General
Controller Responsible for Data Processing
shopware AG takes the protection of your personal data and the legal obligations to ensure data protection very seriously. The law requires full transparency regarding the processing of personal data. You as a data subject can only understand the details of the processing if you are duly informed about the purpose, nature and scope of the processing.
Controller:
shopware AG
Ebbinghoff 10
D-48624 Schöppingen, Germany
Phone: +49 (0) 2555 92885-0
Email: info@shopware.com
Data Protection Officer:
Sascha Kremer
Specialist Lawyer for IT Law (Fachanwalt für IT-Recht)
c/o KREMER RECHTSANWÄLTE
Brückenstraße 21
D-50667 Cologne, Germany
Data Categories
The data categories we process include but are not limited to:
- Master data (e.g. names, addresses, dates of birth)
- Contact data (e.g. email addresses, telephone numbers)
- Content data (e.g. entered texts, photos, videos, document contents)
- Contract data (e.g. contract purpose, contract terms, customer categories)
- Payment data (e.g. bank details, payment history)
- Usage data (e.g. website history, use of certain contents, access times)
- Connection data (e.g. device information, IP addresses, URL referrer)
- Position data (e.g. GPS data, IP geo-localisation)
Legal Basis for Processing
We only process personal data to the extent permitted by law. We only disclose or transfer personal data to third parties in the cases described in this privacy policy. The personal data are protected by appropriate technical and organisational measures (e.g. pseudonymisation, encryption).
Storage Duration
Personal data are deleted as soon as the purpose of processing or prescribed storage period has expired, unless storage needs to continue for the purpose of entering into or performing a contract. Personal data processed for application purposes are stored for six months from completion of the application procedure.
Your Rights as Data Subject
As a data subject, you have the following rights under the GDPR:
- Right of access (Art. 15 GDPR) - You can request information about your personal data we process
- Right to rectification (Art. 16 GDPR) - You can request correction of inaccurate personal data
- Right to erasure (Art. 17 GDPR) - You can request deletion of your personal data
- Right to restriction of processing (Art. 18 GDPR) - You can request restriction of processing
- Right to data portability (Art. 20 GDPR) - You can request transfer of your data
- Right to object - You can object to processing based on legitimate interests or for marketing purposes
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
Supervisory Authority:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2-4
D-40213 Düsseldorf, Germany
Right to Object:
You have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on point (f) of Art. 6 (1) GDPR. Where personal data are processed for direct marketing purposes, you have the right to object at any time to processing of personal data concerning you for such marketing.
Withdrawal of Consent:
You have the right to withdraw your consent at any time with effect for the future. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
Specific Data Processing Activities
Newsletter Subscription
Purpose: Subscription to our newsletter containing news and offers; maintaining proof of consent; ensuring IT system security; personalised newsletter design.
Legal Basis: Art. 6 (1) point (a), Art. 49 (1) point (a) GDPR
Data Categories: Master data, contact data, and connection data
Third-Party Recipients: HubSpot Inc. (USA), rami.io GmbH (Germany)
Website Usage
Purpose: Provision of our website; ensuring functionality and security; statistical analysis; improvement of user experience.
Legal Basis: Art. 6 (1) point (f) GDPR (legitimate interests)
Data Categories: Usage data, connection data, device information
Storage Duration: Log files are typically stored for 30 days, cookies as specified in our consent tool
Webinars and Events
Purpose: Registration for and conducting webinars; maintaining proof of registration; ensuring IT system security.
Legal Basis: Art. 6 (1) point (b) GDPR (contract performance)
Data Categories: Master data, contact data, connection data
Third-Party Recipients: HubSpot Inc., Zoom Video Communications, Thinkific (depending on platform)
Customer Support and Contact
Purpose: Providing customer support; responding to inquiries; maintaining customer relationships.
Legal Basis: Art. 6 (1) point (b) or (f) GDPR
Data Categories: Contact data, content data, contract data
Storage Duration: Until resolution of inquiry plus applicable retention periods
Membership Application ("Join the Alliance")
Purpose: Receiving and processing applications to join the Agentic Commerce Alliance as a vendor or merchant, and contacting applicants about their application and membership.
Legal Basis: Art. 6 (1) point (b) GDPR (steps taken prior to entering into a membership relationship); for the internal notification e-mail additionally Art. 6 (1) point (f) GDPR (legitimate interest in evaluating and responding to applications).
Data Categories: Master data (first and last name), contact data (business e-mail address) and company information (company name, website, size and description).
Recipients: Stored in our database and sent as an internal notification e-mail to the Alliance team (see "Hosting", "Database" and "E-mail Delivery" below). No personal data from your application is transmitted to our analytics provider.
Storage Duration: For the duration of processing your application and any resulting membership; applications that do not lead to membership are deleted within six months (see "Storage Duration" above).
Agentic Commerce Maturity Index (ACMI) Registration
Purpose: Registering your interest in the Agentic Commerce Maturity Index so that we can notify you when it becomes available.
Legal Basis: Art. 6 (1) point (a) GDPR (your consent, given by submitting your e-mail address).
Data Categories: Contact data (e-mail address).
Recipients: Stored in our database (see "Database" below). Not transmitted to our analytics provider.
Storage Duration: Until the Index launches and you have been notified, or until you ask us to delete your registration — whichever is earlier.
Third-Party Services and International Transfers
We use various third-party services to provide our website and services. Some of these may involve transfers to third countries:
HubSpot (CRM and Marketing)
Provider: HubSpot Inc., 25 First Street, 2nd Floor, Cambridge, MA 02141, USA
Purpose: Customer relationship management, marketing automation, analytics
Safeguards: Standard Contractual Clauses (Art. 46 (2) point (c) GDPR)
Hosting (Vercel)
Provider: Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA
Purpose: Hosting the website and running its serverless functions, including form submissions and the analytics endpoint.
