Privacy policy
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR / DSGVO) is:
Navina Bündert
Y Patterns (sole proprietorship / Einzelunternehmen)
Sodenkamp 4b
22337 Hamburg
Germany
Email: hello@y-patterns.com
2. General information on data processing
Unless otherwise stated below, the provision of your personal data is neither legally nor contractually required, nor necessary for the conclusion of a contract. You are not obliged to provide the data. Failure to provide it has no consequences. This applies only insofar as no other information is provided in the processing operations described below.
"Personal data" means any information relating to an identified or identifiable natural person.
3. Hosting and shop platform
Our website is operated on the Shopify platform. The provider is Shopify International Limited (Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland). Shopify processes personal data on our behalf that arises when our website is visited and our online shop is used. Details on data processing by Shopify: https://www.shopify.com/legal/privacy
Processing is based on Art. 6 (1) (f) GDPR/DSGVO out of our legitimate interest in the secure and efficient provision of our online shop. We have concluded a data processing agreement with Shopify. Shopify may also process personal data outside the EU/EEA, in particular in Canada and the USA. Insofar as no adequacy decision exists, the transfer takes place on the basis of suitable safeguards, in particular the EU Standard Contractual Clauses.
4. Server log files
Each time our website is accessed, the hosting provider (Shopify) automatically collects information and stores it in log files (server log files). These data include, among others:
- IP address of the requesting device
- Date and time of access
- Name and URL of the page accessed
- Volume of data transferred
- Browser type and version
- Operating system
- Referrer URL
Processing is based on Art. 6 (1) (f) GDPR/DSGVO out of our legitimate interest in ensuring trouble-free operation of our website and in improving our offering.
5. Cookies and consent management
Our website uses cookies. Cookies are small text files stored in or by the internet browser on a user's computer system. When a user accesses a website, a cookie may be stored on the user's operating system.
Cookies are stored on your device. You therefore have full control over the use of cookies. By selecting the appropriate technical settings in your browser you can prevent the storage of cookies and the transmission of the data they contain. Cookies already stored can be deleted at any time. Please note, however, that you may then not be able to use all functions of this website to their full extent.
Technically necessary cookies. We use technically necessary cookies to make our offering more user-friendly, effective and secure. This includes in particular cookies required for the operation of the shopping cart and the checkout process. The use of technically necessary cookies is based on § 25 (2) no. 2 TDDDG. Processing of your personal data is based on Art. 6 (1) (f) GDPR/DSGVO out of our legitimate interest in ensuring the optimal functionality of the website.
Consent-based cookies. Cookies that are not technically necessary (e.g. for analytics or marketing purposes) are only set with your express consent. Consent is given via our cookie banner. Processing is based on § 25 (1) TDDDG in conjunction with Art. 6 (1) (a) GDPR/DSGVO. You can withdraw your consent at any time.
Analytics and marketing services, in particular Google Analytics, Google Ads conversion tracking, Meta Pixel and Amazon PartnerNet tracking, are only activated if you have previously consented via our consent banner. Without consent, these services are not loaded and no corresponding cookies are set or corresponding terminal-device information read out. You can withdraw your consent at any time via "Cookie settings".
6. Contacting us
By email. If you contact us by email, we collect your personal data (name, email address, message content) only to the extent you provide it. The processing serves to handle and respond to your enquiry. Where contact serves to carry out pre-contractual measures or concerns an existing contract, processing is based on Art. 6 (1) (b) GDPR/DSGVO. Where contact is made for other reasons, processing is based on Art. 6 (1) (f) GDPR/DSGVO out of our legitimate interest in handling your enquiry. Your data will be deleted after the enquiry has been dealt with, subject to statutory retention periods, unless you have consented to further processing.
Contact form. When using the contact form, we collect your personal data (name, email address, message content) only to the extent you provide it. The legal bases correspond to those for email contact (above).
7. Customer account and orders
Customer account. When you open a customer account, we collect the personal data you enter there. The processing serves to improve your shopping experience and simplify order handling. Processing is based on Art. 6 (1) (a) GDPR/DSGVO with your consent. You can withdraw your consent at any time by notifying us; your customer account will then be deleted.
