Cookie Policy


1. Cookie Settings

You can reject any cookie category listed in the cookie settings, except for cookies that are technically necessary. To do this, click on the "Cookie Settings" button.




2. Cookie Overview

Like many other websites, we also use so-called "cookies". These can be information about you, your settings, or your device. Mostly, the information is used to ensure that the website operates as expected. You are usually not directly identified by this information.


You can delete individual cookies or the entire cookie inventory. In addition, you will receive information and instructions on how to delete these cookies or block their storage in advance. Depending on the provider of your browser, you can find the necessary information under the following links:




3. Third Country Transfer

We also process data in countries outside the European Economic Area in so-called third countries or transfer data to recipients in these third countries. Please note that some services we use may transfer data outside the European Union and the European Economic Area and to a country that does not provide an adequate level of data protection. This includes the United States. As a result, there is a risk that your data may be processed by U.S. authorities for control and monitoring purposes, without you possibly having any legal remedies. Please also note that with respect to some of these third countries, there is currently no adequacy decision by the EU Commission that these third countries generally provide an adequate level of data protection. 


Below you will find a list of the services used that may transfer data to third countries. This may be the case for various purposes, for example, for storage or processing.


  • Google Tag Manager
  • Google Analytics
  • Microsoft Advertising
  • Google Ads
  • Facebook Pixel
  • Pinterest tag
  • Vimeo


You can revoke your consent at any time with effect for the future. To do so, deactivate the corresponding checkbox in the cookie settings. We have agreed standard contractual clauses with the relevant providers.

4. Cookie Details

4.1 Technically Necessary Cookies


Purpose and legal basis


We use cookies to make our website more user-friendly. Some elements of our website require the requesting browser to be identifiable even after a page change.

The following data is stored and transmitted in the cookies:

  • Language settings
  • Approval status (Optanon)
  • Selected customer type
  • Selected payment method

  • The purpose of using technically necessary cookies is to simplify the use of websites for users. Some functions of our website cannot be provided without the use of cookies. For these, it must be possible to recognise the browser even after a page change.
    The processing is carried out in accordance with Art. 6 (1) f) GDPR on the basis of our legitimate interest in a user-friendly design of our website.

    The recipients of the data may be technical service providers who act as contract processors for the operation and maintenance of our website.


    Storage period
    For details of how long cookies are stored and the technologies used with these tracking tools, please see the information above about the cookies we use.

    Provision prescribed or required
    The provision of the aforementioned personal data is neither legally nor contractually required. However, without this data the service and functionality of our website cannot be guaranteed. In addition, individual services and services in general may not be available or may be limited.

    Objection
    Please read the information about your right to object according to Art. 21 GDPR.

    a) Google Tag Manager

    Google Tag Manager (Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland) is a tag management system that allows tracking codes and associated code fragments to be placed, updated, and managed on the website. Through the Google Tag Manager tool, through which the tags are implemented, cookies are set and loaded via the googletagmanager.com domain. No personal data is collected itself. The Google Tag Manager only triggers other tags, which in turn may collect data. The Google Tag Manager does not access this data. The service itself does not collect any personal data.

    1. Data protection, privacy information and unsubscribe option
    2. The data processed are:
      • Google Tag Manager HTTP data
        This is log data that is technically generated when using the Google Tag Manager tool used on the website via the Hypertext Transfer Protocol Secure (HTTPS). This includes IP address, type and version of your internet browser, the operating system used, the page accessed, the previously visited page (referrer URL) and the date and time of access.
    3. The legal basis for the processing of the data is Art. 6 (1) a) GDPR (consent) in conjunction with Art. 25 of the Act on Data Protection and Privacy of Telecommunications and Telemedia Services (TTDSG), for the reliable control of cookies.
    4. The data is automatically provided by the user's browser.
    5. The recipients of the data are Google Ireland Limited (Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland) within the scope of order processing. Google Ireland Limited uses Google LLC in the USA (1600 Amphitheatre Parkway, Mountain View, CA 94043, United States of America) as a service provider.
    6. An automated decision-making process takes place regarding the "Technically Necessary Cookies" when you use the website.


    b) OneTrust

    OneTrust (OneTrust Technology Limited, 82 St Johan St, Farringdon, London, EC1M 4JN, United Kingdom) is a cookie consent management tool and is used to manage the consent management of our website visitors. This enables us to use our user data in a GDPR compliant manner. In addition to consent, it is also important to be able to manage possible revocations of consent and objections to the use of cookies.

