Skip to content
ShopBundlesAbout usDoleray logo

Privacy Policy

1. Privacy at a Glance

General Information

The following notes provide a simple overview of what happens to your personal data when you visit our website. Personal data refers to all data that can personally identify you. For detailed information on the subject of data protection, please refer to our privacy policy below.

Data Collection on This Website

Who is responsible for data collection on this website?
The data processing on this website is carried out by the website operator. You can find the operator's contact details in the section "Notice on the Responsible Party" of this privacy policy.

How do we collect your data?
Your data is collected, firstly, when you provide it to us. This may occur, for example, when entering data into a contact form, registering for our newsletter, or completing a purchase in our shop.

Other data is collected automatically or with your consent when you visit the website through our IT systems. This primarily includes technical data (e.g., internet browser, operating system, or time of the page request). The collection of this data happens automatically as soon as you enter our website.

What do we use your data for?
Part of the data is collected to ensure the error-free provision of the website. Other data may be used to analyze your user behavior or for marketing purposes.

What rights do you have regarding your data?
You have the right at any time to obtain free information about the origin, recipient, and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given your consent to data processing, you can revoke this consent at any time with future effect. Additionally, you have the right, under certain circumstances, to request the restriction of processing of your personal data. Furthermore, you have the right to file a complaint with the competent supervisory authority.

If you have further questions on the topic of data protection, you can contact us at any time.

Analytics Tools and Third-Party Tools

When visiting our website, your surfing behavior may be statistically analyzed. This is primarily done using analysis programs and tracking technologies. The analysis of your surfing behavior is anonymous or pseudonymized and cannot be traced back to you.

Detailed information about these tools and their deactivation options can be found in the complete privacy policy.

2. Hosting

Our website is hosted by an external service provider (hosting provider). Personal data collected on this website is stored on the hosting provider's servers. This may include, in particular, IP addresses, metadata, communication data, website access logs, and other data generated via this website.

Hosting Provider

We host our website with: IONOS SE
Elgendorfer Str. 57
56410 Montabaur
Germany

Data Processing by the Hosting Provider:
IONOS processes data to ensure the technical availability of the website and secure operations. The data collected includes:

  • IP address of the visitor
  • Date and time of the request
  • Information about the browser type and operating system used
  • Referrer URL (the previously visited page)

Legal Basis

The processing of your data by our hosting provider is based on Article 6(1)(f) GDPR. Our legitimate interest lies in the secure and efficient provision of our website. If you have given us your consent, the processing will also take place on the basis of Article 6(1)(a) GDPR.

Storage Period

The data is stored for as long as it is necessary for the respective purpose or in accordance with legal requirements. Log files are usually anonymized or deleted after no later than 7 days.

Further Information

For more information about data processing by IONOS, please refer to the IONOS Privacy Policy.

3. Data Collection on This Website

Cookies and Browser Storage

Our website uses so-called "cookies" and browser storage technologies (localStorage, sessionStorage). Cookies are small files that your browser automatically creates and stores on your device when you visit our website. They do not harm your device and do not contain viruses, trojans, or other malicious software.

Cookie Consent Management (Complianz):

We use a cookie consent management system to obtain and manage your cookie preferences. When you first visit our site, you are presented with a cookie banner that allows you to accept or decline non-essential cookies. The following consent management cookies are set:

  • cmplz_banner-status: Records whether you have dismissed the cookie banner (1 year)
  • cmplz_functional: Functional cookies consent status, always enabled (1 year)
  • cmplz_statistics: Analytics cookies consent status (1 year)
  • cmplz_marketing: Marketing cookies consent status (1 year)
  • cmplz_preferences: Preferences cookies consent status (1 year)
  • cmplz_policy_id: Tracks which version of the consent policy was accepted (1 year)
  • cmplz_consented_services: Records consented services (1 year)

Functional Cookies and Storage:

The following cookies and browser storage entries are set regardless of your consent preferences, as they are necessary for the website to function:

  • pll_language (Cookie): Stores your language preference, English or German (1 year)
  • selected_language (localStorage): Persists your language preference
  • user_geo_data (localStorage): Caches your detected country for pricing purposes
  • cookie_consent_status (localStorage): Stores your consent preferences
  • checkout_form_state (sessionStorage): Preserves your checkout form data during the current browser session
  • newsletterPopupShown (sessionStorage): Prevents the newsletter popup from appearing repeatedly in the same session

Analytics and Marketing Cookies:

Analytics and marketing cookies are only set with your explicit consent (see Sections 7 and 8).

