Datenschutzerklaerung
Rechtlich bindende deutsche Datenschutzerklaerung der GeschenkOn GmbH.
1. Controller
GeschenkOn GmbH, Königsallee 2b, 40212 Düsseldorf, Germany, email: [email protected], is responsible for this privacy policy.
2. Purposes and legal bases
We process personal data to provide the website, user accounts, ordering and voucher functions, partner workflows, security mechanisms, and legally required documentation, accounting, and settlement processes.
- Website, public content, search, accounts, and platform functions for contract initiation and performance are processed under Art. 6(1)(b) GDPR.
- Orders, vouchers, redemption, refunds, invoices, partner settlement, and electronic invoice formats are processed under Art. 6(1)(b) and (c) GDPR.
- Partner review, activation, contract administration, onboarding, role assignment, invitations, approvals, and payout preparation are processed under Art. 6(1)(b), (c), and (f) GDPR.
- Transactional emails, delivery checks, security logs, support, and abuse prevention are processed under Art. 6(1)(b) and (f) GDPR.
- Platform protection, authentication, fraud prevention, audit logging, technical troubleshooting, load balancing, and operational stability are processed under Art. 6(1)(f) GDPR.
- Cookie and tracking consent is collected, managed, and documented under Art. 6(1)(a), (c), and (f) GDPR.
Our legitimate interests include secure and stable platform operation, abuse prevention, audit-proof documentation, and the establishment, exercise, or defence of legal claims.
3. Categories of personal data
- Account data: email address, display name, language settings, optional date of birth, and status information.
- Authentication and security data: IP address, user agent, device and session data, social login identifiers, passkey/WebAuthn credential data, challenge and verification logs, and step-up events.
- Usage and access data: requested URLs, referrers, timestamps, response codes, request IDs, device and browser attributes, and server logs.
- Transaction data: order numbers, order items, voucher IDs, voucher type, legal notice versions, checkout confirmations, payment status, invoice data, tax-relevant data, refunds, and cancellations.
- Partner and contract data: contacts, business master data, contract and onboarding status, roles, invitations, review and approval notes, payout and bank verification data, settlement triggers, delay periods, billing cycles, and technical approval status.
- Communication data: support requests, transactional emails, delivery status, delivery events, sending metadata, and communication history.
- Consent and cookie data: consent ID, consent status, categories, timestamps, and technically necessary cookie information.
- Billing and e-invoice data: billing months, net, tax, and gross amounts, corrections, cancellations, file metadata, and structured document content.
- Audit and abuse data: approval histories, role changes, security events, delivery and webhook metadata, abuse signals, and technical evidence.
4. Account, authentication, and social login
We currently use Google Cloud Identity Platform for registration, login, and account management. Depending on the chosen method, we process email address, technical user IDs, session information, status data, and authentication-related security data.
We also support passkey and WebAuthn-based login and security functions. We store the required technical credential data and security logs, but no raw biometric data. Biometric or device-based approval takes place locally on the user device.
We currently offer social login through Google. Depending on the information released, we process in particular email address, technical account ID, and basic profile data.
5. Partner onboarding, contracts, and role management
When companies or representatives apply as partners or existing partner access is administered, we process additional business-related and personal data. This includes company name, contact persons, business contact and address data, onboarding and contract status, intended platform use, review and approval notes, identity or representation checks, payout and bank verification data, and contract and document metadata.
For controlled access management we also process operator invitations and role information, including recipient email address, target role, related franchise, brand, or shop reference, invitation status, expiry date, sending, acceptance, rejection, cancellation and resend events, and the responsible administrator.
6. Orders, vouchers, payments, settlement, and e-invoicing
For contract performance we process order, voucher, payment, communication, and status data, including order numbers, order item data, voucher IDs, recipient references, payment references, invoice numbers, and tax-relevant documentation.
Productive payment processing is handled through Stripe as technical payment service provider. We process payment, checkout, payment status, webhook, and reconciliation data as required for contract performance, fraud prevention, evidence, and tax documentation.
We also process partner-related settlement, payout, and e-invoice data, including billing periods, net, tax, and gross amounts, payout references, Stripe Connect verification and payout status, corrections or cancellations, and structured data for formats such as XRechnung and ZUGFeRD.
For new voucher structures we store the voucher type, relevant legal notice version, required checkout confirmations, and a settlement policy snapshot for each order item. This supports contract performance, evidence, partner settlement, tax documentation, and handling questions or reversals.
7. Transactional emails and communication metadata
We use Mailgun as technical email service provider for transactional emails, preferably in the EU region. We process recipient address, template and delivery information, sending times, message and delivery status, bounce or error events, technical delivery events, security and webhook metadata, and related support and evidence information.
8. Website access, hosting, logs, and technical security
When the website or app is accessed, we process server and access logs, including IP address, access date and time, requested URL, header information, technical response data, device and browser attributes, referrer, and request IDs.
For hosting, delivery, and central platform functions we use Google Cloud services, including Firebase Hosting, Cloud Run, Identity Platform, Cloud Storage, Cloud SQL, and Cloud Tasks.
We additionally process audit, security, and abuse logs, including role and approval events, invitation and onboarding history, error states, delivery and webhook events, abuse signals, and other technical evidence where required for secure provision, troubleshooting, abuse prevention, and legal defence.
9. Cookies and consent management
We use technically necessary cookies and session-related storage mechanisms to provide the website, login, session management, security controls, and core platform functions. We currently use Cookiebot for consent management and process consent status, consent ID, consent categories, timestamps, and technically required cookie information.
