1. Controller

The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:

WorryCharm – Timo Daniel Mayer
c/o Online-Impressum #8756
Europaring 90
53757 St. Augustin
Germany
Email: contact@worrycharm.com

We have not appointed a data protection officer, as the statutory conditions requiring one do not apply.

2. Server log files

When you visit this website, the web server automatically records information in what are known as server log files. The following is recorded:

  • IP address of the accessing device
  • date and time of access
  • name and URL of the file requested
  • volume of data transferred and confirmation of successful retrieval
  • browser type and version, and the operating system used
  • the previously visited page (referrer), where transmitted

Purpose: ensuring trouble-free operation, maintaining system security and diagnosing faults.

Legal basis: Article 6 (1) (f) GDPR. Our legitimate interest lies in the secure and stable operation of this website.

Retention: log files are deleted automatically after 14 days. This data is not combined with other sources and is not analysed for marketing purposes.

3. Cookies and consent

This website needs no cookies at all in order to work. Nothing is stored on your device for the site to function, and there are no advertising cookies and no social media plugins.

The one exception is the web analytics described in section 5. It runs only if you actively agree in the banner shown on your first visit. Until you agree, nothing is loaded from Google and nothing is stored on your device for that purpose. Declining costs you no functionality whatsoever.

So that we do not ask again on every page, your decision itself is stored in your browser's local storage under the key wc-consent-v1, with the value “granted” or “denied”. This entry contains no identifier, is never transmitted to us or to anyone else, and is technically necessary to honour your choice, which is why it does not itself require consent.

Withdrawing: at the bottom of every page there is a “Cookie settings” button. It resets your decision and shows the banner again. A withdrawal takes effect immediately and for the future. You can also delete the entry at any time by clearing your browser data.

4. Third-party resources

All design elements of this website, including fonts, images, stylesheets and scripts, are served exclusively from our own server. No Google Fonts, no content delivery network and no external form service are embedded.

The only external service on this website is the web analytics in section 5, and it is only contacted after you have consented. If you decline, or simply ignore the banner, your IP address is not transmitted to any third party.

5. Web analytics with Google Analytics

Subject to your consent, we use Google Analytics 4, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Purpose: to understand which pages are read and which are not, so that we can improve them. We do not use it for advertising.

What is processed: a shortened IP address, the pages you open and how long you stay, referring page, approximate location derived from the IP (country and region level), and technical details of your device, browser and operating system. Google Analytics assigns a randomly generated identifier to your browser so that repeat visits within a session can be recognised.

Settings we have applied: IP anonymisation is active, and the advertising features “Google Signals” and ad personalisation are switched off. We therefore receive no cross-device advertising profiles, and your data is not used for personalised advertising through us.

Legal basis: your consent, under Article 6 (1) (a) GDPR and Section 25 (1) of the German Telecommunications Digital Services Data Protection Act (TDDDG). Consent is voluntary and can be withdrawn at any time as described in section 3, without affecting the lawfulness of processing carried out before the withdrawal.

Transfer to third countries: data may be transferred to servers of Google LLC in the United States. Google relies on the EU-US Data Privacy Framework and on standard contractual clauses under Article 46 GDPR. Despite these safeguards, it cannot be ruled out that United States authorities may access such data, and there may not be legal remedies against this equivalent to those in the EU. By consenting, you also consent to this transfer under Article 49 (1) (a) GDPR.

Retention: event and user data is deleted automatically after the retention period configured in our Google Analytics property. Aggregated reports contain no personal data.

Further information is available in Google's own privacy policy at policies.google.com/privacy.

6. Hosting

This website is hosted on a rented virtual server. The hosting provider processes the data described in section 2 on our behalf under a data processing agreement pursuant to Article 28 GDPR.

7. External links

This website contains links to external websites, in particular to our shop on Etsy. Clicking such a link takes you away from this website. We have no influence over the data processing carried out by the respective provider. Please refer to that provider's privacy policy for information on the nature, scope and purpose of their processing.

8. Contact by email

If you contact us by email, the data you provide (your email address and the content of your message) is stored for the purpose of handling your enquiry.

Legal basis: Article 6 (1) (f) GDPR for general enquiries, or Article 6 (1) (b) GDPR where the enquiry relates to entering into or performing a contract.

Retention: the data is deleted once it is no longer required and no statutory retention obligations apply.

9. Contact form

Our contact form transmits the name, email address and message text you enter. The form is operated entirely on our own server. No external form service is used, no captcha provider is embedded, and your entries are not passed to any third party.

To answer you, the message is forwarded to our own mailbox and additionally stored on our server in a file that is not publicly accessible.

To keep out automated spam, the form contains a hidden field that is invisible to you, and it checks how much time passed between the page loading and the message being sent. Neither procedure sets cookies or creates a profile.

Legal basis: Article 6 (1) (f) GDPR for general enquiries, or Article 6 (1) (b) GDPR where the enquiry relates to entering into or performing a contract. Providing the data is voluntary, but without it we cannot reply.

Retention: the message is deleted once your enquiry is settled and no statutory retention obligations apply.

10. Waitlist

On several pages you can leave your email address to be told once when ROOTED becomes available. Only the email address is processed. No name, no other data, and no profiling.

Double opt-in: after you submit the form we send exactly one email containing a confirmation link. Your address counts as subscribed only once you open that link. Until then it is held on our server marked as unconfirmed and is never used for anything else. Unconfirmed entries are deleted at the latest when the announcement is sent.

Purpose: a single message informing you that the product is available. There is no newsletter and no further mailing.

Legal basis: your consent, Article 6 (1) (a) GDPR. The double opt-in procedure also serves to demonstrate that consent was given, which is our legitimate interest under Article 6 (1) (f) GDPR.

Withdrawal: reply to any email from us and your address is deleted. Withdrawal takes effect for the future and does not affect processing carried out beforehand.

Recipients: none. The list is stored on our own server and sent from our own mailbox. No mailing service such as Mailchimp or Brevo is involved.

Retention: until you withdraw, or until the announcement has been sent and the list is no longer needed.

11. Your rights

Subject to the statutory conditions, you have the following rights at any time:

  • access to the data stored about you (Article 15 GDPR)
  • rectification of inaccurate data (Article 16 GDPR)
  • erasure of your data (Article 17 GDPR)
  • restriction of processing (Article 18 GDPR)
  • data portability (Article 20 GDPR)
  • objection to processing (Article 21 GDPR)

To exercise your rights, a message to contact@worrycharm.com is sufficient.

12. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority regarding our processing of your personal data (Article 77 GDPR). The competent authority is the one for your habitual residence or for our place of business.

13. SSL encryption

For security reasons this website uses SSL/TLS encryption. You can recognise an encrypted connection by the fact that your browser's address bar begins with “https://”.

14. Status

This privacy policy is current as of August 2026. Further development of this website may make an update necessary.