PRIVACY POLICY (EU & UK)
3. THE TYPES OF PERSONAL DATA WE COLLECT
3.1. WEB SERVER LOGS (INCL. IP ADDRESSES)
3.2. PERSONAL DATA SUBMITTED BY YOU
4. HOW WE PROCESS YOUR PERSONAL DATA
6. HOW WE SECURE YOUR PERSONAL DATA
8. COOKIES AND SIMILAR TECHNOLOGIES
We appreciate your interest in the Redbubble Marketplace, available at www.redbubble.com or in the Redbubble Mobile App available in the Apple App Store or Google Play Store (collectively, the "Marketplace"). We respect your privacy. Therefore, we collect and process your personal data only in accordance with the relevant legal requirements. In no case do we rent or sell your personal data for marketing or other purposes.
This Privacy Policy explains the types of personal data we collect when you use the Marketplace and how we process it.
Please note that any reference to the GDPR shall also apply to the respective section laid out under UK’s Data Protection Act 2018.
DATA CONTROLLER, DATA PROTECTION OFFICER AND REPRESENTATIVE IN THE EUROPEAN UNION (EU) AND UNITED KINGDOM
-
Redbubble Inc (111 Sutter St., 17th Floor, San Francisco, CA 94104, USA) and Redbubble Ltd (Level 12, 697 Collins St., Docklands, Victoria 3008, Australia); email legal@redbubble.com (hereinafter collectively "Redbubble", "we", "our", "us", etc.) are joint data controllers for the purposes of the European Union's General Data Protection Regulation (GDPR) and United Kingdom’s Data Protection Act 2018.
-
You can reach our Data Protection Officer at the following contact details: Data Protection Officer, DP DOCK DPO Services GmbH, Grüffkamp 10, 24159 Kiel, Germany. Email redbubble@dp-officer.com.
-
Our representative in the European Union pursuant to Article 27 of the GDPR is Redbubble Europe GmbH, Stralauer Platz 33-34, 10243 Berlin, Germany. Email privacy@redbubble.com.
-
Our representative in the United Kingdom pursuant to Article 27 of the GDPR is Redbubble UK Limited, 71-75 Shelton Street, WC2H 9JQ London, United Kingdom. Email privacy@redbubble.com.
WHAT IS PERSONAL DATA
Personal data is all information that can be individually assigned to you either directly or indirectly. This includes, for example, your name, address, telephone number, cell phone number, fax number and email address.
THE TYPES OF PERSONAL DATA WE COLLECT
You can generally visit the Marketplace without providing us with any information that directly identifies you. Please note, however, that you may not be able to use certain areas of the Marketplace or certain of the services we offer.
WEB SERVER LOGS (INCL. IP ADDRESSES)
When you visit and use the Marketplace, our web server automatically collects so-called access data out of technical necessity, which your terminal device automatically transmits. This log record may include the following information: your IP address, the date and time you are on the Marketplace, the pages you visit on the Marketplace, the name of the file you retrieve and the amount of data transferred, the message whether the retrieval was successful, the website you were on before (so-called referrer website), the browser you use (e.g. Microsoft Edge or Google Chrome), the operating system you use (e.g. Windows 10) as well as the domain name and address of your internet provider.
We collect the listed data to ensure a smooth connection setup of the website and to enable a comfortable use of our website by the users. In addition, the log file serves the evaluation of system security and stability as well as administrative purposes. The legal basis for the temporary storage of the data or the log files is Art. 6 para. 1 (f) GDPR.
PERSONAL DATA SUBMITTED BY YOU
(a) Otherwise, we collect personal data from you if you have provided it to us on the basis of consent according to Art. 6 para. 1 (a) GDPR in order to provide, operate and administer the Marketplace in accordance with our User Agreement (see www.redbubble.com/agreement) and to provide you with our services.
-
Specifically, we (a) collect your username and email address when you create a user account and register for the Marketplace; (b) collect your name, shipping address, billing address, phone number, email address, and bank or payment information when you order a product through the Marketplace; (c) may collect your legal name, legal business name, address, phone number, email address, bank information, tax ID, date of birth, business registration number (if relevant), VAT number (if relevant), country of tax residency and tax status when you sell products through the Marketplace; and (d) collect your email address when you fill out a form or send us an email. When we collect your personal data, we will inform you whether the provision of the respective personal data is required or merely optional, as well as about the possible consequences if you do not provide the respective information.
