Privacy Policy
Privacy Policy
As of: August 3, 2026
1. Controller
The person responsible for processing personal data in connection with this online shop is:
Mateo Kunert
Business name: RaceHalo
Weststraße 1
06773 Gräfenhainichen
Germany
Phone: +49 151 28781097
Email: racehalo.help@outlook.com
2. General information
We process personal data only insofar as this is necessary to operate the online shop, process inquiries, process orders, personalize products, process payments, deliver goods, or fulfill legal obligations.
Personal data is information through which a natural person can be identified directly or indirectly.
Processing is carried out in particular on the basis of the following provisions:
– Article 6(1)(a) GDPR where consent has been given,
– Article 6(1)(b) GDPR for the performance of a contract or pre-contractual measures,
– Article 6(1)(c) GDPR to comply with legal obligations,
– Article 6(1)(f) GDPR to protect legitimate interests.
3. Provision of the online shop by Shopify
Our online shop is provided through the Shopify e-commerce platform.
For users within the European Economic Area, the following provider is particularly relevant:
Shopify International Limited
Attn: Data Protection Officer
c/o Intertrust Ireland
2nd Floor, 1–2 Victoria Buildings
Haddington Road
Dublin 4, D04 XN32
Ireland
Shopify processes data required for the technical provision, security, administration, and operation of the online shop.
This may include in particular:
– IP address,
– Browser and device information,
– Accessed pages,
– Date and time of access,
– Shopping cart contents,
– Cookie and consent information,
– Name and contact details,
– Billing and delivery address,
– Order information,
– Payment and transaction information,
– Security and fraud-prevention data.
Processing is carried out to provide the online shop, perform the contract, and protect our legitimate interest in operating a secure and reliable shop.
The legal bases are Article 6(1)(b) and (f) GDPR.
Shopify may process data within its corporate group and through engaged service providers outside the European Economic Area.
According to its own information, Shopify uses, depending on the recipient, adequacy decisions, Binding Corporate Rules, or Standard Contractual Clauses in particular as safeguards for international transfers.
4. Technical access data
When visiting our online shop, technically necessary access data is processed.
This may include:
– IP address,
– Date and time,
– Accessed pages and files,
– Browser type and browser version,
– Operating system,
– Referrer address,
– Device information,
– Error and security information.
Processing is carried out to ensure the stable and secure provision of the online shop and to detect technical errors or unauthorized access.
The legal basis is Article 6(1)(f) GDPR.
Our legitimate interest lies in the secure, stable, and technically reliable operation of the online shop.
5. Orders and contract processing
When you place an order, we process in particular:
– first and last name,
– email address,
– telephone number, where provided,
– billing address,
– delivery address,
– ordered products,
– personalization details,
– order number,
– order value,
– selected payment method,
– payment status,
– shipping and tracking information,
– messages related to the order.
Processing is necessary to accept, process, personalize, pay for, and deliver the order.
The legal basis is Article 6(1)(b) GDPR.
Order, contract, payment, and invoice information is also processed insofar as this is necessary to comply with statutory retention obligations under commercial and tax law.
The legal basis is Article 6(1)(c) GDPR.
6. Personalization details and file uploads
For customizable products, you may submit texts, names, numbers, images, logos, patterns, or other templates.
The following data in particular may be processed:
– entered text,
– uploaded files,
– file names and file contents,
– technical upload information,
– order number,
– contact details,
– additional notes on the requested design.
Processing is carried out to review and implement the requested personalization and to handle any potential follow-up questions.
The legal basis is Article 6(1)(b) GDPR.
Personalization details may be transmitted to the partner used for production or personalization and to the technical provider of the upload function, insofar as this is necessary to process the order.
Please do not submit any information that is not required for the requested personalization.
7. Contact by email
We use Microsoft Outlook for email communication.
The provider in the European Economic Area is:
Microsoft Ireland Operations Limited
One Microsoft Place
South County Business Park
Leopardstown
Dublin 18
Ireland
If you contact us by email, we process in particular your email address, the content of your message, and other information voluntarily provided.
If the inquiry concerns an order or a possible contract, the legal basis is Article 6(1)(b) GDPR.
For general inquiries, processing is based on Article 6(1)(f) GDPR.
Our legitimate interest lies in processing and responding to inquiries.
Microsoft may also process data outside the European Economic Area, depending on the service used. According to its own information, Microsoft uses legally prescribed transfer mechanisms for this purpose.
8. Contact form
When you use our contact form, we process in particular:
– name,
– email address,
– order number, where provided,
– content of the message,
– documents or images submitted voluntarily.
The data is used to process and respond to the inquiry.
The legal basis is Article 6(1)(b) GDPR if the inquiry concerns a contract or a potential order.
For other inquiries, the legal basis is Article 6(1)(f) GDPR.
9. Payment processing
The required data is transferred to the payment service provider selected at checkout to process the payment.
This may include in particular:
– name,
– billing address,
– email address,
– order value,
– payment method,
– transaction number,
– payment status,
– technical information required for payment.
Payment data is generally processed directly by the selected payment service provider.
We generally receive only the information required to confirm and process the payment.
The legal basis is Article 6(1)(b) GDPR.
Payment providers may independently carry out security, identity, fraud prevention, or creditworthiness checks.
