German specialistFree standard shippingFast delivery20,000+ repairs · 10,000+ reviews
Airbag24

Privacy Policy

Last updated: September 2026

1. Data protection at a glance

This notice explains which personal data we process when operating the shop, and in connection with orders, repair orders and enquiries. Personal data is any information that can be used to identify you, directly or indirectly.

We process technical data required for secure operation of the shop, as well as data you provide to us when making a purchase, placing a repair order, uploading a file, contacting us or registering. Browser-based usage analytics and marketing are only carried out with your voluntary consent.

2. Controller

Adam Wotzka
AIRBAG24 Airbagsysteme
Schönefelder Chaussee 73
12524 Berlin
Germany

Phone: +49 30 75655671
E-mail: info@airbag24.de

3. Hosting, database and delivery

Render

The storefront, shop backend and internal services are operated on Render. Render processes, in particular, IP address, time of access, the URL accessed, technical request and error data, and the content transmitted for the application. This processing serves the secure and reliable provision of our online offering on the basis of Article 6(1)(f) GDPR and, to the extent necessary for the performance of a contract, Article 6(1)(b) GDPR.

Privacy notice: https://render.com/privacy

Supabase

We use Supabase for our PostgreSQL database and S3-compatible file storage. Depending on the operation, this includes customer, order, repair, communication and upload data. Production resources are operated in a European region. The legal basis is Article 6(1)(b) GDPR for contractual and pre-contractual data, and Article 6(1)(f) GDPR for secure operation.

Privacy notice: https://supabase.com/privacy

Cloudflare

Cloudflare is used for DNS, content delivery and protection against abusive traffic. In this context, IP address, request metadata and security events may be processed. The legal basis is our legitimate interest in security and availability under Article 6(1)(f) GDPR.

Privacy notice: https://www.cloudflare.com/privacypolicy/

Server logs

When you access our website, technically necessary log data is generated, in particular IP address, time, the request target, status code, browser/device information and error data. This is processed for delivery, error diagnosis and defence against attacks. The legal basis is Article 6(1)(f) GDPR. Log data is only stored for as long as it is required for operation, security and error analysis, unless a statutory retention obligation or a specific security investigation requires otherwise.

4. Cookies and privacy settings

We distinguish between necessary, analytics and marketing technologies. Necessary technologies enable, in particular, the shopping cart, login, language selection, security, consent storage and payment processing. They are used on the basis of Section 25(2) German Telecommunications-Digital-Services-Data-Protection Act (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz, TDDDG) and Article 6(1)(b) or (f) GDPR.

Analytics and marketing technologies are only loaded once you activate the relevant category. The legal basis is your consent under Article 6(1)(a) GDPR and Section 25(1) TDDDG. Your selection is stored for up to 180 days in the first-party cookie airbag_consent. You can change it at any time via "Cookie settings" in the footer. A withdrawal takes effect for the future; when you withdraw, we remove the analytics, marketing and attribution identifiers reachable by us from your browser.

Necessary storage includes, depending on use, shopping-cart, login, locale, cache and consent cookies, among others. Declining optional categories does not affect shopping, placing a repair order, or your customer account.

5. Shop, customer account and contract processing

When you place an order or a repair order, we process, in particular, your name, contact, billing and delivery address, shopping cart, products, vehicle and repair details, VIN where provided, fault codes, notes, shipping and payment status, and communication and document data. The purpose is to initiate and perform the contract, customer support, fraud prevention, and compliance with statutory obligations. The legal bases are Article 6(1)(b) and (c) GDPR; security and abuse prevention are additionally based on Article 6(1)(f) GDPR.

The passwordless customer account uses a time-limited one-time code sent by e-mail. In this context we process your e-mail address, login time and necessary security data.

For an intra-Community VAT-exempt supply of goods or services, a VAT identification number may be verified via the EU VIES system and the verification record stored. The legal bases are Article 6(1)(b) and (c) GDPR.

Stripe

We use Stripe for card payments and other payment methods expressly offered at checkout. Payment data is entered directly into Stripe Elements; we receive, in particular, status, amount, payment method and a technical payment reference, but not the full card details. This processing is necessary for payment processing (Article 6(1)(b) GDPR). Stripe may process technically necessary cookies and fraud-prevention data.

Privacy notice: https://stripe.com/de/privacy

UPS

For shipping, collection, label creation and shipment tracking, we transmit the necessary recipient, address, contact and shipment data to UPS. The legal basis is Article 6(1)(b) GDPR.

Privacy notice: UPS privacy notice

easybill

We use easybill to create, manage and, where applicable, send invoices, credit notes and payment records. This involves processing the necessary customer, order, service, payment and tax data. The legal bases are Article 6(1)(b) and (c) GDPR.

Privacy notice: https://www.easybill.de/datenschutz/

Airtable

To the extent required for migration and operational order processing, Airtable is used for the structured management and synchronisation of catalogue, order and process data. This processing is based on Article 6(1)(b) GDPR and our legitimate interest in orderly business organisation under Article 6(1)(f) GDPR.

