Privacy Policy
Last updated: 25 August 2026
This policy explains what personal data Craftkai collects when you use this website, why we collect it, who we share it with, and the rights you have under the EU General Data Protection Regulation (GDPR), the UK GDPR, the German BDSG and equivalent laws.
1. Controller
The controller responsible for the processing of your personal data is:
Tomoko Engelbart-Igami
IgamiLab
Chausseestraße 41b
10115 Berlin, Deutschland
Email: service@craftkai.com
Phone: 030 3435-9582
VAT ID: DE416555623
We are not required to appoint a Data Protection Officer under Art. 37 GDPR or § 38 BDSG. For all data protection matters please write to service@craftkai.com.
2. What we collect and why
2.1 Browsing the site
Our hosting provider records standard server logs (IP address, user agent, referring URL,
timestamp) for security, abuse prevention and debugging. The site also stores your language
choice and, once you have made one, your cookie decision.
Legal basis: legitimate interests (Art. 6(1)(f) GDPR); for the cookie decision, § 25(2)
TDDDG.
2.2 Shopping cart and checkout
When you add items to your basket we create a cart in Shopify and store the cart identifier and
line items in your browser (localStorage). When you click "Checkout" you are redirected to
Shopify's checkout, where Shopify processes your contact, shipping and payment data.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
2.3 Bookings and orders
Once your payment is confirmed, Shopify notifies our site and we store a record of the booking in our own database. That record contains your name, email address and phone number, your language, the order and payment identifiers, the confirmation code, the workshop or product booked, the session date, the venue address and access instructions, quantity, total and currency, the order status, and the original order data received from Shopify.
We use this record to confirm your booking, to send you the venue details and access
instructions, to send reminders before the session, and to handle cancellations and refunds. The
reminder emails go out up to four times before your session; if you would rather not receive
them, tell us and we will switch them off for your booking. Where the booking concerns a
workshop run by an artisan, we pass on the details that artisan needs to receive you.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR); for the reminders, legitimate
interests in a smooth booking (Art. 6(1)(f) GDPR); retention of the accounting record, legal
obligation (Art. 6(1)(c) GDPR).
2.4 Customer accounts
You can create an account to manage your details and to submit a review. We process your email
address, your name if you give one, a hashed password and session tokens. Password reset and
invitation emails are sent through the systems named in section 4. You can delete your account
at any time by writing to us.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
2.5 Reviews
Reviews can only be written by customers who have actually bought the item or attended the
workshop. Some time after your purchase we send you a single-use invitation link by email. If
you write a review, we store its content together with your account, and we check it before it
appears on the site. Published reviews are visible to everyone, so please do not include
anything in the text you would rather keep private.
Legal basis: legitimate interests in genuine, verified reviews (Art. 6(1)(f) GDPR); the review
itself is published on the basis of your consent (Art. 6(1)(a) GDPR), which you can withdraw at
any time by asking us to remove it.
2.6 Service inquiries (lead form)
When you submit a project inquiry to an artisan we collect your name, email, optional phone,
postcode, project type, budget, timeline and the brief you provide. We share these details with
the chosen artisan so they can reply to you, and we keep a record of the inquiry and its status
so we can follow it up. Where that artisan is based in Japan, your data is transferred outside
the EEA; see section 6.
Legal basis: consent (Art. 6(1)(a) GDPR) and pre-contractual measures taken at your request
(Art. 6(1)(b) GDPR).
2.7 Newsletter
If you subscribe to the Craftkai newsletter we store your email address, the interests you select, the point on the site where you signed up, your language, your consent flags and the time of your consent. We do not record your IP address. You can unsubscribe at any time, either through the link in every newsletter or by writing to us.
The newsletter is compiled and sent by us, using the email infrastructure of our provider INWX
(see section 4), whose servers are located in Germany. We do not use an external newsletter
platform, and we do not track whether you open an email or click a link in it.
Legal basis: consent (Art. 6(1)(a) GDPR); for the consent record, legitimate interests
(Art. 6(1)(f) GDPR).
2.8 Contacting us
If you contact us by email or phone, we process the details you provide in order to answer your
enquiry. If you contact us through WhatsApp, LINE or Instagram, the operator of that service
processes your message and your account data under its own privacy policy and as an independent
controller. We have no influence over that processing. If you would prefer not to use those
services, please write to us by email instead.
Legal basis: pre-contractual measures or performance of a contract (Art. 6(1)(b) GDPR) and
legitimate interests in responding (Art. 6(1)(f) GDPR).
2.9 Analytics
With your consent, we use PostHog (hosted in the EU) to understand how the site is used:
pageviews, clicks, navigation patterns and basic device information. The data is held under a
randomly generated identifier rather than your name, and we make no attempt to link it back to
you. The tracker only starts
after you have accepted; if you decline, it is shut down and no analytics data is collected. We
do not use this for advertising or profiling and the data is not sold. Your decision is stored
for twelve months and you can change it at any time via the "Cookie settings" link in the
footer.
Legal basis: consent (Art. 6(1)(a) GDPR), and § 25(1) TDDDG for the storage of and access
to information on your device.
2.10 Content loaded from other companies
Some elements of this site are delivered by other companies. When your browser loads them, your IP address is transmitted to that company, which is technically necessary for the content to reach you.