-
In addition, we collect personal data that you provide to us in connection with your visit to and use of the Marketplace and our services, e.g. your sales and order history, favorite and marked products on the Marketplace, your movements and executed actions on the Marketplace, as well as the content and details of your messages that you send and receive from other users via our BubbleMail service. Insofar as you use a so-called single sign-on function of a social network to log in to the Marketplace, we collect your personal data from the corresponding social network that you have made publicly available there.
(b) If you have given us your consent (Art. 6 para. 1 (a) GDPR), we will also collect your email address as part of the registration process for our newsletter and other promotional messages.
HOW WE PROCESS YOUR PERSONAL DATA
4.1. We process your personal data in order to provide and operate the Marketplace in accordance with our User Agreement and to provide you with our services, in particular (a) for the processing and coordination of sales and orders on the Marketplace; (b) for the provision of a functional and accurately running Marketplace – within the range of what is technically possible and reasonable – by observing, monitoring and maintaining the performance of the Marketplace (in particular by identifying and appropriately resolving problems and errors); (c) for providing and maintaining means of communication with Redbubble Support via live chat, email, web forums, social media or telephone and for handling such communication accordingly; and (d) for providing and maintaining means of communicating or exchanging ideas with other users via message boards, chat rooms or interactive online forums or for submitting reviews for products offered on the Marketplace.
The legal basis for this is the fulfillment of our contractual obligations vis-à-vis our Users according to Article 6 para. 1 (b) GDPR.
Please note with regard to the communication via message boards, chat rooms or interactive online forums explained in section 4.1(d) that if you post a comment on a message board or chat room, this information will be made available to the public in an online environment. Each comment posted is the sole responsibility of the individual user. If you use such an interactive area, you should always be aware that these areas, and therefore any personal information shared there, are publicly accessible. We cannot control how other visitors to the Marketplace use this information. In particular, we cannot prevent you from receiving unsolicited communications.
4.2. Furthermore, we process your personal data as a precaution against and prevention of fraudulent acts on the Marketplace.
The legal basis for this is Article 6 para. 1 (f) GDPR. Our legitimate interests in this context are to protect the integrity of the Marketplace, our services, our system and our users.
4.3. Furthermore, we process your personal data for our efforts to (a) provide you with the most optimal and meaningful user experience possible when visiting and using our Marketplace and services; and (b) improve and optimize the Marketplace, its layout and content, and our services.
The legal basis for this is our legitimate interest according to Article 6 para. 1 (f) GDPR. Our legitimate interests in this context are to provide you with an optimal and meaningful user experience on the Marketplace that meets your expectations and needs on the one hand and fulfills our commercial interests on the other hand.
4.4. To the extent you have given us your consent, we will further process your collected personal data for the provision and optimization of our email marketing efforts, in particular the provision of our newsletter and other marketing messages about Redbubble events, Redbubble services, Redbubble products and special Redbubble offers.
You may revoke your consent at any time with future effect. You may do so at any time by following the instructions included in any email or by contacting our customer service, for example, by sending an email to the contact options listed in Section 1 or by contacting our Help Center at help.redbubble.com/hc/en-us (which you can also access via the "Help" link at the bottom of the Marketplace homepage). If you have given us your consent, we will continue to process your email address to send you helpful information about using our services from time to time. You can disable these messages at any time by deactivating the receipt of such messages in the settings functions of your user account.
The legal basis for this is Article 6(1)(a) GDPR.
4.5. Furthermore, we may process the information collected by our web server (cf. Section 3.1) in the event of system abuse in cooperation with your Internet provider and/or local authorities in order to determine the originator of this abuse.
The legal basis for this is our legitimate interest according to Article 6 para. 1 (f) GDPR. Our legitimate interests in this context are the protection of the integrity of the Marketplace, our services, our system and our users.
TRANSFER OF PERSONAL DATA
Your personal data is very important and helpful for us to provide and optimize the Marketplace and our services. We will only share your personal data with third parties to the extent set out below.