Orders. When you place an order, we collect and process your personal data only insofar as this is necessary to fulfil and process your order and to handle your enquiries. The provision of the data is necessary for the conclusion of the contract; without it, no contract can be concluded. Processing is based on Art. 6 (1) (b) GDPR/DSGVO and is necessary for the performance of a contract with you. Your data may be passed to the payment service providers, order-processing service providers and IT service providers involved. The scope of data transmission is limited to a minimum.
As we offer digital products exclusively, we do not pass on any order data to shipping service providers.
8. Payment service providers
Shopify Payments. For payment processing we use Shopify Payments (provided by Stripe). When paying by credit/debit card (Visa, Mastercard, American Express), Shop Pay, Apple Pay or Google Pay, the data required for payment processing is forwarded to Stripe. Processing is based on Art. 6 (1) (b) GDPR/DSGVO. More information: https://stripe.com/privacy
The payment methods enabled in the Y Patterns checkout are: Shop Pay, PayPal, Apple Pay, Google Pay, Klarna, and credit/debit cards (Visa, Mastercard, American Express) via Shopify Payments.
PayPal. When paying via PayPal, your payment data is transmitted to PayPal (Europe) S.à r.l. et Cie, S.C.A. (22-24 Boulevard Royal, L-2449 Luxembourg). Processing is based on Art. 6 (1) (b) GDPR/DSGVO. PayPal privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full
Klarna. When using Klarna payment methods, your data is transmitted to Klarna Bank AB (Sveavägen 46, 111 34 Stockholm, Sweden). Processing is based on Art. 6 (1) (b) GDPR/DSGVO. Klarna privacy policy: https://www.klarna.com/de/datenschutz/
9. Analytics
Shopify Analytics. We use Shopify's integrated analytics function to obtain information about usage behaviour on our website. Processing is based on Art. 6 (1) (f) GDPR/DSGVO out of our legitimate interest in the needs-based design of our website.
Google Analytics. We use Google Analytics on our website, a web analytics service of Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; "Google"). Google Analytics uses technologies such as cookies that enable analysis of website use. The information generated about your use of this website is generally transferred to and stored on a Google server. A transfer to the USA cannot be excluded. For transfers to the USA, reference is made to the EU Commission's adequacy decision for the EU-U.S. Data Privacy Framework, insofar as the recipient is certified accordingly. IP anonymisation is activated on this website. The use of cookies is based on § 25 (1) TDDDG in conjunction with Art. 6 (1) (a) GDPR/DSGVO (consent); you can withdraw consent at any time. Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de — Google privacy: https://policies.google.com/privacy
10. Advertising and remarketing
Google Ads / conversion tracking. We use the online advertising programme Google Ads and conversion tracking of Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). When you click an ad placed by Google, a cookie for conversion tracking is set. These cookies have limited validity and serve to measure the success of our ads. The use of cookies is based on § 25 (1) TDDDG in conjunction with Art. 6 (1) (a) GDPR/DSGVO (consent); you can withdraw consent at any time. Deactivate personalised advertising: https://adssettings.google.com
Meta Pixel (Facebook / Instagram). We use the Meta Pixel of Meta Platforms Ireland Limited (Merrion Road, Dublin 4, D04 X2K5, Ireland; "Meta"). The pixel serves to address visitors of our website with interest-based advertising on Facebook and Instagram and to measure the effectiveness of our ads. When you visit our website, the pixel establishes a direct connection to Meta servers, transmitting which of our pages you have visited; Meta assigns this information to your personal user account, if any. Your data may be transmitted to the USA; reference is made to the EU Commission's adequacy decision for the EU-U.S. Data Privacy Framework, insofar as the recipient is certified accordingly. Meta and we are joint controllers for the collection of your data when the service is embedded; the joint-processing agreement is available at: https://www.facebook.com/legal/controller_addendum The use of the Meta Pixel is based on § 25 (1) TDDDG in conjunction with Art. 6 (1) (a) GDPR/DSGVO (consent); you can withdraw consent at any time. Meta privacy: https://www.facebook.com/about/privacy/
Social media. Our website contains links to the following social networks: Facebook and Instagram (Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland — https://www.facebook.com/about/privacy/ / https://help.instagram.com/155833707900388), Pinterest (Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland — https://policy.pinterest.com/de/privacy-policy). When you click a social media link you are redirected to the respective platform; only then is data transmitted to the respective provider.
