Skip to content

Privacy policy

Convenience translation. The German version is legally binding.

As of: October 3, 2026

1. Controller

The controller responsible for data processing on this website is:

Lee Esposito
Kiefernweg 19
90513 Zirndorf
Germany
Email: alphatester@rabbitfire.de

2. General information

Personal data is all data with which you can be personally identified. This policy describes which data is processed when you visit this website and when you place an order, what it is used for and what rights you have.

Data is processed on the following legal bases:

  • Art. 6(1)(b) GDPR — to perform a contract, for example when processing an order
  • Art. 6(1)(f) GDPR — legitimate interest, for example in the secure and trouble-free operation of the website and in simple audience measurement
  • Art. 6(1)(a) GDPR — your consent, for example for embedded videos and music
  • Art. 6(1)(c) GDPR — legal obligations, for example tax retention periods

Insofar as information on your device is accessed, Section 25 TDDDG (German Telecommunications Digital Services Data Protection Act) also applies. Consent is only required for this if the access is not strictly necessary (Section 25(2) TDDDG). More on this in section 4.

3. Hosting and server logs

This website is hosted by IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany. The servers are located in Germany. A data processing agreement pursuant to Art. 28 GDPR is in place with IONOS.

When you visit the website, the server automatically collects data that your browser transmits:

  • page accessed and time of access
  • amount of data transferred and notification of successful retrieval
  • browser type and version, operating system
  • previously visited page (referrer)
  • IP address

This data is used for the technical provision and security of the website. It is not combined with other data sources and is automatically deleted after a short time. The legal basis is Art. 6(1)(f) GDPR.

4. No cookies, local storage in the browser

This website does not set any cookies that track you as a visitor and does not embed any advertising or tracking services. That is why there is no cookie banner.

Two settings are stored locally by your browser on your device (local storage). They do not leave your device and are only read by the website itself:

  • Cart — so that your selection is kept while you browse the shop. This is strictly necessary for the ordering process you requested (Section 25(2) no. 2 TDDDG).
  • Light or dark design — only if you use the switch at the top right. This is a function you have expressly requested (Section 25(2) no. 2 TDDDG).

You can delete both entries at any time in your browser settings.

5. Fonts

The fonts of this website are located on our own server and are delivered from there. No connection is made to Google Fonts or other font providers.

6. Audience measurement without cookies

We count page views using our own, very simple method that works without cookies and without third-party services. This lets us see which posts and shirts are read and where visitors come from.

The following is stored:

  • the page accessed and the time of access
  • the origin, if you come from another website or from a link with origin information (e.g. “YouTube” or “Google”, not the full address)
  • the device type (phone, tablet or computer)
  • whether a shirt was put in the cart (without stating who did so)
  • a short code for distinguishing visitors on the same day

The code is generated from your IP address, your browser identifier and a random value that is newly generated every day and deleted afterwards. It is not possible to derive your IP address from it, nor to tell whether you return the next day. Your IP address and your browser identifier themselves are not stored. There is no disclosure to third parties. The entries are deleted after about two years.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is to improve content and offering and to find technical errors (such as pages that cannot be reached). If your browser sends “Do Not Track” or “Global Privacy Control”, we do not count your visit. You can also object to the measurement at any time, informally, at alphatester@rabbitfire.de. Since we cannot recognize individual visitors, this can only be implemented through the browser signals mentioned.

7. Orders in the shop

For an order we need your name, delivery address and email address. We also store the order contents, the amounts, the time, the payment method and the payment reference. There is no customer account.

The purpose is the performance of the purchase contract (Art. 6(1)(b) GDPR). We retain invoice and accounting data for up to ten years because of commercial and tax law obligations (Art. 6(1)(c) GDPR).

To protect against abusive mass orders and against the guessing of login credentials, your IP address is briefly kept in a counting list (generally for no more than one hour) and then deleted (Art. 6(1)(f) GDPR).

After payment you receive an order confirmation and later a shipping notification by email. The messages are sent via the mail server of our host (IONOS).