    1. Data protection and privacy information
      https://www.onetrust.com/privacy-notice/
    2. The data processed are:
      • OneTrust HTTP data
        This is log data that is technically generated when using the cookie consent management tool OneTrust on the website via the Hypertext Transfer Protocol Secure (HTTPS). This includes the IP address, type and version of your Internet browser, the operating system used, the page accessed, the previously visited page (referrer URL) and the date and time of access.
      • OneTrust consent data
        This is log data that registers and stores the decision of you to individual cookie groups. The data we collect through OneTrust does not allow us to directly identify you personally (i.e., by your civil name). It also does not provide any other personal information about the identity of the user.
    3. The legal basis for the processing of the data is Art. 6 (1) a) GDPR (consent) in conjunction with Art. 25 of the Act on Data Protection and Privacy of Telecommunications and Telemedia Services (TTDSG), for the reliable control of cookies.
    4. The data is automatically provided by the user's browser.
    5. The recipients of the data are OneTrust Technology Limited (82 St Johan St, Farringdon, London, EC1M 4JN, United Kingdom) as part of the commissioned processing.
    6. An automated decision-making process takes place regarding the "Technically Necessary Cookies" when you use the website.  

4.2 Functional Cookies


a) Google Analytics

Google Analytics (Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland) is a web analytics service and is used to store information about the user activities of website visitors, in particular the number of visitors, duration of visits, sales transactions and sub-pages visited. The information generated by the cookie about your use of the website will be transmitted to and stored by Google on servers in the United States. However, due to the activation of IP anonymization on these web pages, your IP address will be truncated beforehand by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. Google Analytics serves the purpose of analyzing the use of the website and to be able to continuously improve individual functions and offers as well as the user experience. Through the statistical evaluation of user behavior, it is possible to continuously improve the offer and make it more interesting for you as a user.


  1. Data protection, privacy information and unsubscribe option
  2. The data processed are:
    • Google Analytics HTTP data
      This is log data that is generated for technical reasons when using the Google Analytics web analysis tool used on the website via the Hypertext Transfer Protocol Secure (HTTPS). This includes IP address, type and version of your internet browser, the operating system used, the page accessed, the previously visited page (referrer URL) and the date and time of access.
    • Google Analytics end device data
      This is data generated by Google Analytics and assigned to your terminal device. This includes a unique ID for recognizing returning visitors, the so-called "Client ID", as well as certain technical parameters for controlling data collection for web analysis.
    • Google Analytics measurement data
      These are device-related raw data, so-called "dimensions" and "measured values", which are collected and analyzed by Google Analytics when using our website. This includes information about the sources through which visitors reach our website, information about the location, the browser and the terminal device used, information about the use of the website (page impressions, frequency of visits and length of stay on visited pages) as well as information about the fulfilment of certain objectives (transactions). The data we collect using Google Analytics does not enable us to identify you directly on a personal level (i.e., by your civil name). Nor does it provide any other personal information about the identity of the user.
    • Google Analytics report data
      This is data contained in aggregated reports and is created by raw device-related data. In Google Analytics, we have four report categories available: Audience (location, browser, devices used, as well as other device-related data), Acquisition (sources through which visitors arrive at the web offer), Behavior (information on calling up content of the web offer, visit time, bounce rate), Conversions (information on pre-configured goals, especially transactions in the online shop).
  3. The legal basis for the processing of the data is Art. 6 (1) a) GDPR (consent) in conjunction with Art. 25 of the Act on Data Protection and Privacy of Telecommunications and Telemedia Services (TTDSG).
  4. The data is automatically provided by the user's browser after consent has been given.
  5. The recipients of the data are Google Ireland Limited (Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland) within the scope of order processing. Google Ireland Limited uses Google LLC in the USA (1600 Amphitheatre Parkway, Mountain View, CA 94043, United States of America) as a service provider. The data will only be transmitted if you have given us your consent to do so (Article 6(1)(a) DSGVO).
  6. On this website, a so-called IP anonymization is activated for the use of Google Analytics. The IP anonymization function in Analytics sets the last octet of IPv4 addresses of users and the last 80 bits of IPv6 addresses in memory to zero. This happens shortly after they are sent to Google Analytics. We store the remaining log data for a period of 24 months.
  7. The provision of the above data is neither legally nor contractually required or necessary for the conclusion of a contract. There is no obligation to provide the data. If the data is not provided, we will not be able to perform web analysis using Google Analytics.
  8. There is no automated decision making.


