METMA
Privacy
These notices apply to the Metma website, including the shop and the product worlds LOGOKRUG, LOGOTELLER and further Metma offerings.
LOGOKRUG, LOGOTELLER and further categories still to come are products of Metma. Metma is the sole controller. The product worlds are not separate controllers.
https://metma.de
1. Controller
The controller for personal data on this website and in the online shop is:
Metma, Madeleine Heinrich, Schauberger Straße 20, 96355 Tettau, Germany
Email: info@logokrug.de · Phone: +49 89 85642679
Further provider details are in the Impressum .
2. General notes on processing
We process personal data when you visit our pages, place an order, send a form or subscribe to the newsletter. Legal bases are Art. 6(1)(b) GDPR (contract and pre-contractual requests), Art. 6(1)(c) GDPR (legal duties such as tax and commercial law), Art. 6(1)(a) GDPR (consent, for example the newsletter) and Art. 6(1)(f) GDPR (legitimate interest, for example operation, security and abuse prevention).
You may withdraw consent at any time with effect for the future. You may also object to processing based on legitimate interest. Contact details are above and in the imprint.
3. Hosting and server log files
The website and shop are hosted by Vercel Inc. Each request creates technically necessary server logs, typically IP address, time, requested address, referrer, browser and operating system. The purpose is secure operation. The legal basis is Art. 6(1)(f) GDPR. Whether the Vercel project runs on Pro or Enterprise is not readable from the project configuration. The server region is not hard-coded; a transfer to third countries, in particular the United States, is possible. Vercel states that it uses appropriate safeguards. Notice: vercel.com/legal/privacy-policy .
Content, order and customer data sit in a Supabase database we use (Supabase Inc.). It stores the catalogue, customer records for orders, addresses, orders, invoice files, product images and newsletter addresses. Legal bases are contract, statutory retention and legitimate interest in running the shop. supabase/config.toml does not record a region. Local development uses a local instance. The internal example configuration for production/test names the pooler host aws-1-eu-north-1 (Stockholm, EU). If production uses that host, the database is in the EU. A transfer to third countries by the provider remains possible.
Supabase privacy notice: supabase.com/privacy .
4. Cookies and similar technologies
We use cookies, local storage and session storage only where the shop or a function you chose needs them. Storing and reading these technically necessary items is based on § 25 (2) TDDDG, because they are strictly necessary to provide the service you requested. Art. 6(1)(b) and (f) GDPR also apply. There is no banner that pre-selects tracking, because we currently load no analytics or marketing pixels.
Necessary and without consent: language (cookie and local storage “metma-eshop-locale”), cart (local storage “metma-eshop-cart”), cart badge on the landing page (session storage), checkout product cache (session storage) and your last checkout details (local storage “metma-checkout-customer”: name, email, phone, addresses, payment method). After a successful order we automatically delete the personal checkout data in local storage. Anything that remains on your device (for example the cart or language) stays until you delete it in the browser or the session ends.
You can open the cookie notice again at any time via “Cookies” in the footer. We remember locally under “metma-cookie-notice” that the notice was closed. That is not consent. There are currently no statistics or marketing services. If we add such services later, we will ask for your consent first and store your choice as “metma-cookie-consent”. Those services will load only after you agree.
If you pay online, Stripe loads its own JavaScript in the browser and may set payment cookies. That happens only when you use online payment at checkout. See section 6.
5. Orders and contract performance
In the shop (Metma’s own shop, not Shopify) we collect name, email, phone, delivery and billing address, company and VAT ID if provided, customer type, line items, personalisation (for example a name or message), a pickup slot if chosen, and your legal confirmations. We store this in our database to perform the contract, ship or prepare pickup, and meet legal duties.
Legal bases are Art. 6(1)(b) and (c) GDPR. Product pages may increment an internal view counter. We do not store an IP address in that counter table.
At checkout you can look up an address. Our server sends the typed search text to the Places API of Google Ireland Ltd. (Google LLC, USA). We do not embed a map and do not load Google scripts or tracking cookies in the browser. The purpose is to fill street, postcode and city. Legal basis is Art. 6(1)(b) GDPR. Recipient in a third country (USA) on the basis of Standard Contractual Clauses. Details: policies.google.com/privacy .
