Privacy Policy

1. Controller

The controller responsible for processing personal data through the Gray Fox Book Club website and Gray Fox Book Club application is:

Lillian Gray Rabe Geiselgasteigstraße 132, 81545 Munich, Germany

Email: lilliangrayart@gmail.com

In this Privacy Policy, “Gray Fox Book Club”, “we”, “us” and “our” refer to the above controller.

2. General Information

We take the protection of your personal data seriously.

We process personal data only where there is an appropriate legal basis under the General Data Protection Regulation (“GDPR”) or other applicable law.

This Privacy Policy explains what personal data we collect, why we collect it, how it is used, how long it may be retained, who may receive it and what rights you have.

3. Website Hosting and Server Logs

When you visit our website or use our application, our hosting provider may automatically process technical information necessary to deliver and secure the service.

This may include:

  • IP address
  • date and time of access
  • requested page or resource
  • browser type and version
  • operating system
  • referring website
  • device information
  • technical error and security logs

This processing may be necessary for the operation, security and stability of the website and application.

Legal basis: Article 6(1)(f) GDPR and, where processing is necessary to provide a service requested by you, Article 6(1)(b) GDPR.

Hosting provider:

Hosting provider: Hostinger
Country / privacy information: Hostinger International Limited, registered in Lithuania. For current privacy details, refer to Hostinger’s official Privacy Policy .

Hosting and infrastructure for the Gray Fox Book Club App run on Google Cloud Platform and Firebase (Authentication, Cloud Run, Cloud SQL, Cloud Storage), hosted in the europe-west3 (Frankfurt) region.

4. User Accounts

Members may create accounts to use features of the Gray Fox Book Club website or application.

Depending on the features used, we may process information including:

  • name
  • email address
  • username
  • profile information
  • profile photograph, if provided
  • account creation date
  • login information
  • account status
  • books added to the platform
  • borrowing, lending, swapping or gifting requests
  • waiting lists or lending chains
  • messages or interactions connected to these functions
  • administrative actions relating to the account

We process this information in order to create and administer your account and provide the requested community features.

Legal basis: Article 6(1)(b) GDPR.

Where processing is necessary for platform security, abuse prevention or community moderation, we may rely on our legitimate interests under Article 6(1)(f) GDPR.

5. Book Listings, Lending, Swapping and Gifting

Members may upload information about books they own and indicate whether books are available to lend, swap or give away.

Information associated with a listing may be visible to other authorised members of the Gray Fox Book Club community.

Members should not publish sensitive personal information, private addresses, telephone numbers or other unnecessary personal data in book descriptions or public fields.

When members arrange a physical exchange of a book, any additional information they voluntarily exchange with each other is their responsibility.

Gray Fox Book Club does not require members to publish their home address through the application.

6. Community Administration and Moderation

We may process account information, listings, reports, complaints and activity information where reasonably necessary to:

  • administer the community
  • investigate misuse
  • enforce our Terms & Conditions
  • protect members
  • remove inappropriate or unlawful content
  • prevent fraud or abuse
  • suspend or terminate accounts where appropriate

Legal basis: Article 6(1)(b) GDPR and Article 6(1)(f) GDPR.

7. Contact Forms and Direct Communication

When you contact us by email, contact form or another communication method, we process the information you provide to respond to your enquiry.

This may include your name, email address and the contents of your message.

Legal basis: Article 6(1)(b) GDPR where the communication relates to a contract or requested service, and otherwise Article 6(1)(f) GDPR.

8. Events and Book Club Registrations

When you register for a Gray Fox Book Club event, we may process information necessary to administer the event.

This may include your name, email address, membership information, RSVP information and payment information.

Where event registration is handled through an external platform such as Meetup, that provider may process personal data independently in accordance with its own privacy policy.

9. Merchandise and WooCommerce

Our website may offer Gray Fox Book Club merchandise through WooCommerce.

When you place an order, we may process information including:

  • name
  • billing address
  • delivery address
  • email address
  • telephone number where required
  • products ordered
  • price and transaction information
  • payment status
  • order history

This information is processed to fulfil your order and comply with accounting, tax and legal obligations.

Legal basis: Article 6(1)(b) GDPR and Article 6(1)(c) GDPR.

10. Payment Providers

Payment information may be processed by external payment service providers used during checkout.

Depending on our current configuration, these may include:

PAYPAL / STRIPE / GOOGLE PAY

Payment providers may process information according to their own privacy policies.

