Privacy policy

PRIVACY POLICY

Last updated: July 2026

At DAWID TOMASZEWSKI, we believe that trust is built on transparency. Protecting your privacy and safeguarding your personal information are fundamental to the way we conduct our business.

This Privacy Policy explains how DT Concepts UG (haftungsbeschränkt) ("DAWID TOMASZEWSKI", "we", "our" or "us") collects, uses, stores, shares and protects your personal data when you visit our website, create an account, subscribe to our newsletter or purchase products from our online store.

We process your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the German Federal Data Protection Act (BDSG) and other applicable data protection laws.

By using our website, you acknowledge that your personal data will be processed as described in this Privacy Policy.


1. Data Controller

The controller responsible for processing your personal data is:

DT Concepts UG (haftungsbeschränkt)

Richard-Wagner-Str. 25

10585 Berlin

Germany

Email: info@dawidtomaszewski.com

Telephone: +49 30 296 824 30


2. Scope of this Privacy Policy

This Privacy Policy applies to all visitors, customers and users of the DAWID TOMASZEWSKI online store, including anyone who:

  • visits our website;

  • creates a customer account;

  • places an order;

  • subscribes to our newsletter;

  • contacts our Customer Care team;

  • participates in promotions or marketing activities;

  • interacts with us through social media platforms.


3. Personal Data We Collect

Depending on how you interact with our website, we may collect the following categories of personal data.

Information You Provide

When placing an order or creating a customer account, you may provide:

  • First and last name

  • Billing address

  • Shipping address

  • Email address

  • Telephone number

  • Company name (where applicable)

  • VAT identification number (where applicable)

  • Account password (encrypted)

  • Order notes

Payment Information

Payments are processed securely through our authorised payment service providers.

Depending on the selected payment method, payment-related information may be processed by:

  • Shopify Payments

  • PayPal

  • Klarna

  • Shop Pay

  • Apple Pay

  • Google Pay

  • Sofort

For security reasons, we do not store complete credit or debit card details on our own servers.


Order Information

When you place an order, we collect information relating to:

  • purchased products;

  • order value;

  • discounts;

  • shipping method;

  • payment method;

  • invoices;

  • refunds;

  • returns;

  • communication regarding your order.


Customer Account

If you create a customer account, we store information including:

  • login credentials;

  • order history;

  • delivery addresses;

  • wish lists (if available);

  • saved preferences.


Newsletter

If you subscribe to our newsletter through Mailchimp, we process:

  • your email address;

  • subscription status;

  • language preference (where applicable);

  • interaction with newsletters, including opening and click rates.

You may unsubscribe at any time by clicking the unsubscribe link contained in every newsletter or by contacting us directly.


Customer Support

If you contact us by email or through our contact forms, we may process:

  • your name;

  • your contact details;

  • correspondence;

  • attached documents;

  • information necessary to resolve your enquiry.


4. Information Collected Automatically

When you visit our website, certain technical information is collected automatically.

This may include:

  • IP address;

  • browser type and version;

  • operating system;

  • device type;

  • language settings;

  • referring website;

  • pages visited;

  • products viewed;

  • shopping cart activity;

  • date and time of access;

  • session identifiers;

  • cookie identifiers.

This information helps us improve the performance, security and usability of our website.


5. How We Use Your Personal Data

We process your personal data only where there is an appropriate legal basis under the GDPR.

Your personal data may be used to:

  • fulfil and manage your orders;

  • process payments;

  • deliver products worldwide;

  • communicate with you regarding your purchases;

  • provide customer support;

  • manage your customer account;

  • prevent fraud and abuse;

  • comply with legal and tax obligations;

  • improve our website and services;

  • personalise your shopping experience;

  • send newsletters and marketing communications where you have provided your consent;

  • analyse website performance and user behaviour through analytics tools;

  • protect the security of our systems and services.

We will never sell your personal data to third parties.

6. Legal Basis for Processing

We process your personal data only where a lawful basis exists under Article 6 of the General Data Protection Regulation (GDPR).