b) Hearts & Science Smart Tracking

For the conversion tracking of Hearts & Science Smart Tracking (Hearts & Science München GmbH, Blumenstraße 28, 80331 Munich, Germany), cookies are set on the end devices of the users referred to this online shop. These cookies serve the purpose of a correct allocation of the success of an advertising medium and the corresponding accounting and success-based remuneration of an affiliate. Personal data is only processed in pseudonymous form. Only the information about when a certain advertising medium was clicked on by the respective end device is placed in the cookies. Information about the end device, e.g., the operating system and the calling browser, is also recorded and used to check the mediation activities.

  1. Data protection and privacy information
  2. The data processed are:
    • Hearts & Science Smart Tracking HTTP data
      This is log data that is generated for technical reasons when using the Hearts & Science Smart Tracking via the Hypertext Transfer Protocol Secure (HTTPS) used on the website. This includes the type and version of your Internet browser, the operating system used, the page accessed, the previously visited page (referrer URL) and the date and time of access.
    • Hearts & Science Smart Tracking Transaction Data
      This is device-related raw data that is collected by Hearts & Science Smart Tracking during a transaction on our website. This includes the order value, the OrderID (so-called transaction number) and the shopping cart contents. The information we collect through Hearts & Science Smart Tracking does not enable us to identify you personally (i.e., by your real name). No other personal information about the identity of the user is communicated.
  3. The legal basis for the processing of the data is Art. 6 (1) a) GDPR (consent) in conjunction with Art. 25 of the Act on Data Protection and Privacy of Telecommunications and Telemedia Services (TTDSG).
  4. The data is automatically provided by the user's browser after consent has been given.
  5. The recipients of the data are Hearts & Science München GmbH (Blumenstraße 28, 80331 München, Deutschland) within the scope of order processing. The data will only be transmitted if you have given us your consent to do so (Article 6(1)(a) DSGVO).
  6. This cookie will lose its validity after 14 days.
  7. The provision of the above data is neither legally nor contractually required or necessary for the conclusion of a contract. There is no obligation to provide the data. If the data is not provided, we cannot provide affiliate remuneration via Hearts & Science Smart Tracking.
  8. There is no automated decision making.


c) Mouseflow

Mouseflow (Mouseflow Inc, Flaesketorvet 68, 1711 Copenhagen V, Denmark) is used to analyze this website and its visitors. Data is collected and stored for optimization purposes. The tool creates a log of mouse movements and clicks with the intention of randomly replaying individual website visits to continuously improve individual functions and offers as well as the user experience on the website. The information recorded by Mouseflow is not personal and will not be passed on.

  1. Data protection, privacy information and unsubscribe option
  2. The data processed are:
    • Mouseflow HTTP data
      This is log data that is technically generated when using the web analysis tool Mouseflow on the website via the Hypertext Transfer Protocol Secure (HTTPS). This includes IP address, type and version of your internet browser, the operating system used, the page accessed, the previously visited page (referrer URL) and the date and time of access.
    • Mouseflow measurement data
      This is device-related raw data that is collected and analyzed by Mouseflow when our website is used. This includes information about the sources through which visitors reach our website, information about the location, the browser and the terminal device used, information about the use of the website (page views) and information about the fulfilment of certain objectives (transactions). Furthermore, scrolling activities, viewed content & mouse movements are recorded. The information we collect through Mouseflow does not allow us to directly identify you personally (i.e., by your real name). It also does not provide any other personal information about the identity of the user.
    • Mouseflow report data
      This is data contained in aggregated reports and is generated by raw device-related data.

