Privacy Policy

Privacy Policy

1. General Information

The protection of your personal data is important to us. We process personal data confidentially and in accordance with the applicable data protection laws, in particular the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), the German Telecommunications Digital Services Data Protection Act (TDDDG), and this Privacy Policy.

Personal data means any information relating to an identified or identifiable natural person. This includes, for example, names, email addresses, IP addresses, location data, user identifiers, and content that can be linked to a particular person.

This Privacy Policy explains which personal data is processed when you use the einkaufszentrum.com platform, for which purposes the data is processed, the legal bases on which the processing is carried out, and the rights available to you.

The platform is primarily intended for users, shopping centres, companies, and operators located in Germany.

Last updated: July 2026


2. Controller

The controller within the meaning of the General Data Protection Regulation is:

reDim GmbH
Nußallee 7 F
63450 Hanau
Germany

Email: info@einkaufszentrum.com

A Data Protection Officer has not been appointed because the statutory requirements for mandatory appointment are currently not met.


3. General Legal Bases

We process personal data in particular on the following legal bases:

  • Article 6(1)(a) GDPR, where you have given us your consent;

  • Article 6(1)(b) GDPR, where processing is necessary for the performance of a contract, a user relationship, or for taking steps prior to entering into a contract;

  • Article 6(1)(c) GDPR, where processing is necessary for compliance with a legal obligation;

  • Article 6(1)(f) GDPR, where processing is necessary for the purposes of our legitimate interests or those of a third party, provided that such interests are not overridden by your interests, fundamental rights, or freedoms.

Where information is stored on your device or accessed from your device, the lawfulness of such access is additionally governed by Section 25 TDDDG. Access that is not technically necessary only takes place with your consent in accordance with Section 25(1) TDDDG.


4. Recipients of Personal Data

Personal data is only disclosed to recipients where this is necessary to provide the platform, perform a contract, comply with legal obligations, or where disclosure is based on your consent.

Possible recipients include, in particular:

  • hosting and email service providers;

  • payment service providers;

  • analytics and advertising providers, where you have given your consent;

  • operators of shopping centres, where this is necessary to process a data correction request or a report;

  • technical service providers acting as processors;

  • courts, public authorities, legal advisers, or other bodies where disclosure is legally required or necessary for the establishment, exercise, or defence of legal claims.

We do not sell personal data.


5. Hosting

The platform is hosted on a root server administered by us and provided by IONOS SE. The server, database, and backup systems used by us are located in Germany.

The provider is:

IONOS SE
Elgendorfer Straße 57
56410 Montabaur
Germany

IONOS processes data as a processor in connection with the provision of the server infrastructure. Processing is carried out on the basis of a Data Processing Agreement pursuant to Article 28 GDPR.

The legal basis for using the hosting infrastructure is Article 6(1)(f) GDPR. Our legitimate interest lies in the secure, reliable, and efficient provision of the platform.

Access to the servers and the data stored on them is generally restricted to authorised employees of reDim GmbH and IONOS in connection with the contractually agreed technical services.


6. Server Log Files

Each time the platform is accessed, the server automatically processes technical access data. This may include:

  • IP address of the accessing device;

  • date and time of access;

  • page or file accessed;

  • amount of data transferred;

  • HTTP status code;

  • referring URL;

  • browser type and browser version;

  • operating system used;

  • hostname of the accessing device.

The data is processed for the technical provision of the platform, error analysis, ensuring system security, and detecting and preventing attacks and abusive access.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in providing a secure and stable online service.

Server log files are generally deleted after 90 days, unless a specific security incident, suspected misuse, or another legal reason requires longer retention.

Server log files are not combined with user profiles for advertising or analytics purposes.


7. Security and Login Logs

To protect user accounts and detect abusive access, we process security-related information. This may include:

  • the time of successful or failed login attempts;

  • the time of security-relevant account changes;

  • activation or deactivation of two-factor authentication;

  • security-related system events;

  • technical information used to detect abusive access.

Processing is carried out on the basis of Article 6(1)(f) GDPR. Our legitimate interest lies in protecting the platform, user accounts, and stored data against unauthorised access and misuse.

Security and login logs are generally stored for twelve months. In the event of a specific security incident, the relevant data may be stored until the incident has been fully resolved and, where applicable, for the duration of statutory limitation or retention periods.


8. Backups

Regular backups are created to ensure the availability and recoverability of the platform.

