Legal — Datenschutz
(Please note: This is a translation of our German Privacy Policy. In case of any differences, the German version is legally binding.)
The data controller for this website is New Niche GmbH, Wilhelmshöher Str. 2, 12161 Berlin. If you have any questions or concerns about data protection, you can reach us at info@newniche.com. We are pleased about your interest in our online shop, and we take the protection of your personal data very seriously. In the following, we inform you in detail about how we handle your data (collection, use, and sharing) when you visit our website or use our services.
You may visit our website without providing personal information. However, each time you access our site, the web server automatically records certain access data in so-called server log files. This includes, for example, the name of the requested file, your IP address, date and time of access, the amount of data transferred, and the requesting provider. These access logs are collected and used solely to ensure the stable operation of the site and to improve our services. This is done on the basis of our legitimate interests in presenting our website correctly and securely (legal basis: Art. 6(1)(f) GDPR). All access logs are deleted no later than seven days after your visit.
Hosting: Our online shop runs on two separate technical infrastructures. Product management, order processing and payment processing run on the Shopify commerce platform (Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland); the underlying servers may also be located outside the EU/EEA, including in Canada (recognized by the EU Commission as providing an adequate level of data protection) and the USA. For transfers to the USA we have entered into EU Standard Contractual Clauses (SCCs) with Shopify. The website itself (this frontend, which displays the Shopify data) is delivered via a Cloudflare-based infrastructure; here too, servers may be located outside the EU, and corresponding safeguards (SCCs or equivalent mechanisms) are contractually in place. If you have questions about our hosting arrangements and data protection guarantees, feel free to contact us.
Fonts (Adobe Fonts / Typekit): To display our website correctly, we use web fonts that are loaded directly from Adobe Fonts’ servers (Adobe Inc., 345 Park Avenue, San Jose, CA 95110-2704, USA) whenever a page is opened. This technically requires your IP address to be transmitted to Adobe; Adobe Fonts does not set its own cookies in the process. The legal basis is our legitimate interest in a consistent and correct presentation of our website (Art. 6(1)(f) GDPR); for transfers to the USA we rely on Adobe’s Standard Contractual Clauses. For more information, see Adobe’s privacy policy.
Order Processing: When you place an order through our online shop, we collect and process the personal data you provide (e.g. name, billing and shipping address, email address, payment details) for the purpose of fulfilling your order and managing our contractual relationship (Art. 6(1)(b) GDPR). Fields that are required for order processing are marked as mandatory – without this information, we cannot process your order. The specific data collected can be seen from the input forms on our site. We use these data solely to process your order (including any warranty claims or required updates to products). After complete fulfillment of the contract and payment, your data will be restricted from further use and deleted upon expiry of the applicable commercial and tax retention periods, unless you have consented to a further use or we have a legal basis to retain the data longer (e.g. storage of invoices for tax purposes).
Sharing data with shipping companies: For the purpose of delivering your ordered goods, we will pass on the necessary information (typically your name and delivery address, and if needed your email/phone for notification) to the shipping company entrusted with the delivery (e.g. DHL, UPS, DPD). This data transfer is strictly for fulfilling the contract (delivery of your purchase) and is based on Art. 6(1)(b) GDPR. If you have given us your explicit consent during or after the order, we will also provide your email address or phone number to the shipping provider so they can contact you with shipping updates or delivery scheduling (legal basis: Art. 6(1)(a) GDPR). You can revoke such consent at any time by notifying us or the shipping provider, after which the data will be deleted unless other legal grounds allow further processing.
Sharing data for payment processing: Depending on the payment method you choose during checkout, we may need to share relevant data with the corresponding payment service provider or bank in order to process the payment (Art. 6(1)(b) GDPR). For example, if you pay by credit card, your card details will be transmitted to our payment processor or the credit card company. If you choose PayPal, we will provide necessary order identifiers to PayPal, etc. In some cases, the payment providers collect these data themselves via their own interface integrated on our site – in such cases, the privacy policy of the respective payment provider applies. We do not receive full payment information like your credit card number (except possibly the last few digits for reference). We only get a confirmation of payment or transaction ID. Please consult the privacy notices of the payment service you selected (e.g. PayPal, Stripe, Klarna, etc.) for details on their data processing. If you have any questions about our payment partners and the basis of our cooperation with them, you can reach out to us at any time.
