Privacy policy

Last updated: 12 September 2026

1. Controller and contact details

The controller responsible for the processing of personal data by JERSEYBOYS is:

Dennis Marcheel, trading as Marcheel Media & Merchandise
Steinkamp 2, 31303 Burgdorf, Germany
E-Mail: [email protected]
Telephone: 05136 / 8783994

For data protection enquiries, please use the contact details above. You may also use our email address [email protected] .

2. Shop operation, Shopify and technical access data

We operate our online shop using Shopify. The provider for our business is Shopify International Limited, The Sidings, 4th Floor, Grand Canal Quay, Dublin D02 E7K8, Ireland.

When you access and use the shop, the data processed includes your IP address, pages accessed, access time, browser and device information, and information needed for the cart, login and checkout. This enables us to provide the shop, process your entries, resolve errors and protect against misuse.

The legal basis for requested services and contract performance is Article 6(1)(b) GDPR. Processing for secure and functional operation is based on our legitimate interest under Article 6(1)(f) GDPR. Analytics and advertising functions that require consent are addressed separately in sections 8 to 10.

Shopify generally processes data on our behalf to operate our shop. For certain additional services and its own customer relationships, Shopify acts as a controller in its own right. Information about these roles and international processing is provided in Shopify's data processing terms.

Shopify Network Intelligence

We use Shopify Network Intelligence. Shopify processes information about interactions with our shop together with information about interactions with Shopify and other merchants. This supports additional functions to improve and personalise the shopping experience and may include advertising functions. Shopify acts as an independent controller for this additional processing. Processing that requires consent follows your choices in our cookie settings.

The Shopify Consumer Privacy Policy explains this processing. You can use the Shopify-Datenschutzportal to exercise your rights towards Shopify. You can change your consents for our shop using “Adjust cookie settings” in the footer.

Technical provision and Cloudflare

Shopify uses Cloudflare, Inc., USA, as a subprocessor for load balancing and protection against denial-of-service attacks. This involves processing the access data needed to transmit and secure a connection. The processing serves the technical provision of our shop and our legitimate interest in its availability and security under Article 6(1)(f) GDPR. The Shopify list of subprocessors identifies the companies involved and their tasks.

A Cloudflare page-performance measurement function is also integrated to identify loading and display problems. Performance reports transmit technical timing and display values, the page accessed and the referring page to Cloudflare. According to the provider, the function uses no cookies or persistent browser identifiers; the IP address arising during transmission is discarded at the processing data centre. Performance analytics requiring consent needs your consent under Article 6(1)(a) GDPR and, where applicable, section 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG) for access to your device. The basis for necessary security functions does not automatically extend to performance analytics. Details are provided in the description of Cloudflare's performance service.

3. Orders, customer accounts and business operations

We process contact, billing, delivery and order data, along with payment, delivery, return and refund information. A customer account also involves information needed for login and account management. The purpose is to prepare and perform your contract under Article 6(1)(b) GDPR. Statutory record-keeping and documentation obligations are fulfilled on the basis of Article 6(1)(c) GDPR.

We need information marked as required for the relevant process. Without it, we may be unable to process an order or delivery, for example. Any additional information is voluntary.

The information needed for order management, document creation, accounting, technical order integrations and digital provision is processed within the systems we use. Where necessary for the order, recipients include technical service providers, payment providers, commissioned manufacturing and shipping providers, and recipients involved in accounting or tax obligations. Data is shared for the relevant task in each case.

For digital services, we also process order and contact data needed to allocate and provide a file or download link. Technical security and transaction information may be processed to assess specific payment or misuse risks. Our own processing to prevent misuse is based on Article 6(1)(f) GDPR. The selected payment provider may also decide whether certain payment methods are available.

4. Payment processing

The information needed for payment is transmitted to the payment service you select, particularly the amount, order reference and necessary contact and payment information. The legal basis for our payment processing is Article 6(1)(b) GDPR. Payment providers may also process data as independent controllers, for example to meet legal obligations, verify identities and prevent fraud.

