Privacy
Privacy Policy
The entity responsible for data processing is:
JABs GmbH
Steinbeisstr. 7
72501 Gammertingen
Germany
service@jabs-products.de
We appreciate your interest in our online store. The protection of your privacy is very important to us. Below, we provide you with detailed information about how we handle your data.
1. ACCESS LOG DATA AND HOSTING
You can visit our website without providing any personal information. Each time a page is accessed, the web server automatically records a so-called server log file that contains, for example, the name of the requested file, your IP address, the date and time of your visit, the amount of data transferred, and the requesting provider (access log data), documenting the access. These access data are evaluated solely for the purpose of ensuring the smooth operation of the site and improving our offering. This is done in accordance with our overriding legitimate interests in presenting our offering correctly, pursuant to Art. 6(1)(f) GDPR. All access data are deleted no later than seven days after your visit ends.
1.1 HOSTING
Some services for hosting and displaying the website are provided by our service providers who act on our behalf. Unless otherwise stated in this privacy policy, all access data as well as any data submitted via designated forms on this website are processed on their servers. If you have questions regarding our service providers and the basis of our cooperation with them, please contact us using the contact details provided in this privacy policy.
1.2 CONTENT DELIVERY NETWORK
To reduce load times for certain offerings, we use a Content Delivery Network (“CDN”). With this service, content such as large media files is delivered via regionally distributed servers from external CDN providers. As a result, access data is processed on the providers’ servers. Our providers act as processors on our behalf. They are located and/or use servers in countries outside the EU and EEA, for which the European Commission has not issued an adequacy decision. Our cooperation with them is based on the EU Standard Contractual Clauses. If you have questions about our providers and the basis of our cooperation, please contact us using the contact details provided in this privacy policy.
2. DATA PROCESSING FOR CONTRACT FULFILLMENT AND CONTACT
2.1 DATA PROCESSING FOR CONTRACT FULFILLMENT
For the purpose of contract fulfillment pursuant to Art. 6(1)(b) GDPR, we process personal data when you voluntarily provide it during your order. Mandatory fields are clearly marked as such, since we need that data to fulfill the contract and cannot process the order without it. The specific data collected is indicated in the relevant input forms.
Further information about the processing of your data, in particular disclosures to our service providers for the purposes of order, payment, and shipping processing, can be found in the following sections of this privacy policy. Once the contract has been fully executed, your data will be restricted for further processing and deleted after the expiration of statutory retention periods for tax and commercial law pursuant to Art. 6(1)(c) GDPR, unless you have expressly consented to further use of your data pursuant to Art. 6(1)(a) GDPR or we reserve the right to process data further in accordance with legal provisions and will inform you of this in this policy.
Inventory Management System
We use external service providers’ inventory management systems for order and contract processing. These providers act as processors on our behalf. If you have questions about our providers and the basis of our cooperation, please contact us using the contact details provided in this privacy policy.
Our providers are located and/or use servers in countries outside the EU and EEA, for which no adequacy decision of the European Commission exists. Our cooperation with them is based on the EU Standard Contractual Clauses.
2.2 CUSTOMER ACCOUNT
If you consent under Art. 6(1)(a) GDPR by choosing to open a customer account, we use your data to set up your account and store it for future orders on our website. You can delete your account at any time, either by sending us a message via the contact details provided in this privacy policy or by using the function provided in your account. Once your account is deleted, your data will be deleted unless you have expressly consented to further use of your data pursuant to Art. 6(1)(a) GDPR or we reserve the right to further process data in accordance with legal provisions and will inform you accordingly in this policy.
2.3 CONTACT REQUESTS
When you contact us (e.g., via a contact form or email), we process personal data voluntarily provided by you for the purpose of handling your request under Art. 6(1)(b) GDPR. Required fields are clearly marked, as we need the data to handle your inquiry. The specific data collected is indicated in the relevant input forms. Once your inquiry has been fully processed, your data will be deleted unless you have expressly consented to further use pursuant to Art. 6(1)(a) GDPR or we reserve the right to further process data in accordance with legal provisions and will inform you accordingly in this policy.
3. DATA PROCESSING FOR SHIPPING
For contract fulfillment pursuant to Art. 6(1)(b) GDPR, we forward your data to the appointed shipping provider as far as necessary for delivering the ordered goods.
The same applies to data disclosure to our manufacturers or wholesalers when they handle shipping for us (drop shipping). They shall be regarded as shipping providers for the purposes of this privacy policy.
