Privacy Policy
Protecting your personal data is a particular concern of ours. We therefore process your data exclusively on the basis of the legal provisions (GDPR, Austrian TKG 2021).
Security — TLS (Transport Layer Security)
The order process is transmitted over an encrypted TLS connection. That protects your data in transit against unauthorised access, using measures appropriate to the state of the art (Art. 32 GDPR). No one, however, can promise absolute security for data sent across the internet.
Controller
The controller within the meaning of the GDPR is Adelwöhrer & Puffer OG.
Address: Prankergasse 49, 8020 Graz, Österreich · VAT ID: ATU82108559.
Reachable by email at office@alpenhigh.eu.
Data Protection Officer
No Data Protection Officer has been appointed; there is no obligation to designate one under Art. 37 GDPR.
Hosting
AlpenHigh is operated on Hetzner servers in Germany (EU data centres Falkenstein/Nuremberg). No transfer of data to third countries takes place unless explicitly indicated. We use no CDN — page delivery comes directly from the Hetzner origin server, without a US edge network in front. As a result the page-load path involves no Schrems II transfer to the United States.
Your rights
You have the right to information, rectification, erasure, restriction, data portability, withdrawal of consent and objection. You can exercise these rights by email to office@alpenhigh.eu or by letter.
- Information: You can download your data stored with us as JSON under
/account/data-export. - Erasure: You can delete your account yourself under
/account/delete. While something is still open, for example a live order, a pending payout, an active listing or store credit still to be settled, deletion is not yet possible; we show you what is outstanding before you delete, and deletion becomes available once those points are closed (Art. 17(3) GDPR). Deletion removes your profile, saved addresses, sessions, tokens and security keys (MFA). Order and invoice records, including the name and delivery/billing address frozen on the order, are retained for 7 years under commercial- and tax-law retention obligations (§ 132 BAO, § 190 UGB). If your account is linked to a blog author profile, the link is cut; the published author profile itself (name, short biography, picture, website) remains as part of our editorial content — see the “Blog author profiles” section.
You also have the right to lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, dsb.gv.at) if you believe your rights have been infringed.
Legal bases of processing (Art. 13(1)(c) GDPR)
| Processing | Legal basis |
|---|---|
| Account registration + sign-in | Art. 6(1)(b) GDPR (contract performance) |
| Order fulfilment (address, shipping, invoice) | Art. 6(1)(b) GDPR (contract performance) |
| Bookkeeping + invoice retention (7 years) | Art. 6(1)(c) GDPR (§ 132 BAO, § 190 UGB) |
| MFA / WebAuthn security | Art. 6(1)(f) GDPR (account security) |
| Audit logs (login, address change, MFA) | Art. 6(1)(c) GDPR (record-keeping) and (f) (fraud defence) |
| Newsletter | Art. 6(1)(a) GDPR (consent), § 174 TKG 2021 |
| FAGG cuttings waiver | Art. 6(1)(c) GDPR (legal obligation) |
| Anti-fraud cookies / rate limits | Art. 6(1)(f) GDPR |
| VIES lookup for B2B VAT IDs | Art. 6(1)(c) GDPR (UStG / EU VAT) |
| DAC7 report to the tax authority. What is reported: your name, your main address, your tax identification number and the state that issued it, your date of birth and, where applicable, your place of birth; for a registered business, the company name, the VAT ID and the company register number instead of the birth details; per quarter, your number of sales, the consideration credited to you and the fees we withheld; and, where your state of residence asks for it, the account identifier (IBAN) used for your payouts and, if that account is held by someone else, that person's name. Applies only to sellers credited more than €2,000 of consideration (their share after our commission) in a calendar year or reaching 30 sales; below that no tax identification number is collected, and a number provided voluntarily in advance is stored with your consent (Art. 6(1)(a) GDPR) | Art. 6(1)(c) GDPR (Directive (EU) 2021/514 "DAC7", implemented in the Austrian DPMG) |
| Refunds (payout IBAN or wallet address) | Art. 6(1)(b) GDPR (reversal of the contract) and (c) GDPR (§ 132 BAO payment evidence) |
| Matching incoming bank transfers to your order (the payer's name and IBAN as stated on our bank's account statement) | Art. 6(1)(b) GDPR (allocating the payment) and (c) GDPR (§ 132 BAO accounting evidence) |
| Seller / business application (encrypted photo ID) | Art. 6(1)(b) GDPR (pre-contractual onboarding), (c) GDPR (FM-GwG / EU anti-money-laundering law, 5-year retention) and (f) GDPR (marketplace identity verification, fraud defence) |
| Contact inquiries (contact form / email) | Art. 6(1)(f) GDPR (answering your inquiry); Art. 6(1)(b) GDPR where the inquiry concerns an existing or prospective order |
| Delivering a gifted gift card (the recipient's email address) | Art. 6(1)(f) GDPR (legitimate interest in delivering the gift), see the "Gift cards" section |
| Referral programme (linking a new account to the member who invited it) | Art. 6(1)(b) GDPR for the inviting member (the credit is part of the terms) and Art. 6(1)(f) GDPR for the invited person (running and settling the programme), see the "Referral programme" section |
Your account time zone (e.g. Europe/Vienna) |
Art. 6(1)(b) GDPR (contract performance): invoices, order confirmations and deadlines are shown in your local time. On your first sign-in the time zone reported by your browser is pre-filled once; you can change it in your profile at any time. |
No automated decision-making within the meaning of Art. 22 GDPR takes place. Profiling is not performed.
