Privacy Policy
This policy explains what personal data we collect, why, and what your rights are under the GDPR.
Who we are
Wearable/IM is the data controller for personal data processed via this site. Reach us at support@wearable.im or through the Imprint page.
What we collect
- Account data: username, email, hashed password.
- Order data: shipping address, items bought, total paid, order status. Required to fulfil the contract.
- Payment data: handled directly by Stripe and PayPal; we only store the payment-provider name and a transaction id — never card numbers, CVCs, or PayPal credentials.
- Usage data: anonymous page views and session cookies needed to keep you signed in and to remember your cart.
Why we process it
- Contract (GDPR Art. 6(1)(b)): your account, cart, orders, fulfilment and customer support.
- Legal obligation (Art. 6(1)(c)): tax records, invoicing.
- Legitimate interest (Art. 6(1)(f)): platform security, fraud prevention, anonymous analytics.
- Consent (Art. 6(1)(a)): non-essential cookies and product-update emails — only after you opt in.
Who we share it with
- Print-on-demand fulfilment partner — name + address, so the order can be shipped.
- Stripe / PayPal — to process the payment.
- Email provider — to send order confirmations and shipping notifications.
- Hosting provider — to run the service.
We never sell your data. We sign a Data Processing Agreement (DPA) with every processor and keep an up-to-date list of named sub-processors.
How long we keep it
- Account data — until you delete the account.
- Order & invoicing data — 10 years (German tax law).
- Server logs — 30 days.
Your rights
You can at any time:
- request a copy of your data (Art. 15);
- correct it (Art. 16);
- delete it (Art. 17), as long as no statutory retention applies;
- object to processing (Art. 21);
- port your data to another service (Art. 20);
- complain to your data-protection authority (Art. 77).
To exercise any of these, email support@wearable.im.
International transfers
Some processors (e.g. Stripe, payment networks) may transfer data outside the EEA. Where they do, we rely on the EU Standard Contractual Clauses or an adequacy decision.
Cookies
See our separate Cookie Policy.