DATA DISCLOSURE TO SHIPPING PROVIDERS FOR DELIVERY NOTIFICATIONS
If you expressly consent during or after your order under Art. 6(1)(a) GDPR, we share your email address and telephone number with the selected shipping provider so that they can contact you prior to delivery to announce or coordinate the shipment.
Your consent may be withdrawn at any time via a message to the contact details listed in this privacy policy or directly with the shipping provider using the contact details listed below. After withdrawal, we delete the relevant data unless you have expressly consented to further use or we reserve the right to process data further legally and will inform you accordingly.
United Parcel Service Deutschland S.à r.l. & Co. OHG
Görlitzer Straße 1
41460 Neuss
Germany
DHL Paket GmbH
Sträßchensweg 10
53113 Bonn
Germany
Hermes Germany GmbH
Essener Straße 89
D-22419 Hamburg
Germany
DPD Deutschland GmbH
Wailandtstraße 1
63741 Aschaffenburg
Germany
4. DATA PROCESSING FOR PAYMENT
For payment processing in our online store, we collaborate with the following partners: technical service providers, banks, and payment service providers.
4.1 TRANSACTION PROCESSING
Depending on the selected payment method, we provide the necessary data for processing the payment transaction to our technical service providers (acting as processors), the respective banks, or the chosen payment service provider, to the extent required for processing. This is for contract fulfillment pursuant to Art. 6(1)(b) GDPR. In part, the payment providers collect the required data themselves, e.g., on their own websites or through technical integration in the ordering process. For this, their own privacy policy applies. If you have questions about our payment partners and the basis for our cooperation, please contact us using the contact details provided in this privacy policy.
4.2 FRAUD PREVENTION AND PAYMENT PROCESS OPTIMIZATION
Where applicable, we may share additional data with our providers, which they use alongside the transaction data (as processors) for fraud prevention and to optimize our payment procedures (e.g., invoicing, handling disputed payments, supporting accounting). This is based on our overriding legitimate interest in protection against fraud and efficient payment management pursuant to Art. 6(1)(f) GDPR.
5. ADVERTISING BY EMAIL AND POST
5.1 EMAIL NEWSLETTER (SUBSCRIPTION)
If you sign up for our newsletter, we use the required or separately provided information to send it to you regularly via email based on your consent pursuant to Art. 6(1)(a) GDPR. You can unsubscribe at any time, either via the link in the newsletter or by sending a message to the contact details provided below. After unsubscribing, we delete your email address unless you have expressly consented to further use of your data pursuant to Art. 6(1)(a) GDPR or we reserve the right to further process data legally and will inform you accordingly.
5.2 POSTAL ADVERTISING AND YOUR RIGHT TO OBJECT
We may also use your first and last name and postal address for our own advertising purposes, for example sending offers and product information by post. This is done based on our overriding legitimate interest in marketing to our customers pursuant to Art. 6(1)(f) GDPR. You may object to the storage and use of your data for these purposes at any time by contacting us via the details provided in this privacy policy.
6. COOKIES AND OTHER TECHNOLOGIES
GENERAL INFORMATION
To make visiting our website attractive and enable certain functions, we use technologies such as cookies. Cookies are small text files automatically stored on your device. Some cookies are deleted at the end of the browser session (session cookies), while others remain on your device (persistent cookies) and allow re-recognition of your browser on subsequent visits.
We use such technologies that are strictly necessary for certain website functions (e.g., shopping cart functionality). These technologies collect data such as IP address, visit time, device and browser information, and usage data (e.g., cart contents). This is based on our overriding legitimate interest in optimizing the presentation of our offering pursuant to Art. 6(1)(f) GDPR.
We also use technologies to meet legal obligations (e.g., proof of consent) and for web analytics and online marketing. Further information, including legal basis, is provided in subsequent sections of this privacy policy.
You can find your browser’s cookie settings via the following links: Microsoft Edge™ / Safari™ / Chrome™ / Firefox™ / Opera™
If you have consented to the use of these technologies pursuant to Art. 6(1)(a) GDPR, you can revoke your consent at any time by contacting us as described in this privacy policy.
7. USE OF COOKIES AND OTHER TECHNOLOGIES FOR WEB ANALYTICS AND ADVERTISING PURPOSES
If you have given your consent under Art. 6(1)(a) GDPR, we use the following cookies and other third‑party technologies on our website. Data collected in this context will be deleted once the purpose is fulfilled and we cease to use the respective technology. You may revoke your consent at any time with future effect. For more information, see the “Cookies and Other Technologies” section above. Further details, including the basis of our cooperation with each provider, are provided under the respective technology headings. If you have questions about the providers and our cooperation, please contact us via the details provided in this privacy policy.
