Last updated: May 01, 2026
We appreciate your interest in our online shop, our website and our products. The protection of your personal data is important to us.
In this Privacy Policy, we inform you about which personal data we collect, how we use it, for which purposes processing takes place, which categories of service providers may be used and which rights you have.
This Privacy Policy applies to the online shop, the website, all connected functions, tools, products, services, communication channels, payment, shipping, tracking, returns, marketing, analytics and support processes of Magic Milk Germany.
1. Controller
The controller responsible for the processing of personal data is:
Magic Milk Germany – Mertorhan Avci
Weidenauer Straße 174
57076 Siegen
Germany
Email: support@magicmilk.de
WhatsApp/Phone: +49 15565 408252
Within the meaning of the General Data Protection Regulation, GDPR, we are the controller for the processing of personal data unless otherwise stated in this Privacy Policy.
2. General Information on Data Processing
We process personal data only to the extent necessary to provide our website, process orders, process payments, carry out deliveries, respond to customer inquiries, fulfill legal obligations, protect our systems, prevent fraud, carry out marketing activities or technically and economically improve our shop.
Where consent is required for certain processing activities, processing will only take place after your consent has been given, for example via our cookie or consent banner. You may withdraw consent at any time with effect for the future.
Certain functions of our shop are technically necessary for the shop to function properly. These include, in particular, shopping cart, checkout, payment processing, language settings, security, fraud prevention, server logs and basic shop functions.
Non-essential functions such as marketing tracking, personalized advertising, analytics, session recording, replay functions, certain conversion tracking functions or comparable technologies are only used where legally permissible and, where required, based on corresponding consent.
3. Personal Data We Process
Depending on how you interact with our shop, website or services, we may process in particular the following categories of personal data:
Contact data
Name, first name, last name, address, shipping address, billing address, email address, phone number, WhatsApp number and other contact details.
Order data
Order number, purchased products, shopping cart, checkout data, order time, payment status, shipping status, return status, complaint information, customer notes, order history and other information related to your order.
Payment data
Payment method, payment status, transaction data, payment confirmation, refund data, payment disputes, chargeback information and other data related to payment service providers, banks or payment processors.
Complete payment data such as full credit card numbers are generally not stored directly by us, but are processed by the respective payment service provider.
Communication data
Messages by email, contact form, chat, WhatsApp, AI-supported chat, voice functions, voice messages, support inquiries, return and complaint requests, withdrawal declarations and other content that you voluntarily transmit to us.
Technical data
IP address, device information, browser type, operating system, screen resolution, language settings, referrer URL, date and time of access, visited pages, clicks, scrolling behavior, loading times, error logs, session IDs and similar technical information.
Marketing and usage data
Newsletter subscriptions, SMS marketing consents, email openings, link clicks, abandoned carts, purchase interests, product views, interactions with advertising, ad clicks, conversion events, checkout events and comparable usage information.
Return, complaint and evidence data
Photos of the product, photos of the packaging, photos of the shipping label, description of the defect, tracking information, return status, reason for return, communication history and other information for reviewing returns, complaints or shipping problems.
4. Sources of Personal Data
We receive personal data in particular from the following sources:
Directly from you
For example, when you place an order, create a customer account, contact us, complete a form, use our chatbot, use a voice function, subscribe to the newsletter or submit a return, complaint or withdrawal.
Automatically through our website and systems
For example, through cookies, pixels, tags, tracking technologies, server logs, analytics tools, session recording tools or technical security functions.
From service providers and partners
For example, from shop platforms, payment service providers, shipping carriers, tracking providers, return portals, marketing tools, email service providers, support tools, AI/chatbot providers, review services or other technical providers.
5. Purposes of Processing
We process personal data in particular for the following purposes:
Provision of the online shop
Displaying the website, shopping cart function, checkout, product selection, customer account, technical security, language settings, loading time optimization and troubleshooting.
Order and contract processing
Processing orders, payment processing, shipping, shipment tracking, invoicing, returns, complaints, withdrawal, customer service and other contract-related processes.
Communication with customers
Responding to inquiries, sending order confirmations, shipping information, invoices, payment information, support messages, return information, complaint responses and important notifications.
Security and fraud prevention
Detection of misuse, fraud attempts, payment issues, manipulation, technical attacks, unusual activities, false evidence, abusive refund requests and violations of our terms.
Marketing and advertising
Newsletters, discount campaigns, SMS marketing, cart reminders, personalized offers, onsite messaging, advertisements, conversion tracking, audience building and optimization of advertising campaigns.
