Privacy
This privacy policy explains which personal data we process when you visit our online shop shop.nobis-printen.de and order from us, why we do so and what rights you have.
1. Controller
Nobis Printen e.K., owner Michael Nobis
Charlottenburger Allee 30, 52068 Aachen, Germany
Phone: +49 241 96 80 00
Email: info@nobisprinten.de
You can reach our data protection officer by email at info@nobisprinten.de (subject “Data protection”) or by post at our address, marked “Data protection officer”.
2. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR) and data portability (Art. 20 GDPR). You can withdraw any consent you have given at any time with effect for the future (Art. 7(3) GDPR). You can change your consent on this website at any time via “Privacy settings” at the bottom of every page.
Right to object (Art. 21 GDPR): Where we process your data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you can object at any time on grounds relating to your particular situation. You can object to processing for direct marketing at any time without giving reasons.
For all requests, a message to info@nobisprinten.de or to our postal address is sufficient.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, www.ldi.nrw.de.
3. Legal bases and storage period
We process your data where this is necessary for a contract with you or for steps prior to entering into a contract (Art. 6(1)(b) GDPR), where we are legally obliged to do so (Art. 6(1)(c) GDPR), where we have a legitimate interest (Art. 6(1)(f) GDPR) or where you have given your consent (Art. 6(1)(a) GDPR). Information is stored on or read from your device (for example cookies) only where this is strictly necessary for the service you have requested (Section 25(2) no. 2 TDDDG, the German Telecommunications Digital Services Data Protection Act), otherwise only with your consent (Section 25(1) TDDDG).
We delete your data as soon as it is no longer needed for the respective purpose. Documents that we are required to keep under commercial and tax law (for example invoices and order data) are kept for the statutory periods (Section 257 German Commercial Code, Section 147 German Fiscal Code) and are blocked for other purposes during this time.
4. Hosting and server logs
Our online shop is hosted by JTL-Software-GmbH, Rheinstraße 7, 41836 Hückelhoven, Germany, which acts on our behalf (Art. 28 GDPR). The servers are located in a data centre in Frankfurt am Main, Germany.
Each time a page is accessed, your browser transmits data for technical reasons, which is stored in server logs: IP address, date and time, page requested, status code, amount of data transferred, the previously visited page, and browser and operating system. Upstream protection against automated access (bot protection) checks requests and shows a verification page if there is suspicion. The purpose is the secure and stable operation of the shop; the legal basis is our legitimate interest (Art. 6(1)(f) GDPR). The logs are deleted after 14 days.
5. Cookies and privacy settings
On your first visit, our privacy settings ask which services you consent to. You can accept, choose or reject; rejecting is as easy as accepting. We store your choice in your browser’s storage (“local storage”) and in your session so that we do not ask you again on every page.
Without your consent, we only set what is strictly necessary for the shop (Section 25(2) no. 2 TDDDG, Art. 6(1)(b) and (f) GDPR): the session cookie “JTLSHOP” for the basket, login and checkout (deleted when you close your browser) and your choice in the privacy settings. The Trusted Shops trustmark (section 11) and, in the basket and checkout, the PayPal payment buttons (section 8) also load without consent. All services in section 13 load only after you have given your consent.
6. Orders and customer account
For your order we need your name, billing and delivery address and email address; your phone number, date of birth, company and VAT number are optional. In addition, there is your order, a preferred shipping date, the text of a greeting card and your comments. We use this data to conclude and perform the contract, to send you confirmations and to answer your questions (Art. 6(1)(b) GDPR). We process orders in our merchandise management system (JTL-Wawi).
A customer account is optional. In it we store your details and orders so that you can order faster and view previous orders. You can have your account deleted at any time under “My account” or by email; after that, we only keep order data for the statutory periods.
To protect the login against misuse, we briefly store an irreversible check value (hash) of your IP address for failed attempts (Art. 6(1)(f) GDPR).
7. Address verification
To make sure your parcel arrives, we check addresses and email addresses as you enter them using the service of Endereco UG (haftungsbeschränkt), Balthasar-Neumann-Str. 4b, 97236 Randersacker, Germany, which acts on our behalf (Art. 28 GDPR). Country, postcode, city, street, house number, address supplement, email address, first name and the shop page you are on are transmitted via our server, not directly from your browser. Endereco suggests corrections; you decide whether to accept them. The legal basis is our legitimate interest in correct delivery (Art. 6(1)(f) GDPR).
To improve this verification, we compare the address you entered with the address you submitted on our own server. We keep the result only for the duration of this evaluation, addresses without names and only where there are differences (Art. 6(1)(f) GDPR).
8. Payment
Payments by PayPal, “Pay Later”, credit and debit card, Apple Pay and Google Pay are processed by PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg. For this purpose we transmit the necessary order data (name, address, email, amount, order number) to PayPal (Art. 6(1)(b) GDPR). PayPal processes the data under its own responsibility and may carry out a credit check depending on the payment method; for details see PayPal’s privacy statement: www.paypal.com/de/legalhub/privacy-full. In the basket and checkout, your browser loads the payment buttons from PayPal’s servers; PayPal receives your IP address and technical information about your browser and device, including for fraud prevention. This is necessary for the payment you have requested (Art. 6(1)(b) and (f) GDPR, Section 25(2) no. 2 TDDDG).
We offer purchase on account after your first paid order. We do not carry out a credit check with a credit agency for this.