Providing your data (Art. 13(2)(e) GDPR)
Some details we need in order to enter into and perform a contract with you at all. Providing them is not a statutory requirement but a contractual one:
- Email address — to create your account and sign you in, and for the order confirmation we must send you on a durable medium (§ 7(3) FAGG).
- Date of birth — for the age check; we supply our range only to people aged 18 and over.
- Name and delivery address — for dispatch and delivery, and for the invoice we must retain for seven years (§ 132 BAO).
Without these we can neither create an account nor accept or deliver an order. There is no consequence beyond that.
Everything else is voluntary — a phone number, a profile picture, a billing address different from the delivery address, or the text of a product review. Leaving them out puts you at no disadvantage; only the feature in question is then unavailable.
Recipients and processors (Art. 13(1)(e) GDPR)
| Category | Recipient / processing |
|---|---|
| Hosting | Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany |
| Database + cache | on our own infrastructure in the same Hetzner data centre; no further recipient |
| Crypto payment | Plisio, Inc. (USA), our crypto-payments provider and an independent controller — not a processor — for the data it collects during checkout. When you choose to pay with cryptocurrency you are redirected to Plisio's hosted checkout. We send Plisio an order reference and the amount and your email address, so Plisio can send you the payment confirmation and you do not have to re-enter it on the payment page. Because your browser connects to Plisio directly, Plisio also receives your IP address and the on-chain transaction data (paying wallet address, amount, transaction id). We do not transmit your name or postal address to Plisio. When we refund a crypto payment, we additionally send Plisio the payout wallet address you provide, the coin and the amount, so Plisio can execute the refund. Third country (USA), see the third-country-transfers section. Legal basis: Art. 6(1)(b) GDPR (payment processing). |
| Bank payment (SEPA) | our Austrian house bank (receiving account, IBAN per the imprint). We retrieve the electronic account statements from that bank and match the incoming credits to orders. For each payment we store the name the bank states for the payer and that payer's IBAN; the IBAN is stored encrypted (AES-256-GCM, the key held on the server only) and is read in the clear only when we pay money back to the same account — every such access is logged. Neither detail comes from you: both come from our bank's account statement (source of the data, Art. 14(2)(f) GDPR); where another person pays for your order, they concern that person's name and account. We do not pass these details on to anyone. Legal basis: Art. 6(1)(b) GDPR (allocating the payment) and (c) GDPR (§ 132 BAO). |
| Cash by letter | processed in-house. You send cash by post to our address and enclose the payment sheet carrying the payment reference; that reference is part of your order record and matches the letter to your order. No further data is collected; no third-party payment processor and no third-country transfer is involved. Legal basis: Art. 6(1)(b) GDPR (payment processing). |
| Transactional email + newsletter | Postmark (ActiveCampaign LLC), 225 Franklin Street, Boston, MA, USA — delivers our transactional email and the newsletter; receives your email address (and, for the newsletter, your display name). European Commission adequacy decision for the EU-U.S. Data Privacy Framework (Art. 45 GDPR); Standard Contractual Clauses under Art. 46 GDPR additionally in place as a fallback safeguard |
| Fulfilment + shipping partner | Valeskini + Partner GesbR. Warehousing and dispatch of auction goods; receives name + delivery address to pick, pack and ship. Processor under Art. 28 GDPR (Austria/EU, no third-country transfer). Legal basis: Art. 6(1)(b) GDPR. |
| Shipping platform (label service) | Sendcloud B.V. (Eindhoven, Netherlands) — processor under Art. 28 GDPR: creates our shipping labels and processes tracking events; receives the recipient name, delivery address, email address and, where provided, phone number. When you save a delivery address we have Sendcloud check that it really exists; for that the address is passed to the map service HERE Global B.V. (Eindhoven, Netherlands). This is what keeps parcels from going to addresses that do not exist. EU recipient, no third-country transfer. Legal basis: Art. 6(1)(b) GDPR (delivery of the contract). |