Analytics and optimization
Improving our website, detecting technical errors, optimizing the checkout process, improving the user experience, evaluating shop performance, detecting abandonment points and improving support processes.
Legal obligations and legal enforcement
Fulfillment of tax, commercial and statutory retention obligations, handling disputes, payment objections, chargebacks, payment provider cases, evidence, complaints, claims and legal rights.
6. Legal Bases for Processing
The processing of personal data takes place depending on the purpose on the basis of the following legal bases:
Art. 6(1)(b) GDPR
Processing for the performance of a contract or to take steps prior to entering into a contract, for example ordering, payment, shipping, invoicing, support, returns and reversal.
Art. 6(1)(c) GDPR
Processing for compliance with legal obligations, for example tax and commercial retention obligations.
Art. 6(1)(f) GDPR
Processing based on legitimate interests, for example fraud prevention, IT security, internal organization, enforcement of legal claims, technical improvement, detection of misuse and documentation of support or dispute cases.
Art. 6(1)(a) GDPR
Processing based on your consent, for example for non-essential cookies, marketing tracking, newsletters, SMS marketing, certain analytics functions, session recording, voice/AI functions, personalized advertising or comparable technologies, where consent is required.
7. Shop Platform and Technical Operation
Our online shop is operated through an external e-commerce platform. This provides us with the technical shop infrastructure through which we sell products, process orders, connect payments, organize shipping processes, integrate apps or extensions and manage our shop.
Personal data may be transmitted to and processed by the shop platform and connected technical service providers, in particular:
– Name
– Address
– Email address
– Phone number
– Order data
– Payment status
– Shipping information
– Device and usage data
– IP address
– technical shop and checkout data
The processing takes place to provide the shop, process contracts, ensure technical security, troubleshoot errors and manage shop functions.
8. Services, Apps and Technical Providers Used
We use various technical service providers, shop extensions, platforms and external providers to provide our online shop, process orders, process payments, organize shipping and returns, provide customer service, carry out marketing activities, improve usability and protect our systems.
Depending on the function, in particular the following categories of service providers may be used:
– shop and hosting platforms
– payment service providers and payment processors
– shipping, fulfillment, tracking and return service providers
– invoice, document and accounting service providers
– email, newsletter and SMS marketing service providers
– customer service, chatbot, AI and voice service providers
– analytics, tracking, session recording and optimization service providers
– marketing, advertising and conversion tracking service providers
– review, loyalty and customer retention service providers
– form, withdrawal and complaint service providers
– translation, localization and language service providers
– design, theme, landing page and display service providers
– upsell, cross-sell, discount and checkout optimization service providers
– security, fraud prevention and IT service providers
These providers process personal data only to the extent necessary for the respective purpose, permitted by law or covered by corresponding consent.
Depending on the function, in particular contact data, order data, payment status, shipping data, tracking data, return data, communication data, technical data, usage data, marketing data or support data may be processed.
Where providers act as processors, processing takes place on the basis of corresponding contractual agreements. Where providers process personal data under their own responsibility, the privacy notices of the respective provider also apply.
Upon request, we will inform you which specific service providers were involved in the processing of your personal data in the individual case, insofar as we are legally obliged to do so and no legitimate interests conflict with this.
9. Payment Service Providers
We use external payment service providers for payment processing. Depending on the selected payment method, personal data may be transmitted to payment service providers.
The following data may be processed in particular:
– Name
– Billing address
– Shipping address
– Email address
– Phone number
– Order number
– Payment amount
– Payment status
– Transaction data
– risk assessment data
– data related to refunds, payment disputes or chargebacks
The processing takes place for payment processing, fraud prevention, verification of payment claims, handling refunds and processing disputes.
Please note that payment service providers may also process personal data under their own responsibility. The privacy information of the respective payment service provider also applies.
10. Payment Information and Onsite Notices
Payment methods, installment payment information, invoice purchase notices, payment terms or other payment information may be displayed directly in our shop, on product pages, in the shopping cart or during checkout.
Where necessary and legally permissible, technical data, device information, cart data, order data or payment information may be processed in order to check the availability of certain payment methods, display payment options or process payments.
Where external payment providers process personal data under their own responsibility, their privacy notices also apply.
11. Shipping, Fulfillment, Tracking and Returns
We work with shipping carriers, fulfillment providers, tracking providers and return solutions to process and deliver orders.
