Our data protection and cookie policies at a glance
With us, you remain unaffected by Facebook and other advertising giants that want to access your personal data and learn about your purchasing behavior. This also prevents these providers from tracking your internet activity on our site through so-called "fingerprinting."
We have deliberately decided against using Google Analytics software and social media plugins, as these often collect a large amount of data that often goes beyond the use of the individual website. We want our products to speak for themselves and enable you to purchase them with the greatest possible degree of privacy. Therefore, unlike many other websites, we do not ask for your consent to the collection of your data by third parties. We simply do not allow it.
We cannot avoid the use of individual cookies from our own shop system, which are absolutely necessary to enable you to shop with us without functional restrictions and to provide us with basic statistical data about the use of our site. However, we do this without the help of the widely used "Google Analytics," but rather exclusively through the use of locally installed software (Matomo), which completely anonymizes access to our site and thus does not allow any conclusions to be drawn about you. The few cookies that facilitate your use of our online shop are set exclusively by our own server operated in Germany and are deleted after your visit or at the latest after you manually clear your browser cache.
We only collect personal data if you make a purchase via our website and if we need it for order processing.
Unfortunately, we have no influence on the cookie policy of the payment provider PayPal. However, we have taken precautions and give you the choice: If you wish to use PayPal as your payment method, you can activate this option during the ordering process (you will be expressly notified of this at that point). Until this point, PayPal has no access to your (or our) data.
In this way, we ensure – contrary to the general trend in online shipping – that your personal data is handled consciously and carefully.
1. Data protection at a glance
2. Hosting and web application firewall (WAF)
3. General information and mandatory information
4. Data collection on our website
5. Analysis tools
6. Payment providers
7. News
-
1. Data protection at a glance
-
General
The following information provides a simple overview of what happens to your personal data when you visit our website. Personal data is any data that can be used to identify you personally. For detailed information on the subject of data protection, please refer to our privacy policy listed below this text.
Data collection on our website
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. You can find their contact details in the legal notice on this website.
How do we collect your data?
Your data is collected when you provide it to us. This may include data that you enter in a contact form.
Other data is collected automatically by our IT systems when you visit the website. This is mainly technical data (e.g., Internet browser, operating system, or time of page view). This data is collected automatically as soon as you enter our website.
What do we use your data for?
Some of the data is collected to ensure the error-free provision of the website. Other data may be used to analyze your user behavior.
What rights do you have regarding your data?
You have the right to obtain information about the origin, recipient, and purpose of your stored personal data free of charge at any time. You also have the right to request the correction, blocking, or deletion of this data. You can contact us at any time at the address provided in the legal notice if you have any questions about this or other topics related to data protection. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.
Analysis tools and third-party tools
When you visit our website, your surfing behavior may be statistically evaluated. This is done primarily with cookies and so-called analysis programs. The analysis of your surfing behavior is usually anonymous; the surfing behavior cannot be traced back to you. You can object to this analysis or prevent it by not using certain tools. Detailed information on this can be found in the following privacy policy.
You can object to this analysis. We will inform you about the options for objecting in this privacy policy.
-
2. Hosting and Web Application Firewall (WAF)
-
We host the content of our website with the following provider:
External hosting
This website is hosted externally. The personal data collected on this website is stored on the servers of the host. This may include IP addresses, contact requests, meta and communication data, contract data, contact details, names, website accesses, and other data generated via a website.
External hosting is carried out for the purpose of fulfilling our contractual obligations towards our potential and existing customers (Art. 6 para. 1 lit. b GDPR) and in the interest of a secure, fast, and efficient provision of our online offering by a professional provider (Art. 6 para. 1 lit. f GDPR). If consent has been requested, processing will take place exclusively on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG, insofar as the consent includes the storage of cookies or access to information on the user's end device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.
Our host(s) will only process your data to the extent necessary to fulfill their performance obligations and will follow our instructions regarding this data.
We use the following host(s):
Hetzner Online GmbH
Industriestr. 25
91710 Gunzenhausen
GermanyOrder processing
We have concluded a contract for order processing (AVV) for the use of the above-mentioned service. This is a contract required by data protection law, which ensures that the personal data of our website visitors is only processed in accordance with our instructions and in compliance with the GDPR.
Cloudflare
We use the "Cloudflare" service. The provider is Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA (hereinafter "Cloudflare").
Cloudflare offers a globally distributed content delivery network with DNS. Technically, this means that the information transfer between your browser and our website is routed through Cloudflare's network. This enables Cloudflare to analyze the data traffic between your browser and our website and to act as a filter between our servers and potentially malicious traffic from the Internet.
The use of Cloudflare is based on our legitimate interest in providing our website as error-free and secure as possible (Art. 6 para. 1 lit. f GDPR).
