Privacy Policy

Stand / Aggiornamento: 28.07.2026

This policy covers both orders at our ice cream café and bookings of our ice cream van for events. The general points apply to both cases; the details for each specific area follow below.

The data controller within the meaning of the General Data Protection Regulation (GDPR) is Homann Mauro (Mauro's Eis-Bellacrema). Full contact details (address, phone, email): see Impressum. A data protection officer is not legally required (§ 38 BDSG, German law) and none has been appointed.

1. General Information on Data Processing

We generally process our customers' personal data only to the extent necessary to provide a functioning website and to handle our orders and payments. Processing generally takes place only with the consent of the data subject or where permitted by statutory provisions.

2. Data Collection When Visiting Our Website (Server Log Files)

When you visit our website, our hosting provider automatically collects technical data transmitted by your browser (server log files): IP address, date and time of the request, browser type and version, operating system used, page accessed. This data is processed exclusively to ensure trouble-free operation and the security of our IT systems, and is not combined with other data sources.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure and stable website operation).

3. Cookies and Local Storage on Your Device

When you visit our website, we set a technically necessary session cookie (name „PHPSESSID"), which is automatically deleted when you close your browser. In addition, your browser stores the contents of your shopping cart and the status of an ongoing order locally on your device (local storage), so this information is not lost when navigating between pages or after being redirected to the payment provider.

Both are strictly necessary to provide the service you use, which is why, pursuant to § 25(2) No. 2 TDDDG (German Telecommunications-Digital-Services-Data-Protection Act; called TTDSG until 12 May 2024 — the content is unchanged), no separate consent is required. You may restrict or delete the storage of cookies and local data at any time via your browser settings; this may, however, impair the functionality of our ordering process.

Legal basis: Art. 6(1)(f) GDPR in conjunction with § 25(2) No. 2 TDDDG.

4. Map Service (OpenStreetMap)

When you open the live location display of our ice cream van, map tiles are loaded from the OpenStreetMap Foundation's servers and the Leaflet map library is loaded via the provider unpkg.com. Your IP address is transmitted to these providers. This feature is only triggered if you actively select it via the corresponding button.

Legal basis: Art. 6(1)(b) GDPR (feature requested by you).

5. No Automated Decision-Making

We do not use any automated decision-making process (including profiling) within the meaning of Art. 22 GDPR.

6. Your Rights as a Data Subject

You have the right at any time to:

The competent authority is: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI), Königstraße 10a, 70173 Stuttgart, Germany

Shop and online purchase

7. Placing an Order in the Online Shop

When you place an order through our website, we collect and process: name, phone number, pickup date and time, for larger orders additionally address, postal code, city. This data is used exclusively to process your order (contacting you with questions, organizing pickup).

Legal basis: Art. 6(1)(b) GDPR (performance of a contract or pre-contractual measures at your request).

8. Notifying Branches of Your Pickup (Google Firebase)

To notify our staff in good time before the agreed pickup time, we send a push notification to our branches' tablets. This notification includes your name and the order number, and is technically delivered via the Google Firebase Cloud Messaging service (Google Ireland Limited, with possible server processing by Google LLC, USA). Insofar as this involves a transfer of data to the USA, it relies on the European Commission's adequacy decision of 10 July 2023 on the EU-US Data Privacy Framework (Art. 45 GDPR); Google LLC is certified under this framework.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the smooth organization of pickup).

9. Email Address for Invoice Delivery

To deliver your invoice, we additionally collect your email address. Providing it is voluntary, at your request, by actively entering and confirming it in the order form. We use this address exclusively to send the invoice for your order — no advertising or newsletters.

Legal basis: Art. 6(1)(b) GDPR (fulfilling your request for electronic invoice delivery) as well as, where separately requested during the ordering process, Art. 6(1)(a) GDPR (consent). You may withdraw this consent at any time with effect for the future by contacting us at info@eis-bellacrema.de. The withdrawal does not affect the delivery of invoices already issued.

10. Invoice Download Link

After successful payment, we provide you with the option to download your invoice via a one-time link. This link contains a randomly generated security token, assigned exclusively to your specific order, which automatically becomes invalid 5 minutes after payment.

Legal basis: Art. 6(1)(b) GDPR.

