Privacy Policy (Datenschutzerklärung)

Last updated: August 11, 2026 · Version 1.0

This Privacy Policy explains how we process personal data when you visit the TIRIDA Shop at tirida.world (the “Shop”) and when you place orders with us. It is written to satisfy the EU/EEA General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), the German Telecommunications Digital Services Data Protection Act (TDDDG), and applicable US state privacy laws.

1. Controller

The controller responsible for data processing on this website is:

TIRIDA LLC
225 E 58th Street
New York, NY 10022, United States of America
Email: support@tirida.world
Phone: +1 (656) 222-2507

Represented by: Frederike Falke (Managing Member)

We have not appointed a data protection officer, as we are not legally required to do so.

2. Summary: What We Collect and Why

We run a small online shop selling print-on-demand apparel and mugs as well as digital downloads. We collect only the data needed to operate the Shop and fulfil your orders. We do not use advertising trackers, analytics services, or marketing cookies, and we do not sell or share your personal data for advertising purposes. Only technically necessary cookies are used, which is why no cookie consent banner is displayed.

3. Hosting and Server Log Files

Our website is hosted by Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA (“Vercel”). When you visit the Shop, Vercel automatically processes technical connection data (IP address, date and time of the request, browser type and version, operating system, referrer URL, requested resource) in server log files. This processing is necessary to deliver the website, ensure stability and security, and defend against attacks.

Legal basis: Art. 6 (1)(f) GDPR (legitimate interest in the secure and reliable provision of our website). Log data is deleted or anonymized automatically.

We have concluded a data processing agreement (Art. 28 GDPR) with Vercel. Transfers to the USA are safeguarded by the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

4. Database and File Storage

Order, account, and shop data are stored in a database operated by Neon Inc., USA (“Neon”, serverless Postgres). The database is hosted in a data center located in the European Union (AWS eu-central-1, Frankfurt, Germany).

Files (e.g. digital download products, shop assets, backups) are stored with Backblaze Inc., 201 Baldwin Ave, San Mateo, CA 94401, USA (“Backblaze”, B2 Cloud Storage), in a data center located in the United States (us-east region).

Legal basis: Art. 6 (1)(b) GDPR (performance of the contract) and Art. 6 (1)(f) GDPR (legitimate interest in reliable data storage and backups). Data processing agreements pursuant to Art. 28 GDPR are in place with both providers; transfers to the USA, where they occur, are safeguarded by the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

5. Ordering Process

When you place an order, we collect the data required to conclude and perform the contract: name, shipping address, email address, order contents, and — for physical goods — delivery details. Without this data, we cannot process your order.

Legal basis: Art. 6 (1)(b) GDPR (performance of a contract). Statutory commercial and tax retention obligations (e.g. §§ 147 AO, 257 HGB where applicable, and equivalent US requirements) require us to retain order and invoice data for up to 10 years. Legal basis for retention: Art. 6 (1)(c) GDPR.

6. Payment Processing — Stripe

Payments are processed by Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland, and Stripe, Inc., 354 Oyster Point Blvd, South San Francisco, CA 94080, USA (“Stripe”). When you pay, your payment data (e.g. card number, cardholder name, billing address, payment amount) is transmitted directly to Stripe; we ourselves never receive or store your full card details. Stripe processes payment data partly as our processor and partly as an independent controller (e.g. for fraud prevention and regulatory compliance); Stripe’s own privacy policy is available at https://stripe.com/privacy.

Legal basis: Art. 6 (1)(b) GDPR (payment as part of contract performance) and Art. 6 (1)(f) GDPR (legitimate interest in secure, efficient payment processing and fraud prevention). Transfers to the USA are safeguarded by the EU Standard Contractual Clauses and the EU–US Data Privacy Framework, to which Stripe, Inc. is certified.

7. Order Fulfilment — Printful

Physical products (apparel, mugs) are produced and shipped on demand by our fulfilment partner Printful, Inc., 11025 Westlake Dr, Charlotte, NC 28273, USA, with production facilities in the USA, the EU (including Latvia and Spain), and other locations (“Printful”). To fulfil your order, we transmit to Printful your name and shipping address together with the order details necessary for production and delivery. Printful passes your delivery data on to the shipping carriers used for your order. Where possible, orders for EU customers are routed to Printful’s EU facilities.

Legal basis: Art. 6 (1)(b) GDPR (performance of the contract). A data processing agreement pursuant to Art. 28 GDPR is in place; transfers to the USA are safeguarded by the EU Standard Contractual Clauses.

