This Data Protection Policy informs about which personal data is collected in the using of the website (hereinafter: “Website”), the purposes, the methods the referring data will be used, and the rights which users are entitled.

  1. Responsible Party

The responsible party within the meaning of the General Data Protection Regulation

(hereinafter: “GDPR”) for the processing of personal data concerning the use of the website:

XOUXOU Berlin - Inh. Richard Kirschstein

Hasenheide 12

10967 Berlin


(hereinafter: “xouxouberlin”, “us”, “we”)

  • Processing of data by navigating the website

  • When you navigate the website, the personal data is collected and transmitted by your browser on the server of the website and stored in temporarily Log Files. In this meaning, stored data means especially the following data:

    • IP Address of the inquiring computer
    • Name and URL of the accessed data
    • Date and hour of the access
    • Status of the access/HTTP Code Status
    • Respectively transferred data volume
    • Identification data from the used browser

    The processing of this referring data is technically essential to ensure the stability and security as well as connection reports of the website. The storage in the Log Files occurs to guarantee the functionality of the website. Besides, this data is also used to optimise the website and to guarantee the security of our systems. 

    The processing of the data is the object of Article 6 (1) (f) GDPR (named as legitimate interests) insofar the processing of respective data is within the framework of the navigation of the website. The legitimate interests arise from the purposes aforementioned. 

  • Cookies

  • Our website uses Cookies. Cookies are text files which are stored on a computer system through an Internet browser. When a user visits our website, cookies can be stored on the user’s operating system. These cookies contain a peculiar character sequence which enables the unique identification of the browser in case the website is called up again.

    We use cookies to elaborate a more user-friendly website experience. A few elements from our internet site require that the accessed browser can even be identified after the user changes internet sites. 

    Concerning cookies the following data are stored and transferred:

    • Language settings
    • Items in the shopping cart
    • Log in/User information
    • Frequency of product view
    • Order procedure flow

    You can configure the browser settings accordingly to your wishes, for instance, the acceptance of third-party cookies or the rejection of all cookies. We inform you that if you have rejected the use of all cookies, you may not be able to use the full functionality of this website.

    We use cookies to identify the subsequent visits in case you have an account on the website. On the contrary, you must log in again for each visit.

    The legal basis concerning the processing of personal data originated by the use of cookies is the object of Article 6 (1) (f) GDPR (so called legitimate interests). The legitimate interests arise from the purposes aforementioned and to optimize the use of the website and to improve your user experience.

  • Website analysis
  • Google Analytics

  • This website uses Google Analytics which is a service of web analysis provided by Google LLC. (hereinafter: “Google”). Google Analytics uses the aforementioned “Cookies” which are text files stored on your computer and enable the analysis of the navigation of the website.  The information generated by the cookies regarding your use of the website which usually are transferred and stored to the Google Servers in the United States. However, in cases that the IP-Anonymous is active on the website, your IP-Address will be shortened beforehand within the member states of the European Union or in the other signatories states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address will be transferred to a Google server in the United States and shortened there.

    On behalf of the operator of this website, Google will use this information to evaluate your use of the website,  to compile reports regarding website activities and to provide other services relating to the use of the website as well as the use of the internet in connection with website operator. The IP Address transferred by your browser as part of Google Analytics is not merged with other data from Google. 

    You can impede the storage of cookies on the following settings on the software of your browser. However, please notice that in this case, you may not be able to use all the functionalities of the website to their full extent. Moreover, you can also prevent Google from collecting the data generated by the cookies and the data generated by the use of the website (including your IP Address) as well as the processing of this data through Google by downloading and installing the plug-in which is available under this link:

    As an alternative to browser plugin or within the browsers of your smartphone, please click on the following link in order to set an Opt-Out Cookie which will impede Google Analytics from collecting information from the website in the future (this Opt-Out cookie only works in this browser and only for the website, if you delete your cookies in your browser, you must click on this link again):

    Click here:

    This website uses Google Analytics with the extension "anonymizeIp()". This means that IP addresses are shortened for further processing, which excludes the possibility of personal references. As far as the data collected about you is related to a person, this is immediately excluded and the personal data deleted immediately. 