These processing activities are additionally subject to the privacy notices of the selected payment provider.
10. Shop Pay and accelerated payment functions
If Shop Pay or a comparable accelerated payment function is offered at checkout, customers may use the contact, delivery, and payment information stored with the respective provider for faster processing.
When using Shop Pay, Shopify processes the account, order, contact, and payment information required to provide the function.
Use of an accelerated payment function is voluntary.
The legal basis for the processing required for the order is Article 6(1)(b) GDPR.
11. Production, fulfillment, and shipping
For the personalization, processing, and delivery of an order, the required personal data is transferred to the production, fulfillment, shipping, and logistics partners used.
This may include:
– first and last name,
– delivery address,
– telephone number, insofar as required for delivery,
– order number,
– ordered products,
– personalization details,
– uploaded templates,
– Shipping and shipment tracking information.
The transfer takes place only insofar as it is necessary to process the order.
The legal basis is Article 6(1)(b) GDPR.
Depending on the partner used, data may be transferred to a country outside the European Economic Area.
Where there is no European Commission adequacy decision, data is transferred only in accordance with the statutory requirements and using a permitted transfer mechanism.
12. Customer account
Where customer accounts are offered, the following data in particular may be processed:
– name,
– email address,
– saved addresses,
– Order history,
– Account settings.
Processing is carried out to provide and manage the customer account and to simplify the processing of orders.
The legal basis is Article 6(1)(b) GDPR.
You can request deletion of a customer account via our contact address.
Statutory retention obligations remain unaffected.
13. Newsletter
If you voluntarily subscribe to our newsletter, we process your email address to send you information about products, offers, and news.
The legal basis is your consent pursuant to Article 6(1)(a) GDPR.
You can withdraw your consent at any time, with effect for the future.
To do so, use the unsubscribe link in a newsletter email or contact us:
racehalo.help@outlook.com
The lawfulness of processing carried out before withdrawal remains unaffected.
14. Cookies and similar technologies
Our online store uses cookies and similar technologies.
Technically necessary cookies may be used in particular for the following functions:
– Shopping cart,
– Checkout,
– Customer account,
– Security features,
– Language settings,
– Privacy and consent settings.
Technically necessary cookies are used without separate consent, provided that the statutory requirements are met.
Where personal data is processed in this context, the processing is carried out in particular on the basis of Article 6(1)(b) or (f) GDPR.
Cookies and similar technologies that are not technically necessary are used only if you have previously consented via the cookie banner.
The legal basis is Section 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR.
You can change or withdraw consent at any time via the cookie settings, with effect for the future.
15. Analytics and marketing services
Optional analytics or marketing technologies are activated only if the required consent has been given.
The categories and providers offered in each individual case are displayed in the cookie banner or cookie settings.
Where personal data is processed on the basis of consent, the legal basis is Article 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG.
Consent may be withdrawn at any time via the cookie settings, with effect for the future.
16. Recipients of personal data
Depending on the specific process, personal data may be transmitted to the following categories of recipients:
– Store and hosting providers,
– Providers of the Shopify apps used,
– Production and personalization partners,
– Fulfillment service providers,
– Payment service providers,
– Banks and card companies,
– Shipping and logistics service providers,
– Email and communications providers,
– IT and security service providers,
– Accounting and tax service providers,
– Authorities and public bodies where legally required.
Data is transferred only if necessary for the performance of a contract, required by law, consent has been given, or another legal basis for permission applies.
17. International Data Transfers
Some service providers or recipients used may be located outside the European Economic Area.
In these cases, data is transferred only in compliance with the statutory requirements.
The safeguards considered include, in particular, European Commission adequacy decisions, standard contractual clauses, Binding Corporate Rules, or other safeguards provided for by law.
18. Retention Period
We store personal data only for as long as necessary for the respective processing purpose.
Order, contract, payment, and invoice data is stored in accordance with statutory commercial and tax retention obligations.
Data from customer inquiries is deleted as soon as the inquiry has been conclusively handled and there are no statutory retention obligations or legitimate reasons for further storage.
Newsletter data is stored until consent is withdrawn.
Personalization files are deleted as soon as they are no longer needed for producing, processing potential complaints, and fulfilling statutory obligations to provide evidence.
19. Your Rights
Subject to the statutory requirements, you have, in particular, the following rights:
– Right of access,
– Right to rectification,
– Right to erasure,
– Right to restriction of processing,
– Right to data portability,
– Right to object,
– Right to withdraw consent given.
To exercise your rights, you can contact us:
racehalo.help@outlook.com
20. Right to Object
Where personal data is processed on the basis of Article 6(1)(f) GDPR, you have the right to object to the processing on grounds relating to your particular situation.
If data is processed for direct marketing, you may object to this processing at any time.
21. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates data protection regulations.
In particular, you may contact the supervisory authority at your usual place of residence, your place of work, or the place of the alleged infringement.
22. Data Security
We take appropriate technical and organizational measures to protect personal data against loss, manipulation, unauthorized access, and other security risks.
Data transmission in the online shop is encrypted.
23. Changes to this Privacy Policy
We may amend this Privacy Policy if the services used, data processing activities, or legal requirements change.
The version currently published on this page applies.