Data Categories: Connection data (e.g. IP address, pages accessed) and, in transit, any data you submit through our forms.
Safeguards: EU-US Data Privacy Framework and Standard Contractual Clauses (Art. 46 (2) point (c) GDPR).
Database (Neon)
Provider: Neon Inc. (USA); the database is provisioned via Vercel.
Purpose: Securely storing membership applications and ACMI registrations.
Data Categories: Master data, contact data and company information.
Safeguards: Standard Contractual Clauses (Art. 46 (2) point (c) GDPR); hosted in an EU region where available.
E-mail Delivery
Provider: Our transactional e-mail (SMTP) provider (to be specified by the operator).
Purpose: Sending the internal notification e-mail that contains a submitted membership application.
Data Categories: The master data, contact data and company information contained in the application.
Safeguards: Data processing agreement pursuant to Art. 28 GDPR; Standard Contractual Clauses where the provider is located outside the EU/EEA.
Amplitude (Product Analytics — consent-based)
Provider: Amplitude, Inc., 201 Third Street, Suite 200, San Francisco, CA 94103, USA
Purpose: Measuring page views, sessions and site usage — including recurring, cross-session visits — to understand our audience and improve the website.
Legal Basis: Art. 6 (1) point (a) GDPR and §25 (1) TDDDG (your consent)
Data Categories: Usage data, connection data, device information
Data Location: Processed in Amplitude's EU (Frankfurt, Germany) data centre
Safeguards: EU-US Data Privacy Framework and Standard Contractual Clauses (Art. 46 (2) point (c) GDPR) for any residual transfer to the USA
This part uses cookies and only loads once you accept analytics cookies in our consent tool. You can withdraw your consent at any time via "Cookie settings" in the footer.
Amplitude (Aggregate Page-View Count — cookieless)
Purpose: Counting total page views to measure overall traffic, independently of the cookie consent above.
Legal Basis: Art. 6 (1) point (f) GDPR (legitimate interest in reach measurement). Nothing is stored on or read from your device, so no consent under §25 TDDDG is required.
Data Categories: Usage data only (page path, referrer). Each view is sent with a freshly generated random identifier; your IP address and browser user-agent are never stored and never transmitted to Amplitude.
Data Location: Processed in Amplitude's EU (Frankfurt, Germany) data centre
Because every view carries a new random identifier, visitors cannot be recognised or counted as unique individuals through this measurement — it produces totals only. You may object to this processing at any time (see "Right to Object" above).
In the same anonymous, cookieless way we also record whether visitors accept or reject analytics cookies (a single "accepted"/"rejected" value, with no identifier), so we can measure the overall opt-in rate. This carries no personal data.
The same cookieless channel also records aggregate conversion events — that a membership application or an ACMI registration was submitted — together with non-identifying attributes only (e.g. the applicant's company size). No names, e-mail addresses or other personal data are included.
Amplitude (Product Analytics — consent-based)
Provider: Amplitude, Inc., 201 Third Street, Suite 200, San Francisco, CA 94103, USA
Purpose: Measuring page views, sessions and site usage — including recurring, cross-session visits — to understand our audience and improve the website.
Legal Basis: Art. 6 (1) point (a) GDPR and §25 (1) TDDDG (your consent)
Data Categories: Usage data, connection data, device information
Data Location: Processed in Amplitude's EU (Frankfurt, Germany) data centre
Safeguards: EU-US Data Privacy Framework and Standard Contractual Clauses (Art. 46 (2) point (c) GDPR) for any residual transfer to the USA
This part uses cookies and only loads once you accept analytics cookies in our consent tool. You can withdraw your consent at any time via "Cookie settings" in the footer.
Amplitude (Aggregate Page-View Count — cookieless)
Purpose: Counting total page views to measure overall traffic, independently of the cookie consent above.
Legal Basis: Art. 6 (1) point (f) GDPR (legitimate interest in reach measurement). Nothing is stored on or read from your device, so no consent under §25 TDDDG is required.
Data Categories: Usage data only (page path, referrer). Each view is sent with a freshly generated random identifier; your IP address and browser user-agent are never stored and never transmitted to Amplitude.
Data Location: Processed in Amplitude's EU (Frankfurt, Germany) data centre
Because every view carries a new random identifier, visitors cannot be recognised or counted as unique individuals through this measurement — it produces totals only. You may object to this processing at any time (see "Right to Object" above).
Data Security
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data in transit and at rest
- Pseudonymisation where appropriate
- Regular security assessments and updates
- Access controls and user authentication
- Staff training on data protection
- Incident response procedures
Cookies and Similar Technologies
Our website uses cookies and similar technologies (such as web storage) to provide essential functionality and — only with your consent — analytics. We do not use advertising or marketing cookies. You can manage your preferences at any time through our consent management platform, which appears on your first visit and can be reopened via "Cookie settings" in the footer.
Cookies we use:
Essential: A single first-party cookie that remembers your cookie choice ("cc_cookie"). Always active; no consent required.
Analytics (Amplitude) — only if you accept: The Amplitude Browser SDK stores "AMP_*" cookies and related web storage (up to approximately one year) to recognise returning visitors and measure sessions. These are set only after you accept analytics cookies and are cleared automatically if you withdraw consent.
Contact Us
If you have any questions about this Privacy Policy or our data processing practices, please contact us:
shopware AG
Ebbinghoff 10
48624 Schöppingen, Germany
Email: info@shopware.com
Phone: 00 800 746 7626 0
Last updated: 13/07/2026
This privacy policy may be updated from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes through our website or other appropriate means.
