method (e.g., PayPal). Payments over €25 require device unlocking via face recognition, password, fingerprint, or pattern.

    Your checkout details are sent to Google, which returns a one-time transaction token to the site to verify payment — this token carries no actual payment card data. Google acts only as an intermediary; the transaction itself occurs directly between you and the site. This is processed under Art. 6(1)(b) GDPR.

    Google may also record and retain transaction-specific details for each purchase — date, time, amount, merchant name/location, item description, any photos attached to the transaction, buyer/seller names and emails, payment method, and any transaction notes or linked offers — under Art. 6(1)(f) GDPR, citing its interest in accounting accuracy, transaction verification, and maintaining Google Pay's functionality. Google may combine this with data from your use of other Google services.

    Google Pay terms: https://payments.google.com/payments/apis-secure/u/0/get_legal_document?ldo=0&ldt=googlepaytos&ldl=en Google Pay privacy notice: https://payments.google.com/payments/apis-secure/get_legal_document?ldo=0&ldt=privacynotice&ldl=en

  • Klarna — Klarna Bank AB, Sveavägen 46, 111 34 Stockholm, Sweden. If you choose a Klarna method where you pay upfront (e.g., card payment), your payment details (name, address, banking/card info, currency, transaction number) and order information are shared with Klarna under Art. 6(1)(b) GDPR, solely to process that payment.

    If you choose a Klarna method where Klarna extends you credit (invoice, installments, or direct debit), you'll be asked for additional details during checkout (full name, address, postcode, city, date of birth, email, phone, and possibly alternative payment info). We share this with Klarna under Art. 6(1)(f) GDPR, based on our legitimate interest in verifying customer creditworthiness, so Klarna can assess payment and default risk using your data alongside other order information (cart contents, invoice total, order and payment history).

    As part of that assessment, Klarna may also draw on identity and credit data from third-party credit bureaus under Art. 6(1)(f) GDPR — see the list here: https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_de/credit_rating_agencies

    The resulting credit report may include statistical probability scores derived from an established mathematical model, which factors in address data among other inputs. You may object to this processing at any time by contacting us or Klarna directly, though Klarna may still process your data where necessary to complete the payment.

  • PayPal — PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg. For upfront-payment PayPal methods, your payment and order details are shared with PayPal under Art. 6(1)(b) GDPR strictly to process payment.

    For PayPal methods involving advance payment by PayPal, you'll be asked for additional personal details at checkout (name, address, postcode, city, date of birth, email, phone, alternative payment info if relevant). We share this with PayPal under Art. 6(1)(f) GDPR to support our legitimate interest in assessing customer creditworthiness, so PayPal can evaluate payment/default risk using this data plus your order details.

    Any resulting credit report may include statistical score values from a recognized scoring methodology that factors in address data, among other things. You can object to this processing at any time by contacting us or PayPal, though PayPal may still process data where needed to complete a payment.

  • PayPal Checkout — This combines PayPal's own payment options with local third-party payment methods.

    For PayPal, PayPal Credit Card, PayPal Direct Debit, or "Pay Later" via PayPal, your payment data goes to PayPal (Europe) S.à r.l. et Cie, S.C.A. under Art. 6(1)(b) GDPR, limited to what's needed for payment processing.

    For the credit-based PayPal methods (credit card, direct debit, or Pay Later), PayPal may run a credit check, sharing your data with credit agencies under Art. 6(1)(f) GDPR based on its legitimate interest in assessing your creditworthiness; the outcome — potentially including statistical score values based on a recognized methodology and factors like address data — informs whether that payment method is offered to you. You may object by contacting PayPal directly, though it may still need to process your data to complete payment.

    If you choose "purchase on account" via PayPal, your data is first sent to PayPal, then forwarded to Ratepay GmbH, Franklinstraße 28-29, 10587 Berlin, to execute payment (Art. 6(1)(b) GDPR). Ratepay independently runs its own identity and credit check and may share your data with credit agencies for that purpose under Art. 6(1)(f) GDPR. Agencies Ratepay may use are listed here: https://www.ratepay.com/legal-payment-creditagencies/

    For local third-party payment methods, your data first goes to PayPal (Art. 6(1)(b) GDPR), which then forwards it — depending on which method you pick — to: Apple Pay (Apple Distribution International, Cork, Ireland), Google Pay (Google Ireland Limited, Dublin, Ireland), Klarna (Klarna Bank AB, Stockholm, Sweden), iDeal (Currence Holding BV, Amsterdam, Netherlands), Bancontact (Bancontact Payconiq Company, Brussels, Belgium), BLIK (Polski Standard Płatności sp. z o.o., Warsaw, Poland), EPS (PSA Payment Services Austria GmbH, Vienna, Austria), MyBank (PRETA S.A.S, Paris, France), or Przelewy24 (PayPro SA, Poznań, Poland).

    PayPal's privacy policy: https://www.paypal.com/de/legalhub/paypal/privacy-full?locale.x=en_DE

  • Shopify Payments — Shopify International Limited, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland. For upfront-payment methods through Shopify Payments, your payment and order data (name, address, banking/card info, currency, transaction number) is shared with Shopify under Art. 6(1)(b) GDPR, limited to what payment processing requires.

