Privacy policy
Privacy Policy
Last updated: Q2 2026
Fandom Snacks GmbH operates this shop and website to provide you, the customer, with a personalized shopping experience (the "Services"). This Privacy Policy describes how we collect, use and disclose personal data when you visit, use or make a purchase through our Services, or otherwise communicate with us.
If there is a conflict between our Terms and Conditions and this Privacy Policy, this Privacy Policy shall prevail with regard to the collection, processing and disclosure of your personal data.
Please read this Privacy Policy carefully. By using or accessing any of the Services, you acknowledge that you have read this Privacy Policy and agree to the collection, use and disclosure of your information as described herein.
We are the data controller within the meaning of the General Data Protection Regulation (GDPR) and applicable national data protection laws.
1. What Personal Data Do We Collect?
Depending on how you interact with our Services, we may collect or process the following categories of personal data:
– Contact information: name, postal address, billing address, shipping address, telephone number and email address
– Financial data: payment method, payment confirmation and other payment-related details
– Account information: username, password, security questions, settings and configurations
– Transaction information: items you view, add to cart or purchase, returns, cancellations and past transactions
– Communications: information you provide when contacting customer support
– Device information: information about your device, browser or network connection, IP address and other unique identifiers
– Usage information: information about how and when you interact with our Services
2. Sources of Personal Data
We may collect personal data from the following sources:
– Directly from you: for example when you create an account, use our Services, place an order or contact us
– Automatically through the Services: via cookies and similar technologies when you visit our website
– From service providers: when they collect or process personal data on our behalf
– From partners and other third parties
3. Legal Bases for Processing
We process your personal data on the following legal bases pursuant to Art. 6 of the General Data Protection Regulation (GDPR):
– Order fulfillment, payment and shipping: Art. 6(1)(b) GDPR (performance of a contract)
– Management of your customer account: Art. 6(1)(b) GDPR (contract initiation and performance)
– Fraud prevention and security: Art. 6(1)(f) GDPR (legitimate interest of Fandom Snacks GmbH)
– Technically necessary cookies: Art. 6(1)(f) GDPR (legitimate interest for operating the shop)
– Analytics and marketing cookies: Art. 6(1)(a) GDPR (your consent)
– Email marketing and newsletters: Art. 6(1)(a) GDPR (your explicit consent via double opt-in)
– Compliance with statutory retention obligations: Art. 6(1)(c) GDPR (§ 257 HGB, § 147 AO)
– Customer inquiries and support: Art. 6(1)(b) and (f) GDPR
4. How Do We Use Your Personal Data?
Providing, Customizing and Improving the Services
Including fulfilling our contractual obligations to you, processing payments, executing orders, organizing shipping, handling returns and exchanges, managing accounts, sending order-related notifications and creating a personalized shopping experience.
Marketing and Advertising
Including sending marketing communications by email or post, and showing you personalized advertising based on your interactions with our Services — in each case only with your consent (Art. 6(1)(a) GDPR) and in compliance with applicable law.
Security and Fraud Prevention
Including authenticating accounts, securing transactions, and detecting and preventing fraudulent or unlawful activity.
Communicating with You
Including providing customer support, responding to inquiries and maintaining our business relationship with you.
Legal Reasons
Including complying with applicable laws, responding to lawful requests, enforcing our terms and policies, and protecting our rights and the rights of others.
5. Email Marketing
When you sign up for our newsletter or email marketing communications, we process your email address and, where applicable, your name on the basis of your explicit consent pursuant to Art. 6(1)(a) GDPR.
We use the double opt-in procedure: after registering, you will receive a confirmation email. You will only be added to our mailing list after clicking the confirmation link in that email. A record of your consent is retained.
You may withdraw your consent at any time — either via the unsubscribe link in any of our emails or by contacting info@fandomsnacks.com. Following withdrawal, your data will be deleted from our mailing list.
6. How Do We Share Personal Data?
Service Providers and Processors
Including Shopify and other third parties acting on our behalf, such as IT service providers, payment processors, analytics providers, customer support services, cloud storage providers and fulfillment and shipping partners.
Fulfillment and Logistics
For the purpose of order fulfillment and shipping, we work with professional logistics partners, including Elbe-Werkstätten GmbH. In this context, personal data such as name, shipping address and order details are shared exclusively for the purpose of fulfilling and delivering your order pursuant to Art. 6(1)(b) GDPR. Elbe-Werkstätten GmbH processes personal data strictly on our behalf and under a data processing agreement in accordance with Art. 28 GDPR.
