Privacy policy

Last updated: 12 August 2026

1. Controller

Arsmenzi
Owner: Göktan Zafer Arslan
Nordbergstr. 21
74076 Heilbronn
Germany
Phone: +49 176 87345293
Email: shop@arsmenzi.com

2. Data we process

Depending on your use of the store, we process contact and identification data, billing and delivery addresses, order and payment-related information, account data, correspondence, returns and support information, IP address, browser and log data, cookie identifiers and usage information.

Card and bank information is generally processed directly by the selected payment provider. We receive only information needed to confirm and administer payment.

3. Purposes and legal bases

We process data to perform a contract or take pre-contractual steps (Article 6(1)(b) GDPR), comply with legal obligations (Article 6(1)(c)), pursue legitimate interests in operating, securing, preventing fraud, supporting and improving the store (Article 6(1)(f)), or with consent for optional cookies, analytics or marketing (Article 6(1)(a)). Consent can be withdrawn for the future at any time.

4. Orders, accounts and support

We use provided data to process orders, payments, deliveries, returns, refunds, customer accounts and support requests.

5. Shopify

Our store is hosted by Shopify. Shopify processes data as a service provider and, for certain services, as an independent controller. Data may be processed outside the European Economic Area using recognised transfer mechanisms where required. Further information is available in Shopify's privacy information.

6. Payment providers

Information needed to process, authenticate, prevent fraud and administer a payment is sent to the selected provider. The provider's privacy information applies to processing under its responsibility.

7. Suppliers, fulfilment providers and carriers

We may share the recipient's name, address, required contact details and order information with suppliers, fulfilment providers and carriers where necessary to prepare and deliver an order, manage tracking or returns.

8. Cookies and similar technologies

Necessary technologies provide the store, remember the cart, authenticate users, secure checkout and prevent misuse. Optional analytics and marketing technologies are used only where permitted and, where required, after consent. Choices can be managed in the site's cookie settings.

9. Google services

Where activated with the required consent, Google Analytics, Google Ads, Merchant Center and the Google & YouTube sales channel may be used to measure use, attribute conversions, display products and advertising and create reports. Online identifiers, device information, visited pages, shopping interactions and conversions may be transmitted to Google.

10. Communications and marketing

We use contact details for enquiries and transactional order information. Marketing is sent only with a valid legal basis. You can object to direct marketing at any time.

11. Recipients and international transfers

Recipients can include IT and hosting providers, Shopify, payment providers, suppliers, fulfilment providers, carriers, support providers, advisers and authorities where required, plus consented analytics or advertising providers.

Transfers outside the EEA rely on an adequacy decision, appropriate safeguards such as European Commission standard contractual clauses, or another permitted mechanism.

12. Retention

Data is retained only as long as necessary. Contract, invoice and tax records are retained for applicable statutory periods, generally six or eight years depending on the document and legal requirement. Data needed for legal claims may be retained until the limitation period expires. Other data is deleted or anonymised when no longer required.

13. Your rights

Subject to legal requirements, you can request access, correction, deletion, restriction and portability, and object to processing based on legitimate interests. You may object to direct marketing at any time. Contact shop@arsmenzi.com. We may need to verify your identity.

14. Complaint

You may complain to a data protection authority. The authority responsible for our establishment is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (LfDI Baden-Württemberg). You may also contact the authority at your habitual residence or workplace.

15. Automated decisions

We do not make legally or similarly significant decisions solely through automated processing unless necessary for a contract, permitted by law or based on explicit consent. Fraud and payment providers may conduct checks under their own responsibility.

16. Security

We use appropriate technical and organisational measures to protect data. No internet transmission or storage method can be guaranteed completely secure.

17. Changes

We may update this notice when services, laws or processing activities change. The current version and update date are published here.