Mehr verkaufen mit LaunchMyStore
LaunchMyStore Logo

Kostenlose Rechtsvorlage

Datenschutzerklärung-Generator

Ein paar Fragen zu Ihrem Shop beantworten und eine Datenschutzerklärung erhalten, die Sie heute veröffentlichen können. Eine Startvorlage, keine Rechtsberatung.

Ihr Shop

Details zu Datenschutzerklärung

Dies ist eine Vorlage, keine Rechtsberatung. Prüfen Sie sie, passen Sie sie an Ihr Geschäft an und lassen Sie sie anwaltlich prüfen, wenn Sie in regulierten Kategorien verkaufen.

Die erzeugte Richtlinie ist auf Englisch. Übersetzen Sie sie vor der Veröffentlichung, wenn Ihr Shop in einer anderen Sprache verkauft.

Privacy Policy

[Store name] · Effective September 15, 2026

1. Overview

This Privacy Policy describes how [Store name] ("we", "us" or "our") collects, uses and shares your personal information when you visit [website URL] (the "Site"), buy something from us, or otherwise communicate with us. It takes effect on September 15, 2026.

By using the Site you agree to the collection and use of information as described here. If you do not agree, please do not use the Site or place an order.

2. Information we collect

We collect the following types of personal information:

  • Device information: your browser type, IP address, time zone, approximate location, the pages or products you view, the site that referred you, and how you interact with the Site. We collect this automatically using cookies, log files and similar technologies.
  • Order information: your name, billing address, shipping address, email address, phone number and the items you buy. Payment card details are entered directly with our payment processor; we never see or store your full card number.
  • Account information: if you create an account, we store your name, email address, a hashed version of your password, your order history and any saved addresses.
  • Marketing preferences: whether you have signed up for our emails, which emails you open, and which links you click, so we can send you things you are more likely to want.
  • Customer support information: anything you send us when you contact us, including the contents of your messages and any attachments.

3. How we use your information

We use the information we collect to:

  • Fulfilling orders: processing your payment, arranging shipping, sending order confirmations and updates, and handling returns or refunds.
  • Communicating with you: answering your questions and telling you about changes to your order or to our policies.
  • Preventing fraud: screening orders for risk and protecting the Site, our customers and ourselves from abuse.
  • Improving the Site: understanding how visitors use the Site so we can fix problems and make it better.
  • Marketing: sending you product news, offers and abandoned-cart reminders when you have agreed to receive them. Every marketing email includes an unsubscribe link, and you can opt out at any time.
  • Legal compliance: keeping the records we are required to keep by tax, consumer-protection and other laws.

4. Cookies and analytics

A cookie is a small file stored on your device when you visit a site. We use cookies that are essential for the Site to work (for example, to keep items in your cart and to remember that you are logged in), and, where you allow it, cookies that help us understand and improve the Site.

Google Analytics: we use Google Analytics to understand how visitors find and use the Site. Google collects information such as the pages you visit, how long you stay and the device you use. You can read how Google uses this data at https://policies.google.com/privacy and opt out of Google Analytics at https://tools.google.com/dlpage/gaoptout.

You can control cookies through your browser settings, including blocking or deleting them. If you block essential cookies, parts of the Site, including checkout, may not work.

5. How we share your information

We share your personal information with third parties only where needed to run the store, and never sell it to data brokers:

  • Payment processors: Stripe process your payment on our behalf. They receive your card details and billing information directly and handle them under their own privacy policies (Stripe: https://stripe.com/privacy).
  • Shipping carriers: we share your name, address and phone number with the carriers who deliver your order so they can get it to you and contact you about the delivery.
  • Email service providers: the platform we use to send emails stores your email address and engagement data on our behalf.
  • Analytics and advertising partners: Google, as described in the cookies section above.
  • Service providers: the platform that hosts our store and other providers who help us run the business, all of whom may only use your information to provide their service to us.
  • Legal requirements: we may disclose information to comply with the law, respond to a lawful request, or protect our rights.
  • Business transfers: if we sell or merge the business, your information may be transferred to the new owner, who will be bound by this policy.

6. How long we keep your information

We keep order information for three years after your last order, unless a longer period is required by law, needed to resolve a dispute, or needed to enforce our agreements.

Account information is kept for as long as your account is open. You can ask us to delete your account at any time, after which we keep only the records we are legally required to keep.

Device and analytics information is kept in aggregated form that no longer identifies you.