  3. The legal basis for the processing of the data is Art. 6 (1) a) GDPR (consent) in conjunction with Art. 25 of the Act on Data Protection and Privacy of Telecommunications and Telemedia Services (TTDSG).
  4. The data is automatically provided by the user's browser after consent has been given.
  5. The recipients of the data are Mouseflow Inc (Flaesketorvet 68, 1711 Copenhagen V, Denmark) within the scope of order processing. The data will only be transmitted if you have given us your consent to do so (Article 6(1)(a) DSGVO).
  6. This cookie will lose its validity after the session.
  7. The provision of the above data is neither legally nor contractually required or necessary for the conclusion of a contract. There is no obligation to provide the data. If the data is not provided, we cannot perform web analysis using Mouseflow.
  8. There is no automated decision making.

4.3 Marketing Cookies


a) Microsoft Advertising

The advertising service Microsoft Advertising (Microsoft Ireland Operations Limited, The Atrium Building, Block B, Carmanhall Road, Sandyford Business Estate, Dublin 18, Ireland) makes it possible to play content on Microsoft Advertising that is specifically tailored to your interests and to subsequently analyze the Microsoft campaigns. Universal Event Tracking is used for this purpose. Via the tracking, Microsoft stores a cookie in the user's browser to enable an analysis of the use of our online offer. The prerequisite for this is that the user has reached this website via an advertisement from Microsoft Advertising. In this way, Microsoft and we can recognize that someone has clicked on an ad, has been redirected to our online offer and has reached a predefined target page (so-called conversion measurement). No further personal information about the identity of the user is disclosed.

  1. Privacy information and unsubscribe option
  2. The data processed are:
    • Microsoft Advertising HTTP data
      This is log data that is technically generated when using the Microsoft Advertising used on the website via the Hypertext Transfer Protocol Secure (HTTPS). This includes IP address, type and version of your Internet browser, the operating system used, the page accessed, the previously visited page (referrer URL) and the date and time of access. The cookie ID is also used to determine how often ads are displayed in a browser to control the frequency of ad display.
    • Microsoft Advertising Usage Data
      This is data that shows clicks on ads, time spent on the site, and individual site pages visited.
    • Microsoft Advertising Transaction Data
      This is data that summarizes the results of transactions. The data we collect through the Microsoft Advertising tool does not allow us to directly identify you personally (i.e., by your civil name). Nor does it provide any other personal information regarding the identity of the user.
  3. The legal basis for the processing of the data is Art. 6 (1) a) GDPR (consent) in conjunction with Art. 25 of the Act on Data Protection and Privacy of Telecommunications and Telemedia Services (TTDSG).
  4. The data is automatically provided by the user's browser after consent has been given.
  5. The recipients of the data are Microsoft Ireland Operations Limited (The Atrium Building, Block B, Carmanhall Road, Sandyford Business Estate, Dublin 18, Ireland) as part of the order processing. Microsoft Ireland Operations Limited may use Microsoft Corporations in the United States (One Microsoft Way, Redmond, WA 98052-6399, United States of America) as a service provider. The data will only be transmitted if you have given us your consent to do so (Article 6(1)(a) DSGVO).
  6. This cookie will lose its validity after 30 days.
  7. The provision of the above data is neither legally nor contractually required or necessary for the conclusion of a contract. There is no obligation to provide the data. If the data is not provided, we will not be able to carry out ad analysis and optimization using Microsoft Advertising.
  8. There is no automated decision making. We are not aware of any automated decision making by Microsoft regarding the display of advertisements.


