Privacy policy
Last updated: July 14, 2026
PRIVACY POLICY
InkViper Tattoo Cartridges
Last updated: 14 July 2026
|
Controller: Javier Andres Guarin Lopez, trading as InkViper Tattoo Cartridges |
This Privacy Policy explains how InkViper Tattoo Cartridges ("InkViper", "we", "us" or "our") collects, uses, shares and protects personal data when you visit www.inkviperofficial.com, create an account, place an order, contact us, subscribe to marketing, submit a review or otherwise use our online store and related services (the "Services").
We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the German Federal Data Protection Act (BDSG), the German Telecommunications Digital Services Data Protection Act (TDDDG), and other applicable data protection laws.
This Policy is information about our processing activities. It does not create consent merely because you visit the website. Where consent is required, for example for optional analytics or advertising cookies, we request it separately.
SECTION 1 - WHO IS RESPONSIBLE FOR YOUR DATA?
The controller responsible for deciding why and how your personal data is processed is:
Javier Andres Guarin Lopez, trading as InkViper Tattoo Cartridges
Herdentorsteinweg 5, 28195 Bremen, Germany
Email: inkvipercartridges@gmail.com
Phone: +49 1516 2745293
We have not appointed a data protection officer. You can contact us directly using the details above for privacy questions or requests.
SECTION 2 - PERSONAL DATA WE COLLECT
Depending on how you interact with the Services, we may process the following categories of personal data:
Identification and contact data, such as your name, billing address, shipping address, email address and telephone number.
Account data, such as account identifiers, login credentials, saved addresses, preferences and settings.
Order and transaction data, such as products viewed or purchased, cart contents, order history, returns, refunds, pickup selection, delivery information, invoices and payment status.
Payment-related data, such as the payment method selected, payment confirmation, transaction identifiers and fraud-prevention results. Full payment card data is generally processed directly by the relevant payment provider and is not stored by us.
Communications, such as messages, support requests, complaints, return requests and information you provide when contacting us.
Review and content data, such as ratings, review text, photographs, profile names and other content you choose to submit.
Technical and usage data, such as IP address, device type, operating system, browser, language, time zone, referral URL, pages viewed, clicks, session information and cookie or similar identifiers.
Marketing and consent data, such as newsletter subscription status, consent records, communication preferences and interactions with promotional messages.
Security data, such as login events, suspicious activity indicators, device or network signals and information used to prevent fraud or misuse.
Where information is required to enter into or perform a contract, failure to provide it may prevent us from processing an order, delivering products, arranging pickup, issuing a refund or responding to a request.
SECTION 3 - HOW WE COLLECT PERSONAL DATA
We collect personal data from the following sources:
Directly from you, for example when you place an order, create an account, contact us, subscribe, submit a review or exercise your rights.
Automatically when you use the website, through server logs, cookies and similar technologies.
From service providers that support the store, including Shopify, payment providers, shipping providers, security tools and customer-support services.
From third parties where you choose to interact with us through an integration, social media feature or external platform, subject to that third party’s settings and privacy notice.
SECTION 4 - PURPOSES AND LEGAL BASES
We process personal data only where we have a lawful basis. The main purposes and legal bases are described below.
Orders, payments, delivery and local pickup
We process customer, order, payment-status and delivery data to take steps at your request before entering into a contract, process and fulfil your order, arrange shipping or local pickup, handle returns and refunds, and communicate about the transaction. The legal basis is Article 6(1)(b) GDPR. Where accounting, tax, product-safety or other legal records are required, the legal basis is Article 6(1)(c) GDPR.
Customer accounts and customer service
We process account and communication data to provide account functions, answer questions, resolve problems and maintain our customer relationship. Depending on the request, the legal basis is Article 6(1)(b) GDPR or our legitimate interests in providing effective customer service and operating our business under Article 6(1)(f) GDPR.
Website operation, security and fraud prevention
We process technical, usage and security data to operate the website, maintain functionality, detect abuse, protect accounts and transactions, prevent fraud, enforce our terms and establish, exercise or defend legal claims. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure, reliable and economically sustainable operation of the store. Where processing is necessary to perform the purchase contract, Article 6(1)(b) GDPR also applies.
Marketing communications
We send newsletters or other promotional communications where you have consented, based on Article 6(1)(a) GDPR. You may withdraw consent at any time using the unsubscribe link in an email or by contacting us. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Transactional messages about orders, accounts, security, returns or legal notices are not marketing messages.
