Skip to content

Free delivery from €750.00 · Professional installation across NRW

Last updated: 2026-09-03

Privacy policy

The German version of this document is the authoritative one; translations are provided for understanding only.

Controller

The controller for the processing of personal data on this website is Tieger GmbH, Steeler Straße 285, 45138 Essen, represented by Sadik Kur. You can reach us on +49 173 1667666 and at info@tiegerdeko.com.

Data protection officer

OPEN — to be settled before publication: whether Tieger must appoint a data protection officer depends on how many people are permanently occupied with automated processing of personal data (§ 38 BDSG: twenty or more). If one is appointed, their contact details belong here.

Visiting the website and server logs

When you open our pages, your browser transmits technically necessary data to our hosting provider: IP address, date and time, the address requested, browser and operating-system identification and the referring page. This data is needed to deliver the page and additionally serves to detect and defend against faults and attacks. The legal basis is Art. 6(1)(f) GDPR.

Our host’s network derives a rough estimate of your country from the IP address. We use that estimate only to suggest the matching language version. It never decides prices or taxes — only the delivery address you enter does that.

The fonts used on this website are served from our own server. No connection to Google Fonts or any other third party is made for them.

Cookies and browser storage

We use only cookies and browser storage that are necessary for functions you asked for yourself — signing in, the cart, completing an order and the delivery country. There are no analytics, tracking or advertising services on this website, no Google Analytics, no pixels and no profiling. That is also why no consent banner appears: § 25 (2) TDDDG does not require consent for strictly necessary storage.

When our forms run their security check (Cloudflare Turnstile), Cloudflare may additionally place a technically necessary identifier in the browser in order to recognise a check you have already passed.

Customer account and sign-in

For a customer account we process your email address, your password, your name and optionally your telephone number, plus the addresses you save in your address book. Sign-in runs on Firebase Authentication; your password is stored there only as a cryptographic hash and is never readable by us. The legal basis is Art. 6(1)(b) GDPR.

If you sign in with your Google account, Google passes us your email address, your display name and whether that address is verified. No password is created. You can register with an email address and password instead at any time.

When a password is reset we process the address you entered in order to send you a one-time link. Our answer is always the same, whether or not an account exists for that address — so the form cannot be used to find out who is a customer here.

Orders — with and without an account

For an order we process your name, email address, optionally your telephone number, delivery and billing address, the items ordered with their prices, the shipping method, the VAT breakdown and the order and payment history. This data is required to conclude the contract; without it we cannot deliver. We deliver to: DE, AT, NL, BE, FR. The legal basis is Art. 6(1)(b) GDPR, and Art. 6(1)(c) GDPR for keeping the records.

You can order without an account. We then store the same order data but no user account. To look such an order up later you need the order number **and** the email address used for it; either one alone is never enough, and every failed lookup is answered identically.

If you later create an account with the same, verified email address, we attach your earlier guest orders to it so that they appear in your order history.

Payment

We process payments through Stripe. You enter your card or account details in a field provided by Stripe and they are transmitted directly to Stripe — they never reach our server and we do not store them. We transmit to Stripe the amount payable, the currency, our order number, whether the order is private or business, the VAT breakdown and, for exempt supplies, your VAT ID. We receive back the outcome of the payment and the name of the method actually used.

If you choose a further provider in the payment form — PayPal, Klarna or SEPA direct debit, for example — that provider’s privacy notice applies in addition to whatever you enter there.

The emails we send you

Order confirmations, payment confirmations, status updates, invoices, password resets and withdrawal acknowledgements are sent through the IONOS mail server. For each of these messages we log the recipient address, the subject, the type and whether sending succeeded — we need that to prevent duplicate sends and to be able to show that a legally required confirmation was actually dispatched. These messages are part of performing the contract; they contain no advertising and cannot be unsubscribed from.

Newsletter

The newsletter runs on double opt-in: after you sign up we send you an email with a confirmation link, and you are only on the list once you click it. We store your email address, your language, the time you signed up and the time you confirmed — the latter as evidence of your consent. The legal basis is Art. 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future, using the unsubscribe link in every issue or informally by contacting us.

Contact, project and bulk-order enquiries

Through our forms we process what you enter: name, email address, telephone number where given, town, company, project type, measurements, budget range, timeframe and your message. We use it to answer your enquiry and prepare an offer. The legal basis is Art. 6(1)(b) GDPR for pre-contractual enquiries and otherwise Art. 6(1)(f) GDPR. File upload is currently not available; if you select files, only how many there were is transmitted, so that we know to ask you for them.

Business customers and VAT identification numbers

For a dealer application we process the company name, contact person, email address, telephone number, company address, type of business, trade register and VAT identification numbers, website, expected volume and your message. We use it to assess the application and set your terms. The legal basis is Art. 6(1)(b) GDPR.

