Privacy Notice CoT

The following Privacy Policy provides information on the processing of personal data (hereinafter also refer-red to as ‘data’) in the context of using the Trusted Shops Buyer Protection and other Trusted Shops services. They apply in addition to the general Privacy Policy which is available here. There you will find in particular information about the data controller and your rights. If you have any questions or wish to exercise your data protection rights, please contact us at privacy@trustedshops.com.

 

1. Definitions

Insofar as no specific definition is listed and the terms are legally defined in Art. 4 GDPR, the definitions from the GDPR apply.

"Review Invite”: A review invite is a message sent via email or SMS that contains a personal link to allow you to submit a review for a specific business.

"Guarantor": Trusted Shops uses insurers as guarantors to provide its services. Your purchase is covered by one of the listed guarantors.

"Joint Controllership”: Joint controllership describes the configuration in which Trusted Shops is jointly responsible for a processing operation with one or more other controllers in accordance with Art. 26 GDPR because the purposes and means of the processing are determined jointly.

"Partner Company”: Partner company means a company that uses Trusted Shops services (e.g., buyer protection, the review platform, widgets) and may possibly process personal data together with Trusted Shops.

"Online presence”: The online presence(s) (e.g., webshop, shop application on third-party sites, website, etc.) of the partner company that bears the Trusted Shops seal of approval, uses the review system or/and other services of Trusted Shops that are related to the processing activities described in this Privacy Policy.

“#trstd login“: The #trstd login is a button that can be integrated into the online presence of Trusted Shops or the online presence of a Partner Company. Via the trstd login, visitors to the online presence can register directly for the Trusted Shops services (then “consumer member”) or log into their account as an existing Trusted Shops member.

"Trustbadge/Widget": Trusted Shops provides various widgets that a company can integrate into its online presence. The widgets are used, for example, to display the average value of collected reviews or to inform about the certification and buyer protection of Trusted Shops and to enable the use of the Trusted Shops services. The Trustbadge is a special form of these widgets.

"Trustcard”: The Trustcard appears on the online presence of partner companies following a completed order. By clicking on the correspondingly marked button, you have the option of registering to receive review invitations or/and buyer protection or to completely secure your purchase.

"Buyer Protection": Trusted Shops Buyer Protection is a purchase protection that takes place at Trusted Shops certified partner companies. You can find more information here.

 

2. Information on the controllers subject to data protection law

The services described below are provided by Trusted Shops SE (hereinafter referred to as Trusted Shops) as the controller subject to data protection law. You can find contact information in the Legal Notice and the general Data protection information. For certain processing activities, there is also joint controllership in accordance with Art. 26 GDPR. In these cases, Trusted Shops determines the purposes and means of processing jointly with one or more other controllers. This may also involve an exchange of data. Those processing activities for which there is joint controllership, as well as the areas of responsibility, are identified accordingly in this Privacy Policy.

3. Data collection for the use of the services

a. Collection of personal data when the Trustbadge, #trstd login or widgets are displayed


In order to display the Trusted Shops seal of approval and any reviews collected, as well as to offer Trusted Shops products to buyers, the so-called Trusted Shops Trustbadge, the #trstd login or other widgets are integrated into the online presence of the partner company. The Trustbadge is provided by a CDN provider (content delivery network; subcontractor). Trusted Shops uses a service provider from the USA, whereby the processing takes place on servers in the country from which the website request is made. If you access the website from the EU, the processing will, therefore, take place in the EU. The partner company and Trusted Shops are jointly responsible for the dis-play of the Trustbadge/widget in accordance with Art. 26 GDPR.

In order to display the Trustbadge/#trstd login/widget, the processing of your IP address is technically necessary, among other things. The processing is based on Art. 6 (1) (f) GDPR and is necessary to fulfil the legitimate interest of the shop to offer buyer protection or to advertise it or the shop’s collected reviews. Insofar as the partner company asks for your consent, the legal basis is Art. 6 (1) (a) GDPR.

 

When the Trustbadge/widget is called up, the web server automatically saves a so-called server log file, which also contains your IP address, date and time of the call, amount of data transferred and the requesting provider (access data) and documents the call. The server log file is stored for 7 days and then deleted or anonymised. The legal basis is Art. 6 (1) (f) GPDR. The processing is necessary for the prevention of fraud and abuse, for the optimisation of our offer and website, as well as to ensure that the website, the Trustbadge, the #trstd login or other widget function properly.