b) Facebook Pixel

Through the Facebook Business Tool (Facebook Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin, D02, Ireland), we can place relevant ads for users on the Facebook advertising network (facebook.com, or on partner websites), create reports on campaign performance, build remarketing lists, and create interest-based target groups and lookalikes (so-called statistical twins). For these purposes, the Facebook Pixel is integrated on this website. This informs us how our users move between devices when they visit our website and Facebook and ensures that our ads on Facebook are seen by users who are interested in such ads based on user analytics on our website. By integrating the Facebook Pixel, Facebook receives the information that you have visited our website or clicked on an ad of ours. If you are registered with a Facebook service, Facebook can assign the visit to your account.

  1. Data protection, privacy information and unsubscribe option
  2. The data processed are:
    • Facebook Pixel HTTP data
      This is log data that is technically generated when using the Facebook Pixel on the website via the Hypertext Transfer Protocol Secure (HTTPS). This includes the IP address, type and version of your internet browser, the operating system used, the page accessed, the previously visited page (referrer URL) and the date and time of access.
    • Facebook Pixel end device data
      This is data that is generated by Facebook and assigned to your device. This includes a unique ID to recognize returning visitors.
    • Facebook Pixel measurement data
      This is device-related raw data that is collected and analyzed by the Facebook Pixel when using our website. This includes information on the completion of purchases, the shopping cart, search behavior, as well as individual page views on our website. The data that we collect by means of the Facebook Pixel does not enable us to identify you personally (i.e., based on your civil name). No further personal information about the identity of the user is communicated.
    • Facebook Pixel report data
      This is data contained in aggregated reports and is generated by raw device-related data. This includes information about the effectiveness of advertisements and mapping users to audiences for Facebook ads. Facebook may generate other data based on the information it collects for its own purposes or for the purposes of third parties.
  3. The legal basis for the processing of the data is Art. 6 (1) a) GDPR (consent) in conjunction with Art. 25 of the Act on Data Protection and Privacy of Telecommunications and Telemedia Services (TTDSG).
  4. The data is automatically provided by the user's browser after consent has been given.
  5. The recipients of the data are Facebook Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin, D02, Ireland) as part of the order processing. Facebook Ireland Limited may use Facebook Inc in the USA (1 Hacker Way, Menlo Park, CA 94025, United States of America) as a service provider. The data will only be transmitted if you have given us your consent to do so (Article 6(1)(a) DSGVO).
  6. This cookie will lose its validity after 90 days.
  7. The provision of the above data is neither legally nor contractually required or necessary for the conclusion of a contract. There is no obligation to provide the data. If the data is not provided, we will not be able to carry out ad analysis and optimization using Facebook.
  8. There is no automated decision making. We have no knowledge about the automated decision-making of the ad display by Facebook.


c) Google Ads

The Google Ads advertising service enables the placement of relevant ads in the Google advertising network (e.g., in the search results, or on other websites) and the creation of reports to improve campaign performance. For these purposes, when our website is called up, Google executes a code and integrates so-called remarketing tags into the website. With their help, an individual cookie is stored on the user's device. Remarketing allows us to target users who have already interacted with our website. The cookies can be set by various domains, including google.com, doubleclick.net, googlesyndication.com or googleadservices.com. All user data is processed only as pseudonymous data and we do not receive any information with which we can personally identify users. The ads displayed are therefore not targeted to a person, but to the owner of the cookie.


