Privacy Policy
According to DSGVO (EU) and revDSG (Switzerland)
Key Points at a Glance
LIINI AG, located at Bahnhofstrasse 21, 4571 Lüterkofen, Switzerland, is responsible for processing your personal data. We process your data primarily to fulfill orders in our online store, respond to your inquiries, and operate our website in a secure and user-friendly manner. To this end, we work with selected service providers (e.g., payment and shipping providers, hosting providers). We use marketing cookies and tracking only with your consent, which you may revoke at any time. You have the right to access, correct, delete, restrict, transfer, and object to the processing of your data. Contact: datenschutz@liini.ch.
Contents
- Data Controller and Contact Information
- Scope, Domains, and Terms
- Legal basis
- Nature, Scope, and Purpose of Data Processing
- Online Store and Order Processing
- Payments
- Shipping
- Customer Accounts and Portals
- Fingerprint jewelry
- Customer Service, Ticket System, and Chatbot
- Use of artificial intelligence (AI)
- Newsletters, Notifications, and Announcements
- Reviews (Trustpilot)
- Selling on Amazon
- Applications
- Use of the Website: Cookies, Consent, Server Log Files, Comments
- Digital Infrastructure and Third-Party Services
- Social media
- Advertising
- Success and reach measurement
- Retention Period
- Personal data abroad
- Data security
- Automated Decision-Making and Profiling
- Minors
- Rights of data subjects
- Final provisions
1. Data Controller and Contact Information
In this Privacy Policy, we explain what personal data we process in connection with our activities and operations, including our online store. In particular, we provide information about why, how, and where we process specific personal data, as well as the rights of the individuals whose data we process.
The controller within the meaning of the Swiss Data Protection Act (DSG) and the EU General Data Protection Regulation (GDPR) is:
LIINI AG
21 Bahnhofstrasse
4571 Lüterkofen
Switzerland
Management: Mike Roth
Email: datenschutz@liini.ch
Please direct any inquiries regarding data protection to datenschutz@liini.ch or through our ticket system at www.LIINI.ch/Support.
Data Protection Representative in the European Economic Area (EEA)
We have appointed the following data protection representative in accordance with Article 27 of the GDPR:
VGS Data Protection Partner GmbH
Am Kaiserkai 69
20457 Hamburg
Germany
info@datenschutzpartner.eu
The Data Protection Representation serves as an additional point of contact for data subjects and authorities in the European Union (EU) and the rest of the European Economic Area (EEA) for inquiries related to the GDPR.
We point out if there are other persons responsible for the processing of personal data in individual cases.
2. Scope, Domains, and Definitions
scope
This Privacy Policy applies to our online store, our other online offerings (e.g., Mama Portal, B2B Portal, Creator Club), our social media presence, and our other activities and operations. Additional privacy policies and other legal documents, such as General Terms and Conditions (GTC), Terms of Use, or Terms of Participation, may apply to specific or additional activities.
We are subject to Swiss data protection law as well as any applicable foreign data protection law such as, in particular, that of the European Union (EU) with the General Data Protection Regulation (GDPR). The European Commission recognizes that Swiss data protection law ensures an adequate level of data protection.
Domains
Our online store can be accessed at www.LIINI.ch, as well as at www.LIINI.de, www.LIINI.at, www.LIINI.fr, and www.LIINI.it. This Privacy Policy applies equally to all of these domains.
The following additional domains are domain aliases. When you enter one of these domains, you will be redirected to our online store via an SSL/TLS-encrypted connection:
LIINI.ae, LIINI.asia, LIINI.be, LIINI.cc, LIINI.co, LIINI.com, LIINI.co.uk, LIINI.cz, LIINI.es, LIINI.eu, LIINI.in, LIINI.li, LIINI.lu, LIINI.net, LIINI.nl, LIINI.org, LIINI.pl, LIINI.se, LIINI.sg, LIINI.store, LIINI.swiss, LIINI.uk
Geolocation
When you visit our online store, we use your IP address to determine your approximate location (country) so that we can display the appropriate currency (CHF or EUR), language, and shipping options. The IP address is not permanently stored for this purpose. You can manually change the language and store at any time. The legal basis is our legitimate interest in providing a user-friendly online store (Art. 6(1)(f) of the GDPR).
Terms
Personal data refers to any information relating to an identified or identifiable natural person. A data subject is a person whose personal data we process.
“Processing” encompasses any handling of personal data, regardless of the means and methods used, such as retrieving, comparing, modifying, archiving, storing, reading, disclosing, obtaining, collecting, collection, deletion, disclosure, sorting, organizing, storing, modification, dissemination, linking, destruction, and use of personal data.
