Privacy Policy
Last updated: December 2025
- Introduction
This Privacy Policy explains how Julius Hildebrandt athlete.art (“we”, “us”, “our”) collects, uses, and protects your personal data when you visit our website, purchase a product, or interact with our services.
We comply with the EU General Data Protection Regulation (GDPR) and applicable data protection laws.
Contact:
Julius Hildebrandt
Robert-Bosch-Str. 15
71069 Sindelfingen
Germany
Email: julius.hildebrandt@athlete.art
- Data We Collect
We collect personal data only when necessary to operate our website, process orders, and provide customer support.
2.1. Automatically Collected Data
When you visit our website, technical data is collected automatically:
- IP address
- Browser type and version
- Device information
- Date and time of access
- Referring URL
- Pages accessed
This data is required to ensure website security and proper functionality.
- Data Collected When You Place an Order
When you purchase a product, we collect:
- Name
- Billing and shipping address
- Email address
- Order details
This information is required to process and fulfill your order and to comply with legal requirements (e.g., tax regulations).
We also send order-related email notifications, such as:
- Order confirmation
- Shipping updates
- Payment status
- Order Fulfillment via Gelato (Print-on-Demand)
We use Gelato to fulfil print production and shipping of your order.
For this purpose, the following data is transferred to Gelato:
- Name
- Shipping address
- Product details
- Order ID
Gelato may share this information with:
- Local production partners (for manufacturing)
- Shipping carriers, dynamically selected based on destination and production location (for example DHL, UPS, FedEx, USPS, Royal Mail, or others)
A GDPR-compliant Data Processing Agreement is in place with Gelato.
- Payment Processing
We offer payments via:
- Stripe
- PayPal
- Klarna
- WooCommerce Payments
- Google Pay
- Apple Pay
- Credit and debit cards
Payment information is processed directly by the respective provider.
We do not store sensitive payment data such as full credit card numbers.
Each provider processes personal data under its own privacy policy and GDPR safeguards.
- Cookies and Consent Management (CookieYes)
We use CookieYes to:
- Display a cookie consent banner
- Manage consent preferences
- Block non-essential cookies until consent is given
You can change or withdraw your consent at any time via the cookie banner settings.
- Analytics (Google Analytics)
We use Google Analytics to analyze website usage and improve performance.
Google may process:
- Pseudonymized IP address
- Device and browser information
- Interaction data (pages visited, clicks, time spent)
IP addresses are anonymized within the EU.
Data is processed based on your consent provided through the cookie banner.
- Marketing Tracking (TikTok Pixel)
We use the TikTok Pixel to measure campaign performance and optimize ads.
The pixel may collect:
- Page views
- Purchase events
- Device/browser information
Data is processed only if you give consent via the cookie banner.
- Contact Form
When you contact us through our contact form, we process:
- Name
- Email address
- Message content
We use this data exclusively to respond to your inquiry.
- Product Reviews
You may leave reviews on products.
We process the information you submit with the review, such as:
- Name or chosen display name
- Review text
- Rating
Reviews may be visible publicly.
- Social Media Links
Our website contains links to our social media profiles (e.g., Instagram, TikTok).
Clicking a link directs you to an external website with its own privacy policy.
We do not embed social media content on our website, meaning no data is transmitted until you click the link.
- Legal Bases for Processing
We process personal data according to:
- Art. 6(1)(b) GDPR: Contract performance (processing orders)
- Art. 6(1)(c) GDPR: Legal obligation (tax and accounting)
- Art. 6(1)(f) GDPR: Legitimate interests (security, fraud prevention, analytics)
- Art. 6(1)(a) GDPR: Consent (cookies, analytics, marketing pixels)
- Data Transfers Outside the EU
Some service providers (e.g., Google, TikTok, Stripe) may transfer data outside the EU.
Such transfers rely on:
- Standard Contractual Clauses (SCCs)
- Other appropriate safeguards
- Data Retention
We store data only as long as required:
- Order and tax-related data: up to 10 years (legal obligation)
- Contact form messages: up to 6 months
- Analytics and cookie data: according to provider settings and your consent
- Your GDPR Rights
You have the right to:
- Access your personal data
- Correct inaccurate data
- Request deletion
- Restrict processing
- Object to processing
- Withdraw cookie consent
- Request data portability
To exercise your rights, contact:
julius.hildebrandt@athlete.art
- Security Measures
We apply technical and organizational security measures, including:
- SSL encryption
- Secure EU-based hosting
- Limited access to personal data
- Changes to This Privacy Policy
We may update this Privacy Policy from time to time.
The latest version will always be available on our website.