If you provide a VAT ID we transmit it together with our own to the European Commission’s VIES system, which forwards the query to the issuing member state. We store the result, the time of the check and the reference the authority issues — that is the evidence VAT law requires for an exempt intra-Community supply.

Withdrawing from an order

If you use our withdrawal function we store your statement verbatim, the order concerned, the email address and name you gave, the exact time it arrived, the scope of the withdrawal and any note. We have to keep this in order to acknowledge receipt and, in a dispute, to be able to show when the withdrawal was declared and what it said. We additionally store a hash of your IP address and your browser identification for abuse prevention. The legal basis is Art. 6(1)(c) and (b) GDPR.

Protection against abuse

So that our forms, our ordering process and our outgoing email cannot be abused automatically, we count requests per sender. For that we store **no IP address in the clear**, but a hash derived from it together with a counter and two timestamps. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the availability of the shop and protecting third parties from having our confirmation emails used as a weapon against them.

In addition, Cloudflare Turnstile checks whether a submission came from a person. For that we explicitly transmit your IP address, the one-time token generated in the browser, our domain and the name of the form to Cloudflare. Cloudflare evaluates technical characteristics of your browser for this. No advertising cookies are set and no profiles about you are built.

Transfers to third countries

Some of the providers named above are established in the United States or can access data from there: Google, Stripe, Netlify and Cloudflare. A transfer only takes place where it is necessary for the purpose concerned. The data processing agreements and transfer safeguards this requires — the EU Commission’s standard contractual clauses and, where applicable, certification under the EU-US Data Privacy Framework — are currently being concluded and verified; we deliberately do not state here that a certification exists which has not been individually checked.

Retention

We erase personal data as soon as its purpose ceases and no statutory retention duty stands in the way. Which period applies to which category is set out in the table "Retention in detail" below.

There is no single period, because the law does not provide one. Three commercial and tax periods matter here: invoices are kept for eight years (§ 14b(1) UStG, § 147(1) no. 4a AO), accounting vouchers — the orders that turned into a payment — likewise for eight years (§ 147(1) no. 4 AO, § 257(1) no. 4 HGB), and commercial letters received and sent for six years (§ 147(1) nos. 2 and 3 AO, § 257(1) nos. 2 and 3 HGB). All three begin only at the end of the calendar year in which the document arose (§ 147(4) AO, § 257(5) HGB, § 14b(1) sentence 1 UStG).

The ten-year period often quoted applies to commercial books, inventories, annual accounts and management reports. No such documents arise in this shop, and none are stored here.

An order that was never paid and never invoiced is not an accounting voucher. It carries no tax retention duty and is erased on our own schedule rather than a statutory one.

The table therefore distinguishes three kinds of period, and the distinction is not a formality. "Statutory" means the law fixes the duration and we can neither shorten nor extend it. "Business policy" means the law prescribes nothing, we have committed to a duration and we keep to it — those periods were decided on 4 September 2026. "Technical" means the record expires automatically, without anyone having to act.

For a few categories the period is still open. Where that is so the table says "not yet fixed" — we deliberately do not state a figure nobody has decided. Until one is set, we erase that data as soon as we no longer need it.

A note about backups: our database keeps an automatic recovery window of seven days. When we erase data it disappears from the live records immediately; it leaves the backups as those expire, so within seven days at the latest. Selectively erasing something inside a backup that has already been taken is not technically possible, and would defeat the purpose of a backup — restoring a complete earlier state.

OPEN — to be settled before publication: no binding retention period has been fixed for Notices of withdrawal, Record of erasure requests. The table says "not yet fixed" for those rows.

Your rights

You have the right to information about the data we hold on you (Art. 15 GDPR), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18), to data portability (Art. 20) and to object to processing based on a legitimate interest (Art. 21). Where processing rests on your consent, you may withdraw it at any time with effect for the future.

Simply contact info@tiegerdeko.com. Some of these rights can also be exercised directly in your account: you can change and delete your profile and addresses there yourself.

You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.

Whether you have to provide data

Without a name, a delivery address and an email address we cannot conclude a contract of sale or deliver — that data is required. Telephone number, customer account, VAT ID and newsletter are voluntary; not providing them has no consequences beyond those inherent in the function itself. There is no automated decision-making, including profiling, within the meaning of Art. 22 GDPR.

