Ships from Germany · 1–2 business days

SilentLink

Legal

Privacy Policy

As of: September 2026

1. Controller

Controller within the meaning of the General Data Protection Regulation (GDPR):
SilentLink UG (haftungsbeschränkt)
Heinz-Fangman-Straße 2–6, 42287 Wuppertal, Germany
Represented by the Managing Director Darrel Hozaifeh
Email: info@silentlink.de

2. Overview and legal bases

This statement informs you about how we process personal data when you visit the website silentlink.de (including ordering) and when you use the SilentLink platform (activation, customer account, mediation of messages and calls). We only process what is necessary for the respective purpose. The legal bases are in particular Art. 6(1)(b) GDPR (contract), (f) GDPR (legitimate interest) and (a) GDPR (consent) as well as § 25 TDDDG for the storage of and access to information on your device.

3. Hosting and server log files

Our website is operated by Cloudflare (Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA; hosting via Cloudflare Pages, content delivery network and protection against attacks). In doing so, connection data is automatically processed (in particular IP address, date and time, page accessed, referrer URL as well as browser and operating system information). The basis is our legitimate interest in secure and stable operation (Art. 6(1)(f) GDPR); the data is stored only for a short time. The server-side functions of the website (forms, forwarding of measurement data under section 7) also run at Cloudflare. In addition, we count there anonymously how often the cookie banner is displayed and which choice was made, and how many ad clicks reach the site — only the day, the event and the page are stored as a count, no IP address and no identifier. For third countries, see section 10.

4. Cookies and consent

Our website itself does not set any tracking cookies. We store technically necessary information in your browser's local storage (§ 25(2) TDDDG): the content of your shopping cart and your choice in the cookie banner. So that the checkout knows your choice, it is additionally passed on to Shopify and recorded there in a necessary cookie (_tracking_consent). Services requiring consent (analysis and marketing, see section 7) are only loaded after your consent via the cookie banner (Art. 6(1)(a) GDPR, § 25(1) TDDDG); before that, none of these services is called and nothing is stored on your device for them. You can adjust or withdraw your consent at any time with effect for the future: Open cookie settings.

5. Shop, ordering and payment

The catalogue, shopping cart and checkout run via Shopify (Shopify International Limited, Victoria Buildings, 2nd Floor, 1–2 Haddington Road, Dublin 4, D04 XN32, Ireland). When you fill the shopping cart, your browser transmits the selected items to Shopify; the checkout itself takes place on shop.silentlink.de at Shopify. During the ordering process we process the data required for processing (order data, name, address, email address, payment information) on the basis of Art. 6(1)(b) GDPR. Payment is made via the payment methods offered at checkout (including credit card, PayPal, Klarna as well as wallet payments); your payment data is processed directly by the respective payment service provider. In the case of purchase on account or in instalments, a credit check may be carried out by the payment service provider. Shopify may also transfer data to Shopify Inc. in Canada and to subcontractors in the USA (see section 10).

6. Customer reviews

On our pages we display customer reviews collected via the review service Judge.me. For this purpose, Judge.me processes the order reference, name or abbreviation, email address and review content (Art. 6(1)(f) GDPR). The reviews are retrieved when the website is built and embedded statically; when a page is loaded, none of your data is transmitted to Judge.me. On the website we only display the first name and the first letter of the surname.

7. Analysis and marketing

We use the following services exclusively with your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). They are only loaded after you have consented to the respective category in the cookie banner. In doing so, pseudonymous usage and event data is processed (e.g. pages accessed, clicks, shopping cart events, IP address, device and browser information).

Category "Analytics"

  • Google Analytics 4 (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland): reach measurement and evaluation of usage. Cookies _ga/_ga_*, storage period up to 2 years.
  • Microsoft Clarity (Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland): evaluation of clicks, scrolling behaviour and session recordings in order to improve the usability of the site; entries in form fields are masked. Cookies including _clck (up to 1 year) and _clsk (1 day). Microsoft also sets its own identifiers on Microsoft domains (e.g. MUID, up to around 13 months), which, according to Microsoft, it may also use for advertising purposes.
  • Shopify Analytics (Shopify, see section 5): measurement of page views and shopping cart events so that a visit and an order can be evaluated as one session. Cookies _shopify_y (up to 1 year) and _shopify_s (30 minutes) on silentlink.de.

Category "Marketing"

  • Meta Pixel and Meta Conversions API (Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland): measurement of which ads on Facebook and Instagram lead to visits and purchases, and delivery of these ads. The events are sent from your browser to Meta and additionally via our server at Cloudflare, each with an event ID so that Meta does not count them twice; in the process, the IP address, browser identifier, the Meta click ID and a hashed identifier are transmitted. Cookies _fbp/_fbc, up to 90 days. We are jointly responsible with Meta for the collection and transmission of the data to Meta (Art. 26 GDPR); the further processing lies solely with Meta. The essence of the arrangement can be found at facebook.com/legal/controller_addendum.
  • Google Ads with conversion tracking (Google Ireland Limited, see above): measurement of which Google ads lead to purchases. Cookie _gcl_aw, up to 90 days. In the event of a purchase, hashed contact data (e.g. email address) may additionally be transmitted to Google so that Google can attribute the purchase to the ad ("enhanced conversions").