8. Digital Downloads

If you purchase digital products, we provide the download via our infrastructure (Vercel / Backblaze, see above). We store which downloads your purchase entitles you to and log download access (timestamp, IP address) to secure delivery and prevent abuse.

Legal basis: Art. 6 (1)(b) GDPR (contract performance) and Art. 6 (1)(f) GDPR (abuse prevention).

9. Transactional Email — Resend

We send order confirmations, delivery notifications, download links, and other transactional emails via Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA (“Resend”). For this purpose, your email address and the message content are processed by Resend on our behalf. We do not send marketing newsletters.

Legal basis: Art. 6 (1)(b) GDPR (contract performance). A data processing agreement pursuant to Art. 28 GDPR is in place; transfers to the USA are safeguarded by the EU Standard Contractual Clauses.

10. Contact by Email

If you contact us by email, we process the data you provide (email address, name if given, content of your message) to handle your inquiry.

Legal basis: Art. 6 (1)(b) GDPR if your inquiry relates to a contract, otherwise Art. 6 (1)(f) GDPR (legitimate interest in answering inquiries). Inquiry correspondence is deleted when no longer needed, unless statutory retention duties apply.

11. Cookies

We use only technically necessary cookies (for example, to keep your shopping cart and checkout session working). These cookies are required to provide the service you explicitly request and therefore do not require consent (§ 25 (2) No. 2 TDDDG; Art. 6 (1)(b) and (f) GDPR). We use no analytics, advertising, or third-party tracking cookies, which is why no cookie banner is shown. If we introduce such technologies in the future, we will update this policy and implement a consent mechanism first.

12. Recipients of Personal Data — Overview

We use the following processors and recipients:

ProviderPurposeDataLocation / Transfer safeguard
StripePayment processingPayment and billing dataIreland / USA — SCCs, Data Privacy Framework
PrintfulProduction & shippingName, shipping address, order detailsUSA / EU facilities — SCCs
VercelWebsite hostingTechnical connection data (logs)USA / global edge — SCCs, DPF
NeonDatabase (orders, accounts)Order and customer dataEU data center (Frankfurt); US provider — SCCs
BackblazeFile storage & backupsShop files, backupsUSA (us-east) — SCCs
ResendTransactional emailEmail address, message contentUSA — SCCs

Beyond this, we disclose personal data only where we are legally obliged to do so (e.g. to tax authorities) or where necessary to establish, exercise, or defend legal claims.

13. Third-Country Transfers

Where personal data is transferred to the USA or other countries outside the EU/EEA, we ensure an adequate level of protection through EU Standard Contractual Clauses (Art. 46 (2)(c) GDPR) and, where the recipient is certified, the EU–US Data Privacy Framework (adequacy decision pursuant to Art. 45 GDPR).

14. Storage Periods

We store personal data only as long as necessary for the purposes described above. Order and billing data is retained for the duration of statutory retention periods (generally 6–10 years under German commercial and tax law, and comparable US requirements) and then deleted. Log data is deleted on a short rotation cycle. Contract-related correspondence is deleted once limitation periods for legal claims have expired.

15. Your Rights (GDPR — EU/EEA Customers)

You have the right to:

To exercise your rights, contact us at support@tirida.world.

16. Privacy Notice for US Residents

Depending on your state of residence (e.g. California, Colorado, Connecticut, Texas, Virginia, and others), you may have rights under state privacy laws, including the right to know what personal information we collect, the right to access, correct, and delete it, and the right to opt out of the sale or sharing of personal information and of targeted advertising.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We collect only the categories of information described in this policy (identifiers, contact details, commercial information such as order history, and internet activity in the form of technical logs), use them for the business purposes described here, and disclose them only to the service providers listed above.

Note: Given the current size of our business, we are likely below the applicability thresholds of most US state privacy laws (e.g. the CCPA’s revenue and volume thresholds). We nonetheless honor access, correction, and deletion requests from all US customers voluntarily. To make a request, contact support@tirida.world. We will verify your request using the email address associated with your order. Authorized agents may submit requests with proof of authorization. We do not discriminate against you for exercising your rights.

17. No Automated Decision-Making

We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR. (Note: Stripe may perform automated fraud screening of payment transactions under its own responsibility.)

18. Data Security

We use TLS encryption for all data transmitted through the Shop and restrict access to personal data to what is necessary for operating the business.

19. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes in our services or legal requirements. The current version is always available in the Shop.