Services we use

ServicePurposeDataLegal basisPlace of processing
Google Ireland Ltd. / Google LLC — Firebase Authentication, Cloud Firestore, Cloud StorageCustomer accounts, sign-in, storage of orders, enquiries, addresses and invoice documentsEmail address, password (stored only as a hash at Google), name, telephone number, addresses, order and enquiry data, invoice documentsArt. 6(1)(b) GDPR (contract), Art. 6(1)(c) GDPR (retention), Art. 6(1)(f) GDPR (operating the shop)EU region (europe-west3, Frankfurt); access by Google LLC (USA) possible
Stripe Payments Europe, Ltd. (Irland) / Stripe, Inc. (USA)Payment processing, fraud prevention, refundsPayment data (you enter card or account details directly with Stripe — they never reach our server), amount, currency, order number, customer type, VAT breakdown, your VAT ID where applicable, technical data about your deviceArt. 6(1)(b) GDPR (contract), Art. 6(1)(f) GDPR (fraud prevention)Ireland; transfer to Stripe, Inc. in the USA
Zahlungsdienste innerhalb der Stripe-Zahlungsmaske (u. a. PayPal, Klarna, SEPA-Lastschrift, Link)Carrying out the payment method you choseWhatever you enter with the provider, plus amount, currency and the order reference. We only receive the outcome of the payment and the name of the method used.Art. 6(1)(b) GDPREU or a third country depending on the provider; that provider’s own privacy notice applies in addition
Netlify, Inc. (USA)Hosting the website and its server-side functions, delivery through a content delivery network, technical logsIP address, date and time of access, the address requested, browser and device identification, country (a rough estimate from the IP address)Art. 6(1)(f) GDPR (secure and reliable operation)USA, delivered through European edge nodes
Cloudflare, Inc. (USA) — TurnstileProtecting the forms against automated submissions (spam and abuse prevention)Your IP address (we transmit it explicitly with the verification request), the one-time token the check produces, the domain and the name of the form, and the technical characteristics Cloudflare collects in the browser. No advertising or analytics cookies are set and no personal profiles are built.Art. 6(1)(f) GDPR (defending our forms and our outgoing email against abuse)USA / worldwide network
1&1 IONOS SE (Deutschland)Sending our transactional email (order confirmation, payment confirmation, status updates, password reset, withdrawal acknowledgement)Recipient address, subject and content of the messageArt. 6(1)(b) GDPR (contract), Art. 6(1)(c) GDPR (statutory confirmation duties)Germany
Europäische Kommission — MIAS/VIESChecking a VAT identification number you provide, for exempt intra-Community suppliesThe VAT ID you entered and our own VAT IDArt. 6(1)(c) GDPR (VAT evidence duties), Art. 6(1)(b) GDPREuropean Union

Cookies and browser storage in detail

NamePurposeLifetime
__sessionKeeps you signed in after logging in. HttpOnly, unreadable by scripts.12 hours
order_confirmationLets the browser that has just ordered see its own confirmation and start the payment, with no account. It contains only a signed order identifier, no personal data.1 hour
td_countryRemembers the delivery country you chose, so prices and shipping are shown correctly.1 year
tieger-cart-v1 (localStorage)Stores your shopping cart in your browser only. It is not transmitted to us unless you go to checkout.until you clear it

Retention in detail

CategoryRetentionBasis or trigger
Orders that were paid8 years (statutory)§ 147 Abs. 1 Nr. 4 i. V. m. Abs. 3 AO; § 257 Abs. 1 Nr. 4 i. V. m. Abs. 4 HGB (Buchungsbelege)
Abandoned orders1 year (business policy)Stornierung bzw. Ablauf der Reservierung
Invoices8 years (statutory)§ 14b Abs. 1 UStG; § 147 Abs. 1 Nr. 4a i. V. m. Abs. 3 AO; § 257 HGB
Invoice PDFs8 years (statutory)§ 14b Abs. 1 UStG; § 147 AO; § 257 HGB
Customer account3 years (business policy)Letzte Anmeldung
Enquiries from the forms6 months (business policy)Letzter Kontakt zur Anfrage
Enquiry history3 years (business policy)Löschung oder Anonymisierung der zugehörigen Anfrage
Rejected dealer applications1 year (business policy)Entscheidung über den Antrag
Notices of withdrawalnot yet fixed (business policy)Ende des Kalenderjahres, in dem der Widerruf erklärt wurde
Unconfirmed newsletter sign-ups14 days (technical)Ablauf des Bestätigungslinks nach 14 Tagen
Newsletter subscriptionfor as long as the relationship lasts (business policy)Widerruf der Einwilligung (Abmeldung)
Consent evidence after unsubscribing3 years (business policy)Abmeldung vom Newsletter
Dispatch log of our emails3 years (business policy)Zeitpunkt des Versands
Abuse-detection counters60 minutes at most (technical)Ende des jeweiligen Zeitfensters, längstens 60 Minuten
Administrative activity log3 years (business policy)Zeitpunkt des Vorgangs
Record of erasure requestsnot yet fixed (business policy)Abschluss der Löschung

Questions about this document?

Tieger GmbH
Steeler Straße 285, 45138 Essen
+49 173 1667666

info@tiegerdeko.com
Developer modeLock