The European Economic Area (EEA) comprises the member states of the European Union (EU) as well as the Principality of Liechtenstein, Iceland, and Norway. The General Data Protection Regulation (GDPR) refers to the handling of personal data as the processing of personal data.
3. Legal Basis
We process personal data in accordance with Swiss data protection law, in particular the Federal Act on Data Protection (Data Protection Act, DSG) and the Ordinance on Data Protection (Data Protection Ordinance, DSV).
We process personal data—to the extent that the GDPR applies—in accordance with at least one of the following legal bases:
- Art. 6 para. 1 lit. (b) GDPR for the processing of personal data necessary to fulfill a contract with the data subject and to take steps prior to entering into a contract.
- Art. 6 para. 1 lit. f DSGVO for the necessary processing of personal data to protect the legitimate interests of us or of third parties, unless the fundamental freedoms and rights and interests of the data subject prevail. Legitimate interests include, in particular, our interest in being able to conduct our activities and operations in a sustainable, user-friendly, secure, and reliable manner and to communicate about them; ensuring information security; protecting against misuse and fraud; enforcing our own legal claims; and complying with Swiss law.
- Art. 6 para. 1 lit. c) The GDPR for the processing of personal data necessary to comply with a legal obligation to which we are subject under the applicable laws of Member States in the EEA.
- Art. 6 para. 1 lit. a GDPR for the processing of personal data with the consent of the data subject. Consent that has been given may be revoked at any time with future effect (Art. 7(3) of the GDPR).
- Art. 6 para. 1 lit. d GDPR for the necessary processing of personal data to protect vital interests of the data subject or another natural person.
4. Nature, Scope, and Purpose of Data Processing
We process the personal data necessary to carry out our activities and operations in a sustainable, user-friendly, secure, and reliable manner. Such personal data may fall into the categories of inventory and contact data, browser and device data, content data, meta or marginal data and usage data, location data, sales data, and contract and payment data, in particular.
We may have personal data processed by third parties, process it jointly with third parties, or transfer it to third parties. Such third parties include, in particular, specialized providers whose services we use (processors). We also ensure data protection with regard to such third parties, in particular through appropriate contracts.
As a general rule, we process personal data only with the consent of the individuals concerned. If and to the extent that processing is permitted for other legal reasons, we may refrain from obtaining consent. For example, we may process personal data without consent in order to fulfill a contract, to comply with legal obligations or to protect overriding interests.
In this context, we process, in particular, information that a data subject voluntarily provides to us when contacting us—for example, by mail, email, ticket system, instant messaging, contact form, social media, or telephone—or when registering for a user account. For example, we may store such information in an address book, in a customer relationship management (CRM) system, or with similar tools. If we receive data about other persons, the transmitting persons are obliged to ensure data protection towards these persons as well as to ensure the accuracy of this personal data.
We also process personal data that we receive from third parties, obtain from publicly available sources or collect in the course of our activities and operations, if and to the extent that such processing is permitted for legal reasons.
5. Online Store and Contract Processing
When you place an order through our online store, we process the following personal data: first name, last name, company name (if applicable) and VAT ID number, shipping and billing addresses, email address, phone number (for inquiries and shipping notifications), order details (products ordered, prices, order number, order date), selected payment method and payment information, as well as details regarding communication related to the order.
This processing is necessary to fulfill the sales contract concluded between you and us (Art. 6(1)(b) of the GDPR). Required fields are marked as such; the order cannot be completed without this information. Which data is collected can be seen from the respective input forms.
To process the contract, we will share your data with the payment service providers you have selected (Section 6) and to our shipping service providers (Section 7) Continue. We generate invoices and delivery slips electronically and send them via email.
We will save the contract text, including the Terms and Conditions, and send you the terms of the contract via email. Once the contract has been fully fulfilled, your data will be restricted for further processing and, upon expiration of the retention periods required by tax and commercial law (Section 21), unless you have expressly consented to further use or we reserve the right to use your data beyond these periods as permitted by law, in which case we will inform you of such use in this statement.
Fraud Prevention: To protect against misuse and payment defaults, we and our payment service providers may check order details, IP addresses, and device information for any suspicious activity. The legal basis is our legitimate interest (Art. 6(1)(f) of the GDPR).
