Privacy policy

Privacy Policy (Data Protection Information under the GDPR)

Status: 29/01/2026
This privacy policy informs you about the type, scope, and purpose of the processing of personal data when visiting and using our online shop.


  1. Controller (Art. 4 No. 7 GDPR)
    NapVibeShop (sole proprietorship)
    Owner: Deniel Dimov Ivanov
    Registered office:
    Austria
    6900 Bregenz
    Holzackergasse 28
    Contact: see imprint / e-mail: support@napvibeshop.com
    Website: napvibeshop.com


  1. Definitions
    Personal data are all information relating to an identified or identifiable person (e.g., name, address, e-mail address, IP address, order data).
    Processing means any operation performed on personal data (e.g., collection, storage, transmission).


  1. Legal bases (Art. 6 GDPR)
    We process personal data on the basis of the following legal bases:
    • Art. 6(1)(a) GDPR (consent) – e.g., newsletter, optional cookies
    • Art. 6(1)(b) GDPR (contract/pre-contractual measures) – e.g., order, delivery, customer account
    • Art. 6(1)(c) GDPR (legal obligation) – e.g., tax retention obligations
    • Art. 6(1)(f) GDPR (legitimate interests) – e.g., secure operation, abuse/fraud prevention, IT security


  1. Hosting & shop platform (Shopify)
    Our online shop is operated via Shopify. Shopify provides the technical infrastructure (hosting, shop system, checkout, database).
    Purposes: operation of the shop, presentation of content, checkout/order process, security, error analysis.
    Legal bases: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR.
    International data transfers (Shopify):
    Depending on the configuration, Shopify may also process data outside the EEA (e.g., Canada/USA). For this purpose, Shopify generally uses appropriate safeguards (e.g., Standard Contractual Clauses pursuant to Art. 46 GDPR and/or adequacy decisions, where applicable).
    Additional note on extended platform functions:
    To the extent that Shopify’s system-side analytics and optimization functions (e.g., “Shopify Network Intelligence” or comparable platform services) are enabled, Shopify may process certain usage and transaction data, in addition to pure technical platform provision, also for its own analytics, product improvement, and optimization purposes. In this context, Shopify may act, to that extent, as an independent controller. Processing takes place in accordance with the contractual arrangements between us and Shopify and Shopify’s privacy notices.


  1. Access data / server log files
    When you visit our website, technically necessary data are processed automatically (so-called log files), in particular:
    • IP address
    • date and time of access
    • pages/files accessed
    • browser type/version, operating system
    • referrer URL (if applicable)
    Purposes: IT security, stability, detection of abuse/attacks, error analysis.
    Legal basis: Art. 6(1)(f) GDPR.


  1. Cookies & consent management (Shopify cookie banner)
    Our website uses cookies and similar technologies. We use the Shopify cookie banner to manage consents.
    Technically necessary cookies are set to make the shop functional (e.g., cart, checkout, security).
    Legal basis: Art. 6(1)(f) GDPR and Section 165(3) TKG 2021.
    Optional cookies (e.g., functional, statistics, marketing) are set only if you have given consent.
    Legal basis: Art. 6(1)(a) GDPR.
    You can change or withdraw your consent at any time via the cookie settings.
    Note on tracking:
    Currently, no external tracking tools (e.g., Google Analytics, Meta Pixel) are actively used. If this changes, this privacy policy will be updated in advance and consent will be obtained via the cookie banner.
    Additional note (Shopify’s built-in functions):
    For technical provision and to optimize shop operations, Shopify’s built-in functions (e.g., security functions and shop statistics) may be used. In doing so, Shopify may also process aggregated and/or technical usage data. This takes place within the scope of platform provision and does not constitute external, individual user tracking by us.

  2. Customer account / login (e-mail + one-time code)
    You can use a customer account. Login is via e-mail address and one-time code (without a classic password). If you already have a Shopify account, a corresponding login may also be possible.
    Processed data: e-mail address, if applicable name, addresses, order history, login/usage data.
    Purposes: account management, order overview, simplified repeat purchases, security.
    Legal basis: Art. 6(1)(b) GDPR.

  3. Order processing & customer service
    When placing an order, we process in particular:
    • name, delivery and billing address
    • e-mail address and telephone number (required for shipping/delivery)
    • order data (products, variants, quantity, prices)
    • payment status, shipping/tracking information
    • communication in connection with the order/support
    Purposes: contract performance, shipping, reversals/returns processing, complaints, customer service.
    Legal basis: Art. 6(1)(b) GDPR.

  4. Contact (e-mail only)
    If you contact us by e-mail, we process the data you provide (e.g., e-mail address, message content, if applicable order reference).
    Purposes: handling your request, communication, traceability.
    Legal basis: Art. 6(1)(b) GDPR (contractual/pre-contractual) or Art. 6(1)(f) GDPR.