    In addition, this website uses Google Analytics for a cross-device analysis of the flow of visits, which is conducted with a User-ID. You can deactivate this cross-device analysis on the customer account and the following “My data” “Personal Data” tabs. 

    We use Google Analytics to analyze the use of the website and to improve it regularly. The statistics obtained allow us to improve our services and make them more interesting for you as a user. The legal basis for the use of Google Analytics is Art. 6 (1)(f) GDPR (legitimate interests). 

    For the exceptional cases in which personal data is transferred to the USA, Google has submitted to the EU-US Privacy Shield,

    Further information on Google Analytics can be found here:  

    and Google LLC, 1600 Amphitheater Parkway, Mountainview, California 94043, USA.

  • Marketing on our website
  • When you visit our website we analyze and we keep records of your user behavior to make our website more interesting and to target our advertising individually. In addition, we process your personal data for advertising purposes in the form of remarketing.

  • Google AdWords

  • We use on our website the online advertising system called Google-Ads which is provided by Google LLC., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

    In the context of Google Ads, we use the conversion tracking service (visit evaluation). If  you click on an advertisement placed by Google, a conversion tracking cookie is set. After 30 (thirty) days this mentioned cookie is not valid which means that the users cannot be individually identified. When you visit specific pages of our website and the cookies have not yet expired, Google and us can identify that you clicked on an advertising and that you have been transferred to this website.

    Each Google-Ad customer receives a different cookie. Thus, the cookies cannot be tracked

    through the websites of AdWords customers. The conversion cookie collects information which 

    is used in the production of conversion statistics and for ads customers who have opted-in for 

    conversion tracking. Customers are informed about the total number of users who clicked on 

    the ad and were forwarded to a conversion tracking tag page. However, you will not receive 

    any information enabling you to identify users personally. 

    The use of Google Ads is legally based on Article 6 (1) (f) GDPR (legitimate interests). We 

    have the legitimate interests concerning targeted advertising and the analysis pursuant to the effects and efficiencies of this targeted advertising.

    You are also entitled by law to refute at any time the processing of your personal data based on the Article 6 (1) (f) GDPR.

    You can set your browser up to be informed when cookies are set and only allow cookies in certain cases, such as to accept cookies for specific cases or total exclusion, including to activate automatic deletion of cookies when the browser is closed. You will find instructions on how to do this at:

    If cookies are deactivated, the functionality of this website may be restricted. 

    For the exceptional cases in which personal data is transferred to the USA, Google has submitted to the EU-US Privacy Shield,

    Further information and the privacy policy of Google can be found at:

  • Facebook-Pixel

  • We use the tool analysis named as “Facebook-Pixel” provided by the social media Facebook. Facebook-Pixel is a part of Facebook Inc., and it is located at 1 Hacker Way, Menlo Park, CA 94025, USA, in case you are located in the EU,  Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland („Facebook“).

    Facebook-Pixel help us concerning the measurement of our advertising efficiency and the analysis of actions taken by users on our website. Through Facebook-Pixel we are able to identify you as a visitor of our website as a target group for the presentation of ads (so-called "Facebook ads").

    We use Facebook-Pixel to target the Facebook-Ads only to display to Facebook users who have shown interest in our website or who shown certain features (for instance interest in certain topics or products) that we transfer to Facebook (named as “custom audience”). We want to ensure you that the Facebook-Ads are in accordance with the potential interest of the user.  In addition, we can track the effectiveness of Facebook ads for statistical and market research purposes by seeing if users were redirected to our website after clicking on a Facebook ad (name as "conversion").

    The establishment of Facebook Pixel as the storage of the “Conversion Cookies° are based on Article 6 (1) (f) GDPR (legitimate interests). We have a legitimate interest in the analysis of the behavior of the user in order to optimize our website and advertising.

