Privacy Policy | DillySocks

In the DillySocks Privacy Policy, you will find details on how we handle your data. You can be sure that we comply with data protection regulations, meaning we are GDPR-compliant. See for yourself.

Status: April 2026


1. Controller

The controller for data processing on this website is:

DillySocksAG
Eibenstrasse 9
8045 Zürich
Switzerland

Email: contact@dillysocks.info
Tel: 044 297 32 64

Website: www.dillysocks.info

Commercial Register: CHE-457.921.833


2. General Information and Scope

This privacy policy informs you about which personal data we collect, for what purpose we process it, and to whom we disclose it. It applies to the use of our website dillysocks.info, our online shop, and
our other digital offerings.

Personal data is any information relating to an identified or identifiable natural person. We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU General Data Protection Regulation (GDPR).

The use of our website is generally possible without registration. In this process, certain access data is automatically collected (e.g., pages accessed, date and time, IP address), which cannot be directly assigned to a specific person
. Personal data such as name, address, or email address is only collected if you voluntarily provide it to us.


3. Legal Basis

We process personal data on the following legal bases:

Swiss Law (FADP): Processing is
generally permissible if it does not unlawfully infringe upon the personality of the data subject (Art. 30 et seq. FADP). Where necessary, we rely on your consent, the fulfillment of a contract, or overriding legitimate interests.

EU Law (GDPR), Art. 6 Para. 1: Consent (lit. a), contract performance (lit. b), legal obligation (lit. c), protection of
vital interests (lit. d), or legitimate interests (lit. f), unless your fundamental rights override them.

We only process personal data for as long as it is necessary for the respective purpose
or as long as we are legally obliged to do so.


4. Data Collected


4.1 Automatically Collected Data (Server Log Files)


When you visit our website, the following data is automatically collected: IP address (anonymized), browser type and version, operating system, referrer URL, pages accessed, date and time of access. This data serves to ensure smooth operation and to improve our
offering.


4.2 Data for Orders

When placing an order in our online shop, we collect: first and last name, delivery and billing address, email address, telephone number (optional), payment information (processed directly by the payment service provider),
order history. The legal basis is the fulfillment of the contract (Art. 6 Para. 1 lit. b GDPR) or the legitimate interest in business processing.


4.3 Customer Account

You can optionally create a customer account. The necessary data (name, email, address) is stored to provide you with an order overview and faster checkout. Customer accounts are not public and are not indexed by search engines. If the account is canceled, your
data will be deleted, unless there is a legal retention obligation.


4.4 Newsletter

If you subscribe to our newsletter, we collect your email address and optionally your name. The subscription is carried out via a double opt-in procedure. You can unsubscribe from the newsletter at any time via the unsubscribe link in each email or directly from us.

For the sending and analysis of our newsletters, we use Klaviyo, Inc. (USA). Klaviyo uses cookies and can link your behavior in our webshop with your data if you have subscribed to the newsletter, created a customer account,
or completed an order. Klaviyo's privacy policy can be found at: https://www.klaviyo.com/privacy

The data transfer to the USA is secured by standard contractual clauses (SCCs) and Klaviyo's participation in the EU-US Data Privacy Framework.


4.5 Contact Form

If you contact us via the contact form, your details (name, email address, message) will be stored for the purpose of processing your request. We will not pass on this data without your consent.


5. Hosting and E-Commerce Platform

Our website and online shop are operated via Shopify International Limited (Ireland) or Shopify Inc. (Canada). Shopify processes the data generated during shop operations (order data, customer data, shop analyses, IP addresses) on our behalf. Data may be stored in data centers in the USA and Canada.

Data transfer is secured by standard contractual clauses (SCCs) and appropriate technical and organizational measures. Further information can be found in Shopify's privacy policy: https://www.shopify.com/legal/privacy


6. Cookies and Consent Management

Our website uses cookies – small text files that are stored on your device. Technically necessary cookies are set without consent. For marketing and analysis cookies, we obtain your consent via
our cookie consent solution (Pandectes).

You can adjust your cookie settings at any time via the cookie banner on our website.