8. Payment via Stripe

Payment is processed by Stripe. The provider for customers in the European Economic Area is Stripe Payments Europe, Ltd., Dublin, Ireland; for Stripe companies in the USA it is Stripe, Inc.

When you click “Place order and pay”, we redirect you to Stripe’s payment page. There you enter your payment details (e.g. card number). We do not receive this data. We transmit to Stripe the order number, the amount, the items and your email address. Stripe tells us whether the payment was successful.

The legal basis is Art. 6(1)(b) GDPR. Stripe also processes some data under its own responsibility, for example for fraud prevention and to meet legal obligations. Stripe also uses data in the USA; the EU-U.S. Data Privacy Framework and standard contractual clauses apply to this. On Stripe’s payment page, Stripe’s privacy terms and, where applicable, its cookies apply.

Stripe’s privacy policy

9. Production and shipping via Printful

All shirts are made using print on demand. On our behalf, production and shipping are handled by:

Printful, Inc., 11025 Westlake Dr, Charlotte, NC 28273, USA, as well as affiliated production sites within the EU.

To fulfill your order we transmit name, delivery address, email address and order details to Printful. Printful passes the address on to the shipping company. Without this transmission the goods cannot be made and shipped. The legal basis is Art. 6(1)(b) GDPR.

Printful is based in the USA. The transfer is based on the European Commission’s standard contractual clauses pursuant to Art. 46(2)(c) GDPR. A data processing agreement is in place.

Printful’s privacy policy

10. Embedded videos from YouTube

Videos from YouTube are embedded on product pages and in blog posts. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

The videos are only loaded once you click the preview image. Our server fetches the preview image from YouTube itself and delivers it to you; Google does not learn your IP address in the process. By clicking, you consent to the player being loaded from youtube-nocookie.com. In doing so Google learns your IP address and your device information and can store or read information on your device. If you are logged in to Google at the same time, your visit can be assigned to your account.

The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). You can withdraw it by reloading the page and not playing the video. For transfers to the USA, the EU-U.S. Data Privacy Framework and standard contractual clauses apply.

Google’s privacy policy

11. Embedded content from Spotify

An album from Spotify is embedded on the shop page and on the page of the series “Emma DiAngelo”. The provider is Spotify AB, Regeringsgatan 19, 111 53 Stockholm, Sweden.

The player is only loaded after you click the button. By clicking, you consent to Spotify receiving your IP address and device information and being able to store or read information on your device (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). You can avoid this by not clicking the button.

Spotify’s privacy policy

12. Links, advertising banners and social networks

In the footer and in posts you will find references to YouTube and other sites. These are plain links, not embedded buttons. Data is only transmitted once you click a link and visit the target page. The privacy policy of the respective provider then applies.

The advertising banners in the blog sidebar are marked as “Advertisement”. The images are located on our server. Only when you click a banner do you reach the provider. We may receive a commission for purchases made via such links; nothing changes for you as a result.

13. Contacting us

If you write to us by email, we process your details to handle the inquiry and in case of follow-up questions. The legal basis is Art. 6(1)(b) GDPR if the inquiry is related to a contract, otherwise Art. 6(1)(f) GDPR. The data is deleted as soon as it is no longer required and no statutory retention obligations stand in the way.

14. Storage period

Unless stated otherwise in this policy, we store personal data only for as long as is necessary for the respective purpose. Invoice and accounting data are subject to statutory retention periods of six and ten years respectively. There is no automated decision-making or profiling.

15. Your rights

You have the right at any time to:

  • Access the data stored about you (Art. 15 GDPR)
  • Rectification of incorrect data (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Object to processing based on legitimate interests (Art. 21 GDPR)
  • Withdraw consent with effect for the future (Art. 7(3) GDPR)

To do so, contact alphatester@rabbitfire.de informally.

16. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data. The competent authority is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany
www.lda.bayern.de

17. SSL / TLS encryption

For security reasons, this website uses SSL or TLS encryption. You can recognize this by the address bar of your browser, which begins with https://. When encryption is active, the data you transmit to us cannot be read by third parties.

18. Changes to this policy

We will adapt this privacy policy as soon as the data processing on this website changes — for example because a service is added or removed. The version published here applies at any given time.