Analytics and personalized advertising
Where optional analytics, advertising or cross-site personalization technologies are enabled, we use them only after obtaining any consent required by law. The legal bases are your consent under Article 6(1)(a) GDPR and, for storing or accessing information on your device, Section 25(1) TDDDG. You may withdraw or change consent through the cookie or privacy settings available on the website.
Reviews and customer content
We process reviews and other content you submit in order to publish, moderate and manage that content and to help customers evaluate products. The legal basis is Article 6(1)(b) GDPR where the processing is part of a service you request, Article 6(1)(a) GDPR where we ask for consent, or Article 6(1)(f) GDPR based on our legitimate interest in obtaining product feedback and presenting authentic customer experiences. You may contact us if you want content associated with you removed, subject to legal retention or defense requirements.
Legal compliance and claims
We process personal data to comply with tax, accounting, commercial, consumer-protection, product-safety and law-enforcement obligations, based on Article 6(1)(c) GDPR. We may also process data to establish, exercise or defend legal claims based on Article 6(1)(f) GDPR.
SECTION 5 - SHOPIFY AND STORE HOSTING
Our store is hosted by Shopify. For customers in the European Economic Area, the United Kingdom and Switzerland, personal data is initially processed by Shopify International Limited in Ireland. Shopify and its affiliates and subprocessors provide hosting, checkout, account, security, analytics, support and other platform functions.
Shopify generally processes store customer data on our behalf under a data processing agreement. For certain enhanced, security, analytics or cross-merchant services, Shopify may act as an independent controller and is responsible for that processing. More information is available in Shopify’s Consumer Privacy Policy and privacy portal:
Shopify Consumer Privacy Policy
Shopify Subprocessor Information
SECTION 6 - PAYMENT PROCESSING
Payments are processed by the payment method selected at checkout, which may include Shopify Payments, PayPal or another displayed provider. Payment providers receive the information required to authorize and process the payment, prevent fraud, handle disputes and comply with financial regulations. They may act as independent controllers for some processing and apply their own privacy notices.
We generally receive confirmation of payment, the payment method, transaction references and limited account details, but we do not normally receive or store complete card numbers or card security codes.
SECTION 7 - SHIPPING, DELIVERY AND LOCAL PICKUP
Where an order is shipped, we share necessary contact and delivery information with the selected carrier, fulfilment service or delivery partner so that the order can be delivered, tracked and, where applicable, returned. The legal basis is Article 6(1)(b) GDPR.
Where local pickup at LA TRIBU Tattoo Studio is selected, we process the name, order number, contact details and pickup status required to prepare and hand over the order. The legal basis is Article 6(1)(b) GDPR.
SECTION 8 - COOKIES AND SIMILAR TECHNOLOGIES
The website uses cookies and similar technologies, such as pixels, local storage and device identifiers. Some are strictly necessary for functions requested by you, including cart operation, checkout, security, account login, language preferences and consent management. Access to or storage of information on your device for these purposes is permitted under Section 25(2) TDDDG. Related personal-data processing is based on Article 6(1)(b) or Article 6(1)(f) GDPR, depending on the function.
Optional analytics, advertising and personalization technologies are activated only where and to the extent required consent has been obtained under Section 25(1) TDDDG and Article 6(1)(a) GDPR. You can accept, reject or change optional choices through the cookie banner or privacy settings. Necessary technologies cannot be disabled through the consent tool because the store may not function correctly without them.
The exact technologies, providers, purposes and durations may change as Shopify settings and installed apps change. The current cookie banner or privacy settings on the website provide the most specific available choices.
SECTION 9 - RECIPIENTS OF PERSONAL DATA
We may disclose personal data to the following categories of recipients, only as necessary for the purposes described in this Policy:
Shopify and its affiliated companies and subprocessors.
Payment processors, banks, card networks and fraud-prevention providers.
Shipping carriers, delivery partners and pickup personnel.
IT, hosting, security, communications, customer-support and cloud-service providers.
Analytics, advertising and marketing providers, where the required consent has been obtained.
Accountants, tax advisers, legal advisers, insurers and other professional advisers.
Authorities, courts, regulators or other parties where disclosure is legally required or necessary to protect rights, safety or security.
A buyer, successor or adviser in connection with a proposed or completed sale, restructuring or transfer of the business, subject to applicable data protection requirements.
We do not sell personal data in the ordinary meaning of selling customer lists for money.
SECTION 10 - INTERNATIONAL DATA TRANSFERS
Some service providers, including Shopify and certain subprocessors, may process personal data outside Germany or the European Economic Area. Where personal data is transferred to a country that has not been recognized as providing an adequate level of protection, the transfer is protected by an approved legal mechanism, such as the European Commission’s Standard Contractual Clauses, together with supplementary safeguards where required.
