Privacy policy
1. General
The protection of your personal data is very important to us. This privacy policy informs you about how personal data is collected, processed, stored and protected.
Personal data is processed in accordance with the applicable Swiss data protection laws (revDSG) and, where applicable, the European Union's General Data Protection Regulation (GDPR).
2. Responsible body
The body responsible for data processing is:
www.fanbox.ch
Fabio Tillmann
Ochsengartenstrasse 3
8274 Tägerwilen
Switzerland
Email: info@fanbox.ch
3. Collection and processing of personal data
Personal data is only processed to the extent necessary and legally permissible for the performance of business activities.
3.1 When visiting the website
When you access our website, the following data is automatically collected:
IP address
Date and time of access
Browser type and version
Operating system
Referrer URL
This data is used exclusively for the technical provision, security, stability and optimisation of the website.
3.2 When placing orders in the online shop
When you place an order, we process the following data in particular:
First and last name
Billing and delivery address
Email address
Telephone number (optional)
Payment information
Order and contract data
3.3 When purchasing items
When you purchase items, we also process the following data:
Description of the items offered
Images of the items offered
Account details (IBAN) for payment
4. Purposes of data processing
Personal data is processed in particular for the following purposes:
Processing orders and purchase enquiries
Payment processing and shipping
Customer communication
Fulfilment of legal obligations (e.g. accounting, retention obligations)
Sending newsletters (only with express consent)
Analysis and improvement of our offering and our website
5. Legal basis for processing
Your personal data is processed on the following legal bases:
Fulfilment of a contract (Art. 31(2)(a) revDSG / Art. 6(1)(b) GDPR)
Legal obligation (Art. 31(2)(c) revDSG / Art. 6(1)(c) GDPR)
Legitimate interest (Art. 31(1) revDSG / Art. 6(1)(f) GDPR), in particular IT security, fraud prevention and optimisation
Consent (Art. 31(1) revDSG / Art. 6(1)(a) GDPR), e.g. newsletters and analysis cookies
6. Cookies and analysis tools
Our website uses cookies. Cookies are small text files that are stored on your device and do not cause any damage.
6.1 Necessary cookies
These cookies are essential for the operation of the website (e.g. shopping basket, checkout) and cannot be deactivated.
6.2 Analysis cookies (Google Analytics 4)
If you have given your consent, we use Google Analytics 4, a web analysis service provided by:
Google Ireland Limited
Gordon House, Barrow Street, Dublin 4, Ireland
Purpose: Analysis of user behaviour
Measurement ID: G-LWQ00HETHM
Storage period: 14 months
Legal basis: Consent
IP addresses are processed anonymously.
Further information: policies.google.com/privacy
6.3 Cookie consent
When you first visit our website, you will be asked for your consent via a cookie banner. You can change or revoke your selection at any time via the cookie settings in the footer of the website.
7. Processors and third-party providers
We use carefully selected service providers to deliver our services:
7.1 Shop platform
Shopify Inc.
151 O'Connor Street, Ottawa, Ontario K2P 2L8, Canada
7.2 Payment processing
We use various payment service providers to process payments, depending on the selected payment method. Currently, the following providers in particular can be used:
Shopify Payments / Stripe Payments Europe Ltd., Dublin, Ireland
PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg
TWINT AG, Zurich, Switzerland
Depending on availability, destination country or in exceptional cases, other payment service providers may also be used. Only the personal data required for payment processing is transmitted to the respective payment provider.
7.3 Shipping
We generally use Swiss Post Ltd, Bern, Switzerland, for shipping. Depending on the destination country, shipping method or in exceptional cases, other shipping service providers may also be used. Only the data required for shipping (name and delivery address) will be transmitted.
7.4 Email dispatch
Resend Inc., USA
For transactional emails and newsletters.
8. Data transfer to third countries
Some service providers are located outside Switzerland or the EU/EEA.
USA: Shopify Inc., Google LLC, Resend Inc. → Certification under the EU–U.S. Data Privacy Framework
Canada: EU adequacy decision
In addition, standard contractual clauses are used where necessary.
9. Social media
9.1 Instagram feed
Embedded Instagram images are loaded from our own server. No automatic data transfer to Meta Platforms Ireland Limited takes place.
9.2 Social media links
Links to Instagram and TikTok are simple hyperlinks. Data is only transferred when you actively click on a link.
The data protection provisions of the respective providers apply.
10. Data security
We use appropriate technical and organisational security measures to protect your data from unauthorised access, loss or misuse. Our website is encrypted using SSL/TLS.
11. Your rights
Data subjects have the following rights under the applicable data protection laws. These rights only exist insofar as there are no legal retention obligations, overriding legitimate interests or other legal restrictions.
Your rights:
Information, provided that there are no legal confidentiality or retention obligations
Correction of incorrect or incomplete data
Deletion, provided that there are no legal obligations or legal claims
Restriction of processing, unless provided for by law
Objection, unless the processing is based on legitimate interests and there are no compelling reasons to the contrary
Data portability
The right to data portability exists exclusively if the processing is automated and based on consent or a contract. This right does not apply to data that we process on the basis of legal obligations.
EU data subjects
EU data subjects also have the right to lodge a complaint with a competent data protection supervisory authority.
Exercising your rights
Requests should be sent in writing to info@fanbox.ch . We reserve the right to request appropriate proof of identity. Unfounded or excessive requests may be rejected or subject to a fee, to the extent permitted by law.
12. Retention period
Personal data will only be stored for as long as is necessary for the respective purposes.
Where statutory retention obligations exist, personal data will be stored until the expiry of the respective retention period, regardless of other deletion periods, and will then be deleted or anonymised.
The following retention periods apply in detail:
Order data & invoices: 10 years
Purchase enquiries: 10 years
Newsletter consents: until revoked
Contact enquiries: 3 years
Analysis data (Google Analytics): 14 months
13. Automated decisions
No automated decision-making or profiling takes place.
14. Changes
We reserve the right to amend this privacy policy at any time. The current version on this website applies.
As of: January 2026