This Privacy Policy is issued by Folie Imposée UG (haftungsbeschränkt), Mittenwalderstraße 44, 10961 Berlin, Germany, trading as Moth and Rabbit Perfumes (referred to in this policy as "we," "us," or "the Company"). We are the data controller responsible for your personal data.
This policy applies to all customers worldwide. The rights described below are extended to every customer, regardless of country — customers in the European Union and United Kingdom have these rights as a legal entitlement; for other customers, we apply the same standard as a matter of policy, in addition to whatever rights your own local law provides.
For any question about this policy or your personal data, contact our Privacy Contact at info@moth-rabbit.com.
Identity and contact data — name, billing and delivery address, email address, phone number. Order data — products purchased, order value, payment status. Payment data — handled by our payment processor; we do not store full card details ourselves. Technical data — IP address, browser type, device information, collected automatically when you browse our website. Marketing preferences — whether you have opted in to receive emails from us, and your engagement with those emails.
We process your data to fulfil your order and arrange delivery and returns (performance of our contract with you); to respond to customer service enquiries (performance of our contract / legitimate interest); to send you marketing emails about new fragrances or MAR Diary content (your consent); to prevent fraud and abuse of our returns policy (legitimate interest); to comply with tax, accounting, and commercial record-keeping obligations (legal obligation); and to operate and secure our website (legitimate interest).
For customers in the European Union, each basis above corresponds to a specific Article 6 GDPR legal basis: contract performance (Art. 6(1)(b)), legitimate interest (Art. 6(1)(f)), consent (Art. 6(1)(a)), and legal obligation (Art. 6(1)(c)).
We only send marketing emails if you have given express consent — for example, by opting in at checkout or through a sign-up form. You can withdraw this consent at any time, free of charge, via the unsubscribe link in any marketing email, or by contacting info@moth-rabbit.com. Withdrawing consent does not affect transactional emails relating to an order you have placed.
We share personal data only with the following categories of recipients, and only to the extent necessary for them to provide their service to us: Shopify Inc., which hosts our online store and processes orders on our behalf; payment processors, which handle your payment data directly under PCI-DSS security standards; shipping carriers, to deliver your order and process returns; and our email marketing platform, where you have opted in.
We do not sell your personal data to any third party, and we do not share it for cross-context behavioural advertising.
We may also disclose personal data where required by law, to enforce our Terms of Service, or to protect our rights, property, or safety, or those of our customers.
Some recipients above, including Shopify, may process data outside the European Economic Area (EEA), including in the United States. Where this occurs, the transfer is protected by an appropriate safeguard — an EU adequacy decision, the European Commission's Standard Contractual Clauses, or an equivalent mechanism. You can request details of the specific safeguard used by contacting info@moth-rabbit.com.
Order and invoice data is retained for the period required by German commercial and tax law (generally up to 10 years for accounting records). If you do not withdraw consent, marketing and newsletter data is retained for up to 3 years from your last interaction with us, after which we will either re-confirm your interest or remove you — but if you withdraw consent at any point before then, we stop using your data for marketing immediately, regardless of this 3-year figure. Customer service enquiries are retained for up to 3 years from the end of the year in which your enquiry arose, corresponding to the standard limitation period for civil claims under German law (Sections 195 and 199 of the German Civil Code). Cookies and connection logs are retained only for as long as necessary for the purpose for which each cookie was set, as specified individually in our cookie settings. Other account and browsing data is retained only as long as needed to provide the service, then deleted or anonymised.
We use cookies and similar technologies on our website. Some are strictly necessary for the site to function (e.g. your shopping cart, your session) and do not require consent. Others, such as analytics or marketing cookies, are only set with your prior consent, which you can give or withdraw at any time via the cookie settings on our website.
Providing certain personal data — such as your name, delivery address, and payment details — is necessary to enter into a contract with us. If you do not provide this data, we will not be able to process or ship your order. Providing data for marketing purposes is entirely optional and has no effect on your ability to place an order.
We do not use automated decision-making or profiling that produces legal effects concerning you, or that significantly affects you, without human involvement.
You have the right to know what personal data we hold about you; to correct inaccurate or incomplete data; to delete your data ("right to be forgotten"), subject to our legal retention obligations; to restrict how we process your data in certain circumstances; to object to processing based on legitimate interest, including direct marketing; to receive a copy of your data in a portable, machine-readable format; to withdraw consent at any time, where processing is based on consent; and to non-discrimination — we will not charge you differently or provide a different level of service for exercising any of these rights.
To exercise any of these rights, contact info@moth-rabbit.com. We will respond within one month.
If you are an EU resident, the legal bases above apply under the GDPR (Regulation (EU) 2016/679). Your rights are guaranteed under Articles 15–21 GDPR (access, rectification, erasure, restriction, portability, and objection); the right to withdraw consent is guaranteed under Article 7(3) GDPR.
Right to lodge a complaint: as we are established in Berlin, our lead supervisory authority is the Berliner Beauftragte fĂĽr Datenschutz und Informationsfreiheit (BlnBDI), Alt-Moabit 59-61, 10555 Berlin, Germany. You may also complain to the supervisory authority in your own EU member state of residence.
If you are a UK resident, this policy operates under the UK GDPR and the Data Protection Act 2018, which mirror the rights and bases described above. Where your data is transferred outside the UK, this is protected by the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or an equivalent safeguard.
Right to lodge a complaint: you may contact the Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom.
We extend the rights above to all customers, including California residents, regardless of whether the California Consumer Privacy Act's (CCPA) thresholds for applicability are met. In CCPA terms: we do not sell or share your personal information, and we do not use or disclose sensitive personal information beyond what is necessary to fulfil your order.
Customers in other countries are extended the same rights described above as a matter of policy. Where your local law provides additional or different rights, those rights apply in addition to, and are not limited by, this policy.
Our products and website are not directed at children. We do not knowingly collect personal data from individuals under the age of 16 without parental consent. Placing an order with us also requires the legal capacity to enter into a contract under the law of your country of residence.
We take appropriate technical and organisational measures to protect your personal data against loss, misuse, unauthorised access, disclosure, alteration, or destruction, including encryption of payment data in transit (in line with PCI-DSS requirements) and restricted internal access to personal data. No method of transmission over the internet is completely secure, and we cannot guarantee absolute security.
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Material changes will be highlighted on our website.
Folie Imposée UG (haftungsbeschränkt), trading as Moth and Rabbit Perfumes
MittenwalderstraĂźe 44, 10961 Berlin, Germany
info@moth-rabbit.com