Pre-order: ships from 11 September · Free shipping from Germany · No app needed

Privacy Policy

This English translation is provided for convenience only. The German version is legally binding.

1. Data Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Admir Fazlic, Tapenda
Germanenstr. 34
45888 Gelsenkirchen
Email: info@tapenda.com

You can find our complete contact details in our Legal Notice.

2. Hosting (Vercel)

This website is hosted by Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. When the website is accessed, technically necessary data (including IP address, date and time of access, requested URL, referrer, user agent) is processed in server logs. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure and stable operation). This may involve a transfer to the USA, which is based on the EU Standard Contractual Clauses.

3. Database & Authentication (Supabase)

For our database and authentication, we use Supabase (Supabase Inc.). Product, order and, where applicable, account data as well as admin login credentials are stored and processed there. For the customer account (managing purchased displays) you sign in without a password: we send a one-time login code to your email address; your email address and login timestamps are stored in the process. The legal basis is Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (operation and security of the application). Server location: Frankfurt am Main, Germany (AWS eu-central-1). A data processing agreement (DPA) is in place with the provider.

4. Payment Processing (Stripe)

We process payments via Stripe (Stripe Payments Europe, Ltd., Ireland; Stripe, Inc., USA). As part of the payment process, your name, email address, billing and/or delivery address as well as payment data are transmitted to Stripe and processed there. We do not collect or store credit card and bank details ourselves — these are processed exclusively by Stripe. The legal basis is Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (fraud prevention). Further information: stripe.com/de/privacy.

5. Email Dispatch (Resend)

For sending transactional emails (e.g. order and shipping confirmations) we use Resend (Resend, Inc., USA). In doing so, your email address and the contents of the respective message are processed. The legal basis is Art. 6(1)(b) GDPR (performance of a contract) or Art. 6(1)(f) GDPR (legitimate interest in reliable communication). A transfer to the USA is based on the EU Standard Contractual Clauses.

6. Shipping (Sendcloud, DHL)

We use Sendcloud (Sendcloud B.V., Netherlands) to create shipping labels. This involves processing your name, delivery address and — where required for delivery notifications — your email address, and passing them on to the carrier. Shipping is handled by DHL (DHL Paket GmbH, Germany), which processes this data for delivery under its own responsibility. The legal basis is Art. 6(1)(b) GDPR (performance of a contract). A data processing agreement (DPA) is in place with Sendcloud.

7. Cookies and similar storage technologies

The lists below name every cookie and local storage entry that may be stored on your device when you visit this website — each with its provider, storage duration and purpose.

Technically necessary

  • cartCookie

    Stores the contents of your shopping cart so they are retained between page views.

    Provider: tapenda · Storage duration: 30 days

  • promoCookie

    Remembers a discount code you entered or opened via a promotional link so it can be shown in the cart and redeemed at checkout.

    Provider: tapenda · Storage duration: 30 days

  • reservationCookie

    Records how long the stock reserved for you is held and drives the countdown shown in the cart.

    Provider: tapenda · Storage duration: 1 hour

  • cookie-consentCookie

    Stores your cookie banner decision so we can honour it and do not ask you again.

    Provider: tapenda · Storage duration: 6 months

  • NEXT_LOCALECookie

    Remembers the language you selected so the shop appears in the same language on your next visit.

    Provider: tapenda · Storage duration: 1 year

  • admin_sessionCookie

    Keeps users signed in to the admin area (relevant only to us as the operator).

    Provider: tapenda · Storage duration: 24 hours

  • sb-*-auth-tokenCookie

    Keeps you signed in to the customer portal. Set only if you log in.

    Provider: Supabase Inc. · Storage duration: 400 days, renewed each time you keep using the portal

  • __stripe_midCookie

    Fraud prevention during payment. Set as soon as the express payment methods (Apple Pay, Google Pay, Link) load in the cart.

    Provider: Stripe Payments Europe, Ltd. · Storage duration: 1 year

  • __stripe_sidCookie

    Fraud prevention within an ongoing payment. Same precondition as __stripe_mid.

