---
title: "Privacy policy | RINSUMILA"
description: "Privacy policy: which data we process and which rights you have."
url: "https://rinsumila.com/en/legal/privacy"
image: "https://rinsumila.com/og/rinsumila-c901f058.png"
lang: "en-US"
generated: "2026-10-02T17:57:36.249Z"
source: "rinsumila.com, HTML converted to Markdown at origin"
---

# Privacy Policy

As of: 2 October 2026

## 1\. What this is about

This privacy policy applies to [https://rinsumila.com](https://rinsumila.com/) in the period before the start of sales. During this period you can view the shop, sign up for a notification when products become available, write to us and create a customer account. You cannot yet order or pay. During this period we do not use any statistics or analytics services (including no Google Analytics) and therefore do not show a cookie banner.

Here we describe only the processing that actually takes place before the start of sales. When sales start, we will replace this policy with the full version.

## 2\. Controller

TopieT GmbH Giesenheide 40, 40724 Hilden, Germany E-mail: [support@rinsumila.com](mailto:support@rinsumila.com)

Represented by the managing director Igor Shelkovenkov.

For all questions about data protection and for exercising your rights, you can reach us at [support@rinsumila.com](mailto:support@rinsumila.com) or by post at the address given above.

## 3\. Data protection officer

We have not appointed a data protection officer because we are not obliged to do so.

## 4\. Visiting the website: hosting and server logs

**What happens:** When you open a page, our server processes the data your browser transmits as part of the technical request. Our server logs every request with the following details: IP address (the address of your device as transmitted by Cloudflare, and the address of the Cloudflare server), requested host and path including the parameters in the address (for confirmation and password links, this also includes the code contained in them), request method, status code, date, time and duration of the request, encryption used, browser identifier (user agent), the page visited beforehand (referrer), the browser hints on browser brand and version (client hints), and certain signature headers by which automated requests identify themselves. Cookies and login credentials are not logged.

In addition, the shop's applications write technical logs. The log of our interface contains, for each request, the IP address, the requested address and its parameters. For some processes your e-mail address is also recorded there, for example when you submit the contact form or when an e-mail to us could not be delivered.

To prevent abuse, we limit the number of requests per IP address (for example for forms). For this purpose the IP address is held only briefly in working memory. We count failed login attempts per e-mail address for 15 minutes.

**Purpose:** delivery of the website, security and stability of operations, detection and defence against attacks and abuse, troubleshooting.

**Legal basis:** Art. 6(1)(f) GDPR. Our legitimate interest is a secure, stable and error-free operation of the website.

**Storage period:** The server access log is rotated daily and deleted after 14 days; an entry is therefore stored for 15 days at most. The logs of the applications have a fixed size limit and are continuously overwritten once this limit is reached.

**Hosting:** Our server is located in Finland in a data centre of Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany). Hetzner is our processor (Art. 28 GDPR). All data of the shop (database, logs, media, backup copies) is located on this server in the EU.

## 5\. Cloudflare

**What happens:** All requests to our website and our subdomains run through the network of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Cloudflare distributes the content (content delivery network), protects the shop against attacks (firewall, defence against automated access) and operates name resolution (DNS). This applies to all requests to our web addresses; anyone who accesses our server directly via its IP address bypasses Cloudflare (see Section 6). For this purpose Cloudflare decrypts the traffic and processes your IP address, the requested addresses, the request headers (for example browser identifier) and information about the traffic. Technically, Cloudflare can also see content that you send to us, for example form entries.

For requests that the security system classifies as suspicious (for example from networks of certain cloud providers), Cloudflare may carry out a security check in the browser.

**Cookies from Cloudflare:** Cloudflare may set the following cookies for security purposes:

-   `cf_clearance`: stores that your browser has passed a security check, so that you do not have to go through it again with every request. Duration according to Cloudflare's security setting.
-   `__cf_bm`: serves to distinguish humans from automated access (bot defence). Expires after 30 minutes of inactivity.

**Purpose:** fast and secure delivery of the website, protection against attacks and abusive access.

**Legal basis:** Art. 6(1)(f) GDPR. Our legitimate interest is a secure and reliably accessible website. The security cookies are strictly necessary for us to provide the website to you securely (§ 25(2) no. 2 TDDDG).

**Role:** Cloudflare is our processor (Art. 28 GDPR). For its own purposes, for example the security of its own network, Cloudflare also processes data as a controller; details at [https://www.cloudflare.com/privacypolicy/](https://www.cloudflare.com/privacypolicy/).

**Third country:** Cloudflare may process data in the USA. Cloudflare, Inc. is certified under the EU-US Data Privacy Framework; the transfer is based on the adequacy decision of the European Commission of 10.07.2023 (Art. 45 GDPR). In addition, Cloudflare has agreed the standard contractual clauses of the European Commission (Art. 46(2)(c) GDPR) in its data processing agreement; they are available at [https://www.cloudflare.com/cloudflare-customer-dpa/](https://www.cloudflare.com/cloudflare-customer-dpa/).

