Skip to content

Privacy policy

1C1Y — One Child One Year

Privacy Policy

This Privacy Policy explains how we process your personal data in connection with our offer at 1c1y-shop.com.

 
Contents
  1. Definitions
  2. General Information
  3. Individual Processing Operations
  4. Shopify Analytics
  5. Meta Pixel (Facebook / Instagram)
  6. Microsoft Clarity
  7. Sizekick (Size Advisor)
  8. Google Services
 

Definitions

 

'Personal data' means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

 

'Processing' means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

 

'Controller' means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

 

'Recipient' means a natural or legal person, public authority, agency or another body to which the personal data are disclosed, whether a third party or not.

 

General Information

 

Controller

1C1Y GmbH

Schlossstrasse 18, 74638 Waldenburg, Germany

Phone: (+49) 174 6472295

Email: studio@1c1y.de

 

Data Protection Officer

We have not appointed a data protection officer and are not required to do so.

 

Information on Processing Operations

We indicate the legal basis for each individual processing operation. Where we intend to transfer data to third countries outside the European Union (EU) or the European Economic Area (EEA), this will also be noted.

 

Your Rights as a Data Subject

As a data subject, you have the following rights:

  • Art. 15 GDPR – Right of access You may request information about the personal data we process about you.
  • Art. 16 GDPR – Right to rectification You may request the immediate correction of inaccurate or completion of incomplete personal data.
  • Art. 17 GDPR – Right to erasure You may request the deletion of your stored data, unless statutory retention obligations apply.
  • Art. 18 GDPR – Right to restriction You may request the restriction of the processing of your personal data.
  • Art. 20 GDPR – Right to data portability You may request your data in a structured, machine-readable format or ask for it to be transferred to another controller.
  • Art. 21 GDPR – Right to object You may object to the processing of your personal data.
  • Art. 7 (3) GDPR – Right to withdraw consent You may withdraw any consent you have given at any time with effect for the future.
  • Art. 77 GDPR – Right to lodge a complaint You may lodge a complaint with a supervisory authority. A list of authorities is available at: bfdi.bund.de

To exercise any of the above rights, please contact us using the contact details provided above.

 

Erasure and Restriction of Personal Data

Unless otherwise specified for individual cases in this Privacy Policy, personal data will be deleted once it is no longer necessary for the purposes for which it was collected, provided no statutory retention obligations apply. Tax- and commercial-law relevant data is retained for the statutory periods (generally 10 years).

 

Consent to Transfer of Personal Data to the USA

Where we ask for your consent pursuant to Art. 49(1)(a) GDPR as the legal basis for data transfers to the USA and/or other third countries, the following applies:

Your personal data may be transferred to a country outside the EU/EEA whose data protection standards do not match those of European law. There is a risk that such third countries may not offer an adequate level of protection, and you may have limited or no legal recourse in the event of a violation of your rights.

 

Cookies

We use cookies on our website. Cookies are small text files that your browser automatically creates and stores on your device when you visit our site. They do not cause any harm to your device and contain no viruses or malware.

We use the Shopify shop system, which includes a GDPR-compliant cookie banner allowing you to manage or revoke your cookie preferences at any time.

In connection with newsletter delivery and the use of Klaviyo, cookies or similar technologies may be used to measure interactions with emails (e.g. opens or clicks) and to optimise marketing campaigns. These cookies are only set with your prior consent.

 

Individual Processing Operations

 

Hosting

Our website is hosted on the Shopify platform. The provider is Shopify Inc., 150 Elgin Street, Suite 800, Ottawa, ON, K2P 1L4, Canada. The EU representative is Shopify International Ltd., 2nd Floor, 1-2 Victoria Buildings, Haddington Road, Dublin 4, D04 XN32, Ireland.

In the context of hosting, Shopify processes all data generated on our website on our behalf. An adequacy decision by the EU Commission pursuant to Art. 45 GDPR exists for Canada. Further information: shopify.com/legal/privacy

 

Access Data and Log Files

When you visit our website, information is automatically stored in server log files: IP address, date and time of access, name and URL of the retrieved file, referrer URL, and the browser and operating system used. The legal basis is Art. 6(1)(f) GDPR (legitimate interests).

