Last updated: August 2026

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

ShineGlass – Owner Nikita Chulkov
Sole proprietorship
Kirchseeoner Weg 68
85614 Kirchseeon
Germany

Email: info@shineglass.de
Website: https://shineglass.de/

2. General information

We process personal data only where this is necessary to provide this website, handle enquiries, take steps before entering into and perform contracts, maintain technical security, or where you have given consent. Personal data means any information relating to an identified or identifiable person.

3. Hosting, server logs and encrypted transmission

This website is hosted by IONOS SE. When the website is accessed, the web server processes technically necessary information, in particular the IP address, date and time of access, requested URL, amount of data transferred, referrer URL, browser, operating system and HTTP status. This processing is used to provide the website securely, reliably and without errors and to prevent misuse.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of the website. Log data is deleted when it is no longer required for these purposes, unless a statutory duty or a specific security incident requires longer retention.

Data transmitted between your browser and this website is encrypted via HTTPS/TLS.

4. Contact and general enquiry forms

If you contact us by email or through a contact form, we process the contact details and message content you provide in order to answer your enquiry and continue the communication. Depending on the enquiry, this may include your name, email address, telephone number and a description of your request.

The legal basis is Article 6(1)(b) GDPR where the enquiry relates to a contract or pre-contractual steps. In other cases, processing is based on Article 6(1)(f) GDPR; our legitimate interest is to respond to communications addressed to us. Data is deleted once the enquiry has been fully dealt with, unless statutory retention duties or another legal basis require continued storage.

5. Foto-Check using Fluent Forms

For the Foto-Check, we process the information you enter in the form: first name, last name, telephone number, email address, postcode and town, type of glass surface, type of damage, preferred contact method, description of the damage and the photographs you upload. The purpose is to review your enquiry, provide an initial professional assessment, contact you and, where applicable, prepare a quotation or order.

The legal basis is Article 6(1)(b) GDPR. Where processing is necessary for technical traceability, troubleshooting and secure handling, it is additionally based on Article 6(1)(f) GDPR.

The form data is stored in WordPress and Fluent Forms. As part of the existing workflow, a non-public folder containing the uploaded images and a summary is also created in Google Drive, together with a working row in Google Sheets. The data is accessible only to authorised persons and the processors used.

If a Foto-Check enquiry does not result in an order, we generally delete the enquiry data, damage description and uploaded photographs from WordPress or Fluent Forms, Google Drive and Google Sheets six months after the last contact, unless another legal basis permits longer storage. If the enquiry results in an order, statutory retention periods apply to contract and tax-relevant documents.

6. Processors and recipients

We use carefully selected service providers to operate the website and handle enquiries:

These providers process data only within the scope of their respective services and, where required, under data processing agreements. Data is disclosed to other recipients only where this is necessary to perform a contract, required by law or covered by your consent.

7. Google Analytics 4 and Site Kit

This website uses Google Analytics 4 through the Site Kit by Google WordPress plugin. The provider is Google Ireland Limited. Google Analytics helps us understand how the website is used. This may involve processing pseudonymous online identifiers, device and browser information, approximate location information and details of page views and interactions.

For visitors from the EU, Google Analytics is activated only after consent through our consent management system. The legal bases are Article 6(1)(a) GDPR and Section 25(1) TDDDG. You may withdraw or change your consent at any time with future effect through “Cookie Settings” in the footer. Retention is determined by the respective cookie lifetime and the retention periods configured in Google Analytics. Details of the cookies used are available in our Cookie Policy.

8. Consent management with Complianz

We use Complianz to obtain, manage and document your cookie and service preferences. Technically necessary consent information and corresponding cookies are stored in your browser for this purpose. The legal bases are Article 6(1)(c) GDPR for compliance with data protection accountability duties and Article 6(1)(f) GDPR for reliable consent management. You can change your selection at any time through “Cookie Settings” in the footer.

9. Website security with Wordfence

We use Wordfence Security to protect the website from attacks and unauthorised access. IP addresses and technical request data may be processed and compared with security information. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is protecting the website, stored enquiries and technical infrastructure.

10. Functional technology, language and fonts

We use Polylang for language selection. A functional cookie may be stored to provide the selected language. The necessary processing is based on Section 25(2)(2) TDDDG and Article 6(1)(f) GDPR. Fonts used on the website are hosted locally; loading them does not establish a connection to Google Fonts.

11. Links to Instagram and TikTok

The website contains ordinary links to our Instagram and TikTok profiles. No social-media feeds or widgets are embedded. Only when you click one of these links do you leave our website, after which the relevant provider processes data under its own privacy policy.

12. Transfers to third countries

When services from internationally operating providers are used, processing outside the European Union or European Economic Area, particularly in the United States, cannot be entirely excluded. Where no adequacy decision applies, appropriate safeguards such as the EU Standard Contractual Clauses are used. For consent-dependent services, a transfer occurs only after your consent unless another legal basis applies.

13. Retention

We retain personal data only for as long as necessary for the relevant purpose. The relevant criteria include completion of the enquiry, the period stated above for Foto-Check enquiries that do not lead to an order, the duration of a contractual relationship, and statutory commercial and tax retention duties. Data is then deleted or, where deletion is not yet permitted, its processing is restricted.

14. Your rights

Subject to the statutory requirements, you have the right of access, rectification, erasure, restriction of processing, data portability and objection. You may withdraw consent at any time with future effect. To exercise your rights, email info@shineglass.de.

15. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority. The authority generally responsible for us is:

Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18
91522 Ansbach
Germany
https://www.lda.bayern.de/

16. Automated decision-making

We do not carry out solely automated decision-making, including profiling, within the meaning of Article 22 GDPR.

17. Updates to this Privacy Policy

We update this Privacy Policy when legal requirements or the services we use change. The version published on this page applies.

Anfrage senden
Leave a request