Privacy Policy

Last updated: 1 August 2026

This Privacy Policy explains what personal data we collect when you visit or order from https://frostorio.com, why we collect it, how we use it, and the rights you have under the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

1. Data controller

The data controller responsible for the processing of your personal data on this website is:

ZHENG ZHOU DAI JIU SHANG MAO YOU XIAN GONG SI
(郑州代旧商贸有限公司), trading as Frostorio
Represented by: Aojun Liu (奥军 刘)

Registered office: 河南省郑州市郑东新区博学路257号局外太格茂9层044号, 450000 China
EU service address: Rennstieg 81, 28205 Bremen, Germany
Email: contact@frostorio.com · Phone: +49 89 527488

For all privacy-related requests, please use the email address above with the subject line "GDPR request".

2. What data we process and why

2.1 When you browse the Store

Category Details Legal basis Retention
Server log data IP address, browser type, operating system, referrer URL, timestamp, requested page. Art. 6 (1)(f) GDPR — legitimate interest in secure and reliable operation of the Store. Up to 30 days, then aggregated / anonymised.
Essential cookies Cart, session, security tokens set by Shopify. Art. 6 (1)(f) GDPR / § 25 (2) TTDSG — strictly necessary. Session or up to 12 months.
Optional cookies (analytics / marketing) Only set with your explicit consent via the cookie banner. Art. 6 (1)(a) GDPR + § 25 (1) TTDSG. Per provider (typically 12–24 months); you can withdraw consent at any time.

2.2 When you place an order

Category Details Legal basis Retention
Contact & billing data Name, delivery and billing address, email, phone, company name (if provided), VAT ID (if provided). Art. 6 (1)(b) GDPR — performance of the contract of sale. Duration of contract + up to 10 years to meet German commercial and tax retention obligations (§ 147 AO, § 257 HGB).
Order and product data Items ordered, quantities, order number, price, discount codes, order notes. Art. 6 (1)(b) + Art. 6 (1)(c) GDPR — contract + legal retention obligations. Up to 10 years (§ 147 AO).
Payment data Payment method chosen, transaction reference, payment status. Full card numbers are never seen or stored by us — they are handled directly by our PCI-DSS compliant payment processor. Art. 6 (1)(b) GDPR. As required by tax law and payment provider agreements.
Communication data Emails, phone notes, chat transcripts. Art. 6 (1)(b) or (f) GDPR. Up to 3 years after last contact, unless a longer retention is legally required.

3. Recipients / third parties who process data on our behalf

We use the following categories of processor. Each is bound by a written data processing agreement under Art. 28 GDPR:

  • E-commerce platform — Shopify International Limited (Ireland), which hosts this Store.
  • Payment providers — those you select at checkout (e.g. card, wallets, Klarna). They receive only the data needed to process your payment.
  • Shipping carriers — DHL, DPD, GLS, UPS, FedEx, SF Express, and comparable regional carriers, receiving name, address and phone as needed for delivery.
  • Email & communication — the transactional email provider used to send order confirmations and shipping notifications.
  • Tax & accounting — our tax advisor and accounting provider, to the extent required by German tax law.
  • Group operations — internal fulfilment staff at our Chinese headquarters and German service address, on a need-to-know basis.

4. International data transfers

Where we transfer personal data outside the European Economic Area (EEA) — in particular between our EU service address in Germany and our headquarters in the People's Republic of China — such transfers are made on the basis of the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914 of 4 June 2021), with any additional safeguards required by the case law of the Court of Justice of the European Union (Schrems II). A copy of the SCCs used is available on request.

5. Cookies and tracking

We use only strictly necessary cookies to make the Store work. Any analytics or marketing cookies (if enabled in future) will be set only with your prior consent given via the cookie consent banner, in accordance with § 25 (1) of the German Telecommunications Telemedia Data Protection Act (TTDSG) and Art. 6 (1)(a) GDPR. You can change or withdraw your consent at any time via the cookie settings link in the footer.

6. Your rights under the GDPR

You have the following rights in respect of your personal data:

  • Right of access (Art. 15) — to obtain confirmation of whether we process personal data about you and, if so, a copy.
  • Right to rectification (Art. 16) — to have inaccurate data corrected.
  • Right to erasure (Art. 17) — to have your data deleted where one of the grounds in Art. 17 applies (subject to legal retention obligations).
  • Right to restriction of processing (Art. 18).
  • Right to data portability (Art. 20) — to receive the data you provided in a structured, commonly used, machine-readable format.
  • Right to object (Art. 21) — in particular to processing based on legitimate interests and to direct-marketing processing.
  • Right to withdraw consent (Art. 7 (3)) at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
  • Right to lodge a complaint (Art. 77) with a supervisory authority — see section 7.

To exercise any of these rights, email contact@frostorio.com with the subject "GDPR request". We will respond within one month of receipt (Art. 12 (3) GDPR).

7. Supervisory authority

The competent data protection supervisory authority for our EU service address is:

Landesbeauftragte für Datenschutz und Informationsfreiheit
Freie Hansestadt Bremen
Arndtstraße 1, 27570 Bremerhaven, Germany
Website: datenschutz.bremen.de

8. Security

The Store runs on Shopify with TLS encryption in transit. Access to personal data on our internal systems is restricted to authorised personnel on a need-to-know basis. Payment information is handled exclusively by PCI-DSS compliant payment providers; we never store full card numbers.

9. Children

The Store is intended for adult buyers (natural persons of legal age in their jurisdiction) and for business buyers. We do not knowingly process personal data of children under 16 (Art. 8 GDPR). If you believe a child has provided personal data to us, please contact us and we will delete it without undue delay.

10. Changes to this Policy

We may update this Privacy Policy from time to time (for example, when we add a new processor or a new payment method). The date at the top of this page indicates when the current version came into effect. For material changes we will inform registered customers by email or by a prominent notice on the Store.