Skip to main content

Updated 30 August 2026

Privacy notice

1. Controller

Pia Marie Wieltsch, Collectamie, Stefan-Moser-Straße 6, Door 9, 9500 Villach, Austria, email: pia.wieltsch@collectamie.com, telephone: +43 650 450 6069.

2. Processing and legal bases

  • Shop operation and IT security: connection, device, security and error data for secure delivery of the service, based on legitimate interests under Article 6(1)(f) GDPR.
  • Account, basket and order: identity, contact, address, order, delivery and payment-status data for steps before and performance of a contract under Article 6(1)(b) GDPR.
  • Statutory records: invoice, business, consent and policy-version data to comply with legal duties under Article 6(1)(c) GDPR and for legal claims under point (f).
  • Online withdrawal: name, contract reference, acknowledgement address, scope and content of the declaration and received time to comply with legal duties under Article 6(1)(c) GDPR and as evidence for legal claims under point (f).
  • Optional browser features: consent-dependent storage such as Recently viewed under Article 6(1)(a) GDPR; consent may be withdrawn at any time.

3. Recipients and service providers

Providers receive only data required for their task and are engaged under processor agreements where required. SendGrid and advertising or analytics platforms are not used.

  • Railway for application hosting and PostgreSQL and Redis in EU West (Amsterdam).
  • Medusa as the shop, product, customer, basket and order platform.
  • Stripe for payment processing and fraud prevention.
  • Resend for transactional account, order and withdrawal messages.
  • Cloudflare R2 for product and media files.
  • Sentry for error, performance and OpenTelemetry monitoring where enabled.
  • GLS, DHL, Austrian Post, or another carrier identified at checkout for delivery.
  • OVHcloud for messages sent to the published contact address.

4. Transfers outside the EEA

Although hosting is in the EU, providers or subprocessors may be established outside the EEA or access data from there. Necessary transfers rely on an adequacy decision, including the EU-US Data Privacy Framework where applicable, or EU Standard Contractual Clauses with supplementary measures.

5. Retention

Data is retained only while required for its purpose, statutory record-keeping, or establishing and defending claims. Order, invoice and business records are generally retained for statutory periods, typically seven years. Withdrawal and policy-acceptance evidence is kept at least until relevant limitation and evidence periods expire. Account and technical data that is no longer required is deleted or anonymised.

6. Your rights

Subject to the GDPR, you have rights of access, rectification, erasure, restriction, portability and objection. Consent may be withdrawn at any time for the future. Contact security@collectamie.com to exercise a right.

You may complain to the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, dsb.gv.at, or another competent supervisory authority.

7. Required information and automated decisions

Information marked as required for an account, order, payment or delivery is needed to take pre-contract steps or perform the contract. Without it, the requested account, order, payment or delivery cannot be processed.

Collectamie does not make decisions based solely on automated processing that have legal or similarly significant effects. Stripe may assess payments and fraud risk automatically under its own privacy notice.