Privacy policy
Draft – this text has not been finally reviewed by a lawyer yet.
This English version is provided for your convenience only. The legally binding text is the German version (Datenschutzerklärung).
This policy explains which personal data we process when you visit our online shop and when you place an order, for what purposes, on what legal basis and for how long. It also explains your rights.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is Roman Sukhostavskyi. Postal address and contact details (e-mail) can be found in the legal notice. We have not appointed a data protection officer, as there is no legal obligation to do so.
2. Summary
- We do not use cookies for visitors and customers.
- We do not use tracking or advertising pixels and do not embed content from third-party providers (e.g. fonts, maps, videos) in our pages.
- Your cart is stored only in your own browser.
- Our own visitor statistics do not store IP addresses or any identifiers that could be used to recognise you.
- We only process data about you personally when you place an order, contact us or withdraw from a contract.
3. Provision of the website and server log files
Each time you access our pages, our server processes technically necessary data: your IP address, date and time of access, the address accessed, the status code, the amount of data transferred and information about the browser and operating system used, insofar as your browser transmits it.
The purpose is to deliver the pages and to ensure secure and stable operation, in particular to detect and defend against attacks and errors. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in a secure and functioning online shop.
We delete server log files after 14 days, unless a specific security incident requires longer retention until it has been resolved.
To protect against misuse (e.g. mass automated order attempts), we limit the number of certain requests per IP address. For this purpose the IP address is kept only in working memory, is not stored permanently and is discarded after 15 minutes at most. The legal basis is also Art. 6(1)(f) GDPR.
4. Hosting
Our online shop runs on a server of Hostinger International Limited (Larnaca, Cyprus). Server location: Hostinger (Rechenzentrum in Frankfurt am Main, Deutschland). The provider processes the data listed in section 3 and the data of your order exclusively on our behalf under a data processing agreement pursuant to Art. 28 GDPR.
5. No cookies, cart in your browser
We do not set cookies for visitors and customers. Only in the internal administration area of the shop, which is accessible to us as the operator alone, a technically necessary cookie is used for login.
To keep your cart while you browse, we store the selected motifs, sizes and quantities in your browser's local storage (localStorage). This information does not leave your device until you go to checkout. The storage is strictly necessary to provide the cart you have expressly requested (§ 25(2) no. 2 TDDDG). You can empty the cart at any time or delete the data via your browser settings.
Campaign parameters: if you reach our shop through an advertising or referral link, the address may contain campaign parameters (e.g. `utm_source`, `utm_campaign`). We store these parameters together with the name of the referring website and the first page you opened in the session storage of the open browser tab and remove them from the address bar; they are deleted when the tab is closed. If you place an order, they are stored once together with your order so that we can evaluate which advertising leads to which designs. No cookies, IP addresses, browser fingerprints or personal profiles are created, and we do not use any third-party services for this. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in evaluating our own advertising).
6. Own visitor statistics without cookies
To understand which motifs are popular and where the ordering process is abandoned, we count individual events: viewing a product page, adding to the cart, starting checkout and a completed order. Only the type of event, the motif concerned, the language, the page accessed without parameters, a rough device class (e.g. “mobile” or “desktop”) and the time are stored.
The statistics run exclusively on our own server. We store neither your IP address nor the full browser identifier, set no cookies and assign no identifiers. The stored events therefore cannot be attributed to any person. Insofar as your IP address is briefly processed for technical transmission, this is based on Art. 6(1)(f) GDPR; our legitimate interest lies in improving our offer.
7. Orders
When you place an order, we process the data required to conclude and perform the purchase contract: first and last name, delivery address, e-mail address, ordered items with size and quantity, prices and shipping costs, the time of the order and of acknowledging the terms and conditions, the payment status with the related references of the payment service provider, and the processing and shipping status including a tracking link. The legal basis is Art. 6(1)(b) GDPR.
You receive e-mails about your order (order confirmation, start of production, dispatch). These e-mails are part of performing the contract; we do not send you advertising.
You can check the status of your order via a link containing a randomly generated access key. We store only an irreversible hash of this key.
Providing this data is necessary for an order; without it we cannot conclude or perform the contract.
8. Payment processing via Stripe
After clicking “Place order and pay” you are redirected to a payment page of Stripe Payments Europe, Limited (Dublin, Ireland). For this purpose we transmit your e-mail address, the order number, the ordered items and the amount payable to Stripe. You enter your payment details (e.g. card number) directly with Stripe; we do not receive them, only the information whether the payment was successful and a payment reference.
Stripe processes this data on our behalf to handle the payment. For its own purposes, in particular fraud prevention and compliance with legal obligations (e.g. anti-money laundering), Stripe is itself the controller. The legal basis for the transmission is Art. 6(1)(b) GDPR, for fraud prevention Art. 6(1)(f) GDPR. On the Stripe payment page, Stripe's privacy policy applies: stripe.com/privacy. Stripe may use its own cookies or similar technologies there.
