⚠️ DRAFT – NOT YET LEGALLY REVIEWED. Professionally-informed, modular first draft under the GDPR/BDSG. Not legal advice. Before this is treated as final: (a) every block marked “ONLY IF USED” must be kept only if that tool is actually live — a privacy policy naming services you don’t use is itself a compliance violation — and (b) the text must be reviewed by a lawyer or liability-backed legal-text service. This policy must match the actual cookie-consent banner and actual data flows on the live site.
Draft status: 19 July 2026.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Omar Abu Talib (sole proprietorship “Raivera”)
Email: support@raivera.com
Full registered address: see our Legal Notice.
Note on Data Protection Officer: as a sole proprietorship we are generally not required to appoint a Data Protection Officer (Section 38 BDSG — the obligation generally begins at around 20 people continuously engaged in automated data processing). This section is therefore omitted.
2. General Information on Data Processing
We process the personal data of our users only to the extent necessary to provide a functioning website and our content and services. Processing takes place regularly only with the consent of the user, or where a legal basis permits it.
Legal bases include in particular: Art. 6(1)(a) GDPR (consent); Art. 6(1)(b) GDPR (performance of a contract and pre-contractual measures); Art. 6(1)(c) GDPR (legal obligation, e.g. tax and commercial record-keeping); Art. 6(1)(f) GDPR (legitimate interests).
Retention period: personal data is deleted or restricted as soon as the purpose of storage no longer applies. Longer retention occurs where legally required — in particular to comply with commercial and tax retention obligations (generally 6 or 10 years under the German Commercial Code / Fiscal Code).
3. Hosting / Shop System (Shopify)
Our online shop is operated on the Shopify platform. Provider: Shopify International Limited, Victoria Buildings, 2nd Floor, 1–2 Haddington Road, Dublin 4, D04 XN32, Ireland (“Shopify”).
When you access and use our shop, Shopify processes on our behalf access data (e.g. IP address, date and time of access, pages accessed, browser/operating system used, referrer URL) as well as the data you enter during checkout. Processing is based on Art. 6(1)(b) GDPR (formation/performance of a contract) and Art. 6(1)(f) GDPR (secure and efficient provision of the shop).
A data processing agreement (DPA) under Art. 28 GDPR is in place with Shopify. Where data is transferred to third countries (in particular the USA), this occurs on the basis of the EU Standard Contractual Clauses and/or, where applicable, the EU–U.S. Data Privacy Framework.
4. Access Data / Server Log Files
Each time our site is accessed, information transmitted by your browser is automatically recorded (see Section 3). This data is required for the secure and stable operation of the website (Art. 6(1)(f) GDPR). This data is not combined with other data sources to identify individual persons, except where legally required.
5. Cookies and Consent Management
Our website uses cookies and comparable technologies. Strictly necessary cookies (e.g. cart, session, storage of consent choices) are set without consent on the basis of Section 25(2) TDDDG (German Telecommunications Digital Services Data Protection Act) and Art. 6(1)(f) GDPR.
All non-essential cookies and services (in particular marketing, tracking, and embedded third-party content) are only set after your explicit consent via our consent banner (Section 25(1) TDDDG, Art. 6(1)(a) GDPR). Consent can be withdrawn at any time with future effect via the cookie settings link.
[ONLY IF USED / STRONGLY RECOMMENDED] Where marketing services such as the Meta Pixel are used (Section 9), a legally compliant consent management tool (e.g. Shopify Customer Privacy / a dedicated consent app) is required. Without a functioning consent banner, these services must not load. Provider to be named once the consent tool is finalised.
6. Order, Customer Account and Payment Processing
To process your order, we process the data you provide (name, billing and shipping address, email address, phone number if given, order and payment data). Legal basis is Art. 6(1)(b) GDPR. Data required for tax and commercial purposes is retained for the statutory periods under Art. 6(1)(c) GDPR.
Payment service providers: to process payment, we pass the necessary data to the payment service provider you select. These providers process payment data as independent controllers or as processors under their own privacy terms.
Payment methods offered are still being finalised and are deliberately not listed yet — a privacy policy may only name services actually in use. This section will be completed with the confirmed payment stack (e.g. Shopify Payments/Stripe, PayPal, Klarna, Apple Pay, Google Pay) before public launch.