**Storage period:** Cloudflare determines the storage period according to the purpose of the processing, the scope, nature and protection needs of the data and statutory requirements, and deletes the data when this period expires; details in Cloudflare's privacy policy.

## 6\. Protection against attacks on the server

**What happens:** In addition to Cloudflare, a protection programme (fail2ban) on our server monitors the access log. It blocks, for one hour, IP addresses that access our server directly, bypassing Cloudflare, in large numbers (more than 700 requests per minute). We also permanently block individual addresses and network ranges from which attacks have demonstrably originated. Anyone who visits the shop normally via its address is not affected by the counting. The blocked IP address, the rule and the time are stored.

An automatic message informs us about blocks; it contains only the shortened network range (IPv4: the first three blocks, IPv6: the first 48 bits), not a complete IP address.

**Purpose:** protection of the server and the shop against overload, attacks and automated abuse; rapid response to attacks.

**Legal basis:** Art. 6(1)(f) GDPR. Our legitimate interest is the security and availability of our systems.

**Storage period:** The protection programme's database deletes entries after one day; a time-limited block ends after one hour. We delete the block log after 90 days. Permanent blocks remain in place until we lift them.

## 7\. Cookies and storage in your browser

Before the start of sales we use only cookies and browser storage that are strictly necessary for the functions you use. Some of them are created only when you actively use a function.

| Name | Type | Purpose | Duration |
| --- | --- | --- | --- |
| `NEXT_LOCALE` | Cookie | remembers the language you have expressly chosen | 1 year |
| `pd_lang_choice` | Cookie | remembers that you have deliberately chosen the language, so that the language hint does not appear again | 1 year |
| `pd-lang-hint-dismissed` with language code | local storage | remembers that you have closed the language hint | until you delete it in your browser |
| `theme` | local storage | remembers your choice between light and dark design | until you delete it in your browser |
| `shop-auth` | Cookie | indicator that you are logged in | 30 days |
| `refresh_token` | Cookie (only for our interface, not readable by script) | keeps your login active | 30 days |
| `shop-auth-storage` | local storage | login state with access code and your account data (for example name and e-mail address) | until you log out |
| `cf_clearance`, `__cf_bm` | Cookies from Cloudflare | security, see Section 5 | see Section 5 |

The cookies `shop-auth` and `refresh_token` and the storage `shop-auth-storage` are created only when you log in or register.

**Legal basis:** Storing and reading this information on your device is strictly necessary to provide you with the functions you have expressly requested (§ 25(2) no. 2 TDDDG). We base the subsequent processing on Art. 6(1)(b) GDPR (login to the customer account) and otherwise on Art. 6(1)(f) GDPR; our legitimate interest is to provide the website securely in your chosen language and with your chosen appearance.

You can delete cookies and local storage in your browser at any time. Your settings will then be lost and you will have to log in again.

## 8\. Images and media

We deliver product images and other media via our own media management (Openinary), which runs on our server. The images are retrieved via our own domain. This generates only the data described in Sections 4 and 5; no further service provider is involved.

## 9\. Error monitoring

**What happens:** So that we can find technical errors quickly, we use the error monitoring tool GlitchTip. We operate GlitchTip ourselves on our server; the data does not go to any further service provider. If an error occurs in your browser or on our server, an error report is created. It contains the error message, technical details on the program flow, the requested address (we remove confirmation and password codes beforehand), browser, operating system and device type, and the time. In these error reports we store your IP address only in shortened form. In addition, for a small share of page views (2 percent in the browser, 5 percent on the server) we record measurements of loading times. Warnings and error messages from the logs of our servers are also transferred to GlitchTip; they may contain the IP address and the requested address. We do not make screen recordings of your visit.

**Purpose:** detecting and fixing errors, stability and security of the shop.

**Legal basis:** Art. 6(1)(f) GDPR. Our legitimate interest is a shop that works without errors.

**Storage period:** GlitchTip deletes error reports after 90 days and loading time measurements after 30 days.

## 10\. E-mails: sending and receiving

**What happens:** We send all e-mails of the shop (for example confirmation links, notifications, replies to enquiries) via the Resend service. We also receive e-mails to addresses of our domain via Resend. In doing so, Resend processes the sender and recipient address, subject, content and attachments of the e-mail as well as the delivery status. Resend reports to us whether an e-mail was sent, delivered or rejected and whether the recipient complained. We do not measure whether you open our e-mails or which links you click in them. If an address is permanently undeliverable or the recipient has complained about our e-mails, we put it on a suppression list and send no further e-mails to it. Until they are sent, e-mails are held briefly in a queue on our server.

