Privacy policy
Privacy Policy
Last updated: 29 July 2026
Thank you for your interest in our shop. Protecting your data matters to us. Below you will find out which data we process, why we do so, and what rights you have.
1. Controller
The controller responsible for data processing on this website is:
Benjamin Schwalm
Einzelunternehmen Benjamin Schwalm (sole proprietorship)
Rudolf-Wild-Strasse 84
69214 Eppelheim
Germany
Email: info@roomberry.de
Phone: +49 176 23202605
VAT identification number: DE346581736
This privacy policy applies to our online shops at roomberry.de and roomberry.fr, including all subpages and language versions of these domains.
We have not appointed a data protection officer. We are not required to do so, because fewer than twenty people in our company are permanently engaged in the automated processing of personal data (Section 38(1) of the German Federal Data Protection Act).
2. Access data and hosting
You can visit our pages without providing any personal information. Each time a page is accessed, the web server automatically stores a server log file. It contains the name of the file requested, your IP address, the date and time of the request, the volume of data transferred, browser and device information, and the referring page.
We evaluate this access data solely to ensure the trouble-free operation of the site and to improve our offering. The legal basis is our legitimate interest in a secure and correctly functioning website under Article 6(1)(f) GDPR. Log files are deleted after 30 days at the latest.
Hosting and shop platform: Our shop runs on the platform of Shopify International Limited, Dublin, Ireland, which belongs to the Canadian company Shopify Inc. Shopify processes our customers' data on our behalf as a processor. A data processing agreement under Article 28 GDPR is in place with Shopify.
Shopify processes data in Canada and in the United States. For Canada, the European Commission has established an adequate level of data protection. For transfers to the United States and other third countries, Shopify relies on binding corporate rules as well as on the European Commission's standard contractual clauses.
Shopify's privacy policy: https://www.shopify.com/legal/privacy
3. Data processing when you place an order
When you order from us, we process the data you provide during the order process: first and last name, billing and delivery address, email address, telephone number where applicable, and the details of the payment method you select. Mandatory fields are marked as such — without this information we cannot process your order.
We use this data to perform the purchase contract, to keep you informed about the status of your order, and to handle enquiries regarding warranty or withdrawal. The legal basis is Article 6(1)(b) GDPR (performance of a contract).
Once the contract has been fully performed, we restrict further processing. We delete the data after the retention periods under commercial and tax law have expired — depending on the type of document, six years under Section 257 of the German Commercial Code or ten years under Section 147 of the German Fiscal Code, in each case from the end of the calendar year. The legal basis for this continued storage is Article 6(1)(c) GDPR (legal obligation).
For order processing and shipping we use the software Billbee provided by Billbee GmbH, Germany. Billbee processes order and address data on our behalf as a processor; a data processing agreement under Article 28 GDPR is in place. The legal basis is Article 6(1)(b) GDPR.
4. Shipping
In order to deliver your order, we pass your name and delivery address to the shipping company engaged for this purpose. We ship with DHL (DHL Group, Bonn, Germany). The legal basis is Article 6(1)(b) GDPR.
If you have expressly consented when placing your order, we additionally pass your email address to the shipping company so that you can receive status information about your shipment. In that case the legal basis is Article 6(1)(a) GDPR. You may withdraw this consent at any time.
5. Payment processing
Depending on the payment method you select, we pass the data required for processing the payment to the relevant payment service provider. The legal basis is Article 6(1)(b) GDPR. In some cases the payment service providers collect the data themselves — their own privacy policy then applies in addition.
We work with the following providers:
- Shopify Payments (credit card, Apple Pay, Google Pay, Sofort) — Shopify International Limited, Dublin, Ireland. Privacy policy
- PayPal — PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg. Privacy policy
- Klarna — Klarna Bank AB (publ), Stockholm, Sweden. Privacy policy
For certain payment methods, PayPal and Klarna carry out a credit assessment and transmit data to credit agencies for that purpose. You will find details in the providers' privacy policies linked above.
