Privacy Policy
Last updated: April 2026
1. Data Controller
kulfi (operated by [Your Name / Company Name]), Hafenstrasse 42, 20459 Hamburg, Germany ("kulfi", "we", "us") is the data controller responsible for processing your personal data in accordance with the EU General Data Protection Regulation (GDPR).
Contact: hello@kulfi.store
2. Data We Collect
We collect the following categories of personal data:
- Account data: Name, email address, phone number when you create an account
- Order data: Shipping address, billing address, order history, payment information (processed by Stripe)
- Technical data: IP address, browser type, device information collected automatically
- Usage data: Pages visited, products viewed, search queries via analytics tools
- Communication data: Messages when you contact us via email or forms
3. How We Use Your Data
- Processing and fulfilling your orders
- Managing your account and providing customer support
- Sending order confirmations, shipping updates, and delivery notifications
- Sending marketing communications (only with your explicit consent)
- Improving our website, products, and services
- Fraud prevention and security
4. Legal Basis (GDPR Art. 6)
We process your data based on:
- Contract performance (Art. 6(1)(b)) — to fulfill your orders
- Consent (Art. 6(1)(a)) — for marketing emails and cookies
- Legal obligation (Art. 6(1)(c)) — tax and accounting requirements
- Legitimate interest (Art. 6(1)(f)) — fraud prevention, service improvement
5. Payment Processing
Payments are processed by Stripe, Inc. We never store your full credit card details on our servers. Stripe's privacy policy applies to payment data. Stripe is PCI DSS Level 1 certified.
6. Data Sharing
We share your data only with:
- Shipping providers (DHL, Hermes) — to deliver your orders
- Stripe — for payment processing
- Analytics tools — Google Analytics (anonymized)
- Email service — for transactional and marketing emails
We do not sell your personal data to third parties.
7. Data Retention
- Account data: retained until you delete your account
- Order data: retained for 10 years (German tax law requirement)
- Marketing consent: until withdrawn
- Analytics data: anonymized after 14 months
8. Your Rights (GDPR)
You have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Restrict processing
- Data portability
- Object to processing
- Withdraw consent at any time
- Lodge a complaint with the Hamburg data protection authority (HmbBfDI)
9. Cookies
We use essential cookies for website functionality (cart, session) and optional analytics cookies with your consent. You can manage cookie preferences through our cookie banner or browser settings.
10. Contact
For privacy-related inquiries: hello@kulfi.store
kulfi, Hafenstrasse 42, 20459 Hamburg, Germany