    You may opt out of Facebook-Pixel collection and use of your information to display Facebook ads. You can deactivate the remarketing function "Custom Audiences" here

    For the exceptions where personal information is transferred to the United States, Facebook has submitted to the EU-US Privacy Shield,

    For more information about Facebook's collection and use of this information, your rights in this regard, and how Facebook can protect your privacy, please visit Facebook's privacy policy at

  • Google Analytics Remarketing
  • On the website, we use the Google Analytics Remarketing features in conjunction with the cross-device features of Google Ads and Google DoubleClick. The provider is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

    This feature enables you to link the advertising target groups created with Google Analytics Remarketing with the cross-device functions of Google Ads and Google DoubleClick. This allows us to display interest-based, personalized ads that have been customized to you based on your past usage and browsing behavior on one device (e.g., mobile phone) on another of your devices (e.g., tablet or PC). If you have given your consent, Google will link the web and app browser history to your Google Account for this purpose. In this way, the same personalized advertising messages can be displayed on any device on which you sign in with your Google Account. To support this feature, Google Analytics collects Google-authenticated user IDs that are temporarily linked to our Google Analytics data. This allows target audiences to be defined and created for cross-device advertising.

    You can permanently opt out of cross-device remarketing/targeting by deactivating personalized advertising in your Google Account [Opt-Out Link] and/or by following the link below and downloading and installing the plug-in provided there:

    The data collected in your Google account is summarized on the basis of your consent, which you can give or revoke at Google (Art. 6 (1) (a) GPDR). In the case of data processing that is not merged into your Google Account - for example, because you do not have a Google Account or because you have been objected to the merging - the legal basis is the processing of the data Art. 6 (1) (f) GDPR (legitimate interests). The legitimate interest results from our interest in the anonymous analysis of website visitors for advertising purposes in order to address you in a targeted manner with interest-related advertising.

    For the exceptional cases in which personal data is transferred to the USA, Google has submitted to the EU-US Privacy Shield,

    Further information and the privacy policy of Google can be found at:

  • Establishment of contact

  • A contact form is available on the website, which can be used for electronic contact. The data entered in the input mask will be transmitted to us and stored, if you send us an inquiry. These data are: 

    • Your name 
    • email address 

    Moreover, at the time the message is sent, the date and time will be stored and, if applicable, other data provided by you if you specify in the message sent.

    Alternatively, you can contact us via the e-mail address provided. In this case, the personal data of the user transmitted with the e-mail will be stored. The data is used exclusively for the purpose of processing contact inquiries and serves to prevent misuse of the contact form and to ensure the security of our information technology systems. 

    The legal basis for the processing of this personal data is Art. 6 (1) (f) GDPR (legitimate interests). The legitimate interest arises from the fact that we can only process the user accordingly with the user has acknowledged  (e.g. answering inquiries). Additionally, the legal foundation of data processing is Art. 6 (1) (b) GDPR if the purpose of the contact is to conclude a contract.

  • Newsletter
  • On the website, there is a possibility to order a free newsletter. When you sign up for it, your email is transferred. The collection of user’s email address is to send the newsletter.

    We use for the registration of the newsletter a Double-Opt-In procedure. This means that after registration we will send you an e-mail to the given e-mail address in which we will ask you to confirm that you wish to receive the newsletter. If you do not confirm your registration within 24 hours, your information will be blocked and automatically deleted after one month. In addition, we store the IP addresses you use and the dates of registration and confirmation. The purpose of this procedure is to prove your registration and to clarify and clear any possible misuse of your data.

