Privacy Policy
Last updated: August 2026
1. Controller and Contact
This privacy policy explains how we process personal data when you visit our website and use our service to order printed stickers, including communication via WhatsApp and our web app.
Stick Maniac
E-Mail: info@stickmaniac.com
If you have any questions about this privacy policy or wish to exercise your data protection rights, you can contact us using the details above.
2. Scope of this Policy
This policy applies to:
- Visitors to our website.
- Users who send us stickers and other content via WhatsApp or through our web upload form to order printed products.
- Customers who place orders and make payments via Stripe.
- Users for whom we create a Firebase user account, including phone-number login.
It supplements WhatsApp's, Firebase's and Stripe's own privacy policies, which continue to apply independently when you use those services.
3. Categories of Personal Data
Depending on how you use our service, we may process the following categories of data:
- Basic contact and account data: name (if provided), phone number (for WhatsApp communication and Firebase Authentication), email address, delivery address, and, where applicable, billing address.
- Order and product data: sticker images and other files you send us, order contents (what you purchase, quantities, formats), prices, order timestamps, and communication related to your order.
- Payment data: information necessary to process payments (e.g. card type, last 4 digits, payment status, transaction IDs) via Stripe; card numbers and full payment credentials are processed by Stripe and not stored by us.
- Technical and usage data: IP address, browser type, device information, access times, and basic usage logs from our website and Firebase services (e.g. authentication logs).
- WhatsApp message data: phone numbers, message content (text, images, media), delivery and read receipts, timestamps and related metadata required to send and receive messages via the WhatsApp Business Platform.
4. Purposes and Legal Bases
We process personal data only where we have a legal basis under Art. 6 GDPR and, where relevant, obtain your consent. We use your data for the following purposes:
- Provision of our service and contract performance: processing your sticker submissions, communicating with you about your order, producing and delivering printed stickers, managing your customer account, and handling payment and invoicing. Legal basis: performance of a contract or steps prior to entering into a contract (Art. 6(1)(b) GDPR).
- WhatsApp communication: using the WhatsApp Business Platform to receive your sticker files, send order updates and respond to support requests. This involves transferring your phone number and message content to WhatsApp/Meta as part of the service. Legal basis: your consent (Art. 6(1)(a) GDPR) and, where communication is necessary for your order, contract performance (Art. 6(1)(b) GDPR).
- Firebase user accounts and authentication: creating and maintaining a user account based on your phone number, enabling secure login and protecting our service against abuse. Legal basis: contract performance (Art. 6(1)(b) GDPR) and our legitimate interest in secure and efficient user authentication (Art. 6(1)(f) GDPR).
- Payment processing via Stripe: processing payments, preventing fraud, and fulfilling accounting and tax obligations. Legal basis: performance of a contract (Art. 6(1)(b) GDPR) and legal obligations under German tax and commercial law (Art. 6(1)(c) GDPR).
- Compliance, security and documentation: maintaining records required by German commercial and tax law, enforcing our rights, and ensuring the technical and organizational security of our systems (e.g. logs, backups). Legal basis: legal obligations (Art. 6(1)(c) GDPR) and legitimate interests in IT security and fraud prevention (Art. 6(1)(f) GDPR).
- Analytics and improvement (future use): if we later implement analytics tools (e.g. Firebase Analytics), we will use data to understand how our service is used, fix bugs and improve usability. Where required, we will obtain your consent beforehand and update this policy. Legal basis: consent (Art. 6(1)(a) GDPR) or legitimate interest (Art. 6(1)(f) GDPR), depending on the specific tool and configuration.
5. WhatsApp Business Platform and Meta
When you contact us via WhatsApp or we send you messages using the WhatsApp Business Platform (including Cloud API), WhatsApp and Meta process certain personal data as our service providers. This includes:
- Your WhatsApp phone number, profile information (where visible), message content (text, images, stickers), and technical metadata (delivery status, timestamps, error codes).
- Storage and temporary retention of messages in encrypted form to enable delivery and retry mechanisms.
Meta acts as a data processor/service provider when providing the Cloud API and only processes messages in accordance with our instructions and WhatsApp's Business Data Processing Terms. Your WhatsApp usage is additionally governed by WhatsApp's own privacy policies and terms, which you accept when using WhatsApp.
You may withdraw your consent to receive WhatsApp communication at any time, for example by sending us a message such as "STOP" or by blocking our business account.
6. Firebase
We use Firebase services provided by Google (e.g. Firebase Authentication, Firestore/Database, Storage and hosting) to operate our web app, manage user accounts and store order data. Google generally acts as our data processor under GDPR for Firebase services:
- Firebase processes customer data exclusively to provide the services to us in accordance with the Firebase Data Processing and Security Terms.
- Customer personal data (e.g. phone numbers, authentication data, IP addresses) is processed by Firebase to enable authentication, account management, secure access and abuse prevention.
- Certain Firebase components, including Firebase Authentication, may process data in data centers outside the EU, particularly in the United States, relying on safeguards such as Standard Contractual Clauses and the EU–US Data Privacy Framework.
We configure our Firebase project to use EU regions where available and retain data only as long as needed, using Firebase's deletion mechanisms where appropriate.
7. Payments via Stripe
We use Stripe as a payment service provider to process online payments for your orders. When you make a payment:
- Stripe collects and processes your payment data (e.g. card details, bank information, billing address, device information) as an independent controller and/or processor, in accordance with Stripe's own Privacy Policy and Data Privacy Framework Policy.