**Purpose:** delivery of the e-mails, receipt of your messages, proof of delivery, avoidance of sending to unreachable recipients or recipients who object.

**Legal basis:** Art. 6(1)(b) GDPR, insofar as the e-mail belongs to a contract or your customer account; Art. 6(1)(a) GDPR, insofar as it is based on your consent (Section 11); otherwise Art. 6(1)(f) GDPR. Our legitimate interest is reliable and verifiable e-mail communication.

**Service provider:** Plus Five Five, Inc. (Resend), 2261 Market Street #5039, San Francisco, CA 94114, USA, as our processor (Art. 28 GDPR). A data processing agreement exists with Resend.

**Third country:** Resend handles the sending for our domain via servers in the EU (Ireland). The data is stored at Resend in the USA. Resend is certified under the EU-US Data Privacy Framework; the transfer is based on the adequacy decision of the European Commission of 10.07.2023 (Art. 45 GDPR). In addition, the standard contractual clauses of the European Commission are agreed in the data processing agreement (Art. 46(2)(c) GDPR), available at [https://resend.com/legal/dpa](https://resend.com/legal/dpa).

**Storage period:** We delete completed sending jobs no later than the first daily clean-up run after they have become older than 24 hours, and failed jobs correspondingly after 7 days. Resend stores the content and log data of the e-mails for 30 days; backup copies at Resend are deleted after 7 days. We keep entries on the suppression list for 3 years (1,095 days) so that we do not write to these addresses again.

## 11\. Notification as soon as a product is available

**What happens:** On the product pages you can enter your e-mail address so that we let you know as soon as the product can be ordered. For this purpose we store your e-mail address, the chosen product and, where applicable, the variant, your language, the status of your sign-up, a confirmation code with expiry time, and the time of the sign-up, the confirmation and the notification. We do not store the IP address and browser identifier in this process.

We use the double opt-in procedure: After you sign up, you receive an e-mail with a confirmation link. Only when you open and confirm this link is the sign-up active. The link is valid for 7 days. Without confirmation you will not receive a notification. With the stored times we prove that you have consented.

As soon as the product can be ordered (including at the start of sales), we will send you exactly one e-mail. After that we will not write to you about this sign-up any more. We do not use your address for advertising.

**Purpose:** one-time notification about the availability of the chosen product.

**Legal basis:** your consent under Art. 6(1)(a) GDPR; we keep the proof of consent under Art. 6(1)(c) in conjunction with Art. 7(1) GDPR.

**Withdrawal:** You can withdraw your consent at any time with effect for the future, for example with a short e-mail to [support@rinsumila.com](mailto:support@rinsumila.com). We will then delete your sign-up.

**Recipients:** Resend for sending (Section 10).

**Storage period:** We delete unconfirmed sign-ups 30 days after the confirmation link has expired. We delete confirmed sign-ups 30 days after the notification or after your withdrawal, but at the latest 24 months (730 days) after the confirmation if the product has not become available by then.

## 12\. Contact form and contact by e-mail

**What happens:** When you write to us via the contact form, we process your name, your e-mail address, the chosen topic, the subject and your message. The form sends your message via Resend to our support mailbox; there we store it in the database of our support mailbox. Your e-mail address is entered as the reply address. The log of our interface records that a message with the stated subject has been received from your e-mail address. If you write to us directly by e-mail, we process the details from your e-mail (sender, recipient, subject, text, attachments). We store incoming e-mails in our support mailbox on our server; we retrieve attachments from Resend when needed.

**Purpose:** handling and answering your enquiry.

**Legal basis:** Art. 6(1)(b) GDPR, if your enquiry concerns a contract or your customer account or serves to prepare a contract; otherwise Art. 6(1)(f) GDPR. Our legitimate interest is answering enquiries.

**Recipients:** Resend (Section 10).

**Storage period:** We delete enquiries, including those about your customer account, twelve months (365 days) after the last message in the case, provided they have no connection to an order. For the log period, see Section 4.

## 13\. Customer account

**What happens:** You can create a customer account even before the start of sales. When you register, we process your e-mail address, your password (only as a cryptographic check value (password hash), never in plain text), your name, your telephone number and your language. Your name and your telephone number are optional. In the account you can store addresses (label, first and last name, street and additional line, city, federal state, postal code, country, telephone number). To confirm your e-mail address we send you a link that is valid for 7 days. You can request a password reset link no more than once every 2 minutes; it is valid for 60 minutes. For login we use the cookies and the browser storage from Section 7. We use a telephone number only to reach you about your account at your request.

**Purpose:** provision of the customer account.

**Legal basis:** Art. 6(1)(b) GDPR (contract on the use of the customer account).

**Recipients:** Resend for e-mails about the account (Section 10).

**Storage period:** as long as your account exists. You can have your account deleted at any time; to do so, write to [support@rinsumila.com](mailto:support@rinsumila.com). On your request for deletion we remove your contact data (name, e-mail address, telephone number, addresses) and your access data, unless statutory retention obligations prevent this. Codes for resetting the password and login codes expire after the periods stated above.

