Last updated: 27 August 2026

This Privacy Notice explains which personal data we process when you use our online shop, why we process it and which rights you have.

1. Controller

The controller responsible for processing personal data on this website is:

Karolin Futh
WeserTrade24
Zur Helle 4b
32584 Löhne
Germany

Telephone: +49 5223 9944412
Email: wesertrade24@gmx.net

2. Hosting and server log data

This website is hosted by ALL-INKL.COM – Neue Medien Münnich, proprietor René Münnich, Bautzener Straße 56, 02742 Neusalza-Spremberg, Germany. When you access the website, technically required data is processed. This may include your IP address, date and time of access, requested file or URL, amount of data transferred, referrer URL, browser type and version, operating system and access status.

This processing is required to provide the website, detect attacks and technical faults, and keep the shop secure. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of the online shop. Log data is deleted once it is no longer required for these purposes unless longer storage is necessary to investigate a security incident or comply with a legal obligation. Where required, the hosting provider is engaged under a data processing agreement pursuant to Article 28 GDPR.

3. Encrypted transmission

The connection to our website is protected by TLS encryption. This is intended to protect data you send to us from unauthorised access while it is being transmitted.

4. Cookies and similar storage technologies

The shop uses technically necessary session cookies, in particular a session identifier named GXsid_…. It enables functions including allocation of the shopping cart, customer account login, language selection and security features. The session cookie generally expires when you close your browser. Core shop functions cannot be provided reliably without this technology.

Storing or accessing information that is strictly necessary is permitted under section 25(2) no. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG). Depending on how the shop is used, the subsequent processing of personal data is based on Article 6(1)(b) GDPR for steps prior to entering into a contract or performance of a contract and Article 6(1)(f) GDPR for security and functionality.

We currently do not use analytics, advertising, social media or map services on ordinary content pages that place optional cookies without an active action by you. If non-essential services are added in the future, they will only be loaded after your consent where required by law. Consent can be withdrawn at any time with effect for the future via the cookie settings then provided.

5. Contacting us

If you contact us through the contact form, by email, by telephone or by another means, we process the data you provide. For the contact form, this includes in particular your name, email address, subject and message. Technically required log data, such as the IP address and time of submission, may also be processed to prevent misuse and document the request.

Where your enquiry concerns a contract or steps before entering into a contract, the legal basis is Article 6(1)(b) GDPR. Other enquiries are processed on the basis of Article 6(1)(f) GDPR; our legitimate interest is to answer them properly. The data is deleted once the enquiry has been fully dealt with and there is no legal retention duty or legitimate reason for further storage.

6. Customer accounts, wish lists and orders

When you create a customer account or place an order, we process the information required for registration, ordering, delivery and billing. This may include title, first and last name, company name and VAT identification number, email address, postal address, country, telephone and fax number, login information, shopping cart and order data, payment method, communications and status information. Information not marked as required is voluntary.

Processing is necessary for steps prior to entering into a contract and performance of the purchase contract under Article 6(1)(b) GDPR. Where processing is necessary for tax or commercial records, Article 6(1)(c) GDPR also applies. Login information is stored securely; passwords are not stored in plain text.

A customer account generally remains in place until it is deleted. You may ask us to delete it. Data relating to completed orders may still be retained where required by statutory retention duties or to establish, exercise or defend legal claims. A wish list is associated with your customer account or current session and can be managed there by you.

7. Payment processing

Depending on the payment method offered during checkout and selected by you, we process the order, billing and payment status information required for payment. For advance payment or bank transfer, the payment is made directly between you and the financial institutions involved. For cash payments, no payment data is disclosed to an external payment service provider.

PayPal

If you choose PayPal, the data required to process your payment is disclosed to PayPal (PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg). This may include your name, address, email address, order amount, currency, cart or transaction information and technical data. PayPal also processes data under its own responsibility, for example for fraud prevention, risk assessment and compliance with legal obligations. Further information is available in PayPal's Privacy Statement.

Sofort payment (Klarna/Sofort)

If you choose Sofort payment, the identity, contact, order, payment and technical data required to initiate and confirm payment is disclosed to Klarna/Sofort. The payment provider also processes data under its own responsibility, in particular for payment processing, authentication, fraud and risk assessment and compliance with legal obligations. Further information is available in Klarna's Privacy Notice.