| Map service (address on a map) | OpenStreetMap Foundation, Nominatim (United Kingdom) — when you save a delivery address our server looks up its coordinates once, so we can show you the address on a map. Only street, postcode, city and country are sent; not your name and not your IP address. We store the coordinates with the address, so nothing is looked up again on later views. The map images are served by our own server, so your browser connects to nobody else. Transfer to the United Kingdom on the basis of the European Commission's adequacy decision. Legal basis: Art. 6(1)(b) GDPR (delivery of the contract). |
| Shipping carrier | The parcel carrier selected at checkout (e.g. DPD, GLS, Austrian Post) — receives, via our shipping platform Sendcloud, the recipient name, delivery address, and (for delivery notifications) email address and, where you have provided one, your phone number. EU recipient, no third-country transfer. Legal basis: Art. 6(1)(b) GDPR (delivery of the contract). |
| EU VAT validation | European Commission, VIES interface (VAT-ID lookup only, no profile data) |
| Tax administration (DAC7) | the Austrian tax administration, to which we submit the DAC7 report via FinanzOnline; it passes the report on to the tax administration of your state of residence. Applies only to reportable sellers; what is transmitted is listed in the purposes table above. Not a processor but an authority acting as its own controller. Legal basis: Art. 6(1)(c) GDPR (DPMG). |
| Referral programme | the member who invited you. They see your display name in their account and whether your first order finally went through. They receive nothing else, in particular not your email address, your postal address or what you ordered. |
| ID document (seller / business) | internal only — operator and review staff at AlpenHigh; stored encrypted in the Hetzner data centre (AES-256-GCM, key held server-side only) |
Retention periods (Art. 13(2)(a) GDPR)
| Data category | Retention |
|---|---|
| Sign-in session | 7 days after last use, at most 30 days from when the session was created |
| DAC7 seller reporting data | A filed report is deleted in full 10 years after the end of the reportable period (§ 15 Abs. 3 DPMG); until then it is kept unchanged, including after an account deletion (Art. 17(3)(b) GDPR). Where the account used for your payouts is held by a person other than the seller, that person's name and account identifier (IBAN) are reported as well; to that extent this privacy policy also serves as the notice to the account holder about the transmission. Where nothing has been reported about you, the tax identification number is deleted immediately when your account is erased |
| Audit log (full IP) | 90 days; then the IP is masked to /24. The entry is then pseudonymous (no names, no precise location) and is kept for at least 7 years as accounting evidence (§ 132 BAO, § 190 UGB) and, beyond that for as long as necessary, for fraud and abuse defence (Art. 6(1)(f) GDPR) |
| Order data + invoices | 7 years (§ 132 BAO, § 190 UGB); the buyer's name and address are then anonymised |
| Refund payout details (IBAN or wallet address, encrypted) | until the related order's 7-year window ends; deleted afterwards (the payment evidence is the credit note + bank reference/transaction id) |
| Payer details from the account statement (the name as stated by the bank; the payer's IBAN, encrypted) | the IBAN is deleted at the latest when the related record's 7-year window ends (§ 132 BAO), and immediately when an account is erased. The name the bank stated on the statement stays part of the accounting record until that same 7-year window ends and is then deleted as well; until then it is kept even when an account is erased. The payment evidence itself is the invoice or credit note plus the bank reference |
| Newsletter consent | the consent record (time, wording version) is kept as evidence that you gave consent (Art. 7(1) GDPR); the IP stored with it is deleted after you unsubscribe, once the record is 3 years old, counted from when consent was given |
| In-app notifications | 90 days |
| Your account time zone | for the life of the account; removed when the account is deleted |
| Logs of the emails we sent and of the payment and shipping confirmations we received | 3 years as operational and dispute records; the recipient address and content are then removed |
| Partner-API access log | 3 years; the caller IP is then masked to /24 (fraud prevention / interface integrity, Art. 6(1)(f) GDPR) |
