Privacy Policy
This English translation is provided for your convenience only. Only the German version is legally binding. Read the binding German version.
Privacy Policy
1. Controller
MINTU OG, Handwerkstraße 8, 9500 Villach, Austria · office@mintu.shop. No data protection officer is required (Art. 37 GDPR); enquiries to office@mintu.shop.
2. Data we process
Device/usage data (browser, IP, time zone, cookies, pages viewed, referrer), order data (name, billing/shipping address, payment data, email, phone), account and routine/subscription data on registration.
3. Legal bases
Performance of contract (Art. 6(1)(b)), consent (Art. 6(1)(a), e.g. marketing/optional cookies), legitimate interest (Art. 6(1)(f), security/fraud prevention/analytics), legal obligations (Art. 6(1)(c), retention).
4. Recipients / processors
- Shopify International Ltd. – shop/checkout platform, hosting
- Shopify Payments or the chosen payment provider (card, Apple/Google Pay, PayPal, Klarna, EPS)
- Supabase – backend database/server (EU, eu-central-1)
- Email delivery via our provider''s SMTP service (digitalnova.at)
- Google Ireland Ltd. – Google Analytics (only after consent)
- shipping service providers; optional SMS/push services if activated
Transfers to third countries (e.g. USA) are based on EU Standard Contractual Clauses (Art. 46 GDPR) or an adequacy decision.
5. Cookies / tracking
Necessary cookies without consent; analytics/marketing cookies only after active consent via the cookie banner (opt-in), revocable at any time. Google Analytics and marketing pixels load only after consent.
6. Retention
Only as long as necessary; invoice/tax-relevant data for 7 years (§ 132 BAO / § 147 AO).
7. Your rights
Access, rectification, erasure, restriction, objection, portability, withdrawal of consent. Complaints: Austria – Data Protection Authority, Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at; Germany – your competent state authority.
8. Minors
The offer is intended for persons aged 18+; no knowing collection of minors'' data.