For this purpose, in particular the following data may be processed or shared:
– Name
– Shipping address
– Billing address
– Email address
– Phone number
– Order number
– Tracking number
– Shipping carrier
– Shipping status
– Delivery status
– Return information
– Complaint information
– Address verification data
– Customs and shipping documents, where required
We use this data to ship orders, track shipments, identify delivery issues, process returned shipments, handle returns, inform customers about shipping status and review shipping or complaint cases.
12. Invoices, Documents and Accounting
We may use invoice, document and accounting services to create, manage and send invoices, credit notes, pro forma documents or other order documents.
In particular, the following data may be processed:
– Name
– Billing address
– Shipping address
– Email address
– Order number
– Order date
– purchased products
– prices
– tax information
– payment status
– invoice number
– shipping country
– business data, if provided
The processing takes place to create legally or commercially required documents, for invoicing, accounting, tax documentation and customer communication.
13. Customer Service, Contact and Support
When you contact us, we process the data you provide in order to handle your inquiry.
This applies in particular to inquiries via:
– email
– WhatsApp
– contact form
– chat
– AI-supported chat
– voice function
– social media
– return center
– complaint request
– withdrawal center
In particular, the following data may be processed:
– Name
– Email address
– Phone number
– Order number
– message content
– photos or evidence
– shipping and payment information
– technical data related to the inquiry
The processing takes place for handling your inquiry, documentation, problem solving, fraud prevention, quality assurance and safeguarding our legitimate interests.
14. AI-Supported Customer Support, Chatbot and Voice Functions
We may use AI-supported support functions to answer customer inquiries more quickly, provide information and improve our customer service.
If you use our AI chatbot, voicebot, voice functions or comparable AI-supported support services, in particular the following data may be processed:
– text inputs
– chat histories
– voice inputs or voice messages
– technical device and browser information
– time of communication
– order numbers, if voluntarily provided by you
– content of your inquiry, for example regarding order, shipping, payment, return, complaint or products
The processing takes place in order to answer your inquiry, document support processes, prevent misuse, improve the quality of our customer service and optimize internal processes.
Please do not provide unnecessary sensitive information in the chat or when using voice functions, in particular no health data, payment data, passwords or particularly confidential information.
Where AI or voice functions are provided by external providers, data may be transmitted to these providers and processed there on our behalf. Where consent is required for this, processing takes place only based on your consent.
We do not use voice inputs for biometric identification unless this is expressly stated separately and legally permissible.
15. Analytics, Session Recording, Replay Functions and Technical Optimization
We may use analytics and optimization tools to better understand the use of our website, detect technical errors, analyze checkout problems, prevent fraud attempts and improve usability.
For this purpose, in particular the following data may be processed:
– IP address
– browser and device information
– operating system
– screen resolution
– visited pages
– clicks
– scrolling behavior
– mouse movements
– navigation behavior
– shopping cart and checkout interactions
– technical errors
– loading times
– time and duration of the visit
– pseudonymous user identifiers
We may also use session recording or replay tools with which individual user sessions can be technically reproduced or recorded. Such recordings serve in particular to identify technical errors, display problems, usability problems, checkout drop-offs, fraud attempts or other disruptions.
Where possible, sensitive input fields such as payment data, passwords or comparable confidential information are hidden or masked.
Session recording, analytics and tracking technologies are used only where legally permissible. Where consent is required, processing takes place exclusively based on your consent via our cookie or consent banner.
16. Live Visitor Counters, Social Proof and Real-Time Displays
We may use functions that display certain notices to visitors, for example live visitor numbers, recently purchased products, social proof elements, pop-ups, discount notices or comparable displays.
For this purpose, technical data, usage data, product interactions, device information, cart data or pseudonymous identifiers may be processed.
Where such functions merely support technically necessary shop functions, processing may be based on legitimate interests or contract performance. Where tracking, profiling, marketing or non-essential technologies are used, processing takes place only where legally permissible and, where required, based on your consent.
17. Cookies, Pixels, Tags and Similar Technologies
Our website uses cookies, pixels, tags, local storage technologies and similar technologies.
These technologies may be necessary to technically provide the website, save the shopping cart, enable checkout, store language settings, ensure security or detect errors.
In addition, where you have given consent, we may use non-essential technologies, for example for:
– analytics
– marketing
– conversion tracking
– personalized advertising
– cart reminders
– session recording
– replay functions
– A/B testing
– optimization of user experience
– social proof
– pop-ups
– upsells and cross-sells
You can withdraw or adjust your consent at any time through the cookie or privacy settings of our website.
18. Marketing, Advertising and Conversion Tracking
We use marketing and advertising services to promote our products, evaluate advertising campaigns and optimize our ads.
Pixels, cookies, tags, server-side tracking or similar technologies may be used for this purpose.