  • Instant Transfer via Klarna — Klarna Bank AB (publ), Sveavägen 46, 11134 Stockholm, Sweden. Same handling as other upfront-payment methods: your payment and order data is shared under Art. 6(1)(b) GDPR, limited to what's needed to process payment.

  • Stripe — Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. Same handling as other upfront-payment methods: your payment and order data is shared under Art. 6(1)(b) GDPR, limited to what's needed to process payment.

6) When You Get in Touch With Us

6.1 Judge.me — Judge.me Ltd., c/o Buckworths, 2nd Floor, 1-3 Worship Street, London, England, EC2A 2AB, UK. For review reminders, we send your email address and any relevant customer data to this provider, but only with your explicit consent under Art. 6(1)(a) GDPR, so they can email you a reminder to leave a review. You can withdraw consent at any time, going forward, by telling us or the provider. We have a data processing agreement with them protecting visitor data and prohibiting sharing with third parties. Transfers to their location are covered by a European Commission adequacy decision.

6.2 Reviews.io — REVIEWS.io 2020 GmbH, Skalitzer Str. 104, 10997 Berlin. Same arrangement as above: your email and relevant data are shared only with your explicit consent (Art. 6(1)(a) GDPR) for review reminders; you can withdraw consent anytime; we have a data processing agreement protecting your data from third-party sharing.

6.3 ShopVote — Blickreif GmbH, Schulstraße 46, 80634 Munich. Same arrangement: email and relevant data shared only with your explicit consent (Art. 6(1)(a) GDPR) for review reminders, revocable at any time, under a data processing agreement barring third-party disclosure.

6.4 Trusted Shops — Trusted Shops AG, Subbelrather Str. 15c, 50823 Cologne, Germany. Same arrangement: email and relevant data shared only with your explicit consent (Art. 6(1)(a) GDPR) for review reminders, revocable anytime. Here, we're jointly responsible with Trusted Shops for this processing under Art. 26 GDPR — the joint controllership agreement is viewable at: https://help.etrusted.com/hc/de/articles/4402587369105-Vertrag-%C3%BCber-die-gemeinsame-Verantwortlichkeit-nach-DSGVO

6.5 Trustpilot — Trustpilot A/S, Pilestræde 58, 1112 Copenhagen, Denmark. Same arrangement: email and relevant data shared only with your explicit consent (Art. 6(1)(a) GDPR) for review reminders, revocable at any time, under a data processing agreement barring third-party disclosure.

6.6 When you reach out to us — by contact form or email — we collect the personal data involved. What exactly we collect via a contact form is shown on that form. We use this solely to respond to you, maintain contact, and handle the related administrative work, based on our legitimate interest under Art. 6(1)(f) GDPR (or Art. 6(1)(b) GDPR if your message is aimed at forming a contract). We delete this data once your inquiry is fully resolved — unless a legal retention obligation requires us to keep it longer.

7) Creating a Customer Account

Under Art. 6(1)(b) GDPR, we continue collecting and processing whatever personal data is needed when you open a customer account with us; the exact fields required appear on the account creation form. You can delete your account at any time by messaging the contact address listed above. Once deleted, your data is erased too, provided all related contracts are fully completed, no legal retention rules apply, and we have no remaining legitimate interest in keeping it.

8) Using Your Data for Direct Marketing

8.1 Email Newsletter — Signing up for our email newsletter means we'll periodically send you updates about our offers. Only your email address is required; any other details you provide are optional and used to personalize communications. We use double opt-in: after signing up, you'll get a confirmation email, and we only start sending newsletters once you click the confirmation link.

Clicking that link gives us your consent under Art. 6(1)(a) GDPR. At signup, we also log your IP address (as assigned by your ISP) plus the date and time, so we can trace any future misuse of your email address. This registration data is used solely for newsletter marketing. You can unsubscribe anytime via the newsletter's unsubscribe link or by messaging us directly. Once you unsubscribe, we delete your address from our mailing list immediately — unless you've separately agreed to further use, or another legally permitted use applies that's disclosed elsewhere in this policy.

8.2 Klaviyo — Klaviyo Inc., 125 Summer Street, Floor 6, Boston, MA, 02110, USA. We share your newsletter signup data with Klaviyo, who sends the newsletter on our behalf, based on our legitimate interest in effective, user-friendly email marketing under Art. 6(1)(f) GDPR.

With your explicit consent under Art. 6(1)(a) GDPR, Klaviyo also measures newsletter performance using tracking pixels — open rates and interactions with content — which involves collecting device data (view time, IP address, browser, OS), analyzed separately from other records. You can withdraw consent to this tracking anytime, effective going forward.

We have a data processing agreement with Klaviyo protecting visitor data from third-party disclosure. For transfers to the US, Klaviyo participates in the EU-US Data Privacy Framework, meeting the European standard of protection under a European Commission adequacy decision.

8.3 WhatsApp Newsletter — Subscribing to our WhatsApp newsletter means periodic updates about our offers via WhatsApp, using only your mobile number.

