Privacy Policy
Last updated: July 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
YouVenture! GmbH
Ericusspitze 4
20457 Hamburg
Germany
Commercial register: Amtsgericht Hamburg, HRB 172192
Managing directors authorised to represent the company: Finn Alexander Dubbels, Viktor Dik
Email: support@confettiprints.com
2. Overview of the Data Processing
Confetti Prints is an online service in which users upload a personal photo which is transformed by artificial intelligence into an individual product – a colouring book (“Malbuch”) or a personalised book (e.g. “Mutmachbuch”, “Gefühlebuch”, “ABC-Buch”) in which the person shown is depicted as a character in the illustrations. Once an order has been completed, the generated products are transmitted to a printing company for production and dispatch. The uploaded photo is processed only for the duration of the creation process and is then deleted automatically (see Clauses 5 and 8).
3. Personal Data Collected
In connection with your use of our service, we collect and process the following personal data:
a) Order data
First and last name, email address, delivery address and, where applicable, billing address –
in order to process your order and dispatch the product.
b) Payment data
Payment information (e.g. credit card details) is processed exclusively by our
payment service provider Stripe. We ourselves do not store any complete payment data
(see Clause 7.2).
c) Uploaded photo
The photo you upload is processed exclusively for the purpose of creating your individual product. It is transmitted to our AI service provider for image generation (Clause 5). In the case of the personalised books, the photo is processed temporarily in our storage (EU, see Clause 6) for the duration of the multi-stage generation process and is deleted automatically immediately after completion. In the case of the colouring book, the photo is not stored on our servers; it is transmitted to the AI service provider solely for processing.
d) Characteristics derived from the photo
So that the person shown can be depicted recognisably in the illustrations, the photo is analysed by an AI image analysis model which produces a short description of their appearance (e.g. hair and eye colour, skin tone) as well as an estimated age. These derived details are used only for the generation process and are deleted together with the photo reference once it has been completed. No biometric identification and no comparison with other data sets takes place.
e) Technical data and IP address
When you visit our website, technical information is collected automatically (browser type and version, operating system, referrer URL, date and time of access). In order to protect against misuse and to limit the number of generations (rate limiting), we also process your IP address temporarily. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the security, availability and cost control of our service).
f) Application data
If you apply to us for an advertised position, we process the information and documents that you transmit to us in doing so. Details can be found in Clause 10.
4. Purposes and Legal Bases of the Processing
5. Processing of Your Photo by Artificial Intelligence
5.1 AI service provider used (Replicate)
In order to transform your photo into the product ordered, we use the AI platform:
Replicate, Inc.
58 Maiden Lane, San Francisco, CA 94108, USA
Your photo is processed via Replicate’s application programming interface (API). For image generation and image analysis, Replicate uses models from OpenAI (e.g. “gpt-image-2” and “gpt-4o-mini”) as sub-processors. We do not transmit your photo to OpenAI directly. The product created is transmitted back to us.
By default, Replicate automatically removes the input and output data transmitted via the API after a short time (generally approx. 1 hour). OpenAI does not use the data processed via its API for its own training purposes and stores it only temporarily for the detection of misuse (generally for a maximum of 30 days; longer retention may take place where statutory obligations so require). Replicate processes the data exclusively in order to provide the image generation we have commissioned.
The legal basis for this transfer is Art. 6(1)(b) GDPR (performance of a contract); where special categories of personal data (Art. 9 GDPR) are affected in this context, we additionally base the processing on your explicit consent pursuant to Art. 9(2)(a) GDPR, which you give by uploading the photo.
5.2 Storage period of the photo
The photo is processed only for the duration of the AI generation. In the case of the personalised books, it is deleted automatically from our storage immediately after the book has been completed, but at the latest within 24 hours (automated deletion process). In the case of the colouring book, the photo is not stored.
5.3 Transfer to a third country (USA)
Replicate is based in the USA. The transfer of your photo to Replicate constitutes a transfer to a third country; it takes place on the basis of Standard Contractual Clauses (SCC) pursuant to Art. 46(2)(c) GDPR. OpenAI, the sub-processor used by Replicate, is certified under the EU-US Data Privacy Framework. Further information:
https://replicate.com/privacy
https://openai.com/policies/privacy-policy
5.4 No automated decision-making
No automated decision-making within the meaning of Art. 22 GDPR takes place. The AI-assisted image transformation serves exclusively for creative design purposes and has no legal or similarly significant effects on you.