Fraud prevention: If necessary, we may transmit additional data to our payment service providers (or anti-fraud service providers) along with the payment data to help prevent fraud and ensure secure payment transactions (e.g. verification data, device information). This is done under our legitimate interest in preventing fraud and is covered by Art. 6(1)(f) GDPR.
Customer account: If our website allows the creation of a customer account and you choose to register, we will use the data you provide to set up and manage your account (based on your consent, Art. 6(1)(a) GDPR). The account stores your personal data for future orders (so you don't have to re-enter everything). You can delete your account at any time through the account settings or by contacting us, upon which your data will be erased unless we are permitted or required to retain it under law.
Contact inquiries: When you contact us (e.g. via a contact form on the website or by email), we collect the personal data you provide (your email address, name, and any information included in your message) solely for the purpose of responding to and processing your inquiry. The legal basis for this is Art. 6(1)(b) GDPR (performance of pre-contractual measures or answering your request). You are not obliged to provide additional data beyond the information needed to handle your request. We use this information exclusively to respond to your inquiry. Once your request is fully resolved, we will delete the correspondence and any related data, unless you have given consent to further storage or further processing is justified by another legal basis (e.g. if your inquiry leads to an order or contract).
Newsletter Sign-Up: If you subscribe to our email newsletter, we will use the data necessary for this (usually just your email address, and possibly your name if provided) to send you our newsletter regularly, based on your consent (Art. 6(1)(a) GDPR). We employ a double opt-in process for the newsletter registration when required by law: after signing up, you will receive an email asking you to confirm your subscription. This confirmation ensures that the email address provided is really yours and that you agree to receive the newsletter. Only after confirmation will your address be added to our mailing list.
Newsletter Content: Our newsletters contain information about our products, promotions, and company news which we believe may be interesting to you based on our relationship. The exact content is outlined when you subscribe or in the welcome email.
Unsubscribing: You can unsubscribe from the newsletter at any time. Each newsletter email includes an “unsubscribe” or “opt-out” link that you can click to stop receiving future newsletters. Alternatively, you can send us an email request to remove you from the list. Once you unsubscribe, we will promptly remove your email from our mailing list, unless you have explicitly consented to further use of your data or we are legally permitted to retain it for other purposes.
Newsletter analytics (tracking): If you have given us separate consent to do so, we may analyze your interaction with our newsletters to optimize our email content. This includes measuring how often newsletters are opened and which links are clicked, in order to understand what content is most interesting to our subscribers. For this analysis, our emails may contain small tracking technologies (like tracking pixels or web beacons). When you open an email, these pixels connect to our server (or the server of our email service provider) and allow us to collect technical information such as your IP address, the time of opening, the type of email client (browser or mail app) used, and whether you click on links in the email. We might link this information with your email address or an internal newsletter ID to evaluate which subscribers are reading our newsletters and what links they find interesting. No profiling beyond newsletter optimization occurs – we do not, for example, make any automated decisions based on your newsletter behavior. The insights help us adjust our future newsletters to the interests of our readers (for example, to send more of what appears to be useful and less of what doesn’t). If you do not wish to be tracked in this way, you can either refrain from giving the extra consent for analytics or, if you already did, you can revoke this consent at any time. We will then exclude your newsletter interactions from our analysis. Unsubscribing from the newsletter will also stop any tracking for you. We store the newsletter interaction data as long as you remain subscribed; once you unsubscribe, this data is either deleted or sufficiently anonymized.
Email Service Providers: Our newsletter may be sent using external email service providers who act on our behalf as data processors. These providers help us manage subscriber lists and distribute emails efficiently. We ensure that any service provider we use protects your data in compliance with GDPR. If such providers operate servers outside the EU (for example, in the USA), we have made sure that Standard Contractual Clauses or equivalent safeguards are in place to protect your data, given that an EU-equivalent privacy level may not be guaranteed in those countries.