 

Registration / User Account

You may create a customer account on our website. We collect your name, email address, password, and optionally your address. The legal basis is Art. 6(1)(b) GDPR (contract performance). Data is deleted once the account is closed, provided no retention obligations apply.

 

Contract Data (Orders)

During the order process, we collect: name, delivery and billing address, email address, phone number, payment data, and order history. The legal basis is Art. 6(1)(b) GDPR. Tax- and commercial-law relevant data is retained for 10 years pursuant to Art. 6(1)(c) GDPR.

 

General Contact & Contact Form

When you contact us by email or via the contact form, the data you provide (name, email address, message) is stored to process your enquiry. The legal basis is Art. 6(1)(f) GDPR. Data is deleted once the enquiry has been fully resolved.

 

Newsletter

To subscribe to our newsletter, we require your email address and name. Subscription is handled via a double opt-in process. The legal basis is Art. 6(1)(a) GDPR. You may unsubscribe at any time via the link at the end of every newsletter.

We send our newsletters with a tracking pixel to analyse open and click rates statistically. The data collected is not shared with third parties.

Newsletters are sent via Shopify (Shopify Inc., Canada; adequacy decision in place) and Klaviyo (Klaviyo Inc., 125 Summer Street, Boston, MA 02111, USA; standard contractual clauses pursuant to Art. 46 GDPR). Further information on Klaviyo: klaviyo.com/legal/privacy-notice

 

Direct Email Marketing to Customers

If you are an existing customer, we may use your email address for direct marketing of similar products or services, provided you have not objected (§ 7(3) UWG, Art. 6(1)(f) GDPR). Technical delivery is handled via Shopify and Klaviyo (standard contractual clauses pursuant to Art. 46 GDPR).

 

Payment Service Providers

PayPal

Provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg. Legal basis: Art. 6(1)(b) GDPR. Privacy policy: paypal.com/de/webapps/mpp/ua/privacy-full

Shopify Payments

Credit card payments are processed via Shopify and its payment partners (incl. Stripe). Legal basis: Art. 6(1)(b) GDPR. Further information: shopify.com/legal/privacy

 

Social Media Buttons

Pinterest Pin-It Button

Provider: Pinterest Inc., 505 Brannan Street, San Francisco, CA 94107, USA. Data is only transferred upon an active click. Legal basis: Art. 6(1)(f) GDPR. Privacy policy: policy.pinterest.com/de/privacy-policy

Facebook Plugins

Provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. Data is only transferred upon an active click. Legal basis: Art. 6(1)(f) GDPR. Privacy policy: facebook.com/privacy/explanation

 

Klaviyo (Email Marketing & Marketing Automation)

Provider: Klaviyo Inc., 125 Summer Street, Floor 6, Boston, MA 02111, USA. Klaviyo processes on our behalf: name, email address, purchase behaviour, and open/click rates, to enable newsletter delivery and personalise content. Legal basis: Art. 6(1)(a) and/or (f) GDPR. Transfers to the USA are safeguarded by standard contractual clauses pursuant to Art. 46 GDPR. Further information: klaviyo.com/legal/privacy-notice

 

Shopify Analytics

 

We use Shopify's built-in analytics functions to evaluate user behaviour on our website and improve our offering. The following data is processed, among other things:

  • Page views and pages visited
  • Time on site and navigation paths
  • Device and browser information
  • Visitor origin (traffic sources)
  • Conversion data (e.g. completed orders, cart abandonments)

Processing is carried out by Shopify on our behalf on the basis of Art. 6(1)(f) GDPR (legitimate interest in optimising our offering). Data may be transferred to Shopify Inc. in Canada; an adequacy decision is in place. Further information: shopify.com/legal/privacy

 

Meta Pixel

 

We use the Meta Pixel provided by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland ('Meta'). The Meta Pixel is an analytics and advertising tool that allows us to measure the behaviour of visitors to our website and to display targeted advertisements on Facebook and Instagram.

The Meta Pixel collects and transmits the following data to Meta, among other things:

  • IP address and browser information
  • Pages visited on our website
  • Products viewed and add-to-cart events
  • Completed purchases (conversion tracking)
  • Hashed email address of logged-in users, where applicable

This data is used to measure conversions, serve personalised advertisements on Meta platforms, and to create 'Custom Audiences' and 'Lookalike Audiences'.

