Privacy policy
Privacy Policy / Datenschutzerklärung
Last updated: 09.07.2026
1. Introduction and Data Controller
The Growth Library ("we", "us", "our") takes the protection of your personal data seriously. This Privacy Policy explains what personal data we collect, why we collect it, how it is used, how long it is retained, and what rights you have under the General Data Protection Regulation (GDPR), the Bundesdatenschutzgesetz (BDSG), and other applicable data protection law.
By using our store and services, you acknowledge that you have read and understood this Privacy Policy.
In the event of any conflict between this Privacy Policy and our Terms of Service, this Privacy Policy controls with respect to the collection, processing, and disclosure of your personal data.
Data Controller (Verantwortlicher): The Growth Library Sophie Dahm Hofweg 58 22085 Hamburg Germany Email: growthlibrarian@gmail.com
2. Legal Bases for Processing (Art. 13 GDPR)
We process your personal data only where we have a valid legal basis under Art. 6 GDPR:
- Art. 6(1)(a) GDPR — You have given consent (e.g. cookie preferences)
- Art. 6(1)(b) GDPR — Processing is necessary to perform a contract with you (e.g. processing your order, delivering your digital product)
- Art. 6(1)(c) GDPR — Processing is necessary to comply with a legal obligation (e.g. tax records, accounting obligations under § 147 AO and § 257 HGB)
- Art. 6(1)(f) GDPR — Processing is necessary for our legitimate interests (e.g. fraud prevention, store security, responding to enquiries), provided these are not overridden by your interests or fundamental rights
Where we rely on legitimate interests (Art. 6(1)(f) GDPR), you have the right to object to such processing at any time (see Section 9).
3. Personal Data We Collect and Why
3.1 When you place an order To process your purchase and deliver your digital product, we collect:
- Name and billing address
- Email address
- Payment information (processed securely by our payment provider — we do not store full card details)
- Order details and transaction history
Legal basis: Art. 6(1)(b) GDPR (contract performance); Art. 6(1)(c) GDPR (legal obligation for tax and accounting purposes).
3.2 When you contact us If you contact us by email, we collect your name, email address, and the content of your message in order to respond to your enquiry.
Legal basis: Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries).
3.3 When you visit our store Our store is hosted by Shopify Inc. Shopify automatically collects certain technical data when you visit, including your IP address, browser type, device type, pages visited, and referring URLs. This data is used for store security, fraud prevention, and performance monitoring.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and functional store operation).
3.4 Cookie consent When you visit our store, we use Shopify's built-in cookie consent banner to collect your consent preferences before placing any non-essential cookies. Your consent choice is stored so we can respect it on future visits.
Legal basis: Art. 6(1)(a) GDPR (consent); Art. 6(1)(f) GDPR for strictly necessary cookies.
4. Payment Processing
Payment transactions are processed by Shopify's payment infrastructure and third-party payment providers (such as Shopify Payments, powered by Stripe). We do not store or have access to your full payment card details. All payment data is processed in accordance with PCI-DSS standards.
For details on how Shopify processes payment data, please refer to Shopify's Privacy Policy: https://www.shopify.com/legal/privacy
5. Shopify as Data Processor and Independent Controller
Our store is built on and hosted by Shopify Inc. (151 O'Brien Street, Ottawa, Ontario, Canada). In its role as our hosting and infrastructure provider, Shopify acts as a data processor on our behalf under a Data Processing Agreement (DPA) in accordance with Art. 28 GDPR.
In addition, Shopify independently processes certain data as a data controller in its own right — for example, in connection with Shopify's own platform services, fraud prevention, and analytics across its merchant network. In these circumstances, Shopify is independently responsible for that processing. To learn more and to exercise your rights in relation to Shopify's own processing, visit: https://privacy.shopify.com/en
Canada has been recognized by the European Commission as providing an adequate level of data protection. Where Shopify transfers data to other countries, it relies on Standard Contractual Clauses (SCCs) approved by the European Commission.
6. Cookies and Tracking Technologies
Our store uses cookies — small text files stored on your device — to ensure the store functions correctly and to remember your preferences.
