1. Controller
VOGUE HANDBAGS AG
Zielstattstraße 27, 81379 Munich, Germany
Board Representative: Sibylle Schön (Chairwoman)
Phone: +49 89 76993-0 · Fax: +49 89 7607785
Supervisory Board Chair: Evi Brandl
Register: Amtsgericht München, HRB 63254 · VAT: DE 129272981
Responsible under §18 MStV: Sibylle Schön, same address
Imprint: https://www.voguehandbags.com/imprint
2. Data Protection Officer
Intersoft Consulting Services AG – Attn. Heidrun Ortmeier
Beim Strohhause 17, 20097 Hamburg, Germany
Email: [email protected]
3. Access Data & Hosting
When you visit our site, our server automatically logs: requested file, IP address, date/time, data volume, provider, OS, browser info, and referrer. This “access data” is used to ensure stable, secure operations. Where essential cookies are used, this occurs under §25(2) TDDDG and Art. 6(1)(f) GDPR (legitimate interests). Essential session data is deleted at session end; other access logs are deleted within 7 days.
4. Orders & Contact Requests
We process personal data you voluntarily provide (e.g., name, email, password, message content) to perform contracts (Art. 6(1)(b) GDPR) or respond to inquiries (Art. 6(1)(f) GDPR). After completion:
- Contract-related records are retained per statutory periods (e.g., tax: 10 years; commercial letters: 6 years).
- Inquiry data based on legitimate interest is kept up to 2 years for quality control unless you consent to longer storage or law permits further use. You may object anytime at [email protected].
5. Registration / Customer Account
If you register, we collect title, name, email, password, plus log details (IP, date/time). Basis: Art. 6(1)(b) GDPR to provide a secure account and ordering flow. Security logs are stored for 7 days. You may request account deletion at [email protected] (legal retention duties may still apply).
6. Data Sharing
To fulfill contracts (Art. 6(1)(b) GDPR), we share data with service providers (printing, shipping/logistics, banks, IT, marketing) and—where necessary—advisors, insurers, debt collectors, and public authorities. We use processors under GDPR-compliant contracts. For third-country processing, we verify protection levels and use safeguards (Art. 44 ff GDPR; SCCs; TIAs).
Hosting: maxcluster GmbH, Germany.
Logistics (orders/returns): ITG GmbH Internationale Spedition und Logistik (receives title, name, address, phone, email, articles to deliver/handle returns).
6.2 Payments
Depending on your chosen method, payment data goes to the relevant processor; some providers may act as independent controllers under their own T&Cs and privacy policies.
- Mollie (cards: VISA, Amex, MasterCard) – processes account/card data; see their privacy policy.
- Klarna (Pay in 30 / Slice It) – uses address/identity data for assessment; see Klarna privacy policy.
- PayPal – uses title, name, address, phone, email; see PayPal privacy policy.
- Apple Pay – uses address/identity data; see Apple privacy policy.
If unpaid invoices occur, payment providers or we may engage collection agencies (Art. 6(1)(f) GDPR).
7. Applications (Careers)
We process applicant data to decide on employment (Art. 6(1)(b) GDPR). Typical data: name, address, role applied for, email, CV, certificates, plus optional cover letter.
- Retention: 6 months after process completion (or up to 3 years with consent; longer where needed to defend claims under Art. 6(1)(f)).
- You may withdraw consent anytime at [email protected].
- Only HR and the responsible hiring managers access your application.
8. Trusted Shops Trustbadge / Widgets
We use the Trusted Shops Trustbadge to display the seal, ratings, and buyer protection. Integration serves secure shopping (Art. 6(1)(f) GDPR; §25 TDDDG) and, where applicable, occurs with your consent (Art. 6(1)(a) GDPR; §25(1) TDDDG). On load, a server log file (with IP, date/time, data volume, provider) is generated; IPs are anonymized immediately. After purchase, hashed email/order details may be checked by Trusted Shops to offer buyer protection or rating services (based on consent/contract). Some processing may occur in the USA/Israel under appropriate safeguards (e.g., SCCs, adequacy).