- We receive only limited payment information from Stripe, such as transaction IDs, payment status, and partial card details (e.g. card type and last 4 digits) for reconciliation, fraud prevention and accounting.
Stripe may transfer personal data to the United States and other countries, relying on the EU–US Data Privacy Framework and Standard Contractual Clauses as transfer mechanisms.
8. Cookies and Analytics
Our website may use technically necessary cookies to provide core functionality (e.g. session management, security). These are required for the operation of the site and cannot be disabled.
If we introduce non-essential cookies or analytics/tracking tools (such as Firebase Analytics or other third-party services), we will inform you clearly about these tools, their purposes and the data they collect; request your consent via a cookie/banner mechanism before activating them for you, in line with GDPR and ePrivacy requirements; and provide you with options to withdraw consent at any time and disable tracking. This policy will be updated accordingly if such tools are added.
9. Recipients and Categories of Third Parties
We only share your personal data with third parties where this is necessary for our service, where we are legally obliged to do so, or where you have given consent. Typical recipients include:
- WhatsApp / Meta Platforms: to send and receive messages via WhatsApp Business Platform.
- Google (Firebase): for hosting, authentication, data storage and technical infrastructure.
- Stripe: for payment processing.
- Hosting and infrastructure providers: where we use third-party hosting, email or logging services to run our website and back-end systems (insofar as they act as our processors under Art. 28 GDPR).
- Tax advisors, auditors and authorities: where required to fulfill legal obligations under German tax and commercial law (e.g. bookkeeping, tax audits, statutory retention).
We do not sell your data and do not share it for unrelated marketing purposes without your consent.
10. International Data Transfers
Because we use services from providers like Meta (WhatsApp), Google (Firebase) and Stripe, some processing may occur in countries outside the European Union/EEA, particularly the United States. Where personal data is transferred to third countries, we use appropriate legal safeguards, such as Standard Contractual Clauses approved by the European Commission and, where applicable, reliance on the EU–US Data Privacy Framework. We carefully select our service providers, review their data protection terms and maintain documentation of transfer impact assessments where GDPR requires. You can request more information about specific transfers and safeguards by contacting us.
11. Retention Periods
We store personal data only for as long as necessary for the purposes described above, or as required by statutory retention obligations. In particular:
- Order and invoice data: retained for the duration of the contractual relationship and thereafter for the statutory retention period under German tax and commercial law (usually between 6 and 10 years, and for invoices currently 8 years) starting at the end of the calendar year in which the document was created.
- Customer and account data (Firebase): retained while your user account is active; upon request for deletion or account closure, data is deleted or anonymized, subject to statutory retention requirements and the deletion timelines of the Firebase services (generally up to 180 days in backups).
- WhatsApp message data: stored by our systems only as long as needed to process your request and order; messages processed via Cloud API are generally retained by Meta only for a limited period (e.g. up to 30 days) for delivery and technical purposes.
- Payment data (Stripe): retained by Stripe according to its own legal obligations and internal policies; we keep only necessary transaction records for our accounting within the applicable retention periods.
When the retention period expires, data is deleted or anonymized, unless a longer retention is necessary due to ongoing legal proceedings or statutory requirements.
12. Your Rights under GDPR
As a data subject, you have the following rights under the GDPR, subject to the applicable legal conditions:
- Right of access (Art. 15 GDPR): to obtain confirmation whether we process your personal data and to receive a copy of that data.
- Right to rectification (Art. 16 GDPR): to have inaccurate or incomplete data corrected.
- Right to erasure ("right to be forgotten") (Art. 17 GDPR): to request deletion of your personal data, especially where the data is no longer needed or where you withdraw consent, provided no legal obligations require continued retention.
- Right to restriction of processing (Art. 18 GDPR).
- Right to data portability (Art. 20 GDPR): to receive the data you provided in a structured, commonly used, machine-readable format, and to transmit it to another controller.
- Right to object (Art. 21 GDPR): to object to processing based on our legitimate interests, particularly for direct marketing.
- Right to withdraw consent (Art. 7(3) GDPR): where processing is based on your consent (e.g. WhatsApp communication, certain analytics), you may withdraw that consent at any time with effect for the future.
To exercise these rights, please contact us using the contact details in section 1. You also have the right to lodge a complaint with a supervisory authority, in particular with the data protection authority responsible for your place of residence or for our registered office (e.g. the Landesbeauftragte für Datenschutz in the relevant German federal state).
13. Security Measures
We take appropriate technical and organizational measures to protect your data against unauthorized access, loss, misuse or alteration. These measures include:
- Use of secure transport (HTTPS/TLS) for our website and APIs.
- Access control and authentication mechanisms for administrative accounts.
- Use of reputable service providers (Firebase, Stripe, WhatsApp/Meta) with strong security certifications and data protection terms.
- Regular updates, backups and monitoring to detect and prevent security incidents.
However, no internet transmission is completely secure; we cannot guarantee absolute security.
14. Changes to this Privacy Policy
We may revise this privacy policy from time to time to reflect changes in our service, in the technologies we use (e.g. new analytics tools), or in applicable legal requirements. The current version of this policy is always available on our website. If we introduce significant changes, we will inform you in an appropriate manner (e.g. via notice on the website or in-app notification).