Privacy Policy
This privacy policy applies exclusively to the web shop for the sale of physical devices. Processing in connection with the app, asset tracking, and IoT data is handled separately and is not covered by this privacy policy unless explicitly stated otherwise in a specific case.
1. Controller
TrackDown UG (haftungsbeschränkt)
c/o Am Technologiehof Münster - GründerGarage, Mendelstraße 11, 48149 Münster, Germany
Email: admin@cora-track.de
Represented by: Tobias Nickut
Privacy contact: Tobias Nickut, contactable at admin@cora-track.de
2. Purposes and legal bases of processing
Personal data is processed only to the extent necessary for operating the web shop, handling orders, processing payments, shipping goods, communicating with customers, and ensuring IT security.
The legal bases are, in particular, Art. 6(1)(b) GDPR for pre-contractual steps and contract performance, Art. 6(1)(c) GDPR for statutory retention and documentation obligations, and Art. 6(1)(f) GDPR for the secure and stable operation of the website, abuse prevention, and handling general inquiries.
3. Website access / server log files
When the web shop is accessed, technically necessary data is processed, in particular IP address, date and time of access, requested content, transferred volume, browser type, operating system, and referrer, to the extent transmitted by the browser.
This processing is carried out to provide the website, ensure stability and security, and detect and prevent misuse. The legal basis is Art. 6(1)(f) GDPR.
For strictly internal reach measurement, page views, opens of provided PDF documents, and visible active time per page path are immediately combined into anonymous aggregate counters. No cookies, local storage, device identifiers, IP addresses, raw events, or user profiles are stored for this purpose. Individual visitors are not recognized and no data is disclosed to third parties.
4. Orders and contract performance
In the context of an order, the data required for contract performance is processed. This includes, in particular, name, billing and shipping address, email address, ordered products, order details, price and tax information, and communication relating to the order.
The processing is carried out to handle the order, perform the purchase contract, communicate with customers, deliver the goods, and handle questions, returns, and warranty matters. The legal basis is Art. 6(1)(b) GDPR.
For a non-binding manufacturing reservation, the email address, product, quantity, language, reservation status and timestamps as well as exclusively hashed cancellation and checkout tokens are processed. The data is used for pre-contractual measures, manufacturing coordination, sending the cancellation and subsequent checkout links, and preventing duplicate allocations. The legal basis is Art. 6(1)(b) GDPR.
During fulfilment, the order reference is assigned to the specific device and SIM identifiers and the purchase date. The order email remains only in order records required for contract performance and statutory retention. While it is lawfully held for those purposes, it may be used for a manually initiated advance notice of an intended SIM deactivation. It is not copied into SIM-lifecycle data; no automated reminder process is used. The legal basis is Art. 6(1)(b) and (c) GDPR.
5. Payment processing
An external payment service provider is used for payment processing. The data required for payment is transmitted to that provider or collected directly by it. This includes, in particular, payment information, transaction data, billing information, and technical data required to execute and secure the payment.
The processing is carried out to execute the payment and therefore to perform the contract under Art. 6(1)(b) GDPR. To the extent the payment service provider additionally processes data to comply with regulatory obligations, prevent fraud, or secure payment operations, such processing takes place under its own applicable data-protection responsibilities and contractual terms.
The payment service provider's identity, terms, and privacy information are displayed in the secure payment interface before payment data is entered.
6. Shipping and logistics
To deliver ordered goods, the data required for shipment is transmitted to the commissioned shipping provider. This regularly includes name, delivery address, and, where required for delivery or delivery notice, contact information and shipment-related order data.
The legal basis is Art. 6(1)(b) GDPR.
7. Communication and support
If contact is made, for example by email or contact form, the transmitted data is processed for the purpose of handling the request. This includes, in particular, name, contact details, message content, and, where applicable, order-related information.
The processing is carried out either for pre-contractual or contractual measures under Art. 6(1)(b) GDPR or on the basis of the legitimate interest in handling general inquiries under Art. 6(1)(f) GDPR.
8. Technically necessary storage
The shopping cart is stored in a technically necessary HTTP-only, SameSite=Lax cookie. It contains a random cart ID, product variants, quantities and timestamps, but no payment data. It is retained for no more than 30 days.
A technically necessary language cookie stores the selected site language for no more than one year. The light/dark colour-scheme preference is stored only locally in the browser and is not transmitted to TrackDown. The legal basis for these strictly necessary terminal-storage operations is Section 25(2) no. 2 TDDDG; subsequent processing is based on Art. 6(1)(b) or (f) GDPR.
9. Withdrawal, app-account deletion and password reset
When the electronic withdrawal function is used, name, email address, order or contract reference, contract description, declaration, timestamp, IP address and user agent are processed. The information is emailed to the controller and returned to the supplied address as a receipt confirmation. The legal bases are Art. 6(1)(b) and (c) GDPR and Art. 6(1)(f) GDPR for abuse prevention and evidence.
The website relays confirmed app-account deletions and password-reset confirmations to the app API. The entered data and technically required connection information are processed for this purpose. Further details are provided in the app Privacy Policy.
Before app-account deletion, any applicable earliest SIM-deactivation date is displayed. The app-account email address is deleted with the account and cannot subsequently be used as a contact address for a SIM reminder; the dialog therefore serves as the notice for that app account.
10. Recipients of data
Personal data is disclosed only to the extent necessary for the stated purposes. Recipients may include, in particular, hosting providers, external payment service providers, shipping providers, email or support service providers, Hologram and participating mobile-network operators for embedded-SIM administration, and tax or accounting advisors.
Shop data is not used for positioning or usage profiles. The order reference, purchase date and device/SIM identifiers are combined only for the device and SIM administration described above.
11. Storage period
Personal data is stored only for as long as necessary or while statutory retention duties apply. Order, invoice and accounting data is retained under applicable commercial and tax law. Manufacturing reservations are retained until completion, cancellation or expiry and afterwards only for as long as required for processing, abuse prevention, or the establishment, exercise or defence of legal claims. Technical device/SIM and lifecycle data remains only while needed to administer the supplied device, comply with law or handle legal claims. The cart expires after no more than 30 days. Withdrawal declarations and associated contract evidence are retained for applicable documentation and limitation periods. Server logs are deleted after no more than 30 days unless restricted longer retention is necessary to investigate a specific security incident or defend legal claims.
12. Obligation to provide data
Providing the data required to conclude and perform the contract is necessary. Without this data, an order cannot be placed or fulfilled.
13. Data subject rights
The statutory rights to access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests apply. The contact details above may be used to exercise these rights.
14. Right to lodge a complaint
There is a right to lodge a complaint with a supervisory authority. The competent authority is generally the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia, Kavalleriestraße 2-4, 40213 Düsseldorf, Germany, https://www.ldi.nrw.de/.
15. Version
Version date: 4 September 2026