11. Payment Processing via Mollie

For processing online payments, we use the payment service provider Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, Netherlands. The following data is transmitted to Mollie: name, address, transaction amount, date and time of purchase. Mollie processes this data as an independent controller (not bound by our instructions), which is why no data processing agreement is required.

Legal basis: Art. 6(1)(b) GDPR (performance of the purchase contract) as well as Art. 6(1)(c) GDPR (statutory obligations in payment transactions). Further information: mollie.com/en/privacy

12. Invoice Delivery by Email

The invoice is sent by email via our email service provider (Google/Gmail). Your email address and the content of the invoice (name, ordered items, amount) are transmitted via this provider's servers.

Legal basis: Art. 6(1)(b) GDPR.

13. Legally Required Cash Register Security System (TSE)

To comply with the legal requirements of the German Cash Register Security Ordinance (KassenSichV), we use a certified cloud TSE service (Fiskaly GmbH). The transaction data of your order is digitally signed and stored in a tamper-proof manner.

Legal basis: Art. 6(1)(c) GDPR (statutory tax retention and security obligation).

14. Click and Usage Statistics on the Ordering Process

To improve the usability of our ordering process, we occasionally record individual technical interaction events (e.g. which button was pressed during ordering). We collect exclusively: a short label of the event, your role, and the branch concerned, each with date and time. Explicitly NOT collected: text entries, form content, or any other content you type in (e.g. name, address, messages) — only the technical event of a click is logged, never its content. No cookies are set in this context, no IP address is stored, and no individual user profile is built; it is not possible to identify a specific person. This feature helps us identify technical drop-off points in the ordering process, can be enabled or disabled by us, and automatically switches itself off after 7 days at the latest.

We do not use any third-party analytics or marketing services (e.g. Google Analytics, Meta/Facebook Pixel).

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in improving our online ordering process).

15. Retention Period

Order and invoice data is stored for the duration of the statutory retention periods, in particular 10 years pursuant to § 147 AO and § 257 HGB (German tax/commercial law). After these periods expire, the data is deleted, unless further statutory retention obligations apply.

Van booking for events

16. Van Booking: Data We Collect

We use your data exclusively to process your catering request and contact you about your event.

What data we collect: name, phone number, email address, event address, billing address, number of guests, and the details you give us about your party. For public events, we additionally collect the name and phone number of an on-site responsible person or organization.

What we use it for: to review your booking request, contact you by phone or email, and organize your event. No payment is collected at this stage — we do not collect any payment data here.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures at your request).

17. ZIP Code Lookup and Estimated Driving Time

When you enter the event's postal code, it is transmitted to the external services openplzapi.org and api.zippopotam.us (servers in the USA) to check the distance from our route.

We also estimate the expected driving time to your event address. This calculation is performed by our own, self-hosted routing system on our server — your address is not transmitted to any third party.

Legal basis: Art. 6(1)(b) GDPR.

18. Scheduling via Google Calendar

After your booking is confirmed, our team may enter your data (name, phone number, address, notes) into Google Calendar (Google Ireland Limited, with possible server processing by Google LLC, USA) for internal scheduling. Insofar as this involves a transfer of data to the USA, it relies on the European Commission's adequacy decision of 10 July 2023 on the EU-US Data Privacy Framework (Art. 45 GDPR); Google LLC is certified under this framework.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in organizing your event).

19. Who Has Access & Retention Period

Your request is forwarded internally by email (via our email provider Google/Gmail) to organize your event. No disclosure to other third parties, except the recipients named above (ZIP lookup, Google Calendar).

We keep your data for as long as the request/event is current. If it results in an actual paid booking with an invoice, the statutory retention periods apply (10 years under § 147 AO / § 257 HGB).

Your rights: you may request access, correction, or deletion of your data at any time by contacting us at info@eis-bellacrema.de.

20. No Disclosure to Other Third Parties

Your data is not transferred to any other third parties, except to the recipients named in this policy or where we are legally obliged to do so.

21. Data Security

We use appropriate technical and organizational security measures to protect your data against accidental or intentional manipulation, loss, destruction, or unauthorized access. Transmission is encrypted (SSL/TLS).

22. Changes to This Privacy Policy

We reserve the right to amend this privacy policy so that it always complies with current legal requirements.