Datenschutzerklärung
Last updated: June 2026
1. Introduction & Our Commitment
Nordfeld ("we", "us", "our") is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect the information you provide when using our website at www.nordfeld.de or placing an order with us.
Nordfeld acts as the data controller under the EU General Data Protection Regulation (GDPR). This means we are responsible for determining how and why your personal data is processed. We will never sell, rent, or trade your personal data to third parties under any circumstances.
If you have any questions about this policy or how we handle your data, please contact us at kontakt@nordfeld.de.
2. Information We Collect
We collect two categories of information.
The first is information you provide directly to us. This includes your name, email address, delivery address, billing address, phone number, and payment information when you place an order or contact our support team. We also collect any communications you send us, including enquiries and return requests.
The second is information collected automatically when you visit our website. This includes your IP address, browser type and version, device type, operating system, pages visited, time and date of your visit, and referring URLs. This data is collected through cookies and similar tracking technologies, as described in Section 4.
3. How We Use Your Information
We use your personal data for the following purposes.
We process your name, address, payment, and contact details to fulfil your order, send order confirmation and dispatch emails, and provide customer support. This processing is necessary for the performance of a contract between you and Nordfeld.
Where you have given your consent, we may send you marketing communications about new products, promotions, and updates. You may withdraw your consent at any time by clicking the unsubscribe link in any marketing email or by contacting us directly at kontakt@nordfeld.de. Withdrawal of consent does not affect the lawfulness of processing carried out before that withdrawal.
We also use aggregated and fully anonymised data for internal analytics purposes, such as understanding website traffic patterns and improving the customer experience. This data cannot be used to identify you as an individual.
4. Cookies & Tracking Technologies
Our website uses cookies and similar tracking technologies to operate effectively and to deliver relevant advertising.
Strictly necessary cookies are essential for the website to function correctly. They enable core functionality such as shopping cart management, secure checkout, and session handling. These cookies cannot be disabled without affecting your ability to use the website.
Analytical and advertising cookies are used to understand how visitors interact with our website and to serve relevant ads on third-party platforms. We use cookies and tracking pixels associated with Meta (Facebook and Instagram), Google Ads, and TikTok for these purposes.
On your first visit to our website, you will be presented with a cookie consent tool. You may accept or decline non-essential cookies at that time, and you may update your preferences at any time through the cookie settings on our website.
5. Order Fulfilment & Third-Party Services
To operate our store and deliver your orders, we work with a carefully selected group of trusted third-party service providers. Each provider acts as a data processor on our behalf and is bound by strict data protection obligations.
Our store is built and hosted on Shopify, which provides the infrastructure, checkout, and order management systems we rely on. Shopify processes your data in accordance with their privacy policy and GDPR obligations.
Payment processing is handled by our payment providers, which include Shop Pay, Visa, Mastercard, American Express, Diners Club, Discover, Apple Pay, Google Pay, and PayPal Wallet. These providers handle your payment details securely and in compliance with PCI-DSS standards. Nordfeld does not store your full card details on our systems.
To ensure fast and reliable order delivery, we fulfil orders from multiple logistics centres located in the United States, Germany, and China. All fulfilment centres — regardless of location — operate under the same strict quality control standards, and every order is processed and packaged with the same level of care. Orders are routed to the most efficient centre based on stock availability and proximity to the delivery address, which allows us to dispatch quickly and reduce delivery times. Only your name and delivery address are shared with our fulfilment and shipping partners for the purpose of delivering your order.
Shipping carriers receive only your name and delivery address and use this information solely for the purpose of delivering your order.
We also use advertising and analytics tools provided by Meta, Google Ads, and TikTok. These platforms may use cookies and tracking pixels to measure the performance of our advertising campaigns and to show you relevant ads. For more information, please refer to Section 4.
6. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes described in this policy and to comply with our legal obligations.
Order records, including transaction details and associated personal data, are retained in accordance with German commercial and tax law, which requires retention for a minimum of ten years. After this period, data is securely deleted or anonymised.
If you request deletion of your data, we will fulfil that request within 30 days, subject to any overriding legal obligations that require us to retain certain records.
7. Your Rights Under the GDPR
As a data subject under the EU General Data Protection Regulation, you have the following rights in relation to your personal data.
You have the right to access the personal data we hold about you. You have the right to request correction of any inaccurate or incomplete data. You have the right to request erasure of your data where it is no longer necessary for the purposes for which it was collected. You have the right to restrict processing of your data in certain circumstances. You have the right to data portability, allowing you to receive your data in a structured, machine-readable format. You have the right to object to processing carried out on the basis of legitimate interests or for direct marketing purposes. Where processing is based on consent, you have the right to withdraw that consent at any time.
To exercise any of these rights, please contact us at kontakt@nordfeld.de. We will acknowledge your request within 48 hours and provide a full response within 30 days.
8. International Data Transfers
As some of our third-party service providers operate outside the European Economic Area (EEA), your personal data may be transferred to and processed in countries outside the EEA, including the United States. Where such transfers occur, we ensure they are carried out in accordance with applicable data protection law, using appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission or adequacy decisions issued by the European Commission.
These transfers are subject to oversight by the competent supervisory authority of your EU member state. For customers in Germany, this is the BfDI (Federal Commissioner for Data Protection and Freedom of Information), reachable at bfdi.bund.de.
9. Data Security
We take the security of your personal data seriously. Our website uses SSL/TLS encryption to protect all data transmitted between your browser and our servers. Our store infrastructure is provided and maintained by Shopify, which applies industry-standard security measures including encryption, access controls, and regular security audits.
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours as required by the GDPR, and we will inform affected individuals without undue delay where required.
10. Children's Privacy
Our website and services are not directed at children under the age of 16, as defined under the EU General Data Protection Regulation. We do not knowingly collect personal data from anyone under this age. If you believe a child under 16 has submitted personal data to us, please contact us at kontakt@nordfeld.de and we will promptly delete the relevant information.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational circumstances. The date at the top of this page will always reflect the most recent version. Your continued use of our website following any changes constitutes your acceptance of the updated policy. We encourage you to review this page periodically.
12. Contact Us & Supervisory Authority
If you have any questions, concerns, or requests relating to this Privacy Policy or our data practices, please contact us at:
Email: kontakt@nordfeld.de
We will respond to all data-related enquiries within 48 hours and provide a full response within 30 days.
If you are not satisfied with our response, you have the right to lodge a complaint with the competent supervisory authority in your EU member state. For customers in Germany, the relevant authority is:
BfDI — Federal Commissioner for Data Protection and Freedom of Information Website: bfdi.bund.de