Privacy Policy
Last Updated: 24.05.2025
1. Introduction
We take your privacy seriously. This notice describes how we collect, use, and protect your data, in line with the General Data Protection Regulation (GDPR) and international standards where applicable.
2. Controller
Sa-Sa Li Stories - Sandra Mastinggal
Oberföhringer Straße 24, 81925 München
Email: hello@sasali-stories.com
3. What Data We Collect
Contact details (name, address, email)
Order details (shipping address, items purchased)
Payment data (processed externally via PayPal, Stripe, etc.)
4. Why We Process Your Data
To fulfill your order (Art. 6 (1)(b) GDPR)
To comply with legal obligations (e.g. tax law) (Art. 6 (1)(c) GDPR)
To communicate with you
5. International Data Transfers
If you are located outside the EU, your data will be processed on servers in the EU and possibly transferred to third-party providers located outside the EU (e.g., PayPal). These providers comply with GDPR standards via adequacy decisions or standard contractual clauses.
6. Third-Party Services
We share data only with services needed to fulfill orders, such as:
Payment processors (e.g., PayPal, Stripe)
Hosting provider
Shipping partners
These third parties comply with GDPR through data processing agreements.
7. Your Rights
Under the GDPR, you have the right to:
Access your data (Art. 15)
Correct data (Art. 16)
Erase data (Art. 17)
Restrict processing (Art. 18)
Data portability (Art. 20)
Object to processing (Art. 21)
You can contact us at hello@sasali-stories.com to exercise these rights.
8. Retention
We retain personal data for as long as required to fulfill orders and legal obligations (e.g., tax documentation: typically 10 years in Germany).
9. Data Security
Your data is protected via SSL encryption. Our service providers are selected carefully and bound by data protection agreements.
11. Changes to This Policy
We may update this Privacy Policy occasionally. Please check back for the latest version.