6. Contacting us and the withdrawal form
If you contact us by email or through a form, we process the data you provide in order to answer your enquiry. The legal basis is Article 6(1)(b) GDPR where your enquiry relates to a contract, and otherwise our legitimate interest in responding to enquiries under Article 6(1)(f) GDPR.
Through our withdrawal form we collect your name, your email address and your order number, optionally a different email address for the confirmation, the reason for withdrawal and the items concerned. We need this data in order to identify and process your withdrawal. The legal basis is Article 6(1)(b) GDPR in conjunction with Section 355 of the German Civil Code. Providing a reason for withdrawal is voluntary.
We delete enquiries once they have been dealt with, unless statutory retention periods apply.
7. Newsletter
If you subscribe to our newsletter, we use your email address and the other details you provide in order to send you news and offers on a regular basis. The legal basis is your consent under Article 6(1)(a) GDPR.
For sending we use Klaviyo (Klaviyo, Inc., Boston, Massachusetts, USA). Klaviyo processes the newsletter data on our behalf as a processor; a data processing agreement under Article 28 GDPR is in place.
Klaviyo measures whether and when you open our newsletters and which links you click. We use this to create usage profiles so that we can send you more relevant content. Klaviyo also sets a cookie on our website (__kla_id) which recognises returning visitors and links browsing behaviour to the newsletter profile. We only use this on-site tracking with your consent — the legal basis is Article 6(1)(a) GDPR in conjunction with Section 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG).
Klaviyo processes data in the United States. The transfer is based on Klaviyo's certification under the EU-US Data Privacy Framework and, in addition, on the European Commission's standard contractual clauses. Please also note our information under section 13.
You can unsubscribe at any time — using the unsubscribe link in every email or by sending a message to info@roomberry.de. After you unsubscribe we remove your email address from the distribution list.
Klaviyo's privacy policy: https://www.klaviyo.com/legal/privacy/privacy-notice
8. Cookies and consent
We use cookies and comparable technologies on our website. Cookies are small text files stored on your device. Some are deleted as soon as you close your browser (session cookies), while others remain stored for longer and recognise your browser on your next visit (persistent cookies).
Technically necessary cookies are required for the shop to function at all — for example for the shopping cart, the language and currency selection, and security. We set these without your consent. The basis is Section 25(2) no. 2 TDDDG; for the associated data processing we rely on Article 6(1)(f) GDPR.
All other cookies and technologies — in particular those used for reach measurement, analytics and advertising — are only set if you have given your consent. The legal basis is Section 25(1) TDDDG for storing and reading information on your device, and Article 6(1)(a) GDPR for the subsequent processing of your data.
Consent tool: To obtain and document your consent we use Pandectes GDPR Compliance provided by Pandectes OÜ, based in Estonia. In doing so, the tool stores a randomly generated identifier, the date and time of your decision, the page on which you made it, your shortened IP address, information about your browser, and the content of your decision. We need this data in order to be able to demonstrate your consent — Article 7(1) GDPR requires this of us. The legal basis is Article 6(1)(c) GDPR.
Changing or withdrawing consent: You can change your decision at any time with effect for the future. Please use the Cookie settings link in the footer of every page. Alternatively, a message to info@roomberry.de is sufficient. Withdrawal does not affect the lawfulness of processing carried out up to that point.
You can also block or delete cookies in your browser. Some areas of the shop may then not work properly.
9. Analytics and advertising
We use the following services exclusively with your consent. In each case the legal basis is Article 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG. You can withdraw your consent at any time via the cookie settings.
9.1 Google Analytics 4
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
We use Google Analytics to understand how our shop is used — which pages are viewed, where visitors come from, and where they abandon a purchase. The cookies _ga and _ga_Z7945445X5 are set, and a pseudonymous identifier, your shortened IP address, device and browser information, and your interactions in the shop are processed. Google truncates your IP address before it is stored.
Cookie storage period: up to two years. Google deletes the usage data stored in Google Analytics after 14 months.
