Skip to main content

Privacy Policy

Last updated: 23.07.2026

HIIICH GmbH - Status: 10 July 2026

Protecting your data is important to us. We process personal data under the GDPR, the Austrian Data Protection Act, the Austrian Telecommunications Act and other applicable laws.

The German version is legally authoritative. This English version is provided for information only.

1. Controller

The controller is HIIICH GmbH, Kärntner Straße 47/Top 2+3, 1010 Vienna, Austria, email: office@hiiich.at, phone: +43 1 4090354.

Privacy requests should be sent to office@hiiich.at. No formal data protection officer has currently been appointed.

2. Scope

This Privacy Policy applies to the website, mobile app, online shop, coffeehouse pickup, shop pickup, delivery/shipping of physical products, customer accounts, contact and support requests, product reviews, newsletters/marketing communications, push notifications, transactional emails, admin/operator functions and other HIIICH digital services.

3. Principles and legal bases

We process personal data only where required to provide our services, handle orders, communicate with customers, comply with legal obligations, secure our systems, pursue legitimate interests or act on consent.

Legal bases include Article 6(1)(b) GDPR for contract performance, Article 6(1)(c) GDPR for legal obligations, Article 6(1)(f) GDPR for legitimate interests and Article 6(1)(a) GDPR for consent. Consent may be withdrawn at any time with future effect.

4. Technical operation of website, app and API

When you use the website, app or API functions, technical data may be processed, such as IP address, date and time of access, pages or functions accessed, browser and device information, operating system, language, referrer, logs, technical IDs, request/response metadata and technical error data.

IP addresses may be processed for operation, security, session checks, rate limiting, abuse detection, captcha checks, audit, error analysis and legal traceability. Hosting and operation are provided in particular via Hetzner in Germany/EU and HIIICH deployment, database, cache and operations infrastructure.

5. Customer accounts and authentication

When a customer account is created or used, we process data such as name, email address, phone number where collected, password hash, Google identifier for Google Login, account status, saved addresses, order history, account activity, sessions, IP address, user agent and security metadata.

Login or registration may use email/OTP, password or Google OAuth. Session tokens are stored server-side only as hashes. On the website, the token is transported as an HTTP-only cookie; in the mobile app, it is stored using secure platform storage mechanisms.

6. Orders, checkout and contract performance

For orders, we process checkout data including name, email address, phone number, delivery and billing address, cart, products, quantities, prices, taxes, discounts, discount codes, tips, payment status, order status, fulfilment group, pickup or delivery information, legal acceptances, order history, internal references and hashed technical access tokens.

We store versions and checksums of accepted legal texts to document which terms, privacy and withdrawal information were accepted at the time of order.

7. Payments via Stripe

Payments are processed via Stripe. The website uses Stripe Hosted Checkout; the mobile app may use Stripe PaymentSheet or PaymentIntent.

Stripe receives order line information, amount, currency, customer email where available, success/cancel URLs, payment references and metadata. HIIICH receives payment status, transaction references, Stripe IDs, amounts, currency, shortened payment-method information and receipt information. HIIICH does not store full card data or card verification codes.

8. OrderKing/Kassa and internal order processing

Order data may be transmitted to OrderKing or the connected POS/cash register for order processing, POS reconciliation, tax/cash register logic and operations.

9. Contact, support and transactional emails

If you contact us or use a form, we process data such as name, email address, phone number where provided, message, order number, language, communication history and internal handling notes.

SendGrid or a comparable email provider may be used for transactional emails such as OTP codes, password reset, order confirmations, payment continuation notices, shipping/order updates and operator replies.

10. Newsletters, marketing emails and push notifications

HIIICH may use newsletters, marketing emails and push notifications where the relevant function is technically available and required consent or another lawful basis exists.

For newsletters and marketing emails, we process email address, consent record, delivery status, language, unsubscribe status, signup time and technical evidence. Marketing emails include an unsubscribe option where required by law.

For app push notifications, we may process push tokens, device information, language, notification settings, delivery status and technical error data. Push notifications may be provided via Expo/EAS and platform services from Apple and Google.

11. Product reviews

For product reviews, we process rating, comment, product reference, order/user reference where available, time, IP/security data, moderation status and displayed name or initials where applicable. Reviews are published only after moderation.

12. Admin dashboard and audit logs

In the admin dashboard, we process data of operators, employees or service providers with access to HIIICH systems, including name, email address, password hash, roles, permissions, login times, IP address, user agent, admin sessions and account status.

Admin actions may be stored in audit logs.

13. Media, uploads, signage and object storage

Admin functions may process media and files such as product images, content media and signage images or videos. HIIICH must have the required rights, consents and permissions for uploaded media.

Media and backups may be stored in S3-compatible object storage.

14. Cookies and similar technologies

We use technically necessary cookies, local storage and similar technologies to provide the website, app, cart, language selection, login, security and checkout.

Non-essential technologies, especially analytics or embedded third-party content, are activated only after consent where consent is required. Consent can be managed and withdrawn through the consent tool.

15. Google Analytics

HIIICH may use Google Analytics if a measurement code is configured and the visitor has consented to analytics. Without consent, analytics remains disabled.

16. Google Maps

Google Maps is embedded through a click-to-load solution. Without a click or stored Maps consent, the map is not loaded. Loading the map may transmit data such as IP address, device/browser information, referrer and usage data to Google.

17. Cloudflare Turnstile

HIIICH may use Cloudflare Turnstile to protect against abuse, spam and automated attacks, especially for forms or reviews where configured.

18. Sentry

HIIICH may use Sentry for error analysis and stability improvements where configured. Technical error data, device data, browser/app information, timestamps, affected functions, technical IDs and stack traces may be processed.

19. Recipients and processors

Depending on the function, personal data may be transferred to Stripe, Twilio SendGrid or comparable email providers, Google, Cloudflare, Sentry, OrderKing/Kassa, hosting and infrastructure providers, S3-compatible object storage providers, Apple, Google Play, Expo/EAS, shipping providers, tax advisers, banks, authorities or legal advisers.

Processor agreements under Article 28 GDPR are concluded where required.

20. International transfers

Some providers may process data outside the EEA, in particular in the USA. Where required, transfers are based on adequacy decisions, the EU-U.S. Data Privacy Framework, standard contractual clauses or other lawful transfer mechanisms.

21. Retention

We retain personal data only as long as necessary for the relevant purpose or as required by statutory retention periods.

Order, payment, invoice, tax, accounting and legal-acceptance records are generally retained for seven years or as long as legally required. Accounts, sessions, OTPs, reset tokens, webhook data, logs, audit data, backups and support histories are retained and deleted according to purpose, security, recovery needs and legal obligations.

22. Your rights

You have rights under the GDPR, including access, rectification, erasure, restriction, portability, objection, withdrawal of consent and complaint to a supervisory authority.

Requests should be sent to office@hiiich.at. The competent Austrian supervisory authority is the Austrian Data Protection Authority, Barichgasse 40-42, 1030 Vienna, https://www.dsb.gv.at.

23. No solely automated decisions

HIIICH does not currently make decisions with legal or similarly significant effects based solely on automated processing including profiling.

24. Security

We use technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration or disclosure. Measures may include access controls, roles and permissions, session limits, hashing of tokens and passwords, rate limiting, captcha protection, audit logs, encrypted backups and error/security monitoring.

25. Changes

We may update this Privacy Policy if services, law, technical processing or providers change. The current version is made available on the website and/or app.

You can review or withdraw your cookie consent at any time.