Shopify Payments, card payments and express payments

We use Shopify Payments from Shopify International Limited, The Sidings, 4th Floor, Grand Canal Quay, Dublin D02 E7K8, Ireland. Depending on the payment method, other payment processors, particularly Stripe, may be involved. Information is provided in the Shopify-Payments-Bedingungen, the overview of payment processors and the Stripe Privacy Policy.

Available payment methods are shown at checkout. Availability depends in part on the country, device and payment method. If you choose Shop Pay or an available wallet such as Google Pay or Apple Pay, the relevant wallet provider also processes information needed for login, authorisation and payment. Using such an account is your choice. For Shop and Shop Pay, the following also applies: Shopify Consumer Privacy Policy; for Google Pay, the Google Privacy Policy and for Apple services, the Apple Privacy Policy.

Klarna

If you choose a Klarna payment method, the necessary contact, order and payment data is transmitted to Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden. Depending on the payment method, Klarna may conduct identity, fraud and credit checks. Automated assessments may also determine whether a payment method is available. Information about the processing, credit reference agencies involved and your rights towards Klarna is provided in the Klarna Privacy Policy.

PayPal

If you pay with PayPal, PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg, receives the necessary contact, order and payment information. PayPal also processes data as an independent controller, particularly for payment and fraud prevention. Details are provided in the PayPal Privacy Policy.

Payment in advance by bank transfer

For a bank transfer, we receive payment information from the banks involved, particularly the sender, amount, payment reference and bank details transmitted. We use this to allocate and process your order. Production begins once receipt of payment has been confirmed.

5. Team products, personalisation, design and delivery

For custom products and design services, we process your specifications, logos, print files, names, artwork, approvals and related discussions. This policy covers such content insofar as it contains personal information. The purpose is to design, manufacture, provide and deliver the commissioned service. For our contractual partners' data, this is based on Article 6(1)(b) GDPR.

We use services including Globo Product Options to collect product options and personalisation. This processes the information you enter for the order and any uploaded files. ShipZip is integrated for shipping rules and cost calculation, processing the cart and destination information needed for this purpose. The processing supports your requested product configuration and contract performance.

Commissioned manufacturing, printing and direct-shipping providers receive the design, order and delivery information needed for their tasks. Carriers receive the recipient and address data needed for transport. Manufacturing and shipping may take place at different locations depending on the item. Information about transfers to third countries is provided in section 12.

We store logos, print files and design drafts on our work computer and in Microsoft OneDrive. Designs needed for manufacturing are also retained by the commissioned production provider. This supports ongoing team collaboration and possible repeat orders, so storage does not automatically end when one order is shipped. After an order is completed, further processing of personal content needed for collaboration and repeat orders is based on our legitimate interest under Article 6(1)(f) GDPR. Once these purposes cease and no other retention grounds apply, the personal content must be deleted. This does not restrict your rights, particularly your rights to object and request erasure.

When team representatives provide information about other people, we receive it through team or order coordination rather than directly from those individuals. This particularly includes names, requested prints, sizes and delivery details. We use it to allocate, manufacture and deliver the team order correctly, based on our legitimate interest and that of the customer under Article 6(1)(f) GDPR. Processing is limited to information needed for the order. Affected team members can also exercise their rights directly with us.

Please pass this information to the people affected by your team order. Our own obligation to inform those individuals under Article 14 GDPR remains unaffected.

6. Contact, forms, product complaints and Microsoft 365

When you contact us, we process your contact details, enquiry and any attached files. Contract-related enquiries are covered by Article 6(1)(b) GDPR; other enquiries by our legitimate interest in handling them under Article 6(1)(f) GDPR. Legally required processing and documentation are based on Article 6(1)(c) GDPR.

For product complaints, we process the order reference, description of the defect and submitted photographs in particular. For a withdrawal, we process your statement and its receipt to allocate, handle and confirm it. Shop forms and their automated acknowledgements are provided through Shopify. Contacting us, making a product complaint or withdrawing from a contract does not subscribe you to a newsletter. To withdraw, you can use our Online-Widerrufsformular .