Privacy policy: https://policies.google.com/privacy · Browser opt-out: https://tools.google.com/dlpage/gaoptout
9.2 Google Ads with conversion tracking and remarketing
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
We run advertisements through Google Ads. Using the cookie _gcl_au we measure whether a click on an advertisement led to a purchase, and we can show you advertisements for our products again on other websites within the Google advertising network. This involves processing click and device information, your IP address, the pages you visit and purchase events. Cookie storage period: approximately 90 days.
Google ad settings: https://adssettings.google.com/
9.3 Meta pixel (Facebook and Instagram)
Provider: Meta Platforms Ireland Limited, Dublin, Ireland.
We use the Meta pixel to measure the effectiveness of our advertisements on Facebook and Instagram and to show you relevant advertising there. The cookie _fbp (a pseudonymous browser identifier) is set, and _fbc when you click an advertisement. Events such as page views, product views, add-to-cart actions and purchases are transmitted, including product identifiers and prices, along with your IP address and browser and device information.
For the collection and transmission of this data we are joint controllers with Meta within the meaning of Article 26 GDPR. Meta provides a joint controller arrangement setting out the respective responsibilities. Meta is solely responsible for its own subsequent processing.
Controller addendum: https://www.facebook.com/legal/controller_addendum · Privacy policy: https://www.facebook.com/privacy/policy/
9.4 Pinterest tag
Provider: Pinterest Europe Ltd., Dublin, Ireland.
The Pinterest tag measures whether visits originating from Pinterest lead to a purchase and enables retargeting. The cookie _pin_unauth is set. Event data, your IP address and device and browser information are processed.
Privacy policy: https://policy.pinterest.com/en/privacy-policy
9.5 TikTok pixel
Provider: TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland, together with TikTok Information Technologies UK Limited, London, United Kingdom.
The TikTok pixel measures the success of our advertisements on TikTok and enables retargeting. Cookies set include _ttp, ttclid and ttcsid. Event data, your IP address and device information are processed.
According to its own information, TikTok bases transfers to third countries on adequacy decisions, the European Commission's standard contractual clauses and, in individual cases, on Article 49 GDPR.
Privacy policy: https://www.tiktok.com/legal/page/eea/privacy-policy/en
9.6 Microsoft Clarity — session recording
Provider: Microsoft Ireland Operations Limited, Dublin, Ireland, for Microsoft Corporation, USA.
This service goes beyond simple visitor counting, which is why we explain it in more detail. Microsoft Clarity records how you move around our pages: mouse movements, clicks, scrolling behaviour, page changes and the structure of the pages you see. This makes it possible to reconstruct your session afterwards as a sequence of actions, and it produces analyses showing which areas of a page attract attention. This is not a video recording of your screen, and we do not gain access to your camera or to other programs.
We use this to identify usability problems in the shop — for example points at which orders are regularly abandoned. The cookies _clck and _clsk are set. Recordings are deleted after 30 days.
According to its own information, Microsoft processes this data as an independent controller and not on our behalf. Microsoft's own privacy policy therefore applies to Microsoft's processing.
Privacy policy: https://privacy.microsoft.com/en-gb/privacystatement
9.7 Server-side measurement (Elevar)
Provider: Audiense LLC, Fort Worth, Texas, USA (formerly Elevar).
We use a server-side measurement solution which records events such as add-to-cart actions and purchases not only in the browser but via our server, and passes them on to the providers named above. This serves the completeness of the measurement. Identifiers are stored in your browser's local storage for this purpose (including ___ELEVAR_GTM_SUITE--userId and --sessionId).
We also use this measurement only with your consent. The fact that the data is processed server-side does not remove the requirement for consent.
10. Product reviews
For customer reviews, including uploaded photos, we use the service Loox provided by Loox Online Ltd., Israel.
After a purchase we may ask you by email for a review. This involves processing your name, your email address, the order data, the content of your review and any images you upload. Loox processes this data on our behalf.
We send the invitation to review on the basis of your consent under Article 6(1)(a) GDPR. Your review is published on the basis of the consent you give when you submit it. If you upload a photo in which people are identifiable, please make sure that they agree to this.
