Privacy Policy
Datenschutzerklärung für Guilted
Stand: April 2025
We comply with the GDPR, BDSG, TTDSG, and all applicable EU and German regulations.
1. Controller
Mario Steinbuch
Nachodstr. 18, 10779 Berlin
mario@36chambers.studio
2. Types of Data We Process
2.1 Data provided directly by users
- Email address (creates account automatically)
- Form input describing the gift recipient
- Saved ideas, favorites, and generated content
- Optional newsletter preferences
2.2 Automatically collected data
- IP address (shortened)
- Device/browser type
- Usage events and log data
- Cookies (only after consent)
2.3 Tracking & analytics providers
We use:
- PostHog
- Google Analytics 4 (GA4)
- Microsoft Clarity
These services require user consent under TTDSG.
3. Purposes & Legal Bases
3.1 Providing the Service (Art. 6(1)(b))
- Account creation
- Generating personalized gift ideas
- Storing form submissions
3.2 AI Processing (Art. 6(1)(a) & (b))
AI providers process text entered into the form to create gift ideas.
We use:
- OpenAI
- Anthropic
- Other LLM providers
3.3 Analytics (Art. 6(1)(a))
PostHog, GA4, and Clarity only load after user consent.
3.4 Affiliate links (Art. 6(1)(f))
Commercial interest in participating in affiliate programs.
3.5 Newsletter (Mailchimp) (Art. 6(1)(a))
Double opt-in is required.
Service provider: Mailchimp (The Rocket Science Group LLC) using SCCs.
3.6 Payments (Art. 6(1)(b) & (c))
For premium features (if applicable):
- Stripe
- PayPal
- Klarna
We do not store payment data.
4. Data Retention
- Account data → until user requests deletion
- Form inputs → until account deletion
- Analytics → per provider settings (minimized)
- Payment-related documents → 10 years (legal obligation)
- Newsletter data → until unsubscription
5. Rights of Users
You may exercise the following rights anytime:
- Right of access (Art. 15)
- Right to rectification (Art. 16)
- Right to erasure (Art. 17)
- Right to restriction (Art. 18)
- Right to data portability (Art. 20)
- Right to object (Art. 21)
- Right to withdraw consent (Art. 7(3))
Requests: mario@36chambers.studio
6. Data Transfers to Third Countries
AI providers, Mailchimp, and some analytics services may be located outside the EU.
We use:
- Standard Contractual Clauses (SCCs)
- Additional safeguards
- Adequacy decisions where applicable
7. Security
We implement:
- Encryption
- Access control
- Secure cloud hosting
- Regular audits
8. Children
The service is not intended for users under 16.
9. Automated Decision-Making
No decisions with legal effect are made. AI-generated gift ideas are non-binding suggestions.