Privacy Policy
Last updated: 2/13/2026
Controller
The controller responsible for data processing on this website is [PARTNER GMBH NAME].
[PARTNER GMBH NAME]
[STRASSE HAUSNUMMER]
[PLZ] [STADT]
hello@pxltshirt.com
Data we collect
Image data
- Uploaded images are processed to generate pixel art.
- Images are stored temporarily for processing.
- Generated pixel art is stored for your order.
Order data
- Name, address, and email for shipping.
- Payment information is processed by our payment provider.
Technical data
- IP address for rate limiting, fraud prevention, and security audits.
- Browser and device information for session management.
- Cookies (essential only) for user sessions (no tracking cookies).
Email verification
- When placing a pre-order without being logged in, we send a verification email (Double-Opt-In).
- Verification tokens are stored for up to 30 minutes until confirmed.
- IP address and browser info are logged with verification requests for security.
Legal basis
- Performance of a contract (processing orders).
- Legitimate interest (security and improvement).
- Consent (marketing and optional cookies).
Your rights
- Right to access your data.
- Right to correction or deletion.
- Right to withdraw consent.
Contact us at hello@pxltshirt.com to exercise your rights.
Data sharing
- **Hetzner Cloud** (Germany): Hosting and infrastructure for website and databases
- **Google Cloud** (USA/SCC): Gemini 2.0 Flash (image analysis) and Imagen 4.0 (pixel art generation)
- **PixLab** (USA/SCC): AI-powered background removal and image optimization (optional, can be disabled)
- **Local Server Storage** (Germany): All images stored on our Hetzner server
- **Stripe** (USA/EU): Payment processing and secure card data handling
- **United Domains** (Germany): Email delivery via SMTP
- **Print-on-Demand Provider**: Shipping provider for physical products
We do not sell your personal data. All data transfers to the USA are protected by EU Commission Standard Contractual Clauses (SCCs).
AI processing
- We use AI to generate pixel art from your images.
- Images are processed by third-party AI providers (Google Cloud for generation, optionally PixLab for background removal).
- Data sent to AI providers is used only for processing and is not stored permanently.
- Background removal can alternatively be performed locally in your browser without sending data to external servers.
Security
- We use SSL encryption.
- Access controls are in place.
- Regular security audits.
Cookies
We use cookies to ensure the website functions properly and to analyze traffic.
Data retention
- Order data: 10 years (German tax law requirement).
- User profiles and pixel art: 90 days of inactivity, then deleted with 7 days warning email.
- Anonymous/unselected images: 3 days, then automatically deleted.
- Session data: 24 hours (anonymous) / 30 days (logged in with 'Remember Me').
- Email verification tokens: 30 minutes.
- Account restoration: You can restore your account within 30 days after deletion using your restore token.
- Data export: Before deletion, you receive an export package with all your data (pixel arts, orders, profile).
International data transfers
- Data may be processed outside the EU/EEA (Google Cloud, Cloudflare, Stripe).
- We use EU-approved Standard Contractual Clauses (SCCs) to protect your data.
- Technical measures: TLS encryption during transmission and storage.
- Google Cloud and Cloudflare comply with EU-U.S. Data Privacy Framework where applicable.
- Your data is used only to fulfill the service (image generation, storage, shipping).
Children
Our service is not directed to children under 16.
Changes to policy
We may update this policy from time to time.
Contact
[PARTNER GMBH NAME]
[STRASSE HAUSNUMMER]
[PLZ] [STADT], Germany
Email: hello@pxltshirt.com
Complaints
- You have the right to lodge a complaint with a supervisory authority.
Creator rewards
If you participate in our creator reward program:
- We track sales of your designs.
- We issue vouchers based on sales.
Data processed
- Sales data linked to your account.
- Voucher codes issued.
Processing is based on the performance of the reward program contract.