Depending on the purpose of processing, one or more of the following legal bases apply:

Performance of a Contract

(Article 6(1)(b) GDPR)

We process your personal data where necessary to:

  • process and fulfil your orders;

  • create and manage your customer account;

  • arrange payment and delivery;

  • provide customer support;

  • process returns, exchanges and refunds.

Compliance with Legal Obligations

(Article 6(1)(c) GDPR)

Certain information must be processed and retained to comply with applicable legal obligations, including accounting, tax and commercial record-keeping requirements.

Legitimate Interests

(Article 6(1)(f) GDPR)

Where appropriate, we process personal data in pursuit of our legitimate business interests, including:

  • maintaining the security of our website;

  • preventing fraud and abuse;

  • improving our products and services;

  • analysing website performance;

  • ensuring system stability;

  • defending legal claims;

  • maintaining business operations.

Whenever we rely on legitimate interests, we carefully balance those interests against your rights and freedoms.

Consent

(Article 6(1)(a) GDPR)

Where required by law, we will process your personal data only after obtaining your explicit consent.

This applies in particular to:

  • marketing emails;

  • cookies used for analytics or advertising;

  • Meta Pixel;

  • Google Analytics 4;

  • personalised advertising.

You may withdraw your consent at any time without affecting the lawfulness of processing carried out before the withdrawal.


7. Shopify Services

Our online store is hosted by Shopify Inc., which provides the e-commerce platform enabling us to offer our products and services online.

When you visit our website or place an order, Shopify processes personal data on our behalf, including:

  • account information;

  • order information;

  • payment information;

  • browsing behaviour;

  • technical device information;

  • cookies and session identifiers.

Shopify acts as our data processor for many processing activities and implements appropriate technical and organisational measures to safeguard your personal data.

Additional information is available in Shopify's Privacy Policy.


8. Payment Providers

To process payments securely, we work with authorised payment service providers.

Depending on the payment method selected during checkout, your personal data may be processed by:

  • Shopify Payments

  • PayPal

  • Klarna

  • Shop Pay

  • Apple Pay

  • Google Pay

  • Sofort

  • your credit or debit card issuer

The payment provider is responsible for processing payment transactions in accordance with its own privacy policy.

We never receive or store complete payment card numbers.


9. Shipping Partners

To fulfil your order, we share only the personal information necessary for delivery with our logistics partners.

These may include:

  • DHL

  • DPD

  • GLS

Shared information typically includes:

  • recipient name;

  • delivery address;

  • telephone number (where required);

  • email address (where delivery notifications are requested);

  • parcel information.

Where you have requested delivery notifications, your contact details may be shared solely for this purpose.


10. Newsletter and Marketing Communications

If you subscribe to our newsletter, your email address will be processed through Mailchimp.

Mailchimp enables us to:

  • distribute newsletters;

  • manage subscriber lists;

  • analyse campaign performance;

  • improve future communications.

Newsletter analytics may include information such as:

  • email delivery;

  • email opens;

  • link clicks;

  • device information;

  • approximate location.

You may unsubscribe at any time using the unsubscribe link included in every newsletter.


11. Cookies and Similar Technologies

Our website uses cookies and comparable technologies to improve your browsing experience.

Cookies help us to:

  • remember your preferences;

  • keep your shopping cart active;

  • enable secure checkout;

  • analyse website traffic;

  • measure marketing performance;

  • personalise content where permitted.

We categorise cookies as:

Essential Cookies

These cookies are necessary for the operation of our website and cannot be disabled.

Functional Cookies

These cookies remember your preferences and improve website functionality.

Analytics Cookies

These cookies help us understand how visitors use our website.

Marketing Cookies

These cookies enable us and our advertising partners to measure campaign effectiveness and display relevant advertising.


12. Consent Management

We use Shopify Customer Privacy to manage cookie preferences and consent.

Where required by applicable law, non-essential cookies are activated only after you have provided your consent.

You may change or withdraw your consent at any time through the cookie preferences available on our website.

Your choices are recorded and respected in accordance with applicable privacy legislation.

13. Analytics and Advertising Technologies

Google Analytics 4

Subject to your consent where required by applicable law, we use Google Analytics 4, a web analytics service provided by Google Ireland Limited.