We use Microsoft 365, including OneDrive, in our business account for business email and file storage. This processes messages, contact details, attachments and order files on the basis of the relevant communication or contractual purpose. Microsoft business services are subject to the corresponding data processing terms. For the EEA, Microsoft identifies Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland, as the data protection contact or controller for its own processing. Further information is provided in the Microsoft Privacy Statement.

7. Voluntary communication through Discord and Ticket Tool

You may voluntarily use Discord to coordinate with us. Our email address is available as an alternative. Your displayed username, messages and submitted files are processed to handle your enquiry or order on the legal bases stated in the contact section.

We use the Discord bot Ticket Tool for organisation. A private ticket channel is intended for you as its creator and for us. Open ticket channels remain available for ongoing team communication; closed channels are deleted. If content is also copied into our order records, further storage depends on the relevant order and documentation purpose. Deleting a channel does not automatically end separately required retention of order documents.

Discord and Ticket Tool participate in the technical provision of the service. Discord also processes platform data as an independent controller; for users in the European Economic Area, this is Discord Netherlands BV. Information about processing, international transfers and rights is provided in the Discord Privacy Policy and the Ticket Tool privacy information.

8. Email communication and purchase reminders

Order and service messages

Order, payment, delivery and support messages, as well as messages expressly requested by you, serve contract performance or handling your enquiry. This includes automated acknowledgements of product complaints and withdrawal statements. We process the recipient address, message content, order or enquiry reference and technical delivery information for these purposes. Depending on the circumstances, the legal basis is Article 6(1)(b) or (c) GDPR; general enquiries are handled on the basis of Article 6(1)(f) GDPR.

A service enquiry or acknowledgement of receipt does not constitute a subscription to advertising. Necessary order and service messages have a different purpose from purchase reminders.

Kauf-Erinnerungen

We use Shopify Messaging to send email reminders about purchases that have been started. This processes your email address, information about the started purchase, sending and delivery information, and consent and unsubscribe information. We do not currently send a regular newsletter.

Promotional reminders about a started but unfinished purchase require corresponding consent; the legal basis is Article 6(1)(a) GDPR. Simply entering an email address at checkout does not constitute marketing consent. You may withdraw consent at any time with effect for the future, particularly through the unsubscribe link in the promotional email or by emailing us.

Opens and link clicks

Where a message sent through Shopify contains measurement functions, open and click events may be recorded when an embedded tracking image loads or a suitably marked link is opened. These events can be linked to the message and, where applicable, your recipient address. The analysis helps assess the use of our emails and the effectiveness of purchase reminders. Shopify participates as the sending and analytics service provider.

Personalised performance measurement requires specific consent under Article 6(1)(a) GDPR; section 25(1) TDDDG also applies where access to the device requires consent. Such consent is voluntary and may be withdrawn by emailing us independently of an order. You can also stop further promotional emails through the unsubscribe link. Cookie choices in the shop apply to the browser and do not replace consent required for personalised measurement of email use. Details of the measurement functions are provided in Shopify's information on email analytics.

To respect an unsubscribe request, we retain the suppression information needed to prevent further unwanted promotional messages. It is not used for further promotional sending.

9. Cookies and your consent

We use cookies and similar technologies for shop functions, analytics and consent-based personalisation or marketing. Storing information on your device and accessing it is governed by section 25 TDDDG. Access strictly necessary to provide a service expressly requested by you is permitted without consent. Other access requiring consent is governed by section 25(1) TDDDG.

Subsequent processing of personal data also needs a legal basis under the GDPR. Consent-based analytics and marketing processing is covered by Article 6(1)(a) GDPR. Necessary contractual functions are based on Article 6(1)(b) GDPR; security and reliable operation may be based on Article 6(1)(f) GDPR.

Using “Adjust cookie settings” in the footer you can reopen your choices at any time, reject optional purposes or withdraw consent with effect for the future. Categories include technically necessary functions, personalisation, marketing and analytics. Your selection applies to the relevant browser. You may need to choose again after changing devices or deleting saved settings.