6. Storage on Our Servers
In order to provide the product and to control the multi-stage generation process, we use the following service providers, whose data centres are located in the European Union:
Vercel Inc. (340 S Lemon Ave #4133, Walnut, CA 91789, USA) – hosting of the website as well as object storage (“Vercel Blob”, Frankfurt/Germany region) for the uploaded photo (only during generation) and for the generated images.
Upstash, Inc. (USA) – temporary processing cache (“Redis”, Frankfurt/Germany data centre) for the status of the generation job (including the name and gender of the person shown, the photo reference, the derived description and the references to the images created).
A data processing agreement pursuant to Art. 28 GDPR is in place with both providers. As the data is stored in the EU (Frankfurt), no transfer to a third country takes place in this respect. The storage periods are set out in Clause 8.
7. Disclosure to Third Parties
7.1 Printing company
Following successful checkout, we transmit the generated products as well as the data required for printing and dispatch (name, delivery address) to our printing service provider:
mediaprint solutions GmbH
Eggertstraße 28, 33100 Paderborn, Germany
The legal basis is Art. 6(1)(b) GDPR (performance of a contract). We have concluded a data processing agreement pursuant to Art. 28 GDPR with the printing company.
7.2 Payment service provider
For payment processing we use:
Stripe Payments Europe, Ltd. (1 Grand Canal Street Lower, Grand Canal Dock, Dublin,
D02 H210, Ireland) and Stripe, Inc. (354 Oyster Point Blvd, South San Francisco,
CA 94080, USA) respectively.
Stripe processes your payment data directly and in a PCI-DSS-certified manner. We receive only a confirmation of the payment as well as the last four digits of your card number. The legal basis is Art. 6(1)(b) GDPR. For any data processing in the USA, Stripe is certified under the EU-US Data Privacy Framework; Standard Contractual Clauses apply in addition. Further information:
https://stripe.com/de/privacy
7.3 Sending of emails (contact form & order confirmations)
For the sending of emails (e.g. confirmations, replies to contact enquiries) we use the service Resend (Resend, Inc., USA; processing and dispatch in the EU, Ireland region). If you use our contact form, we transmit your email address, your message and technical context data (e.g. page visited, device) to Resend for delivery. A data processing agreement pursuant to Art. 28 GDPR is in place with Resend. The legal basis is Art. 6(1)(b) or (f) GDPR.
7.4 Trusted Shops (Trustbadge®, reviews and buyer protection)
In order to display the Trusted Shops services (e.g. the trustmark, collected reviews) and to offer Trusted Shops products to buyers after an order has been placed, Trusted Shops widgets are integrated into our website: the Trustbadge® is displayed on our product pages, and the so-called Trustcard after the order has been completed. This serves to safeguard our legitimate interests in optimal marketing by enabling safe shopping, which prevail in a balancing of interests, pursuant to Art. 6(1) first sentence lit. f GDPR. The Trustbadge and the services advertised with it are an offering of
Trusted Shops SE
Subbelrather Str. 15C, 50823 Cologne, Germany
with whom we are joint controllers under data protection law pursuant to Art. 26 GDPR. We inform you below about the essential contents of the arrangement pursuant to Art. 26(2) GDPR.
When you interact with the Trustbadge, session cookies are set in order to store the login status and to display the so-called welcome layer, which shows the details of the respective online shop (company information, reviews, information on the existence of buyer protection). In order to recognise logged-in users, a cookie is set and stored for a maximum of 400 days after login. This is necessary so that Trusted Shops can provide the digital service you have requested. Trusted Shops is responsible for the data processing that takes place when you interact with the Trustbadge.
Within the scope of the joint controllership existing between us and Trusted Shops, please contact Trusted Shops as a matter of preference with data protection questions and in order to exercise your rights, using the contact options set out in the
Trusted Shops privacy information.
Irrespective of this, you may always contact the controller of your choice. Your request will then, if necessary, be passed on to the other controller for a response.
Data processing when the Trustbadge is integrated
The Trustbadge is provided by a US provider of a content delivery network. An adequate level of data protection is ensured by an adequacy decision of the EU Commission; service providers used from the USA are generally certified under the
EU-U.S. Data Privacy Framework.
