Privacy policy
Last updated: 25 September 2026
1. Controller
The controller responsible for processing personal data in this online shop is:
Marc Teipel – Vincent van Dog
Germanenstr. 19C
13156 Berlin
Germany
Email: mteipel@outlook.com
Unless stated otherwise below, the controller determines the purposes and means of processing personal data.
2. Visiting the online shop
When you visit our online shop, technically necessary data is processed. This may include your IP address, date and time of access, page visited, referrer URL, browser, operating system, device information and technical log data.
This processing serves to provide the shop securely and reliably, prevent misuse and analyze technical errors. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of the online shop.
3. Shopify
Our online shop is operated through Shopify. The provider for merchants in the European Economic Area is generally:
Shopify International Limited
Victoria Buildings, 2nd Floor
1–2 Haddington Road
Dublin 4, D04 XN32
Ireland
Shopify processes data required to operate the shop, cart, checkout, orders, payments, fraud prevention and technical security. This may include contact details, delivery and billing addresses, order data, payment status, device and usage data, and IP addresses.
When you choose a portrait to buy, we send only the watermarked preview to Shopify. Shopify stores it as an unlisted product image so that you can see your artwork in the cart and checkout. The image is only reachable through an unguessable link, does not appear in search, collections or the sitemap, and is deleted together with the other generated files within the periods described in section 6. The production file remains on Microsoft Azure.
Processing for pre-contractual steps and contract performance is based on Article 6(1)(b) GDPR. Processing required by law is based on Article 6(1)(c) GDPR. Security and misuse prevention are based on Article 6(1)(f) GDPR.
Shopify may process data through affiliated companies and subprocessors outside the European Economic Area. Where no adequacy decision exists, appropriate safeguards, particularly standard contractual clauses, are used. Further information:
For certain enhanced Shopify functions, Shopify may also process personal data under its own responsibility, for example to provide, protect or improve services across merchants. Shopify’s privacy information applies to that processing. Rights relating to such independent processing can also be exercised directly through Shopify’s privacy portal.
4. Creating a dog portrait
4.1 Data processed
When you use the portrait configurator, we process in particular:
- the dog photo you upload;
- the previews and production files created from it;
- optional portrait revision requests;
- technical status, session and version identifiers;
- your selection and approval of an image;
- the association of the approved image with a paid Shopify order;
- the time of your required confirmation for image processing; and
- pseudonymized identifiers used to limit misuse and automated repeat requests.
For misuse prevention, a cryptographic pseudonymized identifier is formed from a random browser identifier and a network signal. The application stores neither the raw IP address nor the raw browser identifier in its session data. Infrastructure providers may temporarily process IP addresses in technically necessary security and access logs.
4.2 Purposes and legal bases
Processing is carried out to:
- technically assess the uploaded photo;
- reject unsuitable uploads, particularly photos without a clearly identifiable dog or with identifiable people;
- generate up to three portrait versions;
- enable previewing, selection and revision requests;
- create a production-ready file after your approval;
- securely associate the production file with an order; and
- prevent misuse, automated overload and circumvention of usage limits.
Where processing is required to create and order the personalized product, the legal basis is Article 6(1)(b) GDPR. Security and misuse prevention are based on Article 6(1)(f) GDPR. Where we expressly request consent for additional processing, the legal basis is Article 6(1)(a) GDPR. Consent can be withdrawn at any time with effect for the future; processing carried out before withdrawal remains lawful.
Please upload only photos that you are entitled to use. Photos showing identifiable people are not intended for the service and are automatically rejected where possible.
4.3 Automated image screening and generation
The photo is automatically screened for technical suitability and for identifiable dogs and people. Revision requests are automatically screened for prohibited content. The portrait is then created using a generative AI model.
This processing is used solely to provide and safeguard the requested service. It does not produce a solely automated decision with legal or similarly significant effects within the meaning of Article 22 GDPR. If an eligible photo is rejected by mistake, contact us at the email address above.
5. Microsoft Azure and AI services
The upload, storage, screening and generation functions are operated on Microsoft Azure. The contracting entity for European customers is generally:
Microsoft Ireland Operations Limited
One Microsoft Place
South County Business Park
Leopardstown
Dublin 18, D18 P521
Ireland
The application uses Azure Functions, Azure Storage, Azure AI Services and Microsoft Foundry in particular. The primary application and storage resources are operated in Sweden (Sweden Central). Certain globally offered AI functions and technical support, security and telemetry data may also be processed outside the European Economic Area under the applicable Microsoft product terms and privacy safeguards. Where required, Microsoft bases such transfers on adequacy decisions or appropriate safeguards such as standard contractual clauses.
Further information:
We do not use uploaded images or generated portraits for our own advertising or to train our own AI models.