  1. Data protection, privacy information and unsubscribe option
  2. The data processed are:
    • Google Ads HTTP data
      This is log data that is technically generated when using the Google Ads tool used on the website via the Hypertext Transfer Protocol Secure (HTTPS). This includes IP address, type and version of your internet browser, the operating system used, the page accessed, the previously visited page (referrer URL) and the date and time of access. The cookie ID is also used to determine how often ads are displayed in a browser to control the frequency of ad display.
    • Google Ads Usage Data
      This is data that shows clicks on ads, time spent on the site, and individual site pages visited.
    • Google Ads transaction data
      This is data that summarizes the results of transactions. The data we collect through Google Ads does not allow us to directly identify you personally (i.e., by your civil name). It also does not provide any other personal information about the identity of the user.
  3. The legal basis for the processing of the data is Art. 6 (1) a) GDPR (consent) in conjunction with Art. 25 of the Act on Data Protection and Privacy of Telecommunications and Telemedia Services (TTDSG).
  4. The data is automatically provided by the user's browser after consent has been given.
  5. The recipients of the data are Google Ireland Limited (Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland) within the scope of order processing. Google Ireland Limited uses Google LLC in the USA (1600 Amphitheatre Parkway, Mountain View, CA 94043, United States of America) as a service provider. The data will only be transmitted if you have given us your consent to do so (Article 6(1)(a) DSGVO).
  6. This cookie will lose its validity after 90 days.
  7. The provision of the above data is neither legally nor contractually required or necessary for the conclusion of a contract. There is no obligation to provide the data. If the data is not provided, we will not be able to carry out ad analysis and optimization using Google Ads.
  8. There is no automated decision making. We have no knowledge of the automated decision-making process for the display of advertisements by Google.


d) AWIN

AWIN (AWIN AG, Eichhornstraße 3, 10785 Berlin, Germany) is an affiliate marketing platform and enables commercial operators of websites to place advertisements for other companies that are remunerated via click or sale commission. To protect the data of our website visitors in the best possible way, in this case the data collection and processing is carried out via Hearts & Science Smart Tracking. The prerequisite for this is that the user has reached this website via an advertisement of an advertiser. The purpose of the cookie use is the correct allocation of those advertising media that have been successfully used for a transaction on our website and must be settled. This involves recording whether, when and by what action the advertising material was used by a particular end device.

  1. 1. Data protection and privacy information
  2. The data processed are:
    • Hearts & Science Smart Tracking HTTP data
      This is log data that is generated for technical reasons when using the Hearts & Science Smart Tracking via the Hypertext Transfer Protocol Secure (HTTPS) used on the website. This includes the type and version of your Internet browser, the operating system used, the page accessed, the previously visited page (referrer URL) and the date and time of access.
    • Hearts & Science Smart Tracking Transactions data
      This is device-related raw data that is collected by Hearts & Science Smart Tracking during a transaction on our website. This includes the order value, the OrderID (so-called transaction number) and the shopping cart contents. The information we collect through Hearts & Science Smart Tracking does not enable us to identify you personally (i.e., by your real name). No other personal information about the identity of the user is communicated.
  3. The legal basis for the processing of the data is Art. 6 (1) a) GDPR (consent) in conjunction with Art. 25 of the Act on Data Protection and Privacy of Telecommunications and Telemedia Services (TTDSG).
  4. The data is automatically provided by the user's browser after consent has been given.
  5. The recipients of the data are Hearts & Science München GmbH (Blumenstraße 28, 80331 Munich, Germany) within the scope of order processing. The data will only be transmitted if you have given us your consent to do so (Article 6(1)(a) DSGVO).
  6. This cookie will lose its validity after 14 days.
  7. The provision of the above data is neither legally nor contractually required or necessary for the conclusion of a contract. There is no obligation to provide the data. If the data is not provided, we cannot provide affiliate remuneration via Hearts & Science Smart Tracking.
  8. There is no automated decision making.


e) KUPONA

KUPONA (KUPONA GmbH, Kothenbachweg 6, 36041 Fulda, Germany) is a remarketing partner and enables optimized delivery of advertising campaigns. Each visitor to our website is sent cookies by KUPONA and its processors, which are stored by the browser. Both KUPONA and KUPONA's processors, which are required to implement the service, assign the user a unique ID that is stored in the cookie, to which characteristics of the user's browsing behavior may be stored in the cookie or in the service's database. We are jointly responsible for this with KUPONA. KUPONA collects movement data and technical parameters from users who use our website to be able to display advertising to them according to their interests. We cannot draw any conclusions about the identity of the user.

