Server-Side Tracking / Server-Side Tagging (stape.io)
We useserver-side tracking (server-sidetagging) on our website. For this purpose, we utilize the infrastructure of Stape Europe OÜ, Narva mnt 5, 10117 Tallinn, Estonia (“stape.io”), which acts as our data processor.
1. Nature and Scope of Processing
Unlike conventional client-side tracking, tracking scripts and data are not transmitted directly from your browser to third-party providers (e.g., analytics or marketing services). Instead, the data is first sent to a server controlled by us via the stape.io infrastructure. There, the data undergoes pre-processing (e.g., anonymization of the IP address or removal of personal identifiers) before being forwarded to connected third-party providers.
The processed data may include, in particular, information regarding the use of our website, IP addresses, and other identifiers collected during your interactions with our website.
This process gives us improved control over data processing and allows us, in particular, to specifically manage and reduce the transfer of personal data to third parties and to third countries in a manner compliant with data protection regulations.
2. Purpose of Processing
Processing is carried out for the following purposes:
- Analysis of user behavior
- Marketing and campaign optimization
- Technical optimization and improvement of our website
- Increasing data security and making our tracking processes more privacy-friendly
3. Legal basis
Processing is based on your consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TDDDG. Consent is obtained via our consent management system (cookie banner) and may be revoked at any time.
4. Data Processing on Behalf of Others and Data Transfer
Stape Europe OÜ processes the data exclusively on our behalf based on a data processing agreement pursuant to Art. 28 GDPR.
If data is transferred to third countries outside the European Economic Area (EEA) in the course of processing, this is done exclusively in compliance with legal requirements. This includes, in particular, the conclusion of Standard Contractual Clauses (SCCs) as well as appropriate additional safeguards.
5. Storage Location and Duration
Data processing generally takes place on servers within the European Union (e.g., Estonia or Google Cloud regions in Europe).
The data processed as part of server-side tracking is stored only for as long as necessary for the respective processing purposes.
Deletion or anonymization occurs as soon as the purpose of processing no longer applies, in particular when the data is no longer needed for analysis or marketing purposes or you have withdrawn your consent.
Regardless of this, personal data is generally stored for a maximum period of 12 months. Data will only be stored beyond this period if there are legal retention obligations or if this is necessary to assert, exercise, or defend legal claims.
Google Tag Manager
We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Tag Manager is a tool that allows us to integrate tracking or statistics tools and other technologies into our website. Google Tag Manager itself does not create user profiles, store cookies, or perform independent analyses. It serves solely to manage and deploy the tools integrated through it. However, Google Tag Manager records your IP address, which may also be transferred to Google’s parent company in the United States.
The use of Google Tag Manager is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the quick and straightforward integration and management of various tools on its website. If consent has been obtained, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and § 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user’s device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent may be revoked at any time.
The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF commits to complying with these data protection standards. Further information on this is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
Google Analytics
This website uses features of the web analytics service Google Analytics. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics enables the website operator to analyze the behavior of website visitors. In doing so, the website operator receives various usage data, such as page views, time spent on the site, operating systems used, and the user’s origin. This data is aggregated into a user ID and assigned to the website visitor’s respective device.
Furthermore, we can use Google Analytics to track your mouse and scroll movements and clicks, among other things. Google Analytics also uses various modeling approaches to supplement the collected data sets and employs machine learning technologies in data analysis.
Google Analytics uses technologies that enable user recognition for the purpose of analyzing user behavior (e.g., cookies or device fingerprinting). The information collected by Google regarding the use of this website is generally transmitted to a Google server in the United States and stored there.
The use of this service is based on your consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TDDDG. Consent may be revoked at any time.
Data transfer to the United States is based on the EU Commission’s Standard Contractual Clauses. Details can be found here: https://business.safety.google/adscontrollerterms/sccs/.
The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF commits to adhering to these data protection standards. For more information, please visit the provider’s website at the following link: https://www.dataprivacyframework.gov/participant/5780.
IP Anonymization
Google Analytics IP anonymization is enabled. This means that your IP address is truncated by Google within member states of the European Union or in other signatory states to the Agreement on the European Economic Area before being transmitted to the United States. Only in exceptional cases is the full IP address transmitted to a Google server in the United States and truncated there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity, and to provide other services related to website and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.
Browser Plugin You can prevent the collection and processing of your data by Google by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=en.
For more information on how Google Analytics handles user data, please refer to Google’s Privacy Policy: https://support.google.com/analytics/answer/6004245.
Google Signals
We use Google Signals. When you visit our website, Google Analytics collects, among other things, your location, search history, and YouTube history, as well as demographic data (visitor data). This data can be used for personalized advertising with the help of Google Signals. If you have a Google account, the visitor data from Google Signals is linked to your Google account and used for personalized advertising. The data is also used to create anonymized statistics on our users’ behavior.
