Keine Treffer im Archiv
Versuche einen anderen Suchbegriff oder setze die Filter zurück.
Updated 8 October 2026.
Joel Bittner, sole proprietor trading as Disorder119, Nelseestraße 25, 63739 Aschaffenburg, Germany. Email: disorder119shop@gmail.com. See the legal notice for further contact details.
The cart and outfit builder save selections locally. Language, display preferences and discount codes may also be stored locally, as well as whether the one-time newsletter notice has already been shown; for this, the time spent on the site so far is counted locally only and never transmitted. Selected item IDs are sent to our server to calculate shipping and process orders. Accounts are optional and use an emailed sign-in link and an essential HttpOnly session cookie. We process email, optional saved addresses, account/order associations and login times. IP checksums with a private server secret prevent abuse; they are pseudonymous, not anonymous. Order processing includes name, email, delivery address, items, prices and payment/shipping status. Legal bases: GDPR Art. 6(1)(b), (f), statutory recordkeeping Art. 6(1)(c), and necessary storage under §25(2) TDDDG.
Payments use PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg, including offered card payments and Apple Pay through PayPal. Apple also participates in Apple Pay. Their checkout services process transaction and connection data under their own policies; we do not store complete card details or bank login credentials. See PayPal and Apple.
GitHub Pages and Cloudflare deliver the website; Cloudflare operates our API/database and Turnstile protection and processes connection data. Cloudflare checks incoming requests for attacks; only if a security check is required may a strictly necessary cookie (e.g. cf_clearance) be set, used solely to prevent abuse. Brevo (Sendinblue SAS, France) receives recipients and content for transactional and newsletter emails. Incoming mail may be routed through Cloudflare and our mailbox provider. WhatsApp/email enquiries involve the respective communications services. Service agreements and safeguards required by data protection law must be in place. Processing outside the EEA may involve transfers subject to GDPR Art. 44 et seq., including an applicable adequacy decision or appropriate safeguards such as standard contractual clauses; contact us for details. Provider policies: GitHub, Cloudflare, Brevo.
Name and delivery address are sent to the chosen carrier (DHL: Deutsche Post AG, Bonn; DPD: DPD Deutschland GmbH, Aschaffenburg), for delivery to a Packstation also your DHL Postnummer, and, if we book the label through Packlink PRO (Auctane, S.L.U., Spain), to Packlink (Art. 6(1)(b)). Customer email and phone are not passed on. If you choose “To a Packstation or post office” at checkout, our server looks up nearby pickup points with the DHL location finder (Deutsche Post AG); only the postcode and, if entered, street and house number are sent to DHL – not your name, email or IP address (Art. 6(1)(b)). The map of pickup points loads only when you click “Show on map”. The official aerial images are fetched by our server from the survey office of the German state in which the searched postcode lies; the state is determined via OpenPLZ. The survey office only receives the map section shown, not your IP address (Art. 6(1)(b)). For the street map, your browser fetches map tiles directly from OpenStreetMap (OpenStreetMap Foundation, United Kingdom), which receives your IP address and technical browser data (Art. 6(1)(b) and (f); an EU adequacy decision applies to the United Kingdom). Details: OpenStreetMap privacy policy. Address suggestions use postcode and street prefix via our server to OpenPLZ; name, house number and your IP are not forwarded (Art. 6(1)(f)).
When your browser requests a page of this website, our Cloudflare server necessarily receives the page address, referring site, browser identifier and your IP address; Cloudflare derives the country from it. We use this to count visits, including while the shop is password-locked. We store the page, the referring site’s domain, device type, browser, country and a daily changing hash of IP, browser identifier and a private daily salt – not the IP itself and no more precise location. No script runs and, apart from the objection cookie below, nothing is stored on or read from your device for this. For a new visit and when the correct password for the locked shop is entered, the operator receives a Telegram notification (Telegram Messenger Inc.) with device, browser, country and page, without IP; transfers outside the EEA may occur. Legal basis: our legitimate interest in measuring the shop’s reach and responding to visits (Art. 6(1)(f) GDPR). The daily salt is deleted after the day ends, after which the hash can no longer be linked to an IP; entries are deleted after 30 days. DNT and GPC prevent counting. You can object at any time (Art. 21 GDPR) by opening disorder119.com/en/#nicht-zaehlen once; your browser then keeps the necessary cookie “d119_nicht_zaehlen” (§25(2) no. 2 TDDDG). disorder119.com/en/#zaehlen reverses this.
Additional statistics start only after you choose “Allow statistics” in “Privacy settings” (also available on the lock page). A script in your browser then records items viewed, page changes without reloading, duration, cart changes, enquiries, referring site, device/browser and approximate location (city/region). Events use a daily changing pseudonymous IP/browser hash with private daily salt; the IP itself is not stored in statistics. The operator receives Telegram notifications with location, device and item, without IP or customer contacts; transfers outside the EEA may occur. Legal basis: consent, Art. 6(1)(a) GDPR and §25(1) TDDDG. “Necessary only” refuses analytics without affecting shopping. Change or withdraw consent at any time through privacy settings. The choice is stored for up to 180 days; events are cleaned after 30 days. DNT and GPC prevent collection.
The newsletter requires explicit opt-in and email confirmation. We retain email, language, consent text/time and pseudonymous IP checksums. The current newsletter consent includes opening/click measurement; it does not permit general shop analytics. Unsubscribe via each email (Art. 6(1)(a), §7 UWG); abuse prevention relies on Art. 6(1)(f). Consent evidence is retained only as needed to defend claims, generally up to three years after unsubscribe. Online contract withdrawals use form details, order association and receipt timestamp to process and confirm your notice (Art. 6(1)(b),(c)). Optional account information may be erased on request. Legally necessary order, payment and tax records remain subject to retention: for example eight years for accounting vouchers, six for business correspondence and ten for certain books/records, possibly longer during an audit. Sign-in links and sessions expire. Rights requests normally receive a response within one month; a justified extension is communicated.
You may request access, correction, erasure, restriction, portability and objection under GDPR Art. 15–21 and withdraw consent for the future. Contact the controller by email. You may complain to a supervisory authority, including BayLDA (Art. 77). Necessary order/address information is required to fulfil purchases; accounts, newsletters and consent-based statistics are optional; you can object to server-side visit counting. We do not make solely automated decisions with legal or similarly significant effects under Art. 22; payment providers determine their available payment options.
Disorder119-Archiv