Within the meaning of the General DataProtection Regulation (GDPR), the controller is:
Saddle Me Franchise GmbH
Vesbecker Weg 4
29690 Lindwedel (OT Hope)
Telefon: 0511 - 77 95 30 86
E-Mail: info@saddleme.com
We take the protection of your personal data very seriously. Below, we provide information about what data we collect, how we use it and what rights you have with regard to your data.
1. Scope
This privacy policy applies to the use of our website saddleme.com and our online shop at shop.saddleme.com. The onlineshop is currently primarily aimed at customers in Germany; an expansion to further countries (e.g. EU/CH/UK) is planned. We will update this privacy policy if changes occur (e.g. new countries/tools).
2. Purposes and legal bases
We process personal data for the following purposes in particular:
- Provision of the website/online shop (security, stability, error analysis)
- Initiation and processing of orders, delivery and returns
- Payment processing via Shopify Payments
- Customer account and customer service/communication
- Merchandise management, invoicing and shipping preparation via our ERP/merchandise management system (Vario)
- Billing and evaluation of franchise discount codes (without passing on customer data to franchisees; only aggregated evaluations)
Web analysis and marketing (only with consent), e.g. Google Tag Manager, Google Analytics 4, Google Ads, Meta Pixel.
Depending on the processing operation, the legal bases are, in particular:
- Art. 6(1)(b) GDPR (performance of a contract/pre-contractual measures)
- Art. 6(1)(c) GDPR (legal obligations, e.g. commercial and tax law retention)
- Art. 6(1)(f) GDPR (legitimate interests, e.g. IT security, prevention of misuse and fraud, enforcement of claims)
- Art. 6(1)(a) GDPR (consent, e.g. for non-essential cookies/tracking/marketing)
3. Categories of processed data
Depending on usage, we process in particular:
- Master data (e.g. name, address)
- Contact details (e.g. email, telephone number)
- Order and contract details (e.g. items ordered, prices, delivery/billing address, order history)
- Payment and transaction data (to the extent necessary for payment processing)
- Usage and log data (e.g. IP address, device/browser information, log files)
- Communication data (e.g. content of enquiries via email/contact form)
- Consent data (e.g. status and time of your cookie/tracking consents)
4. Visit to the website/online shop (server logs)
Every time you visit our website or online shop, we process technically necessary data in order to deliver the content and ensure security (e.g. IP address, date/time, page accessed, referrer URL, browser/device information, log files). The legal basis for this is Art. 6(1)(f) GDPR.
Hosting/website platform
The saddleme.com website is provided via the Webflow website platform. Webflow processes the technical data required for the operation and delivery of the website (in particular server log data). The legal basis is Art. 6 (1) lit. f GDPR (security, stability, error analysis).
We use the SSL (Secure Socket Layer) procedure during your visit to the website to transmit your data securely.
5. Embedded content (YouTube)
Videos from the YouTube platform may be embedded on our website. This content will only be loaded and displayed once you have given your consent via the cookie banner in the "Functional" category. If you reject cookies/optional technologies, the YouTube videos will not be loaded; this means that no technical data (e.g. IP address, device/browser information) will be transmitted to YouTube/Google in connection with the embedded videos. If you consent and load a video, technical data may be transmitted to YouTube/Google. The legal basis is Art. 6(1)(a) GDPR (consent). Data transfers to third countries (e.g. the USA) cannot be ruled out.
6. Cookies, cookie banners and consent
We use cookies and similar technologies. Technically necessary cookies are required for the operation of the shop and our website. We only use optional cookies/technologies (e.g. for web analysis and marketing) if you have given your prior consent via our cookie banner. You can change or revoke your consent at any time for the future via the cookie settings.
Please note: If you do not accept tracking/marketing, the corresponding tags/pixels will not be loaded.
Consent management
We use the Usercentrics consent management platform for our website saddleme.com and our online shop shop.saddleme.com to obtain, manage and document consent for optional cookies/technologies (e.g. analysis/marketing). In particular, consent status, time of consent/change/revocation and technical information (e.g. browser/device information) are processed. The legal basis is Art. 6 (1) (c) GDPR (proof/fulfilment of legal requirements) and Art. 6 (1) (f) GDPR (legitimate interest in legally compliant consent management). You can change or revoke your selection at any time via the cookie settings.