    Provider: Stripe Payments Europe, Ltd. · Storage duration: 30 minutes

  • tapenda_tour_gesehenLocal storage

    Remembers that you have already seen the introductory tour in the customer portal.

    Provider: tapenda · Storage duration: unlimited, until you clear your browser storage

  • ms:*Local storage

    Remembers per stand which milestone was last celebrated in the customer portal so the same view does not appear repeatedly.

    Provider: tapenda · Storage duration: unlimited, until you clear your browser storage

These entries are required for the operation of the website; the legal basis is § 25(2) TDDDG in conjunction with Art. 6(1)(f) GDPR. No consent is required for this. Some of them are only created by an action on your part — such as logging in to the customer portal, or opening the cart, where the express payment methods are loaded.

Statistics — only with your consent

  • _gaCookie

    Assigns a pseudonymous identifier that lets Google Analytics distinguish returning visits.

    Provider: Google Ireland Ltd. · Storage duration: 2 years

  • _ga_*Cookie

    Holds the session state for our Google Analytics property (page views and events within one session).

    Provider: Google Ireland Ltd. · Storage duration: 2 years

  • _clckCookie

    Assigns a pseudonymous identifier for Microsoft Clarity so that repeat visits belong to the same analysis.

    Provider: Microsoft Ireland Operations Ltd. · Storage duration: 1 year

  • _clskCookie

    Groups the page views of one session for Microsoft Clarity (heatmaps, session recording).

    Provider: Microsoft Ireland Operations Ltd. · Storage duration: 1 day

Marketing — only with your consent

  • _gcl_*Cookie

    Attributes a purchase to a previous click on one of our ads (conversion measurement).

    Provider: Google Ireland Ltd. · Storage duration: 90 days

  • _gac_*Cookie

    Links campaign information from Google Ads with our site's analytics data.

    Provider: Google Ireland Ltd. · Storage duration: 90 days

  • tap_attrCookie

    Stores the click ID passed with an ad click plus campaign parameters in order to attribute a later order to the campaign. Deleted if you withdraw consent.

    Provider: tapenda · Storage duration: 90 days

Statistics and marketing entries are set exclusively after your respective consent via the cookie banner (Art. 6(1)(a) GDPR, § 25(1) TDDDG); the services behind them are described in sections 7a and 7b. You can change or withdraw your consent at any time via the “Cookie settings” link in the page footer.

To fulfil our obligation to demonstrate consent (Art. 7(1) GDPR), we store the state of your consent decision at the time of the order together with the order.

A short question after checkout. On the order confirmation page we ask, voluntarily, how you heard about us. Your answer — the selected category and, for “Something else”, an optional note of at most 120 characters — is stored together with the order so that we can judge how well our advertising works. Answering is optional; nothing about your order changes without it. The legal basis is our legitimate interest in evaluating our own advertising (Art. 6(1)(f) GDPR). No cookies are set and neither your IP address nor your browser is stored; the answer is deleted together with the order.

7a. Web Analytics (Google Analytics 4)

Only with your consent (cookie banner, Art. 6(1)(a) GDPR, § 25(1) TDDDG) do we use Google Analytics 4 provided by Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland. Pseudonymized usage data is processed (pages viewed, events such as “add to cart”, truncated IP address, the approximate location derived from it at city or region level, device information). This may involve a transfer to Google LLC in the USA, which is based on the EU-US Data Privacy Framework or the EU Standard Contractual Clauses. The retention period for the analytics data is a maximum of 14 months.

You can withdraw your consent at any time with effect for the future: via the “Cookie settings” link in the page footer, you can reopen the banner and change your selection (alternatively by deleting the consent cookie). Without consent, no web analytics take place. In addition, we measure order completions on the server side (order value and products) — exclusively if your analytics consent was present at the time of the order; in that case we use the client ID and the session ID from the Google Analytics cookies (_ga, _ga_*) to attribute the order to your session, and we pass along the status of your marketing consent (legal basis Art. 6(1)(a) GDPR). Without consent, no data is transmitted to Google in this process. We store both identifiers with the order and delete them 30 days after the order; the order itself is retained for commercial and tax law reasons (see section 11). By the same route and under the same conditions we report a later refund (order number and refunded amount), so that the analysis does not permanently show revenue that never existed.