10. Categories of recipients
- Google Cloud as technical infrastructure and platform provider.
- Cloudflare for domain and DNS services.
- Mailgun for transactional email delivery and delivery metadata.
- Cookiebot for consent management and consent documentation.
- Partner shops where required for contract performance, redemption, invoicing, partner settlement, or handling partner-related services.
11. Transfers to third countries
Processing by Mailgun in its EU region and by Cloud Storage in europe-west3 takes place within the EU and is not a third-country transfer. For the EEA contracting entity of Stripe, processing in the United States by appropriately certified recipients relies on the adequacy decision for the EU-US Data Privacy Framework.
12. Retention periods
- Server and access logs: generally 30 days unless longer retention is required for security, evidence, or abuse prevention.
- Login and security event data: generally 90 days unless longer storage is required for abuse investigation or legal defence.
- Orders, invoices, and tax-relevant transaction data: 10 years where commercial or tax duties apply.
- Partner contract, onboarding, payout, and verification data: as long as required for contract performance, legal obligations, review purposes, and legal defence.
- Settlement and e-invoice data: as long as required for bookkeeping, tax evidence, compliance, and commercial documentation.
13. Rights of data subjects
You have the right of access, rectification, erasure, restriction of processing, data portability, and objection in accordance with statutory requirements. Where processing is based on consent, you may withdraw that consent at any time with effect for the future.
14. Complaint and changes
You have the right to lodge a complaint with a data protection supervisory authority. We may update this privacy policy if legal, technical, or operational circumstances change or if we introduce new services, functions, or processing activities.
Current clarification on Stripe KYC data (effective 18 July 2026)
In the active Connected Account onboarding flow, Stripe collects and verifies the KYC, identity, representative, tax, document and payout-bank information required for the account directly within Stripe embedded components. For this flow, GeschenkOn generally stores only the Stripe account reference, technical status and requirement codes, timestamps and necessary audit data. Newly entered identity documents, selfies, complete bank details and KYC form contents are not copied into the GeschenkOn onboarding database.
Historical onboarding profile data collected before this change may remain access-restricted until a documented retention and deletion review is completed. It is not reused or displayed in the active Stripe onboarding flow. Legally required contract and business records are processed separately from Stripe KYC data.
Current SC&T allocation and audit-data clarification (effective 22 July 2026)
For the SC&T payment flow, we process immutable allocation and audit data for the checkout batch, seller order, Franchise, payment reference, partner gross proceeds, commission, tax, cross-border transfer service fee, small-order surcharge, partner Transfer, Transfer reversal, refund, dispute, chargeback and correction. Each economically relevant entry receives a unique event key, a source-object reference and an integrity hash; corrections are recorded through linked contra or correction entries and do not silently overwrite the original record. We process this evidence only to the extent required for contract performance, settlement, fraud prevention, legal defence and statutory tax and retention duties.
For a non-German partner commission invoice without German VAT, we process the contractual business and VAT-ID data, documented verification source, review time and reviewer identifier, plus a non-reversible evidence hash linked to the immutable seller allocation. If reviewed evidence is missing, the cross-border zero-VAT path remains blocked.
Stripe continues to collect KYC, identity-document and payout-bank data directly in its embedded components. GeschenkOn does not copy the newly entered KYC form contents, identity documents, selfies or complete bank details into its onboarding database.
Additional information on retention, account deletion, processors, and consent
Retention and account deletion
- We retain order and invoice data due to commercial and tax-law obligations for ten years after the end of the business year in which the order was placed or the invoice was issued. When an account is deleted, these records remain; the link to the user account is permanently and irreversibly masked.
- Functional carts are soft-deleted and personal links are masked after the existing retention period, currently 30 days from the last activity. This happens immediately when an account is deleted.
- Raw reach and usage analytics events are collected only after consent and retained for no more than 14 months from the event. When consent is withdrawn or an account is deleted, they are first converted into anonymous aggregate statistics and then deleted immediately.
- Anonymous aggregate statistics contain no personal data. They are retained for three years after the end of the relevant aggregation period; account deletion has no effect on them.
Recipients, processors, and third-country transfers
Depending on the function used, the following service providers or processors receive data: the EEA contracting entity of Stripe for payments; Google Cloud, including Cloud Storage and Cloud Identity Platform, for infrastructure, files, and authentication, with Cloud Storage processed in the europe-west3 (Frankfurt) region; Mailgun for email in its EU region; Shopify for order and fulfilment processes; and Cookiebot for consent management. Cloudflare is also used for domain and DNS services, and partner shops receive data where necessary for ordering, redemption, billing, or fulfilment.
Processing by Mailgun in its EU region and by Cloud Storage in europe-west3 takes place within the EU and is not a third-country transfer. For the EEA contracting entity of Stripe, processing in the United States by appropriately certified recipients relies on the adequacy decision for the EU-US Data Privacy Framework.
Consent and withdrawal
Statistics, tracking, and marketing are activated only after voluntary consent. Consent can be withdrawn at any time with effect for the future: for cookies, statistics, and marketing through the Cookiebot privacy settings; for email, SMS, or push marketing and for personalisation and analytics in the privacy settings of the user account; or by email to [email protected]. Withdrawal does not affect the lawfulness of processing before withdrawal. Further consent-based collection stops after withdrawal; existing raw events are anonymously aggregated and deleted immediately as described above.