Privacy Policy

1. Data Controller

The controller of your personal data is the operator of steinharttimepieces.com. For full details, refer to the legal notice section.

2. Collected Data

We process:

  • Identity Data: Name, address, contact details
  • Transaction Data: Order history, payment info
  • Technical Data: IP address, browser type, cookies

Processing occurs under:
✓ Contract fulfillment (Art. 6(1)(b) GDPR) – Order processing
✓ Legal obligation (Art. 6(1)(c) GDPR) – Tax compliance
✓ Consent (Art. 6(1)(a) GDPR) – Marketing communications

4. Data Sharing

Recipients may include:
• Payment processors (Stripe, PayPal)
• Logistics partners (DHL, UPS)
• IT service providers (EU-based with GDPR contracts)

5. International Transfers

Data may transit through:

  • Switzerland (Adequacy Decision)
  • USA (Only to Privacy Shield-certified providers)

6. Retention Periods

  • Orders: 10 years (tax requirements)
  • Customer accounts: Until deletion request
  • Cookies: 12-24 months (configurable)

7. Your Rights

You may request:
→ Access to your data
→ Rectification of errors
→ Erasure (“right to be forgotten”)
→ Restriction of processing
→ Data portability

8. Cookies & Tracking

Essential cookies:

  • Session management
  • Shopping cart functionality

Optional cookies (require consent):

  • Google Analytics (anonymized)
  • Marketing pixels

9. Security Measures

We implement:
• TLS 1.3 encryption
• Regular security audits
• Two-factor authentication for staff

10. Policy Updates

Changes will be posted here. Last updated: [Month/Year]