6. Payments
We use specialized service providers to ensure that payments are processed securely and reliably. Depending on the payment method you select, we will forward the necessary information (name, address, email address, amount, currency, order number, and, if applicable, shopping cart contents) to the respective service provider. Credit card information is not collected by us, but directly by the payment service provider. In addition, the legal documents of the individual service providers—such as their Terms and Conditions and Privacy Policies—apply to the processing of payments. The legal basis is the performance of a contract (Art. 6(1)(b) of the GDPR).
We use:
- Stripe (Visa and Mastercard credit cards, Apple Pay, Google Pay): Providers: Stripe Payments Europe Limited (Ireland) for users in the EEA and Switzerland / Stripe Inc. (U.S.); Privacy Information: Stripe’s Privacy Policy. Stripe uses automated checks (Stripe Radar) to prevent fraud.
- Apple Pay: Providers: Apple Distribution International Limited (Ireland) for residents of the EEA and Switzerland / Apple Inc. (U.S.); Privacy Information: Apple’s Privacy Policy.
- Google Pay: Providers: Google Ireland Limited (Ireland) / Google LLC (U.S.); Privacy Information: Google’s Privacy Policy.
- PayPal (including Braintree): Provider: PayPal (Europe) S.à r.l. et Cie, S.C.A. (Luxembourg); Privacy information: PayPal Privacy Policy.
- Klarna (invoice, instant bank transfer, other Klarna payment methods): Provider: Klarna Bank AB (publ) (Sweden) or, for Switzerland, Klarna Bank AB, Swiss Branch; Privacy information: Klarna’s Privacy Policy. Credit Check: When paying by invoice or through an installment plan, we will provide Klarna with the information necessary to process the transaction (name, address, date of birth, email address, phone number, order details). Klarna conducts an identity and credit check to determine whether to approve this payment method and may obtain information from credit bureaus for this purpose. This review is conducted by Klarna as an independent data controller. For more information, please see Klarna’s privacy policy.
- TWINT (Switzerland only): Provider: TWINT AG (Switzerland); Privacy information: TWINT Privacy Policy. The connection is established via a TWINT payment module (mame, Switzerland) hosted on our server; payment data is exchanged directly between your TWINT app and TWINT AG. We receive a payment confirmation from TWINT that includes a transaction number, but no information about your bank account.
7. Shipping
To deliver your order, we will provide your name, shipping address, and—if necessary for delivery or shipment notifications—your email address and phone number to the shipping provider we have contracted. The legal basis is the performance of a contract (Art. 6(1)(b) of the GDPR). The shipping service providers process this data as independent data controllers in accordance with their own privacy policies.
We ship from our warehouses in Switzerland and the EU, primarily using:
- Swiss Post AG (Switzerland)
- DHL Paket GmbH / Deutsche Post AG (Germany)
- DPD (Germany / Switzerland)
- other package delivery services, depending on the destination country
For shipments from Switzerland to the EU or vice versa, your data may also be transferred to customs authorities and customs service providers for customs clearance purposes, to the extent required by law (Art. 6(1)(c) of the GDPR).
8. Customer Accounts and Portals
You can create a customer account in our online store. We process your registration information (name, email address, encrypted password, addresses) as well as your order history. This account makes it easier for you to place future orders and track shipments. The legal basis is the performance of a contract or the implementation of precontractual measures (Art. 6(1)(b) of the GDPR).
We maintain separate accounts for business customers (B2B portal), participants in the LIINI Mama program (Mama portal), and members of the Creator Club. In addition, we process the information requested on the respective registration form (e.g., company information, social media profiles, and payment details for commissions). The respective terms and conditions of participation also apply to these programs.
You can have your account deleted at any time by contacting us through the ticket system or by email at datenschutz@liini.ch. Data that we are required to retain due to legal retention obligations (e.g., invoices) will be deleted once the retention periods have expired.
9. Fingerprint Jewelry
For our personalized necklaces and rings featuring a fingerprint, you will receive a fingerprint kit after placing your order. Please send us the impression you have created—usually your child’s fingerprint—by mail or as a photo or scan via our ticket system.
We process the fingerprint solely for the purpose of creating the jewelry you ordered. We perform the engraving ourselves in Switzerland; the fingerprint is not shared with third parties, is not used to identify individuals, and is not linked to any other data.
Once production is complete and the cancellation or complaint period has expired—but no later than six months after delivery—we will delete or destroy the fingerprint and the associated templates. If you’d like, we can delete them sooner; please let us know via the ticket system.
The legal basis is the performance of a contract (Art. 6(1)(b) of the GDPR). By submitting a child’s fingerprint, you confirm that you are authorized to give consent on the child’s behalf.