We generally do not receive or store complete payment-card details ourselves where payment is processed directly by a payment provider.

11. Print-on-Demand and Order Fulfilment

Where merchandise is manufactured or fulfilled by an external print-on-demand provider, information required to fulfil the order may be shared with that provider.

This may include the customer’s name, delivery address and order details.

Current fulfilment provider:

Printify / relevant print provider

The information is shared only insofar as necessary to manufacture, process and deliver the relevant order.

Legal basis: Article 6(1)(b) GDPR.

12. Newsletter

Users may choose to subscribe to our newsletter.

We may process your name, email address, subscription status and information relating to newsletter delivery.

Newsletter subscriptions are voluntary and may be cancelled at any time using the unsubscribe link contained in the newsletter.

We currently use:

Brevo

to manage and distribute newsletters.

Where required, newsletter subscription is confirmed using a double opt-in procedure.

Legal basis: Article 6(1)(a) GDPR.

Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

13. Cookies and Similar Technologies

Our website uses cookies and similar technologies.

Some technologies are technically necessary for the operation of the website, account login, security, shopping-cart functionality or other services expressly requested by the user.

Other technologies, including certain analytics, marketing or external-media services, are activated only after consent where consent is legally required.

Users can make their selection through our cookie consent management system and can change or withdraw consent at any time through the Cookie Settings link on our website.

Legal basis for consent-based processing: Article 6(1)(a) GDPR in conjunction with applicable German telecommunications and digital-services privacy law.

14. Analytics

If we use analytics services, they will only be used in accordance with applicable data-protection requirements.

Current analytics tools:

GOOGLE ANALYTICS / GOOGLE SITEMAP

Where consent is required, analytics services will not be activated before consent has been obtained.

15. Embedded and Third-Party Content

Our website may contain content or integrations from third parties, such as:

  • Instagram
  • Facebook
  • YouTube
  • Google Maps
  • Meetup
  • other embedded media or social platforms

Third-party content capable of transferring personal information to external providers will be blocked before consent is obtained where consent is required.

16. Social Media

Gray Fox Book Club maintains profiles on third-party social-media platforms.

When you interact with us through those platforms, the relevant platform provider may process information about you independently.

The use of those platforms is additionally governed by the privacy policies and terms of the respective providers.

17. Recipients and Service Providers

Where necessary, personal data may be processed by service providers acting on our behalf, including providers of:

  • website hosting
  • website administration
  • email and newsletter services
  • payment processing
  • merchandise fulfilment
  • technical support
  • analytics, where enabled
  • event administration
  • cloud or database services

Where legally required, appropriate data-processing agreements are entered into with processors.

18. International Data Transfers

Some service providers may process data outside Germany or the European Economic Area.

Where personal data is transferred internationally, we use or rely on an appropriate legal mechanism where required by law, such as an adequacy decision or approved contractual safeguards.

19. Data Retention

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected or as required by law.

Account information is generally retained while the account remains active.

Following deletion of an account, information may continue to be retained where necessary for legal obligations, security, dispute resolution, fraud prevention, establishment or defence of legal claims, accounting or tax requirements.

Order and accounting information may be retained for applicable statutory retention periods.

Consent records may be retained where necessary to demonstrate compliance with legal obligations.

20. Account Deletion

Members may request deletion of their Gray Fox Book Club account by contacting us at:

lilliangrayart@gmail.com

Where an account is deleted, personal data associated with the account will be deleted or anonymised unless continued retention is required or permitted by law.

Certain records may therefore remain for statutory, security or evidentiary purposes.

21. Your Rights

Subject to the requirements of applicable law, you may have the right to:

  • obtain information about personal data we process about you
  • obtain a copy of your personal data
  • correct inaccurate information
  • request deletion of personal data
  • request restriction of processing
  • object to certain processing
  • receive certain data in a portable format
  • withdraw consent at any time where processing is based on consent
  • lodge a complaint with a competent data-protection supervisory authority

To exercise your rights, contact:

lilliangrayart@gmail.com

22. Right to Lodge a Complaint

You have the right to lodge a complaint with a competent data-protection supervisory authority if you believe that processing of your personal data infringes applicable data-protection law.

For a controller established in Bavaria, the competent authority will depend on the nature of the controller and processing activity.

23. Security

We implement reasonable technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.

However, no internet-based system can provide absolute security.

24. Changes to this Privacy Policy

We may update this Privacy Policy when our services, technical systems, providers or legal obligations change.

The current version will always be published on our website.

Last updated: August 2026