9. Email Newsletter (Double Opt-In)
With your consent (Art. 6(1)(a) GDPR), we email updates about VOGUE HANDBAGS AG products/services. You can unsubscribe anytime via link or [email protected]. We use ActiveCampaign (USA; DPF-certified; SCCs in place) as a processor. After you revoke consent, we delete your email and tracking data unless required for compliance proof (Art. 5(2) GDPR).
10. Review Reminders
With your consent (Art. 6(1)(a) GDPR), we may email you reminders to review your order (we may transmit your email and order reference to Trusted Shops). You can revoke via the review email or [email protected]. Review data may be retained up to 2 years for quality assurance.
11. Cookies & Tools
We use cookies and similar technologies:
- Necessary/functional (no consent needed; Art. 6(1)(f) GDPR; §25(2) TDDDG).
- Analytics/performance, targeting/marketing, and third-party cookies require your consent (Art. 6(1)(a) GDPR; §25(1) TDDDG).
You can manage cookies in our banner/footer (“Cookie Settings”) or in your browser settings (links provided for Edge/Safari/Chrome/Firefox/Opera). A detailed cookie list (purpose, runtime, provider, cross-border transfer) is available in Section 15 (Cookie Usage).
12. Analytics & Marketing
- Google Analytics (Universal/GA4) with IP anonymization (consent-based). Data may go to the USA (Google DPF/SCCs). You can revoke consent anytime or use the opt-out add-on.
- Google Ads (Remarketing & Conversion Tracking) (consent-based). Cookies typically last 180 days; you can opt out via Google Ads settings or industry tools.
- Google Tag Manager (used to load other tags; consent-based where it triggers non-essential tools).
- Google reCAPTCHA v2 (consent-based; protects forms from abuse and may use fingerprinting techniques).
- ADCELL Partner Program (consent-based affiliate tracking cookies with specified runtimes).
- Criteo (dynamic retargeting; consent-based; opt-outs available).
- Smartlook (heatmaps/session insights based on legitimate interest; hides personal content).
- New Relic (backend performance monitoring; necessary for site reliability; no personal data or IP addresses sent).
- Matomo (On-Premise) (consent-based; EU storage; IP anonymized; opt-out available).
13. Social Media & Media Embeds
- Shariff is used to prevent automatic data transfer to networks; you decide when to connect.
- YouTube embeds use 2-click solution (consent required; data may go to the USA under SCCs/DPF).
- Instagram (Meta): We use Instagram for communications; Instagram collects data under its own privacy policy. We use Insights (aggregate, anonymized stats). Legal bases: Art. 6(1)(f) (communications), Art. 6(1)(b) (contract-related messages).
- Meta Pixel / Conversion API / Advanced Matching: With your consent, we use these tools for conversion measurement and interest-based ads. Joint controllership with Meta under Art. 26 GDPR (collection & transfer); Meta’s further processing is separate. Transfers to the USA rely on DPF/SCCs + supplementary measures. You can revoke consent anytime in Cookie Settings and use Meta ad preference tools to manage ads. Typical cookie lifetime: up to 180 days; matching data usually deleted within ~48 hours; event data may be retained by Meta per its terms (up to 2 years).
14. Your Rights & Contact
You have rights to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), withdraw consent (Art. 7(3)), complain to a DPA (Art. 77), and object (Art. 21) to processing based on public interest/legitimate interest or for direct marketing.
Contact for rights requests: [email protected].
Supervisory authority: e.g., Bavaria DPA (Promenade 18, 91522 Ansbach; https://www.lda.bayern.de/de/beschwerde.html).
Right to Object: If we process your data for legitimate interests, you may object on grounds relating to your situation; for direct marketing, you may object at any time.
15. Cookie Usage
We only set strictly necessary cookies without consent. All others require your permission. You can change/withdraw consent anytime in our cookie banner. See our privacy policy to learn who we are, how to contact us, and how we process personal data.
Your consent applies to the following domains: us.voguehandbags.com.