10. Customer Service, Ticket System, and Chatbot
Ticket System
You can contact our customer service team through our ticket system at www.LIINI.ch/Support. We run the ticket system using a WordPress plugin (SupportCandy) on our own web server hosted by our hosting provider (item 17). In doing so, we process your name, your email address, the content of your inquiry, any attachments (e.g., photos of a defect, proof of purchase), as well as the date and time of the communication. The legal basis is the performance of the contract or the response to pre-contractual inquiries (Art. 6(1)(b) of the GDPR) and our legitimate interest in providing efficient customer service and in documenting warranty and complaint cases (Art. 6(1)(f) of the GDPR).
Chatbot (DocsBot.ai)
On our website, we use the DocsBot.ai chatbot service to automatically answer your questions based on our website content. Provider: UglyRobot LLC (USA). DocsBot.ai uses AI language models from subcontractors—specifically OpenAI (U.S.)—to generate responses. Privacy Information: DocsBot.ai Privacy Policy, DocsBot.ai GDPR Compliance, DocsBot.ai Data Processing Agreement, Overview of DocsBot.ai’s Third-Party Partners.
When using the chatbot, the following data is processed:
- Communication data: All text you enter in the chat. Please do not enter any sensitive information (e.g., payment information, health information) in the chat.
- Technical Data: Browser type, operating system, time of the request.
- Usage data: What questions are asked and how the answers are rated, so that we can improve the service.
Use of the chatbot is optional. Chat histories are deleted after 90 days unless they have been transferred to a support ticket. The legal basis is our legitimate interest in providing efficient customer service (Art. 6(1)(f) GDPR); if the chatbot is loaded only after you have given your consent, that consent serves as the legal basis (Art. 6(1)(a) GDPR). When transferring data to the United States, we rely on the safeguards set forth in Section 22.
11. Use of Artificial Intelligence (AI)
We use artificial intelligence as a supportive tool, including for the creation and translation of texts, product descriptions, how-to guides, and marketing content, as well as for concept images and visualizations, and in customer service (chatbot, item 10; drafting responses to support inquiries). Key content is reviewed by our team prior to publication; AI does not replace human decision-making.
To the extent that personal data is processed in this context (e.g., when drafting a response to your support request), this is done exclusively for the purposes specified in this Privacy Policy and by service providers with whom we have entered into a data processing agreement. We do not share your data for the purpose of training AI models.
We comply with statutory transparency requirements, including Article 50 of the EU AI Act. For more information, visit https://liini.ch/einsatz-von-ki/.
12. Newsletters, Notifications, and Announcements
We send notifications and communications via email and other communication channels, such as instant messaging or SMS.
Newsletter: We use the service provided by Klaviyo Inc., Boston, USA, to send out our newsletter. In doing so, we process your email address, your name (if provided), the time of registration, your IP address at the time of registration, as well as data regarding when you opened the email and clicked on links.
Consent and Objection: You must expressly consent to the use of your email address and other contact information for newsletters (Art. 6(1)(a) GDPR), unless such use is permitted for other legal reasons (e.g., advertising similar products to existing customers). We use the “double opt-in” process to obtain your consent: You will receive an email containing a web link that you must click to confirm your consent, thereby preventing misuse by unauthorized third parties. We log such consents, including the IP address, date, and time, for evidentiary and security purposes. You can opt out of receiving newsletters at any time, specifically by using the unsubscribe link included in every email. This does not apply to necessary notifications related to your order or your customer account (e.g., order confirmation, shipping notification).
Measuring Success and Reach: Newsletters may contain web links or tracking pixels that track whether a specific message has been opened and which web links have been clicked. We need this analysis so that we can effectively tailor our newsletters to the needs and reading habits of our subscribers. By unsubscribing from the newsletter, you are simultaneously opting out of this tracking.
13. Reviews (Trustpilot)
After a purchase, we may send you an email inviting you to review our store and our products on Trustpilot. To do this, we will send your name, email address, and order reference to Trustpilot. Provider: Trustpilot A/S (Denmark); Privacy information: Trustpilot Privacy Policy. We send review invitations to customers in the EU only with their consent (Art. 6(1)(a) GDPR); you can opt out at any time by clicking the link in the invitation. Reviews you post on Trustpilot are subject to Trustpilot’s Terms and Conditions and Privacy Policy.
We also embed Trustpilot review widgets on our website, which transmit your IP address to Trustpilot when the page loads.
