Privacy Policy for Kiosaurus
Effective Date: 02/10/2025
At Kiosaurus (referred to as "we", "our", or "us"), we value the privacy of our customers and visitors. This Privacy Policy explains how we collect, use, and protect your personal data when you interact with our Etsy shop. As we are based in Germany, we comply with the General Data Protection Regulation (GDPR) and other relevant privacy laws.
1. Information We Collect
When you make a purchase from our Etsy shop, we collect the following personal information:
Name
Email address
Shipping address
Billing address (if applicable)
Payment information (processed by Etsy, not directly stored by us)
Order details (products purchased, quantity, price, etc.)
IP address (for security and analytics)
We also collect any other information you voluntarily provide, such as through direct messages or inquiries.
2. How We Use Your Information
We use the information we collect to:
Process and fulfill your orders
Communicate with you about your order and shipping
Provide customer support and respond to inquiries
Improve our products and services
Comply with legal obligations, such as tax reporting
Protect our legal rights and interests
We do not use your information for marketing purposes or share it with third parties for marketing.
3. Legal Basis for Processing Your Data
Under the GDPR, we rely on the following legal bases to process your personal data:
Contractual necessity: We process your personal data to fulfill our contract with you when you place an order.
Legal obligation: We may need to process your data to comply with legal requirements, such as tax laws.
Legitimate interests: We may process data for our legitimate interests in improving our services and preventing fraud, provided this does not override your rights and freedoms.
4. Data Sharing and Disclosure
We share your data with third parties only to the extent necessary for completing your order and fulfilling our contractual obligations. These third parties include:
Etsy: We use Etsy's platform to process payments, manage orders, and communicate with customers.
Shipping providers: We share your name and address with third-party shipping services (e.g., DHL, UPS) to ship your orders.
Payment processors: Etsy processes payments securely and stores payment information (such as credit card details) on its platform.
We do not sell, rent, or trade your personal data to any third parties for their marketing purposes.
5. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including compliance with legal, accounting, and reporting obligations. Generally, we retain order information for 7 years for accounting and tax purposes, in accordance with German law.
6. Your Rights Under GDPR
As a customer based in the European Union, you have the following rights under the GDPR:
Right to access: You can request a copy of your personal data that we hold.
Right to rectification: You can request that we correct any inaccuracies in your personal data.
Right to erasure: You can request that we delete your personal data, subject to certain legal exceptions.
Right to restrict processing: You can request that we limit the processing of your personal data.
Right to data portability: You can request that we provide your personal data in a machine-readable format.
Right to object: You can object to the processing of your personal data for legitimate interests or direct marketing.
To exercise any of these rights, please contact us using the information provided below.
7. Data Security
We take appropriate technical and organizational measures to protect your personal data from unauthorized access, disclosure, alteration, or destruction. However, please be aware that no method of transmission over the internet is 100% secure.
8. International Transfers of Data
Your personal data may be transferred outside the European Economic Area (EEA) to service providers such as Etsy, which may be based in countries outside the EEA. In such cases, we ensure that appropriate safeguards are in place to protect your data in accordance with the GDPR.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make changes, we will update the "Effective Date" at the top of this page. Please review this Privacy Policy regularly to stay informed about how we protect your personal data.
10. Contact Us
If you have any questions or concerns about how we process your personal data or if you wish to exercise any of your rights under the GDPR, please contact us at:
Kiosaurus
Selina Watanabe
Toepferstrasse 62
63674 Altenstadt
kiosaurusart@gmail.com