Privacy
Privacy policy
Protecting your personal data matters to us. Below we explain which data we process when you use this service and what rights you have.
Controller
The controller responsible for data processing on this website is media:meets GmbH, Schnabelstraße 1, 45134 Essen, Germany.
Email: datenschutz@mediameets.de. Further details are available in our legal notice.
Data minimisation
We process personal data solely within the limits of the applicable law (GDPR, German BDSG and TDDDG). This service is deliberately data-frugal: without your consent we set no analytics or marketing cookies. You can enable optional audience measurement with Google Analytics yourself in the cookie banner.
No account is required to use the free generator.
Legal bases
Where we obtain consent, Art. 6(1)(a) GDPR is the legal basis. Processing to perform a contract or pre-contractual measures relies on Art. 6(1)(b) GDPR, processing to meet legal obligations on Art. 6(1)(c) GDPR, and processing to safeguard legitimate interests on Art. 6(1)(f) GDPR.
Website delivery and server log files
When you access this website, our hosting provider automatically records information in what are known as server log files, transmitted by your browser: IP address, date and time of access, the page requested, the browser and operating system used, and the previously visited page (referrer).
This data serves only the technical delivery, security and stable operation of the service and is not combined with other data sources. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR). The log files are deleted after a short period.
Security logging
To protect the service and detect abusive access attempts, we record security-relevant events in a dedicated security log: sign-ins and sign-outs, failed login attempts, registrations, sign-ins via Google/LinkedIn, enabling and disabling two-factor authentication, password changes and resets, the creation and revocation of API access tokens, and denied access attempts.
The log records only the internal user identifier, the IP address, the event type and a timestamp. Passwords and full email addresses are never logged. The legal basis is our legitimate interest in IT security and in defending against attacks (Art. 6(1)(f) GDPR). The log files are deleted after 90 days.
Cookies
We use strictly necessary cookies only. A session cookie keeps your session alive (for example while you are signed in), a further cookie stores your chosen language, and a consent cookie (cookie_consent) stores your choice in the cookie banner for about six months. These cookies are required to operate the website; no consent is needed for them (Section 25(2) TDDDG).
The cookie banner additionally offers “Analytics” and “Marketing” categories. If you agree, Google Analytics sets cookies for audience measurement, and the Meta Pixel sets cookies to measure our advertising (details in the following sections). All happen only with your explicit consent (Art. 6(1)(a) GDPR), which you can withdraw at any time via “Cookie settings” in the footer; the related cookies are then removed.
Web analytics with Google Analytics
Only if you consent to the “Analytics” category in the cookie banner do we use Google Analytics (GA4), a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics helps us understand how the website is used so we can improve it.
It sets cookies (such as _ga and _ga_*) that recognise returning use. The IP address is truncated or processed anonymously by Google Analytics 4. Data may be transferred to Google servers, including in the USA; Google LLC is certified under the EU-US Data Privacy Framework.
The legal basis is solely your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time with effect for the future via “Cookie settings” in the footer; the cookies set are then deleted. Without your consent no analysis takes place.
- Google: policies.google.com/privacy
Marketing with the Meta Pixel and Conversions API
Only if you consent to the “Marketing” category in the cookie banner do we use the Meta Pixel and the Meta Conversions API, services of Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. We use them to measure the success of our advertising on Facebook and Instagram and to show relevant ads.
The Meta Pixel sets cookies (such as _fbp and _fbc) in your browser and transmits events (such as a page view, a completed sign-up or a purchase) to Meta. To improve measurement quality, the same events are additionally sent server-side via the Conversions API. The data transmitted includes your IP address, information about your browser and device, the event and, for signed-in actions, your email address in a pseudonymised (hashed) form. Data may be transferred to Meta servers, including in the USA.
The legal basis is solely your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time with effect for the future via “Cookie settings” in the footer; the cookies set are then deleted and no further server-side events are sent. Without your consent no Meta tracking takes place.
Creating GARAN labels
To create a label you enter three values: the guarantee duration, the brand and the model identifier. When you use the generator without an account, these inputs are processed solely to render the requested label and are not stored in a database. When you are signed in, a label you download is saved to your personal label library (see “Developer API and label library”).
The rendered label files are cached to speed up repeated requests. They are stored content-addressably via a checksum, which allows no conclusions about your identity. To prevent abuse we limit the number of requests per IP address (Art. 6(1)(f) GDPR).
Batch generation via CSV upload
As a signed-in user you can use batch generation and upload a CSV file with the guarantee duration, brand and model identifier per row. We process this data solely to render the requested labels. The uploaded file is only read temporarily for processing and is not stored permanently.
The resulting ZIP archive containing the labels and a results overview is associated with your account and stored for retrieval. It is retained for as long as your account exists and is removed when you delete your account. The legal basis is the provision of the feature you requested (Art. 6(1)(b) GDPR).
Developer API and label library
As a signed-in user you can use our developer API to generate labels programmatically. To authenticate your requests you create personal access tokens. We store these tokens only in hashed (irreversible) form, together with the name you assign them, and associate them with your account. You can revoke a token at any time in your settings.