14. Selling on Amazon
We also sell our products through the Amazon Marketplace. When an order is placed through Amazon, we receive from Amazon the data necessary to process the order (name, shipping address, order details, anonymized Amazon email address). Amazon (Amazon Europe Core S.à r.l., Luxembourg, and its affiliates) is responsible for processing your data on the Amazon platform. We use the data exclusively to process the order, for warranty and guarantee purposes, and to comply with legal obligations.
15. Applications
We process personal data about applicants to the extent that it is necessary for assessing their suitability for an employment relationship or for the subsequent execution of an employment contract. The required personal data results in particular from the information requested, for example in the context of a job advertisement. We also process personal data that applicants voluntarily provide or publish, in particular as part of cover letters, resumes and other application documents, as well as online profiles.
We process personal data regarding applicants—to the extent that the GDPR applies—in particular in accordance with Art. 6, para. 1 lit. b and Art. 9, para. 2 lit. b GDPR. We delete application documents no later than six months after the application process is completed, unless you have consented to a longer retention period.
16. Use of the Website: Cookies, Consent, Server Log Files, Comments
Cookies
We use cookies. Cookies – our own cookies (first-party cookies) as well as cookies from third parties whose services we use (third-party cookies) – are data that are stored in the browser. Such stored data need not be limited to traditional cookies in text form.
Cookies can be stored in the browser temporarily as “session cookies” or for a certain period of time as so-called permanent cookies. “Session cookies” are automatically deleted when the browser is closed. Permanent cookies have a specific storage period. In particular, cookies allow us to recognize a browser the next time a user visits our website, which enables us, for example, to save the shopping cart, measure our website’s reach, or conduct online marketing.
Consent (Cookie Banner)
We use technically necessary cookies (e.g., for the shopping cart, login, language and currency selection, and cookie settings) based on our legitimate interest in ensuring the website functions properly (Art. 6(1)(f) GDPR). We use all other cookies and similar technologies—in particular for statistics, marketing, and embedded third-party content—only if you have given your consent via our cookie banner (Art. 6(1)(a) GDPR). We use [Consent Management Tool and Provider] to manage consent. Your selection is logged along with the date, time, and a pseudonymous identifier. You can change or withdraw your consent at any time via the cookie settings in the footer of our website.
Cookies can be completely or partially deactivated and deleted in the browser settings at any time. Without cookies, our website may no longer be fully available. For cookies used to measure performance and reach or for advertising purposes, many services offer a general opt-out option through Your Online Choices (European Interactive Digital Advertising Alliance, EDAA) or YourAdChoices (Digital Advertising Alliance).
Server log files
We collect the following information for each visit to our website, provided that this information is transmitted from your browser to our server infrastructure or can be determined by our web server: date and time, including time zone; Internet Protocol (IP) address; access status (HTTP status code); operating system, including user interface and version; browser, including language and version; specific subpages of our website accessed, including the amount of data transferred; and the last webpage accessed in the same browser window (referrer).
We store such information, which may also constitute personal data, in server log files. This information is necessary to ensure that our website remains available, user-friendly, and reliable, and to guarantee data security—and, in particular, the protection of personal data—including through third parties or with the assistance of third parties (Art. 6(1)(f) GDPR). Server log files are generally deleted after 30 days, unless a longer retention period is necessary to investigate security incidents.
Pixel counter
We may use tracking pixels (web beacons) on our website. These are small images that are usually invisible and are automatically loaded when you visit our website. Counting pixels can be used to capture the same information as server log files. We only use third-party tracking pixels (e.g., for advertising) with your consent.
Comments
We allow you to post comments in our magazine. In this context, we process the information you provide to us, as well as the IP address used and the date and time. This information is required to enable the publication of comments and to ensure protection against misuse, which is in our overriding legitimate interest. You can subscribe to email notifications about new comments; to do so, we need your email address. You can unsubscribe from these notifications at any time.
17. Digital Infrastructure and Third-Party Services
We use services of specialized third parties in order to carry out our activities and operations in a durable, user-friendly, safe and reliable manner. Among other things, such services allow us to embed functions and content on our website. In such an integration, the services used collect users’ IP addresses—at least temporarily—for technical reasons. For necessary security, statistical and technical purposes, third parties whose services we use may process data related to our activities and operations in aggregated, anonymized or pseudonymized form.
Hosting and Infrastructure
- Raidboxes: Hosting for our website and online store (WordPress / WooCommerce); Provider: Raidboxes GmbH (Germany); Servers located in Germany; Privacy information: Raidboxes Privacy Policy. We have entered into a contract with Raidboxes for order processing.
