1. Controller
Austin & Gardner GbR (doing business as Republic of Heat), Südostallee 124, 12487 Berlin, Germany.
Contact: contact@republicofheat.com.
This privacy policy covers republicofheat.com and related services (subscriptions, gifts, one-time purchases, events, and the referral program).
2. Data We Collect
- Account data: name, email, delivery address, preferences (e.g., heat level).
- Orders & subscriptions: products, plan, payment status, delivery history.
- Gift subscriptions: purchaser and recipient details plus redemption codes.
- Events: organiser, invited guests, RSVP status, invitation emails.
- Referral program: codes/links, referrer/referee data, UTM parameters, campaign status.
- Waitlists & marketing: email address, interests, language/region.
- Usage data: IP address (shortened/processed), browser type, pages viewed, actions taken.
- Cookies: essential cookies (login, security, cart) and-only with consent-analytics and marketing cookies.
- User content: comments, ratings, reviews.
3. Legal Bases (Art. 6 GDPR)
- Contract (Art. 6(1)(b)): accounts, orders, subscriptions, delivery, gift redemption.
- Consent (Art. 6(1)(a)): analytics & marketing cookies, newsletters, referral cookies.
- Legitimate interests (Art. 6(1)(f)): fraud prevention, service emails, referral tracking, event invitations, product improvements.
- Legal obligation (Art. 6(1)(c)): tax, accounting, and record-keeping duties.
4. Purposes of Processing
- Delivering our services (accounts, orders, deliveries, gifts).
- Managing event invitations and RSVP status (opt-out link in every email).
- Running the referral program (link generation, attribution, abuse prevention).
- Customer.io: transactional emails (order confirmations, shipping updates, price changes) and-only with consent-marketing campaigns.
- Analytics & improvement (usage insights, performance, content).
- Security & fraud prevention (protecting against misuse, ensuring platform integrity).
6. Processors
We share data only with contracted service providers acting on our instructions:
We do not sell data to third parties for advertising.
- Stripe (payment processing).
- Customer.io (email communication).
- Google Analytics (analytics).
- DHL (shipping & tracking).
- Hosting/CDN providers within the EU or other jurisdictions with adequate safeguards.
7. International Transfers
If data is processed outside the EU/EEA, we rely on appropriate safeguards such as Standard Contractual Clauses.
8. Retention
- Accounts & orders: duration of use plus 10 years (statutory retention).
- Subscriptions: duration of the plan plus statutory retention.
- Marketing lists: until you withdraw consent.
- Waitlists: up to 12 months or until you request deletion.
- Referrals: up to 12 months.
- Events: until the event concludes plus a 90-day review period.
- Comments & reviews: until deleted.
- Server logs: 30-90 days for security purposes.
9. Your Rights (GDPR)
To exercise your rights, contact us at contact@republicofheat.com.
- Access, rectification, and erasure of your data.
- Restriction of processing and objection to processing.
- Data portability.
- Withdrawal of consent at any time with future effect.
- Right to lodge a complaint with a supervisory authority.
10. Minors
Our services are intended for adults aged 18+ only.
11. Processing & Location
Processing takes place within the EU/EEA and-where appropriate safeguards exist-in third countries.
12. Changes
We may update this notice. Material updates will be announced on the site or by email.
13. Contact
Email: contact@republicofheat.com.
Controller: Austin & Gardner GbR, Südostallee 124, 12487 Berlin, Germany.