| Application error log (server + browser errors for diagnostics: redacted path, HTTP method/status, your user ID at the time of the error, the browser-reported error message/stack, the browser family without its version — so “Safari” or “Chrome” and nothing more — and the version of our software your browser had loaded) | 30 days, then deleted in full (operations and error diagnostics, Art. 6(1)(f) GDPR) |
| Consent acceptance (IP) | retained as part of the acceptance record for the life of the account; the IP is masked to /24 on account deletion (Art. 7(1) GDPR evidence). Covers the confirmation of a live checkout notice, kept as per-order dispute evidence on the same footing |
| Consignment and sales reports | 7 years (§ 132 BAO) |
| Business profile + VAT-ID evidence | 7 years after end of business relationship |
| Seller / business ID document | 5 years after the end of the business relationship (EU anti-money-laundering law), then deleted |
| Pending email address changes | 7 days after confirmation or revocation; expired requests are deleted no later than 7 days after they lapse |
| WebAuthn / MFA keys | until deletion by the user or account anonymisation |
| Contact requests | as a rule 8 weeks after your request is settled; where the request concerns an order, we keep the correspondence for as long as it is needed to handle the order and to defend possible claims, as a rule up to 3 years (§ 1489 ABGB, Art. 17(3)(e) GDPR) |
| Referral link (which account was invited by whom) | for as long as both accounts exist; an account that is never confirmed is deleted after 30 days together with its referral link. When an account is deleted it is anonymised, so the display name also disappears from the referral list. The credit itself is a store-credit booking and is kept for 7 years (§ 132 BAO) |
| Gift cards: the recipient's email address | until the gift is accepted, declined or withdrawn, and at most 12 months from the offer; the address is then removed automatically, including from the card's transfer log |
| Ban list (email addresses of banned accounts) | for as long as the ban is justified; removed when the ban is lifted (Art. 6(1)(f) GDPR, see the "Ban list for banned accounts" section) |
| Blog author profile (name, short biography, profile picture, website) | as long as the articles it belongs to are published; account deletion cuts the link to the account while the published profile itself remains (Art. 17(3)(a) GDPR) — removal or pseudonymisation on request |
Third-country transfers to the US (Art. 13(1)(f) GDPR)
The following processing involves a transfer of personal data to recipients in the United States (third country under Art. 44 ff. GDPR):
- Postmark / ActiveCampaign LLC, Boston, MA — transactional email (order confirmation, invoice, shipping notification, password reset) and the newsletter broadcast. For the newsletter, your email address and display name are transmitted. Transfer mechanism: European Commission adequacy decision for the EU-U.S. Data Privacy Framework (Implementing Decision (EU) 2023/1795, Art. 45 GDPR). ActiveCampaign LLC and AC PM LLC, which operates Postmark, are certified under the Data Privacy Framework (U.S. Department of Commerce list). In addition, our contract with Postmark contains Standard Contractual Clauses under Art. 46(2)(c) GDPR, which take over as the safeguard should the adequacy decision cease to apply.
- Plisio, Inc., USA — processing of your cryptocurrency payment, and only if you choose to pay with cryptocurrency. As your browser loads Plisio's hosted checkout, Plisio receives your IP address and the on-chain transaction data; we additionally transmit your email address for the payment confirmation, and, when we refund a crypto payment, the payout wallet address you provide together with the coin and the amount. Plisio is not a processor acting on our behalf but an independent controller for the data it collects during checkout; requests to access or erase that data therefore go to Plisio, requests about your order data to us. No European Commission adequacy decision and no Standard Contractual Clauses are in place for Plisio. The transfer is therefore based on Art. 49(1)(b) GDPR (transfer necessary for the performance of the payment contract you initiate by choosing this payment method). Per Plisio's privacy policy, Plisio does not retain transaction details. If you prefer not to send payment data to the USA, choose SEPA bank transfer or cash by letter instead: Plisio is not involved in either. Whichever payment method you choose, we send our order emails (confirmation, invoice, shipping notice) through Postmark in the USA, based on the adequacy decision for the EU-U.S. Data Privacy Framework described above.