7. Your rights under GDPR and UK GDPR

If you are in the European Economic Area, Switzerland or the United Kingdom, we process your personal information on the following legal bases: performance of our contract with you (to fulfil your order); our legitimate interests (to run and improve the Site and prevent fraud); your consent (for marketing and non-essential cookies); and compliance with our legal obligations.

You have the right to:

  • Access the personal information we hold about you and receive a copy of it.
  • Correct inaccurate or incomplete information.
  • Ask us to delete your information, where we have no overriding reason to keep it.
  • Restrict or object to our processing of your information.
  • Receive your information in a portable, machine-readable format.
  • Withdraw consent at any time where we rely on consent, without affecting processing that has already taken place.

To exercise any of these rights, email us at [contact email]. We will respond within one month. You also have the right to lodge a complaint with your local data protection authority.

Because we and our service providers may be located outside your country, your information may be transferred across borders. Where we transfer information out of the EEA or UK, we rely on standard contractual clauses or another lawful transfer mechanism.

8. Your rights under California law (CCPA/CPRA)

If you are a California resident, you have the right to:

  • Know what personal information we collect, use and disclose, and receive a copy of it.
  • Delete personal information we have collected from you, subject to certain exceptions.
  • Correct inaccurate personal information.
  • Opt out of the sale or sharing of your personal information.
  • Not be discriminated against for exercising any of these rights.

We do not sell or share your personal information as those terms are defined under California law.

To exercise your rights, email [contact email]. We may need to verify your identity before responding. You can also authorise an agent to make a request on your behalf.

9. Security

We use reasonable technical and organisational measures to protect your personal information, including encryption in transit (HTTPS) and access controls. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

10. Children

The Site is not intended for anyone under the age of 16, and we do not knowingly collect personal information from children. If you believe a child has given us personal information, contact us at [contact email] and we will delete it.

11. Changes to this policy

We may update this policy from time to time to reflect changes in our practices or for legal reasons. The date at the top shows when it was last changed. If the changes are significant, we will let you know by email or with a notice on the Site.

12. Contact us

Questions about this policy or your personal information? Email us at [contact email].

[Store name], [your country or state].

Ihre Shop-Daten bleiben in diesem Browser, damit die anderen drei Richtlinien vorausgefüllt sind. Nichts wird hochgeladen.

Brauchen Sie dafür einen Shop?LaunchMyStore kostenlos testen
1

Ein paar Fragen beantworten

Was Sie erheben, welche Zahlungsdienstleister und Marketing-Tools Sie nutzen und wohin Sie versenden.

2

Formatierte Erklärung erhalten

Abschnitte zu erhobenen Daten, Cookies, Dritten, Speicherdauer und Nutzerrechten, in klarer Sprache geschrieben.

3

In Ihren Shop kopieren

Fügen Sie den Text auf Ihrer Datenschutzseite ein. Aktualisieren Sie ihn, sobald Sie eine neue App oder ein neues Tool ergänzen.

Was eine Datenschutzerklärung im Shop abdecken muss

Eine Datenschutzerklärung sagt einem Besucher, was Sie über ihn erheben, warum, und wer es sonst noch sieht. Für einen Onlineshop heißt das: personenbezogene Daten aus dem Checkout (Name, Adresse, E-Mail, Telefon), Zahlungsdaten (meist vollständig beim Zahlungsdienstleister, nicht bei Ihnen gespeichert), Kontodaten, falls Kunden sich anmelden können, und Verhaltensdaten aus Cookies und Analyse-Tools.

Sie sollte außerdem die beteiligten Dritten nennen. Das sind Ihr Zahlungs-Gateway, Ihr E-Mail-Marketing-Tool, wenn Sie Newsletter oder Warenkorbabbruch-Mails senden, Ihr Analyse-Anbieter und alle Werbe-Pixel, die Sie für Retargeting einsetzen. Sagen Sie, wie lange Sie Daten aufbewahren, und erklären Sie, wie man Löschung oder Export verlangt.

Halten Sie die Sprache einfach. Eine Erklärung, die niemand lesen kann, ist eine Erklärung, der niemand vertraut, und Aufsichtsbehörden erwarten zunehmend klare Sprache statt juristischer Textbausteine.

Grundlagen zu DSGVO, UK GDPR und CCPA/CPRA

Wenn Sie Kunden in der EU oder in Großbritannien haben, erwarten DSGVO und UK GDPR, dass Sie Ihre Rechtsgrundlage für die Verarbeitung nennen (meist Vertrag bei einer Bestellung, Einwilligung bei Werbung), die Dritten auflisten, mit denen Sie Daten teilen, und erklären, wie jemand Auskunft oder Löschung verlangt.

