Privacy Policy
Information on the processing of personal data in accordance with the General Data Protection Regulation (GDPR).
1. Controller
The controller within the meaning of the GDPR and other data protection regulations is the operator of this online shop ([PLACEHOLDER: Name / Company]):
- [PLACEHOLDER: Name / Company name]
- [PLACEHOLDER: Address]
- Email: support@getplaybookr.com [PLACEHOLDER check]
You can find full contact details in our Legal Notice. [PLACEHOLDER: Check whether a data protection officer must be appointed; add here if applicable.]
2. General Information & Legal Bases
We only process personal data insofar as this is necessary and on the basis of a valid legal basis. The following may apply as legal bases in particular:
- Art. 6 (1) (a) GDPR — consent (e.g. newsletter, non-essential cookies).
- Art. 6 (1) (b) GDPR — performance of a contract and pre-contractual measures (e.g. processing your order and delivering the PDF products).
- Art. 6 (1) (c) GDPR — compliance with legal obligations (e.g. tax and commercial law retention obligations).
- Art. 6 (1) (f) GDPR — legitimate interests (e.g. secure operation and protection of the website).
3. Data Collected During Orders & Contact
When you purchase a product or contact us, we process the data required for this purpose, in particular:
- Email address (for delivery of the PDF download)
- Where applicable, name and billing data (insofar as required for the invoice/receipt)
- Order data (purchased products, amount, time)
- The content of your message when you contact us by email or form
The legal basis is Art. 6 (1) (b) GDPR (contract processing) or, in the case of mere inquiries, Art. 6 (1) (f) GDPR.
4. Hosting & Server Log Files (Vercel)
This website is hosted by Vercel Inc. or its EU subsidiary. When the pages are accessed, information is automatically recorded in so-called server log files that your browser transmits (e.g. IP address, date and time of access, file retrieved, amount of data transferred, browser type). This data serves the secure and stable operation of the website (Art. 6 (1) (f) GDPR).
[PLACEHOLDER: Conclude a data processing agreement (DPA) with Vercel and reference it here. In the case of data transfer to the USA, check and name appropriate safeguards (e.g. EU Standard Contractual Clauses / Data Privacy Framework).]
5. Payment Processing (Mollie)
For the processing of payments, we use the payment service provider Mollie B.V., Keizersgracht 313, 1016 EE Amsterdam, Netherlands. When you place an order, the data required for payment (e.g. payment amount, selected payment method and the data you enter during the payment process) is transmitted to Mollie. Mollie processes some of this data as an independent controller.
The legal basis is Art. 6 (1) (b) GDPR (performance of a contract). Depending on the chosen payment method (e.g. Klarna, PayPal, credit card, SEPA), further recipients may be involved. You can find more information in Mollie's privacy policy at mollie.com/de/privacy.
[PLACEHOLDER: Check the contractual relationship and, where applicable, the DPA with Mollie; specify the roles (controller/processor) depending on the constellation.]
6. Email & Newsletter
If you subscribe to our newsletter, we use your email address to send information and offers. Registration takes place using the so-called double opt-in procedure: after registering, you receive a confirmation email with which you confirm your registration. In this way, we ensure that the registration actually originates from you.
The legal basis is your consent (Art. 6 (1) (a) GDPR). You can unsubscribe from the newsletter at any time, e.g. via the unsubscribe link in every email or by sending us a message. The withdrawal of consent does not affect the lawfulness of the processing carried out up to that point.
[PLACEHOLDER: Name the newsletter/email service provider used and conclude a DPA.]
7. Cookies & Consent
We use technically necessary cookies that are required for the operation of the website and the shopping cart (legal basis: § 25 (2) TDDDG as well as Art. 6 (1) (f) GDPR). The storage of and access to non-essential information on your device takes place exclusively with your consent in accordance with § 25 (1) TDDDG (formerly TTDSG) in conjunction with Art. 6 (1) (a) GDPR.
[PLACEHOLDER: Name the consent management tool used and document the cookie list/storage period.]
8. Reach Measurement & Marketing (optional)
If activated, we use analytics and marketing services as well as pixels to evaluate the use of the website and to display advertising. These are used exclusively after your express consent (Art. 6 (1) (a) GDPR, § 25 (1) TDDDG).
- Meta Pixel (Meta Platforms Ireland Ltd.) — [PLACEHOLDER: Confirm use and pixel ID]
- Google Analytics / Google Ads (Google Ireland Ltd.) — [PLACEHOLDER: Confirm use]
- TikTok Pixel (TikTok Technology Ltd.) — [PLACEHOLDER: Confirm use]
[PLACEHOLDER: Remove unused services. In the case of data transfer to third countries, name appropriate safeguards.]
9. Storage Period
We only process and store personal data for as long as is necessary for the respective purpose or as required by statutory retention obligations. In particular, invoice and accounting data are subject to commercial and tax law retention periods (generally 6 or 10 years). After that, the data is deleted, provided it is no longer needed.
10. Your Rights as a Data Subject
Under the GDPR, you have in particular the following rights:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure ("right to be forgotten", Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object to processing (Art. 21 GDPR)
- Right to withdraw a given consent with effect for the future (Art. 7 (3) GDPR)
To exercise your rights, a message to the email address mentioned above is sufficient.
11. Right to Lodge a Complaint with a Supervisory Authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the Member State of your residence, place of work or the place of the alleged infringement.
[PLACEHOLDER: Name the competent supervisory authority based on the registered office/residence of the controller.]
Last updated of this Privacy Policy: [PLACEHOLDER: Date]. We reserve the right to amend this policy in order to adapt it to changed legal situations or processing operations.
Last updated: 2026-06-25
