925 Silver Jewelry

Privacy Policy

Privacy Policy

Last updated: 6 August 2026

1. Controller

The controller responsible for data processing under the General Data Protection Regulation (GDPR) is:

Myon Rox

Frank Lämmerhirt

(artist name: Frank Blum)

Linienstrasse 141

10115 Berlin Germany

Phone: +49 179 5467900

Email: contact@myonrox.com

Below we inform you about the collection and processing of personal data when you use our website www.myonrox.com and when you place an order in our online shop.


2. General Information on Data Processing

2.1 Scope of processing of personal data

We only process personal data of our users to the extent necessary to provide a functioning website and our content and services. Personal data is processed regularly only with the user's consent or on a legal basis (Art. 6(1) GDPR).

2.2 Legal bases

Where we obtain the consent of the data subject for processing operations involving personal data, Art. 6(1)(a) GDPR serves as the legal basis. For processing necessary for the performance of a contract, Art. 6(1)(b) GDPR applies (e.g. order processing). For processing necessary to comply with a legal obligation, Art. 6(1)(c) GDPR applies (e.g. tax retention obligations). Where processing is necessary to safeguard a legitimate interest of ours or of a third party, and this interest is not overridden by the data subject's interests or fundamental rights and freedoms, Art. 6(1)(f) GDPR serves as the legal basis (e.g. fraud prevention, audience measurement).

2.3 Erasure and storage period

Personal data is erased as soon as the purpose of storage no longer applies, unless statutory retention obligations (in particular commercial and tax law retention periods of 6 or 10 years under §§ 257 HGB, 147 AO) prevent erasure.


3. Hosting and Shop System: Shopify

Our online shop is hosted and operated by Shopify International Ltd., Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland ("Shopify"). Shopify processes personal data on our behalf as a processor (Art. 28 GDPR), including data generated through use of our shop such as IP address, technical device and browser data, and order and customer data.

The legal basis is Art. 6(1)(f) GDPR (legitimate interest in providing a stable, secure and performant online shop). A data processing agreement under Art. 28 GDPR is in place with Shopify.

Further information on data protection at Shopify: https://www.shopify.com/legal/privacy

3.1 Server log files

When you visit our website, Shopify automatically collects technical access data (so-called server log files) that your browser automatically transmits to us. This includes:

  • IP address (shortened/anonymised where technically possible)
  • Date and time of the request
  • Browser type and version, operating system used
  • Referrer URL (previously visited page)
  • Requested file, country detection

This data is used to technically operate and secure the website and is not combined with other data sources. The legal basis is Art. 6(1)(f) GDPR.


4. Cookies and Consent Banner (Shopify Consent Banner)

Our website uses cookies. Cookies are small text files stored on your device that store certain information.

On your first visit to our website, you will see a cookie consent banner (Shopify Consent tool). There you can choose which categories of cookies you agree to (e.g. analytics and marketing cookies) and which you decline. Your choice is saved and can be changed at any time via the "Cookie Settings" link in the footer of our website.

We distinguish between the following cookie categories:

  • Strictly necessary cookies: required for the operation of the shop (e.g. shopping cart, login, security). Legal basis: Art. 6(1)(f) GDPR and/or § 25(2) TTDSG. These cookies cannot be disabled.
  • Statistics/analytics cookies: e.g. Google Analytics 4 (see Section 9). Legal basis: your consent, Art. 6(1)(a) GDPR in conjunction with § 25(1) TTDSG.
  • Marketing cookies: e.g. Meta Pixel (see Section 11). Legal basis: your consent, Art. 6(1)(a) GDPR in conjunction with § 25(1) TTDSG.

You may withdraw any consent given at any time, with effect for the future, via the cookie settings.


5. Customer Account

You have the option of creating a customer account in our online shop. In doing so, we collect the following data:

  • Name, address
  • Email address
  • Phone number, if applicable
  • Order history
  • A password chosen by you (stored by us only in encrypted form)

Creating a customer account is voluntary and makes future orders easier. The legal basis is Art. 6(1)(b) GDPR (pre-contractual/contractual measures) and, for accounts maintained without a current order, Art. 6(1)(f) GDPR (legitimate interest in managing customer relationships).

