Privacy Policy
WHAT IS PERSONAL DATA
Personal data is all information that can be individually assigned to you either directly or indirectly. This includes, for example, your name, address, telephone number, cell phone number, fax number and email address.
THE TYPES OF PERSONAL DATA WE COLLECT
You can generally visit Candlebloom Arts' Shop without providing us with any information that directly identifies you. Please note, however, that you may not be able to use certain areas of the Shop or certain services we offer.
WEB SERVER LOGS (INCL. IP ADDRESSES)
When you visit and use the Shop, our web server automatically collects so-called access data out of technical necessity, which your terminal device automatically transmits. This log record may include the following information: your IP address, the date and time you are on the Shop, the pages you visit on the Shop, the name of the file you retrieve and the amount of data transferred, the message whether the retrieval was successful, the website you were on before (so-called referrer website), the browser you use (e.g. Microsoft Edge or Google Chrome), the operating system you use (e.g. Windows 10) as well as the domain name and address of your internet provider.
We collect the listed data to ensure a smooth connection setup of the website and to enable a comfortable use of our website by the users. In addition, the log file serves the evaluation of system security and stability as well as administrative purposes. The legal basis for the temporary storage of the data or the log files is Art. 6 para. 1 (f) GDPR.
PERSONAL DATA SUBMITTED BY YOU
(a) Otherwise, we collect personal data from you if you have provided it to us on the basis of consent according to Art. 6 para. 1 (a) GDPR in order to provide, operate and administer the Marketplace in accordance with our User Agreement (see www..com/agreement) and to provide you with our services.
-
Specifically, we (a) collect your username and email address when you create a user account and register for the Shop; (b) collect your name, shipping address, billing address, phone number, email address, and bank or payment information when you order a product through the Shop; (c) collect your email address when you fill out a form or send us an email. When we collect your personal data, we will inform you whether the provision of the respective personal data is required or merely optional, as well as about the possible consequences if you do not provide the respective information.
-
In addition, we collect personal data that you provide to us in connection with your visit to and use of the Shop and our services, e.g. your sales and order history, favorite and marked products on the Marketplace, your movements and executed actions on the Shop. Insofar as you use a so-called single sign-on function of a social network to log in to the Shop, we collect your personal data from the corresponding social network that you have made publicly available there.
(b) If you have given us your consent (Art. 6 para. 1 (a) GDPR), we will also collect your email address as part of the registration process for our newsletter and other promotional messages.
HOW WE PROCESS YOUR PERSONAL DATA
4.1. We process your personal data in order to provide and operate the Shop in accordance with our User Agreement and to provide you with our services, in particular (a) for the processing and coordination of sales and orders on the Shop; and (b) for the provision of a functional and accurately running Shop– within the range of what is technically possible and reasonable – by observing, monitoring and maintaining the performance of the Shop(in particular by identifying and appropriately resolving problems and errors).
The legal basis for this is the fulfillment of our contractual obligations vis-à-vis our Users according to Article 6 para. 1 (b) GDPR.
Please note with regard to the communication via message boards, chat rooms or interactive online forums explained in section 4.1(d) that if you post a comment on a message board or chat room, this information will be made available to the public in an online environment. Each comment posted is the sole responsibility of the individual user. If you use such an interactive area, you should always be aware that these areas, and therefore any personal information shared there, are publicly accessible. We cannot control how other visitors to the Shop use this information. In particular, we cannot prevent you from receiving unsolicited communications.
4.2. Furthermore, we process your personal data as a precaution against and prevention of fraudulent acts on the Shop.
The legal basis for this is Article 6 para. 1 (f) GDPR. Our legitimate interests in this context are to protect the integrity of the Shop, our services, our system and our users.
4.3. Furthermore, we process your personal data for our efforts to (a) provide you with the most optimal and meaningful user experience possible when visiting and using our Shop and services; and (b) improve and optimize the Shop, its layout and content, and our services.
The legal basis for this is our legitimate interest according to Article 6 para. 1 (f) GDPR. Our legitimate interests in this context are to provide you with an optimal and meaningful user experience on the Shop that meets your expectations and needs on the one hand and fulfills our commercial interests on the other hand.
4.4. To the extent you have given us your consent, we will further process your collected personal data for the provision and optimization of our email marketing efforts, in particular the provision of our newsletter and other marketing messages about Candlebloom Arts events, Candlebloom Arts services, Candlebloom Arts products and special Candlebloom Arts offers.