Information about Shopify’s international transfers and subprocessors is available through the Shopify links in Section 5.
SECTION 11 - HOW LONG WE KEEP PERSONAL DATA
We retain personal data only for as long as necessary for the relevant purpose and then delete or anonymize it unless continued retention is required or permitted by law. Retention periods depend on the type of record and may include:
Order, invoice, payment and accounting records for applicable German commercial and tax retention periods, which may generally be six, eight or ten years depending on the record.
Account data for as long as the account remains active, followed by deletion subject to legal retention and claims requirements.
Customer-service and complaint records for as long as needed to resolve the matter and for applicable limitation periods.
Consent records for as long as needed to demonstrate compliance and address legal claims.
Marketing data until consent is withdrawn, an objection is made, or the data is no longer needed, subject to limited suppression records used to respect opt-out choices.
Technical logs and cookie data for the period configured for the relevant system, taking into account security, functionality and consent choices.
Data relevant to legal claims until the claim or applicable limitation period has ended.
SECTION 12 - YOUR DATA PROTECTION RIGHTS
Subject to the conditions and exceptions in applicable law, you may have the following rights:
Access, including confirmation of whether we process your personal data and a copy of that data (Article 15 GDPR).
Rectification of inaccurate data and completion of incomplete data (Article 16 GDPR).
Erasure of personal data in the circumstances provided by law (Article 17 GDPR).
Restriction of processing in the circumstances provided by law (Article 18 GDPR).
Data portability for certain data processed by automated means on the basis of consent or contract (Article 20 GDPR).
Objection to processing based on legitimate interests, on grounds relating to your particular situation (Article 21 GDPR).
Objection at any time to processing for direct marketing, including related profiling (Article 21(2) GDPR).
Withdrawal of consent at any time, without affecting prior lawful processing (Article 7(3) GDPR).
The right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, subject to statutory exceptions (Article 22 GDPR).
The right to lodge a complaint with a data protection supervisory authority (Article 77 GDPR).
To exercise a right, email inkvipercartridges@gmail.com. We may request information reasonably necessary to verify your identity and protect your data. We will respond within the periods required by law. Rights are generally free of charge, but the GDPR permits a reasonable fee or refusal for manifestly unfounded or excessive requests.
SECTION 13 - RIGHT TO OBJECT
Where we process personal data on the basis of Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will stop the processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is required for legal claims.
Where personal data is processed for direct marketing, you may object at any time without giving reasons. We will then stop using your data for that marketing purpose.
SECTION 14 - COMPLAINTS AND SUPERVISORY AUTHORITY
Please contact us first if you have concerns, so we can try to resolve them. You also have the right to lodge a complaint with a supervisory authority, particularly in the EU Member State of your habitual residence, place of work or the alleged infringement.
The supervisory authority responsible for our establishment is:
Der Landesbeauftragte für Datenschutz und Informationsfreiheit der Freien Hansestadt Bremen
Georgstraße 122-124, 27570 Bremerhaven, Germany
Email: office@datenschutz.bremen.de
Phone: +49 421 361 2010 or +49 471 596 2010
Bremen Data Protection Authority
SECTION 15 - SECURITY
We use appropriate technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. These measures include access controls and the security functions provided by Shopify and relevant payment providers.
No method of internet transmission or electronic storage can be guaranteed to be completely secure. Please do not send payment card details, passwords or other highly sensitive information through ordinary email or social media messages.
SECTION 16 - CHILDREN
The Services and products are intended for adults and professional users. We do not knowingly collect personal data from children under 16. If you believe a child has provided personal data to us without appropriate authorization, contact us so that we can investigate and delete the information where required.
SECTION 17 - THIRD-PARTY WEBSITES AND SOCIAL MEDIA
The website may contain links or integrations relating to third-party websites, social networks or services. Those third parties are responsible for their own processing and privacy practices. We recommend reviewing their privacy notices before providing information or interacting with them.
SECTION 18 - AUTOMATED DECISION-MAKING
We do not currently make decisions about customers based solely on automated processing that produce legal effects or similarly significantly affect them. Payment and fraud-prevention providers may use automated systems under their own responsibility. If we introduce qualifying automated decision-making, we will provide the information and safeguards required by law.
SECTION 19 - CHANGES TO THIS POLICY
We may update this Privacy Policy to reflect changes in the store, Shopify features, installed apps, service providers, legal requirements or our processing practices. The current version will be published on the website with an updated revision date. Where required by law, we will provide additional notice or request renewed consent.