Privacy policy
Last updated: 30 August 2026
What personal data we process when you use this shop, why we are allowed to, and who else gets to see it.
Who is responsible
We have not appointed a data protection officer. We are not required to: that duty starts at 20 people permanently processing personal data (§ 38 BDSG).
What we collect, and why
Visiting the site
- Data
- IP address, time of request, page requested, browser and operating system
- Purpose
- Delivering the site and keeping it secure. Our hosting providers log this.
- Legal basis
- Art. 6 (1)(f) GDPR — our legitimate interest in operating the site securely.
- Kept for
- Deleted or anonymised by our hosting providers after a short period.
Your account
- Data
- Email address and a password, which is only ever stored as a hash
- Purpose
- Letting you sign in, see your orders and reset your password.
- Legal basis
- Art. 6 (1)(b) GDPR — performing the contract you entered into.
- Kept for
- Until you ask us to delete the account.
Your orders
- Data
- Products, amounts, currency and exchange rate, order status, your email address and the Discord tag you give us
- Purpose
- Handling the order, delivering it, and answering questions about it later.
- Legal basis
- Art. 6 (1)(b) GDPR — performing the contract.
- Kept for
- Order and invoice data is kept for up to 10 years. We are required to: §§ 147 AO and 257 HGB. During that time it is locked away and only used for tax and accounting.
Payments
- Data
- Payment method, amount, transaction reference and payment status
- Purpose
- Matching payments to orders and proving that you paid.
- Legal basis
- Art. 6 (1)(b) and (c) GDPR — performing the contract and meeting our accounting duties.
- Kept for
- Same retention as order data.
We never see or store your card number. Card details are entered on the payment provider’s own page, and we only ever receive a reference and whether the payment succeeded.
Who else sees your data
We use service providers to run the shop. They process data on our instructions under data processing agreements (Art. 28 GDPR), except the payment providers, who decide on their own processing for fraud prevention and their own legal duties.
Supabase
Database and sign-in
Account data, orders, payment records.
Vercel
Hosting for the website
Server logs from your visit.
Railway
Hosting for our backend
Server logs, and the data processed while handling your order.
Stripe Payments Europe, Ltd. (Ireland)
Card payments
Only if you pay by card: your payment data, entered directly on Stripe's page.
PayPal (Europe) S.à r.l. et Cie, S.C.A. (Luxembourg)
PayPal payments
Only if you pay with PayPal: your payment data, handled by PayPal.
Resend (Plus Five Five, Inc.)
Sending your order confirmation
Your email address and the contents of the confirmation — what you ordered, the amount, and the order reference. We are legally required to send this confirmation (§ 312f BGB), so there is no version of an order without it.
Discord Netherlands B.V.
How we deliver
We message you on the Discord tag you gave us. Discord is a separate controller for that conversation and has its own privacy policy.
If you pay by bank transfer, your bank passes your name and account details to our bank as part of the transfer. That is how transfers work; we cannot avoid it.
Where your data actually is
The short version: your account, your orders and your payments stay in Germany. Your order confirmation email does not — it is sent and stored in the United States.
Below is where each piece goes, and what makes the transfer lawful where it leaves the EU. Checked on 5 September 2026.
Supabase
Your account, your orders, your payment records
Frankfurt am Main, Germany (region eu-central-1)
Our contract is with Supabase Pte. Ltd. in Singapore — a country without an EU adequacy decision and not certified under the Data Privacy Framework. The data itself stays in Frankfurt; the safeguard is needed for the provider's own possible access from Singapore. It is the EU standard contractual clauses, modules 2 and 3, included in Supabase's data processing agreement (version of 1 August 2026). We do not use Supabase Edge Functions or their CDN.
Vercel
Server logs from your visit to this website
Frankfurt am Main, Germany for the server functions (region fra1). Routing, middleware and the content delivery network run on Vercel's global infrastructure and are not limited to the EU.
