Updated 30 August 2026
Privacy notice
1. Controller
Pia Marie Wieltsch, Collectamie, Stefan-Moser-Straße 6, Door 9, 9500 Villach, Austria, email: pia.wieltsch@collectamie.com, telephone: +43 650 450 6069.
2. Processing and legal bases
- Shop operation and IT security: connection, device, security and error data for secure delivery of the service, based on legitimate interests under Article 6(1)(f) GDPR.
- Account, basket and order: identity, contact, address, order, delivery and payment-status data for steps before and performance of a contract under Article 6(1)(b) GDPR.
- Statutory records: invoice, business, consent and policy-version data to comply with legal duties under Article 6(1)(c) GDPR and for legal claims under point (f).
- Online withdrawal: name, contract reference, acknowledgement address, scope and content of the declaration and received time to comply with legal duties under Article 6(1)(c) GDPR and as evidence for legal claims under point (f).
- Optional browser features: consent-dependent storage such as Recently viewed under Article 6(1)(a) GDPR; consent may be withdrawn at any time.
3. Recipients and service providers
Providers receive only data required for their task and are engaged under processor agreements where required. SendGrid and advertising or analytics platforms are not used.
- Railway for application hosting and PostgreSQL and Redis in EU West (Amsterdam).
- Medusa as the shop, product, customer, basket and order platform.
- Stripe for payment processing and fraud prevention.
- Resend for transactional account, order and withdrawal messages.
- Cloudflare R2 for product and media files.
- Sentry for error, performance and OpenTelemetry monitoring where enabled.
- GLS, DHL, Austrian Post, or another carrier identified at checkout for delivery.
- OVHcloud for messages sent to the published contact address.
4. Transfers outside the EEA
Although hosting is in the EU, providers or subprocessors may be established outside the EEA or access data from there. Necessary transfers rely on an adequacy decision, including the EU-US Data Privacy Framework where applicable, or EU Standard Contractual Clauses with supplementary measures.
5. Retention
Data is retained only while required for its purpose, statutory record-keeping, or establishing and defending claims. Order, invoice and business records are generally retained for statutory periods, typically seven years. Withdrawal and policy-acceptance evidence is kept at least until relevant limitation and evidence periods expire. Account and technical data that is no longer required is deleted or anonymised.
6. Your rights
Subject to the GDPR, you have rights of access, rectification, erasure, restriction, portability and objection. Consent may be withdrawn at any time for the future. Contact security@collectamie.com to exercise a right.
You may complain to the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, dsb.gv.at, or another competent supervisory authority.
7. Required information and automated decisions
Information marked as required for an account, order, payment or delivery is needed to take pre-contract steps or perform the contract. Without it, the requested account, order, payment or delivery cannot be processed.
Collectamie does not make decisions based solely on automated processing that have legal or similarly significant effects. Stripe may assess payments and fraud risk automatically under its own privacy notice.