Last updated: 7 September 2026
This notice explains how personal data is processed when you visit The Remaining Ember, contact us, make a voluntary support payment, subscribe to article notifications, exercise withdrawal rights, or order physical goods. We do not offer customer accounts or a general marketing newsletter.
1. Controller and privacy contact
Jesse Daniel Hotchkin, trading as The Remaining Ember
Brunnhölzl 2
4873 Frankenburg
Austria
Email: [email protected]
Telephone: +43 681 20617419
2. Website delivery, logs, and security
When the site is requested, our hosting and delivery systems process the IP address, request time, requested URL, referrer, browser/user-agent information, response status, and security or error information. This is necessary to deliver the site and to identify faults, attacks, and misuse. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are reliable website operation, IT security, abuse prevention, and the investigation and defence of legal claims.
Recipients are Hetzner Online GmbH (application and database hosting) and Cloudflare, Inc. and its group or subprocessors (DNS, content delivery, network security, tunnel/email-routing infrastructure, and Turnstile). Routine technical logs are rotated when they are no longer required for operations or security; records needed to investigate a specific incident may be kept until the incident and any resulting claims are resolved.
Some public submission forms, including contact, checkout, and support-payment forms, use Cloudflare Turnstile. Cloudflare receives the challenge token and technical request data, including the IP address supplied for validation. The purpose is bot and abuse prevention, based on Article 6(1)(f) GDPR and our legitimate interest in protecting the shop and its users. Our database stores only a keyed hash of the identity used for application rate limiting; those rate-limit records are deleted after no more than 48 hours.
3. Contact messages and withdrawal requests
If you contact us, we process your name, email address, subject, message, optional attachments, technical routing information, and any order information you include. We use this data to answer and administer the inquiry. For pre-contractual or contract-related inquiries the basis is Article 6(1)(b) GDPR; for other inquiries it is Article 6(1)(f) GDPR, based on our legitimate interest in communicating with people who contact the business and documenting that communication.
For an online withdrawal declaration, we process your name, email, order identifier, withdrawal scope and item details, submission time, status, and confirmation-delivery record. The bases are Article 6(1)(b) and (c) GDPR: processing the contract and complying with consumer-law duties. Required withdrawal fields are necessary to identify, record, and confirm the declaration; without them, the online form cannot be submitted, although you may still use another legally permitted method to withdraw.
Contact and withdrawal email passes through Cloudflare Email Routing and our configured encrypted SMTP relay (currently Sendinblue SAS, trading as Brevo). It is also stored in the shop's Hetzner-hosted inbox. Ordinary inquiries are deleted when resolved and no longer needed, normally within three years after the end of the conversation. Contract, complaint, withdrawal, or accounting correspondence is retained with the corresponding transaction for the period stated below, or longer where a pending claim or legal duty requires it.
Email address, subject, and message are required to submit the website contact form so that we can understand and answer the inquiry. If they are not supplied, the form cannot be submitted; you may instead contact us by another listed method. Information beyond those fields is voluntary unless it is needed for the specific request.
4. Article notifications
If you request article notifications, we process your email address, subscription status, consent-notice version, request and confirmation times, the article from which you subscribed, and confirmation and delivery records. We first send a confirmation link and activate the subscription only after that link is used. The purpose is limited to one notification when a new public article is first published; it is not used for shop promotions or a general newsletter.
The basis is your consent under Article 6(1)(a) GDPR and the applicable electronic-communications rules. You may withdraw consent at any time using the unsubscribe link in every notification or by contacting us. Refusal or withdrawal has no effect on access to the website or shop. Confirmation and notification email is delivered through our configured encrypted SMTP relay, currently Sendinblue SAS, trading as Brevo.
4a. One-time purchasing-availability reminders
If you ask to be told when purchasing becomes available, we process your email address, the shop page from which you made the request, subscription status, consent-notice version, request and confirmation times, and confirmation and delivery records. We activate the request only after you use the emailed confirmation link. The address is used for one purchasing-availability email only, not for article notifications, newsletters, or other promotional email. The opening email is queued by an administrator only after purchasing is available; changing the shop's environment setting does not send it automatically.
The basis is your consent under Article 6(1)(a) GDPR and the applicable electronic-communications rules. You may cancel at any time using the link supplied in the emails or by contacting us. Refusal or cancellation has no effect on access to the website or shop. Email is delivered through our configured encrypted SMTP relay, currently Sendinblue SAS, trading as Brevo.