Shopify
Our Services are hosted on the Shopify platform. Shopify processes personal data related to your use of the Services to provide and improve the platform. Data submitted through the Services may be transferred to Shopify and third parties in other countries. More information can be found in the Shopify Consumer Privacy Policy and the Shopify Privacy Portal.
Other Third Parties
Data may also be shared with business and marketing partners who may process data in accordance with their own privacy policies; with your consent; within our corporate group; and in connection with a business transaction, to comply with legal obligations or to protect rights.
7. Cookies and Similar Technologies
We use cookies and similar tracking technologies on our website. Cookies are small text files stored in your browser. We distinguish the following categories:
Technically Necessary Cookies
These cookies are strictly required for the operation of the shop (e.g. shopping cart, session management, login). Legal basis: Art. 6(1)(f) GDPR. They are set without consent and cannot be deactivated.
Analytics Cookies
With your consent, we use analytics cookies to analyze user behavior and improve our Services. Legal basis: Art. 6(1)(a) GDPR. Storage period: max. 12 months. Withdrawal: at any time via the cookie preference center.
Marketing Cookies
With your consent, we use marketing cookies to show you personalized advertising on other platforms. Legal basis: Art. 6(1)(a) GDPR. Withdrawal: at any time via the cookie preference center.
You may adjust or withdraw your cookie settings at any time via our cookie preference center, which appears on your first visit and is accessible via the "Cookie Settings" link in the footer.
8. Data Retention
We retain personal data only for as long as is necessary for the respective processing purposes or as required by statutory retention obligations:
– Order data and tax-relevant records: 10 years pursuant to § 147 of the German Tax Code (AO)
– Commercial correspondence and business communications: 6 years pursuant to § 257 of the German Commercial Code (HGB)
– Customer account data: until account deletion; thereafter deleted within 30 days, unless statutory retention obligations apply
– Email marketing consent records: until withdrawal of consent; proof of consent retained for max. 3 years after withdrawal
– Cookies and tracking data: in accordance with your consent; technically necessary cookies for max. 12 months
9. Your Rights
Depending on your location, you may have the following rights in relation to your personal data:
– Right of access (Art. 15 GDPR)
– Right to rectification (Art. 16 GDPR)
– Right to erasure (Art. 17 GDPR)
– Right to restriction of processing (Art. 18 GDPR)
– Right to data portability (Art. 20 GDPR)
– Right to object to processing (Art. 21 GDPR)
– Right to withdraw consent (Art. 7(3) GDPR)
– Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
To exercise your rights, please contact: info@fandomsnacks.com
We honor Global Privacy Control (GPC) signals where legally required.
10. Right to Lodge a Complaint
If you believe that the processing of your personal data by Fandom Snacks GmbH violates the GDPR, you have the right to lodge a complaint with the competent data protection supervisory authority at any time.
The competent supervisory authority for Fandom Snacks GmbH is:
The State Commissioner for Data Protection of Lower Saxony (LfD NI)
Prinzenstraße 5, 30159 Hanover, Germany
PO Box 221, 30002 Hanover, Germany
Phone: +49 (0)511 120-4500
Email: poststelle@lfd.niedersachsen.de
Website: www.lfd.niedersachsen.de
You also have the right to lodge a complaint with the supervisory authority of your habitual place of residence, your place of work or the place of the alleged infringement.
11. International Data Transfers
Personal data may be transferred to other countries. Where required, we rely on recognized safeguards, in particular EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR.
12. Third-Party Links
Our Services may contain links to third-party websites or platforms. We are not responsible for their privacy practices or content. Please review their privacy policies before providing personal data.
13. Children's Data
Our Services are not directed at children under the age of 16. We do not knowingly collect personal data from individuals under the age of 16. For the processing of personal data of minors under 16, the consent of a parent or legal guardian is required pursuant to Art. 8 GDPR.
14. Data Security
We take appropriate technical and organizational measures to protect your personal data against unauthorized access, loss or disclosure. No security system is perfect and we cannot guarantee absolute security.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The updated version will be published on our website with a revised "Last updated" date.
16. Contact
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:
Fandom Snacks GmbH
Zum Reiherhorst 6
21435 Stelle
Germany
Phone: +49 (0)4174-5929-0
Email: info@fandomsnacks.com
We are the data controller within the meaning of applicable data protection laws.