Privacy Policy

Privacy Policy

Last updated: 21 August 2026

This Privacy Policy explains how wasted hour collects, uses, discloses and protects personal data when you visit www.thewastedhour.com, place an order, create a customer account, subscribe to our newsletter, contact us or shop at our Hamburg store.

1. Controller

The Wasted Hour UG (haftungsbeschränkt)
Neuer Wall 88
20354 Hamburg
Germany

Managing Director: Martin Hufnagel
Email: cs@thewastedhour.com
Telephone: +49 40 22864350

In this policy, "we", "us" and "our" refer to The Wasted Hour UG (haftungsbeschränkt). "You" refers to visitors, customers, newsletter subscribers and other people who interact with us.

2. Personal data we process

Depending on how you interact with us, we may process the following categories of personal data:

  • identity and contact data, including name, billing and delivery address, email address and telephone number;
  • account data, including login information, customer account details and saved preferences;
  • order and transaction data, including products purchased, order value, returns, refunds, fulfilment status and payment status;
  • payment-related data, which is generally collected directly by the relevant payment service provider. We do not receive your full card number;
  • communications, including emails, telephone enquiries, WhatsApp messages and customer service history;
  • marketing data, including newsletter consent, campaign interactions, browsing events and preferences;
  • technical and usage data, including IP address, device and browser information, time zone, pages viewed, referring page, interactions, cookie identifiers and consent status;
  • store and POS data, including in-store purchases, returns, receipts and legally required fiscal transaction records.

We receive personal data directly from you, automatically from your device, from Shopify and its services, from payment and delivery providers, and from marketing platforms where permitted by law.

3. Purposes and legal bases

We process personal data only where a legal basis applies. The main legal bases are:

  • Article 6(1)(b) GDPR: processing required to enter into or perform a contract, including orders, payments, delivery, returns, customer accounts and pre-contractual enquiries;
  • Article 6(1)(c) GDPR: processing required to comply with legal obligations, including tax, commercial, accounting and fiscal-record obligations;
  • Article 6(1)(f) GDPR: processing based on our legitimate interests, including secure and reliable store operation, fraud prevention, internal administration and responding to general enquiries, provided that your interests and fundamental rights do not override those interests;
  • Article 6(1)(a) GDPR: processing based on your consent, including newsletters, marketing analytics and non-essential cookies or pixels.

Where information is stored on or accessed from your device, we also apply Section 25 of the German Telecommunications Digital Services Data Protection Act, or TDDDG. Non-essential storage and access takes place only after consent.

4. Shopify platform and hosting

Our online store and point-of-sale environment are operated using Shopify. For customers in the European Economic Area, relevant Shopify services are provided by Shopify International Ltd., 2nd Floor, 1-2 Victoria Buildings, Haddington Road, Dublin 4, D04 XN32, Ireland. Shopify processes personal data needed to provide the storefront, checkout, customer accounts, Shop Pay, the Shop channel, Shopify POS, fraud prevention, technical security, analytics and related commerce services.

We also use Shopify services and applications including Online Store, Point of Sale, Shop, Search & Discovery, Order Printer, Stocky and Agentic Storefronts. Product, inventory, order, account and transaction data may be processed through these services according to the feature used. Stocky is currently used for inventory management and is being transitioned to Shopify's native inventory tools.

Shopify may process data in countries outside the European Economic Area. Shopify states that transfers within its group are protected through approved Binding Corporate Rules and that appropriate contractual safeguards are used for relevant third-party transfers.

More information is available in the Shopify Consumer Privacy Policy and the Shopify Privacy Policy.

5. Website access, security and server logs

When you access our website, Shopify and the technical infrastructure used to deliver the store may process technical information such as your IP address, request time, requested page, referrer, browser, operating system, device information and response status.

This processing is necessary to display the website, maintain stability and security, detect misuse and investigate technical problems. The legal basis is Article 6(1)(f) GDPR. Security logs are retained only for as long as reasonably necessary for these purposes or as required by law.