Legal Basis: The use of necessary cookies and functional storage is based on Article 6(1)(f) GDPR, as we have a legitimate interest in ensuring the error-free provision of our services. Other cookies (analytics, marketing) are only set with your consent in accordance with Article 6(1)(a) GDPR.

Cookie Settings: You can change or withdraw your consent at any time via the cookie settings on our website. You can also configure your browser to prevent cookies from being saved. However, disabling cookies may limit the functionality of this website.

Language Detection

On your first visit, we detect your browser's language preference to automatically display the website in German or English. If your browser language is a German variant (e.g., de-DE, de-AT, de-CH), the site is shown in German; otherwise, it defaults to English. You can change the language at any time using the language toggle, and your choice is stored for future visits.

Legal Basis: Article 6(1)(f) GDPR (legitimate interest in providing a localized experience).

Geolocation

When you visit our website, we use a server-side geolocation lookup based on your IP address to determine your country. This is used to display country-specific pricing (including VAT), determine available shipping methods, and check whether we can ship to your region. Your detected country is cached in your browser's local storage. No precise location data (city, coordinates) is stored on the client side.

Legal Basis: Article 6(1)(f) GDPR (legitimate interest in providing accurate pricing and complying with tax regulations).

Server Log Files

Our hosting provider automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These include:

  • Browser type and version
  • Operating system used
  • Referrer URL (the previously visited page)
  • Hostname of the accessing computer
  • Time of the server request
  • IP address

Legal Basis:
The storage of this data is based on Article 6(1)(f) GDPR. We have a legitimate interest in the technically error-free presentation and optimization of our website, for which the server log files must be recorded.

This data is not merged with other data sources and is deleted after no later than 7 days.

Contact via Email

If you contact us by email, your inquiry, including all resulting personal data (e.g., name, contact details, inquiry content), will be stored and processed to handle your request.

Legal Basis:
The processing of this data is based on Article 6(1)(b) GDPR (contractual or pre-contractual measures) or Article 6(1)(f) GDPR (legitimate interest).

Your data will be deleted as soon as your inquiry has been fully processed, provided there are no statutory retention periods.

4. Newsletter

Description and Purpose

We offer you the option to subscribe to our newsletter to regularly receive information about our products, offers, and updates. If you subscribe to our newsletter, we process personal data to provide this service to you.

Collected Data:

  • Email address (mandatory)
  • Date and time of subscription
  • IP address at the time of subscription (to document consent)

Legal Basis: The processing of your data is based on your consent in accordance with Article 6(1)(a) GDPR. You can withdraw your consent at any time with future effect by unsubscribing from the newsletter.

Subscription Process: We use the double opt-in procedure for subscribing to our newsletter. After subscribing, you will receive an email requesting you to confirm your subscription. Your email address will only be added to our distribution list after this confirmation.

Use of MailPoet

We use the WordPress plugin MailPoet by Automattic Inc. for sending our newsletter. The provider is: Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA.

Processing by MailPoet:

  • Storing your data on Automattic's servers.
  • Using the data for sending and analyzing the newsletter.

Data Transfer to the USA:
Automattic is certified under the EU-US Data Privacy Framework (DPF), ensuring an adequate level of data protection.

Analysis of User Behavior:

Our newsletter contains tracking technologies such as counting pixels. This allows us to generate statistical analyses, such as:

  • Whether the newsletter was opened
  • Which links were clicked
  • Time and frequency of interactions

The analysis is pseudonymized and is not merged with other personal data. This analysis serves to optimize our newsletter and is based on your consent in accordance with Article 6(1)(a) GDPR. You can object to this analysis at any time by unsubscribing from the newsletter.

Storage Period: The data you provide as part of the newsletter subscription will be stored as long as you remain subscribed. After unsubscribing, your data will be deleted, provided there are no statutory retention requirements.

Withdrawal of Consent / Unsubscription: You can unsubscribe from the newsletter at any time and withdraw your consent. Use the unsubscribe link provided at the end of each newsletter, the subscription management page on our website, or send a message to info@doleray.com.

5. E-Commerce and Payment Processing

Data Processing by WooCommerce

Our website uses the WooCommerce plugin to provide the functionality of our online shop. The provider of WooCommerce is: Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA.

Data Collected:
As part of your orders, we process the following personal data:

  • First and last name
  • Billing and shipping address
  • Email address
  • Phone number
  • Payment information (handled securely by Stripe)
  • Order and transaction details

Purpose:
The processing of this data is for the purpose of fulfilling your order, including payment processing, delivery, and invoicing.

Legal Basis: Article 6(1)(b) GDPR (contract fulfillment) and Article 6(1)(f) GDPR (legitimate interest in efficient and secure order processing).

