Privacy policy

NIMORI Franke & Thürnagel GbR – as of March 2025

This privacy policy is intended to provide you, as a user of our website www.nimori.de , with comprehensive information about how, to what extent, and for what purpose we – NIMORI Franke & Thürnagel GbR – process your personal data. Protecting your privacy and your personal data is a top priority for us. We treat your data confidentially and in accordance with statutory data protection regulations, in particular the General Data Protection Regulation (GDPR), the Federal Data Protection Act (BDSG), and other relevant legal provisions.

Please note that new legal requirements or changes to our internal processes may result in adjustments to this privacy policy. We therefore recommend that you read this privacy policy regularly. You can save and/or print this policy at any time using your browser.


Controller within the meaning of the GDPR

NIMORI Franke & Thürnagel GbR
Prälat-Wellenhofer-Str. 21
81377 Munich
Germany
Represented by: Ricardo Franke and Nina Thürnagel
Email: info@nimori.de
Phone: 0151 51829241


Hosting and technical operation of the website

Our website is provided via the Shopify shopping cart system . The provider responsible for operating the platform is Shopify Inc., 151 O'Connor Street, Ground Floor, Ottawa, ON K2P 2L8, Canada.

The technical operation of our website (hosting, database provision, content delivery) takes place on servers in Canada and partly in the United States. Shopify processes your personal data under a data processing agreement in accordance with Art. 28 GDPR.

For data transfer to Canada, the European Commission has issued an adequacy decision pursuant to Art. 45 GDPR. For transfer to the USA, Shopify relies on the use of the EU standard contractual clauses pursuant to Art. 46 (2) (c) GDPR.

The following data is automatically processed each time the website is accessed and stored in so-called server log files:

- IP address of the requesting device,

- Date and time of access,

- Name and URL of the retrieved file,

- Referrer URL (website from which access was made),

- browser type used and, if applicable, the operating system of your device,

- Name of your access provider.

The processing of this data is technically necessary to ensure the functionality and stability of our website, as well as for error analysis, optimization, and system security. The legal basis is Art. 6 (1) (f) GDPR.

These log files are stored for security reasons (e.g. to investigate misuse or fraud) for a maximum of 10 days and then archived anonymously.


Customer account and order processing

You have the option of creating a customer account on our website. In this context, we process the following data:

- Name first Name

- Address (billing and delivery address)

- E-mail address

- Password (encrypted)

- Date of registration

- Order history

We process this data to fulfill contractual obligations, in particular for order and payment processing, as well as for any queries. The legal basis is Art. 6 (1) (b) GDPR.

In the case of a guest order, we only process the data necessary to process the contract. Data is stored within the statutory retention periods (Section 257 of the German Commercial Code (HGB), Section 147 of the German Fiscal Code (AO)).


Payment service providers

We work with the following providers for payment processing:

- PayPal (PayPal Europe S.à rl, Luxembourg)

- Klarna (Klarna Bank AB, Sweden)

- Sofortüberweisung (Sofort GmbH, Germany)

- Apple Pay (Apple Inc., USA)

- Stripe (Stripe Payments Europe Ltd., Ireland)

Depending on the payment method selected, we transmit the data necessary to process the payment to the respective service provider. This may include name, address, payment amount, as well as account or credit card information. Processing is based on Art. 6 (1) (b) GDPR.

Some providers transfer data to third countries, particularly the USA. In these cases, the transfer is based on appropriate safeguards in accordance with Art. 46 GDPR (standard contractual clauses).


Shipping service provider

To deliver your order, we use the service provider AMARA Fullfillment UG , Langgarten 21, 69124 Heidelberg. The following information is transmitted to DHL:

- Name

- Delivery address

- if applicable, email address (for shipment notifications)

The processing is carried out in accordance with Art. 6 (1) (b) GDPR for the purpose of fulfilling the contract.


Contact form and communication

If you contact us via our contact form, we collect your email address and any other information you provide in the form. We process this data to process your request in accordance with Art. 6 (1) (b) GDPR.

We also offer you the opportunity to communicate with us via WhatsApp Messenger . Provider: WhatsApp Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. Personal data will be forwarded to WhatsApp LLC (USA). Communication will only take place with your prior express consent in accordance with Art. 6 (1) (a) GDPR. You can revoke your consent at any time with future effect.