In particular, the following data may be processed:
– page views
– product views
– clicks
– cart events
– checkout events
– purchases
– order values
– device and browser information
– IP address
– pseudonymous user identifiers
– interactions with advertisements
This data may be used to measure advertising campaigns, create audiences, optimize ads, build lookalike audiences and show you interest-based advertising on third-party platforms.
The processing takes place only where legally permissible. Where consent is required, processing takes place exclusively based on your consent via our cookie or consent banner.
19. Newsletter, Email Marketing and SMS Marketing
If you subscribe to our newsletter, discount campaigns, SMS notifications or comparable marketing communications, we process the contact data you provide.
This includes in particular:
– email address
– phone number
– name, if provided
– consent status
– time of registration
– email opens
– link clicks
– unsubscribes
– cart and purchase interests
– order and product interactions
We use this data to send you relevant offers, product information, discount codes, reminders, cart reminders and other marketing information.
Sending may be carried out via external email, newsletter or SMS marketing service providers.
You can unsubscribe from receiving marketing communications at any time via the unsubscribe link in the respective message or by contacting us.
20. Upsells, Cross-Sells, Discounts and Checkout Optimization
We may use functions to display suitable product suggestions, bundles, discounts, additional offers, notices, payment options or upsell offers to you in the shop, shopping cart or checkout.
For this purpose, in particular the following data may be processed:
– cart contents
– product views
– purchased products
– order value
– discount usage
– checkout status
– device data
– pseudonymous user identifiers
Where such functions are necessary for sale, shopping cart or checkout, processing may take place for contract performance or based on legitimate interests. Where tracking, marketing or profiling also takes place, processing occurs only where legally permissible and, where required, based on your consent.
21. Reviews, Feedback, Loyalty and Customer Retention
We may use review, feedback, loyalty or customer retention functions to collect reviews, manage customer points, offer discount campaigns or evaluate customer satisfaction.
For this purpose, in particular the following data may be processed:
– name or display name
– email address
– order number
– purchased products
– review text
– star rating
– photos or videos
– product reference
– points or reward status
– discount or referral data
Reviews, feedback or user-generated content may be used to improve our products, our service and our website. Where reviews are published, this takes place only to the legally permissible extent.
22. Social Media and Embedded Content
We operate profiles on social networks and platforms.
If you interact with our profiles, send messages, comment on posts or share content, personal data may be processed by us and by the respective platform.
Our website may also embed social media content, feeds, story elements, videos or widgets.
Technical data such as IP address, device information, usage data or interactions with embedded content may be transmitted to the respective providers. Where consent is required for this, embedding takes place only after your consent.
The platform providers may process data partly under their own responsibility. Please also note the privacy notices of the respective platform.
23. Translation, Language and Localization Functions
We may use translation, language and localization services to provide content in multiple languages, store language settings or adapt the shop for different countries.
In particular, language settings, technical data, location information at country level, browser data or usage data may be processed.
24. Design, Theme, Landing Page and Display Functions
We may use technical functions to visually design our website, create landing pages, improve product pages, provide sliders, animations, preloaders, menus, buttons, buy-box elements or other design elements.
Depending on the technical implementation, technical data, device information, usage data or cookies may be processed. Where this processing is necessary for the display and functionality of the shop, it may be based on legitimate interests or contract performance. Where tracking, analytics or marketing also takes place, this occurs only where legally permissible and, where required, based on your consent.
25. Centers, Withdrawal, Returns and Complaints
If you use centers or request functions on our website, for example contact requests, withdrawal requests, return requests or complaint requests, we process the data entered by you in order to handle your matter.
In particular, the following data may be processed:
– name
– email address
– phone number
– order number
– address
– reason for return
– reason for complaint
– photos and evidence
– message content
– shipping or tracking information
The processing takes place to handle your request, carry out returns or complaints, documentation and legal enforcement.
26. Complaints, Evidence, Photos and Documentation
If you report a complaint, transport damage, incorrect delivery, missing goods or an issue with the shipment, we may request evidence for review.
This may include in particular:
– photos of the product
– photos of the packaging
– photos of the shipping label
– description of the defect
– order number
– communication history
– tracking information
We process this data to review the matter, evaluate replacement shipments, reshipments or refunds, prevent misuse and assert claims against shipping carriers or third parties.
Submitted evidence must be genuine, unaltered and verifiable. In case of suspected manipulated, AI-generated, misleading or intentionally false evidence, we reserve the right to document the matter, request further evidence and have it legally reviewed.