Data contained in backups is overwritten or deleted no later than after 14 days. The immediate targeted deletion of individual records from existing backups is generally not technically possible. However, deleted data will not be restored to the active system unless this is necessary to recover the system following a technical failure.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in ensuring the availability and integrity of the platform.


9. SSL and TLS Encryption

Our platform uses SSL or TLS encryption to protect transmitted data against access by unauthorised third parties.

You can recognise an encrypted connection, in particular, by the website address beginning with “https://” and the padlock symbol in your browser’s address bar.


10. Cookies and Similar Storage Technologies

Our platform uses cookies and similar technologies. Cookies are small files or units of information that can be stored on or accessed from your device.

Technically Necessary Technologies

Technically necessary cookies and storage technologies are used in particular for:

  • providing user sessions;

  • login and authentication;

  • protecting forms against abusive submissions;

  • storing language settings;

  • storing selected privacy settings;

  • two-factor authentication;

  • securely providing user accounts;

  • preventing cross-site request forgery attacks;

  • technical load distribution and error prevention.

These technologies are used on the basis of Section 25(2)(2) TDDDG where storage or access is strictly necessary. The subsequent processing of personal data is carried out, depending on the function, on the basis of Article 6(1)(b) or Article 6(1)(f) GDPR.

Technically necessary session information is generally deleted when the relevant browser session ends. Permanent settings are stored for as long as necessary for the relevant function or until deleted by you.

Analytics and Advertising Technologies

Analytics and advertising technologies are only used after you have expressly given your consent.

This applies in particular to:

  • Google Analytics;

  • Google Signals and demographic reports;

  • Google AdSense;

  • personalised advertising;

  • cookies and online identifiers connected with these services.

The legal basis is your consent pursuant to Article 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG.

Further information about the individual services, the data processed, the purposes, and the retention periods can be found in the relevant sections of this Privacy Policy.


11. Consent Management and Management of Your Choices

We use a self-developed consent management system. When you first visit the platform, you can decide whether you consent to the use of analytics and advertising services.

The options “Accept”, “Reject”, and the individual settings are provided in an equally accessible and user-friendly manner.

To document your decision, we process in particular:

  • a consent or settings identifier;

  • the date and time of the decision;

  • the scope of the consent granted or rejected;

  • the time of subsequent changes or withdrawal;

  • the version of the consent information applicable at the time of the decision;

  • the IP address, where necessary to demonstrate that valid consent was obtained.

The processing serves to demonstrate that consent was validly obtained or rejected in accordance with data protection law.

The legal bases are Article 6(1)(c) GDPR in conjunction with the accountability obligations under Articles 5(2) and 7(1) GDPR, as well as Article 6(1)(f) GDPR. Our legitimate interest lies in documenting lawful consent management and defending against potential legal claims.

Consent records are generally stored for up to three years after the last change to or withdrawal of the relevant consent.

You can review, change, or withdraw your choices at any time through the privacy or cookie settings provided on the platform.

Withdrawal applies with effect for the future and does not affect the lawfulness of processing carried out before the withdrawal.


12. Google Consent Mode

We use Google Consent Mode to control Google services in its basic, so-called “Basic” version.

Google tags for analytics and advertising services are only loaded after you have given the relevant consent through our consent management system. If you reject consent, these services are not activated.

Before consent is given, the relevant Google tags do not transmit analytics or advertising data to Google.


13. Registration and User Accounts

You may create a user account to use certain functions of the platform.

During registration, we process in particular:

  • name;

  • email address;

  • login credentials in encrypted or hashed form;

  • time of registration;

  • time of email verification;

  • account status;

  • time of the last login;

  • an optional billing address;

  • an optional profile picture;

  • selected settings and notification preferences.

The data is processed to create and manage the user account, provide personal functions, and perform the user agreement.

The legal basis is Article 6(1)(b) GDPR.

Mandatory information is required to provide a user account. Registration is not possible without this information. Information marked as optional is provided voluntarily.

Minimum Age

Registration of a user account is generally permitted from the age of 16.

Users under the age of 18 may only create and use a user account with the consent of their legal representatives. Operator accounts may only be created by adults or by companies and organisations represented by an authorised adult.

An automated identity or age verification process is generally not carried out. However, we reserve the right to request appropriate evidence where there are reasonable doubts.

Deletion and Inactivity

Users may delete their account through the function provided for this purpose.

A user account is also generally deleted if no login has taken place for a period of two years and there are no legal, contractual, or legitimate reasons for further storage.

Existing reviews are anonymised when the user account is deleted, unless there are legal reasons requiring complete deletion or continued attribution.

