Privacy policy


Privacy Policy

1. General Information

Unless otherwise stated below, the provision of your personal data is neither legally nor contractually required, nor necessary for the conclusion of a contract.
You are not obliged to provide personal data. Failure to provide such data has no consequences unless otherwise specified in the individual processing operations described below.

“Personal data” means any information relating to an identified or identifiable natural person.


2. Server Log Files

You can visit our website without providing personal information.

Each time our website is accessed, usage data is transmitted by your browser and stored in server log files. These may include:

  • name of accessed page

  • date and time of access

  • IP address (anonymized/shortened)

  • amount of data transferred

  • browser type/version

  • operating system

  • referrer URL

  • internet service provider

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in ensuring technical stability and security).


3. Contact

Controller

Heinz-Peter Hebbel
Im Auchtert 32
72186 Empfingen
Germany
Phone: +49 7720 941558
E-mail: info@hps-sport-shop.de

Contact by Email

When you contact us by email, we process your personal data (name, email address, message content) solely for the purpose of handling your request.

Legal bases:

  • Art. 6(1)(b) GDPR — for pre-contractual inquiries

  • Art. 6(1)(f) GDPR — for general inquiries (legitimate interest: responding to your request)

We delete the data once your request has been fully processed unless statutory retention obligations apply.


4. Customer Accounts & Orders

Customer Account

When creating a customer account, we process your personal data as provided.

Legal basis: Art. 6(1)(a) GDPR (consent).
You may withdraw your consent at any time; the legality of prior processing remains unaffected.

Order Processing

Personal data is processed only insofar as necessary to:

  • fulfil your order

  • communicate with you

  • process payments

  • provide customer service

Legal basis: Art. 6(1)(b) GDPR

Data may be transferred to:

  • shipping providers

  • dropshipping partners

  • payment providers

  • IT service providers

  • the merchandise management system plentymarkets

Transfer is limited to the minimum necessary.


5. Newsletter

We send newsletters only with your explicit consent.

Legal basis: Art. 6(1)(a) GDPR

You may unsubscribe at any time via the link in the newsletter or by contacting us directly.


6. Merchandise Management – plentymarkets

To fulfil your order, we use the system:

plentysystems AG
Johanna-Waescher-Straße 7
34131 Kassel, Germany

Legal basis: Art. 6(1)(b) GDPR


7. Payment Providers

We offer several payment methods.
Personal data may be transferred to the following providers to process payments:


PayPal (including credit cards via PayPal Checkout)

Provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg
Legal basis: Art. 6(1)(b) GDPR

Privacy Policy:
https://www.paypal.com/de/webapps/mpp/ua/privacy-full


Mollie (credit card, Apple Pay, Google Pay, etc.)

Provider: Mollie B.V., The Netherlands
Legal basis: Art. 6(1)(b) GDPR

Privacy Policy:
https://www.mollie.com/en/privacy


Amazon Pay

Provider: Amazon Payments Europe s.c.a., Luxembourg

Privacy Policy:
https://pay.amazon.com/help/201212490


Klarna

Provider: Klarna Bank AB (publ), Sweden

Privacy Policy:
https://www.klarna.com/international/privacy-policy/


Prepayment / Bank Transfer

When choosing prepayment, no data is transferred to external payment service providers.


8. Cookies

We use cookies to operate essential functions of the website.

Technically Necessary Cookies

Cookies are used to ensure:

  • a functional website

  • shopping cart features

  • login/session handling

  • secure operation

Legal basis:

  • Section 25(2) TDDDG

  • Art. 6(1)(f) GDPR (legitimate interest in functional website operations)

You can manage or delete cookies via your browser settings.


9. Analytics & Tracking

Google Analytics 4

Provider: Google Ireland Limited, Dublin

Collected data may include:

  • shortened IP address

  • device information

  • browser type

  • visited pages

  • interaction data

  • location approximations

  • purchasing activity

Legal basis:

  • Section 25(1) TDDDG (consent for cookies)

  • Art. 6(1)(a) GDPR (consent)

Information:
https://policies.google.com/privacy

Data may be transferred to the USA under the EU–U.S. Data Privacy Framework.


10. Uptain – Customer Recovery Tool

Provider: uptain GmbH, Wuppertal, Germany

Data processed (if consent is given):

  • mouse movements

  • device information

  • IP address

  • click paths

  • interaction data

Legal basis:

  • Section 25(1) TDDDG (cookie consent)

  • Art. 6(1)(a) GDPR

Privacy Policy:
https://uptain.de/datenschutz/


11. Google Tag Manager

The Google Tag Manager loads and manages tracking scripts but stores no personal data itself.


12. Cloudflare CDN

Provider: Cloudflare Inc., USA

Purpose:

  • performance optimisation

  • defense against cyberattacks

  • secure content delivery

Data processed:

  • IP address

  • system configuration

  • server log data

Legal basis: Art. 6(1)(f) GDPR

Privacy Policy:
https://www.cloudflare.com/privacy-policy/

Data transfers to USA under the EU–U.S. Data Privacy Framework.


13. AI Chatbot – Voiceflow

Provider: Voiceflow Inc., Canada / USA

Processed data:

  • your chat input (messages, questions, text)

  • technical metadata (timestamp, browser, anonymized IP)

Purpose:

  • automated assistance

  • customer support

  • providing product information

Legal bases:

  • Art. 6(1)(f) GDPR (legitimate interest in efficient communication)

  • Art. 6(1)(a) GDPR (where explicit consent is required)

Privacy Policy:
https://www.voiceflow.com/privacy

Data transfers secured by EU Standard Contractual Clauses (SCCs).


14. Rights of Data Subjects

You have the following rights under the GDPR:

  • Right of access (Art. 15 GDPR)

  • Right to rectification (Art. 16 GDPR)

  • Right to erasure (Art. 17 GDPR)

  • Right to restriction of processing (Art. 18 GDPR)

  • Right to data portability (Art. 20 GDPR)

  • Right to object (Art. 21 GDPR)

You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR).


15. Storage Period

We store personal data:

  • for the duration of the contractual relationship

  • within statutory retention periods (e.g. commercial & tax law)

  • afterwards, data is deleted unless further processing is legally permitted or consented to


Last updated: 25 November 2025