- Hostpoint: Registration and management of our domains; Provider: Hostpoint AG (Switzerland); Privacy information: Hostpoint’s Privacy Policy. Hostpoint does not process any data from visitors to our website.
- Cloudflare: Content Delivery Network (CDN), DNS, and protection against attacks; Provider: Cloudflare Inc. (U.S.) / Cloudflare Germany GmbH; Privacy Information: Cloudflare Privacy Policy. Cloudflare processes IP addresses and access data to deliver content quickly and defend against attacks.
Additional Services
- Google Services: Providers: Google Ireland Limited (Ireland) for users in the EEA and Switzerland / Google LLC (U.S.); General Information on Data Protection: Google’s Privacy Policy, “How we use data from websites or apps where our services are used,” “Types of cookies and other technologies used by Google, ” “Personalized ads” (Settings). In particular, we use Google Workspace (email and documents), Google Fonts, Google reCAPTCHA, Google Analytics, Google Tag Manager, Google Ads, Google Meet, and YouTube.
- Microsoft Services: Providers: Microsoft Ireland Operations Limited (Ireland) for users in the EEA and Switzerland / Microsoft Corporation (U.S.); Privacy Information: Microsoft Privacy Statement, Privacy Dashboard. In particular, we use Microsoft 365 and Microsoft Teams from Microsoft.
Fonts
- Google Fonts: Fonts; Provider: Google; Google Fonts-specific information: “Privacy and Google Fonts.”
Extensions
- Google reCAPTCHA: Spam protection for forms (distinguishes between entries made by humans and automated entries made by bots); Provider: Google; reCAPTCHA-specific information: “What is reCAPTCHA?” To do this, reCAPTCHA analyzes user behavior on the page.
- WPML: Multilingual support for our website; Provider: OnTheGoSystems Limited (Hong Kong); the plugin runs on our server and does not transmit any visitor data to the provider.
Video Content
- YouTube: Video platform; Provider: Google; YouTube-specific information: “Privacy and Security Center.” Embedded videos will not load until you give your consent.
Audio and Video Conferences
For our free babywearing consultations and other online meetings, we use Google Meet (provider: Google; see “Google Meet – Security and Privacy for Users”) and Microsoft Teams (provider: Microsoft; see “Privacy and Microsoft Teams”). In addition, the terms and conditions of the individual services apply to participation. We recommend that you mute your microphone by default when participating and either blur your background or use a virtual background.
18. Social Media
We maintain a presence on social media platforms and other online platforms (particularly Facebook, Instagram, TikTok, YouTube, and Trustpilot) in order to communicate with interested individuals and provide information about our activities and operations. In connection with such platforms, personal data may also be processed outside of Switzerland and the EEA.
The terms and conditions, terms of use, privacy policies, and other provisions of the individual operators of such platforms also apply in each case. These provisions inform in particular about the rights of data subjects directly against the respective platform, which includes, for example, the right to information.
We are jointly responsible with Meta Platforms Ireland Limited (Ireland) for our social media presence on Facebook and Instagram, including so-called Page Insights, to the extent that the GDPR applies. Meta Platforms Ireland Limited is part of the Meta group of companies (including those in the United States). Page Insights provide insight into how visitors interact with our website. We have entered into the so-called “Data Controller Addendum” with Meta, in which we have specifically agreed that Meta is responsible for ensuring the rights of data subjects. For more information , see Meta’s Privacy Policy and the “About Page Insights” page .
Social Media Features and Content
We use third-party services and plugins to embed features and content from social media platforms and to enable content sharing. These embeds will not be loaded until you give your consent.
- Facebook (Social Plugins): Embedding Facebook features and content, such as “Like” or “Share”; Providers: Meta Platforms Ireland Limited (Ireland) and other Meta companies (including those in the U.S.); Privacy Information: Meta’s Privacy Policy.
- Instagram: Embedding Instagram content; Providers: Meta Platforms Ireland Limited (Ireland) and other Meta companies; Privacy information: Instagram’s Privacy Policy.
- TikTok: Embedding TikTok content and features; Providers: TikTok Technology Limited (Ireland) and TikTok Information Technologies UK Limited (United Kingdom) for users in the EEA, the United Kingdom, and Switzerland; Privacy Information: TikTok Privacy Policy, TikTok Cookie Policy.
