Privacy policy
Draft. Not finished legal text.
Everything in [square brackets] is still missing. The operator's name, address and contact details have to be filled in, and the wording should be checked by a lawyer or a legal-text service before the shop goes live.
The short version
You can look around this shop without telling us who you are. We set no cookie unless you use the language switcher, and then only one that remembers your language. There is no cookie banner because there is nothing to agree to.
We count page views on our own, without cookies and without any other company. When you order, we need your name, address and e-mail to send you the parcel; you pay on a secure page run by Stripe.
Who is responsible
The controller under Art. 4(7) GDPR is:
[Full name of the owner, or company name with legal form]
[Street and number]
[Postcode] [City]
Germany
E-mail: [hello@dewlycare.com]
Hosting and server logs
This website and its server functions are hosted by Netlify, Inc., 101 2nd Street, San Francisco, CA 94105, USA.
Every time a page is requested, the server automatically records technical data: your IP address, the date and time, the page requested, the referring page and your browser's user-agent string. We need this to deliver the site and to detect and fend off attacks. Legal basis: Art. 6(1)(f) GDPR (our legitimate interest in a secure, working website).
Netlify processes this data on our behalf under a data processing agreement (Art. 28 GDPR). Data may be transferred to the USA; Netlify is certified under the EU-US Data Privacy Framework, and standard contractual clauses of the EU Commission apply in addition. Retention of server logs: [retention period of Netlify's server logs — to be confirmed].
Our fonts are stored on our own server. Your browser does not contact Google or any other font service.
Cookies and storage in your browser
We set exactly one cookie, and only if you choose a language with the language switcher yourself. It is called dewly-lang, contains nothing but the language code (for example "de"), and keeps your choice for one year so the shop does not switch you back. It is strictly necessary for a function you asked for, so no consent is needed (§ 25(2) no. 2 TDDDG).
Your cart is kept in your own browser (local storage, key dewly-cart-v1): which products, which shade or size, and how many. It stays on your device and is not sent to us until you go to checkout. You can delete it at any time by emptying the cart or clearing your browser data. It, too, is strictly necessary for the cart you use (§ 25(2) no. 2 TDDDG).
How we count visits
We want to know which pages are read, so we count page views ourselves. A small script on the page sends one short message to our own server per page view. No cookie is set, nothing is stored on your device, and no analytics company is involved.
Stored per page view: the page and the time; the name of the site you came from (for example "google" — not the full address); campaign tags in the link (utm_source, utm_medium, utm_campaign); browser, operating system and device type; country and region derived from your IP address; and a daily visitor code. The daily code is a SHA-256 hash of a secret key, the date, your IP address and your browser's user-agent, shortened to 16 characters. Your IP address itself is never stored. Because the date is part of the code, a new, unconnected code is made every day.
This is pseudonymised data, not anonymous data: with the secret key, a date, an IP address and a user-agent, the code could be calculated again. The data is stored with our host, Netlify (Netlify Blobs), see "Hosting". Legal basis: Art. 6(1)(f) GDPR (our legitimate interest in knowing which pages are used, in the least intrusive way).
If your browser sends "Do Not Track" or "Global Privacy Control", the script sends nothing at all.
Retention: [retention period for visit data — to be set, together with the job that deletes older days; nothing is deleted automatically yet].
When you order
When you press "Go to checkout", your cart (products, shade or size, quantities) is sent to our server and you are taken to a payment page run by Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin 2, Ireland. There you enter your e-mail address, name, delivery address, optionally a phone number, and your payment details.
Stripe processes your payment details as an independent controller; we never see your full card details. Stripe's privacy policy: stripe.com/privacy.
After payment we receive from Stripe your name, delivery address, e-mail address, phone number (if given), the products ordered and the amounts. We use them to pack and send your order and to answer questions about it. An order notification with these details is e-mailed to us through Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA, which processes it on our behalf (Art. 28 GDPR); data may be transferred to the USA, Resend is certified under the EU-US Data Privacy Framework and standard contractual clauses apply in addition. Where we use one, the order is also passed to a shipping or fulfilment service over an encrypted connection: [name of the carrier and any fulfilment partner, e.g. DHL — to be added].
Legal basis: Art. 6(1)(b) GDPR (performance of the contract). Order and invoice records are kept for up to 10 years because tax and commercial law require it (Art. 6(1)(c) GDPR with § 147 AO and § 257 HGB); after that they are deleted.
There is no customer account: we do not keep a profile of you beyond the order itself.
When you e-mail us
If you write to us, we use your message and your e-mail address to answer you. Legal basis: Art. 6(1)(b) GDPR where it concerns an order, otherwise Art. 6(1)(f) GDPR. We delete the correspondence once it is no longer needed, unless statutory retention periods apply.
What we do not use
No newsletter, no social media plugins, no tracking pixels, no advertising networks, no third-party analytics, no Google Fonts. We do not sell or rent your data, and we make no automated decisions about you (Art. 22 GDPR).
Your rights
You have the right to access your data (Art. 15 GDPR), to have it corrected (Art. 16), deleted (Art. 17) or its processing restricted (Art. 18), to receive it in a portable format (Art. 20), and to object to processing based on Art. 6(1)(f) (Art. 21). Where processing is based on consent, you can withdraw it at any time with effect for the future (Art. 7(3)). An e-mail to the address above is enough.
You also have the right to complain to a data protection supervisory authority (Art. 77 GDPR), for example the one responsible for us: [data protection authority of the operator's federal state].
Last updated: 25 September 2026