Billing and contractual data may continue to be stored after account deletion where statutory retention obligations apply.


14. Email Verification and Password Recovery

When you register, we send a welcome email containing a verification link. Users may also request an email to reset their password.

For these purposes, we process in particular:

  • email address;

  • time-limited verification or recovery token;

  • time of the request;

  • time of successful verification or password change.

The legal basis is Article 6(1)(b) GDPR. Security-related logging is additionally carried out on the basis of Article 6(1)(f) GDPR.

Verification and recovery tokens become invalid after the technically defined validity period and are subsequently deleted or overwritten.


15. Two-Factor Authentication

Users may protect their user account with two-factor authentication.

We process the technical authentication information necessary for setup and verification, as well as the status and time of activation or deactivation.

The processing is carried out to protect the user account on the basis of Article 6(1)(b) and Article 6(1)(f) GDPR.

When two-factor authentication is activated or deactivated, a notification email is sent for security reasons.


16. Operator Accounts and Claiming a Shopping Centre

Persons wishing to manage a shopping centre or location may apply for operator access.

In this context, we process in particular:

  • name;

  • email address;

  • the shopping centre or company being claimed;

  • confirmation that the applicant is the owner or authorised to represent the organisation;

  • time and status of the request;

  • communication relating to the verification;

  • where applicable, additional evidence of authorisation.

The processing is carried out to verify authorisation, prevent unauthorised takeovers, and create the operator account.

The legal bases are Article 6(1)(b) and Article 6(1)(f) GDPR. Our legitimate interest lies in granting administrative rights only to persons who are actually authorised.

We may request additional evidence in individual cases. Such evidence is generally submitted by email. Verification using publicly available information or personal contact only takes place where necessary. The person concerned will be informed accordingly during the communication.

Additional evidence of authorisation is deleted after completion of the verification process, but no later than six months after the final decision, unless a dispute, suspected misuse, or another legal reason requires longer storage.


17. Administrators, Editors, and Team Members

Operators may invite additional persons as administrators, editors, or team members and assign different permissions to them.

We process in particular:

  • name;

  • email address;

  • assigned operator account;

  • assigned role and permissions;

  • person issuing the invitation;

  • time of invitation;

  • time of acceptance;

  • changes to roles and permissions.

The processing is carried out to provide team and permission management functions on the basis of Article 6(1)(b) GDPR.

Invitations, role changes, and comparable permission changes are logged for two years. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in ensuring that security-relevant permission changes can be traced and that potential misuse can be investigated.

We do not maintain a comprehensive permanent log of every content change made by individual team members.


18. Favourites

Registered users can save shopping centres or other available content as favourites.

The user account records which content has been selected as a favourite. This data is used solely to provide the personal favourites function.

The legal basis is Article 6(1)(b) GDPR.

Favourites are deleted when removed by the user or when the relevant user account is deleted.

Operators do not receive personal information about which individual users have saved a shopping centre or content item as a favourite. Any statistics made available are aggregated and cannot be linked to individual users.


19. Saved Coupons

Registered users can save coupons in their user account.

The following information is stored:

  • the user account to which the coupon is assigned;

  • the coupon that was saved;

  • the time it was saved;

  • where applicable, information required for an expiry notification.

The processing is carried out to provide the saving and reminder functions on the basis of Article 6(1)(b) GDPR.

We do not record or analyse the actual redemption of a coupon on a personal basis. We also do not create personal usage or interest profiles based on saved coupons.

Operators only receive aggregated statistics. Operators cannot link saved coupons to individual users.

Saved coupons are deleted when the user removes them, the user account is deleted, or storage is no longer necessary for the relevant function.

Optional reminders that a coupon is about to expire can be disabled in the account settings.


20. Reviews

Registered users may submit reviews of shopping centres or companies displayed on the platform.

The following data may be processed:

  • user account;

  • public username or selection of the “anonymous” option;

  • star rating;

  • review text;

  • date and time;

  • moderation and approval status;

  • where applicable, a response from the operator;

  • communication relating to a report or moderation process.

Users can choose whether the review is published under their username or anonymously.

For non-anonymous reviews, the selected username is publicly visible. The user’s email address is not published and is not shown to the reviewed operator.

Operators may respond to reviews and report reviews for examination. They generally do not receive any further information about the reviewer beyond the information already displayed publicly with the review.