The website uses TLS encryption to protect data transmitted between your browser and our systems.

6. Cookies and consent management

We use cookies, pixels, local storage and similar technologies. Some are strictly necessary for the operation of the website, checkout, security, shopping cart, customer accounts, language or market selection and consent management. Other technologies are used for analytics, personalisation and marketing only after your consent.

We use Complianz Consent, provided through Complianz B.V., Netherlands, to display the consent banner, record your choices and communicate consent signals to Shopify and connected services. Complianz supports Shopify's Customer Privacy API and Google Consent Mode.

You can accept, reject or adjust non-essential processing through the consent banner. You may change or withdraw your choice at any time using the privacy or cookie settings control displayed on the website. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

The current list of detected cookies, providers, purposes and storage periods is available through the cookie settings interface. Necessary cookies may be used without consent where they are required to provide a service you requested or to secure the store.

More information about the consent service is available in the Complianz privacy information.

7. Customer accounts, orders and contract processing

When you create a customer account, place an order, request store collection, return an item or request a refund, we process the data needed to provide the requested service. This can include your name, contact details, billing and delivery address, account details, ordered products, correspondence, payment status and fulfilment information.

The legal basis is Article 6(1)(b) GDPR. Data required for accounting, tax, fraud prevention or the establishment, exercise or defence of legal claims may continue to be retained under Article 6(1)(c) or Article 6(1)(f) GDPR after the contract has been completed.

You may request the deletion of your customer account by contacting cs@thewastedhour.com. Statutory retention obligations remain unaffected.

8. Payments

We use Shopify Payments to process online payments. Payment information is transmitted to Shopify and the payment processors or payment networks required for the method selected at checkout. We generally receive confirmation of the payment, transaction identifiers, risk information and payment status, but not your complete card details.

Depending on your location and device, the following methods may be available:

  • Visa, Mastercard, American Express, Maestro and UnionPay;
  • Shop Pay, Apple Pay and Google Pay;
  • Bancontact, BLIK, EPS, iDEAL | Wero, Klarna and MobilePay.

Not every method is displayed to every customer. The available method depends on the delivery market, currency, device and eligibility requirements. USDC is not active in our store.

The legal basis for payment processing is Article 6(1)(b) GDPR. Payment providers may independently process data for authentication, fraud prevention, regulatory compliance and, where relevant, credit assessment. Their own terms and privacy notices apply to such processing.

Further information is available in Shopify's payment method information for Germany, the Apple Privacy Policy, the Google Privacy Policy and the Klarna Privacy Policy.

9. Delivery and store collection

For delivery, we disclose the information required to transport and deliver your order, including recipient name, delivery address, email address, telephone number where necessary, parcel details and shipment reference.

Our principal shipping provider is United Parcel Service Deutschland S.à r.l. & Co. OHG, Görlitzer Straße 1, 41460 Neuss, Germany. We also use the UPS Shipping (Official) application to prepare labels, transmit shipping data and manage tracking. The legal basis is Article 6(1)(b) GDPR.

If you choose store collection, we process your order and contact details to prepare the goods and notify you when they are ready. Collection takes place at wasted hour, Neuer Wall 88, 20354 Hamburg.

More information is available in the UPS Privacy Notice.

10. Invoices, receipts, fiscal records and operational applications

We use service providers and Shopify applications to create invoices, packing slips, receipts and barcode labels, administer orders and inventory, and comply with fiscal requirements. Depending on the function used, these services may process customer identity and contact data, order details, product data, transaction data, location data and technical information.

easybill

When the integration is enabled, easybill GmbH, Düsselstr. 21, 41564 Kaarst, Germany, processes customer, order and invoice data to create and administer invoices, credit notes, delivery notes and accounting exports. The legal bases are Article 6(1)(b) and Article 6(1)(c) GDPR.

easybill Privacy Policy

Order Printer Pro, Order Printer Templates and Orderly Emails

We use Order Printer Pro, Order Printer Templates and Orderly Emails, provided by FORSBERG+two ApS, Havesvinget 15, 2950 Vedbæk, Denmark. These services access relevant shop, order, transaction, fulfilment and product information to generate documents, document previews and branded transactional email templates. The legal bases are Article 6(1)(b), Article 6(1)(c) and Article 6(1)(f) GDPR.

