Privacy Policy
1. Data Controller
The controller of your personal data is the operator of steinharttimepieces.com. For full details, refer to the legal notice section.
2. Collected Data
We process:
- Identity Data: Name, address, contact details
- Transaction Data: Order history, payment info
- Technical Data: IP address, browser type, cookies
3. Legal Basis & Purpose
Processing occurs under:
✓ Contract fulfillment (Art. 6(1)(b) GDPR) – Order processing
✓ Legal obligation (Art. 6(1)(c) GDPR) – Tax compliance
✓ Consent (Art. 6(1)(a) GDPR) – Marketing communications
4. Data Sharing
Recipients may include:
• Payment processors (Stripe, PayPal)
• Logistics partners (DHL, UPS)
• IT service providers (EU-based with GDPR contracts)
5. International Transfers
Data may transit through:
- Switzerland (Adequacy Decision)
- USA (Only to Privacy Shield-certified providers)
6. Retention Periods
- Orders: 10 years (tax requirements)
- Customer accounts: Until deletion request
- Cookies: 12-24 months (configurable)
7. Your Rights
You may request:
→ Access to your data
→ Rectification of errors
→ Erasure (“right to be forgotten”)
→ Restriction of processing
→ Data portability
8. Cookies & Tracking
Essential cookies:
- Session management
- Shopping cart functionality
Optional cookies (require consent):
- Google Analytics (anonymized)
- Marketing pixels
9. Security Measures
We implement:
• TLS 1.3 encryption
• Regular security audits
• Two-factor authentication for staff
10. Policy Updates
Changes will be posted here. Last updated: [Month/Year]
