RCK BEAD DESIGN

Privacy Policy

Last updated: September 2026

1. Controller

The controller responsible for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) is:

Hannah Rock
Gerresheimer Straße 186
40233 Düsseldorf
Germany
Email: service@rock-bead.com

2. General information on data processing

We process personal data of our users only insofar as this is necessary to provide a functional website and our content and services. Processing is generally based on consent (Art. 6(1)(a) GDPR), contract performance (b), legal obligation (c) or legitimate interests (f).

3. Website provisioning & server log files

When you visit our site, information is automatically transmitted to the server (IP address, date/time, browser type, operating system, referrer URL). The legal basis is Art. 6(1)(f) GDPR (legitimate interest in stable, secure operation). Data is deleted shortly afterwards unless there are security-relevant incidents.

4. Cookies & consent

We use technically necessary cookies (Art. 6(1)(f) GDPR / § 25(2) TTDSG) to provide core functions such as cart, language and cookie selection. Optional cookies (e.g. analytics and marketing, such as Meta Pixel) are only set with your explicit consent via our cookie banner (Art. 6(1)(a) GDPR, § 25(1) TTDSG). You can withdraw your consent at any time with effect for the future.

5. Order processing & customer account

To process your order we handle inventory and contract data (name, delivery address, email address, phone if applicable, order data). The legal basis is Art. 6(1)(b) GDPR. Data relevant under tax and commercial law is retained according to statutory retention periods (usually 10 years, Art. 6(1)(c) GDPR).

6. Payment processing (Stripe)

For payment processing we use Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. Your payment data is transmitted directly to Stripe; we do not receive complete payment-instrument data ourselves. Legal basis: Art. 6(1)(b) GDPR. More info: stripe.com/privacy.

7. Hosting & backend

Our website and database are operated by providers in the EU or with GDPR-compliant data processing agreements. Data-processing agreements pursuant to Art. 28 GDPR are in place. Any transfer to third countries occurs on the basis of EU standard contractual clauses (Art. 46 GDPR).

8. Newsletter

When you sign up for our newsletter we process your email address to send you information about products, promotions and news. Legal basis is your consent under Art. 6(1)(a) GDPR. You can unsubscribe at any time via the link in every email.

9. Google Analytics 4

If you have consented, we use Google Analytics 4 with IP anonymisation enabled. Legal basis is Art. 6(1)(a) GDPR in conjunction with § 25(1) TTDSG. A transfer to the US may occur, based on the EU standard contractual clauses and the EU-US Data Privacy Framework.

10. Meta Pixel (Facebook / Instagram)

If you have consented, we use the Meta Pixel of Meta Platforms Ireland Ltd. (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland) for marketing and conversion measurement on Facebook and Instagram. Your browser may connect to Meta servers and transmit data such as IP address, browser type and visited pages. Legal basis is Art. 6(1)(a) GDPR in conjunction with § 25(1) TTDSG. A transfer to the US may occur, based on the EU standard contractual clauses and the EU-US Data Privacy Framework. More information: facebook.com/privacy/policy.

11. Contact

When you contact us by email or contact form, we process your information to handle the request (Art. 6(1)(b) or (f) GDPR). The data is deleted as soon as it is no longer required for the purpose for which it was collected.

12. Recipients & processors

We only share your data with third parties insofar as this is necessary for contract performance (e.g. shipping, payment, IT providers), a legal obligation exists, or you have consented. We have data-processing agreements in place pursuant to Art. 28 GDPR.

13. Your rights

You have the following rights regarding your data:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)
  • Right to withdraw consent (Art. 7(3) GDPR)

You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR).

14. Data security

We use technical and organisational measures to protect your data against loss, manipulation and unauthorised access. Transmission is encrypted via TLS/HTTPS.

15. Changes to this privacy policy

We reserve the right to adapt this privacy policy so that it always complies with current legal requirements or to reflect changes to our services.

Ready to design your own piece?

Start designing