You may revoke your consent at any time with future effect. You may do so at any time by following the instructions included in any email or by contacting our customer service. If you have given us your consent, we will continue to process your email address to send you helpful information about using our services from time to time. You can disable these messages at any time by deactivating the receipt of such messages in the settings functions of your user account.
The legal basis for this is Article 6(1)(a) GDPR.
4.5. Furthermore, we may process the information collected by our web server (cf. Section 3.1) in the event of system abuse in cooperation with your Internet provider and/or local authorities in order to determine the originator of this abuse.
The legal basis for this is our legitimate interest according to Article 6 para. 1 (f) GDPR. Our legitimate interests in this context are the protection of the integrity of the Shop, our services, our system and our users.
Google Analytics
Our website uses Google Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). Google Analytics uses so-called cookies.
On behalf of the operator of this website, Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other data from Google.
We only use Google Analytics with IP anonymization activated. This means that the IP address of the user is shortened.
The processing of Google Analytics is carried out in accordance with Art. 6 para. 1 (a) GDPR on the basis of your consent. We have concluded an order processing agreement with the service provider in which we oblige him to protect our customers' data and not to pass it on to third parties.
The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected.
You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) to Google and the processing of this data by Google by downloading and installing the browser plug-in available at the URL https://tools.google.com/dlpage/gaoptout?hl=en.
Information on how Google Analytics handles user data can be found in Google's privacy policy: https://support.google.com/analytics/answer/6004245?hl=en.
HOW WE PROCESS YOUR PERSONAL DATA
We take all necessary and reasonable steps to keep your personal data secure, but by its nature, unfortunately, no system is impenetrable. Due to the inherent nature of the Internet, we cannot guarantee that information is one hundred percent secure from unauthorized access during transmission over the Internet or while it is stored on our system or otherwise. Your payments are made over an encrypted connection or through a secure data processor. Access to your personal data on our databases is subject to appropriate technical security measures.
STORAGE PERIOD
Your personal data will be stored by us only as long as it is necessary to achieve the purposes for which it was collected or, if there are any legal retention periods beyond this, for the duration of the legally prescribed retention period. Subsequently, your personal data will be deleted.
COOKIES AND SIMILAR TECHNOLOGIES
For the processing of personal data using cookies and similar technologies in the context of the Shop, please see our Cookie Policy (including our Consent Manager Tool), which is part of this Privacy Policy.
COOKIES AND SIMILAR TECHNOLOGIES
In accordance with applicable data protection law, you may have the following rights.
9.1 Right to access: You may have the right to request information about your personal data stored by us at any time in accordance with GDPR Article 15. When we process your personal data, we take reasonable steps to ensure that your personal data is accurate and up to date for the purposes for which it was collected.
9.2. Right to Rectification: Your user account shows you the essential personal data that is stored by us. You can view, change and/or delete this personal data at your own discretion. In accordance with GDPR Article 16, if your personal data is inaccurate or incomplete, you may request that it be corrected.
9.3 Right to Erasure (Right to be Forgotten) In accordance with GDPR Article 17, you may have the right to request the deletion or restriction of the processing of your personal data if, for example, there is no longer a legitimate business purpose for such processing under this Privacy Policy or applicable law and legal retention obligations do not prevent further storage.
Furthermore, you can contact us at any time with a request for information, deletion and restriction under the contact options listed in Section 1. In accordance with Article 19, we will communicate any rectification or erasure of personal data to each data subject.
9.4 Right to data portability: In accordance with GDPR Article 20, you may have the right to receive the personal data concerning you that you have provided to us in a structured, common and machine-readable format or to transfer this data to another controller. For this purpose, please contact the contact options listed under Section 1.
9.5 Right to object: In accordance with GDPR Article 21, you may have the right to object to the processing of your personal data on specific grounds relating to your particular situation. To do so, please contact the contact options listed under Section 1.
9.6 Right to revoke your consent: If you have consented to the collection and processing of your personal data, you may revoke your consent at any time with effect for the future, but without affecting the lawfulness of the processing carried out on the basis of the consent until revocation. You can also object to the use of your personal data for the purposes of market and opinion research as well as advertising and to unsubscribe from receiving our newsletter (see Section 4.4). To do so, please use the contact options listed under section 1.
9.7 Without prejudice to any other administrative or judicial remedy, you also have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data infringes the GDPR (Article 77 GDPR).
CHANGES
We reserve the right to change this Privacy Policy at any time in accordance with the law. This may be necessary, for example, to comply with new legislation or in the case of new services. In the event that we make substantial changes, we will notify you via email, push notification or similar.
Last Updated : September 2025