Privacy policy
Last updated: January 17, 2026
1. Controller and Contact Details
The controller responsible for data processing under the General Data Protection Regulation (GDPR) is:
Das Coeur
Polly Bäumler
Clementine-von-Braunmühl-Weg 17
81541 Munich
Email: hello@dascoeur.com
Phone: +49 172 863 3793
2. Overview
This Privacy Policy explains how we collect, use, and process personal data when you visit, use, or make a purchase from our online store (the “Services”).
Our store is hosted on Shopify, which provides the technical infrastructure. Where Shopify processes personal data independently (for example for platform security, analytics, or advertising services), Shopify acts as an independent controller.
3. Categories of Personal Data
We may process the following categories of personal data:
- Contact data: name, billing and shipping address, email address, phone number
- Order and transaction data: purchased items, order history, returns, refunds
- Payment data: payment method and transaction confirmation (payment details are processed by payment providers and are not stored by us)
- Account data: login credentials, preferences
- Communication data: inquiries, customer support messages
- Usage and device data: IP address, browser type, device information, log files
- Marketing data: newsletter subscriptions, consent status, marketing preferences
4. Sources of Personal Data
Personal data is collected:
- directly from you
- automatically through the use of our Services (e.g. cookies and log files)
- from Shopify and other service providers acting on our behalf
5. Purposes and Legal Bases of Processing
We process personal data only where permitted by law. The legal bases under Article 6 GDPR include:
Purpose |
Legal Basis |
|---|---|
Order processing, payment, shipping |
Art. 6(1)(b) GDPR |
Customer account management |
Art. 6(1)(b) GDPR |
Customer support and communication |
Art. 6(1)(b), Art. 6(1)(f) GDPR |
Fraud prevention and platform security |
Art. 6(1)(f) GDPR |
Compliance with legal obligations |
Art. 6(1)(c) GDPR |
Marketing communications (email) |
Art. 6(1)(a) GDPR |
Website analytics and optimization |
Art. 6(1)(a) or Art. 6(1)(f) GDPR |
Affiliate tracking and attribution |
Art. 6(1)(a) GDPR |