Privacy Policy
Protecting your personal data is a particular concern of ours. We therefore process your data exclusively on the basis of the legal provisions (GDPR, Austrian TKG 2021).
Security — TLS (Transport Layer Security)
The order process is transmitted via TLS (Transport Layer Security). We encrypt your data to prevent unauthorised access and ensure that the information reaches only the intended server.
Controller
The controller within the meaning of the GDPR is Adelwöhrer & Puffer OG.
Address: Prankergasse 49, 8020 Graz, Österreich · VAT ID: ATU82108559.
Reachable by email at office@alpenhigh.eu.
Data Protection Officer
No Data Protection Officer has been appointed; there is no obligation to designate one under Art. 37 GDPR.
Hosting
AlpenHigh is operated on Hetzner servers in Germany (EU data centres Falkenstein/Nuremberg). No transfer of data to third countries takes place unless explicitly indicated. We use no CDN — page delivery comes directly from the Hetzner origin server, without a US edge network in front. As a result the page-load path involves no Schrems II transfer to the United States.
Your rights
You have the right to information, rectification, erasure, restriction, data portability, withdrawal of consent and objection. You can exercise these rights by email to office@alpenhigh.eu or by letter.
- Information: You can download your data stored with us as JSON under
/account/data-export. - Erasure: You can delete your account under
/account/delete. This removes your profile, saved addresses, sessions, tokens and security keys (MFA). Order and invoice records — including the name and delivery/billing address frozen on the order — are retained for 7 years under commercial- and tax-law retention obligations (§ 132 BAO, § 190 UGB).
You also have the right to lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, dsb.gv.at) if you believe your rights have been infringed.
Legal bases of processing (Art. 13(1)(c) GDPR)
| Processing | Legal basis |
|---|---|
| Account registration + sign-in | Art. 6(1)(b) GDPR (contract performance) |
| Order fulfilment (address, shipping, invoice) | Art. 6(1)(b) GDPR (contract performance) |
| Bookkeeping + invoice retention (7 years) | Art. 6(1)(c) GDPR (§ 132 BAO, § 190 UGB) |
| MFA / WebAuthn security | Art. 6(1)(f) GDPR (account security) |
| Audit logs (login, address change, MFA) | Art. 6(1)(c) GDPR (record-keeping) and (f) (fraud defence) |
| Newsletter | Art. 6(1)(a) GDPR (consent), § 174 TKG 2021 |
| FAGG cuttings waiver | Art. 6(1)(c) GDPR (legal obligation) |
| Anti-fraud cookies / rate limits | Art. 6(1)(f) GDPR |
| VIES lookup for B2B VAT IDs | Art. 6(1)(c) GDPR (UStG / EU VAT) |
| Refunds (payout IBAN or wallet address) | Art. 6(1)(b) GDPR (reversal of the contract) and (c) GDPR (§ 132 BAO payment evidence) |
| Seller / business application (encrypted photo ID) | Art. 6(1)(b) GDPR (pre-contractual onboarding), (c) GDPR (FM-GwG / EU anti-money-laundering law, 5-year retention) and (f) GDPR (marketplace identity verification, fraud defence) |
| Contact inquiries (contact form / email) | Art. 6(1)(f) GDPR (answering your inquiry); Art. 6(1)(b) GDPR where the inquiry concerns an existing or prospective order |
| Delivering a gifted gift card (the recipient's email address) | Art. 6(1)(f) GDPR (legitimate interest in delivering the gift), see the "Gift cards" section |
| Referral programme (linking a new account to the member who invited it) | Art. 6(1)(b) GDPR for the inviting member (the credit is part of the terms) and Art. 6(1)(f) GDPR for the invited person (running and settling the programme), see the "Referral programme" section |
Your account time zone (e.g. Europe/Vienna) |
Art. 6(1)(b) GDPR (contract performance): invoices, order confirmations and deadlines are shown in your local time. On your first sign-in the time zone reported by your browser is pre-filled once; you can change it in your profile at any time. |
No automated decision-making within the meaning of Art. 22 GDPR takes place. Profiling is not performed.