7. customer account
When you create a customer account, we process the data you provide for account management purposes (e.g. login, order overview, address management). The legal basis for this is Art. 6(1)(b) GDPR.
8. Orders and checkout
When you place an order, we process your data for the purpose of contract fulfilment (e.g. name, delivery and billing address, email address, items ordered, communication regarding the order). The legal basis for this is Art. 6(1)(b) GDPR.
9. Payment via Shopify Payments
Payment processing is carried out via Shopify Payments. Payment and transaction data is transmitted to the payment service providers involved in the payment to the extent necessary to execute the payment. The legal basis is Art. 6 (1) (b) GDPR; where legal obligations exist, Art. 6 (1) (c) GDPR.
Shopify Payments and/or participating payment service providers may carry out automated checks to prevent misuse and fraud. The legal basis for this is Art. 6 (1) lit. f GDPR (legitimate interest in preventing fraud/misuse).
10. Shipping service providers and shipping processing
For delivery purposes, we transmit the necessary data (e.g. name, delivery address, email/telephone number for notification if applicable, shipment data) to shipping service providers (currently usually DHL; in exceptional cases, other transport service providers). The legal basis for this is Art. 6(1)(b) GDPR.
11. Merchandise management/ERP
We use an inventory management/ERP system (“Vario”) for stock management, invoicing, shipping preparation and the internal processing of orders. For this purpose, order data is transferred from Shopify to Vario. The legal basis is Art. 6(1)(b) GDPR; where statutory retention obligations apply, Art. 6(1)(c) GDPR.
If the Vario provider processes personal data on our behalf, we conclude a data processing agreement pursuant to Art. 28 GDPR.
12. Customer service and contact
When you contact us (e.g. by email, contact form, WhatsApp, telephone), we process your details in order to handle your enquiry. The legal basis is Art. 6 (1) (b) GDPR (pre-contractual/contractual) or Art. 6 (1) (f) GDPR (legitimate interest in processing general enquiries). When using the contact form on saddleme.com, the technical provision/transmission of the form enquiry is carried out via Webflow.
12a. Appointment requests via the contact form
If you submit an appointment request (e.g. consultation/saddle fitting appointment) via the main domain (saddleme.com), we will process the data you provide in the form in order to process your request and assign a suitable contact person.
Additional backup/further processing (Zapier/Google Sheets): For internal organisation and tracking purposes, we also automatically back up appointment requests in a spreadsheet (Google Sheets) via Zapier. The contact details and content of the request submitted in the form are processed in this process. The legal basis is Art. 6(1)(b) GDPR (processing of the request) and Art. 6(1)(f) GDPR (efficient, traceable processing).
Forwarding/recipient: Your appointment request will first be received and processed by Saddle Me Franchise GmbH (head office). Your form request will not be forwarded directly to franchisees via the form.
Je nach gewünschter Region bzw. anhand der von Ihnen angegebenen PLZ kann es zur Terminvermittlung erforderlich sein, Ihre Kontaktdaten und Angaben aus derTerminanfrage an einen geeigneten Franchisepartner weiterzugeben.
Note on responsibility: If a franchise partner handles the appointment, they will process the necessary data as an independent controller within the meaning of the GDPR. You will be provided with the name of the responsible contact person as part of the appointment coordination process.
Legal basis: The processing and transfer of your data for the purpose of arranging and coordinating appointments is carried out in accordance with Art. 6 (1) (b) GDPR (pre-contractual measures/contract fulfilment). If you do not provide the necessary information or do not wish it to be passed on to the responsible franchise partner, we will unfortunately not be able to process your appointment request. Withdrawal of consent: You can withdraw your consent, for example, by sending an email to widerruf@saddleme.com (subject line: "Withdrawal of appointment request"). The lawfulness of the processing carried out until the withdrawal remains unaffected. Storage period: We only store data from appointment requests for as long as is necessary to process the request and then delete it, provided that there are no legal retention obligations to the contrary.
13. Franchise discount codes and commission settlement
If you use a discount code when placing an order, we evaluate orders for the purpose of calculating the respective franchisee's share. We only send franchisees aggregated evaluations (e.g. turnover/number of orders per code/period). We do not pass on any customer data or order details for individual orders to franchisees.
