Protecting your personal data is very important to us. This Privacy Policy explains what personal data we collect, how we use it, and what rights you have under the GDPR.
1. Controller
Purchesa.de
Owner: Saira Sheraz (Sole Proprietorship)
Kiesweg 1
61440 Oberursel (Taunus)
Germany
Email: contact@purchesa.de
Website: https://www.purchesa.de
2. Collection and Storage of Personal Data
We may collect and process the following data:
- Name, billing and shipping address
- Email address, phone number
- Payment details (processed securely by providers such as Stripe or PayPal)
- IP address, browser information
- Cookies (for shopping cart, analytics, and functionality)
We collect and process personal data only when necessary for the purposes described below.
3. Purposes of Processing
We process your data for the following purposes:
- To process and fulfill orders and payments
- To provide customer service and support
- To send order confirmations and, where applicable, newsletters (only with your consent)
- To analyze website usage and improve our services
4. Legal Basis for Processing
Processing is carried out in accordance with:
- Art. 6(1)(a) GDPR – based on your consent
- Art. 6(1)(b) GDPR – for contract performance
- Art. 6(1)(c) GDPR – to comply with legal obligations
5. Cookies and Tracking
We use cookies to make our website easier to use and to improve performance:
- Necessary cookies – required for cart and login functionality
- Analytics cookies (e.g., Google Analytics) – used only with your consent
- Marketing cookies – only activated with your permission
The use of cookies is based on your consent in accordance with Art. 6(1)(a) GDPR, unless they are technically necessary (Art. 6(1)(f) GDPR).
You can manage or revoke your cookie preferences at any time via our cookie banner or in your browser settings. See our [Cookie Policy] for details.
6. Data Retention
We store your personal data only as long as necessary to fulfill the purposes described above or as required by law (e.g., statutory retention obligations under commercial and tax law).
7. Your GDPR Rights
Under the GDPR, you have the right to:
- Access your stored data (Art. 15 GDPR)
- Request correction of inaccurate data (Art. 16 GDPR)
- Request deletion of your data (Art. 17 GDPR)
- Restrict processing (Art. 18 GDPR)
- Object to data processing (Art. 21 GDPR)
- Request data portability (Art. 20 GDPR)
- Lodge a complaint with a supervisory authority (e.g., The Federal Commissioner for Data Protection and Freedom of Information – BfDI in Germany)
8. Sharing of Data with Third Parties
We share personal data only where necessary to fulfill our contract with you:
- Payment providers: Stripe, PayPal
- Shipping provider: DHL (including shipment tracking)
- Email/Newsletter providers: Mailchimp or equivalent services
Each of these providers maintains their own Privacy Policy. We do not sell your personal data to third parties.
9. Data Security
We use appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, or misuse.
10. International Data Transfers
Some of our service providers (e.g., Mailchimp, Stripe, PayPal) may process data outside the European Economic Area (EEA), including in the United States.
In such cases, we ensure that appropriate safeguards are in place, such as:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Binding Corporate Rules (BCRs)
- Adequacy decisions by the European Commission (where applicable)
We only work with providers who guarantee compliance with the GDPR and offer sufficient data protection standards.
11. Contact
For questions regarding data protection, please contact us at:
Purchesa.de – Sole Proprietorship
Owner: Saira Sheraz
Kiesweg 1
61440 Oberursel (Taunus)
Germany
Email: contact@purchesa.de