GDPR (EU 2016/679) — last updated May 2026
The controller responsible for processing personal data on this website is the operator named in the Imprint. For any data-protection enquiry, write to privacy@amstags.com.
Order processing
When you place an order we process your name, shipping address, email address, ordered items, and order total. Legal basis: Art. 6 (1) (b) GDPR (performance of a contract). Retention: 10 years to satisfy tax and commercial-law obligations (Art. 6 (1) (c) GDPR).
Payment
Payments are processed by Stripe Payments Europe, Ltd. (Ireland). We never see or store full card numbers. Stripe receives the information necessary to process the transaction (amount, currency, billing details). See stripe.com/privacy.
Transactional email
We send order confirmations, shipping notifications, and replies to support requests to the address you provide at checkout. Legal basis: Art. 6 (1) (b) GDPR. Every email contains an unsubscribe link for non-essential messages.
Shopping cart
Your cart is stored in your browser's local storage so it survives reloads. It is a strictly necessary technical mechanism and not shared with third parties.
Server logs
Our hosting provider stores standard server logs (IP address, timestamp, requested URL, user agent) for security and troubleshooting. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in operating a secure service). Logs are deleted after 30 days at the latest.
We do not use tracking cookies, advertising cookies, or third-party analytics. Only strictly necessary technical storage is used (cart contents, session state). No consent banner is shown because we set no cookies that require consent under § 25 TTDSG.
Where a processor is located outside the EU/EEA (e.g. Stripe in the USA), transfers are protected by the EU Standard Contractual Clauses pursuant to Art. 46 (2) (c) GDPR.
Under the GDPR you have the right to:
To exercise any of these rights, contact privacy@amstags.com. You also have the right to lodge a complaint with your local data-protection authority (Art. 77 GDPR).
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.
We may update this policy to reflect changes to our service or legal requirements. The current version is always available on this page; the date at the top indicates the last update.