Get 30% off your first purchase ⬇️
Subscribe to the newsletter!
Privacy Policy
Last updated: June 2026
This website is operated by:
Anaïs Neumann, trading as Sew Into That
c/o Impressumservice Dein-Impressum
Stettiner Straße 41
35410 Hungen
Germany
Tel.: +49 172 3295668
Email: anais@sewintothat.com
Website: sewintothat.com
Please note: this is a legal correspondence address only. Please do not send parcels to this address.
As the operator of sewintothat.com, Anaïs Neumann is the data controller within the meaning of the EU General Data Protection Regulation (GDPR).
If you have any questions or concerns about this Privacy Policy or how I handle your personal data, please contact me at anais@sewintothat.com.
1. What data I collect and why
1.1 When you make a purchase
To process your order and deliver your digital download, I collect:
- Name and email address
- Billing information (processed securely by Shopify Payments or PayPal — I do not store your full payment card details)
- Order history and download activity
Legal basis: Article 6(1)(b) GDPR — processing is necessary for the performance of a contract.
I am also required by German commercial and tax law (§257 HGB, §147 AO) to retain invoice and transaction data for 10 years. During this retention period, this data cannot be deleted on request, but its use will be restricted to compliance purposes only.
Legal basis for retention: Article 6(1)(c) GDPR — processing is necessary to comply with a legal obligation.
1.2 When you create a customer account
If you register an account on sewintothat.com, I collect:
- Name and email address
- Password (stored in encrypted form by Shopify)
- Order history and download access
This data is held for as long as your account remains active. You may request account deletion at any time by contacting me at anais@sewintothat.com. Note that invoice data subject to the 10-year retention period above cannot be deleted, but will be separated from your account profile.
Legal basis: Article 6(1)(b) GDPR — processing is necessary for the performance of a contract.
1.3 When you sign up for my newsletter
If you subscribe to the Sew Into That newsletter, I collect your email address and, if provided, your first name.
Your subscription is based on your freely given consent. You can unsubscribe at any time by clicking the unsubscribe link in any newsletter email, or by contacting me at anais@sewintothat.com. Withdrawal of consent does not affect the lawfulness of any processing carried out before withdrawal.
Newsletter subscriber data is retained until you unsubscribe or request deletion.
Legal basis: Article 6(1)(a) GDPR — consent.
1.4 When you visit the website
When you visit sewintothat.com, Shopify automatically collects certain technical data, including:
- IP address
- Browser type and version
- Device type and operating system
- Pages visited, time spent, and referring URLs
This data is used to ensure the site functions correctly and to understand how visitors use it. It is processed by Shopify on my behalf (see Section 3).
Legal basis: Article 6(1)(f) GDPR — legitimate interests in maintaining and improving the website.
1.5 When you contact me directly
If you send me an email or contact me through the site, I will process your name, email address, and the content of your message in order to respond to you.
This data is retained for as long as necessary to resolve your enquiry and for a reasonable period thereafter in case of follow-up.
Legal basis: Article 6(1)(f) GDPR — legitimate interests in responding to customer enquiries.
2. Cookies
This website uses cookies. A cookie is a small text file placed on your device when you visit a site.
I use a cookie consent banner to obtain your consent before any non-essential cookies are set. You can manage or withdraw your cookie preferences at any time through the banner.
Essential cookies (no consent required) are necessary for the site to function — for example, to maintain your shopping cart or keep you logged in.
Analytics and preference cookies are only set with your consent and help me understand how the site is used so I can improve it.
For full details of the cookies used on this site, please refer to the cookie settings in the consent banner.
3. Who I share your data with
I do not sell or trade your personal data. I share it only with the following third-party service providers who process data on my behalf, and only to the extent necessary to provide their services:
Shopify Inc.
Shopify powers this store, processes orders, hosts customer accounts, and delivers Shopify Email newsletters. Shopify is based in Canada and also operates servers in the United States. Data transfers are covered by Standard Contractual Clauses (SCCs) in accordance with Article 46 GDPR.
Privacy policy: shopify.com/legal/privacy
Shopify Payments (powered by Stripe)
Payment card transactions are processed securely by Shopify Payments, which uses Stripe's infrastructure. I do not have access to your full card details. Stripe may transfer data to the United States; transfers are covered by SCCs.
Privacy policy: stripe.com/privacy
PayPal
If you choose to pay via PayPal, your payment is processed directly by PayPal (Europe) S.à r.l. et Cie, S.C.A. PayPal operates as an independent data controller for payments made through its platform.
Privacy policy: paypal.com/webapps/mpp/ua/privacy-full
Legal authorities
I may disclose your personal data if required to do so by law, or in response to a valid request from a public authority (such as a court or government agency).
4. International data transfers
Some of the service providers listed above — in particular Shopify and Stripe — are based in or transfer data to countries outside the European Economic Area (EEA), including the United States.
Where such transfers occur, I ensure they are covered by appropriate safeguards, specifically Standard Contractual Clauses (SCCs) approved by the European Commission under Article 46(2)(c) GDPR.
5. Data security
I implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or misuse. These include encrypted data transmission (SSL/TLS) and access controls.
Please be aware that no method of transmission over the internet or electronic storage is completely secure. While I take your data security seriously, I cannot guarantee absolute security.
6. Your rights under GDPR
As a data subject under GDPR, you have the following rights:
- Right of access (Article 15): You can request a copy of the personal data I hold about you.
- Right to rectification (Article 16): You can request that I correct inaccurate or incomplete data.
- Right to erasure (Article 17): You can request that I delete your personal data, subject to any legal retention obligations (see Section 1.1).
- Right to restriction of processing (Article 18): You can request that I restrict how I use your data in certain circumstances.
- Right to data portability (Article 20): You can request your data in a structured, commonly used, machine-readable format.
- Right to object (Article 21): You can object to processing based on legitimate interests (Article 6(1)(f)).
- Right to withdraw consent (Article 7(3)): Where processing is based on your consent (e.g. newsletter), you can withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact me at anais@sewintothat.com. I will respond within 30 days.
7. Right to lodge a complaint
If you believe I have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with the competent supervisory authority.
As I am based in Berlin, the relevant authority is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI)
Friedrichstr. 219
10969 Berlin
Germany
Tel.: +49 30 13889-0
Email: mailbox@datenschutz-berlin.de
Website: datenschutz-berlin.de
You may also lodge a complaint with the supervisory authority of your own EU member state of residence.
8. Third-party links
This website may contain links to third-party websites. I am not responsible for the privacy practices or content of those sites. I encourage you to review the privacy policy of any third-party site you visit.
9. Children's privacy
This website is not directed at children under the age of 16. I do not knowingly collect personal data from children. If you believe a child has provided me with personal data, please contact me at anais@sewintothat.com and I will delete it promptly.
10. Changes to this policy
I may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated date at the top. I encourage you to review this page periodically.
Your continued use of sewintothat.com after any changes are posted constitutes your acceptance of the updated policy.
11. Contact
For any questions about this Privacy Policy or your personal data:
Anaïs Neumann / Sew Into That
anais@sewintothat.com
sewintothat.com
