Privacy Policy
DATA PROTECTION
INFORMATION ON THE COLLECTION OF PERSONAL DATA AND CONTACT DETAILS OF THE CONTROLLER
1.1 We are delighted that you are visiting our website and thank you for your interest. Below, we inform you about the handling of personal data when using our website. Personal data includes all data with which you can be personally identified.
1.2 The controller for data processing on this website, within the meaning of the General Data Protection Regulation (GDPR), is Victoria & Mae Toronto, who is responsible for processing. The controller for personal data is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data.
1.3 This website uses SSL or TLS encryption for security reasons and to protect the transmission of personal data and other confidential content (such as orders or inquiries to the responsible person). You can recognize an encrypted connection by the string “https://” and the lock symbol in your browser bar.
2. DATA COLLECTION WHEN VISITING OUR WEBSITE
When you use our website for informational purposes only, without registering or providing information in any other way, we only collect the data that your browser sends to our server (server log files). When you visit our website, we collect the following data, which is technical and necessary to display the website to you:
-
The website visited
-
Date and time of access
-
Amount of data sent in bytes
-
Source/reference from which you accessed the page
-
Browser used
-
Operating system used
-
IP address used (possibly anonymized)
Processing is carried out in accordance with Article 6(1)(f) GDPR based on our legitimate interest in improving the stability and functionality of our website. The data is not passed on or used in any other way, but we reserve the right to check the server log files retrospectively if there are concrete indications of illegal use.
3. COOKIES
To make your visit to our website attractive and to enable the use of certain functions, we use various types of cookies on different pages. These are small text files stored on your device. Some of the cookies we use are deleted after the end of the browser session (session cookies). Other cookies remain on your device and allow us or our partner companies to recognize your browser on your next visit (persistent cookies). These persistent cookies are automatically deleted after a specified period, which may vary depending on the cookie.
Some cookies are used to store settings and simplify the ordering process (e.g., remembering the contents of a cart). If cookies process personal data implemented by us, this is done in accordance with Article 6(1)(b) GDPR to fulfill the contract, or in accordance with Article 6(1)(f) GDPR to protect our legitimate interests in providing the best possible functionality of the website and a customer-friendly experience.
We may collaborate with advertising partners to make our website more interesting for you. When you visit our website, cookies from partner companies may also be stored on your device (third-party cookies). If we collaborate with advertising partners, you will be informed about such cookies and the scope of information collected below.
Browser settings for cookies:
You can set your browser to inform you about the setting of cookies and individually decide whether to accept them, or disable the acceptance of cookies for specific cases or in general. Instructions:
-
Internet Explorer: https://support.microsoft.com/en-us/help/17442/windows-internet-explorer-delete-manage-cookies
-
Firefox: https://support.mozilla.org/en-US/kb/enable-and-disable-cookies-website-preferences
-
Safari: https://support.apple.com/guide/safari/manage-cookies-and-website-data-sfri11471/mac
-
Opera: https://help.opera.com/en/latest/web-preferences/#cookies
Please note that if you do not accept cookies, the functionality of our website may be limited.
4. CONTACT US
When you contact us (e.g., via the contact form or email), we collect personal data. The specific data collected via a contact form can be found in the respective form. This data is used solely to respond to your request and for associated technical administration. The legal basis is our legitimate interest in responding to your request (Article 6(1)(f) GDPR). If your contact relates to concluding a contract, Article 6(1)(b) GDPR also applies. Your data will be deleted once your request has been fully processed, provided no statutory retention obligations apply.
5. DATA PROCESSING WHEN OPENING A CUSTOMER ACCOUNT AND FOR CONTRACT EXECUTION
In accordance with Article 6(1)(b) GDPR, personal data is collected and processed when you provide it to us to execute a contract or open a customer account. The specific data collected depends on the input forms used. You can have your customer account deleted at any time by contacting the controller above. We store and use the data you provide to process the contract. After full performance of the contract or deletion of your customer account, your data will be processed for tax and accounting purposes and deleted after statutory retention periods, unless you have expressly consented to further processing or such processing is otherwise legally permitted.
6. USE OF YOUR DATA FOR DIRECT ADVERTISING
6.1 Registration for our email newsletter
When you subscribe to our email newsletter, we regularly send you information about our offers. The only mandatory data is your email address; additional data is optional and used for personalization. We use a double-opt-in process. By confirming, you consent to the use of your personal data (Article 6(1)(a) GDPR). We store the IP address, date, and time of registration to prevent misuse. You can unsubscribe at any time via the link in the newsletter or by contacting the controller; your email will then be removed unless you consent to further use or it is legally permitted.
6.2 Email newsletter to existing customers
If you have provided your email address during a purchase, we may send you offers for similar goods or services based on our legitimate interest in personalized direct advertising (Article 6(1)(f) GDPR). You can object at any time at no cost using the standard rates by contacting the controller; upon objection, we will stop using your email for advertising.
7. DATA PROCESSING FOR ORDER PROCESSING
7.1 General
Personal data we collect is processed for contract execution with the transport company responsible for delivery, as far as necessary for delivery. Your payment details may be passed to the relevant credit institution for payment processing. If payment service providers are used, you will be explicitly informed. Legal basis: Article 6(1)(b) GDPR.