Cookies and other technologies are used to enable the #trstd login process and to identify registered users. This processing is based on Art. 6 (1) (b) of the GDPR and Section 25 (2) No. 2 of the TDDDG.

b. Registration via the Trusted Shops website or a shop website

The input of your personal data is done by you when registering for the use of the Trusted Shops Services. The following data is collected:

Buyer Protection:

  • First and last name
  • Email address
  • Password (if applicable)

The initial collection of data takes place when you register for the use of Trusted Shops services either directly on our website, via the #trstd login or following a purchase in a partner company certified by Trusted Shops via the so-called Trusted Shops Trustcard. In order to render the Trusted Shops services you have booked, i.e. securing your purchase at a certified partner company carrying the Trusted Shops Trustmark with the buyer protection, the partner company you purchased from, transmits the order data to us. Whether you are already registered for buyer protection is first determined by transmission of the email address which has been hashed by a cryptological one-way function by the partner company to Trusted Shops. After checking for a match, the parameter is automatically deleted. If you are registered for the use of Trusted Shops Services, the following order data is automatically transferred to Trusted Shops SE.

  • Email address:
  • Shop ID
  • Order number
  • Order total and currency
  • Order date
  • Payment method

Your data will be used for contractual performance in accordance with Art. 6 (1) (b) GDPR in order to be able to offer you the Trusted Shops services for buyers. If we receive the data required for the provision of the services by integrating the Trustbadge into the online presence of the partner company from which you have made a purchase, this partner company is jointly responsible with Trusted Shops for the data collection. For further information, please refer to Clause 12.

 

4. Processing when a buyer protection or warranty case is opened

After you have opened a buyer protection or guarantee claim, the following data will also be collected, if necessary, in order to verify the obligation to refund:

  • Evidence of payments made
    • Copy of the bank statement
    • Cash on delivery receipt
    • Sworn testimony
  • Proof of returns
    • Copy of a deposit receipt
    • Sworn testimony
    • Proof of identity, e.g., copies of identity documents

You may and should black out any personal data not required on supporting documents, in particular, on copies of identity documents and bank statements.

 

You are contractually obligated to submit any evidence and supporting documentation we require. If you do not do this and we are consequently unable to verify the facts of your case, no refund can be made.

 

Your data will be used for contractual performance in accordance with Art. 6 (1) (b) GDPR in order to be able to offer you the Trusted Shops services for buyers. Insofar as we collect data in the context of a guarantee case opened by you, this is done in accordance with Art. 6 (1) (b) GDPR in order to provide you with the buyer protection as stipulated in the Terms of Use. Furthermore, the processing is carried out in accordance with Art. 6 (1) (f) GDPR to protect our overriding legitimate interests and those of the shop in determining whether there is an obligation to issue a refund.

 

Trusted Shops will provide the partner company with information regarding whether your order is covered and, if so, to what extent, as well as the status of any guarantee claims that have been filed. Any supporting documents you submit will also be forwarded to the partner company if necessary.

 

5. Sending review invites

If you have registered with us for our services, we will send you review invites as part of the service user agreement. In these cases, the data processing is necessary for the fulfilment of the contract in order to enable you to submit a review and is hence based on Art. 6 (1) (b) GDPR.

 

If you have given your express consent to a partner company using the Trusted Shops review system during or after your order in accordance with Art. 6 (1) (a) GDPR, we will use your email address to send you a re-view invite by email on behalf of the partner company. The consent can be revoked at any time by sending a message to the respective partner company.

 

The partner company for which Trusted Shops sends a review invite receives information from Trusted Shops on the status of the review invite (e.g., whether it has been sent and whether it has arrived). This is done in accordance with Art. 6 (1) (f) GDPR to fulfil the legitimate interest of the partner company to receive information on review invites sent on its behalf, in order to carry out optimisations based on this if necessary, as well as to fulfil the legitimate interest of Trusted Shops to be able to offer this service.

 

If you submit a review via the Trusted Shops review system, then, in accordance with Article 6 (1) (b) GDPR, Trusted Shops and the rated company will require your e-mail address to ensure the validity and trustworthiness of the review and to contact you if necessary in order to clarify any complaints and verify the submitted review. The e-mail address will be stored for this purpose along with a transaction number and the review, and will be shared with the reviewed company.

 

The respective partner company from which you have made a purchase is jointly responsible with Trusted Shops for the sending of review invites and the collection and display of information on its status. For further information, please refer to Clause 12.

 

You have the option of permanently unsubscribing from receiving review invites, regardless of the partner company for which Trusted Shops sends them. In this case, your email address will be placed on an internal blocklist. You can unsubscribe by clicking the link labeled as such, which is included in every review invitation. This unsubscription applies to the partner company for which you received the review invite. After clicking the link, you have the option to unsubscribe from all review invites, regardless of the partner company. You can also unsubscribe by sending an email to the contact address provided above. The processing is carried out in accordance with Art. 6 (1) (f) GDPR in order to fulfil our legitimate interest in preventing the sending of review invites.

