Privacy policy
Privacy Policy
Last updated: 25 March 2026
1. Controller
The controller responsible for data processing on this website is:
The Treats GmbH
Rosa-Luxemburg-Str. 23
10178 Berlin
Germany
Email: hello@1-3-3-1.com
2. General information
This Privacy Policy explains how we process personal data when you visit our website, create a customer account, place an order, contact us, subscribe to our newsletter, use our wishlist function, or otherwise interact with our online shop.
We process personal data in accordance with the General Data Protection Regulation (“GDPR”) and applicable German data protection law.
3. Categories of personal data
Depending on how you use our website, we may process the following categories of personal data:
- name, billing address, shipping address
- email address
- order, payment, and transaction data
- customer account data and login-related information
- communications submitted through the contact form or by email
- technical and usage data, such as IP address, browser, device, language, date and time of access
- consent and preference data, such as cookie choices and newsletter subscription status
- wishlist-related data
4. Accessing the website and server log files
When you visit our website, we automatically collect certain technical data that is required to display the website, ensure security and stability, and prevent misuse.
This may include:
- IP address
- date and time of access
- browser type and version
- operating system
- referrer URL
- accessed pages and files
- internet service provider
Legal basis: Art. 6(1)(f) GDPR
Our legitimate interest: secure and technically reliable operation of the website
5. Hosting and shop system via Shopify
Our online shop is operated via Shopify. Shopify provides the e-commerce platform through which we offer our products and services, including hosting, checkout, store functionality, and related technical services. Shopify says merchants must review and update privacy settings and content so they accurately reflect actual business practices.
Depending on the services used, Shopify may process personal data as our processor and, in some cases, for certain services, under its own responsibility as described in Shopify’s documentation and data processing terms. Shopify also provides tools for customer privacy settings, cookie banners, and policy management.
Legal basis:
Art. 6(1)(b) GDPR for order-related processing
Art. 6(1)(f) GDPR for secure and efficient operation of the shop
6. Customer account
Customers can create an account in our shop. When you do so, we process the data required to create and manage your account and to make future purchases easier.
This may include:
- name
- email address
- address details
- login details
- order history linked to the account
Legal basis: Art. 6(1)(b) GDPR
7. Orders and contract performance
When you place an order, we process your personal data to conclude and perform the contract.
This includes in particular:
- processing your order
- payment handling
- shipping and delivery
- invoicing
- communication regarding your order
- returns and customer service
Legal basis: Art. 6(1)(b) GDPR
Without the required data, we cannot process your order.
8. Payment processing
For payment processing, we use:
- PayPal
- Shopify Payments
The data required for payment processing is transmitted to the selected payment provider only to the extent necessary for the transaction.
Legal basis: Art. 6(1)(b) GDPR
Please note that the respective payment provider may process personal data under its own responsibility where necessary for payment execution, fraud prevention, regulatory compliance, or legal obligations.
9. Shipping
For the shipment of orders, we use:
- DHL
For this purpose, we transmit the data required for delivery, in particular name and shipping address and, where necessary, further delivery-related details.
Legal basis: Art. 6(1)(b) GDPR
10. Accounting and bookkeeping
For accounting and bookkeeping, we use sevdesk.
In this context, invoice and transaction data may be processed for bookkeeping, accounting, and tax purposes.
Legal basis:
Art. 6(1)(c) GDPR
where applicable, Art. 6(1)(f) GDPR for efficient business administration
11. Wishlist function
We use Wishlist Plus to provide a wishlist function in our shop. If you use this feature, data may be processed to save and display products you mark for later.
Depending on the configuration, this may include:
- saved products
- account-related identifiers
- browser-related identifiers
- technical usage data
Legal basis:
Art. 6(1)(b) GDPR if the feature is part of the service you request
or Art. 6(1)(f) GDPR for convenient shop functionality
where required, Art. 6(1)(a) GDPR for consent-based technologies
12. Newsletter via Klaviyo
If you subscribe to our newsletter, we process your email address and any additional data entered in the signup form in order to send you newsletters and related communications.
We use Klaviyo for newsletter management and delivery.
To document your consent, we may also store:
- the date and time of registration
- the IP address used at registration
- the date and time of confirmation
Legal basis: Art. 6(1)(a) GDPR
You can withdraw your consent at any time with effect for the future, for example via the unsubscribe link in each newsletter or by emailing us at hello@1-3-3-1.com.
13. Newsletter tracking
If newsletter performance tracking is activated in Klaviyo, we may process data on whether emails are opened and which links are clicked in order to better understand the relevance of our content and improve future newsletters. The EDPB has clarified that tracking techniques beyond classic cookies can also fall within ePrivacy-related rules.
Legal basis: Art. 6(1)(a) GDPR where consent is required
If you have disabled open and click tracking in Klaviyo, you should remove this section.