27. Recipients of Personal Data
We may share personal data with the following categories of recipients:
– shop and hosting platforms
– shop app and technical service providers
– payment service providers
– banks and payment processors
– shipping carriers
– fulfillment and warehouse service providers
– tracking and return providers
– email and newsletter providers
– SMS and communication providers
– AI, chatbot and voicebot providers
– analytics and tracking providers
– marketing and advertising platforms
– review and loyalty providers
– design, theme and landing page providers
– center and support service providers
– IT, hosting and cloud service providers
– tax advisors, accounting and invoice service providers
– authorities, courts, lawyers or other bodies where legally required or necessary for legal enforcement
Data is shared only to the extent necessary for the respective purposes, legally permitted or covered by your consent.
28. International Data Transfers
Some service providers may process personal data outside the European Union or the European Economic Area, in particular in the USA, Canada, the United Kingdom or other third countries.
Where personal data is transferred to third countries, this takes place only where an appropriate legal basis exists. This may include, in particular, adequacy decisions, standard contractual clauses or other appropriate safeguards.
29. Storage Period
We store personal data only for as long as necessary for the respective purposes or as long as statutory retention obligations exist.
Order, invoice and payment data are generally stored for the duration of statutory commercial and tax retention periods.
Support, complaint, return, payment dispute and chargeback data are stored for as long as necessary for processing, documentation, legal enforcement or defense.
Data processed based on consent is generally stored only until consent is withdrawn or the purpose ceases to apply, unless another legal basis exists for further storage.
30. Security
We take appropriate technical and organizational measures to protect personal data against loss, misuse, unauthorized access, alteration or disclosure.
Please note, however, that no data transmission on the internet is completely secure. We recommend that you do not transmit particularly sensitive data via insecure communication channels.
31. Children’s Data
Our website and services are not directed at children. We do not knowingly collect personal data from children who cannot validly consent under applicable law.
If you believe that a child has transmitted personal data to us, you may contact us so that we can review the matter and delete the data if necessary.
32. Obligation to Provide Data
The provision of certain personal data is necessary to execute an order, process payments, ship goods, create invoices or handle support requests.
If you do not provide required data, we may not be able to process your order, request, return, complaint or other service, or may not be able to process it completely.
33. Automated Decision-Making
We do not use personal data for exclusively automated decisions with legal effect or similarly significant impact unless expressly stated.
Payment service providers, fraud prevention providers, payment providers or checkout services may, however, carry out their own automated checks, for example for payment approval, risk assessment, fraud prevention or availability of certain payment methods. The privacy information of the respective provider also applies.
34. Your Rights
Subject to the statutory requirements, you have in particular the following rights:
Right of access
You may request information about which personal data we process about you.
Right to rectification
You may request correction of inaccurate or incomplete data.
Right to erasure
You may request deletion of your personal data, provided that no statutory retention obligations or other legitimate reasons prevent deletion.
Right to restriction of processing
Under certain conditions, you may request restriction of processing.
Right to data portability
You may request that we provide certain data to you in a structured, commonly used and machine-readable format.
Right to object
You may object to the processing of personal data where processing is based on legitimate interests.
Right to withdraw consent
You may withdraw consent at any time with effect for the future.
Right to lodge a complaint
You have the right to lodge a complaint with a competent data protection supervisory authority.
For North Rhine-Westphalia, this is in particular:
State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia
Kavalleriestraße 2–4
40213 Düsseldorf
Germany
To exercise your rights, you may contact us at any time:
support@magicmilk.de
35. Cookie and Consent Settings
Where we use cookies, pixels, tracking, analytics, marketing, session recording, voice or AI functions based on your consent, you may withdraw or adjust your consent at any time with effect for the future.
You can change your settings via our cookie or consent banner or via the privacy/cookie settings provided on our website.
36. Objection to Direct Advertising
If we process personal data for direct advertising, you may object to this processing at any time.
If you object, your personal data will no longer be used for direct advertising.
For newsletters or marketing emails, you may also use the unsubscribe link in the respective message.
37. Changes to This Privacy Policy
We may update this Privacy Policy from time to time, for example if our processes, services used, legal requirements, shop functions or technical systems change.
The current version is available on our website.
38. Contact
If you have questions about this Privacy Policy, the processing of your personal data, our apps, tools, cookies, tracking, AI or voice functions, or if you wish to exercise your rights, you may contact us:
Magic Milk Germany – Mertorhan Avci
Weidenauer Straße 174
57076 Siegen
Germany
Email: support@magicmilk.de
WhatsApp/Phone: +49 15565 408252