Privacy Policy (Datenschutzerklärung)
Last updated: August 11, 2026 · Version 1.0
This Privacy Policy explains how we process personal data when you visit the TIRIDA Shop at tirida.world (the “Shop”) and when you place orders with us. It is written to satisfy the EU/EEA General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), the German Telecommunications Digital Services Data Protection Act (TDDDG), and applicable US state privacy laws.
1. Controller
The controller responsible for data processing on this website is:
TIRIDA LLC
225 E 58th Street
New York, NY 10022, United States of America
Email: support@tirida.world
Phone: +1 (656) 222-2507
Represented by: Frederike Falke (Managing Member)
We have not appointed a data protection officer, as we are not legally required to do so.
2. Summary: What We Collect and Why
We run a small online shop selling print-on-demand apparel and mugs as well as digital downloads. We collect only the data needed to operate the Shop and fulfil your orders. We do not use advertising trackers, analytics services, or marketing cookies, and we do not sell or share your personal data for advertising purposes. Only technically necessary cookies are used, which is why no cookie consent banner is displayed.
3. Hosting and Server Log Files
Our website is hosted by Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA (“Vercel”). When you visit the Shop, Vercel automatically processes technical connection data (IP address, date and time of the request, browser type and version, operating system, referrer URL, requested resource) in server log files. This processing is necessary to deliver the website, ensure stability and security, and defend against attacks.
Legal basis: Art. 6 (1)(f) GDPR (legitimate interest in the secure and reliable provision of our website). Log data is deleted or anonymized automatically.
We have concluded a data processing agreement (Art. 28 GDPR) with Vercel. Transfers to the USA are safeguarded by the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
4. Database and File Storage
Order, account, and shop data are stored in a database operated by Neon Inc., USA (“Neon”, serverless Postgres). The database is hosted in a data center located in the European Union (AWS eu-central-1, Frankfurt, Germany).
Files (e.g. digital download products, shop assets, backups) are stored with Backblaze Inc., 201 Baldwin Ave, San Mateo, CA 94401, USA (“Backblaze”, B2 Cloud Storage), in a data center located in the United States (us-east region).
Legal basis: Art. 6 (1)(b) GDPR (performance of the contract) and Art. 6 (1)(f) GDPR (legitimate interest in reliable data storage and backups). Data processing agreements pursuant to Art. 28 GDPR are in place with both providers; transfers to the USA, where they occur, are safeguarded by the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
5. Ordering Process
When you place an order, we collect the data required to conclude and perform the contract: name, shipping address, email address, order contents, and — for physical goods — delivery details. Without this data, we cannot process your order.
Legal basis: Art. 6 (1)(b) GDPR (performance of a contract). Statutory commercial and tax retention obligations (e.g. §§ 147 AO, 257 HGB where applicable, and equivalent US requirements) require us to retain order and invoice data for up to 10 years. Legal basis for retention: Art. 6 (1)(c) GDPR.
6. Payment Processing — Stripe
Payments are processed by Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland, and Stripe, Inc., 354 Oyster Point Blvd, South San Francisco, CA 94080, USA (“Stripe”). When you pay, your payment data (e.g. card number, cardholder name, billing address, payment amount) is transmitted directly to Stripe; we ourselves never receive or store your full card details. Stripe processes payment data partly as our processor and partly as an independent controller (e.g. for fraud prevention and regulatory compliance); Stripe’s own privacy policy is available at https://stripe.com/privacy.
Legal basis: Art. 6 (1)(b) GDPR (payment as part of contract performance) and Art. 6 (1)(f) GDPR (legitimate interest in secure, efficient payment processing and fraud prevention). Transfers to the USA are safeguarded by the EU Standard Contractual Clauses and the EU–US Data Privacy Framework, to which Stripe, Inc. is certified.
7. Order Fulfilment — Printful
Physical products (apparel, mugs) are produced and shipped on demand by our fulfilment partner Printful, Inc., 11025 Westlake Dr, Charlotte, NC 28273, USA, with production facilities in the USA, the EU (including Latvia and Spain), and other locations (“Printful”). To fulfil your order, we transmit to Printful your name and shipping address together with the order details necessary for production and delivery. Printful passes your delivery data on to the shipping carriers used for your order. Where possible, orders for EU customers are routed to Printful’s EU facilities.
Legal basis: Art. 6 (1)(b) GDPR (performance of the contract). A data processing agreement pursuant to Art. 28 GDPR is in place; transfers to the USA are safeguarded by the EU Standard Contractual Clauses.
8. Digital Downloads
If you purchase digital products, we provide the download via our infrastructure (Vercel / Backblaze, see above). We store which downloads your purchase entitles you to and log download access (timestamp, IP address) to secure delivery and prevent abuse.
Legal basis: Art. 6 (1)(b) GDPR (contract performance) and Art. 6 (1)(f) GDPR (abuse prevention).
