Table of Contents

Introduction and Contact Details of the Responsible Person

Data Collection When Visiting Our Website

Hosting & Content Delivery Network

Cookies

Contact

Comment Function

Data Processing When Opening a Customer Account

Use of Customer Data for Direct Marketing

Data Processing for Order Processing

Online Marketing

Web Analysis Services

Retargeting/Remarketing and Conversion Tracking

Page Functionalities

Tools and Others

Rights of the Data Subject

Duration of Storage of Personal Data

1) Introduction and Contact Details of the Responsible Person

1.1 We are pleased that you are visiting our website and appreciate your interest. Below, we inform you about how we handle your personal data when you use our website. Personal data refers to any information that can be used to identify you personally.

1.2 The entity responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is Dinar Shop. The controller responsible for processing personal data is the individual or legal entity that decides alone or jointly with others on the purposes and means of processing personal data.

2) Data Collection When Visiting Our Website

2.1 If you use our website for informational purposes only, we collect only the data that your browser transmits to our website server (“server log files”). These include:

Our visited website

Date and time of access

Amount of data sent in bytes

Source/reference from which you accessed the page

Browser used

Operating system used

IP address (if applicable, in anonymized form)

Processing is carried out in accordance with Art. 6 (1) (f) GDPR based on our legitimate interest in improving the stability and functionality of our website. This data will not be shared or used for other purposes unless there are concrete indications of illegal use.

2.2 To protect the transmission of personal data and other confidential content, we use SSL or TLS encryption. You can recognize an encrypted connection by “https://” and the lock symbol in your browser.

3) Hosting & Content Delivery Network

3.1 We use a hosting provider that operates servers within the European Union. All collected data is processed on these servers. We have signed a data processing agreement with the provider to ensure data protection.

3.2 Cloudflare

We use Cloudflare Inc., 101 Townsend St, San Francisco, CA 94107, USA, as a content delivery network (CDN). This helps us deliver content more efficiently via regional servers. Processing is based on Art. 6 (1) (f) GDPR to improve website performance and security. Cloudflare is part of the EU-US Data Privacy Framework, ensuring compliance with EU data protection standards.

4) Cookies

We use cookies to enhance the functionality of our website. Some cookies are session-based and expire when the browser is closed, while others persist to save settings. You can manage cookie preferences in your browser. If you disable cookies, website functionality may be limited.

Processing is conducted in accordance with:

Art. 6 (1) (b) GDPR (contract execution)

Art. 6 (1) (a) GDPR (consent-based processing)

Art. 6 (1) (f) GDPR (legitimate interests)

5) Contact

If you contact us via email, WhatsApp Business, or a contact form, we process your data solely for the purpose of responding to your request. The legal basis is Art. 6 (1) (f) GDPR, and if the request pertains to a contract, then Art. 6 (1) (b) GDPR applies.

We use WhatsApp Business for customer communication. Meta Platforms Inc. may process contact data. WhatsApp users must consent to their phone number being shared with contacts under WhatsApp’s terms.

6) Comment Function

When you comment on our website, your comment, timestamp, and selected username will be stored and published. Your IP address is also logged to protect against misuse.

7) Data Processing When Opening a Customer Account

Upon registering a customer account, we process your personal data as necessary for contract execution (Art. 6 (1) (b) GDPR). You may request account deletion at any time.

8) Use of Customer Data for Direct Marketing

If you subscribe to our newsletter, we will send promotional emails based on your consent (Art. 6 (1) (a) GDPR). You may unsubscribe at any time.

9) Data Processing for Order Processing

To fulfill orders, we share necessary data with shipping providers and payment service providers (Art. 6 (1) (b) GDPR). Additional consent-based transfers (e.g., email for shipping updates) require your explicit approval.

10) Online Marketing

We use Google Ads, Meta Pixel, and similar marketing tools to optimize advertising effectiveness. Data processing occurs only with your consent (Art. 6 (1) (a) GDPR).

11) Web Analysis Services

We use Google Analytics 4 for website analysis. Google may process anonymized IP addresses for traffic tracking. Google adheres to the EU-US Data Privacy Framework.

12) Retargeting/Remarketing and Conversion Tracking

We use remarketing tools from Google Ads and Meta Platforms to display targeted advertisements. Data is processed only with user consent (Art. 6 (1) (a) GDPR).

13) Page Functionalities

Our website integrates third-party services such as Google Maps, YouTube, and social media plugins. These providers may process personal data based on user consent.

14) Tools and Others

We use a cookie consent tool to manage user permissions for cookie-based processing. Consent management is conducted in accordance with Art. 6 (1) (c) GDPR.

15) Rights of the Data Subject

As a user, you have the following rights under GDPR:

Right to access (Art. 15 GDPR)

Right to rectification (Art. 16 GDPR)

Right to erasure (Art. 17 GDPR)

Right to restriction of processing (Art. 18 GDPR)

Right to object (Art. 21 GDPR)

Right to data portability (Art. 20 GDPR)

Right to file complaints (Art. 77 GDPR)

You may revoke consent-based processing at any time.

16) Duration of Storage of Personal Data

Personal data is stored for as long as necessary for the respective purpose, statutory retention requirements, or until a user exercises their right to erasure. If personal data is processed based on consent, it will be retained until consent is withdrawn.