5. Product orders and contract records
At checkout we process the customer name, email address, contact and delivery address, country, cart contents, prices, taxes, shipping method, order and payment identifiers, payment status, shipment and tracking data, accepted legal-content version, and an order-time contract snapshot. The purposes are checkout, contract formation, payment, delivery, customer service, refunds, complaints, recalls, accounting, and proof of the transaction.
Article 6(1)(b) GDPR is the basis for steps requested before the contract and performance of the contract. Article 6(1)(c) GDPR is the basis for tax, accounting, consumer-protection, product-safety, and other mandatory records. Article 6(1)(f) GDPR applies where records are needed to prevent fraud or establish, exercise, or defend legal claims; those are our legitimate interests.
The name, email, contact/delivery address, country, and payment are required to accept, document, and fulfil an order. The address and contact details are also prefilled into Stripe's billing-details form for you to review. If required information is not supplied, we cannot conclude or fulfil the order.
6. Payments
Product orders accept credit and debit cards through Stripe Payments Europe, Limited, Stripe Technology Europe, Limited, and relevant Stripe group companies. Stripe receives the payment details entered into its Payment Element, plus transaction amount, currency, order/payment reference, customer contact and billing information, device data, and fraud-prevention signals. We receive payment status, limited card information such as brand and last digits where returned, and provider identifiers—not the full card number or security code. The bases are Article 6(1)(b) GDPR for payment performance, Article 6(1)(c) GDPR for financial records, and Article 6(1)(f) GDPR for payment security and fraud prevention.
Separately labelled voluntary support offerings may use Stripe or, only when that option is configured, PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg. For those payments we may retain the supporter name, email, country, amount, currency, status, provider IDs, and refund/accounting data returned by the provider. PayPal is not a payment method for product orders. The selected payment provider also processes data under its own legal duties and privacy notice.
Provider details: Stripe privacy notice and PayPal privacy notice.
7. Delivery
To deliver an order, we disclose the recipient name and address, parcel and tracking details, and—only when required for delivery notifications—the email address to the selected carrier. The basis is Article 6(1)(b) GDPR. The carriers used are GLS or Österreichische Post AG for Austria and UPS for Great Britain. Carrier tracking data is retained with the order for fulfilment, complaints, and proof of delivery, subject to the order-retention period below. Each carrier processes delivery data under its own legal obligations and privacy notice.
8. First-party shop analytics
We operate cookieless analytics in our own Hetzner-hosted database to understand shop use and improve navigation, inventory, and checkout. Events can include page views, cart changes, checkout starts, payment confirmation, checkout errors, stock friction, outbound clicks, and product-media interactions. Records can contain the page path without query parameters, event time and type, product/category, quantity or amount, referring/destination host, campaign fields, approximate viewport, browser language, page title, checkout country, and a coarse country/region derived from the request.
The analytics table does not store the IP address, user-agent string, advertising identifier, or an analytics cookie. The basis is Article 6(1)(f) GDPR. Our legitimate interests are measuring whether the shop works, identifying usability or stock problems, and improving it without cross-site profiling. Global Privacy Control and Do Not Track signals suppress these optional events. Analytics events are automatically deleted after 180 days. You may object at any time using the contact details above.
9. Optional marketing analytics
Google Analytics, Meta Pixel, and TikTok Pixel are currently disabled. No optional third-party marketing analytics script is loaded and no marketing-analytics consent cookie is set. If one is enabled later, this notice will identify the active provider and a consent banner will appear before its script can load.
10. Cookies and local browser storage
The public shop stores cart contents and the visual theme locally in your browser so that the requested functions persist between pages and visits. Withdrawal review uses a short-lived, secure anti-forgery cookie and signed review data that expire after about one hour. Turnstile may use storage strictly necessary for security. These technologies are used to provide requested functions or protect the service, not for advertising. Local data remains until it expires, is replaced, or you clear it in your browser. If optional marketing analytics is active, its separate consent choice is retained for 180 days as described above.
