1. Who we are
TouchCard is operated as an Einzelunternehmen (sole proprietorship), based in Germany. We sell personalised Braille birthday cards online and ship across Europe.
Contact: hello@touchcard.eu
2. What data we collect
We collect the minimum data needed to fulfil your order:
- Order data: Your name, recipient's name, delivery address, email address.
- Custom message text: The personal message you write for the card. We ask you not to include sensitive personal information (e.g. health, religion, sexual orientation) unless necessary. We process the message only to produce your card and delete it within 60 days of fulfilment.
- Newsletter: Your email address if you opt in to receive notifications about new card designs.
- Analytics: Anonymous page visit data via Cloudflare Web Analytics (no cookies, no personal data, no tracking across sites).
- Cookie preference: Your accept/decline choice is stored locally in your browser (localStorage).
3. Legal basis for processing
- Order fulfilment (name, address, message text): Art. 6(1)(b) GDPR โ necessary for performance of the contract.
- Sensitive data (Art. 9 GDPR), if voluntarily included in the message: Art. 9(2)(a) GDPR โ explicit consent (which you give via the checkbox at checkout).
- Newsletter: Art. 6(1)(a) GDPR โ consent (revocable at any time).
- Tax records: Art. 6(1)(c) GDPR โ legal obligation (German tax law).
4. How we use your data
- To produce and ship your Braille card.
- To transmit your custom message text to our production partner in the EU for Braille production (under a Data Processing Agreement, Art. 28 GDPR).
- To send order confirmation and dispatch notifications by email.
- To send occasional newsletter emails about new designs (only if you subscribed โ you can unsubscribe at any time).
- To understand how visitors use our website (aggregate, anonymous analytics only).
5. Who we share data with
We do not sell your data. We share data only with:
- Production partner (EU): Your custom message text and recipient address are transmitted to our production facility within the EU for Braille printing. This is an intra-EU transfer (no third-country transfer). A Data Processing Agreement (Art. 28 GDPR) governs this relationship.
- Postal services: Delivery address to ship your card.
- Payment providers: Stripe (when enabled) processes payment details โ we never see or store your card number.
- Cloudflare: Hosts our website and provides anonymous analytics.
6. How long we keep data
- Invoice and transaction data (name, address, payment evidence): Retained for up to 10 years as required by German commercial and tax law (HGB / AO).
- Custom message text: Permanently deleted within 60 days after order fulfilment. We do not retain your personal message longer than necessary.
- Newsletter emails: Until you unsubscribe.
- Analytics: Aggregated, anonymous โ no personal data stored.
7. Your rights (GDPR)
Under EU data protection law, you have the right to:
- Access โ request a copy of your personal data.
- Correction โ ask us to fix inaccurate data.
- Deletion โ ask us to delete your data ("right to be forgotten").
- Portability โ receive your data in a machine-readable format.
- Withdraw consent โ unsubscribe from newsletter or withdraw cookie consent at any time.
To exercise any of these rights, email hello@touchcard.eu. We'll respond within 30 days.
8. Cookies
We use no third-party tracking cookies. The only data stored in your browser is:
- Your cookie consent preference (localStorage).
- Newsletter subscription data if the backend is unavailable (localStorage fallback).
Cloudflare Web Analytics does not use cookies and does not track individual users.
9. Right of withdrawal (Widerrufsrecht)
Under EU consumer protection law, you generally have a 14-day right to withdraw from a distance purchase. However, personalised goods are exempt from this right under ยง312g Abs. 2 Nr. 1 BGB (German Civil Code) and EU Directive 2011/83/EU Article 16(c).
Because each TouchCard carries a unique Braille message that permanently alters the card and cannot be reversed or resold, the right of withdrawal does not apply to our personalised Braille cards. You will be clearly informed of this exemption on the product page and before completing your purchase.
If you receive a defective product (e.g. incorrect Braille, damaged in transit, production error), your normal warranty rights apply and we will replace it free of charge.
10. Consumer dispute resolution
We are not obliged and not willing to participate in dispute settlement proceedings before a consumer arbitration board (Verbraucherschlichtungsstelle) within the meaning of the German Consumer Dispute Resolution Act (VSBG).
11. Security
Our website is served over HTTPS via Cloudflare. Payment processing (when enabled) is handled by Stripe, which is PCI DSS Level 1 certified. We never store credit card details on our servers.
12. Changes to this policy
If we make significant changes to this policy, we'll update the date below and, where appropriate, notify existing customers by email.
Last updated: May 2026