6. Payments
Invoice: payment runs without a payment provider. We store the payment method and status with the order.
Online payment via Stripe (card, PayPal, and Apple Pay or Google Pay if your device supports them). The provider is Stripe. Payment data is processed by Stripe; we store the payment-intent id and status, not the full card number. Legal basis: Art. 6(1)(b) GDPR. Stripe may transfer data to the United States and other third countries. Notice: stripe.com/privacy .
7. Shipping
We ship with DHL. We send DHL the recipient’s name and address and, for shipments outside Germany, phone and email if we have them. Purpose: delivery and tracking. Legal basis: Art. 6(1)(b) GDPR. DHL notice: dhl.de/datenschutz .
8. Contact
Contact form, LOGOKRUG retailer/business enquiry, Logoteller enquiry and withdrawal form: name, email, phone if given, message or topic or series, and for retailer/business enquiries also company, address and website; for withdrawal the order number and an optional reason. Consent is not the legal basis for these forms. Where the message aims at a contract or pre-contractual steps, Art. 6(1)(b) GDPR applies. Otherwise we handle the enquiry under Art. 6(1)(f) GDPR (legitimate interest in answering and documenting the exchange). The withdrawal form asks you to acknowledge the privacy notice; that is not consent under Art. 6(1)(a) GDPR.
We send the messages via Resend to our inbox and as a confirmation to you. Business enquiries from the shop (Firmenkrügerl) are sent to our server (company, contact details, configuration).
To limit abuse we rate-limit submissions by IP address. That check stays only briefly in server memory and is not stored in the customer database. Forms include a hidden honeypot field against automated input.
9. Newsletter
In the footer you can subscribe with your email address and express consent (Art. 6(1)(a) GDPR). We store email, language, signup source, time and a personal unsubscribe token in our database. After you subscribe we send an email with a unique unsubscribe link. You can unsubscribe at any time via that personal link; we then delete the address from the list. The unsubscribe page is metma.de/en/newsletter/unsubscribe . You may also withdraw by emailing the address in the imprint.
10. Analytics and marketing
We currently do not use Google Analytics, Google Tag Manager, Google Ads or marketing pixels (such as Meta, TikTok or Pinterest). If that changes, we will update this notice and load those services only after your consent via the cookie notice.
11. External media and services
We do not embed maps (Google Maps, OpenStreetMap), video players (YouTube, Vimeo) or social media feeds. Address suggestions at checkout query the Google Places API on our server, without loading a map or Google scripts in the browser. Fonts are hosted on our own servers (Comfortaa). Links to Instagram or Facebook leave our site; the providers’ terms apply there.
12. Recipients of personal data
- Vercel — hosting and delivery of the website
- Supabase — database, file storage, technical authentication for the internal dashboard
- Stripe — online payments
- DHL — shipping
- Google Ireland Ltd. / Google LLC — address suggestions at checkout (Places API)
- Resend — sending emails (orders, forms, confirmations)
We do not share data beyond this unless we are legally required to. The internal dashboard is for staff only and is not part of the public site.
13. Retention
We keep data only as long as needed for the purpose or as statutory periods require. Order and invoice data are kept under commercial and tax retention rules. Newsletter addresses until you withdraw via the personal unsubscribe link or by email. Enquiries until the matter is closed and any evidence periods end. Server logs only while needed for operation and security. We delete personal checkout data in local storage after a successful order. Other storage on your device (cart, language) remains until you delete it or the session ends.
14. Your rights
You have the right to access, rectification, erasure, restriction, data portability and to object to processing based on Art. 6(1)(e) or (f) GDPR. You may withdraw consent at any time. A message to the contact details in section 1 is enough.
15. Right to lodge a complaint
You may lodge a complaint with a data protection supervisory authority, in particular the authority responsible for us in Bavaria: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA). Further information: lda.bayern.de .
16. Security
Transmission uses HTTPS. Access to orders and customer data in the dashboard is limited to staff. No method can guarantee complete security on the internet.
17. Changes to this privacy notice
We update this notice when services, technology or the law change. The version published on this page applies.