Protecting your personal data is vital to us. We handle information shared on our website with utmost confidentiality, following data protection laws and this privacy policy. This policy details the data we collect, its use, potential sharing, and your rights concerning your information. Personal data is any information linked to an identifiable individual as defined in Article 4 No. 1 of the GDPR.
Responsible for this website is:
Corbado GmbH
Lindwurmstraße 44
8033 Munich
Our website uses cookies, which are small text files stored in web browsers. They store identifiers and other data on devices like computers and phones, enhancing the overall user experience of our online service. Cookies cannot harm your device in any way; instead, they help us remember settings like language preferences, understand if you've accepted other optional cookies, and identify returning visitors. They also allow for a smoother browsing experience and the efficient functioning of our website. We don't just refer to traditional cookies. When we mention "cookies", it includes similar technologies serving the same purpose. Our site integrates both our proprietary cookies and those from third-party services.
Technically necessary or required cookies:
These are set when you visit our website and are critical for its proper functioning. Examples include cookies recognizing language choices or noting if you've agreed to other optional cookies. These essential cookies are temporary and get removed when you close your browser. The use of such cookies aligns with Art. 6 para. 1 p. 1 lit. f) GDPR, reflecting our genuine intent to ensure a seamless and efficient website experience.
Non-Required Cookies:
These are used to gather extra insights about our visitors' preferences and behaviors, helping us refine our website and improve customer interactions. Setting these cookies happens only with your clear approval. The legal grounding for these cookies comes from your explicit consent, as per Art. 6 (1) S.1 lit. a) GDPR.
To deliver the features of our website, we incorporate services from third parties. We categorize these services into functional and analytical ones in the sections below.
Functional services ensure a seamless experience on our website and are essential for its use.
StripeThis site offers payment through Stripe Payments Europe, Ltd, Grand Canal Dock, Dublin. When paying via Stripe, your data is sent through our interface for processing. Learn more in Stripe's privacy policy: https://stripe.com/de/privacy. Data transfer to Stripe follows Art. 6 para. 1 p.1 lit. b) GDPR and our interest in secure payment methods (Art. 6 para. 1 p.1 lit. f) GDPR). Data is stored for its intended purpose and then deleted, unless legally required otherwise.
Hotjar
We use Hotjar for analytics, provided by Hotjar Ltd in Malta. They process user and meta data in the EU. The processing is based on consent per Art. 6 para. 1 p. 1 lit. a DSGVO, which can be revoked anytime. Data is kept until its purpose ends and there's no retention obligation. More details: https://www.hotjar.com/legal/policies/privacy/.
Webflow
We use Webflow, based in San Francisco, CA, USA, for website creation. They process user and meta data in the USA. Our legitimate interest in maintaining a website is grounded on Art. 6 para. 1 p. 1 lit. f DSGVO. Data transfer outside the EEA relies on standard contractual clauses, ensuring protection per GDPR's Article 46(2)(c). Data is kept until its purpose concludes. More details: https://webflow.com/legal/eu-privacy-policy.
Sendgrid
We use Sendgrid by Twilio, Inc, based in San Francisco, CA, USA, for sending emails.They process content and data in the USA. Order confirmations rely on Art. 6 para. 1 b) DSGVO, while consent-based emails use Art. 6 para. 1 lit. a) DSGVO. Data is retained until its purpose concludes. More details: https://www.twilio.com/legal/privacy.
These services assist us in gaining insights into the usage patterns of our website.
Google Analytics
We use Google Analytics, a tool from Google Ireland Limited, to analyze our website's user behavior. It gathers data like pages viewed, time spent, operating systems, and user origins, which Google may organize into specific user profiles. This service uses technologies like cookies and may store data on US-based Google servers. Due to potential data protection differences, there's a risk of data access by authorities in the USA. For enhanced privacy, we employ IP anonymization, truncating IP addresses within the European Union before sending them to the USA. Google processes this data to assess website usage and promises not to merge IP addresses with other data. Users can restrict Google's data collection by installing a specific browser plugin.
Google Ads
The website uses Google Ads from Google Ireland Limited for online advertising. Google Ads displays ads based on user's search terms and user data like location and interests. We can assess the effectiveness of our ads by analyzing which search terms triggered them and the resulting clicks. Using Google Ads requires explicit user consent as per Art. 6 para. 1 p. 1 lit. a) GDPR, which can be withdrawn anytime.
Google Conversion-Tracking
This website utilizes Google Conversion Tracking, provided by Google Ireland Limited, Gordon House, Dublin. Google and we use this tool to track user actions, like button clicks and frequent product views or purchases. The gathered data helps us generate conversion stats, but doesn't personally identify users. Google employs cookies or similar technologies for this. Your consent, based on Art. 6 para. 1 p. 1 lit. a) GDPR, is required and can be revoked anytime. More on Google Conversion Tracking is in Google's privacy policy: https://policies.google.com/privacy?hl=de.
Google Tag Manager
We use Google Tag Manager, by Google Ireland Limited in Dublin, for analysis and advertising. They process user data in the USA. Based on Art. 6 para. 1 p. 1 lit. a DSGVO, processing requires consent, which can be revoked at any time via our privacy policy contact details. Data transfer outside the EEA is secured by standard contractual clauses following GDPR's Article 46(2)(c). Data is retained until its purpose ends. More: https://policies.google.com/privacy?hl=de.
Matomo
We use Matomo for website analytics, operated by Matomo.org in Wellington, New Zealand. Matomo analyzes user behavior, including site visits and device details, based on Art. 6 para. 1 p. 1 lit. a DSGVO and user consent. Consent can be revoked anytime via our contact details. We store Matomo data on our servers, ensuring enhanced privacy, and anonymize IP addresses. Data is kept until its purpose concludes. More details: https://matomo.org/privacy-policy/.
Our website is hosted by an external provider. Data, including IP addresses, contact details, and website activity, is stored on their servers. We use this hoster to fulfill contracts with clients and ensure our website is secure and efficient as per Art. 6 para. 1 p. 1 lit. b) and f) GDPR. The hoster processes your data only as required to provide their services.
Unless specified in this Privacy Policy, your personal data won't be shared with third parties or processors as per Article 28 of the GDPR.
Your personal data may be processed in third countries, subject to local laws, making them accessible to local entities. To ensure data security during such transfers outside the EU, we adopt measures like EU standard contractual clauses or internal data protection guidelines. If these aren't applicable, transfers are conducted based on Art. 49 GDPR exceptions. Regardless of location, we implement safeguards to maintain data security at EU-equivalent levels.
We prioritize minimalistic data processing and only store your personal data as long as necessary for its original purpose or as mandated by legal obligations, such as commercial and tax retention requirements. Typically, data is retained for the duration of our contractual relationship or in line with legal retention periods, like those in the German Commercial Code and Tax Code. For security and technical reasons, IP addresses and server log files are stored for seven days. The duration of storage is also influenced by factors like data relevance, contract status, inquiry status, and relevant legal retention periods for the respective personal data.