The processing is carried out to provide the review function and perform the user agreement on the basis of Article 6(1)(b) GDPR. Moderation, security, and misuse checks are additionally carried out on the basis of Article 6(1)(f) GDPR.

Users may be informed by email about the status of their review, an operator response, or deletion of the review. Non-essential notifications can be disabled in the account settings.

When the user account is deleted, existing reviews are generally anonymised, unless legal reasons require complete deletion or continued attribution.


21. Contacting Us

If you contact us by contact form or email, we process the information you provide.

This may include:

  • name;

  • email address;

  • optional telephone number;

  • subject;

  • message;

  • time of contact.

The information is used solely to process your enquiry and any follow-up questions.

Where the enquiry concerns the conclusion or performance of a contract, processing is carried out on the basis of Article 6(1)(b) GDPR. In all other cases, processing is carried out on the basis of Article 6(1)(f) GDPR. Our legitimate interest lies in processing incoming enquiries appropriately and efficiently.

Contact enquiries are not additionally stored permanently in a platform database. However, they are received and processed through our email accounts hosted by IONOS.

Messages are deleted after the enquiry has been fully processed, unless contractual, legal, or legitimate reasons require further storage. General contact enquiries are generally deleted no later than twelve months after completion of the processing.

An automatic confirmation of receipt may be sent to the email address provided after a contact form has been submitted.


22. Requests Relating to Data Subject Rights

If you request access, rectification, deletion, restriction, or data portability, we process the information required to handle the request and verify your identity.

This may include:

  • name;

  • email address;

  • content and scope of the request;

  • verification token;

  • time of submission and verification;

  • communication and outcome of the request.

To prevent unauthorised disclosure or deletion of data, we may send a verification email.

The processing is carried out to comply with our legal obligations on the basis of Article 6(1)(c) GDPR in conjunction with Articles 12 to 22 GDPR.

After successful verification, we may provide a data export and notify the user by email when it is ready. Temporarily available export files are deleted after the applicable availability period expires.

Documentation of a completed request is only stored for as long as necessary to demonstrate proper handling of the request or to establish, exercise, or defend legal claims.


23. Reporting Incorrect Data and Submitting Corrections

Users may report incorrect or outdated information relating to shopping centres, shops, or other platform content.

We process the information entered in the relevant form, in particular:

  • description of the incorrect information;

  • proposed correction;

  • voluntarily provided contact details, where applicable;

  • date and time of the report;

  • reference to the affected shopping centre or content.

The report is processed by reDim GmbH. If a responsible operator is available for the relevant shopping centre, the information provided, including any voluntarily supplied contact details, may be forwarded to that operator where necessary to examine and correct the information.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in ensuring that information published on the platform is correct and up to date.

The data is deleted after the correction process has been completed, unless legal or factual reasons require further storage.


24. Reporting Abusive or Unlawful Content

Users may report content that may violate laws, third-party rights, our Terms and Conditions, or other platform rules.

We process in particular:

  • email address of the reporting person;

  • content and reasons for the report;

  • affected content or URL;

  • date and time of the report;

  • communication and outcome of the examination.

The email address of the reporting person generally remains exclusively with reDim GmbH.

Where an operator is responsible for the affected content, the description of the report required for examination may be forwarded to that operator. The reporting person’s email address is generally not disclosed to the operator.

Processing is carried out on the basis of Article 6(1)(c) GDPR where statutory examination and action obligations apply, and Article 6(1)(f) GDPR. Our legitimate interest lies in maintaining a secure and lawful platform and preventing legal violations and misuse.

The retention period depends on the nature, scope, and legal significance of the report. The data is deleted as soon as it is no longer required to examine the report, implement necessary measures, and document the process, and provided that no legal obligations or potential legal claims require further storage.


25. Content and Files Published by Operators

Operators may publish the following content within the scope of their permissions:

  • text and news;

  • events;

  • promotions and offers;

  • opening hours;

  • images and logos;

  • files in JPG, JPEG, PNG, and WebP formats;

  • PDF documents;

  • other content permitted on the platform.

Content is generally published immediately. We do not conduct a general manual review of all content before publication.

We technically process the content in order to:

  • store it;

  • make it publicly accessible;

  • adapt it to different screen sizes;

  • compress it or convert it into suitable technical formats;

  • create preview images;

  • back it up;

  • examine it in connection with reports;

  • block or remove it in the event of legal violations.

When images are uploaded, existing image metadata, in particular EXIF and GPS information, is technically removed.