 

6. Consumer Account and #trstd login

Consumer Account

When you register for the Trusted Shops services, a consumer account is created using your email address, allowing you to log in. You have the option, among other things, to view your protected purchases from the past 12 months, open buyer protection cases and submit reviews. You can also publish your review profile so that submitted reviews are shown in a personalised manner. In your personal address book, you can store addresses that you use during your purchases. The creation of the profile as well as any processing of personal data in the consumer account is carried out for the fulfilment of contractual obligations pursuant to Art. 6(1) (b) GDPR.

After logging in for the first time, you'll be asked to set a personal secret (#trstd secret). The #trstd secret consists of your name, a color of your choice, and a date that is meaningful to you. This serves to protect you from fakes by personalizing your profile so that you can always be sure you’ve logged into a consumer account and that the page you’re on is genuine. You can also upload a profile picture.

#trstd login

If the trstd login is integrated into online presences of partner companies, Trusted Shops and the partner company are joint controllers for the processing described below in accordance with Art. 26 GDPR. If the trstd login is integrated into online presences of Trusted Shops, Trusted Shops is the sole controller for the processing described below.

The #trstd login is a button that can be integrated into the online presence of Trusted Shops or the online presence of a Partner Company. Via the trstd login, visitors to the online presence can register directly for the Trusted Shops services (then “consumer member”) or log into their account as an existing Trusted Shops member. In addition to the data required for technical purposes to display the #trstd login, the #trstd secret you have stored will be displayed after you log in. If you are using the #trstd app, a push notification will be sent to your smartphone to provide you with information about the authenticity of the website you are visiting. This processing is based on Article 6(1)(b) of the GDPR.

In addition, when using the #trstd login, further data may be processed for the purposes described below.

a. Use of information for marketing and analysis purposes

Trusted Shops and the partner companies use the information you provide for analysis purposes, for the general optimization of the online presence and to be able to provide you with individual offers. The processing is based on the predominantly legitimate interests of Trusted Shops and the partner company in the aforementioned purposes in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR.

b. Collection of order information for personalization, marketing and analysis purposes

If you are logged in via the trstd login integrated into the online presence of an online store, Trusted Shops collects order information, such as the product purchased, in order to pass this information on to partner companies on an aggregated or personalized basis. Personal information may only be passed on after you have given your prior consent and only if you are logged in to the online presence of the respective partner company via the trstd login.

Order information for purchases on the respective online presence visited is shared with this partner company on the basis of the overriding legitimate interests of Trusted Shops and the partner company whose online presence is visited in the optimal marketing of the products and personalized customer service if a login is made via the trstd login.

c. Transfer of delivery address to partner companies

Using the trstd login, you can select from the address book the address needed for the respective purchase to automatically populate the delivery data in the partner company’s order process. These data are transmitted to the partner company upon full completion of the order. The legal basis for the transmission of your delivery address to the partner company is Art. 6(1)(1)(b) GDPR.

7. Review submission

If you click on a review invite link or log into the Consumer Account (only for registered users), you have the opportunity to review the partner company from which you have made a purchase, or a product that you have purchased and to write a review text. You will find links to the relevant terms of use and privacy policy before submitting the review. The partner company has the possibility to view and manage the submitted reviews in a system provided by Trusted Shops, and to comment on them. In addition, reviews submitted by the partner company can be exported and used for other purposes. The respective partner company and Trusted Shops are jointly responsible for the collection of the review as well as the processing in the systems of Trusted Shops in accordance with Art. 26 GDPR. The respective partner company is solely responsible for any further processing, in particular, for the export of evaluations and subsequent processing, as well as all associated obligations.

8. Processing for advertising purposes

We may use your email address, which we have received from you in the course of registering for the Trusted Shops Services, to send you advertising for our own similar goods or services. Advertising mails like this are sent out in accordance with Art. 6 (1) (f) GDPR for the fulfilment of our legitimate interest to advertise our products. The processing is carried out in accordance with the provisions of Section 7 (3) UWG (German Unfair Competition Act).

9. Recipients and categories of recipients incl. third country transfer

Hereinafter, we will inform you about data recipients or categories of data recipients, i.e., other responsible parties or order processors who receive personal data from Trusted Shops when you use the Trusted Shops services. In addition, we inform you about potential data transmissions to third countries.

 

Guarantor

The Trusted Shops Buyer Protection is an offer of the Trusted Shops SE. The Trusted Shops guarantee is offered by one of the following guarantors:

  • Atradius Kreditversicherung, Branch of Atradius Crédito y Caución S.A. de Seguros y Reaseguros, Opladener Straße 14, 50679 Cologne, Germany, Principal Representative: Dr. Thomas Langen, Amtsgericht (Local Court) Köln HRB 89229, main business activity: Credit Insurance, Data Protection Notice: https://atradius.de/datenschutz.html
  • R+V Versicherung AG, Raiffeisenplatz 1, 65189 Wiesbaden, Amtsgericht Wiesbaden HRB 7934, Data Protection Notice https://www.ruv.de/datenschutz

The respective guarantor is selected by Trusted Shops SE and will be named to you after you have registered for buyer protection. Transmission of your personal data collected during the use of the Trusted Shops Buyer Protection takes place only between Trusted Shops SE and the correspondingly selected guarantor and within the scope of necessity for the processing and/or implementation of the guarantee. This data will not be passed on to other third parties. The guarantor receives personal data only to the extent necessary for the performance of the guarantee. The legal basis for the transmission is Art. 6 para. 1 sentence 1 lit. b(1) (b) GDPR. The disclosure is necessary in order to provide the guarantee service offered by the guarantor.