7.1 USE OF GOOGLE SERVICES FOR WEB ANALYTICS AND ADVERTISING PURPOSES
We use the following technologies from Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). The information automatically collected about your website use is generally transferred to a server of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, and stored there. As the U.S. is not subject to an adequacy decision by the European Commission, our cooperation is based on the EU Standard Contractual Clauses. Subject to IP anonymization, your IP address is shortened before storage on Google’s servers. In rare cases, the full IP is transmitted and anonymized on Google’s side. Unless stated otherwise, data processing is carried out under a joint-controller agreement pursuant to Art. 26 GDPR. Further information on Google’s processing can be found in the Google Privacy Policy.
GOOGLE ANALYTICS
We use Google Analytics to analyze website usage. Collected data includes IP address, visit times, device and browser information, and usage data, which is pseudonymized to create usage profiles. Cookies may be used. Your IP address is not linked to other Google data. Data processing is based on a processor agreement with Google.
To optimize marketing, we have enabled the data-sharing settings for “Google Products and Services,” which allow Google to access and use Google Analytics data to improve its services. The data sharing is based on a joint agreement. We have no influence on processing by Google.
We also use Google Optimize for A/B testing in conjunction with Google Analytics.
We use the User-ID feature to assign a unique, persistent ID to your interactions across sessions and devices.
Via Google Signals, cross-device tracking is enabled for analytics if your devices are linked to your Google account and you have enabled “personalized advertising” in your account. We receive only aggregated statistics.
Through the DoubleClick cookie in Google Analytics, your browser can be recognized on other sites, allowing Google to compile reports on website activity and provide related services.
GOOGLE ADSENSE
We monetize our website using Google AdSense, which displays third-party ads. Using the DoubleClick cookie, interest-based advertising is enabled based on data collected such as IP address, browsing behavior, and a pseudonymous User ID.
GOOGLE ADS
We use Google Remarketing for advertising in Google Search results and on third-party sites. A remarketing cookie is set when you visit our website—based on IP, device, browser, and visited pages, Google enables interest-based ads if you have “personalized advertising” enabled in your Google account. If you are logged into Google, Google may use Analytics data to create cross-device remarketing lists.
We use Google Ads Conversion Tracking to measure your behavior after clicking on ads, such as visiting a page or signing up for the newsletter. Pseudonymous data is collected via cookies.
GOOGLE MAPS
We use Google Maps to display geographic information. Data on your use of map features, including IP address and location data, is collected by Google and processed under their control.
GOOGLE RECAPTCHA
We use Google reCAPTCHA to protect our forms from abuse. Google collects data such as IP address, visit time, browser information, and usage via JavaScript and cookies. No personal form input is accessed by Google.
GOOGLE FONTS
We implement Google Fonts for consistent typography. Data such as IP address, visit time, and device/browser information is sent to and processed by Google.
YOUTUBE VIDEO PLUGIN
Embedded YouTube videos (in enhanced privacy mode) collect data such as IP address, visit time, device/browser information and send it to Google only when you play the video.
7.2 USE OF FACEBOOK SERVICES FOR WEB ANALYTICS AND ADVERTISING PURPOSES
FACEBOOK PIXEL
We use Facebook Pixel from Facebook Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland (“Facebook”). The Pixel automatically collects data such as IP address, visit time, device/browser information, and usage events (e.g., page visits, newsletter sign-up). It sets a pseudonymous cookie ID to recognize your browser across sites. Facebook may combine this information with your Facebook account data to generate reports and provide personalized/group-based ads.
Data is transmitted to Facebook, Inc., 1601 Willow Road, Menlo Park, CA 94025, USA. As the U.S. lacks an adequacy decision, our cooperation is based on EU Standard Contractual Clauses. More information can be found in Facebook’s privacy policy.
FACEBOOK ANALYTICS
Using Facebook Analytics, we generate statistics about visitor activities from Pixel data. Data processing is based on a processor agreement with Facebook and is used to optimize and market our website.
FACEBOOK ADS
We advertise on Facebook and other platforms via Facebook Ads. We set campaign parameters, while Facebook handles ad placement. Unless specified otherwise, data processing is based on a joint-controller agreement under Art. 26 GDPR. Facebook Ireland and we are jointly responsible only for data collection and transfer; subsequent processing by Facebook Ireland is not covered.