7. Analysis and Marketing Services


7.1 Google Analytics 4 (GA4)

We use Google Analytics 4, a web analytics service from Google Ireland Limited (Ireland). GA4 uses cookies and collects information about your use of our website (pages visited, time spent, device type, approximate location). In GA4, IP addresses are not fully stored by default.

The data collected helps us to improve our offer. The legal basis is your consent (Art. 6 Para. 1 lit. a GDPR) via the cookie banner. You can prevent data collection by adjusting your cookie settings or by installing the Google Analytics Opt-out Browser Add-on: https://tools.google.com/dlpage/gaoptout


7.2 Google Ads and Conversion Tracking

We use Google Ads for online advertising. If you reach our website via a Google ad, a conversion cookie is set (validity: 30 days). This cookie is used to measure campaign success and does not contain
personal information. You can prevent participation via your
cookie settings or at https://adssettings.google.com.


7.3 Google Remarketing

We use Google's remarketing function to show you interest-based ads within the
Google advertising network. You can deactivate this at http://www.google.com/settings/ads.


7.4 Google Tag Manager

We use Google Tag Manager to manage website tags. The Tag Manager itself does not collect any personal data. Usage policies:
https://www.google.com/intl/de/tagmanager/use-policy.html


7.5 Google Web Fonts

To ensure a consistent display of fonts, we use Google Web Fonts. When you call up a page, your browser loads the necessary fonts. In doing so, your IP address is transmitted to Google. More at: https://developers.google.com/fonts/faq


7.6 Meta (Facebook) Pixel

We use the Meta Pixel from Meta Platforms, Inc. (1 Hacker Way, Menlo Park, CA 94025, USA). The Pixel is only activated if you have given your consent via the cookie banner. It is used to measure the effectiveness of our advertisements on Facebook and Instagram. More at:
https://www.facebook.com/about/privacy


7.7 Klar (Tracking & Marketing Attribution)

On our website, we use the services of Klar (Klar Insights GmbH, Marktstrasse 18, 80802 Munich, Germany). Klar collects, processes, and stores data on this website and its sub-pages for reach measurement, marketing attribution, and statistical analysis on our behalf.

For this purpose, Klar uses a tracking pixel that is integrated via Shopify Customer Events. The following data is collected in particular: page views, click behavior, referrer URLs, UTM parameters, device information (browser type, operating system, screen resolution), IP address (shortened/pseudonymized) as well as – in the case of an order – pseudonymized order data for attributing the conversion to the respective marketing source (multi-touch attribution).

Klar does not create individual user profiles from this that allow direct identification. Klar is ISO 27001 certified. Data processing is fully GDPR-compliant; all data is hosted in data centers in the EU (Germany). No transfer to third countries takes place within the scope of Klar tracking. We have concluded a data processing agreement (DPA) with Klar in accordance with Art. 28 GDPR.

The legal basis for the use of Klar is your consent (Art. 6 Para. 1 lit. a GDPR), which you give via our cookie banner (Pandectes). The Shopify Customer Events are only triggered if you have agreed to tracking. You can revoke your consent at any time via the cookie settings on our website.

Further information on data protection and data use by Klar can be found at: https://www.getklar.com/data-protection


8. Social Media


8.1 Instagram


Functions from Instagram (Meta Platforms, Inc.) are integrated into our website. If you are logged into your Instagram account and interact with the integrated functions, Instagram can assign this visit to your account. Further information:
https://help.instagram.com/519522125107875


8.2 Pinterest


We use social plugins from Pinterest Inc. (505 Brannan Street, San Francisco, CA 94107, USA). When you call up a page with a Pinterest plugin, your browser establishes a connection to Pinterest servers, whereby log data (IP address, visited page, browser type) can be transmitted. More: https://policy.pinterest.com/privacy-policy


8.3 LinkedIn


Our website uses functions from LinkedIn (LinkedIn Corporation, 1000 W. Maude Ave., Sunnyvale, CA 94085, USA). When you call up pages with LinkedIn functions, a connection to LinkedIn servers is established. More: https://www.linkedin.com/legal/privacy-policy


9. Payment Service Providers


We use external payment service providers to process payments. We
ourselves do not receive credit card or bank details, but only a
confirmation or rejection of the payment. The payment data is processed exclusively by the respective service provider.