The providers we currently use are:
Klaviyo: We use Klaviyo for managing our email newsletter list and sending emails. The service provider is Klaviyo Inc., 125 Summer St, Boston, MA 02110, USA. Klaviyo is an email marketing platform. When you subscribe to our newsletter, the data required (email address, and if provided your name) is stored on Klaviyo’s servers. Klaviyo may also collect certain technical data (like email open rates, IP address at open time, etc.) to provide us with analytics on our newsletter performance. Because Klaviyo is a US-based company, it may process your personal data on servers in the United States. According to the European Court of Justice, the US is currently not considered to have an adequate level of data protection. To cover this, we have signed the European Commission’s Standard Contractual Clauses (SCCs) with Klaviyo, obligating Klaviyo to comply with EU data protection standards for data it processes on our behalf. Klaviyo has also published a Data Processing Agreement including these SCCs. In practical terms, this means Klaviyo must protect your data and not use it for any purposes other than sending our newsletter and analyzing it as instructed by us. For more details, please see Klaviyo’s privacy policy. You can withdraw your newsletter consent at any time (see above), and then we will remove your data from Klaviyo, too, unless retention is necessary by law.
Beehiiv: We occasionally distribute newsletters via beehiiv. Beehiiv is a newsletter platform provided by beehiiv Inc., 228 Park Avenue #2329976, New York, NY 10003, USA. If you subscribe to a newsletter that we send through Beehiiv, your email address (and any other info you optionally provide for that newsletter) will be stored on Beehiiv’s systems. Beehiiv processes this data strictly for sending out our newsletters and for analytics on our behalf. Similar to Klaviyo, Beehiiv might use tracking pixels in the emails to inform us, for instance, how many subscribers opened the email and from which region. Beehiiv may also collect technical metadata such as your IP address and approximate location at the time of subscription or email open, primarily to prevent fraudulent sign-ups and give us insight into our subscriber base distribution. Beehiiv is a US-based company, meaning your data could be transferred to or stored in the USA. We have also entered into Standard Contractual Clauses with Beehiiv (or rely on Beehiiv’s adherence to such EU safeguards) to legitimize these transfers and ensure protection of your data. Beehiiv’s privacy practices are detailed in their privacy policy (available on their website). If you unsubscribe from a Beehiiv-powered newsletter, we will ensure your data is deleted from Beehiiv’s database as well, unless continued retention is legally required.
To make our website user-friendly and to enable certain features, we use cookies and similar technologies on various pages. Some of these technologies are essential for the operation of the website, while others serve analytics and marketing purposes. In this section, we explain what these technologies are, what they do, and how you can control them.
What are cookies? Cookies are small text files that your browser stores on your device. Cookies can store information like user preferences, login status, or identifiers that allow a site to recognize your browser across visits. Session cookies are temporary cookies that are deleted when you close your browser, whereas persistent cookies remain on your device for a set period or until you delete them, so that the site can remember you on your next visit.
Essential cookies: Some cookies are technically necessary for the website to function properly. For example, if our site has a shopping cart, a cookie might remember the items you added so that your cart isn’t empty when you navigate between pages. Other essential cookies may be needed for security or to remember your privacy settings. These essential cookies do not require consent, as without them the site cannot provide the service you explicitly request (per EU ePrivacy rules). We process data collected by essential cookies based on our legitimate interest in providing a functional website (Art. 6(1)(f) GDPR).
Functional cookies (consent-based): For our newsletter sign-up widget we use the provider Klaviyo (see section 4 for details on Klaviyo as our processor, its US server location, and Standard Contractual Clauses). The script this requires, and any cookies Klaviyo sets, only load once you have agreed to them in our cookie banner (Art. 6(1)(a) GDPR). Without your consent, this widget is replaced by a short notice with a button to grant consent afterwards — no script loads and no cookie is set.
Analytics and advertising-tracking cookies: We currently do not use any web-analytics tools (e.g. Google Analytics) or advertising/retargeting technologies (e.g. Google Ads remarketing, the Meta/Facebook Pixel). Should we introduce such technologies in the future, we will update this Privacy Policy first and obtain your consent via our cookie banner before any such cookies are set.
Our cookie consent tool: We use a self-built cookie banner integrated directly into our website — we do not hand this off to an external cookie-consent vendor. Your choice (“necessary” / “functional”) is stored only locally in your browser (localStorage), not on our servers or with a third party. You can change your choice at any time via the “Cookie settings” link in our website’s footer. If you clear your browser data, the banner will reappear on your next visit.
Under the General Data Protection Regulation (GDPR), you have various rights regarding your personal data. Below is an overview of these rights:
Right of Access (Art. 15 GDPR): You have the right to obtain confirmation from us as to whether or not personal data concerning you is being processed, and if so, access to that personal data and information about how it’s processed. This includes information on the purposes of processing, categories of data, recipients, envisaged storage period, and the existence of other rights such as rectification or complaint. We will provide you with a copy of the personal data undergoing processing upon request.