    The newsletter is sent by a service called “MailChimp”, which is located in the USA. Therefore, the transmitted data is processed in this mentioned jurisdiction.  The email delivery MailChimp has certified to the EU-U.S. Privacy Shield Framework and Swiss-U.S. Privacy Shield Framework thus offers a guarantee to comply with the European data protection level ( The data protection regulations of this service provider can be viewed here: "MailChimp" can use the data of the recipients without allocation to an individual user, to optimize its own service or for statistical purposes. The email delivery service does not use the data of our newsletter recipients to itself or to forward the data to third parties. When the newsletter is sent, your user behavior is evaluated by MailChimp. For this evaluation, the e-mails sent contain so-called Web-beacons, more specifically, tracking pixels, which represent one-pixel image files stored on our website. For evaluation purposes, we link the data specified in Section II and the Web-Beacons with your e-mail address and an individual ID. We use the data obtained in this way to create a user profile in order to target the newsletter to your individual interests. We record when you read our newsletter, which links you click in it and infer your personal interests from this. We link this data with the actions you take on our website. You can unsubscribe this tracking at any time by clicking on the separate link provided in each e-mail or by informing us through another contact procedure. The information is stored as long as you have subscribed to the newsletter. After you have unsubscribed, we store the data purely statistically and anonymously. Such tracking is also not possible if you have deactivated the display of images in your e-mail program by default. In this case, the newsletter will not be displayed completely and you may not be able to use all functions. If you display the images manually, the above tracking will take place in connection with data processing for the delivery of newsletters, except for the provider MailChimp, no data is forwarded to third parties. The data will be used exclusively for the email delivery of the newsletter.

    The data will only be stored until you unsubscribe from the newsletter. Subsequently, the e-mail address will be blocked for the delivery of the newsletter and may be deleted altogether. You can unsubscribe from the newsletter at any time. For this purpose, you will find a corresponding opt-out link in every newsletter. You can also declare your cancellation by e-mail or by sending a message to the address given in the contact details website option.

    The legal basis for the processing of data relating to the delivery of newsletter by us is Article 6 (1) (a) GDPR (consent of the user) or, if there is a business relationship with regard to information on at least similar services by us, also Art. 6 (1) (b) GDPR (performance of contract). The email delivery service provider "MailChimp" will be informed based on legitimate interests pursuant to Art. 6 (1) (f) GDPR as well as contract order processing under Art. 28 (1) (3) GDPR.

    The legal basis for the processing of data relating to the delivery of newsletter by us is Art. 6 (1) (a) GDPR (consent of the user) or, if there is a business relationship with regard to information on at least similar services by us, also Art. 6 (1) (b) GDPR (performance of contract). The email delivery service provider "MailChimp" will be informed based on our legitimate interests pursuant to Art. 6 (1) (f) GDPR as well as contract order processing under Art. 28 (1) (3) GDPR.

  • Third parties

  • Vimeo

  • We have integrated videos and plug-ins of the online video platform "Vimeo" of the operator Vimeo, LLC, 555 West 18th Street, New York, New York 10011, USA. The content is stored on the servers of Vimeo and can be played directly from our website. Each time you access a page that offers one or more Vimeo video clips, a direct connection is established between your browser and a Vimeo server in the USA. The information about your visit and your IP address is also stored in the USA. Through interactions with the Vimeo plugins (e.g. clicking the start button), this information is also transmitted to Vimeo and stored in the USA. You can access the Vimeo's Privacy Policy, which explains how the company collects and uses your information:

    If you have a Vimeo user account and you do not want that Vimeo collects information about you and link it to your Vimeo member information through this website, you must log out of Vimeo before visiting this website.

    Besides, Vimeo uses the Google Analytics tracker via an iFrame in which the video is played. This is Vimeo's own tracking and we do not have any access to it. You can cancel the tracking   through Google Analytics by using the deactivation tools that Google offers for determined Internet browsers. 

    You can also prevent Google from collecting the data generated by Google Analytics and 

    according to your use of the website (including your IP address) as well as prevent Google from processing this data by downloading and installing the browser plug-in available at the following link:

    The legal foundation is Art. 6 (1) (f) GDPR (legitimate interests). The legitimate interest hereby is that the provider has a legitimate interest in understanding whether and how often the website is used to ensure and improve the functionality of its services. In addition, our legitimate interest lies in an appealing presentation and illustration of our offers through videos on the website for the benefit of the users and a needs-based design of our website.

  • Social Media 

    1. Plug-Ins

    We currently use the following social media plug-ins: Facebook, Instagram, and Pinterest. We  

    use the so-called Double-click solution. This means that when you visit our website, no personal data will be forwarded to providers of the plug-ins. You can recognize the provider of the plug-in by the marking on the box above its initial letter or logo. The buttons allow you  to communicate directly with the provider of the plug-in. If you click on the marked area and thereby activate it, the plug-in provider receives the information that you have visited the corresponding website of our online service. In addition, the data aforementioned to in Clause II (Processing of data by navigating the website) shall be transmitted. 