Our current payment service providers are [CHECK – please confirm current list]:

TWINT: https://www.twint.ch/datenschutzerklaerung/

PostFinance: https://www.postfinance.ch/de/detail/rechtliches-barrierefreiheit.html

Stripe: https://stripe.com/ch/privacy

Klarna: https://www.klarna.com/de/datenschutz/

PayPal: https://www.paypal.com/de/webapps/mpp/ua/privacy-full

Apple Pay: https://support.apple.com/de-ch/ht203027

Visa / Mastercard / American Express: (processed via Stripe)

CembraPay: GTC and Privacy Policy of CembraPay AG

The legal basis is the fulfillment of the contract (Art. 6 Para. 1 lit. b GDPR) and our legitimate interest in secure payment options (Art. 6 Para. 1 lit. f GDPR).


10. Shipping Service Providers

For the delivery of your order, we transmit the necessary data
(name, address, if applicable, email for tracking) to our shipping partners. Current partners are [CHECK]:

• Swiss Post (Switzerland)

• DHL / Deutsche Post (EU)

• DPD (EU)


11. YouTube

Videos from YouTube (Google Ireland Limited) may be embedded on our website. When a video is played, a connection to YouTube servers is established. Where possible, we use the extended data protection mode, where YouTube only sets cookies if you play a video. More: https://www.youtube.com/howyoutubeworks/our-commitments/protecting-user-data/


12. Data Transfer Abroad


Within the scope of our business activities and the use of the aforementioned services,
personal data may be transferred to the following countries:

• USA (Google, Meta, Klaviyo, Stripe,
Pinterest, LinkedIn)

• Canada (Shopify)

• Ireland (Shopify International, Google Ireland)

Data transfer to countries without an adequate level of data protection is secured by:

• EU Standard Contractual Clauses (SCCs)

• EU-US Data Privacy Framework (DPF) – if the
recipient is certified

• Supplementary technical and organizational measures

Switzerland also has its own list of countries that guarantee an adequate level of data protection (Art. 16 FADP in conjunction with Annex 1 FADP Ordinance). The Federal Council has recognized EU/EEA member states as countries with adequate protection.


13. Retention Period


We store personal data only as long as it is necessary for the respective purpose or we are legally obliged to do so:

• Contract and business data: 10 years (commercial and
tax law retention obligation according to Art. 958f CO)

• Accounting records: 10 years

• Newsletter data: until unsubscribed, then
deleted immediately

• Web analysis data: max. 26 months (depending on Google
Analytics settings)

• Contact inquiries: 2 years after completion of the inquiry,
unless a contractual relationship arises

• Server log files: max. 90 days


14. Data Security

We take appropriate technical and organizational measures to protect your personal data from unauthorized access, loss, misuse, or destruction. These include, among other things, the encryption of data transmission (SSL/TLS), access protection to our systems, and regular reviews of our security measures.

However, we point out that data transmission on the Internet (e.g., via
email) can have security vulnerabilities. Complete protection against third-party access is not possible.


15. Rights of Data Subjects

You have the following rights at any time regarding your personal data:

• Right of access (Art. 25 FADP / Art. 15 GDPR): You can request information about the personal data we process.

• Right to rectification (Art. 32 Para. 1 FADP / Art. 16 GDPR): You can request the correction of inaccurate data.


• Right to erasure (Art. 32 Para. 2 lit. c FADP / Art. 17 GDPR): You can request the deletion of your data, provided that there is no legal
retention obligation to the contrary.


• Right to data portability (Art. 28
FADP / Art. 20 GDPR): You can request the provision of your data in a common electronic format.


• Right to object (Art. 21 GDPR): You can object to the processing of your data, especially for marketing purposes.


• Right to withdraw consent: You can withdraw given consent at any time with effect for the future.


Please direct your inquiries to: contact@dillysocks.info


16. Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority:

Switzerland: Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, https://www.edoeb.admin.ch

EU: You can contact the data protection supervisory authority of your country of residence.

17. Changes to this Privacy Policy

We may adapt this privacy policy at any time, e.g., due to
changes in law, new regulatory requirements, or the introduction of new services. The current version published on our website always applies.

Last updated: April 2026