You may view or change your customer account at any time in your account settings, or request its deletion by contacting contact@myonrox.com.


6. Orders / Contract Processing

When you place an order, we collect and process the following data to the extent necessary for the performance of the contract:

  • First and last name
  • Billing and delivery address
  • Email address and, if applicable, phone number
  • Order content (items, quantity, price)
  • Payment information (see Section 8)
  • IP address (for fraud prevention)

This data is processed to process your order, arrange delivery, and, where legally required, for tax and commercial law purposes, and is stored in accordance with statutory retention periods. The legal basis is Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(c) GDPR (statutory retention obligations).

For the purpose of shipping, we pass on the necessary data (name, delivery address, and, where applicable, phone number/email for shipping notifications) to the shipping carrier engaged.


7. Contact Form / Email Contact

If you contact us via our contact form or by email, the data you provide (e.g. name, email address, phone number, message content) will be stored by us for the purpose of processing your enquiry and in case of follow-up questions.

The legal basis is Art. 6(1)(b) GDPR, where the enquiry relates to a contract or pre-contractual measures, and otherwise Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries).

Our contact form is protected against misuse (spam, automated attacks) by hCaptcha. In this process, technical data (including IP address, device and browser information) is transmitted to the hCaptcha operator, Intuition Machines, Inc. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in preventing abuse). Further information: https://www.hcaptcha.com/privacy

We delete data arising from contact requests once processing of the enquiry is complete and no statutory retention obligations apply.


8. Payment Methods

When you place an order, we transmit the data necessary for payment processing (name, billing address, order amount, order number, and, where applicable, account details) to the payment service provider you select. The legal basis is Art. 6(1)(b) GDPR (contract performance).

8.1 Shopify Payments

Payments may be processed via Shopify Payments, a service provided by Shopify International Ltd. (Ireland), using the Stripe infrastructure that technically underpins Shopify Payments. Depending on your chosen payment method, the following payment types are supported:

  • Visa
  • Mastercard
  • Maestro
  • American Express
  • UnionPay
  • Apple Pay
  • Google Pay
  • Bancontact
  • EPS
  • MobilePay
  • BLIK

Payment data you enter (card/account details) is transmitted directly and in encrypted form to the respective payment service provider; we ourselves do not receive or store full card details. Further information: https://www.shopify.com/legal/privacy

8.2 PayPal

If you pay via PayPal, your data (including name, address, order amount) is transmitted to PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg. PayPal's own privacy policy applies: https://www.paypal.com/uk/webapps/mpp/ua/privacy-full

8.3 Apple Pay / Google Pay

When Apple Pay or Google Pay is used as a payment method within Shopify Payments, Apple Inc. and Google Ireland Limited respectively additionally process device and authentication data in accordance with their own privacy policies:

  • Apple: https://www.apple.com/legal/privacy/
  • Google: https://policies.google.com/privacy


9. Google Analytics 4

Subject to your consent, this website uses Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google").

Google Analytics uses cookies or comparable technologies that allow an analysis of your use of our website (e.g. pages visited, time spent, referral source). The information generated is generally transmitted to and processed on a Google server in the EU or the US. IP anonymisation is enabled, meaning your IP address is shortened by Google within the EU/EEA beforehand.

The legal basis is your consent, Art. 6(1)(a) GDPR in conjunction with § 25(1) TTDSG. You may withdraw your consent at any time via our cookie consent banner.

Further information on Google Analytics: https://policies.google.com/privacy


10. Google Tag Manager

Subject to your consent, we use Google Tag Manager, a service provided by Google Ireland Limited. Tag Manager is a solution that allows us to manage website tags (e.g. Google Analytics, Meta Pixel) centrally. Tag Manager itself does not create cookies and does not process personal data — it merely triggers the individual services you have consented to. The separate privacy notices of the respective providers apply to the services embedded via Tag Manager (see Sections 9 and 11).


