Privacy Policy

Last updated: August 2026

Introduction and general information

Thank you for your interest in our website. Protecting your personal data is very important to us. Below you will find information about how we handle data collected when you use our website. We process personal data exclusively in accordance with applicable data protection laws, in particular the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). Personal data means any information relating to an identified or identifiable natural person, for example name, email address, postal address, or technical access data.

The controller responsible for data processing on this website within the meaning of the GDPR is Titanova GbR, represented by Gheddiseh Zarvandi, Adam-Opel-Straße 26A, 63322 Rödermark, Germany, Tel.: +4915567290035, Email: gheddisehzar@gmail.com. The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.

No data protection officer has been appointed for our company, as there is no legal obligation to do so.

Server log files

When you visit our website, it is technically necessary for data to be transmitted from your internet browser to our web server. The following data may be recorded during an active connection between your browser and our web server:

  • IP addresses
  • Date and time of access
  • Browser and operating system used
  • Amount of data transferred
  • Page or resource accessed
  • Referrer (the source from which you reached the page)

We collect the listed data to ensure a smooth connection to the website and the technically error-free provision of our services. Processing this data is strictly necessary to make the website available to you. The log files are used to evaluate system security and stability and for administrative purposes. The legal basis for processing is our legitimate interest in protecting and maintaining the functionality of our website pursuant to Art. 6(1)(f) GDPR.

Web hosting

Our website is provided via Cloudflare Pages by Cloudflare.

Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA

Personal data collected on this website is stored on the host’s servers. Cloudflare processes data to provide our website securely, reliably, and efficiently. In particular, processing serves the delivery of website content, technical functionality and stability, and protection against abusive access and security threats.

Cloudflare operates a globally distributed network. As a result, personal data may also be processed outside the European Union or the European Economic Area, in particular in the USA. According to Cloudflare, it provides appropriate data protection safeguards and contractual arrangements for international transfers. Cloudflare also provides a Data Processing Addendum (DPA).

Further information on Cloudflare’s processing of personal data is available in Cloudflare’s privacy policy: https://www.cloudflare.com/privacypolicy/

Cookies

Our website uses so-called “cookies” and similar technologies. Cookies are small text files that are stored on your device either temporarily for the duration of a session (session cookies) or permanently (persistent cookies). Session cookies are deleted automatically when your visit ends. Persistent cookies remain on your device until you delete them yourself or your browser deletes them automatically.

Cookies serve various functions. Many cookies are technically necessary because certain website functions would not work without them (e.g. the shopping cart or language settings). Other cookies are used to analyse user behaviour or display advertising.

Processing of data through strictly necessary cookies is based on our legitimate interest pursuant to Art. 6(1)(f) GDPR in providing our services in a technically error-free manner. Details of processing purposes and legitimate interests are set out in the descriptions of the specific processing activities.

Processing of personal data through other cookies is based on consent pursuant to Art. 6(1)(a) GDPR. Consent may be withdrawn at any time with effect for the future. Where such cookies are used for analysis and optimisation, we will inform you separately in this privacy policy and obtain consent pursuant to Art. 6(1)(a) GDPR.

Payment processing via Stripe

For processing payments and subscriptions on our website we use the payment service provider Stripe:

Stripe Technology Company Limited (STC), One Wilton Park, Wilton Place, Dublin 2, D02 FX04, Ireland

If you place an order or make a payment via our website, the data required for payment processing is transmitted to Stripe. In particular, the following data may be processed:

  • Name
  • Email address
  • Billing and shipping address
  • Payment information
  • Payment method used
  • Transaction amount
  • Transaction date
  • Order information
  • IP address

Actual payment data, such as credit card details, is processed by Stripe. Based on the current technical setup of our website, full payment card data is not stored in our own database.

This data is processed in particular to carry out and settle payments, to prevent and detect fraudulent transactions, and to ensure the security of payment transactions.

Where processing is necessary for the performance of a contract or pre-contractual measures, it is based on Art. 6(1)(b) GDPR. Where processing serves fraud prevention and security, it may be based on Art. 6(1)(f) GDPR.

Using Stripe may involve transfers of personal data to countries outside the European Union or the European Economic Area. According to Stripe, it uses among other things Standard Contractual Clauses approved by the European Commission and, where applicable, participates in the EU-U.S. Data Privacy Framework.

Further information on Stripe’s processing of personal data is available in Stripe’s privacy policy: https://stripe.com/privacy

Payment methods and payment providers

PayPal

We offer payment via PayPal on our website. The provider is:

PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg

If you select PayPal as your payment method, the data required for payment processing is transmitted to and/or processed by PayPal. This may include in particular name, address, and transaction data (including bank and card information, currency, and transaction number). Processing takes place for the purpose of handling the payment and performing the contract. The legal basis is Art. 6(1)(b) GDPR. Where processing serves fraud prevention, security, or compliance with legal obligations, additional legal bases may apply. PayPal is offered as part of payment processing via Stripe.