14. Contact form and email contact
If you contact us via the contact form or by email, we process the data you provide in order to handle your inquiry and any follow-up communication.
Legal basis:
Art. 6(1)(b) GDPR if your inquiry relates to an order or a potential contract
otherwise Art. 6(1)(f) GDPR
Our legitimate interest: efficient processing of inquiries and communication with customers and interested parties
15. Google Analytics
If you have given your consent, we use Google Analytics to analyze the use of our website and better understand how visitors interact with our shop.
In this context, information may be collected such as:
- pages visited
- duration of visit
- device and browser information
- approximate location
- interactions on the website
Google Analytics is only used if the required consent has been given through our cookie banner. Under German law, storing or accessing non-essential information on a user’s device generally requires prior consent unless an exception applies.
Legal basis: Art. 6(1)(a) GDPR
16. Meta technologies
If you have given your consent, we use Meta technologies such as the Meta Pixel in order to measure the effectiveness of our advertising, understand interactions with our website, and optimize future advertising activities.
This may involve the collection of information about:
- page views
- visited content
- actions taken on the website
- browser and device data
- marketing-related events
These technologies are used only on the basis of consent where required.
Legal basis: Art. 6(1)(a) GDPR
17. Cookies and similar technologies
We use cookies and similar technologies on our website.
Some of these are strictly necessary for the website and online shop to function properly. Others are used only with consent, for example for analytics or marketing.
Categories may include:
- strictly necessary technologies for cart, checkout, login, security, and consent settings
- functional technologies for convenience features such as wishlist functionality
- analytics technologies, including Google Analytics
- marketing technologies, including Meta
German law generally requires consent for storing information on, or accessing information from, a user’s device unless an exception applies. Shopify explains that its customer privacy tools can be configured so that, in consent regions, non-essential collection begins only after consent.
We use Shopify’s integrated customer privacy and cookie banner tools.
You can give, refuse, or withdraw your consent at any time through the cookie banner or privacy settings tool on our website.
18. Recipients or categories of recipients
We share personal data only where necessary and legally permitted. Recipients may include:
- Shopify as our e-commerce platform provider
- PayPal and Shopify Payments for payment processing
- DHL for shipping
- Klaviyo for newsletter delivery
- sevdesk for accounting and bookkeeping
- Wishlist Plus for wishlist functionality
- Google in connection with Google Analytics, where activated and consented to
- Meta in connection with Meta technologies, where activated and consented to
- IT, hosting, support, and service providers where necessary
- authorities, courts, legal advisers, or tax advisers where legally required or necessary
19. International data transfers
Some service providers we use may process personal data outside the European Union or European Economic Area, or may permit access from third countries.
This can apply in particular to Shopify and potentially to other software providers depending on their infrastructure and subprocessors. Shopify states that customer personal data may be transferred outside the EEA, UK, and Switzerland as necessary to provide services.
Where personal data is transferred to a third country, we ensure that an adequate level of protection is in place, for example through:
- an adequacy decision of the European Commission, where applicable
- standard contractual clauses or other appropriate safeguards, where required
You may request further information on the safeguards used by contacting us at hello@1-3-3-1.com.
20. Storage period
We store personal data only for as long as necessary for the relevant purposes or as required by law.
As a general rule:
- order, invoice, payment, and accounting data are stored for the period required under applicable commercial and tax law
- customer account data are stored for as long as the account exists, unless legal obligations require longer retention
- contact inquiry data are stored for as long as necessary to process the inquiry and any related follow-up
- newsletter data are stored until you unsubscribe or withdraw consent
- consent records may be stored for as long as necessary to demonstrate compliance
- technical log data are stored only for as long as necessary for security and operational purposes
21. Obligation to provide data
The provision of certain personal data is necessary for the conclusion and performance of a contract, especially in the context of orders and customer accounts. Without this data, we may be unable to process your order or provide the requested service.
Where data must be provided due to legal obligations, this follows from the applicable statutory provisions.
22. Your rights
Under the GDPR, you have the following rights, subject to the applicable legal conditions:
- right of access
- right to rectification
- right to erasure
- right to restriction of processing
- right to data portability
- right to object
- right to withdraw consent at any time with effect for the future
- right to lodge a complaint with a supervisory authority
To exercise your rights, please contact us at:
hello@1-3-3-1.com
23. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement. Germany has a federal system of data protection supervision, including state authorities.
For Berlin-based companies, the competent authority is generally the:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61
10555 Berlin
Germany
24. Automated decision-making
We do not use automated decision-making within the meaning of Art. 22 GDPR unless expressly stated otherwise in this Privacy Policy.
25. Changes to this Privacy Policy
We may update this Privacy Policy from time to time in order to reflect legal, technical, or business developments.