Data transfer to the US is based on the standard contractual clauses of the EU Commission. Details can be found here: https://www.cloudflare.com/privacypolicy/.
Further information on security and data protection at Cloudflare can be found here: https://www.cloudflare.com/privacypolicy/.
Order processing
We have concluded a contract for order processing (AVV) for the use of the above-mentioned service. This is a contract required by data protection law, which ensures that the personal data of our website visitors is only processed in accordance with our instructions and in compliance with the GDPR.
Friendly Captcha
We use Friendly Captcha (hereinafter "Friendly Captcha") on this website. The provider is Friendly Captcha GmbH, Am Anger 3-5, 82237 Woerthsee, Germany.
Friendly Captcha is used to check whether the data entered on this website (e.g. in a contact form) is entered by a human or by an automated program. To do this, Friendly Captcha analyzes the behavior of the website visitor based on various characteristics. For the analysis, Friendly Captcha evaluates various information (e.g. anonymized IP address, referrer, visit time, etc.). Further information can be found at: https://friendlycaptcha.com/legal/privacy-end-users/.
The storage and analysis of the data is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in protecting its web offerings from abusive automated spying and from SPAM. If consent has been requested, processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG, insofar as the consent includes the storage of cookies or access to information on the user's terminal device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.
-
3. General information and mandatory information
-
Data protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.
When you use this website, various personal data is collected. Personal data is data with which you can be personally identified. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done.
We would like to point out that data transmission over the Internet (e.g. when communicating by email) may be subject to security vulnerabilities. It is not possible to completely protect data from access by third parties.
Information about the responsible body
The responsible body for data processing on this website is:
Harald Daub
Thomas Hoof Produktgesellschaft mbH & Co. KG
Bahnhofstraße 3
59348 LüdinghausenPhone: +49 2591 2590-210
Email: info@thpg.deThe responsible body is the natural or legal person who alone or jointly with others decides on the purposes and means of the processing of personal data (e.g. names, email addresses, etc.).
Revocation of your consent to data processing
Many data processing operations are only possible with your express consent. You can revoke your consent at any time. To do so, simply send us an informal email. The legality of the data processing carried out until the revocation remains unaffected by the revocation.
Right to lodge a complaint with the competent supervisory authority
In the event of violations of data protection law, the data subject has the right to lodge a complaint with the competent supervisory authority. The competent supervisory authority for data protection issues is the state data protection officer of the state in which our company is based. A list of data protection officers and their contact details can be found at the following link: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html.
Right to data portability
You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract delivered to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another responsible party, this will only be done to the extent that it is technically feasible.
SSL or TLS encryption
For security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the site operator, this site uses SSL or TLS encryption. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.
If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
Encrypted payment transactions on this website
If, after concluding a contract that involves payment, you are required to provide us with your payment details (e.g., account number for direct debit), this data will be used for payment processing.
Payment transactions using standard payment methods (Visa/MasterCard, direct debit) are carried out exclusively via an encrypted SSL or TLS connection. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.
With encrypted communication, your payment data that you transmit to us cannot be read by third parties.
Information, blocking, deletion
Within the framework of the applicable legal provisions, you have the right to obtain information free of charge at any time about your stored personal data, its origin and recipients, and the purpose of data processing, and, if applicable, a right to correction, blocking, or deletion of this data. For this purpose, as well as for further questions on the subject of personal data, you can contact us at any time at the address given in the legal notice.
Objection to advertising emails
We hereby object to the use of contact data published within the scope of the imprint obligation for the purpose of sending unsolicited advertising and information material. The operators of the pages expressly reserve the right to take legal action in the event of unsolicited sending of advertising information, for example through spam emails.
-
4. Data collection on our website
-
Cookies
Some of the Internet pages use so-called cookies. Cookies do not cause any damage to your computer and do not contain viruses. Cookies serve to make our offer more user-friendly, effective, and secure. Cookies are small text files that are stored on your computer and saved by your browser.
Most of the cookies we use are so-called "session cookies." They are automatically deleted after your visit. Other cookies remain on your device until you delete them. These cookies enable us to recognize your browser when you return.
You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when you close your browser. If you deactivate cookies, the functionality of this website may be restricted.
Cookies that are necessary for the electronic communication process or for the provision of certain functions you have requested (e.g., shopping cart function) are stored on the basis of Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in storing cookies for the technically error-free and optimized provision of its services. If other cookies (e.g., cookies for analyzing your surfing behavior) are stored, these are treated separately in this privacy policy.
Server log files
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
- Browser type and browser version
- operating system
- Referrer URL
- Host name of the accessing computer
- Time of the server request
- IP
This data is not merged with other data sources.
The basis for data processing is Art. 6 para. 1 lit. f GDPR, which permits the processing of data for the fulfillment of a contract or pre-contractual measures.