Privacy notice: https://www.airtable.com/company/privacy

6. Contact, e-mail and communication

If you contact us by form, e-mail, phone or fax, we process your information to handle your enquiry. The legal basis is Article 6(1)(b) GDPR for pre-contractual or contractual matters, and otherwise Article 6(1)(f) GDPR. Statutory retention obligations remain unaffected.

Resend

Transactional, login, service and status e-mails are sent via Resend. This involves processing, in particular, the recipient address, subject, message content, attachments, delivery status and technical delivery information. The legal bases are Article 6(1)(b) and (f) GDPR.

Privacy notice: https://resend.com/legal/privacy-policy

WhatsApp

If you voluntarily contact us via WhatsApp, WhatsApp processes not only the content of the communication but also metadata such as phone numbers and timestamps. The provider is WhatsApp Ireland Limited. For particularly confidential content, please prefer e-mail or post. The legal basis is Article 6(1)(b) GDPR where there is a contractual connection, and otherwise Article 6(1)(f) GDPR.

Privacy notice: https://www.whatsapp.com/legal/privacy-policy-eea

Superchat

We embed the Superchat chat widget on our pages, which allows you to write to us directly. The provider is SuperX GmbH, Prenzlauer Allee 242–247, 10405 Berlin. When the widget loads, your IP address and technical browser, device and page data are transmitted to Superchat. If you use the chat, the content of your messages, the contact details you provide and timestamps are added; Superchat stores identifiers in your browser to associate your conversation history. The widget is not loaded on tokenised payment pages. The legal basis is Article 6(1)(b) GDPR where there is a contractual connection, and otherwise our legitimate interest in reachable customer support under Article 6(1)(f) GDPR.

Privacy notice: https://www.superchat.de/datenschutz

AI-assisted matching of incoming messages

To ensure that incoming messages (in particular e-mails) are assigned to the correct repair or order process, we use a language model provided by Anthropic in cases of doubt. The provider is Anthropic PBC, San Francisco, USA. A case of doubt exists where a message does not contain a clear order number and our rule-based matching finds several possible orders, or only orders that have already been completed.

In such cases, we transmit the subject line and the text of your message (truncated to 2,000 characters), together with a short list of the orders under consideration (order number, order date, vehicle model, part number, vehicle identification number, fault code and processing status). The model returns only which of these orders the message belongs to, or that no match is possible. It does not make any decision about repair, price or contract content; there is no automated decision-making in an individual case within the meaning of Article 22 GDPR. If the evaluation fails, we assign the message on a rule-based or manual basis.

The legal basis is our legitimate interest in the fast and accurate handling of customer matters under Article 6(1)(f) GDPR. This processing takes place in the USA; to the extent no adequacy decision of the European Commission applies, we base the transfer on the EU Standard Contractual Clauses or, where available, a certification of the provider under the EU-US Data Privacy Framework. Under the provider's terms of service, content transmitted via the application programming interface is not used to train its models.

Privacy notice: https://www.anthropic.com/legal/privacy

7. Uploads and AI-assisted fault code recognition

Within the repair order, you can voluntarily upload diagnostic logs, PDFs or images. Files are stored in our Supabase storage. If you start the AI-assisted evaluation, the selected files are transmitted to Anthropic solely to extract fault codes. Text files are technically checked and masked for VIN-like character strings before transmission; for images and PDFs, complete automatic masking cannot be guaranteed. Please therefore only upload content that is necessary for the diagnosis.

The AI does not make any autonomous decision on repair or price. Extracted codes are matched against our own verified database. The legal basis is Article 6(1)(b) GDPR, because the evaluation is carried out at your request to prepare or carry out the repair order. For the transfer to a third country, the information in Section 6 applies accordingly.

Privacy notice: https://www.anthropic.com/legal/privacy

8. Google reviews

On our website, we display publicly accessible Google reviews of our business. The reviews are retrieved regularly and automatically from Google Maps via the service provider Apify (Apify Technologies s.r.o., Prague, Czech Republic) and stored in our own database. This processing covers the name of the reviewer as shown on Google, the review text, the star rating, the publication date, a review identifier, where available the public profile picture, and any response from the business.

This data does not originate from the data subjects themselves but from the publicly accessible source Google Maps. We inform you of this pursuant to Article 14 GDPR. The legal basis is our legitimate interest in a transparent and complete presentation of existing customer reviews under Article 6(1)(f) GDPR.

If you have written a review and do not wish it to be displayed on our website, a message to info@airbag24.de is sufficient; we will then remove it from our display. Only you, as the author, can delete the review on Google itself.