Wenn Sie Kunden in Kalifornien haben, erwarten CCPA und die Neufassung CPRA, dass Sie die Kategorien erhobener und verkaufter oder geteilter personenbezogener Daten offenlegen (auch für Werbe-Targeting) und Einwohnern eine Möglichkeit geben, dem Verkauf oder Teilen zu widersprechen, oft als Link „Do Not Sell or Share My Personal Information“. Weitere US-Bundesstaaten, darunter Virginia, Colorado und Connecticut, haben ähnliche Gesetze mit eigenen Schwellenwerten.

Sie müssen kein großes Unternehmen sein, damit das gilt. Wenn Sie an Einwohner dieser Regionen verkaufen, decken Sie die Grundlagen ab, statt sie zu überspringen.

Wohin damit

Verlinken Sie die Erklärung auf jeder Seite in der Fußzeile Ihres Shops und noch einmal im Checkout, in der Nähe des Felds, mit dem ein Kunde Ihren Bedingungen zustimmt. Wenn Sie Werbe-E-Mails versenden, verlinken Sie sie auch in der Fußzeile jeder Kampagne, denn dort schauen eine Aufsichtsbehörde oder ein Provider zuerst nach.

Häufige Fragen

Ist dieser Datenschutzerklärung-Generator kostenlos?
Ja. Beantworten Sie die Fragen und kopieren Sie den Text, ohne Anmeldung.
Ist die erzeugte Erklärung eine Rechtsberatung?
Nein. Das ist eine Startvorlage auf Basis gängiger E-Commerce-Praxis, keine Rechtsberatung. Lassen Sie sie von einem Anwalt prüfen, bevor Sie sich darauf verlassen, besonders wenn Sie in mehreren Ländern tätig sind oder sensible Daten verarbeiten.
Deckt sie DSGVO und CCPA ab?
Sie enthält die üblichen Abschnitte zu DSGVO, UK GDPR und CCPA/CPRA: Rechtsgrundlage der Verarbeitung, Offenlegung der Datenweitergabe, Speicherdauer und der Weg zu Auskunft, Löschung oder Widerspruch. Prüfen Sie trotzdem, ob sie zu Ihrer tatsächlichen Datenpraxis passt.
Brauche ich eine Datenschutzerklärung, wenn ich ein kleiner Shop bin?
Ja. Wenn Sie personenbezogene Daten erheben, und das tut jeder Checkout, verlangen die meisten Rechtsordnungen und die meisten Zahlungsdienstleister und Werbeplattformen eine veröffentlichte Datenschutzerklärung, unabhängig von Ihrer Größe.
Muss ich Cookies gesondert erwähnen?
Cookies werden meist innerhalb der Datenschutzerklärung in einem eigenen Abschnitt abgedeckt statt in einem separaten Dokument, außer Sie betreiben ein Cookie-Banner, dann verlinken Sie beide miteinander.
Was ist mit Apps, die eigene Daten erheben?
Listen Sie sie auf. Zahlungsdienstleister, Bewertungs-Apps, Live-Chat und Analyse-Tools erheben Daten unter ihrer eigenen Datenschutzerklärung, und Ihre sollte sagen, welche Tools Sie nutzen, und auf deren Erklärungen verlinken.
Wie oft sollte ich meine Datenschutzerklärung aktualisieren?
Immer wenn Sie ein Tool hinzufügen oder entfernen, das Kundendaten berührt: ein neues Zahlungs-Gateway, eine neue Marketing-Plattform, ein neues Analyse-Tool. Prüfen Sie sie mindestens einmal im Jahr, auch wenn sich nichts geändert hat.
Kann ich das nutzen, wenn ich international verkaufe?
Ja, die Vorlage deckt die gängigen Grundlagen für die USA und die EU/Großbritannien ab. Hat ein bestimmtes Land, in das Sie verkaufen, strengere Regeln, etwa Brasiliens LGPD oder Kanadas PIPEDA, ergänzen Sie eine Zeile dazu oder lassen es anwaltlich prüfen.

7 Tage kostenlos testen

Starten Sie heute Ihren kostenlosen Shop.

Keine Kreditkarte nötig. Alle Tools auf dieser Seite funktionieren weiter, ob Sie sich anmelden oder nicht.