    In Germany, the IP information originated through the Facebook platform will be automatically anonymized after collection. By activating the plug-in, your personal data will be transferred to the Plug-In provider and then store in the USA in case the provider is situated in this jurisdiction. Since the plug-in provider collects data in particular via cookies, we recommend that you delete all cookies via your browser's security settings before clicking on the grey box. 

    We do not influence on the collected data and data processing procedures, nor are we aware of the full scope of the data processing, the purposes of data processing, the periods of storage. Moreover, no information is present to us according to the deletion of the raised data by the plug-in providers.

    The plug-in provider stores the data collected about you as usage profiles, and uses the

    following data for purposes of advertising, market research and/or demand-oriented designs of its website. Such evaluation is carried out in particular (also for users who are not logged in) to display demand-driven and oriented advertising and to attract your network about your

    activities on our website. You are entitled to object to the creation of these user profiles,

    whereby you must contact the respective plug-in provider to exercise this right. Through the

    plug-ins, we offer the possibility to interact with social networks and other users, so that we can improve our offer and make it more interesting for you as a user. 

    The legal basis for the use of the plug-ins is Art. 6 (1) (f) GDPR (legitimate interests).

    The data transfer takes place regardless of whether you have an account with the plug-in 

    provider and are logged in. If you are logged in at the plug-in provider, your data collected by 

    us will be directly transferred to your existing account in the platform of the plug-in. If you press 

    the activated button and, for example, link the page, the plug-in provider also stores this 

    information in your user account and communicates it publicly to your contacts. We 

    recommend that you log out regularly after using a social network, especially before activating 

    the button, as this avoids assigning your profile to the plug-in provider.

    1. Website of the Company

    When you visit our Facebook, Instagram and/or Pinterest profiles, these platforms collect your 

    personal information. This is also valid if you do not have a respective user account. Please note that we cannot control the type and extent of data processing by social media providers. The providers only provide us with anonymous demographic data in aggregated form, which helps us to get to know our audience better.

    1. Further Information about the Social Media Providers

    Further information on the purpose and scope of data processing and the processing by social

    media providers can be found in the Data Privacy Policies of these providers. In the mentioned 

    policies, you will also find further information on the relevant rights and setting options to 

    protect your privacy. 

  • Instagram, Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland 

  • Shopping

  • Registration and User Account

  • You can create a user account on our website. The data is entered in an input mask and 

    transmitted to us and stored. When registering for a user account, the following data is 

    collected and stored  is saved:


    As part of the login process, your e-mail address and a self-chosen password will be collected. 

    Moreover, the IP address of the user as well as the date and time of the login are stored at 

    the time of the login. 

    The legal basis for the processing of the aforementioned data is Art. 6 (1) (b) GDPR

    (performance of contract and pre-contractual measures). The registration and the login area 

    are necessary for the fulfillment of the contract or the implementation of pre-contractual 

    measures. The purpose of registration and login is to provide the login function for the order, to view your most recent orders, to manage your delivery and billing addresses and to edit the 

    password and account details. Your personal information will be used to support your user 

    experience on our website and to manage the access to your account.

  • Order

  • In addition, on the website we offer the possibility to request and purchase our products without registering for a customer account via an order form.

    The following data is collected as part of the order process through the order form:

    • First and last name (required)
    • Billing or delivery address (required)
    • E-mail address (required)
    • if applicable, details of payment method such as bank account number or credit card number, IBAN or Paypal (required)

    The order form serves the purpose of concluding a contract with us or sending a manufacturing request. The data which is processed in the order form, thus serves to conclude or terminate the contract with the user.