Vercel Inc. is in the USA and is certified under the EU–U.S. Data Privacy Framework, status Active, covering non-HR data — the basis for the transfer. Standard contractual clauses apply in addition through Vercel's data processing agreement.
Railway
Server logs, and everything processed while your order is handled
Amsterdam, Netherlands (region EU West)
Railway Corporation is in the USA and is certified under the EU–U.S. Data Privacy Framework, status Active. We concluded their data processing agreement on 5 September 2026; it includes the standard contractual clauses, modules 1 to 3. Railway's representative in the EU under Art. 27 GDPR is DP-Dock GmbH, Ballindamm 39, 20095 Hamburg.
Resend
Your email address, the contents of your order confirmation, and the delivery logs for it
United States
This one is different from the others, so we spell it out: we send from a European address, but that setting only controls where the sending happens. Resend stores the data in the United States — message content, delivery logs and account records. There is no EU storage option. Resend (Plus Five Five, Inc., San Francisco) is certified under the EU–U.S. Data Privacy Framework for non-HR data; its status on 5 September 2026 was Active – Re-certification under Review. Standard contractual clauses apply in addition through their data processing agreement (version of 27 August 2026). Resend uses further sub-processors, all in the United States.
Stripe, PayPal and Discord are named above with their European entities. They decide on parts of their processing themselves and publish their own privacy policies.
Two things we do not know, and would rather say so than pretend otherwise. Supabase names Supabase, Inc. in the USA in its privacy policy, while its terms and its data processing agreement name Supabase Pte. Ltd. in Singapore as our contractual partner; we have not been able to resolve that difference. And Railway does not document where the account data, logs and metrics of its control plane are held when a service runs in Amsterdam — its privacy policy names the USA, the Netherlands and Singapore in general terms.
Certifications under the Data Privacy Framework can lapse or be withdrawn, which is why the date above matters. You can check the current status of any company on the official list at dataprivacyframework.gov. Where a certification no longer applies, the standard contractual clauses named above remain in place.
Cookies and local storage
We do not use any tracking, analytics or advertising services, and we set no cookies for those purposes. There is no consent banner because there is nothing to consent to.
We set exactly one cookie, and only once you sign in:
- veraze_refresh — keeps you signed in beyond the first hour. Your access token expires after 60 minutes; this cookie is what lets the shop quietly get a new one instead of signing you out, possibly in the middle of a checkout. It is set when you sign in, deleted when you sign out, and expires after 30 days. It is marked HttpOnly, so no script on this site can read it, and it is only ever sent to our own API. It contains no information about you beyond the session itself.
Your browser also stores three things locally, on your device only. None of them is ever sent anywhere except as needed to serve you:
- Your cart — so it survives a page reload.
- Your sign-in token — so you stay signed in.
- Your currency choice — so you do not have to pick it again.
All four are strictly necessary to provide the service you asked for, so they fall under the exception in § 25 (2) TDDDG and need no consent. You can clear them at any time in your browser settings; the shop will simply forget your cart and sign you out.
The typeface used on this site is delivered from our own server. Your browser makes no connection to Google Fonts or any other third-party font service.
Your rights
Under the GDPR you have the right to:
- ask what data we hold about you (Art. 15)
- have inaccurate data corrected (Art. 16)
- have data deleted (Art. 17)
- have processing restricted (Art. 18)
- receive your data in a portable format (Art. 20)
- object to processing based on our legitimate interests (Art. 21)
Write to verazeservices@web.de and we will deal with it.
Deletion has a limit: where we are legally required to keep order and invoice records, we restrict processing instead of deleting, and the data is removed once the retention period ends.
You can also complain to a data protection authority. The one responsible for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit.
Do you have to give us this data
No, but without an email address and a Discord tag we cannot create an account or deliver an order. There is no obligation to give us anything else, and we do not ask for anything else.
Automated decisions
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.
Security
The site is served over HTTPS. Passwords are stored only as hashes and are never visible to us, and access to order data is checked against the signed-in account on every request.
More on how orders and payments are protected is in our terms.