Contact
If you send us inquiries via the contact form, your details from the inquiry form, including the contact details you provided there, will be stored by us for the purpose of processing the inquiry and in the event of follow-up questions. We will not pass on this data without your consent.
The processing of the data entered in the contact form is therefore carried out exclusively on the basis of your consent (Art. 6 para. 1 lit. a GDPR). You can revoke this consent at any time. An informal email to us is sufficient for this. The legality of the data processing operations carried out until the revocation remains unaffected by the revocation.
The data you enter in the contact form will remain with us until you request its deletion, revoke your consent to its storage, or the purpose for which it was collected no longer applies (e.g., after your request has been processed). Mandatory legal provisions—in particular retention periods—remain unaffected.
Registration on this website
You can register on our website to use additional features on the site. We only use the data you enter for the purpose of using the respective offer or service for which you have registered. The mandatory information requested during registration must be provided in full. Otherwise, we will reject the registration.
For important changes, such as changes to the scope of the offer or technically necessary changes, we will use the email address provided during registration to inform you.
The data entered during registration will be processed on the basis of your consent (Art. 6 para. 1 lit. a GDPR). You can revoke your consent at any time. To do so, simply send us an informal email. The legality of the data processing already carried out remains unaffected by the revocation.
The data collected during registration will be stored by us for as long as you are registered on our website and will then be deleted. Statutory retention periods remain unaffected.
Processing of data (customer and contract data)
We collect, process, and use personal data only to the extent necessary for the establishment, content, or modification of the legal relationship (inventory data). This is done on the basis of Art. 6 para. 1 lit. b GDPR, which permits the processing of data for the fulfillment of a contract or pre-contractual measures. We collect, process, and use personal data about the use of our website (usage data) only to the extent necessary to enable the user to use the service or to bill for it.
The customer data collected will be deleted after completion of the order or termination of the business relationship. Statutory retention periods remain unaffected.
Data transfer upon conclusion of a contract for online shops, retailers, and goods shipping
We only transfer personal data to third parties if this is necessary for the execution of the contract, for example to companies entrusted with the delivery of goods or the credit institution responsible for payment processing. Further transfer of data does not take place or only takes place if you have expressly consented to the transfer. Your data will not be passed on to third parties without your express consent, for example for advertising purposes.
The basis for data processing is Art. 6 para. 1 lit. b GDPR, which permits the processing of data for the fulfillment of a contract or pre-contractual measures.
-
5. Analysis tools
-
Matomo (formerly Piwik)
This website uses the open source web analytics service Matomo. Matomo uses technologies that enable cross-page recognition of users to analyze user behavior (e.g., cookies or device fingerprinting). The information collected by Matomo about the use of this website is stored on our server. The IP address is anonymized before storage.
With the help of Matomo, we are able to collect and analyze data about the use of our website by website visitors. This allows us, among other things, to find out when which pages were viewed and from which region they came. We also collect various log files (e.g., IP address, referrer, browsers and operating systems used) and can measure whether our website visitors perform certain actions (e.g., clicks, purchases, etc.).
The use of this analysis tool is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the anonymous analysis of user behavior in order to optimize both its website and its advertising. If a corresponding consent has been requested (e.g., consent to the storage of cookies), processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR; consent can be revoked at any time.
IP anonymization
We use IP anonymization for analysis with Matomo. This means that your IP address is shortened before analysis so that it can no longer be clearly assigned to you.
-
6. Payment providers
-
PayPal
On our website, we offer payment via PayPal, among other methods. This payment service is provided by PayPal (Europe) S.à.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter referred to as "PayPal").
If you select payment via PayPal, the payment details you enter will be transmitted to PayPal.
The transfer of your data to PayPal is based on Art. 6 para. 1 lit. a GDPR (consent) and Art. 6 para. 1 lit. b GDPR (processing for the performance of a contract). You have the option to revoke your consent to data processing at any time. A revocation does not affect the effectiveness of data processing operations that have taken place in the past.
-
7. Newsletter
-
Newsletter data
If you subscribe to our newsletter (info letter), we will use the email address you provide to send you our email newsletter on a regular basis based on your consent in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR.
If we receive your email address in connection with the sale of a product and you have not objected to this, we reserve the right to send you regular offers for similar products from our range by email on the basis of Section 7 (3) UWG (German Unfair Competition Act). This serves to protect our legitimate interests in advertising to our customers, which outweigh any interests in protecting your rights and freedoms, in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR.
We use the double opt-in procedure to register you for our newsletter. This means that after you provide your email address, we will send a confirmation email to the email address you provided, asking you to confirm that you wish to receive the newsletter. If you do not confirm this, your registration will be automatically deleted. If you confirm that you wish to receive the newsletter, we will store your email address until you unsubscribe from the newsletter. The storage serves the sole purpose of sending you the newsletter. Furthermore, we store your IP addresses and the times of registration and confirmation in order to prevent misuse of your personal data.