11. Meta Pixel (Facebook/Instagram)

Subject to your consent, we use the "Meta Pixel" provided by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland ("Meta"). The Meta Pixel enables us to track visitors to our website in order to, for example, display interest-based advertising to you on Instagram or Facebook (remarketing) and measure the effectiveness of our advertising.

In doing so, a connection is established to Meta's servers, and data (including IP address, pages visited) may be transmitted to Meta in the US and linked to any Facebook/Instagram account you may hold. We have no influence over the extent and further use of the data by Meta.

The legal basis is your consent, Art. 6(1)(a) GDPR in conjunction with § 25(1) TTDSG. Further information and opt-out options: https://www.facebook.com/privacy/policy/ and https://www.facebook.com/help/568137493302217


12. Newsletter (Shopify Email)

If you sign up for our newsletter, we use your email address to regularly send you information about our products and offers. We use Shopify Email, a service provided by Shopify International Ltd., to send these emails.

Sign-up takes place via a double opt-in process: after signing up, you will receive a confirmation email in which you must confirm your subscription. You will only receive our newsletter after this confirmation.

The legal basis is your consent, Art. 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future by using the unsubscribe link at the bottom of every newsletter, or by contacting us at contact@myonrox.com. The lawfulness of processing carried out until the withdrawal remains unaffected.


13. International Data Transfers

Some of the service providers we use (in particular Shopify, Google, Meta, PayPal, Apple) also process data outside the EU/EEA, including in the United States. Where data is transferred to third countries without a level of data protection deemed adequate by the European Commission, we ensure that an adequate level of data protection is guaranteed — in particular through:

  • the conclusion of EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) with the respective provider, and/or
  • the provider's certification under the EU-US Data Privacy Framework (where applicable), e.g. for Google and Meta.

You may request a copy of the respective safeguards using the contact details provided in this policy.


14. Your Rights as a Data Subject (GDPR Rights)

You generally have the following rights regarding your personal data stored by us:

  • Right of access (Art. 15 GDPR): You may request information about the personal data we process about you.
  • Right to rectification (Art. 16 GDPR): You may request the correction of inaccurate data or completion of incomplete data.
  • Right to erasure (Art. 17 GDPR): You may request the deletion of your data stored by us, provided no statutory retention obligations apply.
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR): You may object at any time, on grounds relating to your particular situation, to the processing of your data carried out on the basis of Art. 6(1)(f) GDPR; this also applies to profiling based on this provision. You may object to the processing of your data for direct marketing purposes at any time, without giving reasons.
  • Right to withdraw consent (Art. 7(3) GDPR): You may withdraw any consent given at any time, with effect for the future.
  • Right to lodge a complaint with a supervisory authority (Art. 77 GDPR): You have the right to lodge a complaint with a data protection supervisory authority regarding our processing of your personal data.

To exercise your rights, please contact: contact@myonrox.com

The supervisory authority responsible for us is:

Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit) Friedrichstr. 219 10969 Berlin, Germany mailbox@datenschutz-berlin.de


15. Data Security

We use the widely accepted SSL/TLS (Secure Socket Layer/Transport Layer Security) encryption protocol during your website visit, in conjunction with the highest level of encryption supported by your browser. This is generally 256-bit encryption. You can tell whether an individual page of our website is transmitted in encrypted form by the closed padlock or key symbol in your browser's status bar.

We also use appropriate technical and organisational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction, or unauthorised access by third parties. Our security measures are continuously improved in line with technological developments.


16. Currency and Amendment of this Privacy Policy

This privacy policy is currently valid and dated 6 August 2026. As we further develop our website and offerings, or due to changes in legal or regulatory requirements, it may become necessary to amend this privacy policy. The current version of this privacy policy can be accessed and printed at any time on this page.


17. Contact

If you have any questions about data protection, please feel free to contact us at any time:

Myon Rox

Frank Lämmerhirt

Linienstrasse 141

10115 Berlin,

Germany

Email: contact@myonrox.com

Phone: +49 179 5467900