Data Processing
We have entered into a data processing agreement with Google and fully comply with the strict requirements of German data protection authorities when using Google Analytics.
Matomo
This website of the online kitchen planner uses the open-source web analytics service Matomo. The provider is InnoCraft Ltd., 150 Willis St, 6011 Wellington, New Zealand.
With the help of Matomo, we are able to collect and analyze data regarding how website visitors use our site. This allows us, among other things, to determine when specific pages were viewed and from which region the visitors are coming. In addition, we collect various log files (e.g., IP address, referrer, browsers and operating systems used) and can measure whether our website visitors perform certain actions (e.g., clicks, purchases, etc.).
The use of this analytics tool is based on Article 6(1)(f) of the GDPR. The website operator has a legitimate interest in analyzing user behavior in order to optimize both its website and its advertising. If consent has been obtained, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and § 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user’s device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent may be revoked at any time.
Hosting
External
Google Ads
The website operator uses Google Ads. Google Ads is an online advertising program provided by Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Ads enables us to display advertisements in the Google search engine or on third-party websites when the user enters specific search terms into Google (keyword targeting). Furthermore, targeted advertisements can be displayed based on user data available to Google (e.g., location data and interests) (audience targeting). As the website operator, we can evaluate this data quantitatively, for example by analyzing which search terms led to the display of our advertisements and how many ads resulted in corresponding clicks.
The use of this service is based on your consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TDDDG. Consent may be revoked at any time.
Data transfer to the U.S. is based on the EU Commission’s Standard Contractual Clauses. Details can be found here: https://policies.google.com/privacy/frameworks and https://business.safety.google/controllerterms/.
The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF commits to adhering to these data protection standards. For more information, please visit the provider’s website at the following link: https://www.dataprivacyframework.gov/participant/5780.
Google Ads Remarketing
This website uses the features of Google Ads Remarketing. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
With Google Ads Remarketing, we can assign people who interact with our online offering to specific target groups in order to subsequently display interest-based advertising to them on the Google advertising network (remarketing or retargeting).
Furthermore, the advertising target groups created with Google Ads Remarketing can be linked to Google’s cross-device features. In this way, interest-based, personalized advertising messages that have been tailored to you based on your previous usage and browsing behavior on one device (e.g., a mobile phone) can also be displayed on another of your devices (e.g., a tablet or PC).
If you have a Google account, you can opt out of personalized advertising at the following link: https://adssettings.google.com/anonymous.
The use of this service is based on your consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TDDDG. You may revoke your consent at any time.
Further information and the privacy policy can be found in Google’s privacy policy at: https://policies.google.com/technologies/ads.
The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF commits to adhering to these data protection standards. Further information on this is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
Google Conversion Tracking
This website uses Google Conversion Tracking. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
With the help of Google Conversion Tracking, Google and we can determine whether the user has performed certain actions. For example, we can evaluate which buttons on our website are clicked and how often, and which products were viewed or purchased particularly frequently. This information is used to generate conversion statistics. We learn the total number of users who clicked on our ads and what actions they performed. We do not receive any information that allows us to personally identify the user. Google itself uses cookies or similar recognition technologies for identification.
The use of this service is based on your consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TDDDG. Consent may be revoked at any time.
For more information on Google Conversion Tracking, please refer to Google’s Privacy Policy: https://policies.google.com/privacy.
The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF commits to adhering to these data protection standards. For more information, please visit the provider’s website at the following link: https://www.dataprivacyframework.gov/participant/5780.
Meta Custom Audiences
We use Meta Custom Audiences. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland.
When you visit or use our websites and apps, take advantage of our free or paid offers, transmit data to us, or interact with our company’s Facebook or Instagram content, we collect your personal data in the process. If you grant us consent to use Meta Custom Audiences, we will transmit this data to Meta, which Meta can then use to display relevant advertisements to you. Furthermore, your data can be used to define target groups (Lookalike Audiences).
Meta processes this data as our data processor. Details can be found in Meta’s Terms of Use: https://www.facebook.com/legal/terms/customaudience.
The use of this service is based on your consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TDDDG. You may revoke your consent at any time.
Data transfers to the U.S. are based on the EU Commission’s Standard Contractual Clauses. Details can be found here: https://www.facebook.com/legal/terms/customaudience and https://www.facebook.com/legal/terms/dataprocessing.
The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF commits to adhering to these data protection standards. For more information, please visit the provider’s website at the following link: https://www.dataprivacyframework.gov/participant/4452.
TikTok Pixel
We have integrated the TikTok Pixel into this website. The provider is TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland (hereinafter “TikTok”).