Labels you generate – whether by downloading one while signed in, via the API, or via batch generation – are saved to your personal label library. For each label we store the three values you entered (guarantee duration, brand and model identifier) and associate them with your account, so you can view your labels again and re-download them at any time without paying twice for the same label. This data is retained for as long as your account exists and is removed when you delete your account. The legal basis is the provision of the feature you requested (Art. 6(1)(b) GDPR).
Payment processing via Stripe
To buy credits for batch generation we use the payment provider Stripe. For users in the European Economic Area the provider is Stripe Payments Europe, Ltd., The One Building, 1 Grand Canal Street Lower, Dublin 2, Ireland. The payment is handled directly by Stripe; you enter your full payment details (such as your card number) only with Stripe, and we do not receive them.
For a purchase, we and Stripe process your name, email address, your billing address (which you enter during checkout; it is required to calculate tax) and, if you purchase as a business and your country supports it, your VAT identification number, your preferred language (so invoices are issued in your language) and payment and transaction data (such as the pack purchased, amount, time and a Stripe payment or customer identifier). We store that identifier to associate your purchase with your account and to credit your balance. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR).
Alternatively you can choose usage-based billing ("pay as you go"). You then store a payment method with Stripe and enter into a recurring subscription; the number of labels you generate is invoiced monthly. For this purpose we transmit the usage volume (number of labels generated) and a customer identifier to Stripe. The legal basis is likewise the performance of the contract (Art. 6(1)(b) GDPR).
Data may be transferred to Stripe servers, including in the USA. The transfer is safeguarded by the EU Commission's standard contractual clauses; Stripe, Inc. is additionally certified under the EU-US Data Privacy Framework.
- Stripe: stripe.com/privacy
Registration and user account
You may optionally create an account. In doing so we process your name, your email address, your preferred language and – when you register with a password – your password, which is stored in encrypted form only. The processing serves to provide and manage your account (Art. 6(1)(b) GDPR).
After registering with email and password we send you an email to confirm your address. We store your account data until you delete your account. You can delete your account yourself at any time in the settings.
Sign-in with Google and LinkedIn
Alternatively you can sign in with Google or LinkedIn. When you click the relevant button you are redirected to the respective provider and sign in there. We then receive your name, your email address and a unique user identifier from the provider, which we associate with your account.
We store neither access tokens nor your profile picture. The providers are Google Ireland Limited and LinkedIn Ireland Unlimited Company. Data may be transferred to servers in the USA; the providers are certified under the EU-US Data Privacy Framework. The legal basis is Art. 6(1)(b) GDPR together with your consent (Art. 6(1)(a) GDPR).
- Google: policies.google.com/privacy
- LinkedIn: linkedin.com/legal/privacy-policy
Within an account we send functional emails only: the confirmation of your email address and, on your request, a link to reset your password. Beyond that we only send our newsletter "Compliance & E-Commerce Radar", and only if you have explicitly subscribed to it (see the next section).
Newsletter "Compliance & E-Commerce Radar"
You can subscribe to our newsletter "Compliance & E-Commerce Radar". It covers EU e-commerce compliance — in particular the GARAN label and Regulation (EU) 2025/1960 as well as other EU rules such as the GPSR (General Product Safety Regulation) —, updates to our generator, and selected news from the e-commerce industry. The legal basis is your consent under Art. 6(1)(a) GDPR.
We use a double opt-in process: after you sign up we send an email with a confirmation link. Your address is only added to the list once you click it. If you do not confirm within seven days, the link expires.
If you have an account, you can also subscribe to the newsletter in your account settings. Your consent is then stored together with your account, including the time of consent and the IP address used, to evidence your consent and to send the newsletter to your account email address. You can turn the subscription off again at any time in your account settings; deleting your account also deletes this consent.
We store your email address, the chosen language, the time of sign-up and confirmation, and the IP address used at confirmation. This data serves solely to evidence your consent and to send the newsletter; it is not shared with third parties and not used for advertising tracking.
You can withdraw your consent at any time with effect for the future. Every newsletter email contains an unsubscribe link; once you unsubscribe you receive no further newsletters. We keep the data until you unsubscribe.
Your rights
Under the GDPR you have the following rights:
- Access to the data stored about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure of your data (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing (Art. 21 GDPR)
- Withdrawal of a given consent with effect for the future (Art. 7(3) GDPR)
Right to complain
To exercise your rights, a message to datenschutz@mediameets.de is enough. You also have the right to lodge a complaint with a data protection supervisory authority, for example the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia.
Retention and deletion
We store personal data only for as long as is necessary for the purposes stated or as required by statutory retention periods. Account data is removed when you delete your account, except for invoice and payment data, which we continue to store at Stripe to meet statutory tax and commercial retention obligations. Server log files are stored for a short period.
Changes to this privacy policy
We update this privacy policy whenever changes to our services or the legal situation make it necessary. The version published on this page at any given time applies.