11. Recipients and processors
Personal data is disclosed only where necessary to the following recipients or categories:
- Hetzner Online GmbH for application, database, storage, and infrastructure hosting;
- Cloudflare, Inc. and relevant subprocessors for DNS, network delivery/security, Turnstile, tunnel, and inbound email routing;
- our encrypted SMTP relay, currently Sendinblue SAS, trading as Brevo, for transactional, contact, subscription-confirmation, article-notification, and one-time purchasing-availability email;
- Stripe and, for a separately selected support offering only, PayPal, for payments, fraud prevention, refunds, and payment records;
- GLS, Österreichische Post AG, or UPS, according to the delivery method and destination;
- tax advisers, accountants, banks, insurers, legal advisers, courts, authorities, or enforcement bodies where required for professional services, compliance, or claims; and
- the active consent-based analytics providers identified in section 9, if any.
We do not sell personal data.
12. Processing outside the EEA
We prefer processing in the European Economic Area, but the global services below can involve access or onward processing in the United States or other countries. The applicable safeguards are:
- Cloudflare: Cloudflare states that covered transfers to the United States rely on its EU–US Data Privacy Framework certification and that its customer data-processing terms provide the applicable contractual safeguards for processor data.
- Stripe: the Austrian service agreement involves the Irish Stripe entities named above. Restricted onward transfers by Stripe are governed by an applicable adequacy framework, including the EU–US Data Privacy Framework where the receiving entity and data are covered, or the European Commission's Standard Contractual Clauses under Stripe's data-processing terms.
- PayPal: PayPal (Europe) S.à r.l. et Cie, S.C.A. states that intra-group transfers rely on approved Binding Corporate Rules and that other non-adequate-country transfers use Standard Contractual Clauses or another lawful GDPR mechanism.
- Brevo: Sendinblue SAS is established in France. Where its subprocessors process data in a country without an adequacy decision, the accepted Brevo data-processing terms must provide Standard Contractual Clauses and any required supplementary measures.
The provider-specific notices linked above contain further details. You may request information about the mechanism relevant to your data and a copy of the safeguards from us; protected commercial or security information may be redacted.
13. Retention
- Orders, invoices, payments, and accounting evidence: seven years from the end of the relevant calendar year under Austrian tax-record rules, and longer only while required for a pending tax matter, recall, or legal claim.
- Contract and withdrawal evidence: retained with the relevant order for the applicable statutory and claims periods.
- Ordinary contact inquiries: until resolved and normally no more than three years after the conversation ends, unless the message belongs to a transaction or claim with a longer period.
- Article notifications: unconfirmed requests are deleted after seven days; active subscription data is kept until you unsubscribe; consent and delivery evidence is then retained for no more than three years to demonstrate compliance and handle claims.
- Purchasing-availability reminders: unconfirmed requests are deleted after seven days; confirmed requests are kept until the one-time notice is sent or you cancel; consent and delivery evidence is then retained for no more than three years.
- First-party analytics: no more than 180 days.
- Application abuse-limit records: no more than 48 hours.
- Local cart/theme data: until replaced or cleared in your browser; optional marketing consent, if used, lasts 180 days.
- Routine technical logs: until no longer needed for operations and security; incident records may remain until the incident and related claims are resolved.
When a record is due for deletion, it is also removed from backups as those protected backup sets rotate. Data restored temporarily for disaster recovery remains subject to the same deletion rule. Providers apply their own retention periods to data they process as independent controllers.
14. Automated decisions
We do not make our own decisions based solely on automated processing that produce legal or similarly significant effects. Payment providers may use automated fraud, authentication, and risk checks under their own legal responsibilities; a payment can be declined or require additional authentication. Their notices explain those systems and the available review or contact routes.
15. Your rights
Subject to the GDPR's conditions and exceptions, you may request access, rectification, erasure, restriction, data portability, or object to processing based on Article 6(1)(f). Where processing is based on consent, you may withdraw it at any time without affecting processing already carried out lawfully. You may also complain to a supervisory authority. To exercise a right, email [email protected]. We may need information to verify your identity and locate the relevant records.
16. Complaint to the Austrian Data Protection Authority
Österreichische Datenschutzbehörde
Barichgasse 40–42
1030 Vienna, Austria
Email: [email protected]
Website: dsb.gv.at
17. Changes to this notice
We update this notice when the shop's processing, recipients, or legal requirements change. The date at the top identifies the published version. Material changes apply prospectively and, where consent is required, will not take effect for that processing without a valid choice.