The consent also applies to the checkout on shop.silentlink.de. You can withdraw it at any time with effect for the future in the cookie settings.

8. Contact and forms

When you contact us by email or via our contact and enquiry forms, we process your information (in particular email address, request, optionally name or company) in order to process your enquiry and send you a confirmation of receipt (Art. 6(1)(b) or (f) GDPR). We send the emails from the website's forms via Resend (Plus Five Five, Inc., San Francisco, USA) as a processor.

On our pages for businesses you can book an appointment via Cal.com (Cal.com, Inc., San Francisco, USA). The calendar is only loaded when you click "Pick an open slot"; in doing so, your IP address and the data you enter (name, email address, preferred appointment) are transmitted to Cal.com (Art. 6(1)(b) GDPR).

If you use our online withdrawal function (Cancel contract), we process the data provided there to process your withdrawal and to fulfil our statutory obligation to promptly confirm receipt (Art. 6(1)(b) and (c) GDPR). The data is deleted as soon as it is no longer required and no statutory retention obligations preclude this.

On selected pages we offer a live chat. It is only loaded after you explicitly click the chat button — before that, no data is sent to the chat and no cookies or local storage entries are set. The chat runs on our own infrastructure operated in the EU (Chatwoot, open source, available at chat.silentlink.de); the conversation content does not leave our hosting. We process the message history, a randomly assigned session identifier, technical details of your browser and any contact details you provide voluntarily (Art. 6(1)(b) and (f) GDPR). Once opened, the chat stores local entries in your browser so that an ongoing conversation survives page changes.

9. SilentLink platform (customer account, activation and mediation)

A core function of our products is the anonymous mediation of contact: whoever scans a contact code never sees your contact data at any time; the transmission takes place exclusively via our platform to the channel you have chosen. For the use of the platform we process your account and contact data (in particular name, email address and the stored contact channels) as well as the information you voluntarily store for your product (Art. 6(1)(b) GDPR).

Mediation of messages and calls. If a finder gets in touch via a contact code, we process the content of the report as well as the contact data voluntarily provided in the process in order to deliver the message to you via the chosen channel (Art. 6(1)(b) and (f) GDPR). For delivery we use specialised communication service providers. In the case of anonymous calls, your phone number remains hidden from the caller; we store callers' phone numbers exclusively in pseudonymised (hashed) form.

Scan notification and location. If a contact code is scanned, we inform the owner about the scan. This notification may contain an approximate location at city level that is estimated from the IP address of the scanning device; this is pointed out on the scan page (Art. 6(1)(f) GDPR). Your exact location (GPS) is only transmitted if you actively release it on the scan page (Art. 6(1)(a) GDPR); the release is voluntary. To convert a released location into an address, we use a map service.

Misuse and fraud prevention. When scanning, we process technical information about the access (including IP address, browser and device information as well as characteristics for detecting misuse) for security and fraud detection (Art. 6(1)(f) GDPR); for this we use a corresponding service provider. We store this data for this purpose for a maximum of three months.

Paid plans. If you conclude a paid plan, we process payment and invoicing via a payment service provider (Art. 6(1)(b) GDPR). We retain invoices within the scope of the statutory retention obligations.

Emergency and health information. Insofar as you voluntarily store special categories of personal data (such as emergency or health information) for certain products so that these can be displayed if needed, we process these exclusively on the basis of your explicit consent and because you yourself designate this information for display (Art. 9(2)(a) and (e) GDPR). You are responsible for the content you enter; you can change or delete it at any time.

10. Recipients and transfer to third countries

We only pass on personal data insofar as this is necessary for the stated purposes — in particular to carefully selected processors (categories: hosting/IT operations, communication, payment, shipping, map, analysis and marketing service providers) with whom data processing agreements under Art. 28 GDPR exist, as well as to bodies to which we are legally obliged to disclose. We name the providers used on the website in sections 3 to 8. Several of them are based in the USA or may transfer data there (Cloudflare, Shopify, Google, Microsoft, Meta, Resend, Cal.com). We base these transfers on the adequacy decision for the EU-US Data Privacy Framework, insofar as the provider is certified under it, and otherwise on EU standard contractual clauses (Art. 46(2)(c) GDPR). For Canada, an adequacy decision of the European Commission exists. We will provide you with an overview of the processors of the SilentLink platform (section 9) on request.

11. Storage period

We store personal data only for as long as it is necessary for the respective purposes or statutory retention obligations exist (in particular under commercial and tax law, 6 or 10 years). On the platform, we generally delete finder reports and associated histories after 30 days and technical data for misuse prevention after three months at the latest. If you delete your account, we remove your personal data after a withdrawal period of 30 days; documents to be retained by law (in particular invoices) remain unaffected.

12. Your rights

You have the following rights under the GDPR:

  • Access (Art. 15), rectification (Art. 16), erasure (Art. 17) and restriction (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)
  • Withdrawal of consent given, with effect for the future (Art. 7(3) GDPR)
  • Complaint to a supervisory authority (Art. 77 GDPR) — competent for us: State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia

13. Changes

We adapt this statement when the data processing or the legal situation changes; the version published here at any given time applies.

Legal guarantee