The legal basis for technical processing is Article 6(1)(b) GDPR where processing is necessary to perform the contract with the operator. Security, moderation, and misuse checks are additionally carried out on the basis of Article 6(1)(f) GDPR.

Responsibility of Operators

The relevant operator is responsible for ensuring that the content it uploads is lawful and that it holds all rights and data protection permissions required for publication.

This applies in particular to personal data, names, images, contact details, documents, and information relating to employees, contact persons, artists, event participants, customers, or other persons.

Operators may only upload or publish personal data relating to third parties where an appropriate legal basis exists and the affected persons have been properly informed.

reDim GmbH is not required to generally monitor all content uploaded by users before publication or actively search for unlawful circumstances.

If we become aware of potentially unlawful content or there are specific indications of a violation, we will examine the relevant content and block or remove it where legally required.

For processing activities initiated by an operator through the independent selection and publication of personal content, the relevant operator may be independently responsible under data protection law.


26. Storage of Operator Content After Contract Termination

Time-limited or operator-created content, in particular events, promotions, and similar publications, is deleted after termination of the contract or after it is no longer relevant, unless legal or legitimate reasons require further storage.

Generally accessible information about a shopping centre, company, or location may remain available after the termination of an operator agreement where the information remains publicly accessible, factually correct, and relevant to the informational purpose of the platform.

Personal data is only processed further where an independent legal basis exists.


27. Information From Publicly Available Sources

We provide information about shopping centres, companies, shops, and comparable locations on our platform.

This information may originate from publicly available sources, in particular:

  • official websites of the relevant shopping centres or companies;

  • publicly available company profiles;

  • publicly published contact information;

  • publicly accessible business or location directories;

  • information provided by operators or users.

We do not use automated scraping processes for the continuous collection of personal data.

The information processed may include:

  • name and address of a shopping centre or company;

  • publicly listed telephone numbers;

  • general business email addresses;

  • opening hours;

  • website addresses;

  • publicly listed social media profiles;

  • contact persons publicly identified as contacts for the relevant shopping centre;

  • personal business email addresses where they have demonstrably been published as contact addresses for the relevant shopping centre.

We do not obtain or publish internal, non-public contact details or contact persons.

The information is processed for the purpose of providing a comprehensive and up-to-date directory of shopping centres and associated companies.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in providing accurate and publicly available location and company information.

The information is displayed publicly on the platform. It is updated or deleted where it is no longer current, the underlying source no longer exists, a data subject validly objects, or there is no sufficient legal basis for continued processing.

Data subjects may object to the processing on grounds relating to their particular situation in accordance with Article 21 GDPR. Please contact info@einkaufszentrum.com for this purpose.


28. Location Detection and Nearby Search

You may use your browser’s location function to display shopping centres near you.

Location detection only takes place when you actively use the relevant function and confirm location access in your browser or operating system.

The location provided by your device is transmitted to our server in order to calculate distances to shopping centres and display suitable results.

The location is:

  • used only for the relevant search request;

  • not stored permanently;

  • not linked to a user account;

  • not used to create a movement or interest profile.

The legal basis is your consent pursuant to Article 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG.

You may withdraw or disable location access at any time through the settings of your browser or operating system.


29. OpenStreetMap

We use map material from the OpenStreetMap project to display maps. The maps are integrated through a proxy server operated by us.

Your browser does not establish a direct connection to OpenStreetMap servers. OpenStreetMap therefore does not receive the IP address of your device, but only the IP address of our server.

Depending on the selected map section, technical map or coordinate information may be transmitted by our server to the map infrastructure. This information is not transmitted to OpenStreetMap together with your IP address or user account.

The maps are integrated for the user-friendly presentation of locations on the basis of Article 6(1)(f) GDPR. Our legitimate interest lies in providing a clear geographical presentation of the shopping centres and companies listed on the platform.

Further information about the OpenStreetMap project and data protection can be found in the privacy information of the OpenStreetMap Foundation.


30. Route Planning Using Google Maps

Google Maps is not directly embedded into our platform for the “Plan route” function. You are only redirected to Google Maps after actively clicking the relevant link.

From that point onward, Google processes data under its own responsibility under data protection law. This may include your IP address, device information, selected destination, and, depending on your Google and device settings, your current location.

The provider for users in the European Economic Area is generally:

Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland

Further information can be found in Google’s privacy information.


31. Static Social Media and Sharing Links

Our platform may include static links or sharing buttons to social networks, in particular:

  • Facebook;

  • Instagram;

  • LinkedIn;

  • X;

  • YouTube;

  • TikTok.