Purpose | Legal Basis |
---|---|
In order to provide our services in the form of processing and coordinating sales or orders between users on the Marketplace, it is necessary to pass on your name, delivery address and telephone number to production, printing, logistics or processing service providers on behalf of the seller. Please note that this information is shared solely for the purpose of processing the sale or order made between users. However, this information will not be made available to the aforementioned service providers for marketing purposes under any circumstances. | Article 6 para. 1 (b) GDPR – our contractual obligations |
In the event that claims are made by third parties claiming that any content transmitted by you to the Marketplace violates applicable law, intellectual property rights of the third party (e.g. copyrights and ancillary copyrights, patents, trademarks, company logos, work titles or designs) and/or other rights of the third party (e.g. general personal rights or the right to one's own image), we are entitled in accordance with the legal requirements under applicable law to pass on your name, address and/or further information about the content objected to by the third party to the third party in order to enable the third party to assert its rights against you. | Article 6 para. 1 (c) GDPR – our compliance with a legal obligation |
We are further entitled to outsource the processing of personal data in whole or in part to external service providers who act for us as processors within the meaning of Article 4(8) GDPR. If these service providers are located outside the European Union or European Economic Area, we will take appropriate security measures in accordance with legal and regulatory requirements to ensure the security of your personal data. | Article 6 para. 1 (b) GDPR – our contractual obligations |
We use external service providers as part of the provision and operation of the Marketplace and the provision of our services for the purposes listed below:
For hosting the Marketplace | The legal basis for this is Article 6 para. 1 (b) GDPR – our contractual obligations |
---|---|
For storing the databases in the backend of the Marketplace | The legal basis for this is Article 6 para. 1 (f) GDPR our legitimate interest |
For enabling and providing live chat communications. | The legal basis for this is Article 6 para. 1 (b) GDPR – our contractual obligations |
For enabling and providing the technical requirements for product reviews by users. | The legal basis for this is Article 6 para. 1 (f) GDPR our legitimate interest |
For the precaution against as well as the detection, identification and prevention of fraudulent actions on the Marketplace. | The legal basis for this is Article 6 para. 1 (f) GDPR. |
For observing and monitoring the performance of the Marketplace and detecting, identifying and resolving problems and errors on the Marketplace. | The legal basis for this is Article 6 para. 1 (f) GDPR – our legitimate interest. |
For providing our Customer Relationship Management, in particular customer and product support for the Marketplace, as well as investigating, identifying and resolving customer support requests via live chat, email, web forums, social media or telephone | The legal basis for this is Article 6 para. 1 (b) GDPR – our contractual obligations |
For enabling data reporting and analytics for our internal business purposes. | The legal basis for this is Article 6 para. 1 (f) GDPR – our legitimate interest. |
For optimizing typography in the Marketplace. | The legal basis for this is Article 6 para. 1 (f) GDPR – our legitimate interest.. |
For effectively and efficiently organizing and administering our internal business goals. | The legal basis for this is Article 6 para. 1 (f) GDPR – our legitimate interest.. |
For optimizing and improving our budget planning, business performance, analysis and reporting. | The legal basis for this is Article 6 para. 1 (f) GDPR – our legitimate interest. |
For providing services for our marketing as well as for optimizing our marketing, such as delivering digital ads relevant to you via targeting or advertising cookies. These types of cookies also limit the number of times that you see an ad and help us measure the effectiveness of our marketing campaigns. We use cookies to help us identify and retarget users who may be interested in our products, services or offerings both on the Marketplace and on third party websites. | The legal basis for this is Article 6 para. 1 (1)(b) GDPR – our contractual obligations. |
For providing payment services to our users. | The legal basis for this is Article 6 para. 1 (b) GDPR – our contractual obligations. |
For verifying some users as per our tax obligations | Article 6 para. 1 (c) GDPR – our compliance with a legal obligation |
Klarna:
In order to offer you Klarna's payment methods, we might in the checkout pass your personal data in the form of contact and order details to Klarna, in order for Klarna to assess whether you qualify for their payment methods and to tailor those payment methods for you. Your personal data transferred is processed in line with Klarna's own privacy notice.
Google Analytics
Our website uses Google Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). Google Analytics uses so-called cookies.
On behalf of the operator of this website, Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other data from Google.
We only use Google Analytics with IP anonymization activated. This means that the IP address of the user is shortened.
The processing of Google Analytics is carried out in accordance with Art. 6 para. 1 (a) GDPR on the basis of your consent. We have concluded an order processing agreement with the service provider in which we oblige him to protect our customers' data and not to pass it on to third parties.
The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected.
