Privacy Policy

1) Information about the collection of personal data and controller contact details

1.1 We are pleased that you are visiting our website and thank you for your interest. Below, we inform you about the handling of your personal data when using our website. Personal data means any data with which you can be personally identified.

1.2 The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is SHAP. The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data.

1.3 For security reasons and to protect the transmission of personal data and other confidential content (e.g. orders or inquiries), this website uses SSL or TLS encryption. You can recognize an encrypted connection by “https://” and the lock symbol in your browser.

2) Data collection when visiting our website

When using our website for informational purposes only, we collect the data your browser transmits to our server (“server log files”):

    • Visited website
    • Date and time of access
    • Amount of data sent
    • Source/referrer
    • Browser used
    • Operating system
    • IP address (possibly anonymized)

Processing is based on Art. 6(1)(f) GDPR (legitimate interest). Data is not used otherwise unless unlawful use is suspected.

3) Cookies

We use cookies to improve functionality and user experience. Some cookies are deleted after the session; others remain stored (persistent cookies).

Cookies may process browser, location, and IP data. Processing is based on:

    • Art. 6(1)(b) GDPR (contract performance), or
    • Art. 6(1)(f) GDPR (legitimate interest)

You can manage cookie settings in your browser. Please note that disabling cookies may limit website functionality.

4) Contacting us

When contacting us (e.g. via email or contact form), personal data is collected solely to process your request.

Legal basis:

    • Art. 6(1)(f) GDPR or
    • Art. 6(1)(b) GDPR

Data is deleted once your inquiry is resolved unless legal retention applies.

5) Data processing for customer accounts and contracts

Personal data is processed under Art. 6(1)(b) GDPR for contract execution or account creation. You may delete your account at any time.

Data is retained according to statutory requirements and deleted after expiry unless consent or legal grounds apply.

6) Use of your data for direct advertising

6.1 Newsletter subscription: Subscription uses double opt-in. Legal basis: Art. 6(1)(a) GDPR. You may unsubscribe anytime.

6.2 Newsletter to existing customers: We may email similar offers based on Art. 6(1)(f) GDPR. You may object anytime.

7) Data processing for order handling

Your data is shared with:

    • Shipping providers (delivery)
    • Payment providers (payment processing)

Legal basis: Art. 6(1)(b) GDPR.

Payment providers may include:

    • PayPal
    • Klarna / SOFORT

8) Review reminders

With explicit consent (Art. 6(1)(a) GDPR), we may send a one-time review reminder. Consent can be withdrawn at any time.

9) Social media plugins

We use social plugins via the Shariff solution. Data is only transferred when you click a plugin.

10) Online marketing

We use Google Ads and DoubleClick based on Art. 6(1)(f) GDPR. You may opt out via Google ad settings.

11) Web analytics

We use Google Analytics with anonymized IPs. Processing is based on Art. 6(1)(f) GDPR. You may opt out via browser tools.

12) Retargeting / remarketing

    • Facebook Pixel (Art. 6(1)(a) GDPR)
    • Google Ads Remarketing (Art. 6(1)(f) GDPR)

You may opt out via ad settings.

13) Rights of the data subject

You have rights to access, correction, deletion, restriction, portability, consent withdrawal, and complaint under GDPR.

You may object at any time to data processing based on legitimate interest or for direct marketing.

14) Storage duration

Data is stored in accordance with statutory retention obligations and deleted once no longer required.

📧 Contact: hello@shap.ae