We use Facebook Custom Audiences to carry out group-based advertising based on Pixel-derived visitor statistics.
We use Facebook Pixel Remarketing to display personalized ads based on pseudonymous cookie ID and usage data.
We use Facebook Pixel Conversions to track events for analytics and remarketing when visitors come via Facebook Ads. Data processing is based on a processor agreement with Facebook.
7.3 OTHER WEB ANALYTICS AND ONLINE MARKETING SERVICE PROVIDERS
VIMEO VIDEO PLUGIN FOR THIRD‑PARTY CONTENT
We embed Vimeo videos via the Vimeo LLC plugin, collecting data such as IP address, visit time, and device/browser information, which is transmitted to and processed by Vimeo. Processing is based on a joint-controller agreement under Art. 26 GDPR. The Vimeo plugin includes Google Analytics integration, which collects data for analytics purposes. Google Ireland Ltd. handles analytics data on Google servers in the U.S. IP addresses are anonymized. We have no influence or access to Vimeo’s or Google's data processing. The U.S. lacks an adequacy decision; cooperation is based on EU Standard Contractual Clauses.
8. SOCIAL MEDIA
8.1 SOCIAL PLUGINS FROM FACEBOOK, INSTAGRAM, PINTEREST
Our website uses social buttons for these networks, which are embedded only as HTML links. No connection to the providers' servers is made unless you click the button, which opens the provider’s website in a new window where you can interact (e.g., Like or Share).
8.2 OUR ONLINE PRESENCE ON FACEBOOK, INSTAGRAM, PINTEREST
If you consent under Art. 6(1)(a) GDPR to the respective social media provider, data about your visit to our presence on these platforms is automatically collected and stored under pseudonyms for market research and advertising. This may be used to serve interest-based ads within and beyond the platforms, typically via cookies. Detailed information and contact options are available in the providers’ privacy policies. If you need assistance, please contact us.
Facebook is provided by Facebook Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland. Data about your use of our Facebook presence is transferred to and stored by Facebook, Inc., 1601 Willow Road, Menlo Park, CA 94025, USA. The U.S. lacks an adequacy decision. Cooperation is based on EU Standard Contractual Clauses. Data processing for visits to our Facebook page is conducted under a joint responsibility agreement pursuant to Art. 26 GDPR. More information about Insights data is available here.
Instagram is provided by Facebook Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland. Your data during visits is transferred to and stored by Facebook, Inc., 1601 Willow Road, Menlo Park, CA 94025, USA. The U.S. lacks an adequacy decision. Cooperation is based on EU Standard Contractual Clauses. Data processing for visits to our Instagram page is conducted under a joint responsibility agreement pursuant to Art. 26 GDPR. More Insight data info is available here.
Pinterest is provided by Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland. Data about your use of our Pinterest presence are transferred to and stored by Pinterest, Inc., 505 Brannan St., San Francisco, CA 94107, USA. The U.S. lacks an adequacy decision. Cooperation is based on EU Standard Contractual Clauses.
9. CONTACT DETAILS AND YOUR RIGHTS
9.1 YOUR RIGHTS
As a data subject, you have the following rights:
- Right to access your personal data under Art. 15 GDPR;
- Right to rectification under Art. 16 GDPR;
- Right to erasure under Art. 17 GDPR, except where processing is necessary for freedom of expression, legal compliance, public interest, or for legal claims;
- Right to restriction of processing under Art. 18 GDPR if accuracy is contested, processing is unlawful but erasure is opposed, data is no longer needed by us but needed by you for legal claims, or you have objected under Art. 21 GDPR;
- Right to data portability under Art. 20 GDPR, to receive your data in a structured, commonly used format or to transfer it to another controller;
- Right to lodge a complaint under Art. 77 GDPR with a supervisory authority, typically your place of residence, workplace, or our company headquarters.
|
Right to Object If we process personal data based on our overriding legitimate interests, you may object at any time for future purposes. For direct marketing, you may object at any time as described above. For other purposes, objection is allowed based on your specific situation. Upon objection, we will stop such processing unless we have compelling legitimate grounds or need the data for legal claims. This does not apply to direct marketing, where processing will cease immediately. |
9.2 CONTACT DETAILS
If you have questions about data collection, processing, or use, or wish to exercise your rights regarding access, rectification, restriction, or erasure, or to withdraw consent or object to specific data use, please contact us via the contact details provided in our imprint.