## 14\. Data backup

We create daily backup copies of the shop database, the error monitoring and the media files. The backups are stored with restricted access on our server at Hetzner (Section 4). Backups are deleted during the daily backup run as soon as they are at least 15 days old. Deleted data can therefore remain in backups for up to 16 more days.

We implement the deletion periods of Sections 10 to 12 (queue, suppression list, notifications, enquiries) with an automatic deletion run that takes place nightly every day. This data is therefore deleted at the first deletion run after the respective period has expired, at the latest.

**Purpose:** recovery after technical faults or data loss. **Legal basis:** Art. 6(1)(f) GDPR (our legitimate interest in the availability and integrity of the data) and Art. 32(1)(c) GDPR.

## 15\. Overview of recipients

| Recipient | Role | Section |
| --- | --- | --- |
| Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany | Processor (hosting) | 4, 14 |
| Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA | Processor (delivery, security, DNS) | 5   |
| Plus Five Five, Inc. (Resend), 2261 Market Street #5039, San Francisco, CA 94114, USA | Processor (e-mail) | 10, 11, 12, 13 |

Beyond this, we pass on your data only if we are legally obliged to do so, for example to public authorities pursuant to an order.

## 16\. Transfers to countries outside the EU

Data goes to countries outside the EU only in Sections 5 (Cloudflare, USA) and 10 (Resend, USA). For the USA, in the case of certified companies we rely on the adequacy decision of the European Commission on the EU-US Data Privacy Framework (Art. 45 GDPR) and, in addition, on the standard contractual clauses of the European Commission (Art. 46(2)(c) GDPR). You can obtain a copy of the standard contractual clauses on request to [support@rinsumila.com](mailto:support@rinsumila.com); they are also available in the providers' agreements mentioned in the sections.

## 17\. Your rights

You have the following rights towards us regarding your personal data:

-   access to the data we process about you (Art. 15 GDPR),
-   rectification of inaccurate data (Art. 16 GDPR),
-   erasure (Art. 17 GDPR),
-   restriction of processing (Art. 18 GDPR),
-   data portability: release of the data you have provided to us in a commonly used, machine-readable format (Art. 20 GDPR),
-   objection to processing (Art. 21 GDPR, see Section 18).

If we rectify or erase data or restrict its processing, we notify the recipients to whom we have disclosed the data, where this is possible (Art. 19 GDPR). Write to us at [support@rinsumila.com](mailto:support@rinsumila.com) for all requests.

## 18\. Your right to object

> **Right to object under Art. 21 GDPR**
> 
> Where we process your data on the basis of Art. 6(1)(f) GDPR (legitimate interest), you have the right to object, on grounds relating to your particular situation, at any time to this processing. We will then no longer process your data, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
> 
> Where we process your data for direct marketing, you can object to this processing at any time without giving reasons. We will then no longer use your data for this purpose.
> 
> You can object informally, most simply by e-mail to [support@rinsumila.com](mailto:support@rinsumila.com).

## 19\. Withdrawal of your consent

If you have consented to processing, you can withdraw this consent at any time with effect for the future (Art. 7(3) GDPR). The lawfulness of the processing up to the withdrawal remains unaffected. An e-mail to [support@rinsumila.com](mailto:support@rinsumila.com) is sufficient.

## 20\. Complaint to a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. The authority responsible for us is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen Kavalleriestraße 2-4, 40213 Düsseldorf Postal address: Postfach 20 04 44, 40102 Düsseldorf Telephone: +49 211 38424-0 E-mail: [poststelle@ldi.nrw.de](mailto:poststelle@ldi.nrw.de) Website: [https://www.ldi.nrw.de](https://www.ldi.nrw.de/)

## 21\. Do you have to give us data?

You are neither legally nor contractually obliged to provide data to us. Without the data that arises technically when the website is accessed (Sections 4 and 5), we cannot display the website to you. Without an e-mail address we cannot notify you or answer your enquiry. For a customer account we need your e-mail address and a password; without them you cannot create an account.

## 22\. No automated decision-making

We do not make decisions based solely on automated processing, including profiling, which produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR). The blocks in Section 6 concern only technical access to our server for the duration of the block.

## 23\. Changes to this privacy policy

We adapt this privacy policy when our shop, our service providers or the legal situation change, at the latest at the start of sales. The version published on this page at the time applies; the date is shown at the top under "As of". If we want to use data already collected for a new purpose, we will inform you beforehand.

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://rinsumila.com/en"},{"@type":"ListItem","position":2,"name":"Privacy policy","item":"https://rinsumila.com/en/legal/privacy"}]}
```