You can revoke your consent to receive the newsletter at any time. You can revoke your consent by clicking on the link provided in every newsletter email, by sending an email to info@thpg.de, or by sending a message to the contact details provided in the legal notice. You will not incur any costs other than the transmission costs according to the basic rates.
We use a newsletter service provider, which is described below, to process the newsletter.
Inxmail
This website uses Inxmail to send newsletters. The provider is Inxmail GmbH, Wetzinger Straße 17, 79106 Freiburg (hereinafter referred to as Inxmail). Inxmail is a service that can be used, among other things, to organize and analyze the sending of newsletters. The data you enter for the purpose of receiving the newsletter will be processed on Inxmail's servers.
Data analysis by Inxmail
With the help of Inxmail, we are able to analyze our newsletter campaigns. For example, we can see whether a newsletter message has been opened and which links have been clicked on. This allows us to determine, among other things, which links have been clicked on particularly often. We can also see whether certain predefined actions have been carried out after opening/clicking (conversion rate). This allows us to see, for example, whether you made a purchase after clicking on the newsletter.
You can find Inxmail's privacy policy at: https://www.inxmail.de/datenschutz.
Anonymized tracking
We use anonymous tracking from Inxmail, which does not allow any conclusions to be drawn about your identity if you have expressly consented to this in advance.
Legal
Data processing is based on your consent (Art. 6 para. 1 lit. a GDPR). You can revoke this consent at any time with future effect.
Storage
The data you provide us for the purpose of receiving the newsletter will be stored by us until you unsubscribe from the newsletter or until the newsletter is no longer required. We reserve the right to delete or block email addresses from our newsletter distribution list at our own discretion within the scope of our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR. Data stored by us for other purposes remains unaffected by this.
After you unsubscribe from the newsletter distribution list, your email address may be stored by us or the newsletter service provider in a blacklist if this is necessary to prevent future mailings. The data from the blacklist will only be used for this purpose and will not be merged with other data. This serves both your interests and our interests in complying with the legal requirements for sending newsletters (legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR). Storage in the blacklist is not limited in time. You can object to the storage if your interests outweigh our legitimate interest.
Order processing
We have concluded a contract for order processing (AVV) with the above-mentioned provider. This is a contract required by data protection law, which ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
Website cookies
The following table shows which cookies we use and what information they store. All cookies are technically necessary and are required to ensure the technical performance of the website.
| Cookie name | Host(s) | Lifetime | Cookie description |
|---|---|---|---|
| FORM_KEY |
THPG.de .thpg.de |
Session 1 hour |
Ensures secure browsing for visitors by preventing cross-site request forgery. This cookie is essential for the security of the website and the visitor. |
| PHPSESSID | thpg.de | Session | Maintains the user's state across all page requests. |
| MAGE MESSAGES | thpg.de | 1 hour | Tracks error messages and other notifications displayed to the user, such as the cookie consent message and various error messages. The message is deleted from the cookie after it has been displayed to the buyer. |
| login_redirect | thpg.de | Session | Retains the target page that was loaded before the customer was prompted to log in. Only set if necessary. |
| MAGE-CACHE-SESSID | thpg.de | Session | Used in connection with load balancing. This optimizes the response rate between visitors and the site by distributing the traffic load across multiple network connections or servers. |
| MAGE-CACHE-STORAGE | thpg.de | 1 hour | Used in connection with load balancing. This optimizes the response rate between visitors and the site by distributing the traffic load across multiple network connections or servers. |
| MAGE-CACHE-STORAGE-SECTION-INVALIDATION | thpg.de | depends on the settings of the browser's local storage | Used in connection with load balancing. This optimizes the response rate between visitors and the site by distributing the traffic load across multiple network connections or servers. |
| SECTION_DATA_CLEAN | thpg.de | 1 hour | Used in connection with the shopping cart functionality. Remembers all wish lists and visitor passes during checkout. |
| SECTION_DATA_IDS | thpg.de | 1 hour | Used in connection with the shopping cart functionality. Remembers all wish lists and visitor badges during checkout. |
| PRIVATE_CONTENT_VERSION | thpg.de | 1 day | Required for the cache function. A cache is used by the website to optimize the response time between the visitor and the website. The cache is usually stored in the visitor's browser. |
| X-Magento-Vary | thpg.de | 1 hour | This cookie is used to deliver the correct customer-specific views of the shop from the cache. |
| MATOMO_SESSID | stats.thpg.de | 2 weeks | Used to store Matomo opt-out status. |
* Session = period until the browser is closed.
** Cookies that exceed the duration of a session can also be deleted manually via the browser settings or on the device under "Privacy" or "Content settings."