Customer account. If you are signed in to the customer portal and have consented to the “Statistics” category, we additionally transmit a pseudonymous account identifier (a random string, known as a user ID) to Google Analytics. It lets us count visits from the same account on different devices as belonging together. Your email address, your name or other details from which Google could identify you are not transmitted.

Microsoft Clarity. Also only with your consent to the “Statistics” category do we use Microsoft Clarity provided by Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Clarity records the course of your visit (mouse movement, clicks, scrolling, page changes) and derives heatmaps and session replays from it. The sole purpose on our side is to identify usability problems — for example, at which step of the checkout visitors abandon. Text you enter and the contents of form fields are masked and are not transmitted. This may involve a transfer to Microsoft Corporation in the USA, which is based on the EU-US Data Privacy Framework or the EU Standard Contractual Clauses. Microsoft deletes session replays after 30 days, and heatmaps, flagged sessions and click data after 9 months.

Microsoft is an independent controller here — not our processor. That distinction affects you directly, which is why it appears here and not in the fine print: under the Clarity terms of use, Microsoft and we are two independent controllers. Microsoft therefore does not act on our instructions, and we cannot determine how Microsoft handles the data. By its own account Microsoft may use the data it collects for its own purposes: to provide the service, to improve its own products and services, and to create user profiles, including for advertising; non-personal data additionally for research, development and the training of models. This is precisely what we ask your consent for as well — if you do not consent to the “Statistics” category, none of it takes place. What Microsoft does with the data is set out in the Microsoft privacy statement. Clarity provides no way to delete an individual person’s data; a request for access to or erasure of that data should therefore be addressed to Microsoft. If you contact us, we will pass it on.

Which cookies Clarity sets — and which it does not. With your consent to the “Statistics” category, Clarity sets its two own cookies _clck and _clsk. Beyond that, Clarity may set cookies on Microsoft domains (MUID, CLID, MR, SM, ANONCHK); according to Microsoft, the identifier MUID is also used for advertising. On our site these cookies are never created — not even if you consent to the “Marketing” category. We permanently pass consent for advertising storage (ad_Storage) to Clarity as denied, and only the statistics decision as such (analytics_Storage). The reason is simple: we want to identify usability problems and we do not run Microsoft advertising, so there is no occasion for identifiers that recognise you across Microsoft services. Nor could we delete cookies on Microsoft domains — what is never created needs no deleting. If you withdraw the statistics consent, Clarity ends the session, deletes its own cookies and only records without a recognisable identifier; we additionally delete _clck and _clsk ourselves.

What else we pass on to Clarity. So that the recordings can be analysed at all, we pass Clarity the same attributes that appear in our audience measurement: the type of page (product page, cart and so on), whether we recognise you as a new or returning customer and which portal plan you are on, the identifying code of the ad or printed material that brought you to us, and the name of the action concerned — the same one our audience measurement counts: viewing a product, adding it to the cart, starting the ordering process or signing in to the customer portal. Only the name is transmitted, not its content: neither order value nor item nor order number. Sessions containing a cart or ordering step are additionally flagged to Clarity as a priority, so that they in particular are not lost to the recording limit. These attributes describe the visit, not the person: we do not pass Clarity names, email addresses, postal addresses, order numbers or customer numbers, and we deliberately do not use the feature that would allow sessions to be linked to an account.

7b. Advertising (Google Ads)

Only with your consent (cookie banner, “Marketing” category, Art. 6(1)(a) GDPR, § 25(1) TDDDG) do we use Google Ads provided by Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland, for conversion measurement and remarketing. In doing so, cookies are set (including _gcl_*, _gac_*) and information about your use of our website is processed in order to measure the success of our advertisements and to show you interest-based advertising on Google services and partner websites; for this, Google builds interest profiles across multiple websites. This may involve a transfer to Google LLC in the USA, which is based on the EU-US Data Privacy Framework or the EU Standard Contractual Clauses.