Recipients and processors (Art. 13(1)(e) GDPR)
| Category | Recipient / processing |
|---|---|
| Hosting | Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany |
| Database + cache | on our own infrastructure in the same Hetzner data centre; no further recipient |
| Crypto payment | Plisio, Inc. (USA), our crypto-payments provider. When you choose to pay with cryptocurrency you are redirected to Plisio's hosted checkout. We send Plisio an order reference and the amount and your email address, so Plisio can send you the payment confirmation and you do not have to re-enter it on the payment page. Because your browser connects to Plisio directly, Plisio also receives your IP address and the on-chain transaction data (paying wallet address, amount, transaction id). We do not transmit your name or postal address to Plisio. When we refund a crypto payment, we additionally send Plisio the payout wallet address you provide, the coin and the amount, so Plisio can execute the refund. Third country (USA), see the third-country-transfers section. Legal basis: Art. 6(1)(b) GDPR (payment processing). |
| Bank payment (SEPA) | our Austrian house bank (receiving account, IBAN per the imprint) |
| Cash by letter | processed in-house. You send cash by post to our address; the carrier and tracking number you enter are stored on your order so we can trace the letter. No third-party payment processor and no third-country transfer is involved. Legal basis: Art. 6(1)(b) GDPR (payment processing). |
| Transactional email + newsletter | Postmark (ActiveCampaign LLC), 225 Franklin Street, Boston, MA, USA — delivers our transactional email and the newsletter; receives your email address (and, for the newsletter, your display name). Standard Contractual Clauses under Art. 46 GDPR |
| Fulfilment + shipping partner | Valeskini + Partner GesbR. Warehousing and dispatch of auction goods; receives name + delivery address to pick, pack and ship. Processor under Art. 28 GDPR (Austria/EU, no third-country transfer). Legal basis: Art. 6(1)(b) GDPR. |
| Shipping platform (label service) | Sendcloud B.V. (Eindhoven, Netherlands) — processor under Art. 28 GDPR: creates our shipping labels and processes tracking events; receives the recipient name, delivery address, email address and, where provided, phone number. EU recipient, no third-country transfer. Legal basis: Art. 6(1)(b) GDPR (delivery of the contract). |
| Shipping carrier | The parcel carrier selected at checkout (e.g. DPD, GLS, Austrian Post) — receives, via our shipping platform Sendcloud, the recipient name, delivery address, and (for delivery notifications) email address and, where you have provided one, your phone number. EU recipient, no third-country transfer. Legal basis: Art. 6(1)(b) GDPR (delivery of the contract). |
| EU VAT validation | European Commission, VIES interface (VAT-ID lookup only, no profile data) |
| Referral programme | the member who invited you. They see your display name in their account and whether your first order finally went through. They receive nothing else, in particular not your email address, your postal address or what you ordered. |
| ID document (seller / business) | internal only — operator and review staff at AlpenHigh; stored encrypted in the Hetzner data centre (AES-256-GCM, key held server-side only) |
Retention periods (Art. 13(2)(a) GDPR)
| Data category | Retention |
|---|---|
| Sign-in session | 30 days after last login |
| Audit log (full IP) | 90 days; then the IP is masked to /24. The entry is then pseudonymous (no names, no precise location) and is kept for at least 7 years as accounting evidence (§ 132 BAO, § 190 UGB) and, beyond that for as long as necessary, for fraud and abuse defence (Art. 6(1)(f) GDPR) |
| Order data + invoices | 7 years (§ 132 BAO, § 190 UGB); the buyer's name and address are then anonymised |
| Refund payout details (IBAN or wallet address, encrypted) | until the related order's 7-year window ends; deleted afterwards (the payment evidence is the credit note + bank reference/transaction id) |
| Newsletter consent | the consent record (time, wording version) is kept as evidence that you gave consent (Art. 7(1) GDPR); the IP stored with it is deleted after you unsubscribe, once the record is 3 years old, counted from when consent was given |
| In-app notifications | 90 days |
| Your account time zone | for the life of the account; removed when the account is deleted |
| Logs of the emails we sent and of the payment and shipping confirmations we received | 3 years as operational and dispute records; the recipient address and content are then removed |
| Partner-API access log | 3 years; the caller IP is then masked to /24 (fraud prevention / interface integrity, Art. 6(1)(f) GDPR) |
