1. Controller
The controller responsible for data processing on this website is:
Monvou Robert Clemens Moltkestr. 1350859 Köln info@monvou.com +4915115553398Service providers and recipients
We use the providers listed below for hosting, email, delivery, payment and product visibility. Data is transferred only insofar as necessary for the relevant purpose.
Hosting
ALL-INKL.COM – Neue Medien Münnich
Hauptstraße 68 02742 Friedersdorf Deutschland
Provider privacy information
Email delivery
ALL-INKL.COM – Neue Medien Münnich
Hauptstraße 68 02742 Friedersdorf Deutschland
Provider privacy information
Shipping
Deutsche Post AG
Charles-de-Gaulle-Straße 20, 53113 Bonn, Deutschland
Provider privacy information
Payment processing
Stripe Payments Europe, Limited
1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Irland
Provider privacy information
Google Merchant Center
Google Ireland Limited
Gordon House, Barrow Street, Dublin 4, Irland
Provider privacy information
Under the current hosting configuration, server logs are generally retained for up to 14 days unless longer storage is necessary to prevent or investigate a specific security incident.
Specific standard periods
- Order, invoice and payment data: generally 10 years where statutory retention duties apply.
- General contact enquiries: generally up to 24 months after completion unless longer retention is required.
- Withdrawal, return and refund documentation: generally 3 years after completion unless longer statutory or evidentiary retention is required.
2. Scope
This policy applies to the Monvou shop, product pages, gift advisor, cart, discount and gift-voucher functions, checkout, order confirmation, order and shipping communications, digital credit purchases, returns and the electronic withdrawal function. Separate privacy information for the Monvou app applies to a digital message opened later through a QR code.
3. Website access and server logs
When the website is accessed, the web server processes connection data that is technically required. This may include:
- a shortened IP address or an IP address technically processed by the hosting provider
- date and time of access
- requested file or page and transferred data volume
- browser, operating system and device type
- previously visited page where supplied by the browser
Processing is used to provide a stable and secure service, analyse errors and prevent abuse. The legal basis is Article 6(1)(f) GDPR. Logs are retained only as long as required for security and error analysis.
Abuse prevention and rate limits
To protect the administration area and discount or voucher-code checks, the application briefly processes pseudonymised verification keys, time windows and attempt counts. The security table stores neither submitted codes nor email addresses or raw IP addresses. Verification keys are created using HMAC; expired entries are deleted with the next security-sensitive request. The legal basis is Article 6(1)(f) GDPR. The legitimate interest is preventing brute-force attacks and misuse.
4. Technically necessary session
The shop uses a technically necessary session cookie for language, CSRF protection, cart and checkout state. It is not used for advertising or reach measurement and generally ends with the browser session. Legal bases are Section 25(2) TDDDG and Article 6(1)(b) or (f) GDPR.
5. Cart
Product identifiers and quantities are stored in the current session. Names and addresses are collected only at checkout. The legal basis is Article 6(1)(b) GDPR.
6. Checkout and payment
At checkout we process name, email address, optional phone and company, billing and delivery address, order note, and product, price, discount-code, gift-voucher, shipping, payment, status and timestamp data. For discount codes with per-email usage limits, a pseudonymised verification hash is derived from the normalized email address. For gift vouchers, validation, reservation, redemption and possible restoration use in particular a code hash, the final code characters, balance and transaction data; the complete voucher code is not displayed in the order. These data are required for ordering, code validation, payment allocation, delivery, refunds and communication. Legal bases are Article 6(1)(b) and, where required by law, Article 6(1)(c) GDPR.
7. Stripe and necessary storage access
The payment interface is loaded on checkout through Stripe.js. Stripe processes payment and device data for payment, authentication and fraud prevention and may use cookies or similar storage. Complete card or login details do not pass through our server. Where storage is strictly necessary for the requested payment and security, we rely on Section 25(2) TDDDG; processing is based on Article 6(1)(b) and (f) GDPR. Other providers may be involved depending on the selected method. See the Stripe Privacy Center.
8. Orders, delivery and accounting
Order data is used for fulfilment, production, delivery, complaints and accounting. Carriers receive required recipient details. Tax and commercial records are kept for statutory periods. Legal bases are Article 6(1)(b) and (c) GDPR.
9. Order and service email
We use the email address for order confirmation, payment status, shipping, questions and legally required messages. Advertising is sent only with a separate legal basis. Email is sent through the configured provider.
10. Returns, withdrawal and refunds
For returns, withdrawal, complaints or refunds we process contact details, order number, items, declaration, timestamps, correspondence and payment status to handle contractual and statutory claims.
11. Contact
When you contact us by email or phone, we process the information to respond. The legal basis is Article 6(1)(b) GDPR for contractual matters and otherwise Article 6(1)(f) GDPR.
12. Credit purchase and transfer to the Monvou app
When purchasing a credit package, we additionally process the pseudonymous Monvou code, package SKU, quantity, order ID, line-item ID, payment and order status and technical delivery identifiers. After payment is confirmed, only the data required to allocate the credit is sent to the technically separate Monvou app through a signed server-to-server connection. Billing address, contact details and payment data are not part of this webhook. Processing is necessary for contract performance, unambiguous allocation, duplicate prevention and error handling under Article 6(1)(b) and (f) GDPR.
13. Google Merchant Center and visibility
The public product feed intentionally sends only product, price, stock, image, link and business data to Google Merchant Center, not customer data. Google may retrieve public pages and feeds. Referrer and campaign parameters may appear in server logs after a click. Google Analytics, advertising and remarketing tags are not currently active; consent and privacy information will be updated before any later activation.
14. Recipients
Where required, recipients may include hosting and email providers, Stripe and selected payment providers, carriers, accounting or tax advisers, technical service providers and authorities. Processors are bound under Article 28 GDPR where required.
15. International transfers
Global payment and IT providers may process data outside the EEA. They state that transfers rely on adequacy decisions, safeguards such as EU standard contractual clauses or other permitted mechanisms. Details are in each provider’s privacy information.
16. Retention
Session data generally ends with the browser session. Server logs are retained only for security and error analysis. Contact requests are deleted after completion unless duties or claims require retention. Order, payment, invoice and shipping data is kept for applicable commercial and tax periods. Withdrawal and complaint records are retained as required for processing, evidence and claims.
17. Your rights
You may exercise the following rights, subject to legal requirements, at info@monvou.com:
- access to personal data stored about you
- rectification of inaccurate or incomplete data
- erasure of your data
- restriction of processing
- data portability
- objection to processing based on legitimate interests
- withdraw consent with future effect
18. Complaint
You may complain to a supervisory authority. For a controller in North Rhine-Westphalia, the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia is available.
19. Security
We use technical and organisational safeguards including HTTPS, secure sessions, CSRF protection, access restrictions, security headers and protected payment fields. Absolute security cannot be guaranteed for internet transmission.
20. Automated decisions
Monvou does not make solely automated decisions with legal or similarly significant effects. Payment providers may perform their own automated risk and fraud checks; their information and remedies apply.
21. Updates
We update this policy if features, providers or law change. The version published here applies.