To attribute orders to ad clicks, we additionally store our own first-party cookie tap_attr: it contains the click ID passed by Google when you click on an ad (gclid, gbraid or wbraid) and, where applicable, campaign parameters (utm_*), with a lifetime of 90 days. It is only set after your consent to the “Marketing” category and is deleted upon withdrawal. If you complete an order, we store this information with the order to evaluate the performance of our advertising campaigns and delete it there 90 days after the order.

For remarketing, we also transmit which products you viewed or added to your cart: the item number of the respective variant — the same one used in our product data feed — along with its price. This allows Google to later show you ads for exactly those products. If you complete an order, we additionally transmit the item numbers, quantities and prices of the purchased items as well as any discount granted, so that we can evaluate advertising performance per product. This too happens solely after your consent to the “Marketing” category and does not take place without it.

To improve conversion measurement, we also use Google’s “enhanced conversions”: when you complete an order, the order data you provide (email address, name, phone number, postal address) is transmitted to Google in hashed, i.e. SHA-256 pseudonymized, form. Google uses this data solely on our behalf to match it against signed-in Google accounts and attribute conversions to our ads. No plain-text data is transferred to Google in this process. The legal basis is likewise your consent to the “Marketing” category (Art. 6(1)(a) GDPR); without this consent, no transmission takes place.

The same applies to our contact and enquiry forms: if you submit one, we transmit — again only with consent to the “Marketing” category — solely your hashed email address (SHA-256) to Google, so that Google can attribute the enquiry to a previous ad click. The hash is created on our server; your address in plain text, your name and the content of your message do not leave our system. Without consent, the transmission is omitted entirely — the enquiry itself reaches us regardless.

We use Google Consent Mode v2: without your consent, no marketing cookies are set and no advertising data (ad_storage, ad_user_data, ad_personalization) is transmitted to Google. You can withdraw your consent at any time with effect for the future — via the “Cookie settings” link in the page footer; the associated cookies are deleted upon withdrawal. Further information on data processing by Google: policies.google.com/privacy.

7c. Setting up your stand

During the order process we ask for the name and town of your business; you may optionally add the link to your Google listing. We use these details solely to set up your stand’s redirect target before dispatch — usually the review link of your Google Business Profile. To do so we look up your publicly visible Google Maps listing; your details are not transmitted to Google, they are merely looked up as in an ordinary search. The legal basis is Art. 6(1)(b) GDPR (performance of the purchase contract): the configured redirect is part of what we owe you.

The details are stored with your order and deleted along with it (see section 11). You can change or clear the configured target yourself at any time in your customer account.

8. Redirect & Scan Statistics

When a redirect link is accessed (path /r/{code}, e.g. by scanning a QR code or tapping an NFC tag), we log the time of access, a coarse device category (iOS, Android or other) and the host of the referring site (e.g. google.com) for statistical purposes. We do not store the full user agent or the full referring URL; both are reduced to those two values as the request comes in and discarded otherwise. This data serves to evaluate the reach and usage of the codes we provide; the owner of the respective stand can view it in their customer account.

Your IP address is not stored with the scan. It is processed transiently only and stored solely as a cryptographic hash (SHA-256 with a server secret) in an abuse-protection counter that limits scan spam. That counter is deleted no later than 24 hours after its time window has expired.

The legal basis is Art. 6(1)(f) GDPR (legitimate interest in evaluating the use of our products and redirects, and in protecting against abusive use). Retention period for individual events: 14 months; they are then deleted automatically. Only anonymous monthly totals per stand remain (plain numbers without device, referrer or time details), which no longer allow any reference to a person. You can object to the processing pursuant to Art. 21 GDPR.

Printed advertising. QR codes on our own flyers and posters lead to our website via the path /f/{code}. What we log here is even less: only the identifier of the advertising medium, the time, the country (country code derived from the network connection, e.g. DE) and whether the request came from a mobile device. Neither the referrer nor the user agent is stored; your IP address is handled as described above. These details allow no conclusions about you as a person — not even in combination — and serve solely to answer how often an advertising medium was scanned. The legal basis for the abuse protection is Art. 6(1)(f) GDPR. On the destination page, the usual rules of this policy apply; in particular, analytics and marketing services are only loaded after you have given your consent.