Apple Pay

We offer Apple Pay as a payment method on our website. Apple Pay is a payment service of Apple. The provider is:

Apple Distribution International Limited, Hollyhill Industrial Estate, Cork, Ireland

If you select Apple Pay, payment is processed via Apple Pay and our payment service provider Stripe.

Apple Pay does not use your actual credit or debit card number for payment processing. Instead, a device-specific Device Account Number is used together with a dynamic security code generated for the transaction. The actual card number is not transmitted to us as the merchant by Apple or by the device used.

For website payments, Apple receives encrypted transaction information and re-encrypts it with a merchant- or developer-specific key before the information is transmitted to the merchant or involved payment service provider. This is intended to ensure that encrypted payment information can only be processed by the intended recipient.

Where necessary to fulfil and process the order, information released by the customer — for example name, billing or shipping address, and contact details — may be transmitted to the merchant. This information is made available only after payment authorisation according to the relevant Apple Pay configuration.

Apple states that for payments with credit, debit, or prepaid cards it does not retain transaction information that can be personally linked to the user. Apple may, however, process anonymised transaction information — for example approximate purchase amount and the time and successful completion of the transaction — to improve Apple Pay and other services.

Processing of personal data required for payment processing takes place for the purpose of carrying out the payment and performing the contract on the basis of Art. 6(1)(b) GDPR.

Further information on Apple’s processing of personal data and Apple Pay privacy and security measures is available here: https://support.apple.com/en-us/101554

Google Pay

We offer Google Pay as a payment method on our website. Google Pay is a payment service of Google. The provider is:

Google Ireland Limited, Gordon House, Barrow Street 4, Dublin, Ireland

If you select Google Pay, payment is processed via Google Pay and our payment service provider Stripe.

When paying with Google Pay, the payment information required for processing is transmitted as a signed and encrypted payment token. This token is forwarded to the payment service provider used for payment processing and processed there to carry out the payment. Google Pay supports both card information and tokenised card data.

For supported cards, a virtual or tokenised card number may be used instead of the actual card number, so that the actual card number does not need to be transmitted directly to the merchant. Google states that it encrypts payment information in transit and uses security mechanisms to protect against unauthorised access and fraudulent payments.

Depending on the card used and the specific Google Pay configuration, information about the payment method used, the card network, and tokenised payment information may be transmitted for payment processing. Where required for the order and provided by the user, contact, billing, or shipping information may also be processed.

In connection with Google Pay, Google may also process transaction data, in particular to carry out payments, provide transaction information and history, resolve payment issues, and provide Google Pay features.

Processing of personal data required for payment processing takes place for the purpose of carrying out the payment and performing the contract on the basis of Art. 6(1)(b) GDPR.

Further information on Google Pay’s processing of personal data and privacy is available here: Google Pay Privacy Notice

Card payments

We offer payment by credit and debit card on our website. Payment processing is handled by our payment service provider Stripe.

If you select card payment, the data required to carry out the payment is processed by Stripe. This may include in particular name, email address, billing and, where applicable, shipping address, details of the payment method used, transaction amount, date and status of the payment, and other information required for payment processing. Full card details are not stored by us, but are processed by Stripe.

Processing of personal data required for payment processing takes place for the purpose of carrying out the payment and performing the contract on the basis of Art. 6(1)(b) GDPR.

Supabase

For the technical storage of customer, order, and subscription information we use the service provider Supabase:

Supabase Pte. Ltd., 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513

Processing takes place in particular to technically provide our online shop, to process and manage orders, and to securely store the data required for these purposes.

Our Supabase project is operated in the EU region Frankfurt (Germany) (eu-central-1). As a result, data processed via Supabase is generally stored and processed within the European Union.

Supabase also provides a Data Processing Addendum (DPA) containing rules on the processing of personal data and addressing the requirements of the GDPR in particular.

Payment card information is not stored in our Supabase database, but is processed by the payment service provider Stripe.

Further information on privacy and Supabase’s processing of personal data is available here: https://supabase.com/privacy

External links

Social networks (Instagram and TikTok) are embedded on our website only as links to the respective services. After clicking the embedded text/image link, you are redirected to the provider’s website. Only after redirection is user information transmitted to the respective provider. For information on how those websites handle your personal data, please refer to the privacy policies of the providers you use.

Transactional emails via Resend

For sending transactional emails — in particular order confirmations, payment or order information, and other messages directly related to the use of our online shop — we use the email service Resend.

The provider is: Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA

When we send you a transactional email, the personal data required for sending is transmitted to and processed by Resend. This includes in particular your email address, technical email metadata, and the content of the respective message. Depending on the email content, further personal data may be included, for example your name and information about your order.

Processing takes place so that we can reliably deliver the emails required to perform and settle your order or a contract with us.

Where the email is necessary for the performance of a contract or pre-contractual measures, processing is based on Art. 6(1)(b) GDPR.