Cookies described by Shopify include “_tracking_consent” for consent choices, lasting one year; “cart” for the shopping cart, lasting two weeks; and “localization” for country selection, lasting one year. For analytics, Shopify describes cookies including “_shopify_s”, lasting 30 minutes from the last activity, and “_shopify_y”, lasting one year. Other analytics and marketing cookies have their own lifetimes depending on their function. Which cookies are needed and set depends on your use and choices. The Shopify cookie overview lists their names, purposes and lifetimes. A cookie's lifetime is distinct from the subsequent retention period of processed data.

10. Google Analytics, Google tags and other measurement functions

Google Analytics 4

We use Google Analytics 4 to analyse use of our shop. The provider for EEA users is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Google LLC in the USA may also be involved in processing.

Data processed may include page and product views, search and cart interactions, checkout and purchase events, technical browser and device information, location information and online identifiers. This helps us analyse shop use and performance and improve our offering. Consent-based analytics processing is governed by Article 6(1)(a) GDPR and corresponding device access additionally by section 25(1) TDDDG. Your choice is passed to the Google integration through Shopify's consent controls.

According to Google, IP addresses of visitors from the EU, Switzerland and the United Kingdom are used to derive location information and then deleted; they are not logged or stored for this purpose. This does not mean all analytics data is fully anonymous. Information is provided in Google's description of regional data processing.

In our Analytics property, the retention period for event data is 2 months and for user data 14 months. New user activity restarts the retention period for user data. These settings do not cover all aggregated standard reports. Google describes a two-year lifetime for the “_ga” analytics cookie; this lifetime is distinct from the Analytics retention periods above.

Google signals and the additional collection of user-provided data are disabled in our Analytics property. Use of Analytics data for advertising personalisation is disabled at property level for all regions.

Further information is provided in the Google Privacy Policy, the Google data processing terms and the information on data retention. You can withdraw your analytics consent through our shop's cookie settings.

Google product listings and additional measurement functions

Through the Google & YouTube integration, we synchronise product information with Google Merchant Center. Google tags also support measurement of shop interactions and the impact of product listings. Transmitting product data is distinct from processing personal usage data; measurements requiring consent follow your corresponding choice.

Another measurement function is configured through the integration of a commissioned manufacturing and direct-shipping provider. It concerns shop interactions and is assigned to analytics and marketing purposes in Shopify. This optional measurement is distinct from sharing order data needed for manufacturing and delivery. Consent-based processing is covered by Article 6(1)(a) GDPR and corresponding device access by section 25(1) TDDDG. You may reject these purposes in the cookie settings.

11. Retention, deletion and data protection enquiries

Retention depends on the purpose and type of data. Where no fixed period has already been specified, the following criteria apply:

  • Order and payment documents: The duration of contract performance plus applicable tax and commercial-law retention periods for the relevant document type. A statutory duty to retain records does not automatically justify retaining all other customer data for the same period.
  • Enquiries, product complaints and withdrawal statements: The time needed for handling and subsequent required documentation, particularly while claims remain open or proceedings are ongoing.
  • Team communication, logos and designs: The duration of collaboration and retention needed for repeat orders. Personal files are not deleted solely because an individual order is completed. What matters is whether they are still needed for further collaboration or another lawful retention ground applies.
  • Consent records and unsubscribe suppression data: The period needed to provide evidence or respect your unsubscribe request. Data is retained for this limited purpose.
  • Google-Analytics-Daten: The periods of 2 and 14 months stated in section 10, including the restart of the period upon new user activity described there.

Personal sending and analytics data from email communication is needed for as long as necessary to conduct that communication or fulfil a lawful analytics purpose. When that purpose ends or consent is withdrawn, further personalised analysis stops; any remaining statutory documentation and retention grounds are considered separately. For technical access data, the relevant question is whether it is still needed to provide the service, resolve errors or investigate specific security incidents. Personal data no longer needed for any lawful purpose is deleted or anonymised so that individuals can no longer be identified.

Data protection enquiries are handled by the controller named above. Any identity verification is limited to the information needed for secure identification. Deletion takes account of the affected systems and, where relevant, commissioned service providers. Records subject to statutory retention may have their further processing restricted instead of being deleted immediately. Backups and technical deletion cycles may mean not every copy is removed at once; they do not justify further use of deleted data for other purposes.