19. Advertising
We take advantage of the opportunity to display targeted advertisements for our activities and services on third-party platforms, such as social media platforms and search engines. With this type of advertising, we want to reach, in particular, people who are already interested in our products or who might be interested in them (remarketing and targeting). To this end, we may disclose relevant information—including, where applicable, personal information—to third parties that enable such advertising. We can also determine whether our advertising is successful—specifically, whether it leads to visits to our website or to purchases (conversion tracking).
We use the pixels and cookies for this purpose only with your consent (Art. 6(1)(a) of the GDPR). Third parties with whom we advertise and where you are registered as a user may be able to assign the use of our website to your profile there.
We use:
- Meta Advertising (Facebook Ads and Instagram Ads): Social media advertising; Providers: Meta Platforms Ireland Limited (Ireland) and other Meta companies (including those in the U.S.); Privacy Information: Remarketing and targeting, in particular using the Meta Pixel and the Conversions API, as well as Custom Audiences—including Lookalike Audiences— Meta’s Privacy Policy, “Ad Preferences” (registration required).
- Google Ads: Search engine and shopping ads; Provider: Google; Google Ads-specific details: Ads based, among other things, on search queries, using various domain names—in particular doubleclick.net, googleadservices.com, and googlesyndication.com; Conversion tracking and remarketing; “Ads” (Google), “Why am I seeing a specific ad?”
- TikTok Ads: Social media advertising; Providers: TikTok Technology Limited (Ireland) and TikTok Information Technologies UK Limited (United Kingdom); Privacy Information: Remarketing and targeting, particularly using the TikTok pixel; TikTok’s Privacy Policy; “TikTok for Business – Privacy and Cookie Policy.”
20. Measuring Success and Reach
We are trying to determine how our online offering is being used. In this context, we can, for example, measure the success and reach of our activities and operations as well as the effect of third-party links to our website. However, we can also, for example, test and compare how different parts or versions of our online offering are used (“A/B testing”). Based on the results, we can, in particular, correct errors, highlight popular content, or make improvements to our online offerings.
To measure success and reach, IP addresses are truncated (“IP masking”) or pseudonymized in order to comply with the principle of data minimization. Cookies may be used, and pseudonymous user profiles may be created. Such user profiles include, for example, the pages visited or content viewed, information about the size of the screen or browser window, and the user’s location—at least approximately. User profiles are not used to identify individual users. Certain third-party services with which users have accounts may, in some cases, associate the use of our online service with the user’s account on that service.
We use these services only with your consent (Art. 6(1)(a) of the GDPR). We use:
- Google Analytics 4: Performance and Reach Measurement; Provider: Google; Google Analytics-specific information: Measurement also across different browsers and devices (cross-device tracking); IP addresses are not stored; “Privacy” (Google Analytics); “Browser add-on to disable Google Analytics.”
- Google Tag Manager: Integration and management of services for measuring performance and reach, as well as other services; Provider: Google; Google Tag Manager-specific information: “Data collected using Google Tag Manager.” The Tag Manager itself does not set any cookies; the integrated services are loaded only with your consent.
21. Retention Period
We process personal data for as long as is necessary for the respective purpose or as required by law. Personal data whose processing is no longer necessary is anonymized or deleted. In particular, the following deadlines apply:
- Order, invoice, and payment data: 10 years after the end of the fiscal year (Art. 958f of the Swiss Code of Obligations) or in accordance with the commercial and tax retention requirements of the respective country of delivery.
- Customer account: until you delete it or after a period of inactivity; data subject to legal retention requirements will be retained until the applicable retention periods expire.
- Support tickets and warranty claims: 3 years after the case is closed, but no later than the expiration of the warranty and guarantee periods, as well as any applicable statutes of limitations.
- Chatbot history: 90 days.
- Fingerprint templates: no later than 6 months after delivery (Section 9).
- Server log files: typically 30 days.
- Newsletter data: until consent is revoked; proof of consent is retained for 3 years after unsubscription.
- Application materials: 6 months after the application process is completed.
- Cookie banner consent records: 12 months.
22. Personal Data Abroad
We generally process personal data in Switzerland and in the European Economic Area (EEA). However, we may also export or transfer personal data to other countries, in particular to have it processed there by service providers. This applies in particular to the United States (e.g., Google, Meta, Microsoft, Cloudflare, Stripe, UglyRobot/DocsBot.ai, OpenAI) as well as the United Kingdom and Singapore (TikTok).
We export personal data to countries whose laws ensure an adequate level of data protection in accordance with a decision by the Swiss Federal Council and—if and to the extent that the GDPR applies—in accordance with a decision by the European Commission. In the U.S., this applies to companies certified under the Swiss-U.S. Data Privacy Framework or the EU-U.S. Data Privacy Framework; this includes most of the U.S. providers we use.