7.2 Use of payment service providers
PayPal
When paying via PayPal services, your payment data will be transmitted to PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg, in accordance with Article 6(1)(b) GDPR. PayPal may conduct a credit check (Article 6(1)(f) GDPR). Details: PayPal Privacy Policy: https://www.paypal.com/en/webapps/mpp/ua/privacy-full. You can object to this processing by contacting PayPal.
SOFORT (Klarna)
If you select “SOFORT,” the payment is processed by SOFORT GmbH, Theresienhöhe 12, 80339 Munich, Germany. We transmit data required for payment processing pursuant to Article 6(1)(b) GDPR. Details: https://www.klarna.com/sofort/datenschutz
8. CONTACT FOR REVIEW REMINDER
If you have expressly consented during or after your order, we will use your email address once to request a review (Article 6(1)(a) GDPR). You can revoke consent at any time by contacting the controller.
9. USE OF SOCIAL MEDIA: SOCIAL PLUGINS
9.1 Facebook plugins with Shariff solution
Plugins of Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA (“Facebook”). To protect your data, buttons are integrated only as HTML links (no connection to Facebook until you click). For details and your rights, see Facebook’s privacy policy: https://www.facebook.com/policy.php
9.2 Google+ plugins with Shariff solution
Plugins of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”). Integrated as HTML links. Privacy policy: https://www.google.com/policies/privacy/
9.3 Instagram plugins with Shariff solution
Plugins of Instagram LLC, 1601 Willow Rd, Menlo Park, CA 94025, USA (“Instagram”). Integrated as HTML links. Privacy policy: https://help.instagram.com/155833707900388/
10. ONLINE MARKETING
10.1 DoubleClick by Google
We use DoubleClick (Google LLC). Cookies may be used for ad relevance and conversion reporting based on consent and/or Article 6(1)(f) GDPR. More info: https://www.google.de/policies/privacy/
You can opt out by blocking cookies from www.googleadservices.com, using www.aboutads.info, or adjusting your browser. Disabling cookies may limit website functionality.
10.2 Google Ads (AdWords) Conversion Tracking
We use Google Ads conversion cookies to measure ad performance (Article 6(1)(f) GDPR). Cookies expire after ~30 days and aren’t used for personal identification. Opt out by disabling the Google conversion cookie in your browser settings. Privacy: https://www.google.de/policies/privacy/
11. WEB ANALYSIS SERVICES — Google (Universal) Analytics
This website uses Google Analytics (Google LLC). We use _anonymizeIp() so IP addresses are shortened within the EU/EEA. Processing is based on our legitimate interests in statistical analysis for optimization and marketing (Article 6(1)(f) GDPR).
You can prevent cookies via browser settings or install the opt-out add-on: https://tools.google.com/dlpage/gaoptout
Mobile opt-out works via setting an opt-out cookie (note: cookie is browser/domain-specific and must be reset after deletions).
More on Universal Analytics: https://support.google.com/analytics/answer/2838718
We may also use cross-device analysis via a user ID (no personal data in the ID).
12. RETARGETING/REMARKETING/REFERRAL ADVERTISING
Facebook Custom Audiences (Pixel)
With your explicit consent (Article 6(1)(a) GDPR), we use Facebook Pixel (Facebook Inc.) to measure ad effectiveness and optimize targeting. Policy: https://www.facebook.com/about/privacy/
You can manage third-party cookie choices at https://www.aboutads.info/choices/
Google Ads Remarketing
We use Google Ads Remarketing (Google LLC) to show relevant ads based on your site visits (Article 6(1)(f) GDPR). Manage ad settings: https://www.google.com/settings/ads/onweb/
More info: https://www.google.com/policies/technologies/ads/
13. RIGHTS OF THE DATA SUBJECT
13.1 You have the following rights under the GDPR regarding your personal data:
-
Right of access (Art. 15)
-
Right to rectification (Art. 16)
-
Right to erasure (Art. 17)
-
Right to restriction of processing (Art. 18)
-
Right to notification (Art. 19)
-
Right to data portability (Art. 20)
-
Right to withdraw consent (Art. 7(3))
-
Right to lodge a complaint with a supervisory authority (Art. 77)
13.2 RIGHT TO OBJECT
IF WE PROCESS YOUR PERSONAL DATA BASED ON LEGITIMATE INTERESTS (ARTICLE 6(1)(f) GDPR), YOU HAVE THE RIGHT TO OBJECT ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION.
YOU ALSO HAVE THE RIGHT TO OBJECT AT ANY TIME TO PROCESSING FOR DIRECT MARKETING PURPOSES.
IF YOU OBJECT, WE WILL STOP PROCESSING THE DATA FOR THESE PURPOSES UNLESS WE DEMONSTRATE COMPELLING LEGITIMATE GROUNDS OR THE PROCESSING IS FOR LEGAL CLAIMS.
14. DURATION OF STORAGE OF PERSONAL DATA
The duration of storage is based on statutory retention periods (e.g., commercial and tax). After expiry, data is routinely deleted unless it is still required to fulfill or conclude a contract and/or we have a legitimate interest justifying storage.
Contact
For privacy questions or to exercise your rights:
📧 info@victoriamaetoronto.com

