EN DE

Privacy Policy

Last updated: August 2026

1. Controller and Contact

This privacy policy explains how we process personal data when you visit our website and use our service to order printed stickers, including communication via WhatsApp and our web app.

Stick Maniac
E-Mail: info@stickmaniac.com

If you have any questions about this privacy policy or wish to exercise your data protection rights, you can contact us using the details above.

2. Scope of this Policy

This policy applies to:

It supplements WhatsApp's, Firebase's and Stripe's own privacy policies, which continue to apply independently when you use those services.

3. Categories of Personal Data

Depending on how you use our service, we may process the following categories of data:

4. Purposes and Legal Bases

We process personal data only where we have a legal basis under Art. 6 GDPR and, where relevant, obtain your consent. We use your data for the following purposes:

5. WhatsApp Business Platform and Meta

When you contact us via WhatsApp or we send you messages using the WhatsApp Business Platform (including Cloud API), WhatsApp and Meta process certain personal data as our service providers. This includes:

Meta acts as a data processor/service provider when providing the Cloud API and only processes messages in accordance with our instructions and WhatsApp's Business Data Processing Terms. Your WhatsApp usage is additionally governed by WhatsApp's own privacy policies and terms, which you accept when using WhatsApp.

You may withdraw your consent to receive WhatsApp communication at any time, for example by sending us a message such as "STOP" or by blocking our business account.

6. Firebase

We use Firebase services provided by Google (e.g. Firebase Authentication, Firestore/Database, Storage and hosting) to operate our web app, manage user accounts and store order data. Google generally acts as our data processor under GDPR for Firebase services:

We configure our Firebase project to use EU regions where available and retain data only as long as needed, using Firebase's deletion mechanisms where appropriate.

7. Payments via Stripe

We use Stripe as a payment service provider to process online payments for your orders. When you make a payment:

Stripe may transfer personal data to the United States and other countries, relying on the EU–US Data Privacy Framework and Standard Contractual Clauses as transfer mechanisms.

8. Cookies and Analytics

Our website may use technically necessary cookies to provide core functionality (e.g. session management, security). These are required for the operation of the site and cannot be disabled.

If we introduce non-essential cookies or analytics/tracking tools (such as Firebase Analytics or other third-party services), we will inform you clearly about these tools, their purposes and the data they collect; request your consent via a cookie/banner mechanism before activating them for you, in line with GDPR and ePrivacy requirements; and provide you with options to withdraw consent at any time and disable tracking. This policy will be updated accordingly if such tools are added.

9. Recipients and Categories of Third Parties

We only share your personal data with third parties where this is necessary for our service, where we are legally obliged to do so, or where you have given consent. Typical recipients include:

We do not sell your data and do not share it for unrelated marketing purposes without your consent.

10. International Data Transfers

Because we use services from providers like Meta (WhatsApp), Google (Firebase) and Stripe, some processing may occur in countries outside the European Union/EEA, particularly the United States. Where personal data is transferred to third countries, we use appropriate legal safeguards, such as Standard Contractual Clauses approved by the European Commission and, where applicable, reliance on the EU–US Data Privacy Framework. We carefully select our service providers, review their data protection terms and maintain documentation of transfer impact assessments where GDPR requires. You can request more information about specific transfers and safeguards by contacting us.

11. Retention Periods

We store personal data only for as long as necessary for the purposes described above, or as required by statutory retention obligations. In particular:

When the retention period expires, data is deleted or anonymized, unless a longer retention is necessary due to ongoing legal proceedings or statutory requirements.

12. Your Rights under GDPR

As a data subject, you have the following rights under the GDPR, subject to the applicable legal conditions:

To exercise these rights, please contact us using the contact details in section 1. You also have the right to lodge a complaint with a supervisory authority, in particular with the data protection authority responsible for your place of residence or for our registered office (e.g. the Landesbeauftragte für Datenschutz in the relevant German federal state).

13. Security Measures

We take appropriate technical and organizational measures to protect your data against unauthorized access, loss, misuse or alteration. These measures include:

However, no internet transmission is completely secure; we cannot guarantee absolute security.

14. Changes to this Privacy Policy

We may revise this privacy policy from time to time to reflect changes in our service, in the technologies we use (e.g. new analytics tools), or in applicable legal requirements. The current version of this policy is always available on our website. If we introduce significant changes, we will inform you in an appropriate manner (e.g. via notice on the website or in-app notification).