Data Transfer:
WooCommerce stores your data on Automattic's servers. This may involve data transfers to the USA. Automattic is certified under the EU-US Data Privacy Framework (DPF), ensuring an adequate level of data protection.

Payment Processing (Stripe)

All payments are processed by Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland.

Available payment methods are provided dynamically through Stripe and may vary depending on your region and availability. Sensitive payment information (card numbers, bank details) is entered directly into Stripe's secure Payment Element and is never transmitted through or stored on our servers.

Data shared with Stripe:

  • Billing and shipping address
  • Email address
  • Order amount and currency
  • Selected shipping method

Processing by Stripe:
Stripe processes this data to handle payments, prevent fraud, and comply with legal obligations. Stripe may transfer data to servers in the United States. Stripe is certified under the EU-US Data Privacy Framework and uses EU Standard Contractual Clauses.

Legal Basis: Article 6(1)(b) GDPR (contract fulfillment) and Article 6(1)(f) GDPR (legitimate interest in secure payment processing).

For more information, refer to the Stripe Privacy Policy.

Address Autocomplete (Geoapify)

During checkout, we offer address autocomplete suggestions powered by Geoapify GmbH, Glogauer Straße 5, 10999 Berlin, Germany.

When you type an address in the checkout form, your input text and country filter are sent to Geoapify's API to retrieve matching address suggestions. No account data or personal identifiers are sent with these requests.

Legal Basis: Article 6(1)(f) GDPR (legitimate interest in providing a convenient checkout experience).

For more information, refer to the Geoapify Privacy Policy.

Storage Period

Your data will be stored as long as necessary to fulfill your order, including statutory retention periods (e.g., tax regulations).

6. Shipping Providers

Data Transfer to DHL

To deliver your order, we work with the shipping provider DHL Paket GmbH, Strässchensweg 10, 53113 Bonn, Germany. To enable the delivery of your order, we transfer the following personal data to DHL:

  • First and last name
  • Shipping address
  • Email address (for delivery notifications, if provided)
  • Phone number (optional, if required for delivery)

Legal Basis: Article 6(1)(b) GDPR (contract fulfillment) and Article 6(1)(f) GDPR (legitimate interest in efficient delivery).

For more information, refer to the DHL Privacy Policy.

Data Transfer to Hermes

We also work with Hermes Germany GmbH, Essener Straße 89, 22419 Hamburg, Germany. The same categories of personal data are transferred to Hermes for the purpose of delivering your order.

Legal Basis: Article 6(1)(b) GDPR (contract fulfillment) and Article 6(1)(f) GDPR (legitimate interest in efficient delivery).

For more information, refer to the Hermes Privacy Policy.

Storage Period

The data is stored only as long as necessary for the delivery process. It will be deleted thereafter unless legal retention obligations exist.

7. Analytics (Consent Required)

Google Analytics

We use Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

By default, all analytics storage is denied. Only when you explicitly consent to "Statistics" in our cookie banner do we enable analytics data collection.

Data Collected (when consented):

  • Pages visited and duration of visit
  • Interactions with website elements
  • IP address (anonymized)
  • Technical information (e.g., browser, device type, operating system)

IP Anonymization: We have enabled IP anonymization. Your IP address will be shortened by Google within the EU or EEA before being transferred to the USA.

Data Transfer to the USA: Google is certified under the EU-US Data Privacy Framework and uses Standard Contractual Clauses (SCC).

Legal Basis: Article 6(1)(a) GDPR (your consent). You can withdraw your consent at any time via the cookie settings on our website.

Opt-Out: You can prevent Google Analytics from collecting your data by adjusting your cookie settings or by installing the Google Analytics Opt-out Browser Add-on.

8. Marketing (Consent Required)

If you consent to marketing cookies in our cookie banner, advertising storage is enabled through Google Tag Manager. This may be used for remarketing and personalized advertising purposes.

By default, all advertising storage is denied until you explicitly consent.

Legal Basis: Article 6(1)(a) GDPR (your consent). You can withdraw your consent at any time via the cookie settings on our website.

9. Social Media Links

Our website contains links to external social media platforms (e.g., Facebook, Instagram). These are simple hyperlinks — no data is shared with these platforms, no plugins are loaded, and no tracking scripts are executed until you click a link and leave our website.

10. Data Transfers to Third Countries

As part of using third-party services, your personal data may be transferred to countries outside the European Union (EU) or the European Economic Area (EEA), in particular to the USA.