Disclosure to the payment provider selected by you is necessary for performance of the contract under Article 6(1)(b) GDPR. Where payment providers process data to meet their own legal obligations or carry out their own risk checks, they determine the applicable legal bases themselves. As a rule, we receive only the payment confirmation, reference and status information required for the order; we do not store full login credentials for your bank or payment account.

8. Delivery by parcel service or freight forwarder

To perform the purchase contract, we disclose the data required for delivery to the transport company commissioned for your order. Depending on an item's size, weight and characteristics, delivery is made by a parcel service or – especially for large pieces of furniture and sun islands – by a freight forwarder.

Only information required for transport, advance notice and delivery is disclosed. This particularly includes your name, delivery address, order or delivery information and, where required to arrange a delivery time or complete delivery properly, your telephone number and/or email address. The legal basis is Article 6(1)(b) GDPR. Where contact information is only intended to provide additional, non-essential delivery convenience, it will only be disclosed on an applicable legal basis, where necessary with your consent. The transport company may process the data under its own responsibility to comply with its own legal obligations.

If collection by the customer has been agreed, no delivery data is disclosed to a parcel service or freight forwarder.

9. Newsletter

If you expressly subscribe to our newsletter, we process your email address to send it. The legal basis is your consent under Article 6(1)(a) GDPR. The time of subscription and confirmation as well as technical log data may be retained to document your subscription. You may withdraw your consent at any time with effect for the future by using the unsubscribe link in the newsletter or contacting us. Following unsubscription, your address is removed from the active mailing list. Evidence of consent may be retained for as long as necessary to defend against potential legal claims.

10. Recipients and technical service providers

Within our business, access is limited to those persons who require the data to deal with your enquiry or order. In addition, data may be disclosed – in each case only to the extent necessary – to the following categories of recipients:

  • hosting, email and IT service providers, in particular ALL-INKL.COM and the technical service provider DOST-IT,
  • banks and the payment provider selected by you,
  • parcel services, freight forwarders and other logistics partners,
  • tax advisers, accounting and legal advisers, authorities and courts where required by law or necessary to protect legal claims.

Service providers that process data solely on our instructions are contractually bound pursuant to Article 28 GDPR where required.

11. Transfers to third countries

As part of the direct operation of the shop, we generally do not intend to transfer personal data to countries outside the European Union or European Economic Area. However, such processing cannot be ruled out entirely when international payment or IT providers are used. In that case, the provider concerned is responsible for ensuring appropriate safeguards under Articles 44 et seq. GDPR, such as an adequacy decision or EU standard contractual clauses. Details are available in the respective provider's privacy notice.

12. Retention periods

We retain personal data only for as long as it is needed for the relevant purpose. It is then deleted or restricted unless statutory retention duties, legitimate interests in preserving evidence or pending legal proceedings require otherwise. Depending on the type of document, business and tax records are generally retained for six, eight or ten years. The period generally begins at the end of the calendar year in which the document was created. Statutory limitation periods may additionally apply to individual claims.

13. Your rights

Where the relevant legal requirements are met, you have in particular the right to:

  • obtain access to your personal data (Article 15 GDPR),
  • have inaccurate data corrected (Article 16 GDPR),
  • request erasure of your data (Article 17 GDPR),
  • obtain restriction of processing (Article 18 GDPR),
  • receive data in a portable format (Article 20 GDPR),
  • object, on grounds relating to your particular situation, to processing based on Article 6(1)(e) or (f) GDPR (Article 21 GDPR),
  • withdraw consent at any time with effect for the future (Article 7(3) GDPR).

To exercise your rights, simply contact us using the details given in section 1. To protect your data, we may ask for appropriate proof of identity.

14. Right to lodge a complaint

Under Article 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for our registered office is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Kavalleriestraße 2–4
40213 Düsseldorf
Germany
Website: www.ldi.nrw.de

15. Automated decision-making

We do not make decisions in the online shop based solely on automated processing that produce legal or similarly significant effects. Selected payment providers may carry out automated fraud or risk assessments under their own responsibility; further information is available in their privacy notices.

16. Changes to this Privacy Notice

We update this Privacy Notice when legal requirements, services used or our processes change. The version published on this website applies.