You have the right to request a copy of the applicable safeguards (SCC text or adequacy-decision notice); email office@alpenhigh.eu.
Transfer to third parties
We transfer your personal data, including your postal and email address, to third parties only in these cases: where it is necessary to perform your contract (for instance to our crypto payment provider if you choose that payment method; see the recipients table above); where you have given your express consent (which you can withdraw at any time with effect for the future); where we are legally obliged to do so or an authority lawfully requires it, for example the tax administration in an audit, courts or law-enforcement authorities (Art. 6(1)(c) GDPR, § 143 and § 147 BAO); or where it is necessary to establish or defend legal claims (Art. 6(1)(f) GDPR). Service-provider partners receive exclusively the data necessary for order fulfilment.
Data storage
Customer data — including name, address and payment information — is stored for order fulfilment. Order and invoice records are retained in unalterable form for seven years pursuant to § 132 BAO and § 190 UGB. Deleting your account removes your live profile, saved addresses, sessions, tokens and security keys; the legally retained order and invoice records — including the name and delivery/billing address frozen on the order — are unaffected.
IP addresses processed
We capture your IP address at the following clearly delimited points. The legal basis is in each case Art. 6(1)(f) GDPR (legitimate interest in fraud prevention, security auditing and legally mandated evidentiary record-keeping) unless otherwise indicated:
- Sign-in (session cookie): IP captured when a login session is created, kept for the lifetime of the session (a sliding window capped at 30 days from creation) and deleted when the session expires.
- Audit log: IP for every security-relevant action (login, password reset, MFA change, order, address change). Retained 90 days in full, then masked to /24. The entry is then pseudonymous and is kept for at least 7 years as accounting evidence (§ 132 BAO, § 190 UGB) and, beyond that for as long as necessary, for fraud and abuse defence (Art. 6(1)(f) GDPR).
- Newsletter consent: IP when setting the newsletter toggle — Art. 7(1) GDPR requires evidence of consent. Retained while the consent is in force; after withdrawal the IP is deleted once the evidence is three years old (counted from when the consent was given).
- FAGG cuttings waiver: IP when submitting the waiver at checkout. Retained 90 days in full, then masked to /24 (the waiver itself and its timestamp remain as evidence).
- Email address change: IP on request of an address change — fraud defence against account hijack. Retained 7 days after confirmation or revocation; expired requests are deleted no later than 7 days after they lapse.
- Crypto checkout: if you pay with cryptocurrency, your IP address reaches our crypto-payments provider Plisio (USA) as your browser loads its hosted checkout. Legal basis: Art. 6(1)(b) GDPR; see the third-country-transfers section for the transfer mechanism.
- Partner-API access log: if your account has created an API key for the business-partner interface, we log the calling IP address (along with the method, path and scope) on every API request, for fraud prevention and the integrity of the interface. Retained three years, then masked to /24.
- Language selection on your first visit: if you open the site without a
language prefix in the URL and neither your account nor your browser
(
Accept-Language) offers a language we serve, we redirect you to the matching language version based on the country of your IP address. The lookup runs locally on our server against a bundled dataset — no third party is contacted and nothing is stored: the IP address is evaluated in memory for that single request only. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a comprehensible first view). - Consent acceptance (terms / privacy / withdrawal / checkout notice): IP each time you accept a published version of our terms, privacy policy or withdrawal terms — at registration, on re-acceptance after an update, and on every order placement (including auction settlement) — and each time you confirm a checkout notice we have live at the moment you place a shop order. Legal basis: Art. 7(1) GDPR (evidence of consent). The IP is retained as part of the acceptance record for the life of your account and masked to /24 when the account is deleted; the checkout-notice acceptance is kept as per-order dispute evidence on the same footing.
The IP address is not used for profiling or marketing purposes. You can
review the stored values via your GDPR data export at
/account/data-export.
Ban list for banned accounts
If we ban an account for a violation and that account is subsequently erased at the request of the data subject, we retain the account's email address on an internal ban list. Without this retention, the erasure would lift the ban and the same address could register again immediately. The legal basis is our legitimate interest in enforcing the ban and preventing abuse (Art. 6(1)(f) GDPR). This interest is compelling within the meaning of Art. 21(1) GDPR because the ban can only be enforced by remembering exactly this address — comparable to an advertising suppression list, which must store an address in order to honour the objection permanently.