9. Transactional Email — Resend
We send order confirmations, delivery notifications, download links, and other transactional emails via Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA (“Resend”). For this purpose, your email address and the message content are processed by Resend on our behalf. We do not send marketing newsletters.
Legal basis: Art. 6 (1)(b) GDPR (contract performance). A data processing agreement pursuant to Art. 28 GDPR is in place; transfers to the USA are safeguarded by the EU Standard Contractual Clauses.
10. Contact by Email
If you contact us by email, we process the data you provide (email address, name if given, content of your message) to handle your inquiry.
Legal basis: Art. 6 (1)(b) GDPR if your inquiry relates to a contract, otherwise Art. 6 (1)(f) GDPR (legitimate interest in answering inquiries). Inquiry correspondence is deleted when no longer needed, unless statutory retention duties apply.
11. Cookies
We use only technically necessary cookies (for example, to keep your shopping cart and checkout session working). These cookies are required to provide the service you explicitly request and therefore do not require consent (§ 25 (2) No. 2 TDDDG; Art. 6 (1)(b) and (f) GDPR). We use no analytics, advertising, or third-party tracking cookies, which is why no cookie banner is shown. If we introduce such technologies in the future, we will update this policy and implement a consent mechanism first.
12. Recipients of Personal Data — Overview
We use the following processors and recipients:
| Provider | Purpose | Data | Location / Transfer safeguard |
|---|---|---|---|
| Stripe | Payment processing | Payment and billing data | Ireland / USA — SCCs, Data Privacy Framework |
| Printful | Production & shipping | Name, shipping address, order details | USA / EU facilities — SCCs |
| Vercel | Website hosting | Technical connection data (logs) | USA / global edge — SCCs, DPF |
| Neon | Database (orders, accounts) | Order and customer data | EU data center (Frankfurt); US provider — SCCs |
| Backblaze | File storage & backups | Shop files, backups | USA (us-east) — SCCs |
| Resend | Transactional email | Email address, message content | USA — SCCs |
Beyond this, we disclose personal data only where we are legally obliged to do so (e.g. to tax authorities) or where necessary to establish, exercise, or defend legal claims.
13. Third-Country Transfers
Where personal data is transferred to the USA or other countries outside the EU/EEA, we ensure an adequate level of protection through EU Standard Contractual Clauses (Art. 46 (2)(c) GDPR) and, where the recipient is certified, the EU–US Data Privacy Framework (adequacy decision pursuant to Art. 45 GDPR).
14. Storage Periods
We store personal data only as long as necessary for the purposes described above. Order and billing data is retained for the duration of statutory retention periods (generally 6–10 years under German commercial and tax law, and comparable US requirements) and then deleted. Log data is deleted on a short rotation cycle. Contract-related correspondence is deleted once limitation periods for legal claims have expired.
15. Your Rights (GDPR — EU/EEA Customers)
You have the right to:
- Access (Art. 15 GDPR) — obtain confirmation and a copy of your personal data;
- Rectification (Art. 16 GDPR) — have inaccurate data corrected;
- Erasure (Art. 17 GDPR) — have your data deleted where the conditions are met;
- Restriction of processing (Art. 18 GDPR);
- Data portability (Art. 20 GDPR) — receive your data in a structured, commonly used, machine-readable format;
- Object (Art. 21 GDPR) — object at any time to processing based on legitimate interests, for reasons arising from your particular situation;
- Withdraw consent (Art. 7 (3) GDPR) — where processing is based on consent, with effect for the future;
- Lodge a complaint (Art. 77 GDPR) with a supervisory authority, in particular in the EU member state of your habitual residence, place of work, or the place of the alleged infringement.
To exercise your rights, contact us at support@tirida.world.
16. Privacy Notice for US Residents
Depending on your state of residence (e.g. California, Colorado, Connecticut, Texas, Virginia, and others), you may have rights under state privacy laws, including the right to know what personal information we collect, the right to access, correct, and delete it, and the right to opt out of the sale or sharing of personal information and of targeted advertising.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We collect only the categories of information described in this policy (identifiers, contact details, commercial information such as order history, and internet activity in the form of technical logs), use them for the business purposes described here, and disclose them only to the service providers listed above.
Note: Given the current size of our business, we are likely below the applicability thresholds of most US state privacy laws (e.g. the CCPA’s revenue and volume thresholds). We nonetheless honor access, correction, and deletion requests from all US customers voluntarily. To make a request, contact support@tirida.world. We will verify your request using the email address associated with your order. Authorized agents may submit requests with proof of authorization. We do not discriminate against you for exercising your rights.
17. No Automated Decision-Making
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR. (Note: Stripe may perform automated fraud screening of payment transactions under its own responsibility.)
18. Data Security
We use TLS encryption for all data transmitted through the Shop and restrict access to personal data to what is necessary for operating the business.
19. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes in our services or legal requirements. The current version is always available in the Shop.