FORSBERG+two Privacy Policy

OpenFiskal

For legally compliant POS fiscalisation, receipts, TSE signatures, cash-book records and required exports, we use OpenFiskal GmbH, Rosenthaler Str. 72A, 10119 Berlin, Germany. OpenFiskal may process customer, order, transaction, refund, product, location and technical data. Processing is based on Article 6(1)(b) and Article 6(1)(c) GDPR.

OpenFiskal Privacy Policy

Barcode Man

We use BarcodeMan Barcode Labels, provided by Gookit, Inc., Taipei City, Taiwan, to generate and print product barcodes and labels. The application has technical access permissions for product, shop and certain customer or device data within Shopify. Data is processed only to the extent required to provide and support the application. The legal basis is Article 6(1)(f) GDPR, based on our interest in accurate product and inventory administration.

BarcodeMan information in the Shopify App Store

11. Custom fonts and theme functionality

We use the RT: Google Fonts, Custom Fonts application, also displayed as Font Picker, provided by RoarTheme, District 2, Ho Chi Minh City, Vietnam, to apply our own brand font to the Shopify theme. Our intended configuration uses uploaded custom font files delivered through the store infrastructure rather than loading fonts directly from Google Fonts.

The provider may process technical shop and administrator information required to operate and support the application. The legal basis is Article 6(1)(f) GDPR, based on our interest in a consistent brand presentation and reliable theme operation.

RoarTheme Privacy Policy

12. Contact by email, telephone and WhatsApp

If you contact us by email or telephone, we process the information you provide to respond to your request. The legal basis is Article 6(1)(f) GDPR for general enquiries and Article 6(1)(b) GDPR where the communication relates to a purchase or prospective contract.

We also provide a link to contact us through WhatsApp. When you use that link or send us a WhatsApp message, WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland, processes your telephone number, message content, communication metadata and other information according to its own privacy terms. Please do not send sensitive information through WhatsApp.

WhatsApp Privacy Policy for the EEA

13. Newsletter and Mailchimp

If you subscribe to our newsletter, we process your email address and, where provided, your name and preferences to send news about products, events, collaborations and store updates. Registration uses a double opt-in process. This means that you must confirm your subscription through a confirmation email.

The legal basis is your consent under Article 6(1)(a) GDPR. We retain evidence of the consent, including registration and confirmation time and relevant technical information, to demonstrate compliance.

We use Mailchimp, a service of Intuit and The Rocket Science Group LLC, United States, to manage subscriptions, send newsletters and evaluate campaign performance. Subject to your consent, Mailchimp may record email delivery, opens, link clicks, device information, IP-derived information and resulting website interactions. Mailchimp is also connected to Shopify through web and server events for consented marketing automation and measurement.

You can unsubscribe at any time using the link in every newsletter or by emailing cs@thewastedhour.com. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Mailchimp Privacy Statement

14. Analytics, advertising and customer events

With your consent, we use customer-event pixels and related server-side integrations to understand how the store is used, measure campaigns, create audiences and display relevant advertising. These services can process online identifiers, IP address, browser and device information, pages and products viewed, searches, cart activity, purchases, transaction values and campaign interactions.

Marketing and analytics technologies are activated only in accordance with your consent choices. The legal basis is Article 6(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw consent at any time through the website's privacy or cookie settings.

Google & YouTube

We use the Google & YouTube sales channel and its web pixel, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Depending on the enabled configuration and your consent, Google may process browsing and purchase events for analytics, conversion measurement, product listings, advertising and audience functions. Google may link this information to a Google account if you are signed in and its own settings permit this.