  1. Data protection and privacy information


f) Lead Alliance

Lead Alliance (lead alliance GmbH, Karlstraße 9, 90403 Nuremberg, Germany) is an advertising service in the field of affiliate marketing, which makes it possible for commercial website operators to display advertising on advertisers' websites, remunerated via click or sale commissions. To protect the data of our website visitors in the best possible way, in this case the data collection and processing is carried out via Hearts & Science Media Smart Tracking. The prerequisite for this is that the user has reached this website via an advertisement of an advertiser. The purpose of the cookie use is the correct allocation of those advertising media that have been successfully used for a transaction on our website and must be settled. This involves recording whether, when and by what action the advertising material was used by a particular end device.

  1. Data protection and privacy information
  2. The data processed are:
    • Hearts & Science Smart Tracking HTTP data
      This is log data that is generated for technical reasons when using the Hearts & Science Smart Tracking via the Hypertext Transfer Protocol Secure (HTTPS) used on the website. This includes the type and version of your Internet browser, the operating system used, the page accessed, the previously visited page (referrer URL) and the date and time of access.
    • Hearts & Science Smart Tracking Transaction Data
      This is device-related raw data that is collected by Hearts & Science Smart Tracking during a transaction on our website. This includes the order value, the OrderID (so-called transaction number) and the shopping cart contents. The information we collect through Hearts & Science Smart Tracking does not enable us to identify you personally (i.e., by your real name). No other personal information about the identity of the user is communicated.
  3. The legal basis for the processing of the data is Art. 6 (1) a) GDPR (consent) in conjunction with Art. 25 of the Act on Data Protection and Privacy of Telecommunications and Telemedia Services (TTDSG).
  4. The data is automatically provided by the user's browser after consent has been given.
  5. The recipients of the data are Hearts & Science München GmbH (Blumenstraße 28, 80331 Munich, Germany) within the scope of order processing. The data will only be transmitted if you have given us your consent to do so (Article 6(1)(a) DSGVO).
  6. This cookie will lose its validity after 14 days.
  7. The provision of the above data is neither legally nor contractually required or necessary for the conclusion of a contract. There is no obligation to provide the data. If the data is not provided, we cannot provide affiliate remuneration via Hearts & Science Smart Tracking.
  8. There is no automated decision making.


g) Pinterest

Through the Pinterest conversion tracking technology (Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland) of the social network Pinterest, we can create relevant ads for users, reports on campaign performance, build remarketing lists, as well as interest-based target groups and lookalikes (so-called statistical twins). For this purpose, a so-called conversion tracking pixel from Pinterest is integrated on our pages, via which Pinterest is informed when you visit our website that you have accessed our website and in which parts of our offer you were interested. If, for example, you have shown interest in one of our products on our website, you may be shown an ad for our products on Pinterest.

  1. Data protection and privacy information
  2. The data processed are:
    • Pinterest Tag HTTP data
      This is log data that is technically generated when the Pinterest tag used on the website is used via the Hypertext Transfer Protocol Secure (HTTPS). This includes the IP address, type and version of your internet browser, the operating system used, the page accessed, the previously visited page (referrer URL) and the date and time of access.
    • Pinterest tag device data
      This is data that is generated by Pinterest and assigned to your device. This includes the device type, the operating system, or a unique device identifier.
    • Pinterest Tag Measurement Data
      This is device-related raw data that is collected and analyzed by the Pinterest tag when using our website. This includes information on the completion of purchases, the shopping cart, search behavior, as well as individual page views on our website. The data that we collect using the Pinterest tag does not allow us to identify you personally (i.e., by your civil name). No further personal information about the identity of the user is communicated.
    • Pinterest Tag Report Data
      This is data contained in aggregated reports and is generated by raw device-related data. This includes information about the effectiveness of ads and mapping users to audiences for Pinterest ads. Pinterest may generate other data from the information it collects for its own purposes or for the purposes of third parties.
  3. The legal basis for the processing of the data is Art. 6 (1) a) GDPR (consent) in conjunction with Art. 25 of the Act on Data Protection and Privacy of Telecommunications and Telemedia Services (TTDSG).
  4. The data is made available automatically by the user's browser after consent has been given.
  5. The recipients of the data are Pinterest Europe Limited (Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland) as part of the order processing. Pinterest Europe Limited may use Pinterest Inc in the USA (505 Brannan Street, San Francisco, CA 94107, United States of America) as a service provider. The data will only be transmitted if you have given us your consent to do so (Article 6(1)(a) DSGVO).
  6. This cookie will lose its validity after 365 days.
  7. The provision of the above data is neither legally nor contractually required or necessary for the conclusion of a contract. There is no obligation to provide the data. If the data is not provided, we cannot carry out ad analysis and optimization using Pinterest.
  8. There is no automated decision making. We have no knowledge about the automated decision-making of the ad display by Pinterest.