Sharing buttons provided by us are available in particular for Facebook, LinkedIn, and X.

The buttons are embedded as ordinary links. No connection to the relevant social network is established merely by visiting our platform.

Only when you click such a link are you redirected to the relevant platform. The provider may then process your IP address, device information, the previously visited page, and other data. If you are logged in to the relevant provider, the visit may be linked to your user account.

Further processing is carried out under the responsibility of the relevant platform operator and is governed by that provider’s privacy information.


32. Local Protection Against Automated Form Submissions

To protect our forms against automated and abusive submissions, we use a locally operated protection solution based on ALTCHA.

The verification is carried out on our own infrastructure. No data is transmitted to an external CAPTCHA provider.

Technical verification values are only processed temporarily to the extent necessary to validate the relevant request. No permanent personal storage takes place for this function.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in protecting our forms and systems against spam, automated attacks, and abusive use.


33. Google Analytics

Where you have given your consent, we use Google Analytics 4, a web analytics service provided by:

Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland

Google Analytics enables us to statistically evaluate the use of our platform.

The following data may be processed:

  • pages visited and functions accessed;

  • time and duration of a visit;

  • interactions and technical events;

  • referring URL;

  • browser and device information;

  • operating system;

  • screen resolution;

  • language setting;

  • approximate geographical location;

  • online identifiers and cookie identifiers;

  • randomly generated pseudonymous user identifier;

  • for logged-in users, a randomly generated pseudonymous User ID.

We do not transmit names, email addresses, or other directly identifying account information to Google as a User ID.

Google Analytics uses the IP address during data collection to determine an approximate location. According to Google, IP addresses of users from the European Union are not logged or stored, but are discarded before permanent storage.

Purpose of Processing

The processing is carried out in particular to:

  • statistically evaluate the use of the platform;

  • measure reach and page views;

  • identify technical and content-related opportunities for improvement;

  • assess the effectiveness of campaigns;

  • create aggregated reports about platform usage.

User ID

For logged-in users, a randomly generated pseudonymous User ID may be used to combine sessions within Google Analytics.

The User ID does not contain the user’s name, email address, or other directly identifying information. Google cannot identify a specific user solely on the basis of the identifier transmitted.

Google Signals and Demographic Reports

We have enabled Google Signals. This allows Google Analytics to provide additional aggregated information for users who are logged in to their Google account and have enabled personalised advertising in their Google account.

This may include:

  • approximate age groups;

  • gender;

  • interests;

  • cross-device usage.

We only receive this information in aggregated form. Google applies data thresholds intended to prevent conclusions being drawn about individual users.

Advertising personalisation is disabled in our Google Analytics settings. However, Google Analytics is linked to our Google Ads account where this has been configured for campaign and performance measurement.

Legal Basis

Google Analytics is only used after you have expressly given your consent.

The legal basis is Article 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG.

You may withdraw your consent at any time through our privacy settings.

Retention Period

The retention period for user and event data in Google Analytics is set to 14 months.

Standard aggregated reports provided by Google may not be fully covered by this setting for technical reasons. Any further storage and processing by Google is additionally governed by Google’s privacy and retention policies.

Data Processing and International Transfers

Where Google processes data on our behalf, the applicable data processing terms agreed with Google apply.

Google may also process data outside the European Union and the European Economic Area, in particular in the United States.

According to its own information, Google LLC is certified under the EU-U.S. Data Privacy Framework. Standard Contractual Clauses approved by the European Commission may also be used.

Further information can be found in Google’s privacy information and information about international data transfers.


34. Google AdSense

Where you have given your consent, we use Google AdSense to display advertisements.

The provider is:

Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland

We use automatic and personalised advertisements.

Personalised advertisements may be selected on the basis of previously collected or historical information. This may include previous searches, visits to websites or apps, approximate location information, interests, and demographic characteristics.

Google AdSense may process in particular:

  • IP address;

  • browser and device information;

  • operating system;

  • page accessed;

  • time of access;

  • advertisement displayed;

  • interactions with advertisements;

  • online identifiers;

  • cookie identifiers;

  • approximate location information;

  • information relating to advertising frequency;

  • information used to detect invalid or fraudulent access.

Google may use cookies and similar technologies to recognise browsers, select advertisements, limit the frequency of advertisements, measure advertising performance, and prevent misuse.

Depending on the user’s settings and Google account, information may be linked to an existing Google account.

Legal Basis

Google AdSense and personalised advertising are only activated after you have expressly given your consent.

