Privacy Policy
1. Data Controller
TDYSKY — Owner: Nicole Rudolf, Die Halde 2, 64853 Otzberg, Deutschland. Contact: [email protected]
2. Data We Collect
When you visit our website, we may collect: browser type, operating system, referrer URL, time of access, and IP address (anonymized). This data ensures security and functionality.
3. Cookies
We use cookies only to store your theme and language preferences. These are technically necessary cookies and do not track you.
4. Third-Party Services
Our shop redirects to Tebex (tebex.io) for payment processing. We also use Discord for community support. This website itself does not handle any payment data. Please refer to their respective privacy policies.
4a. Google Analytics 4
We use Google Analytics 4 (measurement ID G-LMQNCV8KT9) to understand how visitors use the shop. Loading is consent-gated — GA4 is initialised with Google's Consent Mode v2 and defaults to denied. No tracking cookies (_ga, _ga_*) are set before you accept via the banner. On acceptance, the cookies are scoped to .agencyg.de so one session spans agencyg.de, docs.agencyg.de and shop.agencyg.de. IP anonymisation is enabled. Your consent is stored in a first-party cookie agency_privacy_consent_v1 on .agencyg.de (1 year) so the decision is respected across all our subdomains. You can withdraw consent anytime by clearing that cookie. Legal basis: Art. 6(1)(a) GDPR (your consent). More details: Google Privacy Policy.
4b. Tebex (Tebex-store purchases)
Purchases made via the "Shop on our Tebex Store" button are processed by Tebex Limited (UK), a PCI-DSS-compliant payment processor and our merchant-of-record for those transactions. You are redirected to Tebex's checkout where you enter payment details directly on Tebex's infrastructure — we do not receive or store your card or PayPal credentials. Tebex may set its own cookies for fraud prevention and session handling. Data transferred: order details, email address (for receipt delivery), and IP (for fraud scoring). Legal basis: Art. 6(1)(b) GDPR (contract performance). See Tebex Privacy Policy.
4c. Newsletter (double opt-in)
Our newsletter is delivered by Brevo SAS (France). When you subscribe via the exit popup, the newsletter page, the CTA in our transactional mails or the optional checkbox at PayPal checkout, we first send you a confirmation email; no marketing data is stored in Brevo until you click the confirmation link. The link contains an HMAC-signed token so nobody can confirm for you.
On confirmation we store your email, language code and a timestamp (DOI_CONFIRMED_AT) in Brevo. Legal basis: Art. 6(1)(a) GDPR (consent). Every mail includes a one-click unsubscribe (RFC 8058 List-Unsubscribe-Post) and you can also withdraw consent any time by emailing [email protected]. See Brevo Privacy Policy.
4d. Newsletter welcome coupons
After you confirm the newsletter, we generate a unique single-use 20% discount code via the Tebex Plugin API and email it to you. The code is attached to Tebex's coupon system and linked to your email in an internal note so our team can identify the source of the discount. Codes expire after 30 days and are automatically purged from the Tebex dashboard by a daily cleanup job. Legal basis: Art. 6(1)(a) GDPR (consent via newsletter signup) in combination with Art. 6(1)(f) GDPR (legitimate interest in running the welcome promotion).
4e. Customer reviews
When you submit a review, we store your display name, rating, title, text and the product you reviewed. Your email is stored privately for duplicate detection only — it is never displayed on the public review wall. Reviews are auto-translated into our 5 storefront languages via Groq/OpenAI and mirrored to our public Discord feedback channel. Legal basis: Art. 6(1)(a) GDPR (your explicit consent via checkbox on the form). You can request deletion any time via [email protected].
4f. YouTube product showcases
Some product detail pages display a Showcase video hosted by YouTube (Google Ireland Limited, Ireland). We use a strict consent-gated "click-to-load" pattern: no third-party requests are made before you click the play button. The placeholder you see initially is rendered entirely from our own servers — no thumbnails, scripts or cookies are fetched from Google.
When you click play, we load the YouTube player from www.youtube-nocookie.com (Google's Privacy Enhanced Mode). At that moment your IP address, browser user-agent and the video URL are transmitted to Google. Tracking cookies are only set once playback actually begins. Some non-personalised functional data may still be collected by Google for video-watching analytics. Legal basis for the loading event: Art. 6(1)(a) GDPR (your explicit consent given by clicking play). See Google Privacy Policy and YouTube Privacy Guidelines.
Google may transfer data to the United States. The transfer is covered by the EU-U.S. Data Privacy Framework (adequacy decision of 10 July 2023). You can withdraw consent at any time simply by not clicking play — once clicked, you can also clear your browser cookies set by youtube-nocookie.com / google.com to remove any data Google associated with your session.
4g. PayPal (cart direct checkout)
When you use the "Pay with PayPal" option in the shopping cart, we — TDYSKY — process your payment directly through PayPal (Europe) S.à r.l. et Cie, S.C.A. (Luxembourg). The cart contents, your selected currency and the amount charged are transmitted to PayPal for execution. PayPal's own privacy policy applies to the data they collect on their checkout page (card details, PayPal account, IP, fraud signals) — we never see your payment credentials.
Data we receive back from PayPal: order ID, capture ID, payer email, transaction status. We store these alongside the cart contents plus the consents you ticked, the IP-hash at the moment of consent (HMAC SHA256, daily-rotating salt — not reversible) and the timestamp, as proof of compliance with §312i, §312j(3) and §356(5) BGB.
Legal basis: Art. 6(1)(b) GDPR (contract performance) for purchase data; Art. 6(1)(c) GDPR (legal obligation) for the consent record under BGB. Records are retained for 10 years per §147 AO / §257 HGB (commercial record-keeping), then deleted. See PayPal Privacy Statement.
4h. Tebex Gift Card delivery
After a successful PayPal payment via the cart, we create a Tebex gift card via the Tebex Plugin API and email the code to the address you provided at checkout. The minimal data sent to Tebex for this operation: the gift card amount (in EUR) and an internal note containing the short cart order ID (not your email). The code itself is delivered via our regular transactional mail provider (see section 4c).
Legal basis: Art. 6(1)(b) GDPR (contract performance — delivering what you paid for).
4i. Exchange rates (Frankfurter API)
To display prices in USD, GBP or CHF in the cart, we fetch daily EUR exchange rates from Frankfurter (api.frankfurter.app, sourced from ECB reference rates). The request originates server-side and contains no personal data — only the symbolic query "EUR → USD, GBP, CHF". Results are cached in process memory for 6 hours.
Legal basis: not applicable — no personal data is processed by this call.
5. Your Rights (GDPR)
Under the GDPR, you have the right to: access, rectification, erasure, restriction, data portability, and objection to processing of your personal data.
6. Contact
For any data protection inquiries, please contact us at [email protected] or via our Discord server.