With the help of the TikTok Pixel, we can display interest-based advertising on TikTok (TikTok Ads) to website visitors who have viewed our offers. At the same time, we can use the TikTok Pixel to determine how effective our advertising on TikTok is. This allows the effectiveness of TikTok ads to be evaluated for statistical and market research purposes and optimized for future advertising campaigns. In this process, various usage data are processed, such as IP address, page views, duration of visit, operating systems used, and the user’s origin, as well as information about the ad a person clicked on TikTok or an event that was triggered (timestamp). This data is aggregated into a user ID and assigned to the website visitor’s respective device.
Use of this service is based on your consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TDDDG. Consent may be revoked at any time.
Data transfers to third countries are based on the EU Commission’s Standard Contractual Clauses. Details can be found here: https://www.tiktok.com/legal/page/eea/privacy-policy/en and https://ads.tiktok.com/i18n/official/policy/controller-to-controller.
Data Processing Agreement
We have entered into a Data Processing Agreement (DPA) for the use of the aforementioned service. This is a contract required by data protection law that ensures the service provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
LinkedIn Insight Tag
This website uses the LinkedIn Insight Tag. The provider of this service is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland.
Data Processing via LinkedIn Insight Tag
With the help of the LinkedIn Insight Tag, we receive information about visitors to our website. If a website visitor is registered with LinkedIn, we can analyze, among other things, the key professional data (e.g., career level, company size, country, location, industry, and job title) of our website visitors and thus better tailor our site to the respective target groups. Furthermore, with the help of LinkedIn Insight Tags, we can measure whether visitors to our websites make a purchase or take another action (conversion tracking). Conversion tracking can also be performed across devices (e.g., from PC to tablet). LinkedIn Insight Tag also offers a retargeting feature that allows us to display targeted ads to our website visitors outside the website; however, according to LinkedIn, the recipient of the ad is not identified.
LinkedIn itself also collects so-called log files (URL, referrer URL, IP address, device and browser properties, and time of access). IP addresses are truncated or (if used to reach LinkedIn members across devices) hashed (pseudonymized). The direct identifiers of LinkedIn members are deleted by LinkedIn after seven days. The remaining pseudonymized data is then deleted within 180 days.
As the website operator, we cannot associate the data collected by LinkedIn with specific individuals. LinkedIn will store the collected personal data of website visitors on its servers in the U.S. and use it for its own advertising purposes. For details, please refer to LinkedIn’s Privacy Policy at https://www.linkedin.com/legal/privacy-policy#choices-oblig.
Legal Basis
Where consent has been obtained, the use of the aforementioned service is based exclusively on Article 6(1)(a) of the GDPR and Section 25 of the TDDDG. Consent may be revoked at any time. Where consent has not been obtained, the use of this service is based on Article 6(1)(f) of the GDPR; the website operator has a legitimate interest in effective advertising measures, including social media.
Data transfers to the U.S. are based on the EU Commission’s Standard Contractual Clauses. Details can be found here: https://www.linkedin.com/legal/l/dpa and https://www.linkedin.com/legal/l/eu-sccs.
The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF commits to adhering to these data protection standards. For more information, please visit the provider’s website at the following link: https://www.dataprivacyframework.gov/participant/5448.
Object to the use of the LinkedIn Insight Tag
Object to the analysis of usage behavior and targeted advertising by LinkedIn via the following link: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
Furthermore, LinkedIn members can control the use of their personal data for advertising purposes in their account settings. To prevent LinkedIn from linking data collected on our website to your LinkedIn account, you must log out of your LinkedIn account before visiting our website.
Pinterest Tag
We have integrated the Pinterest Tag on this website. The provider is Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland.
The Pinterest Tag is used to track certain actions you perform on our website. The data can then be used to display interest-based ads to you on our website or on another site within the Pinterest Tag advertising network.
For this purpose, the Pinterest tag collects, among other things, a tag ID, your location, and the referrer URL. Additionally, action-specific data such as order value, order quantity, order number, category of purchased items, and video views may be collected.
Pinterest Tag uses technologies that enable cross-site recognition of the user to analyze user behavior (e.g., cookies or device fingerprinting).
To the extent that consent has been obtained, the use of the aforementioned service is based exclusively on Article 6(1)(a) of the GDPR and Section 25 of the TDDDG. Consent may be revoked at any time. If consent has not been obtained, the use of this service is based on Article 6(1)(f) of the GDPR; the website operator has a legitimate interest in marketing measures that are as effective as possible.
Pinterest is a global company, so data may also be transferred to the United States. According to Pinterest, this data transfer is based on the EU Commission’s Standard Contractual Clauses. Details can be found here: https://policy.pinterest.com/de/privacy-policy.
Further information on the Pinterest tag can be found here: https://help.pinterest.com/de/business/article/track-conversions-with-pinterest-tag.
The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF commits to adhering to these data protection standards. For more information, please visit the provider’s website at the following link: https://www.dataprivacyframework.gov/participant/4203.
Data Processing Agreement We have entered into a Data Processing Agreement (DPA) for the use of the aforementioned service. This is a contract required by data protection law that ensures the service provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.