9. Shipping
For delivery, we pass your name and delivery address on to the shipping company (Art. 6(1)(b) GDPR): within Germany to DHL Paket GmbH, Sträßchensweg 10, 53113 Bonn, Germany, abroad to United Parcel Service Deutschland S.à r.l. & Co. OHG, Görlitzer Straße 1, 41460 Neuss, Germany. For shipments outside the EU, the information required for customs is added. We do not pass your email address or phone number on to DHL or UPS; the shipping companies therefore do not send you their own parcel notification.
10. Contact, corporate enquiries and withdrawal
If you contact us by email or phone, we use your details to deal with your request (Art. 6(1)(b) GDPR for questions about an order, otherwise point (f)).
Via the enquiry form for corporate gifts we receive your company, contact person, email, optionally phone number, website, quantity, preferred date, your requirements and any files you attach (for example a logo). The enquiry is sent to our team by email and stored in the shop system so that we can refer to it for later questions and repeat orders; it is deleted automatically after three years. Attached files remain on the server only until the email has been sent, for no more than seven days. The legal basis is steps prior to entering into a contract (Art. 6(1)(b) GDPR).
If you declare a withdrawal via “Withdraw contract”, we store your name, order number, email address, your comment and the date and time of receipt and send you an acknowledgement of receipt (Art. 6(1)(c) GDPR in conjunction with Section 356a of the German Civil Code).
11. Trusted Shops
We are a member of Trusted Shops, Trusted Shops SE, Subbelrather Straße 15c, 50823 Cologne, Germany. On our pages we show the Trusted Shops trustmark with our reviews; to do so, your browser loads content from Trusted Shops’ servers, transmitting your IP address, date and time, the page requested and browser information. The legal basis is our legitimate interest in showing you our reviews and the buyer protection (Art. 6(1)(f) GDPR). The trustmark stores technical information in your browser’s session storage, which is deleted when you close your browser.
On the page after your order, Trusted Shops offers you buyer protection and a later review. For this purpose we pass the order number, order value, currency, payment method, estimated delivery date, the items ordered and your email address to Trusted Shops there (Art. 6(1)(f) GDPR). You will only receive an invitation to review by email if you agree to this there (Art. 6(1)(a) GDPR): 14 days after your order and, if you have not yet left a review, a reminder three days later. You can withdraw your consent at any time, for example via the unsubscribe link in the email. Trusted Shops is itself responsible for the buyer protection and the reviews. Details: www.trustedshops.de/impressum/#datenschutz.
12. Newsletter
You will only receive our newsletter if you subscribe to it and confirm your subscription via a link in an email (double opt-in). We store your email address, any optional details and the times of subscription and confirmation in order to be able to prove your consent (Art. 6(1)(a) GDPR). For sending, we use CleverReach GmbH & Co. KG, Schafjückenweg 2, 26180 Rastede, Germany, which acts on our behalf (Art. 28 GDPR). We measure whether a newsletter is opened and which links in it are clicked in order to improve our newsletters; this evaluation is part of your consent. You can unsubscribe at any time via the link in every issue or by email.
13. Analytics and advertising (only with consent)
The following services only load once you have given your consent in the privacy settings (Section 25(1) TDDDG, Art. 6(1)(a) GDPR). Without consent, no data is transmitted to these providers. You can withdraw your consent at any time via “Privacy settings” at the bottom of every page.
The providers also process data in the USA. Google and Meta are certified under the EU-US Data Privacy Framework; these transfers are covered by an adequacy decision of the European Commission (Art. 45 GDPR).
Google Tag Manager
We use Google Tag Manager to integrate Google Analytics and Google Ads. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Tag Manager itself does not evaluate any data, but transmits your IP address to Google when it loads.
Google Analytics 4
With Google Analytics we measure how our shop is used: pages viewed, time spent, where visits come from, device and browser, approximate location, basket and order events with order number and value. For this, Google sets cookies (_ga, _ga_10EZFKR64H, up to two years); Google Analytics 4 does not store full IP addresses. We keep event data in Google Analytics for two months and user-related data for 14 months (the period restarts with every new visit). We have activated Google Signals: if you are signed in to Google and have allowed personalised advertising there, Google links the data to your Google account so that we receive cross-device reports; you can view and delete your activity at myactivity.google.com. When you place an order, we also transmit your email address and contact details to Google Analytics in encrypted form (hash) (“user-provided data”). Google’s privacy policy: policies.google.com/privacy.
Google Ads
We advertise with Google Ads, measure whether an order results from an ad (conversion tracking) and may later show ads to visitors of our shop (remarketing). For this, Google uses cookies and browser storage (for example _gcl_au, _gcl_ls, up to 90 days). When you place an order, we transmit the order number and value; with “enhanced conversions”, we also transmit your email address, phone number, name and address in encrypted form (hash) so that Google can attribute the order to an ad.
Meta Pixel
With the Meta Pixel of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland, we measure the success of our advertising on Facebook and Instagram and may show ads to visitors there. For this, Meta sets a cookie (_fbp, up to 90 days) and receives information about pages visited and orders. We are joint controllers with Meta for the collection and transmission (Art. 26 GDPR); you can find the agreement at www.facebook.com/legal/controller_addendum. Meta’s privacy policy: www.facebook.com/privacy/policy.
14. Links to social networks
At the bottom of every page we link to our profiles on Facebook, Instagram, YouTube, TikTok and LinkedIn. These are simple links: only when you click on them are you taken to the respective network, which then collects its own data.
15. Fonts and data security
We load all fonts from our own server; no data is transmitted to third parties. We transmit all pages in encrypted form (TLS, recognisable by “https” and the padlock symbol in your browser).
16. Changes
We adapt this privacy policy when our shop or the legal situation changes. Last updated: October 2026.