Legal Basis for Data Transfers

Personal data is transferred to third countries only under the following conditions:

  • EU-US Data Privacy Framework (DPF): For certified US companies, this ensures an adequate level of data protection.
  • EU Standard Contractual Clauses (SCC): Where no adequacy decision exists, data transfers are based on Standard Contractual Clauses adopted by the European Commission under Article 46 GDPR.
  • Consent: In individual cases, transfers may be based on your consent under Article 49(1)(a) GDPR.

Providers with Data Transfers to Third Countries

  • Google Analytics: Data processed in the USA (DPF certified, SCC)
  • Stripe: Data processed in the USA (DPF certified, SCC)
  • Automattic (WooCommerce, MailPoet): Data processed in the USA (DPF certified)

Your Rights Regarding Data Transfers

You have the right to be informed about the appropriate safeguards related to the transfer of your data. You can object to data transfers based on legitimate interests and withdraw your consent for data transfers at any time through our cookie settings.

11. Returns and Order Inquiries

When you submit a return request through our return request page, we collect:

  • Order number
  • Email address
  • Return items and reasons
  • Preferred refund method

This data is used solely to process your return.

Legal Basis: Article 6(1)(b) GDPR (contract fulfillment).

12. Shipping Providers

To deliver your order, we work with the following shipping providers:

  • DHL Paket GmbH, Sträßchensweg 10, 53113 Bonn, Germany
  • Hermes Germany GmbH, Essener Straße 89, 22419 Hamburg, Germany

The choice of shipping provider is at our discretion and depends on availability in the customer's delivery area.

To fulfill the contract, we transmit your name, delivery address, and where applicable your email address and phone number to the respective shipping provider, insofar as this is necessary for delivery.

Legal Basis: Article 6(1)(b) GDPR (contract fulfillment).

For more information on data protection, see: DHL Privacy Policy | Hermes Privacy Policy

13. Storage Period

The storage duration of your personal data depends on the respective processing purpose and statutory retention obligations:

  • Contract and order data: 6–10 years (German tax and commercial law, §§ 147 AO, 257 HGB)
  • Customer inquiries: Deleted after resolution, unless subject to retention obligations
  • Newsletter subscriber data: Deleted upon unsubscription
  • Server log files: 7 days (anonymized/deleted)
  • Cookie consent preferences: 1 year
  • Browser local storage: Until manually cleared by the user

14. Rights of Data Subjects

As a data subject, you have various rights under the General Data Protection Regulation (GDPR):

Right to Access (Article 15 GDPR)

You have the right to request information about your personal data stored by us at any time, including the purpose of processing, categories of data, recipients, and storage duration.

Right to Rectification (Article 16 GDPR)

If your personal data is incorrect or incomplete, you have the right to request immediate correction or completion.

Right to Erasure (Article 17 GDPR)

You have the right to request the deletion of your personal data if it is no longer necessary, you withdraw consent, or the data was processed unlawfully. This right may be limited by statutory retention obligations.

Right to Restriction of Processing (Article 18 GDPR)

You have the right to request the restriction of processing under certain conditions, such as when you dispute the accuracy of your data.

Right to Data Portability (Article 20 GDPR)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format or to have it transmitted to another controller.

Right to Object (Article 21 GDPR)

You have the right to object to the processing of your personal data if it is based on Article 6(1)(e) or (f) GDPR. You can object to processing for direct marketing purposes at any time.

Right to Withdraw Consent (Article 7(3) GDPR)

You have the right to withdraw your consent at any time with future effect. The legality of processing carried out prior to withdrawal remains unaffected.

Right to Lodge a Complaint (Article 77 GDPR)

If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority. The competent authority in Germany is:

Der Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI)
Graurheindorfer Str. 153
53117 Bonn
Phone: +49 228 997799-0
Email: poststelle@bfdi.bund.de

Exercising Your Rights

To exercise your rights, contact us at: info@doleray.com

15. Data Security

We implement appropriate technical and organizational measures to protect your personal data from unauthorized access, loss, misuse, or destruction. These include:

  • SSL/TLS Encryption: All data transmissions are encrypted. You can recognize this by the "https://" prefix and lock icon in your browser.
  • Firewalls: Protect against unauthorized access to our systems.
  • Regular Security Updates: Keep our systems up-to-date.
  • Access Controls: Only authorized personnel have access to personal data.

Please note that data transmission over the Internet can have security vulnerabilities. Complete protection against third-party access is not possible.

16. Changes to this Privacy Policy

We reserve the right to update this privacy policy to reflect changes in legal, technical, or organizational conditions. The current version is always available on our website.

Date of last update: 03/2026