We transfer personal data to countries whose laws do not ensure adequate data protection, or to non-certified providers, only if data protection is ensured for other reasons—in particular, based on the European Commission’s Standard Data Protection Clauses (with adaptations for Switzerland) or other appropriate safeguards. Exceptionally, we may export personal data to countries without adequate or appropriate data protection if the special data protection requirements are met, for example, the express consent of the data subjects or a direct connection with the conclusion or performance of a contract. Upon request, we are happy to provide affected individuals with information about the safeguards or supply them with a copy of the safeguards.
23. Data Security
We take suitable technical and organizational measures to ensure data security that is appropriate to the respective risk. These include, in particular, the use of transport-layer encryption on our website (SSL/TLS, HTTPS), encrypted storage of passwords, access restrictions limited to what is necessary, regular backups, and the careful selection of our service providers.
However, we cannot guarantee absolute data security. Our digital communications—like all digital communications, in principle—are subject to surveillance by security agencies in Switzerland, the rest of Europe, the United States, and other countries. We cannot directly influence the corresponding processing of personal data by secret services, police agencies and other security authorities.
24. Automated Decision-Making and Profiling
We do not make any automated decisions in individual cases that have legal effects on you or that significantly affect you in a similar manner. However, our payment service providers may perform automated checks—specifically, Klarna as part of the credit check for purchases on account, and Stripe as part of fraud prevention. These checks are conducted by the respective providers, who act as independent data controllers; you can find information about this and your rights in their privacy policies. If a payment method is declined, you can select a different payment method at any time.
Profiling for advertising purposes is conducted only in a pseudonymized manner and only with your consent (Sections 19 and 20).
25. Minors
Our online store is intended for adults. We do not knowingly collect any personal data from children, with the exception of information that parents or legal guardians intentionally provide to us for the purpose of creating personalized products (Section 9) or in connection with a support request.
26. Rights of Data Subjects
We grant data subjects all rights provided for under applicable data protection laws. Data subjects have the following rights in particular:
- Right to Access: You may request information regarding whether we process personal data about you and, if so, what personal data is involved. You will also receive the information necessary to exercise your data protection rights and to ensure transparency, including details regarding the purpose of processing, the retention period, any disclosure or export to other countries, and the source of the personal data.
- Correction and Restriction: You may correct inaccurate personal data, complete incomplete data, and request that the processing of your data be restricted.
- Deletion and Objection: You may request that your personal data be deleted (“right to be forgotten”) and object to the processing of your data with future effect, in particular to processing for direct marketing purposes.
- Withdrawal of Consent: You may withdraw any consent you have given at any time, effective for the future, without affecting the lawfulness of the processing that took place prior to the withdrawal.
- Data Disclosure and Data Transfer: You may request that your personal data be disclosed in a commonly used electronic format or transferred to another data controller.
We may defer, restrict, or deny the exercise of these rights to the extent permitted by law; for example, we may refuse to provide information on the grounds of trade secrets or the protection of others, or refuse to delete data on the grounds of statutory retention requirements. In exceptional cases, we may charge a fee for the exercise of these rights and will provide advance notice of this.
We are required to take reasonable steps to identify data subjects who request information or assert other rights. Affected persons are obliged to cooperate. We typically respond to inquiries within 30 days.
Right to File a Complaint: You have the right to enforce your data protection rights through legal action or to file a complaint with a competent data protection supervisory authority. The data protection supervisory authority for private data controllers in Switzerland is the Federal Data Protection and Information Commissioner (FDPIC). Data subjects in the EEA have—provided and to the extent that the GDPR applies—the right to lodge a complaint with a competent European data protection supervisory authority, in particular in their country of habitual residence.
27. Final Provisions
We may amend and supplement this privacy policy at any time. We will provide notice of such changes and additions in an appropriate manner, in particular by publishing the most current privacy policy on our website.
In addition to the original German version, we provide translations in English, French, and Italian. In the event of any discrepancies, the German version shall prevail.
Privacy Policy Effective Date: September 2026

4.0 PRObattery · on the go
Home 230Vfor home
Baby food warmersfrom 6 months
Night Stationfor the night











Cleaning Wipes Monthly Pack
Home & 2Go Bundle
Formula Dispenser Avent
Baby Bottle Bundle






