  5. Newsletter (Shopify Email) – double opt-in
    If you subscribe to our newsletter, we use the double opt-in procedure. Registration is activated only after clicking the confirmation link.
    Processed data: e-mail address, time of registration/confirmation, if applicable technical evidence.
    Purposes: sending information, offers, and news.
    Legal basis: Art. 6(1)(a) GDPR (consent).
    Unsubscribe is possible at any time (unsubscribe link in the newsletter or message to support@napvibeshop.com).

  6. Payment processing (payment service providers)
    We offer payments via external payment service providers. We do not receive full card or bank account details.
    11.1 Shopify Payments
    When using Shopify Payments, payment data are processed by Shopify and technically carried out via payment processors.
    Payment processing is carried out via Shopify International Limited (Ireland) and technically via Stripe Payments Europe, Ltd. (Ireland) (as part of Shopify Payments in Europe).
    Payment data are processed directly by the respective payment service providers. We do not have access to full card or bank account details.
    Purposes: payment processing, fraud prevention, billing.
    Legal basis: Art. 6(1)(b) GDPR (performance of contract).
    11.2 PayPal
    If you pay via PayPal, personal data are transmitted to PayPal.
    Purpose: payment processing.
    Legal basis: Art. 6(1)(b) GDPR.
    PayPal may process data as an independent controller in accordance with its privacy notices.

  7. Fulfillment / shipping service providers (including possible processing in third countries)
    To fulfill your order, we work with external fulfillment and logistics partners who support the physical order processing (picking, packing, shipping, tracking, delivery). For this purpose, the data required for delivery are transmitted, in particular:
    • name
    • delivery address
    • if applicable telephone number/e-mail (delivery notification/coordination, where required)
    • order data (item/variant/quantity)
    Purposes: picking, packing, shipping, tracking, delivery.
    Legal basis: Art. 6(1)(b) GDPR.
    International data transfers:
    Depending on the shipping route, processing outside the EEA may be necessary (in particular for international fulfillment structures). Under our current operational setup, fulfillment processing takes place predominantly via international logistics and warehouse structures outside the European Economic Area. Depending on availability, shipping route, and operational processing, processing via regional warehouse locations within or outside the EU may also occur in individual cases.
    Where order and shipping data are processed outside the EEA as part of fulfillment, processing or transfer to third countries (e.g., China) cannot be ruled out. Transfer takes place only to the extent of the data required for contract performance (data minimization).

  8. Apps/tools used
    In the Shopify backend, we use, among others, the following tools/apps:
    • Shopify Flow (automations)
    • Translate & Adapt (multilingualism/localization)
    • Messaging (communication functions in the system)
    • fulfillment app for order transmission/processing
    Depending on their function, these applications may access data required to perform the respective task.
    Legal bases: Art. 6(1)(b) GDPR and/or Art. 6(1)(f) GDPR.
    We restrict these apps’ access to data to the absolute minimum necessary for the respective function.

  9. Recipients / categories of recipients
    Personal data may, depending on the process, be transmitted to the following categories of recipients:
    • hosting/shop system provider (shop platform)
    • payment service providers (shop payment systems, PayPal)
    • shipping/logistics/fulfillment partners
    • IT/security and support service providers (where required)

  10. Storage period / deletion
    We store personal data only as long as necessary for the respective purposes and/or as long as legal obligations exist.
    • order and invoice documents: generally 7 years (AT, tax/business retention obligations, in particular pursuant to Section 132(1) BAO)
    • customer account data: until deletion of the account or as long as necessary for account functions and traceability
    • support communication: generally until resolved, then appropriate retention for traceability (typically up to 24 months)
    • newsletter data: until consent is withdrawn
    • server log files: short-term storage for security/error analysis purposes

  11. Data security (Art. 32 GDPR)
    We implement appropriate technical and organizational measures (TOMs) to protect data against loss, misuse, and unauthorized access, in particular:
    • HTTPS/encryption during data transmission
    • role/permission concepts in the backend
    • access restrictions and authentication measures
    • platform-side security and backup mechanisms

  12. Your rights (data subject rights)
    You have in particular the following rights:
    • access (Art. 15 GDPR)
    • rectification (Art. 16 GDPR)
    • erasure (Art. 17 GDPR)
    • restriction of processing (Art. 18 GDPR)
    • data portability (Art. 20 GDPR)
    • objection (Art. 21 GDPR)
    • withdrawal of consents (Art. 7(3) GDPR)
    In particular, you have the right to object at any time to the processing of your data for the purposes of direct marketing.
    Requests should be addressed to: support@napvibeshop.com

  13. Right to lodge a complaint
    You have the right to lodge a complaint with a data protection supervisory authority.
    In Austria: Austrian Data Protection Authority (DSB), Vienna – https://www.dsb.gv.at/

  14. Changes to this privacy policy
    We reserve the right to adapt this privacy policy if technical, legal, or organizational changes require it. The version currently published on our website shall apply.


The German version of this document is legally binding. The English version is provided for informational purposes only.