Stripe may also transfer data to affiliated companies in the USA, in particular Stripe, Inc. Stripe is certified under the EU-U.S. Data Privacy Framework; to that extent an adequacy decision of the European Commission exists for the USA (Art. 45 GDPR). In addition, Stripe uses EU standard contractual clauses (Art. 46(2)(c) GDPR).
If you choose a payment method of another provider during payment (e.g. PayPal, Klarna, Apple Pay or Google Pay), the data required for this payment is additionally transmitted to that provider, which processes it under its own responsibility in accordance with its privacy policy. For purchase on invoice or instalments, the provider may carry out an identity and credit check; the provider informs you about this during payment.
9. Production and shipping
Your order is produced and shipped on our behalf by Shirtigo GmbH, Winterstraße 2a, 50354 Hürth, Germany. For this purpose we transmit your first and last name, delivery address, e-mail address, the order number and the ordered items with size and quantity to Shirtigo. Shirtigo processes this data as our processor pursuant to Art. 28 GDPR. The legal basis is Art. 6(1)(b) GDPR.
For delivery, the carrier Deutsche Post / DHL (Deutschland), Asendia / GLS (Österreich) sowie der von Shirtigo jeweils beauftragte Versanddienstleister (übrige EU-Lieferländer) receives your name and delivery address and processes this data under its own responsibility to carry out the delivery. The legal basis is Art. 6(1)(b) GDPR.
10. E-mail delivery
We send e-mails about your order and about a withdrawal via Zoho Mail (Zoho Corporation B.V., Niederlande; Rechenzentren in der EU). The provider processes your e-mail address and the content of the message on our behalf pursuant to Art. 28 GDPR.
E-mails you send to hallo@illegaltowear.com are forwarded to our mailbox via the e-mail forwarding service of our domain registrar Namecheap, Inc. (Phoenix, USA). Namecheap processes your e-mail address and the content of the message on our behalf pursuant to Art. 28 GDPR; transfers to the USA are based on the EU standard contractual clauses or the EU-US Data Privacy Framework, insofar as the provider is certified.
11. Contact by e-mail
If you write to us by e-mail, we process your e-mail address, your name and the content of your message to handle your request. If the request concerns an order or a possible contract, the legal basis is Art. 6(1)(b) GDPR, otherwise Art. 6(1)(f) GDPR; our legitimate interest lies in answering your request.
12. Withdrawal via the online function
If you withdraw from a contract using the “Withdraw from contract” button, we process your name, the order number provided, your e-mail address, an optional comment and the date and time of receipt. We need this data to match the withdrawal, confirm its receipt to you and process the reversal. The legal basis is Art. 6(1)(c) GDPR in conjunction with § 356a BGB and Art. 6(1)(b) GDPR.
13. Retention
We store personal data only for as long as necessary for the respective purpose or as required by statutory retention obligations.
- Orders whose payment was not completed are deleted after 30 days.
- We need the data of completed orders to perform the contract and for possible claims for defects, which as a rule become time-barred two years after delivery.
- Irrespective of this, we retain documents where tax and commercial law so require: accounting records, such as order and payment data, for eight years (§ 147(1) no. 4, (3) AO; for invoices § 14b UStG), and business letters received and sent, such as order confirmations, e-mails about your order and withdrawal statements, for six years (§ 147(1) nos. 2, 3, (3) AO). These periods start at the end of the calendar year in which the document was created. The legal basis is Art. 6(1)(c) GDPR.
- E-mail enquiries unrelated to an order are deleted once your request has been dealt with, unless a retention obligation applies.
- For server log files and misuse limitation, see section 3.
After these periods expire, the data is deleted.
14. No automated decision-making
We do not make decisions based solely on automated processing, including profiling (Art. 22 GDPR). For checks by payment providers, see section 8.
15. Your rights
Under the GDPR you have the following rights vis-à-vis us:
- access to the data stored about you (Art. 15 GDPR),
- rectification of inaccurate data (Art. 16 GDPR),
- erasure of your data, unless a retention obligation prevents it (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- objection to processing based on Art. 6(1)(f) GDPR on grounds relating to your particular situation (Art. 21 GDPR).
To exercise your rights, an informal message to the e-mail address given in the legal notice is sufficient.
16. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. The supervisory authority responsible for us is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Heilbronner Straße 35, 70191 Stuttgart, Germany (postal address: Postfach 10 29 32, 70025 Stuttgart), www.baden-wuerttemberg.datenschutz.de
17. Version
Version of this privacy policy: September 2026. We will update it if our offer or the legal situation changes.