| Application error log (server + browser errors for diagnostics: redacted path, HTTP method/status, your user ID at the time of the error, and the browser-reported error message/stack) | 30 days, then deleted in full (operations and error diagnostics, Art. 6(1)(f) GDPR) |
| Consent acceptance (IP) | retained as part of the acceptance record for the life of the account; the IP is masked to /24 on account deletion (Art. 7(1) GDPR evidence) |
| Consignment and sales reports | 7 years (§ 132 BAO) |
| Business profile + VAT-ID evidence | 7 years after end of business relationship |
| Seller / business ID document | 5 years after the end of the business relationship (EU anti-money-laundering law), then deleted |
| Pending email address changes | 7 days after confirmation or revocation; expired requests are deleted no later than 7 days after they lapse |
| WebAuthn / MFA keys | until deletion by the user or account anonymisation |
| Contact requests | maximum 6 months (typically 8 weeks) |
| Referral link (which account was invited by whom) | for as long as both accounts exist; an account that is never confirmed is deleted after 30 days together with its referral link. When an account is deleted it is anonymised, so the display name also disappears from the referral list. The credit itself is a store-credit booking and is kept for 7 years (§ 132 BAO) |
| Gift cards: the recipient's email address | until the gift is accepted, declined or withdrawn, and at most 12 months from the offer; the address is then removed automatically, including from the card's transfer log |
| Ban list (email addresses of banned accounts) | for as long as the ban is justified; removed when the ban is lifted (Art. 6(1)(f) GDPR, see the "Ban list for banned accounts" section) |
Third-country transfers to the US (Art. 13(1)(f) GDPR)
The following processing involves a transfer of personal data to recipients in the United States (third country under Art. 44 ff. GDPR):
- Postmark / ActiveCampaign LLC, Boston, MA — transactional email (order confirmation, invoice, shipping notification, password reset) and the newsletter broadcast. For the newsletter, your email address and display name are transmitted. Transfer mechanism: Standard Contractual Clauses under Art. 46(2)(c) GDPR.
- Plisio, Inc., USA — processing of your cryptocurrency payment, and only if you choose to pay with cryptocurrency. As your browser loads Plisio's hosted checkout, Plisio receives your IP address and the on-chain transaction data; we additionally transmit your email address for the payment confirmation, and, when we refund a crypto payment, the payout wallet address you provide together with the coin and the amount. No European Commission adequacy decision and no Standard Contractual Clauses are in place for Plisio. The transfer is therefore based on Art. 49(1)(b) GDPR (transfer necessary for the performance of the payment contract you initiate by choosing this payment method). Per Plisio's privacy policy, Plisio does not retain transaction details. If you prefer not to transfer any data to the USA, choose SEPA bank transfer instead (no third-country transfer).
You have the right to request a copy of the applicable safeguards (SCC text or adequacy-decision notice); email office@alpenhigh.eu.
Transfer to third parties
We transfer your personal data — including postal and email address — to third parties only where this is necessary to perform your contract (for instance to our crypto payment provider if you choose that payment method; see the recipients table above) or where you have given your express, revocable consent. Service-provider partners receive exclusively the data necessary for order fulfilment.
Data storage
Customer data — including name, address and payment information — is stored for order fulfilment. Order and invoice records are retained in unalterable form for seven years pursuant to § 132 BAO and § 190 UGB. Deleting your account removes your live profile, saved addresses, sessions, tokens and security keys; the legally retained order and invoice records — including the name and delivery/billing address frozen on the order — are unaffected.
IP addresses processed
We capture your IP address at the following clearly delimited points. The legal basis is in each case Art. 6(1)(f) GDPR (legitimate interest in fraud prevention, security auditing and legally mandated evidentiary record-keeping) unless otherwise indicated:
- Sign-in (session cookie): IP captured when a login session is created, kept for the lifetime of the session (a sliding window capped at 30 days from creation) and deleted when the session expires.
- Audit log: IP for every security-relevant action (login, password reset, MFA change, order, address change). Retained 90 days in full, then masked to /24; total seven years (forensic traceability under UGB).