Google Analytics helps us understand how visitors interact with our website by collecting information such as:

  • pages visited;

  • time spent on the website;

  • navigation paths;

  • device and browser information;

  • approximate geographic location;

  • conversion events.

Google Analytics uses cookies and similar technologies to generate aggregated reports and improve our website.

Where applicable, IP addresses are anonymised before processing. Data may be transferred to countries outside the European Economic Area (EEA). Where such transfers occur, appropriate safeguards, including the European Commission's Standard Contractual Clauses or the EU–U.S. Data Privacy Framework (where applicable), are used.

You can withdraw your consent at any time through our cookie preferences.


Meta Pixel

We use the Meta Pixel, provided by Meta Platforms Ireland Limited, to measure the effectiveness of our advertising campaigns and better understand how visitors interact with our website.

The Meta Pixel may collect information such as:

  • pages visited;

  • products viewed;

  • shopping cart activity;

  • completed purchases;

  • browser information;

  • device identifiers.

Where you have consented, this information may be used to create audiences for advertising campaigns on Facebook and Instagram.

Meta acts as an independent controller for certain processing activities. Further information is available in Meta's Privacy Policy.


Google Maps

Our website may include Google Maps to help visitors locate our business or other relevant locations.

When Google Maps is accessed, Google may process technical information, including your IP address and device information.

Google Maps is only activated where legally permitted or with your consent where required.


Google reCAPTCHA

To protect our website against spam, fraud and automated misuse, we use Google reCAPTCHA.

reCAPTCHA analyses technical information, including browser characteristics and IP address, solely for security purposes.

The use of reCAPTCHA is based on our legitimate interest in protecting our website and customers against malicious activities.


14. International Data Transfers

As an international online retailer, some of our service providers may process personal data outside the European Economic Area (EEA).

Whenever personal data is transferred internationally, we ensure that appropriate safeguards are in place, including:

  • an adequacy decision issued by the European Commission;

  • the EU Standard Contractual Clauses (SCCs);

  • certification under the EU–U.S. Data Privacy Framework, where applicable; or

  • other legally recognised transfer mechanisms.

We take reasonable steps to ensure that your personal data receives an equivalent level of protection wherever it is processed.


15. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes described in this Privacy Policy or to comply with applicable legal obligations.

Retention periods may vary depending on the type of information involved.

In particular, we may retain data:

  • for the duration of our contractual relationship;

  • to comply with tax, accounting and commercial record-keeping obligations;

  • to resolve disputes;

  • to enforce our legal rights;

  • to prevent fraud.

When personal data is no longer required, it is securely deleted or anonymised.


16. Data Security

We implement appropriate technical and organisational measures designed to protect your personal data against:

  • accidental loss;

  • unauthorised access;

  • unlawful processing;

  • disclosure;

  • alteration;

  • destruction.

These measures include encrypted data transmission (SSL/TLS), restricted access controls, secure hosting environments and regular security reviews.

Although we strive to protect your information, no method of electronic transmission or storage can be guaranteed to be completely secure.


17. Your Rights

Subject to applicable law, you have the right to:

  • request access to your personal data;

  • request correction of inaccurate or incomplete information;

  • request deletion of your personal data;

  • request restriction of processing;

  • object to certain processing activities;

  • withdraw consent at any time where processing is based on consent;

  • receive your personal data in a structured, commonly used and machine-readable format;

  • lodge a complaint with the competent supervisory authority.

To exercise any of these rights, please contact us using the details provided below.


18. Children's Privacy

Our online store is intended for adults.

We do not knowingly collect personal data from children under the age required by applicable law to provide valid consent.

If we become aware that personal data relating to a child has been collected without appropriate consent, we will delete such information without undue delay.


19. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our business, legal requirements or the services we use.

The latest version will always be published on our website together with the revision date.

Where required by law, we will notify you of material changes.


20. Contact Us

If you have any questions regarding this Privacy Policy or the processing of your personal data, please contact:

DT Concepts UG (haftungsbeschränkt)

Richard-Wagner-Str. 25

10585 Berlin

Germany

Email: info@dawidtomaszewski.com

Telephone: +49 30 296 824 30


Effective Date: July 2026

© DAWID TOMASZEWSKI. All rights reserved.