Privacy policy
Privacy policy
Last updated: 13 September 2026
MobiHero GmbH operates the KRONHERR Gastro shop and this website, including all related information, content, features, tools, products and services, to provide you with a personalised shopping experience (the “Services”). This privacy policy describes how we collect, use and disclose personal data when you visit or use the website, make a purchase or other transaction through the Services, or otherwise communicate with us.
Using this website alone does not constitute consent to processing that requires consent. We obtain any necessary consent separately.
Controller
MobiHero GmbH, Braunstr. 7, 81545 München, Germany. Contact: info@mobihero.de, telephone +49 176 550 64000.
Legal bases and cookies
We process order, payment and delivery data to take steps before entering into a contract and perform contracts under Article 6(1)(b) GDPR. We fulfil statutory retention and documentation obligations under Article 6(1)(c) GDPR. Where necessary and permissible following a balancing of interests, we rely on Article 6(1)(f) GDPR for secure operation, preventing abuse and handling general enquiries. Our legitimate interests are operating a secure shop and addressing your concerns.
Advertising, analytics and personalisation requiring consent are based on your consent under Article 6(1)(a) GDPR. Non-essential cookies and similar access to your device require consent under section 25(1) TDDDG. Strictly necessary storage and access are based on section 25(2) TDDDG. Manage your choices in the cookie banner; you may withdraw consent at any time with future effect. Unsubscribe from newsletters using the unsubscribe link.
Shopify
We use Shopify for hosting, checkout, customer accounts and order processing. Shopify Network Intelligence is enabled. Shopify processes interactions with our shop together with interactions with other shops to improve features, personalisation and advertising. Shopify acts as controller for this processing and respects your consent and objection choices. See Shopify's Consumer Privacy Policy and our supplementary privacy policy for Shopify features. Exercise your rights with Shopify through the Shopify Privacy Portal.
What personal data do we collect or process?
Depending on how you interact with the Services, where you live and what applicable law permits or requires, we may collect or process:
- Contact details, including name, postal address, billing and delivery addresses, telephone number and email address.
- Financial data, including credit and debit card and financial account numbers, payment card information, transaction details, payment method and other payment details.
- Account information, including username, password, security questions, configurations and settings.
- Transaction information, including items you view, add to your cart or wishlist, purchase, return, exchange or cancel.
- Communications with us, including information you provide when contacting us.
- Device information, including device, browser and network connection details, IP address and other unique identifiers.
- Usage information, including how you interact with the Services.
Sources of personal data
- Directly from you, when you create an account, access or use the Services, communicate with us or otherwise provide personal data.
- Automatically through the Services, from your device or when using our products or Services, through cookies and similar technologies.
- From our service providers, when they collect or process personal data on our behalf.
- From our partners and other third parties.
How do we use your personal data?
- Providing, adapting and improving the Services. Performing our contract, processing payments, fulfilling orders and arranging shipping.
- Marketing and advertising. Sending marketing and advertising communications by email, SMS or post.
- Security and fraud prevention. Authenticating accounts and detecting and preventing fraudulent activity.
- Communicating with you. Providing customer support and responding promptly to enquiries.
- Legal reasons. Complying with applicable law and responding to lawful proceedings.
How do we disclose personal data?
In certain circumstances, we may disclose personal data to third parties for legitimate purposes, including providers delivering services on our behalf (IT management, payment processing, data analytics, customer support, cloud storage, fulfilment and shipping), as well as business and marketing partners.
Third-party websites and links
The Services may link to websites or other platforms operated by third parties. We make no guarantees and are not responsible for those websites' privacy or security.
Children's data
The Services are not intended for children, and we do not knowingly collect personal data from children under the age of majority in your country.
Security and retention
No security measures are perfect or impenetrable. How long we retain personal data depends on factors including whether we need it to manage your account, provide Services or comply with legal obligations.
Your rights and choices
- Right of access. Access to personal data held about you.
- Right to erasure. Deletion of personal data held about you.
- Right to rectification. Correction of inaccurate personal data.
- Right to data portability. A copy of your personal data in a commonly used format.
- Right to object and restrict processing.
- Withdrawal of consent.
Right to lodge a complaint
You may complain to a data protection supervisory authority, particularly in the member state of your residence, workplace or the alleged infringement. The Bavarian State Office for Data Protection Supervision is responsible for private companies in Bavaria.
Providing your data
We need the information marked as required for an order to perform the purchase contract. Without it, we cannot process the order. Optional information and consent are not prerequisites for purchasing.
International transfers
We may transfer, store and process personal data outside your country of residence. When transferring it outside the European Economic Area, we rely on recognised mechanisms such as the European Commission's Standard Contractual Clauses.
Sharing customer data with Google (Customer Match and personalised advertising)
We share customer data with third parties providing services on our behalf, including advertising and marketing providers such as Google. In particular, we may send hashed contact details, such as email addresses and telephone numbers, to Google to run audience-based campaigns through Google Ads Customer Match, reach existing customers through Google services and reach similar audiences.
Where required by law or applicable Google personalised advertising and user consent policies, including Google's EU User Consent Policy, we obtain your express consent before sharing, generally through our cookie and consent banner. You may withdraw consent at any time with future effect.
To comply with GDPR, Google's Ads Data Processing Terms apply between Google and us for Customer Match. Under these terms, Google acts as a processor for personal data submitted for Customer Match. Uploaded data is used solely to match your customers with Google accounts and ensure compliance with Google's Customer Match policies.
Changes to this privacy policy
We may update this policy from time to time to reflect changes in our practices or for other operational, legal or regulatory reasons.
Contact
For questions about our privacy practices or this policy, email info@mobihero.de or write to Braunstr. 7, 81545 München, Germany.