12. International data processing

The services described also process data outside the European Union and European Economic Area, particularly within the international infrastructure of Shopify, Google, Microsoft, Cloudflare and Discord. A European contractual partner or hosting location therefore does not mean all processing takes place exclusively in Europe.

The data processing terms of the individual services provide for the following transfer mechanisms:

  • Shopify: For intra-group transfers from the EEA to other Shopify entities covered by the data processing addendum, Shopify uses Binding Corporate Rules. For other transfers to countries without an adequate level of data protection, the terms provide additional safeguards, including EU Standard Contractual Clauses. In particular, see Annex C, section II B 8 of the Shopify-Datenverarbeitungsbedingungen.
  • Google: For the transfers of European data to Google LLC and covered US subsidiaries described by Google, Google uses the EU–US Data Privacy Framework. For covered transfers not based on this or another recognised mechanism, the Google-Datenverarbeitungsbedingungen provide relevant Standard Contractual Clauses in Annex 3 A. Details are provided in Google's information on international data transfers.
  • Microsoft 365: Microsoft's business terms incorporate EU Standard Contractual Clauses for the transfers they cover. This also applies to the Office 365 services named there. Details are provided in the Microsoft-Datenverarbeitungsbedingungen and the Microsoft statement on EU Standard Contractual Clauses.
  • Cloudflare: The Cloudflare-Datenverarbeitungsbedingungen provide Standard Contractual Clauses in section 6 for covered EU transfers; Module 2 or Module 3 applies depending on the customer's role. When Cloudflare acts as a Shopify subprocessor, contractual requirements within Shopify's processing chain also apply.
  • Discord: In its Privacy Policy under “International data transfers”, Discord describes the use of Standard Contractual Clauses, adequacy decisions and the EU–US Data Privacy Framework for covered transfers.
  • Contract manufacturing and direct shipping: The data processing terms of our commissioned provider incorporate Module 2 of the EU Standard Contractual Clauses for covered transfers to it as a processor in a third country. Module 3 is provided for corresponding onward transfers to subprocessors. The processing covered includes necessary names, contact and delivery details, and order content in particular. Information about transfers relating to your order and a copy of the relevant safeguards are available on request using our contact address.

An adequacy decision under Article 45 GDPR applies only within its respective scope. Under the EU–US Data Privacy Framework, it covers only appropriately certified US recipients and the processing included in their certification. For covered transfers without an adequacy decision, the contractual safeguards described provide protection under Article 46 or 47 GDPR. You may request information or a copy of the safeguards relevant to your data using our contact address.

For the payment services you select, the information linked in section 4 also applies. Commissioned manufacturing and shipping providers receive the order data needed to manufacture and deliver the goods; their location depends on the product and delivery destination.

13. Your rights

Subject to statutory conditions, you have the following rights in particular:

  • Access to your personal data under Article 15 GDPR;
  • Rectification of inaccurate data and completion of incomplete data under Article 16 GDPR;
  • Erasure under Article 17 GDPR;
  • Restriction of processing under Article 18 GDPR;
  • Data portability under Article 20 GDPR;
  • Rights concerning solely automated decisions with legal or similarly significant effects under Article 22 GDPR;
  • The right to lodge a complaint with a data protection supervisory authority under Article 77 GDPR, particularly in your place of residence, place of work or the place of the alleged infringement.

The supervisory authority responsible for our business is the State Commissioner for Data Protection of Lower Saxony at: Postfach 221, 30002 Hannover; email: [email protected].

Withdrawal of consent

You may withdraw consent at any time with effect for the future. This does not affect the lawfulness of processing before withdrawal. Depending on the process, use the cookie settings, unsubscribe link or our email address.

Right to object

Where processing is based on Article 6(1)(f) GDPR, you may object on grounds relating to your particular situation. We will then stop processing the data for that purpose unless overriding compelling legitimate grounds apply or processing serves the establishment, exercise or defence of legal claims.

You may object to direct marketing, including related profiling, at any time without giving reasons. Your data will then no longer be used for those purposes. Please send your objection to [email protected].