Strictly necessary cookies (no consent required):
- Session cookies required for the shopping cart and checkout to function
- Security and fraud prevention cookies set by Shopify
Non-essential cookies (require your consent):
- We use Shopify's built-in cookie consent banner to obtain your consent before placing any non-essential cookies
- You may withdraw or change your consent at any time by adjusting your preferences via the banner
We do not use Google Analytics, Meta Pixel, or any other third-party advertising or tracking tools. No data is shared with advertising networks or used for behavioural advertising.
7. Children's Data
Our store and services are not directed at children under the age of 16. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at growthlibrarian@gmail.com and we will delete it promptly.
8. Data Retention
We retain your personal data only for as long as necessary for the purposes described in this Privacy Policy, or as required by law:
- Order and transaction data: retained for 10 years in accordance with German commercial and tax law (§ 147 AO, § 257 HGB)
- Contact and support enquiries: retained for up to 3 years from the date of last contact, or until the matter is fully resolved
- Cookie consent records: retained for up to 1 year
- Technical and log data: retained by Shopify for a limited period for security and operational purposes
After the applicable retention period, data is securely deleted or anonymised.
Now paste Part 2 immediately after:
9. Your Rights Under GDPR
As a data subject under the GDPR, you have the following rights. These rights are not absolute and may be subject to exceptions under applicable law:
- Art. 15 GDPR — Right of access: You may request confirmation of whether we process your personal data and, if so, a copy of that data along with information about how it is processed
- Art. 16 GDPR — Right to rectification: You may request correction of inaccurate or incomplete personal data we hold about you
- Art. 17 GDPR — Right to erasure ("right to be forgotten"): You may request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, subject to our legal retention obligations
- Art. 18 GDPR — Right to restriction of processing: You may request that we restrict the processing of your personal data in certain circumstances
- Art. 20 GDPR — Right to data portability: You may request a copy of your personal data in a structured, commonly used, machine-readable format, and request that it be transferred to another controller where technically feasible
- Art. 21 GDPR — Right to object: You have the right to object at any time to processing of your personal data based on Art. 6(1)(f) GDPR (legitimate interests). We will cease such processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms
- Art. 7(3) GDPR — Right to withdraw consent:Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal
- Right to opt out of marketing: If you receive any promotional communications from us, you may opt out at any time using the unsubscribe link in the email or by contacting us directly
How to exercise your rights: Contact us at growthlibrarian@gmail.com or by post at: The Growth Library, Sophie Dahm, Hofweg 58, 22085 Hamburg, Germany.
We will respond within 30 days of receiving your request, in accordance with Art. 12 GDPR. We may need to verify your identity before processing your request. We will not charge a fee for reasonable requests.
We will not discriminate against you for exercising any of these rights.
10. Right to Lodge a Complaint
If you believe that our processing of your personal data violates applicable data protection law, you have the right to lodge a complaint with a supervisory authority. The competent supervisory authority for Hamburg is:
Hamburgischer Beauftragter für Datenschutz und Informationsfreiheit (HmbBfDI) Ludwig-Erhard-Str. 22, 7. OG 20459 Hamburg Germany Website: https://datenschutz.hamburg.de
You may also lodge a complaint with the supervisory authority of your country of residence or place of work within the EU/EEA.
11. Third-Party Websites and Links
Our store may contain links to third-party websites or platforms. We are not responsible for the privacy practices or content of those sites. We recommend reviewing the privacy policy of any third-party site you visit. Our inclusion of a link does not imply endorsement of that site or its operators.
12. International Data Transfers
Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA), including by Shopify Inc. in Canada (which has been recognized by the European Commission as providing an adequate level of data protection) and, where applicable, in other countries via Standard Contractual Clauses (SCCs) approved by the European Commission.
We do not transfer your personal data to any other third parties outside the EEA.
13. Online Dispute Resolution (ODR)
The European Commission provides an online dispute resolution platform for consumers:https://ec.europa.eu/consumers/odr Our email address for ODR purposes: growthlibrarian@gmail.com
14. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or destruction. However, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security, and we recommend that you do not transmit sensitive information via unsecured channels.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational reasons. We will post the updated version on this page and update the "Last updated" date. We encourage you to review this policy periodically.
16. Contact
For any questions about this Privacy Policy, to exercise your data protection rights, or for any other privacy-related enquiries, please contact us:
The Growth Library Sophie Dahm Hofweg 58 22085 Hamburg Germany Email: growthlibrarian@gmail.com