Privacy Policy
Privacy Policy
Last updated: 2026-05-26
This Privacy Policy explains how Happy Eye GmbH ("Happy Eye", "we", "us", "our") collects, uses, and shares information about you when you visit happy-eye.com (the "Site") or purchase our products.
We are a controller of your personal data under the EU General Data Protection Regulation (GDPR) and the UK GDPR. For California residents, the California Consumer Privacy Act (CCPA) applies.
1. Who we are
- Legal entity: Happy Eye GmbH
- Address: Musterstrasse 1, 10115 Berlin, Germany
- Contact: privacy@happy-eye.com
- EU representative (if applicable): EU representative: Prighter GmbH, Pater-Schwartz-Gasse 11A, 1150 Wien, Austria
2. Information we collect
| Category | Examples | Source |
|---|---|---|
| Contact data | name, email, postal address, phone | You, at checkout / account creation / form fills |
| Order data | products purchased, prices, order history, subscription status | You and Shopify |
| Payment data | billing address; we do not store full card numbers — Shopify Payments / Stripe handle this | Payment processor |
| Account data | login, password hash | You |
| Marketing data | newsletter preferences, click history | Klaviyo |
| Device data | IP address, browser, device type, OS, referrer | Automatic |
| Usage data | pages viewed, time on site, clicks, add-to-cart events | Analytics tools |
3. How we use your information
- To fulfil orders, including handing off to CJ Dropshipping for shipping.
- To manage subscriptions and recurring charges via Shopify Subscriptions.
- To send transactional emails (order confirmations, shipping updates, renewal reminders).
- To send marketing emails — only if you have opted in. You can unsubscribe at any time.
- To analyse and improve our site (Google Analytics, Meta Pixel, TikTok Pixel — see Section 6).
- To prevent fraud and comply with legal obligations.
Legal bases under GDPR (Art. 6)
- Performing the contract with you (Art. 6(1)(b)) — orders, accounts, subscriptions.
- Legitimate interest (Art. 6(1)(f)) — security, fraud prevention, basic analytics.
- Your consent (Art. 6(1)(a)) — marketing emails, non-essential cookies/tracking.
- Compliance with legal obligation (Art. 6(1)(c)) — tax, accounting.
4. Sharing with processors and third parties
We share data only with processors who are contractually bound to protect it. Main processors:
| Processor | Purpose | Data shared | Location |
|---|---|---|---|
| Shopify Inc. | E-commerce platform, payments, subscriptions | All order, account, payment data | Canada, US |
| CJ Dropshipping | Order fulfilment | Shipping name, address, products, contact | China |
| Klaviyo | Email & SMS marketing | Email, name, marketing preferences | US |
| Google (GA4) | Analytics | Device/usage data (anonymised) | US |
| Meta (Facebook/Instagram) | Advertising pixel | Hashed email, events, device data | US |
| TikTok | Advertising pixel | Hashed email, events, device data | US, Singapore |
| Judge.me | Product reviews | Email, order data, review text | Hong Kong |
International transfers outside the EEA/UK rely on Standard Contractual Clauses approved by the EU Commission.
5. Subscriptions
If you subscribe to recurring deliveries, we keep your subscription details (product, frequency, billing token) for as long as the subscription is active. You can pause, skip, or cancel anytime from your customer account. See our Subscription Terms.
6. Cookies and tracking
We use cookies and similar technologies. Strictly necessary cookies are always active. Marketing and analytics cookies load only after you give consent via our cookie banner (Pandectes). See our Cookie Policy for the full list.
7. Your rights
Under GDPR / UK GDPR you have the right to:
- access your data;
- have inaccurate data corrected;
- have data erased ("right to be forgotten");
- restrict or object to processing;
- data portability;
- withdraw consent at any time;
- lodge a complaint with a supervisory authority.
To exercise these rights, email privacy@happy-eye.com. We respond within 30 days.
For California residents, you additionally have the right to opt out of "sale" or "sharing" of personal data — use the Do Not Sell or Share My Personal Information link in our footer.
8. Data retention
- Order records: 10 years (tax law).
- Account data: until account deletion + 30 days.
- Marketing data: until opt-out + 30 days.
- Analytics data: anonymised after 14 months (GA4 default).
9. Security
We use TLS encryption in transit, role-based admin access, and the security controls of our processors (Shopify is PCI-DSS Level 1).
10. Children
The Site is not directed to children under 16. We do not knowingly collect data from children.
11. Changes
We may update this policy. Material changes will be announced on the Site at least 14 days in advance.
Questions? Contact us at privacy@happy-eye.com.