1. Controller
4BeaTz – Music & Fashion GbR
Heribertistraße 40, 44866 Bochum, Germany
E‑mail: info@4beatzfashion.com • Phone: +49 155 61531050
Represented by: Kevin Orhan Heine, Denise Heine
Data Protection Officer: not appointed (no statutory requirement)
2. Hosting & platform (Shopify)
Our store is operated on Shopify (Shopify International Ltd., 2nd Floor, 1–2 Victoria Buildings, Haddington Road, Dublin 4, D04 XN32, Ireland). Processing may occur in Canada and the USA. Shopify uses EU Standard Contractual Clauses to safeguard international transfers. Details are available in Shopify’s privacy information (linked in our store).
Legal bases: Art. 6 (1) (b) GDPR (contract/order fulfilment), (f) (operation/security), and (c) (legal obligations) where applicable.
3. Access data & log files
When you visit our pages, Shopify processes technical data (IP address, time, requested URL, user agent). Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in stability/security).
4. Cookies & consent (German TDDDG / GDPR)
We use cookies and similar technologies. Non‑essential tools (e.g., analytics/marketing) are activated only with your prior consent (opt‑in pursuant to Section 25 TDDDG in conjunction with Art. 6 (1) (a) GDPR). You can adjust your choices at any time in the consent banner/preferences center.
5. Data we process & purposes
Categories: name, billing and shipping address, contact details, order information, payment transaction identifiers (no full card numbers), and communication data.
Purposes: order processing, customer service, store operation, fraud prevention, compliance with legal duties.
Recipients / categories:
Payment services: Shopify Payments (credit card), PayPal, Klarna/Sofort
Fulfilment/production: print‑on‑demand/production partners we commission
Carriers: e.g., DHL/DPD/UPS
IT/analytics/marketing providers as listed below, after consent
6. Customer account
If you create an account, we process master data, order history and login details (Art. 6 (1) (b) GDPR). We delete upon request or after purpose ends, subject to statutory retention.
7. Analytics & marketing tools (after consent)
Google Analytics 4 (GA4) via Google Tag Manager (Google Ireland Ltd.): statistics/usage analysis; IP anonymization; retention per property settings.
Meta Pixel (Meta Platforms Ireland Ltd.): conversion tracking/retargeting.
Shopify analytics: operational statistics.
Legal basis: Art. 6 (1) (a) GDPR and Section 25 TDDDG; you may withdraw consent at any time with effect for the future in the consent banner.
8. Communication
When you contact us (e‑mail/phone/contact form), we process your data to handle the request (Art. 6 (1) (b) and (f) GDPR). E‑mail provider: e.g., Zoho Mail (if used).
9. Retention
Commercial/tax records are kept for 10 years (Sections 147 AO, 257 HGB). We delete other data once purposes cease and no retention duties apply.
10. Your rights (Art. 12–22 GDPR)
You have the rights to access, rectification, erasure, restriction, data portability, objection (Art. 21 GDPR), withdrawal of consent (Art. 7 (3) GDPR), and to lodge a complaint with a supervisory authority. The competent authority is typically the State Commissioner for Data Protection and Freedom of Information North Rhine‑Westphalia (LDI NRW).
11. International transfers
Where providers outside the EU/EEA are used, we ensure adequate safeguards (e.g., Standard Contractual Clauses, Art. 46 GDPR).
12. Security
We apply technical and organizational measures (including TLS encryption) to protect your data.
13. Updates
We update this policy if our processing changes. Last updated: 02 Nov 2025.