- Newsletter consent: IP when setting the newsletter toggle — Art. 7(1) GDPR requires evidence of consent. Retained while the consent is in force; after withdrawal the IP is deleted once the evidence is three years old (counted from when the consent was given).
- FAGG cuttings waiver: IP when submitting the waiver at checkout. Retained 90 days in full, then masked to /24 (the waiver itself and its timestamp remain as evidence).
- Email address change: IP on request of an address change — fraud defence against account hijack. Retained 7 days after confirmation or revocation; expired requests are deleted no later than 7 days after they lapse.
- Crypto checkout: if you pay with cryptocurrency, your IP address reaches our crypto-payments provider Plisio (USA) as your browser loads its hosted checkout. Legal basis: Art. 6(1)(b) GDPR; see the third-country-transfers section for the transfer mechanism.
- Partner-API access log: if your account has created an API key for the business-partner interface, we log the calling IP address (along with the method, path and scope) on every API request, for fraud prevention and the integrity of the interface. Retained three years, then masked to /24.
- Language selection on your first visit: if you open the site without a
language prefix in the URL and neither your account nor your browser
(
Accept-Language) offers a language we serve, we redirect you to the matching language version based on the country of your IP address. The lookup runs locally on our server against a bundled dataset — no third party is contacted and nothing is stored: the IP address is evaluated in memory for that single request only. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a comprehensible first view). - Consent acceptance (terms / privacy / withdrawal): IP each time you accept a published version of our terms, privacy policy or withdrawal terms — at registration, on re-acceptance after an update, and on every order placement (including auction settlement). Legal basis: Art. 7(1) GDPR (evidence of consent). The IP is retained as part of the acceptance record for the life of your account and masked to /24 when the account is deleted.
The IP address is not used for profiling or marketing purposes. You can
review the stored values via your GDPR data export at
/account/data-export.
Ban list for banned accounts
If we ban an account for a violation and that account is subsequently erased at the request of the data subject, we retain the account's email address on an internal ban list. Without this retention, the erasure would lift the ban and the same address could register again immediately. The legal basis is our legitimate interest in enforcing the ban and preventing abuse (Art. 6(1)(f) GDPR). This interest is compelling within the meaning of Art. 21(1) GDPR because the ban can only be enforced by remembering exactly this address — comparable to an advertising suppression list, which must store an address in order to honour the objection permanently.
The ban list contains only the email address and the date of the ban. It is checked solely when a new account is created and when an existing account changes its email address, and it is used for no other purpose; nothing is ever sent to the address. The entry remains for as long as the ban is justified and is removed when the ban is lifted.
If you delete your account yourself and no ban is in place, your email address is not retained.
Cookies
We use exclusively technically necessary cookies, required for site operation and sign-in:
- Session cookie — keeps you signed in after login.
- MFA cookie (temporary) — only during the MFA confirmation step.
- Locale preference — set only when you switch the language yourself (the header switcher or your profile setting), and remembers that choice (German, English, French, Spanish) for 30 days. Merely visiting the site sets nothing: the language is carried by the URL prefix (/de, /en, /fr, /es).
- Shopping-cart intent (temporary) — if you click "Add to cart" before signing in, a short-lived cookie remembers the item so it's added to your cart once you log in. Expires after 24 hours.
- Passkey sign-in cookie (temporary) — only during passkey/passwordless sign-in; expires after a few minutes.
We use no tracking, analytics or marketing cookies, and we embed no third-party cookies. For that reason we do not show a cookie banner: there is nothing for you to consent to.
You can configure your browser to block cookies — that will, however, restrict site functionality (signing in, for example, will not be possible).
Newsletter
Subscribing to a newsletter requires your express consent. The
subscription takes place exclusively from your account under
/account/newsletter — anonymous email subscription is not offered. This
ensures that only you yourself can enter your address (your email was
confirmed at registration).
Legal basis: Art. 6(1)(a) GDPR (consent), § 174 TKG 2021.
Which data: your account email address, your display name (used in the greeting), the time of your consent and the IP address from which you activated the toggle (Art. 7(1) GDPR — evidence of consent). The newsletter is delivered through Postmark (ActiveCampaign LLC, USA) under the same Standard Contractual Clauses as our transactional email; your email address and display name are transmitted there for delivery (see the third-country transfers section).