Google Privacy Policy

Facebook & Instagram

We use the Facebook & Instagram sales channel, Meta Pixel and server-side event transmission, provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. Depending on your consent and our configuration, Meta may receive browser events, server events, product and purchase information, transaction identifiers and matched or hashed contact information for conversion measurement, advertising and audience functions. Meta may associate this information with Facebook or Instagram accounts.

Meta Privacy Policy

Mailchimp customer events

Mailchimp receives consented web and server events through its Shopify integration. These events may be used for newsletter analytics, customer segmentation, campaign measurement and marketing automation as described in Section 13.

15. Social media and external links

Our website may link to external services such as Instagram and Facebook. A simple link does not transmit data to the destination provider until you click it. Once you follow an external link, the relevant provider processes data under its own responsibility and privacy terms.

Our products may also appear through Shopify's Shop channel, Google, Meta and Shopify Agentic Storefronts. If you interact with us through a third-party platform, that platform's privacy policy applies in addition to this policy.

16. Recipients and international data transfers

We disclose personal data only where necessary for the purposes described in this policy. Recipients can include:

  • Shopify and its subprocessors;
  • payment providers, payment networks, banks and fraud-prevention services;
  • shipping and logistics providers;
  • invoice, accounting, POS, fiscalisation, document and inventory service providers;
  • newsletter, consent, analytics and advertising providers;
  • professional advisers, public authorities and courts where legally required.

Some providers are located outside the European Economic Area or process data in other countries, including Canada, the United States, Taiwan and Vietnam. Data transfers take place only where permitted under Chapter V GDPR, for example on the basis of an adequacy decision, approved Binding Corporate Rules, European Commission Standard Contractual Clauses or another lawful transfer mechanism. Depending on the country, local authorities may have access rights that differ from those within the European Union.

17. Data retention

We retain personal data only for as long as necessary for the relevant purpose or as required by law. In particular:

  • order, invoice, accounting and fiscal records are retained for the applicable statutory retention periods under German commercial and tax law;
  • customer account data is retained until the account is deleted, subject to legal retention obligations;
  • customer service communications are retained until the enquiry is resolved and for an appropriate period thereafter where required for documentation or legal claims;
  • newsletter data is retained until consent is withdrawn, while evidence of consent may be retained for the relevant limitation period;
  • consent records are retained for as long as necessary to demonstrate compliance;
  • analytics and advertising data is retained according to the configured periods of the relevant provider and your consent choices.

Data may be retained for longer where required to comply with law, resolve disputes or establish, exercise or defend legal claims. When the purpose and legal retention requirements end, data is deleted or anonymised.

18. Your rights

Subject to the conditions of the GDPR, you may have the following rights:

  • the right of access under Article 15 GDPR;
  • the right to rectification under Article 16 GDPR;
  • the right to erasure under Article 17 GDPR;
  • the right to restriction of processing under Article 18 GDPR;
  • the right to data portability under Article 20 GDPR;
  • the right to object to processing based on Article 6(1)(e) or Article 6(1)(f) GDPR under Article 21 GDPR;
  • the right to withdraw consent at any time under Article 7(3) GDPR;
  • the right to lodge a complaint with a supervisory authority under Article 77 GDPR.

If personal data is processed for direct marketing, you have the right to object at any time. We will then stop processing the relevant data for direct marketing.

To exercise your rights, contact cs@thewastedhour.com. We may need to verify your identity before completing a request.

19. Supervisory authority

You may lodge a complaint with the data protection authority responsible for your habitual residence, place of work or the alleged infringement. Our local supervisory authority is:

The Hamburg Commissioner for Data Protection and Freedom of Information
Ludwig-Erhard-Str. 22
20459 Hamburg
Germany
datenschutz-hamburg.de

20. Changes to this Privacy Policy

We may update this Privacy Policy when our services, providers, legal obligations or processing activities change. The current version and its update date are published on this page. Where required by law, we will provide additional notice or request renewed consent.