h) trbo

TRBO (trbo GmbH, Leopoldstr. 41, 80802 Munich, Germany) is an onsite personalization platform to address customers individually, personally and in real time. In the process, data is collected and stored, from which usage profiles are created using pseudonyms. Cookies can be used for this purpose, which enable the recognition of an Internet browser. These usage profiles are used to analyse visitor behaviour and are evaluated to improve our offer and to design it in line with requirements. The pseudonymised usage profiles are not combined with personal data about the bearer of the pseudonym without the separate consent of the person concerned. We are not informed of any personal information about the identity of the user.

  1. Privacy information and unsubscribe option
  2. The data processed are:
    • trbo HTTP data
      This is log data that is technically generated when the web personalization tool trbo used on the website is used via the Hypertext Transfer Protocol Secure (HTTPS). This includes IP address, type and version of your internet browser, the operating system used, the page accessed, the previously visited page (referrer URL) and the date and time of access.
    • trbo usage data
      This is device-related raw data that is collected and analyzed by trbo when you use our website. For this purpose, pseudonymous usage profiles are created to be able to offer personalized customer benefits. The data that we collect through trbo does not enable us to identify you directly on a personal level (i.e. on the basis of your civil name). Also, no further personal information about the identity of the user is communicated.
  3. The legal basis for the processing of the data is Art. 6 (1) a) GDPR (consent) in conjunction with Art. 25 of the Act on Data Protection and Privacy of Telecommunications and Telemedia Services (TTDSG).
  4. The data is automatically provided by the user's browser after consent has been given.
  5. ecipients of the data are trbo GmbH (Leopoldstr. 41, 80802 Munich, Germany) within the scope of order processing. The data will only be transmitted if you have given us your consent to do so (Article 6(1)(a) DSGVO).
  6. This cookie will lose its validity after the 1095 days.
  7. The provision of the above data is neither legally nor contractually required or necessary for the conclusion of a contract. There is no obligation to provide the data. If the data is not provided, we cannot guarantee the proper use of the website.
  8. There is no automated decision making.


i) Use of Vimeo video


1. Nature and purpose of the processing

Videos from the provider Vimeo LLC, 555 West 18th Street, New York, New York 10011 USA (hereinafter “Vimeo”) are embedded on our website. When you visit a page with the Vimeo plugin, a connection to Vimeo servers is established. This tells Vimeo which pages you are visiting. If you are logged into your Vimeo account, Vimeo can link your surfing behaviour to you personally. You can prevent this by logging out of your Vimeo account beforehand or by not giving us your consent. When a Vimeo video is started, the provider uses cookies that collect information about user behaviour.

2. Legal basis

The legal basis for the integration of Vimeo is your consent in accordance with Art. 6 (1) a) GDPR (consent) in conjunction with Art. 25 of the Act on Data Protection and Privacy of Telecommunications and Telemedia Services (TTDSG).

3. Withdrawal of consent

You may revoke your consent to the processing of personal data at any time with effect for the future. Section 2 Cookie Overview contains information on how to remove cookies. For more information about data protection at Vimeo, please see the provider's privacy policy at: https://vimeo.com/privacy.

4. Provision prescribed or required

The provision of your personal data is voluntary and based solely on your consent. If you block access, this may result in functional restrictions on the website.
Loading...