7. Contact
When you contact us by email, we process the data you provide to handle your enquiry (Art. 6(1)(b) GDPR where directed at a contract; otherwise Art. 6(1)(f) GDPR). Data is deleted once it is no longer required for its purpose and no statutory retention obligation applies.
8. Newsletter / Email Marketing
[ONLY IF USED — provider and details to be added once confirmed]
If we send email newsletters, order-related emails, or marketing messages, this occurs via a dedicated service provider using double opt-in: after signing up you receive a confirmation email, and you are only added to the list after confirming. Legal basis is your consent (Art. 6(1)(a) GDPR); for existing customers, Section 7(3) of the German Act Against Unfair Competition (UWG) in conjunction with Art. 6(1)(f) GDPR may apply. You can unsubscribe at any time via the unsubscribe link or by contacting us.
9. Analytics and Marketing (Tracking Pixels, Ads)
[ONLY IF USED — LOADS ONLY AFTER CONSENT, see Section 5]
If deployed, services such as the Meta Pixel (Meta Platforms Ireland Ltd.), Google Ads/Analytics (Google Ireland Ltd.), or the TikTok Pixel (TikTok Technology Ltd.) may set cookies and process data (including IP address, device and usage data), potentially transferring it to third countries. These services are activated only after your consent and will be named individually, with links to their respective privacy policies, once confirmed live.
10. Customer Reviews
We use Okendo to collect and display product reviews. Provider: Okendo Pty Ltd, Suite 4.07, Level 4, 50 Holt Street, Surry Hills, NSW, Australia. After a purchase, we may send you an invitation to leave a review. Legal basis is your consent or our legitimate interest in meaningful reviews (Art. 6(1)(a) or (f) GDPR respectively). Incentivised reviews (e.g. offered in exchange for product samples or discounts) are clearly labelled as such. A data processing agreement is in place with Okendo where required.
11. Shipping and Logistics
[ONLY IF USED — carrier to be confirmed]
To deliver your order, we pass your name and delivery address, and — for tracking/notification purposes — your email address and/or phone number where applicable, to our shipping provider. Legal basis is Art. 6(1)(b) GDPR. The shipping provider’s own privacy notices apply in addition. Carrier to be named once confirmed.
12. Fonts
Our website uses the typefaces “Sora” and “Rethink Sans”. These fonts are hosted locally as part of our theme (verified live 19 July 2026). No connection to Google’s servers occurs when this page loads, and no IP address is transmitted to Google.
13. Social Media Profiles
[ONLY IF USED] We may maintain profiles on social networks (e.g. Instagram, TikTok, Facebook). When visiting these profiles, the respective provider’s privacy terms apply. Links from our website to these profiles do not load any network content without your interaction.
14. Recipients and Data Processing
We disclose personal data only to the extent necessary to perform a contract, where you have consented, where a legal obligation exists, or where a legitimate interest justifies it. Data processing agreements under Art. 28 GDPR are in place with our service providers where required.
15. International Data Transfers
Where data is transferred outside the EEA (in particular to the USA), we ensure an adequate level of data protection through appropriate safeguards — in particular the EU Standard Contractual Clauses and/or, where certified, the EU–U.S. Data Privacy Framework.
16. Your Rights as a Data Subject
You have the following rights regarding your personal data: Access (Art. 15 GDPR); Rectification (Art. 16 GDPR); Erasure (Art. 17 GDPR); Restriction of processing (Art. 18 GDPR); Data portability (Art. 20 GDPR); Objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR); Withdrawal of consent with future effect (Art. 7(3) GDPR).
To exercise any of these rights, a message to the contact details above is sufficient.
Right to lodge a complaint with a supervisory authority (Art. 77 GDPR): you have the right to lodge a complaint with a data protection supervisory authority, in particular the authority responsible for your place of residence or for us. The supervisory authority responsible for Lower Saxony (Niedersachsen) is:
Der Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5
30159 Hannover, Germany
Email: poststelle@lfd.niedersachsen.de · Phone: +49 511 120-4500
17. Right to Object to Direct Marketing
Where your data is processed for direct marketing purposes, you have the right to object to this processing at any time (Art. 21(2) GDPR). Following your objection, your data will no longer be used for direct marketing purposes.
18. Data Security and Currency of this Policy
We take appropriate technical and organisational measures to protect your data against loss and unauthorised access (including TLS encryption). This Privacy Policy will be updated as the legal situation or our processing activities change.
As of: 19 July 2026.