Privacy policy

Privacy Policy (English Translation)

Last updated: 04 June 2026

1. Data Controller

Timeless Events
Sara Bogsan Nogueira
Rembergstraße 57
58095 Hagen
Germany
Email: info@timelessevents.co

2. General Information

Timeless Events operates this online shop on Shopify. This privacy policy describes how we collect, use, and share personal data when you visit, use, or place an order on our website.

3. Data We Collect

We process the following personal data:

— Contact data (name, address, email, phone number)
— Payment data (processed via payment providers)
— Order and transaction data
— Account information
— Communication data (e.g., inquiries)
— Device and usage data (IP address, browser, usage)
— For digital products: access data (download timestamps, delivery confirmation)

4. Sources of Data

Your data is collected:

— directly from you (e.g., orders, contact requests)
— automatically via our website (cookies, log files)
— via service providers (e.g., payment providers, Shopify)

5. Purposes of Processing

We use your data for:

— Contract fulfillment (orders, delivery, payment)
— Provision of digital content (download links, access data)
— Customer service and communication
— Review requests after purchase (via Judge.me)
— Security and fraud prevention
— Improvement of our services
— Marketing (only with consent)

6. Legal Basis (Art. 6 GDPR)

Processing is based on:

— Art. 6(1)(b) GDPR (contract performance)
— Art. 6(1)(a) GDPR (consent, e.g., newsletter, cookies)
— Art. 6(1)(f) GDPR (legitimate interest, e.g., security, optimization, review requests)

7. Data Sharing

We share data with:

— Shopify (hosting and shop system)
— Payment providers (e.g., PayPal, Shopify Payments)
— Shipping providers (e.g., DHL)
— Judge.me (review platform: name, email, order data for review requests)
— IT and marketing service providers
— TikTok (Pixel, Events API, and Advanced Matching for advertising measurement)

These processes are partially carried out under data processing agreements pursuant to Art. 28 GDPR.

7.1 TikTok Pixel, Events API, and Advanced Matching

We use the TikTok Pixel and TikTok Events API (via the official TikTok Shopify app) to measure and optimize advertising campaigns and deliver relevant ads.

For this purpose, the following data may be transmitted to TikTok during certain website interactions (e.g., page views, search, add to cart, checkout, purchase):

— Events: page views (View Content), search, “Add to Cart”, “Initiate Checkout”, “Add Payment Information”, purchase completion (Complete Payment), registration completion, etc.
— Identifiers for Advanced Matching (where technically possible, hashed): email address, phone number, first name, last name, city, state, postal code, country.

This data allows TikTok to match website visitors with TikTok users and improve ad effectiveness and personalization.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in effective online advertising and measurement). Where non-essential tracking cookies or similar technologies are used, consent is obtained under Art. 6(1)(a) GDPR via the cookie banner.

Data may be transferred to TikTok Technology Ltd. (Ireland) or affiliated companies. Processing in third countries (outside the EU) may occur. Further information is available in TikTok’s privacy policy and TikTok Business Products (Data) Terms.

You may object to personalized advertising in your TikTok account settings.

7.2 ParcelWILL (Shipment Tracking)

We use ParcelWILL (formerly ParcelPanel) by CWILL Tech Inc. for shipment tracking.

Data shared: name, delivery address, email address, order number, and shipping tracking information.

Processing is carried out under a data processing agreement pursuant to Art. 28 GDPR. Data transfers outside the EU/EEA may occur. ParcelWILL has appointed an EU representative (EDPO) and relies on Standard Contractual Clauses.

Privacy policy: https://www.parcelpanel.com/privacy-policy/

7.3 Shipping Providers and Shipping Label Apps

For shipping labels, we use easyDHL, easyDPD (247apps), and the official Shopify app Post & DHL Shipping.

Data transmitted: name, delivery address, order number.

DHL and DPD act as independent data controllers in this context. Processing is based on Art. 6(1)(b) GDPR (contract performance).

DHL privacy policy: https://www.dhl.de/de/privatkunden/hilfe-kundenservice/datenschutz.html
DPD privacy policy: https://www.dpd.com/de/de/datenschutz/

7.4 Pinterest

We use Pinterest as a sales channel. If you arrive at our shop via Pinterest or complete a purchase there, your data is processed according to Pinterest Ireland Ltd.’s privacy policy. Pinterest acts as an independent controller.

Privacy policy: https://policy.pinterest.com/de/privacy-policy

7.5 Shopify Messaging (Email and SMS Marketing)

We use Shopify Messaging for marketing emails and SMS messages. Processing is based on consent (Art. 6(1)(a) GDPR).

Data processed: name, email address, and/or phone number of customers who opted in.

Consent can be withdrawn at any time via the unsubscribe link in each message.

7.6 Shopify Forms (Waitlist)

Used for waitlists for not yet released products. Data collected: name and email address.

Legal basis: consent (Art. 6(1)(a) GDPR) and processing under Shopify’s data processing agreement. Consent can be withdrawn by contacting info@timelessevents.co.

7.7 EU Withdrawal Button

We use the EU Withdrawal Button (euwiderrufsbutton.de) for handling statutory withdrawal rights.

Data processed: name, email address, order reference.

Legal basis: Art. 6(1)(c) GDPR (legal obligation) and Art. 28 GDPR (data processing agreement).

More information: https://euwiderrufsbutton.de

8. Use of Shopify

Our shop is operated via Shopify International Ltd. Shopify processes data on our behalf and may transfer data to third countries (e.g., Canada, USA). Transfers are based on appropriate safeguards (Standard Contractual Clauses).

More information: https://www.shopify.com/legal/privacy

9. Judge.me

We use Judge.me for product reviews. After purchase, Judge.me may send automated review requests via email.

Data processed: name, email address, order reference (used only for this purpose).

More information: https://judge.me/privacy

10. Cookies

We use cookies:

— Strictly necessary cookies for website functionality
— Optional cookies (analytics/marketing) only with consent
— TikTok Pixel and Events API

You can change settings at any time via the cookie banner. Further details are available in our Cookie Policy.

11. Data Retention

We store personal data only as long as necessary:

— Order and invoice data: up to 10 years (legal obligation)
— Customer data: until deletion
— Inquiries: after processing
— Digital access data: up to 2 years

12. Your Rights

You have the following rights:

— Access (Art. 15 GDPR)
— Rectification (Art. 16 GDPR)
— Erasure (Art. 17 GDPR)
— Restriction (Art. 18 GDPR)
— Data portability (Art. 20 GDPR)
— Objection (Art. 21 GDPR)

Contact: info@timelessevents.co

13. Right to Lodge a Complaint

You may lodge a complaint with a supervisory authority:

State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (LDI NRW)
https://www.ldi.nrw.de

14. Data Security

We implement appropriate technical and organizational measures in accordance with Art. 32 GDPR.

15. International Data Transfers

Data may be processed outside the EU (e.g., Shopify or Judge.me). Transfers are carried out in accordance with legal requirements based on Standard Contractual Clauses.

16. Changes

We reserve the right to update this privacy policy. The current version applies.

17. Contact

Email: info@timelessevents.co
Address: Rembergstraße 57, 58095 Hagen, Germany