Consent banner acceptance rate. As soon as you make a choice in the banner — whether you accept, decline or select individual categories — we record on our server only which categories were chosen, whether the decision was made in the notice dialog or in the cookie settings, what type of page you were on (e.g. home page, product page), in which language, and whether the request came from a mobile device. Neither your IP address nor the user agent, referrer or any identifier is stored; nothing is read from or written to your device for this purpose. These details allow no conclusions about you as a person and serve solely to answer how often our banner is accepted. They are deleted after 90 days. The legal basis for this analysis and for the abuse protection (your IP address is used solely in hashed form for a rate limit and is not stored) is our legitimate interest in a reliable reach figure, Art. 6(1)(f) GDPR. No consent is required because nothing is stored on or read from your device (Section 25(1) TDDDG).

9. Product Reviews

After an order has been shipped, we send a one-time email requesting a product review (legal basis: Art. 6(1)(f) GDPR — legitimate interest in customer feedback on purchased products; § 7(3) UWG). If you submit a review, we process the review content, the optionally provided display name and the association with your order (proof of “verified purchase”). Approved reviews are displayed publicly on the product page with the display name (or “Anonymous”). You can request the deletion of your review at any time without any formal requirements.

10. Newsletter

You can sign up for our newsletter via the newsletter form or via a non-pre-selected checkbox in the shopping cart. When you sign up, we store your email address and the time of registration and confirmation (double opt-in) — you will only receive advertising after clicking the confirmation link. The legal basis is your consent (Art. 6(1)(a) GDPR); dispatch is carried out via Resend (see section 5). You can unsubscribe at any time via the link in every email.

As a thank-you for signing up, once you complete the double opt-in you receive a one-time discount code for 10% off your first order (implemented as a personal, single-use Stripe voucher valid for 90 days). Your consent is voluntary; not signing up puts you at no disadvantage — the discount is simply an added benefit. You can end your subscription at any time without a code you already received expiring.

11. Retention Period

We store personal data only for as long as is necessary for the respective purposes or as required by statutory retention periods (e.g. up to 10 years under commercial and tax law). After that, the data is deleted or anonymized.

11a. Transfers to third countries and where to inspect the safeguards

Several of the services named above process data in the USA or may transfer it there: Vercel (hosting), Stripe (payment processing), Resend (email delivery), Google (web analytics and advertising) and Microsoft (Clarity). There is no general adequacy decision for the USA. The transfers therefore rest on two instruments:

  • EU-U.S. Data Privacy Framework. For companies certified under that framework, the European Commission’s adequacy decision of 10 July 2023 applies. You can check at any time whether a given company is certified in the public list: dataprivacyframework.gov/list.
  • EU Standard Contractual Clauses. Where no certification applies, we have concluded the European Commission’s standard contractual clauses with the provider concerned. Their wording is officially published in Implementing Decision (EU) 2021/914: eur-lex.europa.eu.

Copy on request. We will provide you with a copy of the safeguards actually concluded for a particular service on request. A short message to the postal or email address given in section 1 is enough; please name the service concerned. We may redact trade secrets and details concerning third parties — the data protection provisions themselves remain fully legible.

Microsoft Clarity is a different case, and we say so plainly: Microsoft is an independent controller there and not our processor (see section 7a). We therefore cannot present you with safeguards concluded with Microsoft for that processing — the transfer within the Microsoft group to the USA is governed by Microsoft itself.

12. Your Rights as a Data Subject

You have the following rights:

  • Access to your stored data (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)
  • Withdrawal of consent granted, with effect for the future

To exercise your rights, an informal message to the following address is sufficient: info@tapenda.com.

13. Right to Lodge a Complaint with a Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data (Art. 77 GDPR). The competent authority is, among others, the supervisory authority of your habitual residence or the supervisory authority responsible for us, the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf.

Last updated: 21 August 2026. This privacy policy will be adjusted in the event of changes to data processing.