14. Web analytics and marketing (Google Tag Manager, Google Analytics 4, Google Ads, Meta Pixel)
If you have given your consent, we use technologies to analyse and market our website and online shop. These may include Google Tag Manager (for integrating additional tags), Google Analytics 4 (web analysis), Google Ads (conversion tracking/remarketing) and Meta Pixel (conversion tracking/remarketing). Which tools are active depends on your consent and our respective configuration. We also use Google Consent Mode (v2). Depending on your selection in the cookie banner, Google tags are loaded in a restricted mode or signals are processed; which functions are active depends on your consent and our configuration.
The legal basis is Art. 6(1)(a) GDPR (consent). You can withdraw your consent at any time via the cookie settings.
The use of these services may result in data being transferred to third countries (e.g. the USA). In such cases, we base the transfer on appropriate safeguards (e.g. EU standard contractual clauses) and take additional protective measures where necessary.
15. Recipients/Categories of recipients
We use service providers to deliver our services. Recipients may include, in particular:
- Shopify (platform/hosting/shop operation). We do not currently use any additional Shopify apps. If we introduce further apps/tools, we will update this privacy policy accordingly.
- Payment service providers within the scope of Shopify Payments
- Shipping service providers (e.g. DHL)
- inventory management/ERP system (“Vario”)
- IT and hosting service providers (in particular Webflow for saddleme.com), consent management (Usercentrics), automation/integration service providers (Zapier), cloud/office service providers (e.g. Google Sheets/Google Workspace for internal processing of enquiries; Microsoft 365 for email communication), support and communication service providers
- Tax advisors, authorities/public bodies, where required by law
16. Shopify as a platform provider (hosting and order processing)
Our online shop is operated via the Shopify platform. Shopify processes data that is necessary for the operation of the shop and the processing of orders. In many cases, Shopify processes customer data as a processor. Shopify may use subcontractors (sub-processors).
Note: The Shopify feature "Shopify Network Intelligence/Enhanced Services" is currently disabled. Should we activate this feature in the future, we will amend this privacy policy accordingly.
17. transfers to third countries
Processing may also take place outside the European Economic Area (EEA), in particular when using international service providers (e.g. Shopify or analysis/marketing services). Insofar as no adequacy decision has been made by the EU Commission, we use appropriate safeguards (e.g. EU standard contractual clauses).
18. storage period
We only store personal data for as long as is necessary for the respective purposes. In addition, we store data insofar as we are subject to statutory retention and documentation obligations (e.g. in accordance with the German Commercial Code (HGB) and Fiscal Code (AO), usually 2 to 10 years). In individual cases, longer storage periods may apply (e.g. limitation periods).
19. Your rights
Depending on the circumstances, you have the following rights:
- Information (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Deletion (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
- Withdrawal of consent with effect for the future (Art. 7 GDPR)
- Complaint to a data protection supervisory authority (Art. 77 GDPR)
20. Automated decision-making
We do not make any exclusively automated decisions within the meaning of Article 22 GDPR that have legal effect on you or significantly affect you in a similar way. This does not affect automated risk and fraud checks in payment transactions.
21. Changes to this privacy policy
We may amend this privacy policy if legal requirements or our processing procedures change. The current version is available on our website and in our online shop.
Version: Januar 2026
When you access our website, information is automatically sent to the server of our website.
This information is temporarily stored in so-called log files.
The following information may be collected without your intervention:
The legal basis for data processing is Art. 6(1)(f) GDPR. Our legitimate interest arises from the purposes listed above.
If you contact us via the contact form, WhatsApp, e-mail, or telephone, we process the data you provide (e.g., name, e-mail address, telephone number, content of inquiry) to handle your request.
The legal basis for this processing is Art. 6(1)(b) GDPR, if the contact is made for the initiation of a contract.
Art. 6(1)(f) GDPR applies if our legitimate interest in processing your request outweighs other considerations.
We use SSL encryption (Secure Socket Layer) during your visit to our website to ensure your data is transmitted securely.
This privacy policy is currently valid and has the status of December 2024.Updates may be required at any time, for example, due to changes in legal requirements or our services.
Get advice from our experts and find the perfect saddle for you and your horse.