The ban list contains only the email address and the date of the ban. It is checked solely when a new account is created and when an existing account changes its email address, and it is used for no other purpose; nothing is ever sent to the address. The entry remains for as long as the ban is justified and is removed when the ban is lifted.
If you delete your account yourself and no ban is in place, your email address is not retained.
Cookies
We use exclusively technically necessary cookies, required for site operation and sign-in:
- Session cookie — keeps you signed in after login.
- MFA cookie (temporary) — only during the MFA confirmation step.
- Locale preference — set only when you switch the language yourself (the header switcher or your profile setting), and remembers that choice (German, English, French, Spanish) for 30 days. Merely visiting the site sets nothing: the language is carried by the URL prefix (/de, /en, /fr, /es).
- Shopping-cart intent (temporary) — if you click "Add to cart" before signing in, a short-lived cookie remembers the item so it's added to your cart once you log in. Expires after 7 days.
- Passkey sign-in cookie (temporary) — only during passkey/passwordless sign-in; expires after a few minutes.
- Notice dismissed (temporary) — set only when you close the notice strip at the top of the page yourself, and remembers nothing but which notice you closed. It ends after 24 hours; if we change the notice text, it reappears.
- Theme choice — set only when you switch between the light and dark theme yourself, and remembers nothing but that choice (light or dark) for 30 days.
We use no tracking, analytics or marketing cookies, and we embed no third-party cookies. For that reason we do not show a cookie banner: there is nothing for you to consent to.
You can configure your browser to block cookies — that will, however, restrict site functionality (signing in, for example, will not be possible).
Newsletter
Subscribing to a newsletter requires your express consent. The
subscription takes place exclusively from your account under
/account/newsletter — anonymous email subscription is not offered. This
ensures that only you yourself can enter your address (your email was
confirmed at registration).
Legal basis: Art. 6(1)(a) GDPR (consent), § 174 TKG 2021.
Which data: your account email address, your display name (used in the greeting), the time of your consent and the IP address from which you activated the toggle (Art. 7(1) GDPR — evidence of consent). The newsletter is delivered through Postmark (ActiveCampaign LLC, USA) on the same basis as our transactional email (adequacy decision for the EU-U.S. Data Privacy Framework); your email address and display name are transmitted there for delivery (see the third-country transfers section).
Discount: subscribers with a private account currently receive a discount on shop orders; it does not apply to business accounts or reverse-charge orders. The discount is a voluntary benefit that we may change or discontinue for the future; the price shown in your cart is always the one that counts. Subscribing is optional: you can order at any time without a subscription, just without that discount.
Unsubscribe: at any time with one click — either via the unsubscribe
link in every newsletter email (no login needed) or directly at
/account/newsletter. After unsubscribing, your address is removed from
the newsletter distribution list.
Product reviews
As a buyer you can review purchased products (stars, text, and optional photos). Published reviews are publicly visible and show your display name and — where set — your profile picture alongside the review content. Reviews may be checked by our team before publication; if a review is declined you will see the reason in your account.
Legal basis: Art. 6(1)(b) GDPR (the review feature is part of the platform contract; submitting a review is voluntary).
Which data: star rating, review text, uploaded photos, display name and profile picture, the purchase link (for the "verified buyer" label), and the time of the review.
Retention: until you delete the review yourself (possible at any time at
/account/reviews) or your account is deleted — account deletion removes
your reviews including photos entirely.
Blog author profiles
Articles on our blog appear under an author profile: name, short biography, profile picture and — where given — a website. An author profile can be linked to a member account; the linked person is then notified about new comments on their articles, and their own comments carry an author marker under the article.
Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in attributable authorship of editorial content (transparency towards readers, a recognisable professional source).
Which data: name, short biography, profile picture, website, and the link to a member account where one exists.
Retention: an author profile stays as long as the articles it belongs to are published — including after the linked account is deleted. Account deletion cuts the link to the account; the published profile itself is part of our editorial content and is kept in the exercise of the right to freedom of expression and information (Art. 17(3)(a) GDPR). You can ask for your author profile to be removed or pseudonymised at any time at office@alpenhigh.eu; we then remove the biography, picture and website and replace the name, unless overriding interests prevent it (Art. 21 GDPR).
