Privacy policy
Privacy Policy
Last updated: December 17th, 2025
1. General Information
Welcome to Art by Mercy ("we," "our," "us"). Protecting your personal data is important to us. This Privacy Policy explains how we collect, use, and share your data when you visit or make a purchase from www.artbymercy.myshopify.com in compliance with the General Data Protection Regulation (GDPR) and German privacy laws (TTDSG).
2. Data Controller
Art by Mercy
artbymercynunez@gmail.com
This website is hosted by Shopify Inc., a Canadian company that processes data in accordance with GDPR via Standard Contractual Clauses.
3. What Data We Collect
We collect and process the following personal data:
-
Identity Data: Name, email, phone number, shipping & billing address.
-
Payment Information: Processed securely via Shopify Payments, PayPal, Stripe (we do not store your payment details).
-
Technical Data: IP address, browser type, operating system, referring URLs.
-
Usage Data: Pages visited, time spent on the website, interactions with content.
-
Marketing Data: Newsletter preferences (only if you opt-in).
4. How We Collect Your Data
-
When you place an order or create an account.
-
When you contact us via email or forms.
-
Through cookies & tracking technologies (Google Analytics, Meta Pixel, etc.).
5. Why We Collect Your Data (Legal Basis)
-
To fulfil orders & deliver products (Art. 6 (1)(b) GDPR).
-
To improve our website & customer experience (Art. 6 (1)(f) GDPR).
-
To comply with legal obligations (e.g., tax regulations) (Art. 6 (1)(c) GDPR).
-
With your consent for marketing communications (Art. 6 (1)(a) GDPR).
6. Data Sharing & Third Parties
We only share your data with trusted third parties to process your order efficiently:
-
Shopify (E-commerce platform)
-
Payment Processors: Shopify Payments, PayPal, Stripe
-
Shipping Providers: DHL, Deutsche Post
-
Analytics & Marketing: Google Analytics, Meta Pixel
7. Cookies & Tracking
We use cookies to enhance your experience. You can manage cookie settings in your browser. Read our Cookie Policy for more details.
8. Data Retention & Deletion
-
We retain order data for tax/legal compliance for 10 years.
-
Marketing data is stored until you withdraw consent.
-
You can request data deletion at any time.
9. Your Rights (GDPR Compliance)
You have the right to:
-
Access, correct, or delete your personal data.
-
Restrict or object to data processing.
-
Withdraw consent for marketing emails.
-
Request data portability.
10. Contact for Privacy Concerns
For questions regarding your data, contact us at: artbymercynunez@gmail.com
If you believe we are mishandling your data, you can contact the German Data Protection Authority (BfDI):
Website: https://www.bfdi.bund.de/
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page. Please check back regularly.