Privacy policy

Last updated: September 2026

We process your personal data only to the extent required to run this shop and to handle your orders. This policy describes which data is involved and which rights you have.

Controller

The controller for data processing in this shop is Tobon. The contact details are listed in the imprint.

Visiting the pages

When you visit this shop, the server processes technically necessary access data, in particular IP address, time, requested address and browser identifier. This data is used to deliver the pages and to keep the service secure, for example to fend off attacks. The legal basis is our legitimate interest in secure operation (Art. 6(1)(f) GDPR).

Customer account

If you create a customer account, we store your phone number, your name, your password as a non-reversible hash and the addresses you save. The account is used to assign your orders to you and to show them (Art. 6(1)(b) GDPR).

You can remove your account yourself at any time under “Delete account” in your customer account. Orders remain with the branch as records.

Orders

For an order we process your name, your phone number, the items ordered, the chosen branch, your note and, for a delivery, the delivery address. This data is passed to the till system of the branch that assembles, hands over or delivers your order. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR).

If a customer card of the branch is registered under your phone number, the shop may display its tier and points balance.

Cookies and browser storage

The shop uses only technically necessary cookies and browser storage:

  • kassio_session keeps you signed in after you log in.
  • kassio_device links a cart without an account to your device.
  • kassio_branch remembers the chosen branch.
  • Browser storage holds the chosen appearance (light or dark) and, until you submit it, the draft of your order.

No cookies are set for analytics or advertising, and no third-party content is embedded. The legal basis is Section 25(2) TDDDG in conjunction with Art. 6(1)(b) and (f) GDPR.

Visitor statistics

To learn how the shop is used, we count page views, viewed products, search terms, additions to the cart, the approximate length of a visit, the device type (phone, tablet, computer), the page language and where the visit came from (for example a search engine or a shared link).

  • Nothing is stored on or read from your device for this: no cookie, no browser storage.
  • Your IP address is not stored. Together with the browser identifier it is turned, using a key that changes daily, into a value that groups visits only within the same day. The key is deleted after 30 days; after that the value cannot be linked to anyone.
  • Individual visits are deleted after 30 days. What remains are daily totals with no link to a person; they are passed to the operator's point-of-sale system and deleted after two years.
  • If your browser sends the “Global Privacy Control” or “Do Not Track” signal, nothing is counted.

The legal basis is our legitimate interest in improving the offer (Art. 6(1)(f) GDPR).

Recipients

We do not sell your data. Recipients are the branch that processes your order and technical service providers that operate the shop on our behalf and are bound by our instructions.

Retention period

We keep personal data only as long as it is needed for the purposes described. Order and record data is kept as long as statutory retention obligations apply (Art. 6(1)(c) GDPR).

Your rights

You have the right to access, rectification, erasure and restriction of processing, to data portability, and the right to object to processing based on legitimate interests. Please use the contact details in the imprint. You may also lodge a complaint with a data protection supervisory authority.

Changes

We update this policy when the shop or the legal situation changes. The version published here applies.