Where service providers used are not certified under the DPF, Standard Contractual Clauses have been concluded as an appropriate safeguard.
When the Trustbadge is called up, the web server automatically stores a so-called server log file which also contains your IP address, the date and time of the request, the volume of data transferred and the requesting provider (access data), and which documents the request. The IP address is anonymised immediately after collection, so that the stored data cannot be attributed to you. The anonymised data is used in particular for statistical purposes and for error analysis.
Data processing after completion of an order
After the order has been completed, order information (order number, order value, currency, payment method and expected delivery date) as well as your email address, hashed by means of a cryptographic one-way function, are transmitted to Trusted Shops. The legal basis is Art. 6(1) first sentence lit. f GDPR. This serves to check whether you are already registered for services with Trusted Shops and is therefore necessary for the fulfilment of our and Trusted Shops’ overriding legitimate interests in the provision of the buyer protection linked to the specific order and of the transactional review services pursuant to Art. 6(1) first sentence lit. f GDPR. If this is the case, further processing takes place in accordance with the contractual agreement concluded between you and Trusted Shops. If you are not yet registered for the services, you will subsequently be given the opportunity to do so for the first time. Further processing after registration has taken place is likewise governed by the contractual agreement with Trusted Shops. If you do not register, all transmitted data will be deleted automatically by Trusted Shops and it will then no longer be possible to identify you.
Review invitation after dispatch
As soon as our printing company reports the dispatch of your order, we transmit your email address, your order number and the time of dispatch via the Trusted Shops interface, so that the review invitation is only scheduled once your book is actually on its way. The invitation is sent by Trusted Shops a few days later and only if you have previously consented to receiving review invitations. The legal basis is Art. 6(1) first sentence lit. f GDPR in conjunction with the consent you have declared to Trusted Shops.
Trusted Shops uses service providers in the areas of hosting, monitoring and logging. The legal basis is Art. 6(1)(f) GDPR for the purpose of ensuring trouble-free operation. Processing in third countries (the USA and Israel) may take place in this context. An adequate level of data protection is ensured in each case by an adequacy decision of the EU Commission.
8. Storage Period and Deletion
after completion, at the latest after 24 hours. In the case of the colouring book, no storage takes place.
(for the preview, repeat access and complaints) and then deleted automatically.
required for this purpose.
tax and commercial law (Section 147 of the German Fiscal Code (AO), Section 257 of the German Commercial Code (HGB)).
9. Cookies, Reach Measurement and Marketing
We use technically necessary cookies which are required for the operation of the website and for processing the ordering procedure (e.g. session and basket cookies). The legal basis is Art. 6(1)(f) GDPR and Section 25(2) TDDDG (German Telecommunications Digital Services Data Protection Act).
In addition, we use marketing and reach measurement tools only with your express consent (via our cookie banner). The legal basis is your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You may withdraw your consent at any time with effect for the future.
9.1 Meta pixel
Provider: Meta Platforms Ireland Ltd. (4 Grand Canal Square, Dublin 2, Ireland). In order to measure the effectiveness of our advertising on Facebook/Instagram and to build target audiences, we use the Meta pixel. It records certain events (e.g. page view, basket, purchase) and in doing so transmits, among other things, online identifiers, IP address and technical browser data to Meta. The Meta pixel is only loaded after you have given your consent via the cookie banner (Art. 6(1)(a) GDPR).
Meta is certified under the EU-US Data Privacy Framework. Further information:
Meta’s privacy policy.
9.2 Google Ads conversion tracking
Provider: Google Ireland Ltd. (Gordon House, Barrow Street, Dublin 4, Ireland). In order to measure the success of our Google ads, the Google tag (gtag.js) is loaded – only after you have given your consent. IP address and technical browser data may be transmitted to Google in this process. Google is certified under the EU-US Data Privacy Framework. Further information:
Google’s privacy policy.
9.3 Direct advertising by email (existing customers)
Insofar as you have purchased a product from us, we use the email address collected in connection with the order in order to send you occasional information about our own similar products. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in direct marketing) in conjunction with Section 7(3) of the German Act Against Unfair Competition (UWG). You may object to this use at any time – via the unsubscribe link in every email or informally to
support@confettiprints.com – without incurring any costs other than the transmission costs at basic rates. Following an objection, we will no longer use your email address for advertising purposes.