The legal basis is Article 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG.

If consent is rejected or withdrawn, the relevant advertising and tracking technologies are not activated or are disabled for future page views.

You may withdraw your consent at any time through our privacy settings.

Consent Management

Consent is obtained through our consent management system. The technical standards of the IAB Europe Transparency and Consent Framework may be used to transmit the consent decision to Google and participating advertising partners.

International Data Transfers

Google may process personal data outside the European Union and the European Economic Area, in particular in the United States.

According to its own information, Google LLC is certified under the EU-U.S. Data Privacy Framework. Standard Contractual Clauses approved by the European Commission may also be used.

Further information about the processing of personal data and the use of cookies for advertising can be found in Google’s privacy and advertising information.


35. Paid Services and Billing Data

Certain services and operator packages may be booked for a fee.

As part of the booking and contractual process, we process in particular:

  • name and company;

  • email address;

  • billing address;

  • selected package or service;

  • contract start date and contract status;

  • invoice amount and currency;

  • payment status;

  • transaction or reference number;

  • selected payment method;

  • communication relating to payment and contract processing.

The processing is carried out for the performance of the contract and billing purposes on the basis of Article 6(1)(b) GDPR.

Where we are required to retain invoices and accounting documents under tax or commercial law, further storage is carried out on the basis of Article 6(1)(c) GDPR.

Invoice and accounting data is stored for the applicable statutory retention period.


36. Stripe

We use Stripe Checkout for certain payments.

The provider for customers in the European Economic Area is generally:

Stripe Payments Europe, Limited
1 Grand Canal Street Lower
Grand Canal Dock
Dublin
D02 H210
Ireland

If you select Stripe as your payment method, the Stripe Checkout process opens in a correspondingly labelled window or payment area.

Payment information required for the transaction is entered directly with Stripe and processed by Stripe. We do not receive complete credit card, bank account, or login information.

We only receive the information necessary for contractual and payment processing, in particular:

  • payment status;

  • payment amount;

  • currency;

  • transaction or reference number;

  • time of payment;

  • where applicable, the type of payment method used;

  • information about refunds or failed payments.

The transfer of data to Stripe is necessary to process the selected payment transaction.

The legal basis is Article 6(1)(b) GDPR.

Stripe processes certain data as an independent controller, in particular for payment processing, compliance with legal obligations, and fraud and misuse prevention.

Stripe may process data outside the European Union and the European Economic Area. Stripe uses the safeguards described in its privacy information, in particular adequacy decisions and Standard Contractual Clauses.

Further information can be found in Stripe’s Privacy Policy.


37. PayPal

We offer PayPal Checkout for certain payments.

The provider is:

PayPal (Europe) S.à r.l. et Cie, S.C.A.
22–24 Boulevard Royal
L-2449 Luxembourg

If you select PayPal as your payment method, the correspondingly labelled PayPal Checkout process opens.

PayPal login details, payment information, and any credit card data required for the transaction are processed directly by PayPal. We do not receive complete PayPal login details, credit card information, or bank account information.

We only receive the information necessary for contractual and payment processing, in particular:

  • payment status;

  • payment amount;

  • currency;

  • transaction or reference number;

  • time of payment;

  • where applicable, the type of payment method;

  • information about refunds or failed payments.

The data is transmitted for the purpose of carrying out the payment transaction on the basis of Article 6(1)(b) GDPR.

PayPal processes personal data in connection with payment processing as an independent controller. This includes payment execution, compliance with legal obligations, and fraud and misuse prevention.

PayPal may process data outside the European Union and the European Economic Area as part of its international corporate structure. The safeguards described in PayPal’s privacy information apply to such transfers.

Further information can be found in PayPal’s Privacy Statement.


38. Automated Emails and Notifications

We send automated emails in order to provide and secure the platform.

Required Notifications

Emails required for account, security, contractual, or legal purposes include in particular:

  • welcome and verification emails;

  • password reset emails;

  • security-related notifications;

  • activation or deactivation of two-factor authentication;

  • team invitations;

  • security-relevant role and permission changes;

  • notifications relating to operator and shopping centre claims;

  • notifications relating to contract, package, and payment changes;

  • verification of data protection requests;

  • provision of a data export;

  • confirmation of account deletion;

  • necessary notifications relating to reviews or moderation decisions.

These emails are necessary for the relevant function and cannot be completely disabled.

Depending on the content, the legal bases are Article 6(1)(b), Article 6(1)(c), or Article 6(1)(f) GDPR.

