Privacy policy
Privacy Policy
1. General Information
Unless otherwise stated below, the provision of your personal data is neither legally nor contractually required, nor necessary for the conclusion of a contract.
You are not obliged to provide personal data. Failure to provide such data has no consequences unless otherwise specified in the individual processing operations described below.
“Personal data” means any information relating to an identified or identifiable natural person.
2. Server Log Files
You can visit our website without providing personal information.
Each time our website is accessed, usage data is transmitted by your browser and stored in server log files. These may include:
name of accessed page
date and time of access
IP address (anonymized/shortened)
amount of data transferred
browser type/version
operating system
referrer URL
internet service provider
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in ensuring technical stability and security).
3. Contact
Controller
Heinz-Peter Hebbel
Im Auchtert 32
72186 Empfingen
Germany
Phone: +49 7720 941558
E-mail: info@hps-sport-shop.de
Contact by Email
When you contact us by email, we process your personal data (name, email address, message content) solely for the purpose of handling your request.
Legal bases:
Art. 6(1)(b) GDPR — for pre-contractual inquiries
Art. 6(1)(f) GDPR — for general inquiries (legitimate interest: responding to your request)
We delete the data once your request has been fully processed unless statutory retention obligations apply.
4. Customer Accounts & Orders
Customer Account
When creating a customer account, we process your personal data as provided.
Legal basis: Art. 6(1)(a) GDPR (consent).
You may withdraw your consent at any time; the legality of prior processing remains unaffected.
Order Processing
Personal data is processed only insofar as necessary to:
fulfil your order
communicate with you
process payments
provide customer service
Legal basis: Art. 6(1)(b) GDPR
Data may be transferred to:
shipping providers
dropshipping partners
payment providers
IT service providers
the merchandise management system plentymarkets
Transfer is limited to the minimum necessary.
5. Newsletter
We send newsletters only with your explicit consent.
Legal basis: Art. 6(1)(a) GDPR
You may unsubscribe at any time via the link in the newsletter or by contacting us directly.
6. Merchandise Management – plentymarkets
To fulfil your order, we use the system:
plentysystems AG
Johanna-Waescher-Straße 7
34131 Kassel, Germany
Legal basis: Art. 6(1)(b) GDPR
7. Payment Providers
We offer several payment methods.
Personal data may be transferred to the following providers to process payments:
PayPal (including credit cards via PayPal Checkout)
Provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg
Legal basis: Art. 6(1)(b) GDPR
Privacy Policy:
https://www.paypal.com/de/webapps/mpp/ua/privacy-full
Mollie (credit card, Apple Pay, Google Pay, etc.)
Provider: Mollie B.V., The Netherlands
Legal basis: Art. 6(1)(b) GDPR
Privacy Policy:
https://www.mollie.com/en/privacy
Amazon Pay
Provider: Amazon Payments Europe s.c.a., Luxembourg
Privacy Policy:
https://pay.amazon.com/help/201212490
Klarna
Provider: Klarna Bank AB (publ), Sweden
Privacy Policy:
https://www.klarna.com/international/privacy-policy/
Prepayment / Bank Transfer
When choosing prepayment, no data is transferred to external payment service providers.
8. Cookies
We use cookies to operate essential functions of the website.
Technically Necessary Cookies
Cookies are used to ensure:
a functional website
shopping cart features
login/session handling
secure operation
Legal basis:
Section 25(2) TDDDG
Art. 6(1)(f) GDPR (legitimate interest in functional website operations)
You can manage or delete cookies via your browser settings.
9. Analytics & Tracking
Google Analytics 4
Provider: Google Ireland Limited, Dublin
Collected data may include:
shortened IP address
device information
browser type
visited pages
interaction data
location approximations
purchasing activity
Legal basis:
Section 25(1) TDDDG (consent for cookies)
Art. 6(1)(a) GDPR (consent)
Information:
https://policies.google.com/privacy
Data may be transferred to the USA under the EU–U.S. Data Privacy Framework.
10. Uptain – Customer Recovery Tool
Provider: uptain GmbH, Wuppertal, Germany
Data processed (if consent is given):
mouse movements
device information
IP address
click paths
interaction data
Legal basis:
Section 25(1) TDDDG (cookie consent)
Art. 6(1)(a) GDPR
Privacy Policy:
https://uptain.de/datenschutz/
11. Google Tag Manager
The Google Tag Manager loads and manages tracking scripts but stores no personal data itself.
12. Cloudflare CDN
Provider: Cloudflare Inc., USA
Purpose:
performance optimisation
defense against cyberattacks
secure content delivery
Data processed:
IP address
system configuration
server log data
Legal basis: Art. 6(1)(f) GDPR
Privacy Policy:
https://www.cloudflare.com/privacy-policy/
Data transfers to USA under the EU–U.S. Data Privacy Framework.
13. AI Chatbot – Voiceflow
Provider: Voiceflow Inc., Canada / USA
Processed data:
your chat input (messages, questions, text)
technical metadata (timestamp, browser, anonymized IP)
Purpose:
automated assistance
customer support
providing product information
Legal bases:
Art. 6(1)(f) GDPR (legitimate interest in efficient communication)
Art. 6(1)(a) GDPR (where explicit consent is required)
Privacy Policy:
https://www.voiceflow.com/privacy
Data transfers secured by EU Standard Contractual Clauses (SCCs).
14. Rights of Data Subjects
You have the following rights under the GDPR:
Right of access (Art. 15 GDPR)
Right to rectification (Art. 16 GDPR)
Right to erasure (Art. 17 GDPR)
Right to restriction of processing (Art. 18 GDPR)
Right to data portability (Art. 20 GDPR)
Right to object (Art. 21 GDPR)
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR).
15. Storage Period
We store personal data:
for the duration of the contractual relationship
within statutory retention periods (e.g. commercial & tax law)
afterwards, data is deleted unless further processing is legally permitted or consented to