6. Retention of photos and portraits
The following deletion periods currently apply to the portrait service:
- Without a purchase: The uploaded source photo is generally deleted within seven days. Generated portraits and previews are generally deleted within 30 days.
- After purchase and fulfillment: The source photo is generally deleted within 30 days after fulfillment. The selected production file is generally deleted within 180 days after fulfillment, in particular so that valid complaints or a required replacement can be handled.
- Cancellation or refund: The source photo and generated files return to the shorter deletion periods of generally seven and 30 days respectively.
- Deletion request: Unless statutory retention obligations or overriding legitimate grounds prevent this, we delete the affected files earlier.
Backups and technical logs may continue to exist for a limited period until they are overwritten or deleted in the ordinary cycle.
7. Orders, payments and shipping
When an order is placed, we process the data required for the contract, particularly name, contact details, delivery and billing addresses, order items, payment status and shipping information. The legal basis is Article 6(1)(b) GDPR.
Depending on the payment method selected in checkout, payment data is processed by Shopify and the payment provider identified there. We generally do not receive full card or payment-account details, but primarily payment status and transaction references. For shipping, we provide the required data to the carrier named in checkout or the dispatch confirmation.
We retain order and invoice data relevant under tax and commercial law for the applicable statutory retention periods. The data is deleted when those periods expire unless another legal basis applies.
8. Contacting us
If you contact us, we process your contact details and the content of your message to respond to your request. For contract-related inquiries, the legal basis is Article 6(1)(b) GDPR. Otherwise, processing is based on Article 6(1)(f) GDPR; our legitimate interest is handling inquiries. Retention required by law is based on Article 6(1)(c) GDPR.
9. Cookies and similar technologies
The shop uses technically necessary cookies and similar technologies required for the cart, checkout, security, language settings and basic shop functions. Their use is based on Section 25(2) TDDDG; subsequent data processing is based on Article 6(1)(b) or (f) GDPR depending on the purpose.
Non-essential analytics, personalization or marketing technologies are used only with your consent. The legal bases are Section 25(1) TDDDG and Article 6(1)(a) GDPR. You can change or withdraw consent at any time with effect for the future through the shop’s privacy settings.
If additional analytics or marketing services are enabled in the future, this privacy policy will be updated before they are used.
10. Third-party websites and links
Our shop may contain links to third-party websites or services. Their operators are responsible for their privacy and security practices. Please review their privacy information before submitting personal data. A link does not mean that we adopt all content of the external service as our own.
11. Children’s data
Our service is not specifically directed at children. We do not knowingly collect personal data from children who cannot validly consent to the relevant processing or conclude the contract under applicable law. If you are a parent or guardian and believe that a child has submitted personal data to us, contact us so that we can investigate and, where appropriate, delete the data.
12. Recipients
Depending on how you use the service, data may be disclosed in particular to the following categories of recipients:
- Shopify and its subprocessors for the shop, cart, checkout, orders and security;
- Microsoft and its subprocessors for hosting, storage, image screening, AI image generation and telemetry;
- the payment provider selected in checkout;
- the carrier commissioned for delivery; and
- tax advisers, authorities or other bodies where required by law or for the establishment, exercise or defense of legal claims.
Data is disclosed only where required for the relevant purpose or another legal basis applies.
13. Your rights
Subject to the statutory requirements, you have the following rights in particular:
- access to your personal data (Article 15 GDPR);
- rectification of inaccurate data (Article 16 GDPR);
- erasure (Article 17 GDPR);
- restriction of processing (Article 18 GDPR);
- data portability (Article 20 GDPR);
- objection to processing based on Article 6(1)(e) or (f) GDPR (Article 21 GDPR);
- withdrawal of consent with effect for the future (Article 7(3) GDPR); and
- the right to lodge a complaint with a data protection supervisory authority (Article 77 GDPR).
To exercise your rights, send a message to mteipel@outlook.com. We may request additional information where necessary to verify your identity securely.
You may complain in particular to the supervisory authority responsible for our place of business or to the authority at your habitual residence.
14. Right to object
Where we process personal data on the basis of legitimate interests under Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will then no longer process the data unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is required for the establishment, exercise or defense of legal claims.
If you object to direct marketing, we will stop it without balancing interests. Personalized direct marketing is not currently planned.
15. Data security
We take appropriate technical and organizational measures to protect personal data. These include encrypted transmission, private cloud storage, short-lived upload and preview permissions, separate watermarked previews, access controls, signed Shopify requests, pseudonymized misuse-prevention identifiers and limited retention periods.
16. Changes to this privacy policy
We update this privacy policy when functions, providers, legal bases or statutory requirements change. The version published in the online shop at the relevant time applies.