Optional Notifications

Optional informational and convenience notifications may include:

  • reminders that saved coupons are about to expire;

  • non-security-related status information;

  • other informational messages selected by the user.

These notifications can be disabled in the account settings.

Depending on the function, processing is carried out on the basis of Article 6(1)(b) GDPR or your voluntary selection pursuant to Article 6(1)(a) GDPR.

We do not use email opening or click tracking.


39. Email Delivery

Emails are sent through our own email accounts hosted by IONOS.

IONOS processes the data required for delivery as a processor. This may include email addresses, sender and recipient information, timestamps, and the content of the relevant message.

The legal basis depends on the purpose of the relevant message and is described in the corresponding sections of this Privacy Policy.

We do not use a newsletter service or an external marketing email provider.


40. No Automated Decision-Making

We do not make decisions that produce legal effects concerning you or similarly significantly affect you solely on the basis of automated processing within the meaning of Article 22 GDPR.

Automated systems may only be used to provide technical support, security checks, filtering, or structuring of processes. Decisions concerning account suspensions, operator approvals, or comparable significant measures are not made solely by automated means.

Processing carried out by Google in connection with personalised advertising is described in the section concerning Google AdSense.


41. Transfers to Third Countries

Some of the service providers used by us may process personal data outside the European Union and the European Economic Area.

This applies in particular to Google and potentially to international processing by Stripe and PayPal.

Data is only transferred where the requirements of Articles 44 et seq. GDPR are met.

Appropriate safeguards may include:

  • an adequacy decision of the European Commission;

  • participation of a U.S. company in the EU-U.S. Data Privacy Framework;

  • Standard Contractual Clauses approved by the European Commission;

  • supplementary technical and organisational safeguards.

For Google services requiring consent, data is only transferred after you have consented to the relevant service.

Despite the available safeguards, it cannot always be completely ruled out that public authorities in third countries may access data within the scope of their statutory powers.


42. Retention Period

Unless a specific retention period is stated in this Privacy Policy, we store personal data only for as long as necessary for the relevant purpose.

The data is subsequently deleted unless statutory retention obligations, potential legal claims, security reasons, or other lawful grounds require continued storage.

The relevant criteria include in particular:

  • duration of the user or contractual relationship;

  • time of the last login;

  • completion of an enquiry or report;

  • expiry of statutory retention periods;

  • duration of potential limitation periods;

  • necessity of investigating a security or misuse incident;

  • withdrawal of consent;

  • a valid objection to processing.


43. Your Rights

Subject to the applicable statutory requirements, you have the following rights:

Right of Access

Under Article 15 GDPR, you may request information as to whether and which personal data we process about you.

Right to Rectification

Under Article 16 GDPR, you may request the correction of inaccurate data and the completion of incomplete data.

Right to Erasure

Under Article 17 GDPR, you may request the deletion of your personal data where there are no legal grounds for continued processing.

Right to Restriction of Processing

Under Article 18 GDPR, you may request the restriction of processing subject to the statutory requirements.

Right to Data Portability

Under Article 20 GDPR, you may request that the data you have provided be made available to you in a structured, commonly used, and machine-readable format or transmitted to another controller.

Right to Object

Under Article 21 GDPR, you have the right to object at any time, on grounds relating to your particular situation, to processing based on Article 6(1)(e) or Article 6(1)(f) GDPR.

Where we process personal data for direct marketing purposes, you may object to such processing at any time without stating particular grounds.

Right to Withdraw Consent

Under Article 7(3) GDPR, you may withdraw consent at any time with effect for the future.

Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority concerning the processing of your personal data.

The supervisory authority responsible for us is:

The Hessian Commissioner for Data Protection and Freedom of Information
Wilhelmstraße 7
65185 Wiesbaden
Germany

Postal address:
Postfach 3163
65021 Wiesbaden
Germany

Telephone: +49 611 1408-0
Email: poststelle@datenschutz.hessen.de

Alternatively, you may contact the data protection supervisory authority responsible for your habitual residence or place of work.


44. Exercising Your Rights

To exercise your data protection rights, please contact:

reDim GmbH
Nußallee 7 F
63450 Hanau
Germany

Email: info@einkaufszentrum.com

To protect your data, we may request additional information where there are reasonable doubts concerning your identity.


45. Amendments to This Privacy Policy

We reserve the right to amend this Privacy Policy where legal requirements, the technical design of the platform, or the services used by us change.

The version currently published on the platform applies.