Privacy policy

Last updated: 9 December 2025

1 | Controller

Ehrlich & Friedrich GbR Scharnweberstraße 49 10247 Berlin, Germany E-mail: hello@solarpunknow.world Phone: +49 176 480 848 32

2 | Data Protection Officer

Denny Ehrlich – reachable via the contact details above or by e-mail at: denny@solarpunknow.world

3 | Hosting & Content Delivery

Our shop is hosted by Shopify International Ltd., Ireland (data processing on our behalf pursuant to Art. 28 GDPR). Shopify uses sub-processors (including Shopify Inc., Canada/USA, DPF-certified). Data transfers are based on the EU Standard Contractual Clauses (SCC) and/or the EU-US Data Privacy Framework (DPF).

4 | Server Log Files

Each time the site is accessed, the servers automatically store:

  • IP address
  • Date / time
  • Request URL, referrer
  • Browser & operating system
  • Volume of data transferred

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in the technically error-free operation of the site). Deletion: automatically after 30 days.

5 | Cookies & Consent Management

We use cookies to ensure the functionality of our website (necessary cookies) as well as for statistical and marketing purposes. We use the consent management tool Consentmo to obtain your consent to the storage of certain cookies on your device and to document this consent in compliance with data protection law.

  • Necessary cookies: Set on the basis of legitimate interest (Art. 6 (1) (f) GDPR) (e.g. shopping cart).
  • Analytics & marketing cookies: Are only set after you have given your consent via our consent banner (Art. 6 (1) (a) GDPR).
  • You can withdraw or adjust your consent at any time via the cookie settings (link in the footer “Cookie Settings & List”).

6 | Shop Functions

6.1 Customer Account & Orders We process your name, address, e-mail, payment and order data for the performance of the contract pursuant to Art. 6 (1) (b) GDPR.

6.2 Shipping We pass on your address and (optionally, for parcel notifications) your e-mail address to our shipping service provider (e.g. DHL Paket GmbH) (Art. 6 (1) (b) GDPR).

6.3 Payments To process payments, we pass on data to the respective payment service provider (Art. 6 (1) (b) GDPR):

  • Shopify Payments / Stripe Inc. (USA, DPF-certified)
  • PayPal (Europe) S.à r.l. et Cie, S.C.A.
  • Klarna Bank AB (invoice / Sofort)

7 | Newsletter

Sign-up takes place via a double opt-in procedure. The newsletter is sent via Shopify Email. Legal basis: consent pursuant to Art. 6 (1) (a) GDPR. You can unsubscribe at any time via the link in the newsletter.

8 | Web Analytics & Online Marketing

Provided you have given your consent (Art. 6 (1) (a) GDPR), we use the following services:

8.1 Google Analytics 4 & Google Ads We use Google Analytics 4 provided by Google Ireland Limited. In the process, data (e.g. your IP address, truncated) is also transferred to the USA. Google is certified under the Data Privacy Framework (DPF). The cookie _gcl_au is used to attribute conversions (purchases) to advertisements (Google Ads conversion tracking).

  • Cookie storage period: up to 2 years (_ga).

8.2 Meta Pixel (Facebook & Instagram) We use the "Meta Pixel" provided by Meta Platforms Ireland Ltd. This enables us to track the behaviour of users after they have been redirected to our website by clicking on a Facebook/Instagram advertisement (conversion measurement) and to create audiences for advertising (Custom Audiences). In the process, data (including the cookie _fbp) is collected and transmitted to Meta (including in the USA). Meta is DPF-certified.

  • Cookie storage period: 3 months.

8.3 TikTok Pixel We use the pixel provided by TikTok Technology Limited (Ireland) and TikTok Inc. (USA). The pixel enables us to track the behaviour of users who reach our site via TikTok ads and to optimise our advertising activities. In the process, cookies (e.g. _ttp, ttcsid) are set and data is transmitted to TikTok.

  • Cookie storage period: up to 13 months.

9 | Social Media Presences

We maintain profiles on Instagram, Facebook, YouTube and Pinterest. When you visit these platforms, their terms and conditions and data processing policies apply. Insofar as we receive statistical data (insights) there, we are jointly responsible with the platform (Art. 26 GDPR).

10 | Storage Period

We delete personal data as soon as:

  • the purpose for which it was stored no longer applies,
  • no statutory retention obligations exist (e.g. 10 years for invoices pursuant to the German Fiscal Code (AO)), or
  • you withdraw your consent.

11 | Your Rights

You have the right to:

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection (Art. 21 GDPR)
  • Lodge a complaint with a supervisory authority (Art. 77 GDPR).
  • 12 | Changes

We will publish any amendments required by legal or technical developments here. Please check back regularly.