Amazon affiliate programme. We participate in the "Amazon PartnerNet" affiliate programme of Amazon EU S.à.r.l. (5 Rue Plaetis, L-2338 Luxembourg). Advertising links to offers on Amazon are set up on our website. Amazon uses cookies to trace the origin of orders. The use of cookies is based on § 25 (1) TDDDG in conjunction with Art. 6 (1) (a) GDPR/DSGVO (consent); you can withdraw consent at any time. Amazon privacy: https://www.amazon.de/gp/help/customer/display.html?nodeId=201909010
Customer reviews (Judge.me). We use the review service Judge.me (Judge.me LTD, 19 Kingsford St, Belmore NSW 2192, Australia) on our website. We only send review requests by email if you have consented to this or insofar as the conditions of § 7 (3) UWG are met. You can object to receiving review requests at any time, without incurring costs other than the transmission costs at the basic rates. We mark reviews as "verified" if they can be assigned to an order in our shop; reviews without such an assignment are not marked as verified. A transfer to Australia only takes place insofar as suitable safeguards pursuant to Art. 46 GDPR, in particular the EU Standard Contractual Clauses, have been concluded. More information: https://judge.me/privacy
Wishlist (Wishlist Hero). We use the wishlist service Wishlist Hero, operated by Revamp (8400 Normandale Lake Blvd., Suite 920, Minneapolis, MN 55437, USA). When you add products to your wishlist, the service stores the products concerned together with an identifier of your browser/device and, for logged-in customers, your customer ID, so that your wishlist remains available. Processing is based on Art. 6 (1) (f) GDPR/DSGVO (legitimate interest in providing a wishlist function) or, where set via non-essential cookies, on § 25 (1) TDDDG in conjunction with Art. 6 (1) (a) GDPR/DSGVO (consent). Data may be transferred to the USA; such transfer only takes place insofar as suitable safeguards pursuant to Art. 46 GDPR, in particular the EU Standard Contractual Clauses, have been concluded. More information: https://www.revampco.com/privacy-policy/
11. Newsletter (Brevo)
For sending our newsletter we use the service Brevo (Sendinblue GmbH, Köpenicker Str. 126, 10179 Berlin). When you subscribe to our newsletter, your email address and, where applicable, your name are transmitted to and stored at Brevo. Processing is based on Art. 6 (1) (a) GDPR/DSGVO with your consent. You can withdraw your consent at any time, e.g. via the unsubscribe link in every newsletter; your email address is then removed from the distribution list. Brevo privacy: https://www.brevo.com/de/legal/privacypolicy/
Direct advertising by email. We use the email address we received in connection with the sale of goods or services to send electronic advertising for our own similar goods or services, unless you have objected to this use. Processing is based on Art. 6 (1) (f) GDPR/DSGVO (legitimate interest in direct advertising) in conjunction with § 7 (3) UWG. You can object to this use at any time, e.g. via the unsubscribe link in the email or by notifying us.
12. Data subject rights
Where the legal requirements are met, you have the following rights under Art. 15 to 20 GDPR/DSGVO:
- Right of access (Art. 15)
- Right to rectification (Art. 16)
- Right to erasure (Art. 17)
- Right to restriction of processing (Art. 18)
- Right to data portability (Art. 20)
- Right to object (Art. 21)
Right to object. Where the processing of personal data described here is based on our legitimate interest under Art. 6 (1) (f) GDPR/DSGVO, you have the right to object at any time, for reasons arising from your particular situation, to such processing with effect for the future. Where personal data is processed for direct advertising purposes, you can object to this processing at any time by notifying us; after your objection we will cease processing the data concerned for direct advertising.
Right to lodge a complaint. Under Art. 77 GDPR/DSGVO you have the right to lodge a complaint with a supervisory authority if you consider that the processing of your personal data is unlawful. The supervisory authority responsible for us is: Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit, Ludwig-Erhard-Str. 22, 20459 Hamburg.
13. Duration of storage
After complete contract processing, the data is initially stored for the duration of the warranty period, then subject to statutory retention periods, in particular under tax and commercial law, and then deleted after expiry of those periods, unless you have consented to further processing and use.
This is an English courtesy translation. For consumers resident in Germany, the German version is legally authoritative.
Last updated: 20 June 2026