To subscribe, save our number to your phone's contacts and message us "Start" on WhatsApp. Sending that message gives us consent under Art. 6(1)(a) GDPR to use your data for the newsletter, and we'll add you to our list.

We use this data solely for newsletter marketing. Unsubscribe anytime by messaging "Stop" via WhatsApp — your number is then removed from our list immediately, unless you've agreed to further use or another disclosed legal basis applies.

Note that WhatsApp accesses the address book on the device we use to send the newsletter, and automatically sends any stored phone numbers to a Facebook server in the US. To limit this, we keep a dedicated device whose address book contains only the WhatsApp contact info of our newsletter subscribers — meaning everyone in that address book has already consented to sharing their WhatsApp number from their own contacts under Art. 6(1)(a) GDPR by agreeing to WhatsApp's terms when they first used the app. People who don't use WhatsApp, or haven't contacted us there, are not affected.

For details on WhatsApp's own data handling and your rights and settings, see: https://www.whatsapp.com/legal/privacy-policy-eea?lang=en

As part of this, data may reach Meta Platforms Inc. servers in the US. Transfers there are covered under the EU-US Data Privacy Framework and a corresponding European Commission adequacy decision.

9) Retargeting and Advertising Tracking

TikTok Pixel — TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland. If you arrived at our site via an ad on TikTok's platform, we can measure that ad's effectiveness using cookies or similar technology (tracking pixels, web beacons, pings, HTTP requests).

This involves reading certain device/browser data, including your IP address where relevant, to track actions we've defined (completed purchases, leads, on-site searches, product page views). This lets us build behavioral statistics for visitors coming from ads, which we use to refine our advertising.

All of this — particularly any cookie that reads device information — only happens with your explicit consent under Art. 6(1)(a) GDPR, which you can withdraw anytime via our cookie consent tool. We have a data processing agreement with TikTok protecting visitor data from unauthorized third-party disclosure.

10) Tools and Other Notes

Our site uses a "cookie consent tool" to properly obtain your consent for cookies and related applications that legally require it. It appears as an interactive interface when you visit, letting you tick boxes to consent to specific cookies or cookie-based services.

Cookies or services needing consent only load once you've checked the corresponding box — nothing is set on your device without that consent.

The tool itself sets a technically necessary cookie just to remember your preferences; this generally doesn't involve personal data. Where personal data (like an IP address) is processed to record, assign, or log your cookie choices, we rely on Art. 6(1)(f) GDPR — our legitimate interest in running a legally compliant, user-specific, and user-friendly consent system — as well as Art. 6(1)(c) GDPR, since we're legally required to make non-essential cookies conditional on your consent.

For more on the tool's operator and its settings, see the interface directly on our site.

11) Your Rights

11.1 Data protection law gives you the following rights regarding how we handle your personal data:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure / "right to be forgotten" (Art. 17 GDPR)
  • Right to restrict processing (Art. 18 GDPR)
  • Right to be informed (Art. 19 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to withdraw consent (Art. 7(3) GDPR)
  • Right to lodge a complaint (Art. 77 GDPR)

11.2 RIGHT TO OBJECT

WHERE WE PROCESS YOUR PERSONAL DATA BASED ON A BALANCING OF INTERESTS IN OUR FAVOR (LEGITIMATE INTEREST), YOU MAY OBJECT AT ANY TIME, GOING FORWARD, ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION.

IF YOU OBJECT, WE WILL STOP THAT PROCESSING — UNLESS WE CAN DEMONSTRATE COMPELLING, PROTECTION-WORTHY GROUNDS THAT OUTWEIGH YOUR INTERESTS, RIGHTS, AND FREEDOMS, OR THE PROCESSING IS NEEDED TO ESTABLISH, EXERCISE, OR DEFEND LEGAL CLAIMS.

WHERE WE PROCESS YOUR DATA FOR DIRECT MARKETING, YOU MAY OBJECT AT ANY TIME, USING THE SAME PROCESS DESCRIBED ABOVE.

IF YOU OBJECT TO MARKETING USE, WE WILL STOP THAT PROCESSING FOR MARKETING PURPOSES.

How Long We Keep Your Data

Retention periods depend on the legal basis, the purpose of processing, and any applicable statutory retention rules (e.g., commercial or tax record-keeping requirements).

Data processed based on your explicit consent (Art. 6(1)(a) GDPR) is kept until you withdraw that consent.

Data processed to meet a legal or similar obligation (Art. 6(1)(b) GDPR) is routinely deleted once the relevant retention period ends, provided it's no longer needed to fulfill or initiate a contract and we have no further legitimate reason to keep it.

Data processed under our legitimate interest (Art. 6(1)(f) GDPR) is kept until you object under Art. 21(1) GDPR — unless we can show compelling, protection-worthy grounds that outweigh your rights and interests, or the data is needed for legal claims.

Data processed for direct marketing under Art. 6(1)(f) GDPR is kept until you object under Art. 21(2) GDPR.

Unless stated otherwise elsewhere in this declaration for a specific situation, we delete stored personal data once it's no longer needed for the purpose it was originally collected or processed for.