Skip to main content

Information pursuant to Art. 13 GDPR

Privacy Policy

Last updated: September 2026

Protecting your personal data matters to us. Below we explain which data we process when you visit this website or use our contact forms, for what purpose, and what rights you have.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Maker Studio UG (haftungsbeschränkt)
Druffeler Straße 6, 33397 Rietberg, Germany

Email: support@maker-studio.io
Phone: +49 163 2208155

We are not legally required to appoint a data protection officer. If you have any questions about data protection, you can reach us at any time using the contact details above.

2. Principles of processing

Personal data is any information relating to an identifiable natural person. We process such data exclusively on the basis of applicable data protection law, in particular the GDPR and the German Federal Data Protection Act (BDSG).

Depending on the processing, the legal basis is your consent (Art. 6(1)(a) GDPR), the performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR), compliance with legal obligations (Art. 6(1)(c) GDPR), or our legitimate interest in operating this website securely and effectively (Art. 6(1)(f) GDPR).

Providing your data is voluntary. However, without the information marked as required in our forms we cannot process your request.

3. Hosting and server log files

This website is operated by an external service provider (host) that makes it available on its servers on our behalf. A data processing agreement pursuant to Art. 28 GDPR is in place with the host.

When you open a page, your browser transmits technically necessary data that is stored in server log files: IP address, date and time of access, page requested, amount of data transferred, referrer URL, and browser and operating system identifiers.

This data serves stable operation, error analysis and the prevention of attacks. The legal basis is Art. 6(1)(f) GDPR. Log files are deleted after a short period unless they are needed to investigate a security incident.

4. Contact forms and project inquiries

Two forms are available on this website: the general project inquiry and the Shopify migration request. When you submit a form, we process the data you have entered.

We process your name, email address, optionally your phone number and company, and your project details – for project inquiries the project type, short and long description and budget range; for migration requests the store URL, source platform, number of products and orders, requested add-ons and notes on plugins. We also store the subpage the request was sent from and the language you selected.

The purpose of processing is to handle your request and prepare a possible contractual relationship. The legal basis is Art. 6(1)(b) GDPR, and for purely informational requests additionally Art. 6(1)(f) GDPR.

To protect against automated spam submissions we use an invisible form field (honeypot) and a limit on requests per IP address. The IP address is only processed briefly in memory for this purpose and is not stored permanently. The legal basis is Art. 6(1)(f) GDPR.

We store your request for as long as it is required to process it. If no contract is concluded, we generally delete the data after six months at the latest. Statutory retention periods under commercial and tax law remain unaffected.

5. Email delivery

Form submissions are forwarded to us by email. At the same time you receive an automatic confirmation at the email address you provided. Delivery takes place via the SMTP server of our email provider.

Our email provider processes sender and recipient data as well as the content of the message on our behalf; a data processing agreement is in place. The legal basis is Art. 6(1)(b) and (f) GDPR.

Email communication may have security vulnerabilities. Complete protection of data against access by third parties is not possible with unencrypted email.

6. Performance measurement (RUM)

To measure the technical performance of our website we use a self-operated analytics script loaded from dashboard.maker-studio.io/rum.js. The measurements are transmitted to an endpoint we operate at Supabase and stored there.

We collect technical metrics such as load times and Web Vitals values, the page requested, referrer, browser and device type, and a coarse geographic classification. We use this data in aggregated form only, to improve speed and stability. No cross-site tracking or profiling takes place, and we do not use cookies for this purpose.

The legal basis is our legitimate interest in a technically sound and fast website pursuant to Art. 6(1)(f) GDPR.

The service provider operating the measurement endpoint is Supabase. Any transfer to third countries takes place only on the basis of appropriate safeguards, in particular the European Commission's standard contractual clauses pursuant to Art. 46 GDPR.

7. Cookies and local storage

We do not use cookies for advertising or tracking purposes. Technically necessary information such as the selected language version is represented in the URL and handled by our language routing.

Fonts and media are served from our own server. Google Fonts and comparable services are not embedded.

8. External links and embedded content

Our website links to external offerings, including the Apple App Store, Google Play, reference stores and social network profiles. Data is only transmitted to the respective provider once you click such a link. The respective provider is solely responsible for data processing on linked pages.

9. Recipients and transfers to third countries

We only share personal data where this is necessary to perform a contract, where you have consented, where a legal obligation applies, or where we engage service providers as processors. These include our host, our email provider and the provider of our measurement endpoint.

If data is transferred to countries outside the EU or EEA, we ensure an adequate level of data protection through appropriate safeguards pursuant to Art. 44 et seq. GDPR. We do not sell personal data.

10. Data security

This website is served exclusively over an encrypted connection (TLS/HTTPS). The data you send us is therefore protected against access by third parties in transit. In addition, we take technical and organisational measures to protect your data against loss, manipulation and unauthorised access.

11. Your rights

As a data subject you have the following rights under the GDPR:

  • Access to the data stored about you (Art. 15 GDPR)
  • Rectification of inaccurate or incomplete data (Art. 16 GDPR)
  • Erasure of your data, unless retention obligations apply (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability in a structured, commonly used format (Art. 20 GDPR)
  • Objection to processing based on a legitimate interest (Art. 21 GDPR)
  • Withdrawal of consent with effect for the future (Art. 7(3) GDPR)

A message to support@maker-studio.io is sufficient to exercise your rights.

12. Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint about the processing of your data with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.

13. Changes to this privacy policy

We update this privacy policy when the legal situation, our services or our data processing change. The version published on this page applies.

To the legal notice