Apify's privacy notice: https://apify.com/privacy-policy

9. Analytics and marketing

PostHog

After your consent to analytics, we use PostHog to evaluate page views, interactions, purchase funnels, technical performance metrics and JavaScript errors. This may involve processing pseudonymous device/session identifiers, URL, referrer, event data and technical error information. Private payment pages are excluded from this tracking. Data is transmitted to PostHog's EU infrastructure via a proxy of the same name.

The legal basis is Article 6(1)(a) GDPR and Section 25(1) TDDDG. On withdrawal, tracking is stopped and the PostHog identifiers reachable by us are reset in your browser.

Independently of the optional browser analytics, serious backend errors may be transmitted to PostHog as technical security and operational events. Before transmission, e-mail addresses, bearer tokens, secrets, query parameters and private token paths are redacted; no personal profile is created. The legal basis is our legitimate interest in stability, error diagnosis and security under Article 6(1)(f) GDPR.

Privacy notice: https://posthog.com/privacy

Google Analytics

After your consent to analytics, we use Google Analytics 4 to measure page views, usage, conversions and technical performance. We use the Google tag in basic consent mode: before consent, it is not loaded and no analytics events are sent to Google. After consent, Google cookies and pseudonymous identifiers may be processed.

The legal basis is Article 6(1)(a) GDPR and Section 25(1) TDDDG.

Google Ads and conversion measurement

After your consent to marketing, we use Google Ads for conversion measurement. This may involve processing click identifiers such as gclid, gbraid or wbraid, transaction reference, time, country, currency and order value. Hashed contact data is only used for Enhanced Conversions where marketing consent has been given. Without marketing consent, stored click identifiers are neither attached to an order nor uploaded server-side to Google Ads.

The legal basis is Article 6(1)(a) GDPR and Section 25(1) TDDDG.

Google's privacy notice: https://policies.google.com/privacy?hl=de

Google Tag Manager and Meta Pixel

After your consent to marketing, our Google Tag Manager container may load marketing tags, currently in particular the Meta Pixel. This allows us to measure whether advertisements on Facebook or Instagram led to a page view or a conversion. This may involve processing the URL without query parameters, referrer, time, browser/device information, IP address, and Meta identifiers such as _fbp or _fbc. The provider is Meta Platforms Ireland Limited.

The container is not loaded before marketing consent is given. On withdrawal, we send the Meta consent-revoke signal, stop new marketing events and delete the Meta identifiers reachable by us in your browser. The legal basis is Article 6(1)(a) GDPR and Section 25(1) TDDDG.

Meta's privacy notice: https://www.facebook.com/privacy/policy/

10. Recipients, processors and transfers to third countries

We only disclose personal data where necessary for the purposes stated above, for the performance of a contract, due to a statutory obligation, or with your consent. Where required, we enter into data processing agreements with service providers acting on our instructions.

Individual providers or sub-processors may process data outside the European Economic Area. Where no adequacy decision of the European Commission applies, we use appropriate safeguards, in particular the EU Standard Contractual Clauses, and assess additional protective measures. Details of the respective transfer mechanisms can be found in the linked privacy notices of the providers.

11. Retention period

We only store personal data for as long as necessary for the respective purpose. Contract, invoice and tax-relevant documents are retained in accordance with the statutory retention periods under commercial and tax law, generally between six and ten years. Contact and repair data is deleted or restricted once the purpose no longer applies and no warranty, evidentiary or retention obligation stands in the way. Uploads are deleted as soon as they are no longer needed for the order, as evidence or in connection with a complaint.

Consent and attribution cookies expire after 180 days at the latest; a withdrawal deletes the optional browser identifiers reachable by us earlier. The specific retention periods of external providers are additionally governed by their own configuration and privacy notices.

12. Legal bases

  • Article 6(1)(a) GDPR for voluntary consent;
  • Article 6(1)(b) GDPR for contracts and pre-contractual measures;
  • Article 6(1)(c) GDPR for legal obligations;
  • Article 6(1)(f) GDPR for security, abuse prevention, error analysis, the display of reviews and efficient business organisation;
  • Section 25 TDDDG for the storage of, or access to, information on the end device.

13. Your rights

Subject to the statutory requirements, you have the right to access, rectification, erasure, restriction of processing, data portability and objection. You may withdraw consent at any time with effect for the future. The lawfulness of processing carried out before the withdrawal remains unaffected.

You can change your cookie selection via "Cookie settings" in the footer. Other consents can be withdrawn at info@airbag24.de.

Where processing is based on Article 6(1)(e) or (f) GDPR, you may object on grounds relating to your particular situation. You may object to processing for direct marketing purposes at any time.

You may lodge a complaint with a data protection supervisory authority, in particular in the place of your habitual residence, place of work or the place of the alleged infringement.

14. Security and changes

This website uses TLS encryption. We also use access restrictions, roles, logging and technical protective measures. Absolute protection for internet transmissions cannot be guaranteed.

We update this privacy policy when the legal situation, providers or data flows change materially. In the event of material changes to the consent model, we will request a new selection from you.