- Google Ireland Limited: the typefaces used across this site are loaded from Google's font servers (fonts.googleapis.com and fonts.gstatic.com). This happens as the page loads, so it takes place before you have made any cookie choice. Google receives your IP address and information about your browser. Google states that this data is used to deliver the fonts and is not used to identify you or to build an advertising profile. Google may process the request outside the EEA, including in the United States; see section 6.
- Shopify: product and workshop images, and the live availability of places, are loaded from Shopify's content delivery network.
- Open-Meteo: for a small number of workshop locations, the coordinates for our map are looked up through the Open-Meteo geocoding service. Only the place name is sent; no data about you is transmitted apart from the technically unavoidable connection data.
- YouTube and Vimeo: where an article or workshop page includes a video, the player is embedded from that platform. The embed only loads on pages that actually contain a video.
Legal basis: legitimate interests in presenting the site as intended (Art. 6(1)(f) GDPR).
Our own map is drawn by us and does not use Google Maps or any comparable service.
2.11 Administrative access
Our own staff and invited editors sign in to an administrative area. We process email, hashed
password, session tokens, assigned role, and for invitations a single-use token and its expiry
date.
Legal basis: legitimate interests (Art. 6(1)(f) GDPR); for invited external contributors, the
performance of our contract with them (Art. 6(1)(b) GDPR).
3. Is providing data mandatory?
You are not legally or contractually obliged to provide personal data. However, without the data marked as required in a given form we cannot process your order, confirm your booking, forward your inquiry to an artisan, or send you the newsletter.
4. Recipients and processors
We use the following processors. Each has signed a Data Processing Agreement covering Art. 28 GDPR obligations.
- Lovable: application hosting and delivery.
- Supabase: database, authentication, file storage. Data residency: West EU (Irland).
- PostHog: analytics. Region: EU (eu.i.posthog.com).
- Shopify Inc.: cart, checkout, payment and order fulfilment. Headquartered in Canada with infrastructure in Canada and the United States.
- INWX GmbH & Co. KG, Berlin: domain services and email hosting, including our own email correspondence and the newsletter dispatch. Servers in Germany.
The automated emails around your booking, your confirmation, the reminders before your session and the review invitation, are generated by an automation service we operate ourselves on our own infrastructure in Frankfurt, Germany, and are delivered through the mail infrastructure named above. They are not passed to any third-party marketing platform.
Payments are handled in Shopify's checkout by the payment method you choose, currently card payment and PayPal. The payment provider processes your payment data as an independent controller under its own privacy policy.
Beyond these processors, we pass the content of a service inquiry to the artisan you have selected, and the details needed to receive you to the artisan running a workshop you have booked. Those artisans act as independent controllers for what they then do with your data. We disclose data to public authorities only where we are legally required to do so.
5. No sale of personal data
We do not sell your personal data, we do not pass it to advertising networks, and we do not use it to build profiles about you. This site carries no advertising pixels and no chat widgets.
6. International data transfers
Some of our processors, notably Shopify, process data outside the EEA. Transfers to Canada are covered by the European Commission's adequacy decision. Transfers to the United States are covered by the EU-U.S. Data Privacy Framework where the recipient is certified, and otherwise by Standard Contractual Clauses with supplementary measures. The same applies to the delivery of typefaces by Google. Transfers to artisans and partners in Japan are covered by the European Commission's adequacy decision for Japan.
7. Retention
- Booking and order records: retained for the duration of the booking and then for as long as German commercial and tax law requires, up to 10 years under § 147 AO.
- Customer accounts: until you delete the account or ask us to.
- Reviews: until you ask us to remove the review or delete your account.
- Service leads: kept for 24 months after last contact, then deleted.
- Newsletter data: until you unsubscribe; the consent record for a further three years.
- Analytics events: 12 months.
- Sessions and invitation tokens: lifetime of the session, or the expiry date of the invitation.
- Server logs: 7 days.
8. Your rights
You have the right to:
- Access the personal data we hold about you (Art. 15 GDPR).
- Have inaccurate data corrected (Art. 16 GDPR).
- Have your data erased (Art. 17 GDPR).
- Restrict processing (Art. 18 GDPR).
- Receive your data in a portable format (Art. 20 GDPR).
- Object to processing based on legitimate interests (Art. 21 GDPR).
- Withdraw consent at any time, without affecting prior processing (Art. 7(3) GDPR).
To exercise any of these rights please contact us at service@craftkai.com. We will respond within one month.
You also have the right to lodge a complaint with a supervisory authority. The authority responsible for us is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59-61, 10555 Berlin
www.datenschutz-berlin.de
9. Automated decision-making
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.
10. Cookies and similar technologies
For a full inventory of cookies and browser storage used on this site, see our Cookie Policy.
11. Security
We use HTTPS in transit, row-level security on our database, role-gated administrative access, encrypted storage of third-party access tokens, signature verification on incoming order webhooks, and industry-standard password hashing. Despite reasonable measures, no online service can be guaranteed fully secure.
12. Children
Craftkai is not directed at children under 16. We do not knowingly collect personal data from minors. If you believe we have, please contact us so we can delete it.
13. Changes to this policy
We update this policy when our processing changes. The "last updated" date at the top reflects the most recent revision. Material changes will be flagged on the site.