You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) to Google and the processing of this data by Google by downloading and installing the browser plug-in available at the URL https://tools.google.com/dlpage/gaoptout?hl=en.
Information on how Google Analytics handles user data can be found in Google's privacy policy: https://support.google.com/analytics/answer/6004245?hl=en.
Stripe:
As per our tax reporting obligations, we are legally obliged to verify certain information for which we use the Stripe Connect solution. If you sell products on the Marketplace, Stripe may collect information including an identification document, legal name, address, tax ID, date of birth, business registration number, VAT number, bank account number, country of tax residence and legal business name. For further information on how Stripe processes your data, please see Stripe’s Privacy Policy.
HOW WE SECURE YOUR PERSONAL DATA
We take all necessary and reasonable steps to keep your personal data secure, but by its nature, unfortunately, no system is impenetrable. Due to the inherent nature of the Internet, we cannot guarantee that information is one hundred percent secure from unauthorized access during transmission over the Internet or while it is stored on our system or otherwise. Your payments are made over an encrypted connection or through a secure data processor. Access to your personal data on our databases is subject to appropriate technical security measures. Furthermore, only persons authorized by us can access your personal data to the extent necessary for their respective activities (so-called need-to-know principle). External service providers who have access to personal data in the course of their activities must sign a commissioned processing agreement (Article 28 GDPR) with us, which obliges them to implement the necessary and appropriate steps to protect the personal data provided to them.
STORAGE PERIOD
Your personal data will be stored by us only as long as it is necessary to achieve the purposes for which it was collected or, if there are any legal retention periods beyond this, for the duration of the legally prescribed retention period. Subsequently, your personal data will be deleted.
COOKIES AND SIMILAR TECHNOLOGIES
For the processing of personal data using cookies and similar technologies in the context of the Marketplace, please see our Cookie Policy (including our Consent Manager Tool), which is part of this Privacy Policy.
YOUR RIGHTS UNDER DATA PROTECTION LAW
In accordance with applicable data protection law, you may have the following rights.
9.1 Right to access: You may have the right to request information about your personal data stored by us at any time in accordance with GDPR Article 15. When we process your personal data, we take reasonable steps to ensure that your personal data is accurate and up to date for the purposes for which it was collected.
9.2. Right to Rectification: Your user account shows you the essential personal data that is stored by us. You can view, change and/or delete this personal data at your own discretion. In accordance with GDPR Article 16, if your personal data is inaccurate or incomplete, you may request that it be corrected.
9.3 Right to Erasure (Right to be Forgotten) In accordance with GDPR Article 17, you may have the right to request the deletion or restriction of the processing of your personal data if, for example, there is no longer a legitimate business purpose for such processing under this Privacy Policy or applicable law and legal retention obligations do not prevent further storage.
Furthermore, you can contact us at any time with a request for information, deletion and restriction under the contact options listed in Section 1. In accordance with Article 19, we will communicate any rectification or erasure of personal data to each data subject.
9.4 Right to data portability: In accordance with GDPR Article 20, you may have the right to receive the personal data concerning you that you have provided to us in a structured, common and machine-readable format or to transfer this data to another controller. For this purpose, please contact the contact options listed under Section 1.
9.5 Right to object: In accordance with GDPR Article 21, you may have the right to object to the processing of your personal data on specific grounds relating to your particular situation. To do so, please contact the contact options listed under Section 1.
9.6 Right to revoke your consent: If you have consented to the collection and processing of your personal data, you may revoke your consent at any time with effect for the future, but without affecting the lawfulness of the processing carried out on the basis of the consent until revocation. You can also object to the use of your personal data for the purposes of market and opinion research as well as advertising and to unsubscribe from receiving our newsletter (see Section 4.4). To do so, please use the contact options listed under section 1.
9.7 Without prejudice to any other administrative or judicial remedy, you also have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data infringes the GDPR (Article 77 GDPR). You can assert this right in Berlin at the supervisory authority responsible for us: Berlin Commissioner for Data Protection and Freedom of Information, Friedrichstr. 219, 10969 Berlin, Germany. Email mailbox@datenschutz-berlin.de.
CHANGES
We reserve the right to change this Privacy Policy at any time in accordance with the law. This may be necessary, for example, to comply with new legislation or in the case of new services. In the event that we make substantial changes, we will notify you via email, push notification or similar.
Last update: June 2024