Right to Rectification (Art. 16 GDPR): You have the right to request that we correct any inaccurate personal data about you, and to have incomplete data completed, taking into account the purposes of the processing. If you become aware that, for example, we have an incorrect spelling of your name or an outdated address, you can ask us to update it.
Right to Erasure (Art. 17 GDPR): Commonly known as the “right to be forgotten,” this allows you to request the deletion of your personal data under certain conditions. You can ask us to erase your personal data when it’s no longer needed for the purposes for which it was collected, if you have withdrawn your consent and there is no other legal ground, or if you object to processing and we have no overriding legitimate grounds, among other reasons. Note that this right is not absolute – we may have legal obligations or other legitimate grounds to retain some data (for example, we cannot delete data that we must keep by law, such as certain transaction records).
Right to Restriction of Processing (Art. 18 GDPR): You can ask us to restrict (i.e. lock down) your data so that it’s only stored and not further processed, in certain circumstances. This applies, for instance, if you contest the accuracy of your data (for a period enabling us to verify it), or if the processing is unlawful but you oppose deletion and request restriction instead, or if we no longer need the data but you require it for the establishment, exercise, or defense of legal claims.
Right to Data Portability (Art. 20 GDPR): Where processing is based on your consent or on a contract and is carried out by automated means, you have the right to receive the personal data you provided to us in a structured, commonly used, machine-readable format and have the right to transmit that data to another controller (e.g. another service provider). You can also ask, where technically feasible, that we transfer your data directly to the other provider. This right is intended to give you more control over your data across different services.
Right to Object (Art. 21 GDPR): You have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you that we perform based on a legitimate interest (Art. 6(1)(f)). If you lodge an objection, we will review it and typically stop processing the data for that purpose, unless we demonstrate compelling legitimate grounds for the processing that override your interests, or unless we need to continue processing for the establishment, exercise, or defense of legal claims. Right to object to direct marketing: If your personal data are processed for direct marketing purposes, you have the right to object at any time to such processing. This is an absolute right – if you object to processing for direct marketing, we will stop using your data for that purpose immediately. For example, if you object to receiving marketing emails or postal mail, we will put you on a do-not-contact list.
Right to Withdraw Consent (Art. 7(3) GDPR): If we are processing your data based on your consent, you have the right to withdraw that consent at any time. The withdrawal will not affect the lawfulness of processing that was done before you withdrew consent, but it means we will stop the processing going forward. For instance, you can unsubscribe from our newsletter (withdraw consent to email marketing) or turn off analytics/marketing cookies (withdraw consent to tracking) at any time.
Right to Lodge a Complaint (Art. 77 GDPR): If you believe that we have infringed data protection laws when processing your data, you have the right to file a complaint with a data protection supervisory authority, particularly in the EU country where you reside, where you work, or where the alleged infringement occurred. For example, if you live in Germany, you can complain to the data protection authority of your German state. We would, of course, appreciate the chance to address your concerns directly before you approach a regulator, but you are free to do so. In Berlin (where our company might be based), the supervisory authority is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit). Their contact details: Alt-Moabit 59-61, 10555 Berlin, Germany, Tel. +49 30 13889-0.
Exercising your rights: You can contact us at any time to exercise the above rights, for example by sending an email to info@newniche.com. There is no cost for you to exercise these rights (aside from any network or postage fees in sending us the request). We will respond to your request as soon as possible, generally within one month as mandated by GDPR. This period may be extended by two further months if necessary, taking into account the complexity and number of requests, but we will inform you if an extension is needed. We may need to verify your identity to ensure that your data isn’t disclosed to someone else – for instance, we might ask for you to send the request from the email address associated with your account or order, or we might ask for other identification if necessary.
Please note that these rights are not absolute. Each right can be subject to certain legal conditions and exceptions. If we cannot comply with a particular request (for example, if you ask us to delete data we are required by law to keep), we will explain the reasons.
This Privacy Policy is current as of 09. July 2026. We may update or modify this policy from time to time to reflect changes in our practices or relevant laws. If we make material changes, we will notify you by (for example) posting a notice on our website or contacting you via email (if appropriate), and by updating the “last updated” date on this document. We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information.
Last updated: 09. July 2026.