Discount: subscribers with a private account get a discount on their shop orders; it does not apply to business accounts or reverse-charge orders. Subscribing is optional — you can order at any time without a subscription, just without that discount.
Unsubscribe: at any time with one click — either via the unsubscribe
link in every newsletter email (no login needed) or directly at
/account/newsletter. After unsubscribing, your address is removed from
the newsletter distribution list.
Product reviews
As a buyer you can review purchased products (stars, text, and optional photos). Published reviews are publicly visible and show your display name and — where set — your profile picture alongside the review content. Reviews may be checked by our team before publication; if a review is declined you will see the reason in your account.
Legal basis: Art. 6(1)(b) GDPR (the review feature is part of the platform contract; submitting a review is voluntary).
Which data: star rating, review text, uploaded photos, display name and profile picture, the purchase link (for the "verified buyer" label), and the time of the review.
Retention: until you delete the review yourself (possible at any time at
/account/reviews) or your account is deleted — account deletion removes
your reviews including photos entirely.
Referral programme
Members can share a personal invite link. If you register through such a link, we permanently link your account to the account of the member who invited you. We say so on the registration form itself, before you create the account.
What the inviting member sees: your display name and whether your first order finally went through, that is the status "open" or "credited". They do not see your email address, your postal address, or the size and content of your orders.
Why: the inviting member receives store credit once your first order is paid and the 14-day withdrawal period has passed. The link is what that settlement runs on, and it stops the same referral being rewarded twice.
Legal basis: Art. 6(1)(b) GDPR for the inviting member (the credit is part of the terms), and Art. 6(1)(f) GDPR for you as the invited person (running and settling the programme). You can object to this processing at any time (Art. 21 GDPR) with an informal message to office@alpenhigh.eu. If you register without an invite link, no such link is created at all.
Retention: for as long as both accounts exist. An account that is never confirmed is deleted after 30 days together with its referral link. When an account is deleted it is anonymised, so the display name also disappears from the inviting member's referral list. The credit itself is a store-credit booking and is kept for 7 years (§ 132 BAO).
Gift cards
When someone gives you a gift card, that person enters your email address here. So we did not receive your address from you (Art. 14 GDPR). We use it only to deliver the gift: you get an email with the gift card as a PDF. It does not sign you up for advertising or for the newsletter.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in delivering the gift). If you have an account with us, Art. 6(1)(b) GDPR additionally applies to transferring the card to your account.
What data: your email address, the time of the offer and the value of the card. The address also appears in the card's transfer log, which lets us trace who passed the card on and when.
Retention: until the gift is accepted, declined or withdrawn by the giver, and at most 12 months from the offer. Your address is then removed from the card and from the transfer log; the log itself is kept without your address.
Your rights: you can object to this processing at any time and ask for access or erasure. An informal message to office@alpenhigh.eu is enough; you do not need an account.
ID document upload during seller or business application
If you apply to become a seller or business account, the onboarding form asks you to upload a photo ID (national ID card or passport). This step serves exclusively:
- age verification (sale of age-restricted goods),
- vendor identity verification for marketplace integrity,
- fraud and money-laundering defence.
Storage: The file is encrypted with AES-256-GCM immediately upon upload and written to our server; the key lives exclusively in the server environment and never in the database. The document never exists in plaintext on disk.
Access: Only operator and review staff at AlpenHigh can briefly view the document in the browser for application review. Every individual access is logged in the audit log with timestamp, reviewer ID and IP address.
Retention period: 5 years after the end of the business relationship (EU anti-money-laundering law), then deleted. On application rejection or account anonymisation the document is deleted sooner.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual identity verification during seller onboarding) and (f) GDPR (legitimate interest in marketplace integrity, vendor verification and fraud defence). The ID number and photograph are not actively further-processed — they remain encrypted and are only decrypted on a concrete reviewer request.
Contact
Data you send us by email or via the contact form is stored exclusively for handling your request and any follow-up questions for a maximum of six months (as a rule, eight weeks). Legal basis: Art. 6(1)(f) GDPR (answering your inquiry) or, where the inquiry concerns an existing or prospective order, Art. 6(1)(b) GDPR.