Reports about sellers
Signed-in members can report a seller to us via the auction page ("Report this seller"). The report goes exclusively to our team; the reported seller never learns who reported them. After review we notify you via the bell that your report has been closed — without details about any measures taken towards the seller.
Which data: your free-text reason, the reference to the auction and the reported seller, timestamps and the processing state.
Legal basis: Art. 6(1)(f) GDPR (handling notices of allegedly unlawful or rule-breaking content, Art. 16 DSA); submitting a report is voluntary.
Retention: for the lifetime of the accounts involved. If your account or the reported seller's account is deleted (Art. 17 GDPR), we delete the report permanently.
Referral programme
Members can share a personal invite link. If you register through such a link, we permanently link your account to the account of the member who invited you. We say so on the registration form itself, before you create the account.
What the inviting member sees: your display name and whether your first order finally went through, that is the status "open" or "credited". They do not see your email address, your postal address, or the size and content of your orders.
Why: under the conditions of the referral programme, the inviting member can receive store credit, at the earliest once your first order is paid, delivered and past the 14-day withdrawal period. The full conditions, including any cap on the number of rewarded referrals, are shown in the account under "Wallet & referrals". The link is what that settlement runs on, and it stops the same referral being rewarded twice.
Legal basis: Art. 6(1)(b) GDPR for the inviting member (the credit is part of the terms), and Art. 6(1)(f) GDPR for you as the invited person (running and settling the programme). You can object to this processing at any time (Art. 21 GDPR) with an informal message to office@alpenhigh.eu. If you register without an invite link, no such link is created at all.
Retention: for as long as both accounts exist. An account that is never confirmed is deleted after 30 days together with its referral link. When an account is deleted it is anonymised, so the display name also disappears from the inviting member's referral list. The credit itself is a store-credit booking and is kept for 7 years (§ 132 BAO).
Gift cards
When someone gives you a gift card, that person enters your email address here. So we did not receive your address from you (Art. 14 GDPR). We use it only to deliver the gift: you get an email with the gift card as a PDF. It does not sign you up for advertising or for the newsletter.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in delivering the gift). If you have an account with us, Art. 6(1)(b) GDPR additionally applies to transferring the card to your account.
What data: your email address, the time of the offer and the value of the card. The address also appears in the card's transfer log, which lets us trace who passed the card on and when.
Retention: until the gift is accepted, declined or withdrawn by the giver, and at most 12 months from the offer. Your address is then removed from the card and from the transfer log; the log itself is kept without your address.
Your rights: you can object to this processing at any time and ask for access or erasure. An informal message to office@alpenhigh.eu is enough; you do not need an account.
ID document upload during seller or business application
If you apply to become a seller or business account, the onboarding form asks you to upload a photo ID (national ID card or passport). This step serves exclusively:
- age verification (sale of age-restricted goods),
- vendor identity verification for marketplace integrity,
- fraud and money-laundering defence.
Storage: The file is encrypted with AES-256-GCM immediately upon upload and written to our server; the key lives exclusively in the server environment and never in the database. The document never exists in plaintext on disk.
Access: Only operator and review staff at AlpenHigh can briefly view the document in the browser for application review. Every individual access is logged in the audit log with timestamp, reviewer ID and IP address.
Retention period: 5 years after the end of the business relationship (EU anti-money-laundering law), then deleted. On application rejection or account anonymisation the document is deleted sooner.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual identity verification during seller onboarding) and (f) GDPR (legitimate interest in marketplace integrity, vendor verification and fraud defence). The ID number and photograph are not actively further-processed — they remain encrypted and are only decrypted on a concrete reviewer request.
Contact
We use data you send us by email or via the contact form to handle your request and any follow-up questions. We delete it once we no longer need it for that, as a rule eight weeks after the request is settled. Where your request concerns an order, we keep the correspondence for as long as it is needed to handle the order and any claims arising from it, as a rule up to three years (Art. 17(3)(e) GDPR and the limitation periods under the ABGB). Where a message becomes an accounting document, for example your withdrawal or refund declaration for an order, the statutory seven-year retention applies (§ 132 BAO). The email we send is additionally recorded in the log of sent emails, see the "Retention periods" table. Legal basis: Art. 6(1)(f) GDPR (answering your inquiry) or, where the inquiry concerns an existing or prospective order, Art. 6(1)(b) GDPR.