According to Resend, it processes and stores customer data in the USA. According to Resend, it is certified under the EU-U.S. Data Privacy Framework. In addition, Resend’s Data Processing Addendum (DPA) includes the Standard Contractual Clauses adopted by the European Commission for relevant international transfers.

Resend processes personal data as a processor in the course of providing the email service.

Further information on Resend’s processing of personal data is available here: https://resend.com/legal/privacy-policy

Contact

If you contact us by email or via the contact form, we process the information you provide in order to handle your enquiry.

This may include in particular:

  • Name
  • Email address
  • Content of your message
  • Any other information you voluntarily provide

The legal basis is Art. 6(1)(b) GDPR if your enquiry relates to an existing or prospective contractual relationship.

For other enquiries, processing is based on our legitimate interest in handling enquiries pursuant to Art. 6(1)(f) GDPR.

Data entered via the contact form is not stored in our own database.

To send contact enquiries we use the email service Resend. The data you enter is transmitted via our website to Resend and from there forwarded to our email inbox. Resend processes the data as a technical service provider for email delivery. We retain personal data collected in connection with your enquiry only for as long as necessary to handle your request. After communication has ended, the data is deleted unless legal provisions require longer retention.

Electronic withdrawal function

If you use the electronic withdrawal function provided on our website, we process the personal data you enter in order to receive, assign and handle your withdrawal declaration.

In particular, the following data may be processed:

  • Name
  • Email address
  • Order or contract reference
  • Information about the relevant contract or order
  • Where applicable, any message text you enter
  • Date and time of submission

This data is processed to fulfil our legal obligations and to carry out and document the withdrawal.

To transmit the withdrawal declaration and send the electronic confirmation of receipt, we use our email service provider Resend, which is already described in this privacy policy. The data is processed only to the extent necessary for sending and handling the withdrawal declaration.

Data entered via the withdrawal function is not additionally stored in Supabase or in a separate withdrawal database.

The data is processed or retained only for as long as necessary to handle the withdrawal and to comply with statutory evidence and retention obligations.

Local storage

Our website uses your browser’s local storage (“Local Storage”) to store certain technically necessary or user-selected settings locally on your device.

Based on our current technical setup, this concerns in particular:

  • Shopping cart: Cart contents or state may be stored locally so that your selection is preserved while you navigate the website.
  • Language setting: The selected language may be stored locally so that the website can be displayed accordingly on later visits.

This information is used to provide the website functions you request.

Where access to local storage is technically necessary for a service you expressly request, it takes place in accordance with applicable legal requirements.

Retention period

The retention period for personal data is based on applicable statutory retention periods (e.g. under commercial and tax law). After the relevant period expires, the corresponding data is routinely deleted. Where data is required for contract performance or initiation, or where we have a legitimate interest in continued storage, the data is deleted when it is no longer required for those purposes or when you exercise your right of withdrawal or objection.

Your rights

Subject to statutory requirements, you have in particular the following rights:

  • Access to the processing of your personal data pursuant to Art. 15 GDPR
  • Rectification of inaccurate data pursuant to Art. 16 GDPR
  • Erasure of your data pursuant to Art. 17 GDPR
  • Restriction of processing pursuant to Art. 18 GDPR
  • Data portability pursuant to Art. 20 GDPR
  • Objection to processing pursuant to Art. 21 GDPR
  • Withdrawal of consent pursuant to Art. 7(3) GDPR with effect for the future

To exercise your rights, you may contact us at:

Gheddiseh Zarvandi, Email: gheddisehzar@gmail.com

Right to object

Where we process your personal data on the basis of legitimate interests pursuant to Art. 6(1) sentence 1(f) GDPR, you have the right under Art. 21 GDPR to object to processing of your personal data on grounds relating to your particular situation. Where the objection concerns processing for direct marketing purposes, you have a general right to object without needing to state a particular situation.

If you wish to exercise your right of withdrawal or objection, an email to gheddisehzar@gmail.com is sufficient.

Disclosure of personal data to third parties

Your personal data is not disclosed to third parties except

  • where we have explicitly indicated this in the description of the relevant processing,
  • where you have given express consent pursuant to Art. 6(1) sentence 1(a) GDPR,
  • where disclosure is necessary pursuant to Art. 6(1) sentence 1(f) GDPR for the establishment, exercise, or defence of legal claims and there is no reason to assume that you have an overriding legitimate interest in non-disclosure,
  • where there is a legal obligation to disclose pursuant to Art. 6(1) sentence 1(c) GDPR, and
  • where this is necessary pursuant to Art. 6(1) sentence 1(b) GDPR for the performance of contractual relationships with you.

Statutory obligations

Providing personal data for decisions about concluding a contract, performing a contract, or carrying out pre-contractual measures is voluntary. However, we can only make decisions in the context of contractual measures if you provide the personal data required for concluding, performing, or preparing the contract.

Changes to this privacy policy

We reserve the right to adapt this privacy policy if our website, the services used, or legal requirements change.

The version published on this website at any given time applies.