The legal basis is your consent pursuant to Art. 6(1)(a) GDPR. You may withdraw your consent at any time via our cookie banner.

Data is transferred to the USA on the basis of the EU–US Data Privacy Framework (adequacy decision of 10 July 2023) and supplementarily on the basis of standard contractual clauses pursuant to Art. 46 GDPR. With regard to the Meta Pixel, we are joint controllers with Meta within the meaning of Art. 26 GDPR.

Opt-out: facebook.com/settings?tab=ads — Meta privacy policy: facebook.com/privacy/explanation

 

Microsoft Clarity

 

We use Microsoft Clarity, a behavioural analytics tool provided by Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA ('Microsoft'). Microsoft Clarity allows us to analyse user behaviour through heatmaps and session recordings in order to improve the usability of our shop.

Microsoft Clarity collects and processes the following data, among other things:

  • Mouse movements, scroll behaviour and clicks
  • Page views and navigation paths
  • Session recordings (recordings of user sessions)
  • Heatmap data (aggregated visualisation of interaction points)
  • IP address (anonymised), device and browser information

Please note: Session recordings may indirectly capture personal data if users enter text into form fields. Microsoft Clarity uses automatic masking functions to hide sensitive fields (e.g. passwords, payment data).

The legal basis is your consent pursuant to Art. 6(1)(a) GDPR. Data is transferred to the USA on the basis of the EU–US Data Privacy Framework and supplementarily on the basis of standard contractual clauses pursuant to Art. 46 GDPR. We have entered into a data processing agreement with Microsoft pursuant to Art. 28 GDPR.

Further information: privacy.microsoft.com/en-us/privacystatement

 

Sizekick

 

On our product pages, we offer the 'Sizekick' size advisor tool to help visitors find the right clothing size. The following data may be collected and processed during use:

  • Body measurements (e.g. height, weight, body shape)
  • Fit preferences

This data is used exclusively to calculate a size recommendation. Use of the tool is voluntary. The legal basis is Art. 6(1)(a) GDPR (consent). Please note that body measurements may, depending on context, qualify as a special category of personal data.

For further information on data processing, please refer to Sizekick's own privacy policy.

 

Google Services

 

The Google services described below are only used on the basis of your prior consent pursuant to Art. 6(1)(a) GDPR. You may withdraw your consent at any time via our cookie banner.

 

Google Analytics

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics uses cookies and similar technologies to analyse the behaviour of website visitors. The following data is processed, among other things:

  • IP address (anonymised; the last octet is truncated before transmission to Google)
  • Pages visited and time on site
  • Origin of visit (referrer)
  • Device, browser and operating system
  • Conversion events (e.g. purchases, newsletter sign-ups)

We have concluded a data processing agreement with Google pursuant to Art. 28 GDPR. Transfers to the USA are made on the basis of the EU–US Data Privacy Framework and supplementarily on the basis of standard contractual clauses.

Opt-out: tools.google.com/dlpage/gaoptout — Privacy policy: policies.google.com/privacy

 

Demographic Features in Google Analytics

We use the 'Demographic Features' function in Google Analytics to create anonymised statistics on age groups, gender and interests of website visitors. The data originates from Google's interest-based advertising and cannot be traced back to individuals. Legal basis: Art. 6(1)(a) GDPR.

 

Google Tag Manager

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The Google Tag Manager does not itself process any personal data, but manages and fires other tags and scripts on our website. Legal basis: Art. 6(1)(f) GDPR. Further information: marketingplatform.google.com

 

reCAPTCHA

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google reCAPTCHA protects our forms against spam and abuse. In doing so, user inputs, IP address and browser data are transmitted to Google. Legal basis: Art. 6(1)(f) GDPR. Further information: policies.google.com/privacy

 

Google Fonts

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. When a page is loaded, your browser retrieves the required fonts from Google's servers, transmitting your IP address in the process. Legal basis: Art. 6(1)(f) GDPR. Further information: policies.google.com/privacy

 

© 2026 — 1C1Y GmbH, Waldenburg

Last updated: April 2026