Newsletter distribution with Klaviyo

If you sign up for our newsletter, we will use your email address to regularly send you information about our products, offers, and promotions. For delivery and analysis, we use the "Klaviyo" service, provided by Klaviyo Inc., 125 Summer Street, Boston, MA 02110, USA.

Registration process: Registration is done using the double opt-in process. This means that after registration, you will receive an email asking you to confirm your registration. Only after confirmation will your email address be added to the mailing list.

Data collected:

- E-mail address

- Time of registration and confirmation

- IP address

- Interaction data (e.g. opens, clicks, unsubscribes)

Legal basis: Art. 6 (1) (a) GDPR (consent). You can revoke your consent at any time with future effect, e.g., via the unsubscribe link in every newsletter email.

Data transfer to third countries: Klaviyo transfers data to the USA. The transfer is based on the EU Commission's standard contractual clauses in accordance with Art. 46 (2) (c) GDPR.


Web analysis and tracking

We use technologies on our website to analyze user behavior and display personalized advertising.

Google Analytics

This website uses Google Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). Google Analytics uses cookies to analyze website usage. Your IP address will be shortened (IP anonymization enabled).

Data transfer to the USA: The data is transferred to Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. The transfer is based on standard contractual clauses in accordance with Art. 46 GDPR.

Legal basis: Art. 6 (1) (a) GDPR (consent via cookie banner).

Meta Pixel

We use the so-called "Meta Pixel" from Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. This allows us to measure the effectiveness of Facebook/Instagram ads.

Data processed: visitor behavior, referrer URLs, IP addresses, browser information. The data is anonymous to us, but Meta can link it to your Facebook account.

Legal basis: Art. 6 (1) (a) GDPR.

Data transfer to third countries: Meta Platforms Inc. (USA) is protected by standard contractual clauses in accordance with Art. 46 GDPR.


Use of cookies and consent tool

Our website uses cookies. These are necessary to provide the website in a functional and secure manner, as well as for analytical and marketing purposes.

Consent to the use of cookies is given via a cookie consent tool when you first visit our website. You can change or revoke your decision there at any time.

Legal basis:

- Essential cookies: Art. 6 (1) (f) GDPR (legitimate interest)

- Functional, analytical and marketing cookies: Art. 6 (1) (a) GDPR (consent)


Product reviews on Judge.me

We use the service Judge.me (Judge.me LLC, 914 Fulton Street, FL 4, Chicago, IL 60657, USA) to collect and publish product reviews .

Data processed:

- Name

- E-mail address

- Product review

- Order reference

Purpose: Publication of transparent customer reviews for quality improvement. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest). Data transfer: To the USA using the EU standard contractual clauses.


Competitions and promotions

If you participate in our competitions or promotions, we process the necessary data (e.g. name, email address, time of participation).

Legal basis: Art. 6 (1) (b) GDPR (contract on conditions of participation). After the competition ends, your data will be deleted unless there is a legal obligation to retain it.


Transfer to third countries

Some of the tools mentioned above transfer data to third countries outside the EU, particularly to the USA. The transfer occurs exclusively on the basis of:

- an adequacy decision by the EU Commission (e.g. for Canada)

- or by concluding EU standard contractual clauses with the respective service provider (Art. 46 GDPR)


Your rights under the GDPR

As a data subject, you have the right at any time:

- to information about your stored data (Art. 15 GDPR)

- to rectification of incorrect or incomplete data (Art. 16 GDPR)

- to deletion (“right to be forgotten”, Art. 17 GDPR)

- to restriction of processing (Art. 18 GDPR)

- to data portability (Art. 20 GDPR)

- to object to processing (Art. 21 GDPR)

- to revoke consent given (Art. 7 para. 3 GDPR)

- to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR)

You can assert your rights by email to info@nimori.de or by post to the above address.


Data security

We implement technical and organizational security measures in accordance with Art. 32 GDPR to protect your data against loss, manipulation, or unauthorized access by third parties. Our website uses SSL/TLS encryption.


Last updated: March 2025

This privacy policy is regularly reviewed and updated to comply with legal requirements and our internal processes.