Trust, Security & Privacy

This page is maintained by the Minikunstbieb team to answer common security and privacy questions about our website. It describes the controls and practices currently in place and is not an independent certification.

Accounts & authentication

Customer accounts are protected with email and password sign-in. Passwords are hashed by our authentication provider; we never see or store plain-text passwords. Administrative areas of the site are restricted to verified admin accounts and protected by server-side role checks.

Payments

Orders and payments are processed through our Shopify storefront. Card details and payment credentials are handled by Shopify and its PCI-compliant payment processors — they are never stored on Minikunstbieb's own servers.

Data we collect

We collect the information you give us to fulfil orders and respond to messages: name, email address, shipping address, order history, and any content you submit through the contact or newsletter forms. We also collect basic analytics about how the site is used (for example page views) to improve the shop.

How we use your data

Your data is used to process orders, ship products, answer your questions, and — if you subscribed — send our newsletter. We do not sell personal data to third parties. You can unsubscribe from the newsletter at any time using the link in every email.

Subprocessors & integrations

We rely on a small number of trusted providers to operate the shop, including Shopify (storefront, checkout and payments), our hosting and database provider, and our email delivery provider. Each provider only receives the data needed to perform its service.

Data retention & deletion

Order and invoice data is retained for the period required by applicable tax and bookkeeping law. You may request access to or deletion of your personal data at any time by contacting us — see below.

Cookies & analytics

The site uses functional cookies required for the shopping cart and authentication, and limited analytics to understand site usage. No cross-site advertising profiles are built from your visit.

Reporting a security issue

If you believe you have found a security or privacy issue, please contact us via the contact page. We aim to respond to security reports promptly.

This page describes current practices and may be updated as the shop evolves.