Loox processes data in Israel. For Israel, the European Commission has established an adequate level of data protection.
Privacy policy: https://loox.io/legal/privacy_policy
11. Our social media profiles
We maintain our own profiles on Facebook, Instagram, Pinterest and TikTok. When you visit these profiles, the respective networks process your data in accordance with their own terms — we have no influence over this.
The networks provide us with anonymised statistics about the use of our profiles. In this respect we are joint controllers with the respective network under Article 26 GDPR. The legal basis for our presence on social media is our legitimate interest in external communication and customer contact under Article 6(1)(f) GDPR.
The links to our profiles on our website are simple links. Merely visiting our pages does not establish any connection to the networks.
12. Use of artificial intelligence
We use AI tools in our day-to-day work — exclusively in areas where no customer data is involved.
Specifically, we use AI for:
- creating and editing product images and advertising visuals,
- drafting text for product descriptions, newsletters and advertisements,
- analysing aggregated business figures without any personal reference, such as revenue and inventory trends.
We do not enter any personal data from orders, customer accounts or enquiries into these tools. Your data is not used to train AI models.
We do not take any decisions about you based solely on automated processing, including profiling, which produce legal effects concerning you or similarly significantly affect you — in other words, no automated decision-making within the meaning of Article 22 GDPR takes place.
Should we use AI tools that process personal data in future, we will inform you here in advance and put in place the necessary legal basis.
13. Transfers to countries outside the EU
Some of the providers named above process data in the United States or in other countries outside the European Union. For some of these countries there is no European Commission decision establishing an adequate level of data protection.
Where we rely on the European Commission's standard contractual clauses, these are agreed in the respective contracts with the providers. Some providers are additionally certified under the EU-US Data Privacy Framework, for which the European Commission has established an adequate level of protection.
We openly point out that, in the case of transfers to the United States, authorities there may under certain conditions access data, and that comparable legal remedies to those available under European law may not exist. Transfers to these providers therefore only take place if you have given your consent — and you can withdraw that consent at any time.
14. Your rights
You have the following rights in relation to us:
- Access (Article 15 GDPR): You can find out which of your data we process.
- Rectification (Article 16 GDPR): You can ask us to correct inaccurate data or complete incomplete data.
- Erasure (Article 17 GDPR): You can request the deletion of your data, provided we no longer need it and no statutory retention obligation prevents this.
- Restriction of processing (Article 18 GDPR).
- Data portability (Article 20 GDPR): You can receive the data you have provided to us in a common, machine-readable format.
- Withdrawal of consent (Article 7(3) GDPR): You can withdraw consent you have given at any time with effect for the future.
- Complaint to a supervisory authority (Article 77 GDPR).
Right to object under Article 21 GDPR
Where we process data on the basis of legitimate interests under Article 6(1)(f) GDPR, you can object to that processing if grounds arise from your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds which override your interests, or the processing serves to establish, exercise or defend legal claims.
If we process your data for direct marketing, you can object at any time and without giving reasons. We will then no longer use your data for that purpose.
An informal message to info@roomberry.de is sufficient for any of these requests.
15. Right to complain to the supervisory authority
You have the right to complain to a data protection supervisory authority. The authority responsible for us is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
(State Commissioner for Data Protection and Freedom of Information, Baden-Württemberg)
Räpplenstrasse 2
70191 Stuttgart, Germany
(Postal address: Postfach 10 29 32, 70025 Stuttgart)
Phone: +49 711 615541-0
Email: poststelle@lfdi.bwl.de
Web: www.baden-wuerttemberg.datenschutz.de
You may also contact the supervisory authority of your habitual residence or place of work.
16. Obligation to provide data
In order to conclude a purchase contract, you must provide us with the data required to perform the contract — in particular your name, delivery and billing address and email address. Without this information we cannot enter into a contract with you. All other information is voluntary.
17. Changes to this privacy policy
We update this privacy policy when our offering, the services we use or the legal framework change. The version published here applies in each case. You will find the date of the current version at the top.