 

Partner company

If you receive a review invite and, potentially, submit a review, the respective partner company will receive information from Trusted Shops as described in this Privacy Policy.

If you open a buyer protection case, it may also be necessary to transmit data to the partner company to which the buyer protection relates. The purpose is to check the plausibility of your information and to give the partner company the opportunity to issue a statement with their view on the matter. The legal basis is Art. 6 (1) (b) GDPR, as the transmission is necessary to provide the buyer protection. Moreover, the transmission is also based on Art. 6 (1) (f) GDPR. The transmission is necessary to protect our legitimate interest in determining whether or not there is a valid buyer protection / guarantee claim. In addition, the partner company also has a legitimate interest to comment and defend themselves.

 

Use of service providers

In addition, we use various service providers that process data on our behalf in order to provide our services, for example, for hosting, email dispatch, or subscription and payment management. Generally, data processing takes place in member states of the European Union (EU) or the European Economic Area (EEA). Your personal data collected when using the Trusted Shops Buyer Protection is only transferred to third countries if you contact our customer service that uses a ticket system provider as a subprocessor in order to process enquiries and requests. We have concluded standard data protection clauses with our service providers in accordance with Art. 46 (2) (c) GDPR. In addition, our service provider for the ticket system has adopted Binding Corporate Rules approved by the competent supervisory authority in accordance with Art. 47 GDPR. Nevertheless, there may be risks associated with processing personal data in third countries. Please refer to the "Third Country Transfer" section of the Privacy Policy on our website. For transfers to the United States, an adequacy decision applies to all companies registered under the EU-U.S. Data Privacy Framework (DPF). In this case, data may be transferred without further safeguards.

10. Automated decision making including profiling

Using the Trusted Shops Buyer Protection does not entail any automated decision-making processes.

11. Duration of the storage of personal data

The personal data processed is generally stored for as long as you are registered for the Trusted Shops ser-vices. In addition, the storage period is based on the necessity for the specific processing purposes and the relevant retention periods of 6 years or 10 years stipulated respectively by the German Commercial Code (Sec. 257) and the German Fiscal Code (Sec. 147). The personal data is, therefore, stored at least for the duration of the statutory retention periods. If personal data is required for verification and documentation purposes, the storage period is 3 years.

12. Information on joint controllership in accordance with Art. 26 (2) (2) GDPR

Joint controllership with the partner company

Trusted Shops has concluded an agreement in accordance with Art. 26 GDPR with each partner company in terms of our joint controllership.

The partner company is responsible for fulfilling its information obligations and for ensuring a legal basis in connection with the collection of personal data that takes place in its online presence (for example, with regard to the transmission of order data for the conclusion of buyer protection or for dispatching review invites). If data is stored on systems of the partner company, then said partner company is responsible for all associated obligations, in particular, ensuring the security of processing and compliance with erasure obligations.

Trusted Shops is responsible for the fulfilment of information obligations and other obligations arising from the GDPR, insofar as personal data is collected on its own websites (for example, when you submit reviews) or is processed on its own systems. This particularly concerns our ensuring that the data processing is secure as well as our compliance with deletion obligations.

You can file requests based on your data subject rights in connection with any processing activities that are subject to joint controllership with Trusted Shops. Nevertheless, you have the right to also contact the respective partner company directly. Your request may be forwarded to other responsible parties if this is necessary for processing.

 

Joint controllership with the guarantor

Trusted Shops SE and the respective guarantor are joint controllers within the meaning of the German Data Protection Act and Art. 26 (1) GDPR.

Trusted Shops SE is responsible for complying with all data protection requirements laid down by the GDPR insofar as the data processing is carried out by Trusted Shops SE. As soon as personal data has been transmitted to the respective guarantor, it is responsible for all processing activities on its own part, and for its compliance with the respective GDPR requirements.

We kindly ask you to contact Trusted Shops SE with any data protection concerns and, in particular, with the assertion of your data subject rights in connection with the use of the Buyer Protection. You nevertheless have the right to contact the guarantor directly as well. For information on data protection, please refer to the privacy policies of the guarantors that are linked above.

 

 

Status of the privacy notice: April 2026