    For the operation of our online store we use Shopify, a service of Shopify Inc., Shopify International Limited Victoria Buildings, 2nd floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland. Shopify provides an e-commerce platform through which we sell our goods. The personal data processed by Shopify, e.g. As part of the ordering process, they will also be transmitted to regions outside Europe, including Canada and the United States, where the data may also be stored. Further information can be found in the privacy notices of Shopify at

    The legal basis for this data processing is Art. 6 (1) (b) GDPR (fulfillment of contract and pre-contractual measures), as the user provides us with the data based on the respective contractual relationship (for example, managing the customer account, processing the purchase contract).

  • Payment Service Providers

  • We use external payment service providers such as Paypal, Instant Transfer, Google Pay and, Apple Pay to process credit card payments, whose platforms are used to process payment transactions. The following data belong to the data processed by the payment service providers: Inventory data, such as name and address, bank data, such as account numbers or credit card numbers, passwords, TANs and checksums, as well as contract, total and recipient details. Depending on the service provider, this information is mandatory in order to successfully complete the transactions. 

    The data entered by you will only be processed and stored by the external payment service providers named by us. We do not receive account or credit card related information. We will be only informed either the payment is completed or we will receive negative information. Under certain circumstances, the data may be transmitted to credit agencies of the payment service providers named by us. The purpose of this transmission is to check identity and creditworthiness. The payment transactions are subject to the data protection notices of the respective payment service providers, which can be accessed within the respective websites or transaction applications. We refer to these also for the purpose of further information and assertion of revocation, information and any other affected rights:

  • Transmission of Data
  • The personal data collected within the framework of the use of the website will not be passed on to third parties or transmitted in any other way without your consent, unless otherwise expressly described in this Data Protection Policy.

    For the operation of the website and the services offered on the website, external service providers (e.g. hosting providers; newsletter service providers) are used who process your personal data on our behalf and exclusively in accordance with our instructions. The legal basis for such data processing is Art. 6 (1)(b) GDPR (performance of contract and pre-contractual measures) and Art. 28 GDPR  (contract order processing).

    If necessary, personal data will be transferred to state institutions and authorities, insofar as there is a legal obligation to do under Art. 6 (1) (c) GDPR.

  • Storage Duration
  • Your personal data will only be stored for as long as is necessary to process your requests to us, unless a different storage duration results from other provisions of this Data Protection Policy. Moreover, we store your data only to the extent and to the extent that we are obliged to do so by mandatory statutory storage obligations. If we no longer need your data for the purposes described above, they will only be stored during the respective legal retention period and not processed for other purposes.

  • Rights of persons affected 
  • Right of Objection

  • You have the right of objection against the processing of your personal data (Art. 21 GDPR) if the relevant personal data is processed based on legitimate interests (Art. 6 (1) (f) GDPR) and in case reasons are arising from your particular situation. In case of direct advertising, you may object to the processing of the data is possible at any time without providing any particular information.

  • Further Rights
  • Moreover, you have the right to:

    1. a) to request information about the personal data stored about you at any time (Art. 15 GDPR);
    2. b) to demand the correction or completion (Art. 16 GDPR), deletion (Art. 17 GDPR) or restriction (Art. 18 GDPR) of the processing of the corresponding personal data, insofar as the legal requirements are met;
    3. c) to receive your personal data in a structured, common and machine-readable format (Art. 20 GDPR);
    4. d) revoke at any time for the future any consent granted to the use of personal data (Art. 7 para. 3 GDPR); and 
    5. e) complain to the competent data protection supervisory authority if you are of the opinion that the processing of your personal data concerning  the use of the website violates applicable data protection law (Art. 77 GDPR).
    1. To make use of one of your rights mentioned above, simply send an e-mail to

  • Data Security
  • To guarantee data security, in particular to protect your personal data from the risks involving data transmissions and from third parties gaining knowledge, we use current technical and organizational measures when operating the website. These are being adjusted accordingly to the latest forms of technology.

  • Changes and Update
  • Due to further developments of our website or the amendment of legal dispositions, it may be necessary to change this privacy policy. Therefore, we reserve the right to change this Data Protection Policy at any time with effect for the future and thus recommend that you read this Data Protection Policy regularly.

    Last Update: November 2019