9.4 Newsletter (with consent)
On our website you can subscribe to our free newsletter, with which we inform you about offers, discounts and news. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR, which you give by ticking the box when subscribing.
Subscription takes place using the double opt-in procedure: after you have entered your email address, we send you a confirmation email. Only once you click the link it contains is your address added to the newsletter distribution list. In this way we ensure that the subscription actually originates from you.
We process your email address as well as – as evidence of your consent
(Art. 7(1) GDPR) – the time of the subscription and of the confirmation, your IP address and the version of the consent text. For storage and dispatch we use the service
Resend as a processor (see Clause 7.3).
We store this data for as long as you subscribe to the newsletter. You may withdraw your consent at any time with effect for the future and unsubscribe from the newsletter – via the
unsubscribe link in every newsletter email or informally to
support@confettiprints.com.
The lawfulness of the processing carried out up to the point of withdrawal remains unaffected.
10. Job Applications
We advertise open positions on our jobs page. Applications reach us by email to
support@confettiprints.com.
The following applies to the data transmitted in this context:
10.1 Which data we process
We process the information you provide in your application: your name, your contact details (email address and, where applicable, telephone number and postal address), your details on your career history and qualifications, as well as all other content and attachments that you send us voluntarily (e.g. CV, references). You decide for yourself which information you provide – we do not specify any mandatory fields. Without contact details and information about you, however, we cannot process your application.
10.2 Purpose and legal basis
We process your application data exclusively in order to carry out the application procedure and to decide on the establishment of an employment relationship. The legal basis is
Section 26(1) sentence 1 of the German Federal Data Protection Act (BDSG) in conjunction with Art. 88 GDPR as well as Art. 6(1)(b) GDPR (pre-contractual measures). Insofar as we require data beyond this in order to defend against legal claims – for example under the German General Equal Treatment Act (Allgemeines Gleichbehandlungsgesetz, AGG) – we base this on Art. 6(1)(f) GDPR.
10.3 Recipients
Your application arrives in our email inbox. We operate this using
Microsoft 365 (Microsoft Ireland Operations Limited, One Microsoft Place, South County
Business Park, Leopardstown, Dublin 18, Ireland) as a processor pursuant to Art. 28 GDPR.
Access is available exclusively to the persons involved in the selection decision. No disclosure
to further third parties takes place.
10.4 No AI analysis, no automated decision-making
In the handling of customer enquiries we use an AI service which suggests draft replies to us. Applications are excluded from this: your application content is not transmitted to the AI service for this purpose. Decisions on your application are taken exclusively by humans – no automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.
10.5 Storage period
If you are not hired, we delete your application documents at the latest
six months after the end of the application procedure. This period takes account of the
statutory time limits for bringing claims (Section 15(4) AGG). If you would like us to delete your documents
sooner, an informal message to
support@confettiprints.com is sufficient.
If you are hired, we transfer the necessary data to your personnel file.
11. Overview of Transfers to Third Countries
Insofar as recipients in the USA are certified under the EU-US Data Privacy Framework (OpenAI, Stripe, Meta, Google), the transfer takes place on the basis of the adequacy decision of the EU Commission (Art. 45 GDPR). For recipients that are not certified (Replicate), we base the transfer on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR). The photo and order data itself is stored in the EU (Frankfurt) (Clause 6).
12. Your Rights as a Data Subject
Under the GDPR you have the following rights:
(e.g. photo upload, marketing cookies), you may withdraw it at any time with effect for the
future.
To exercise your rights, please contact:
support@confettiprints.com
13. Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority. The supervisory authority responsible for us is:
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit (Hamburg Commissioner for Data Protection and Freedom of Information)
Ludwig-Erhard-Str. 22, 7. OG
20459 Hamburg
Telephone: 040 / 428 54 – 4040
Email: mailbox@datenschutz.hamburg.de
14. Changes to This Privacy Policy
We reserve the right to amend this privacy policy in order to adapt it to changes in the legal situation or to changes in our service. The version currently in force can always be found on our website.
15. Contact
If you have any questions about data protection, you can reach us at:
Email: support@confettiprints.com










