← Back to Cozy Picks

Privacy Policy

COZYVIBE · PRIVACY UNDER THE GDPR

Last updated: 3 September 2026 · Version 1.1

Protecting personal data matters to me. This policy describes what data is processed when you visit and use this service, for what purpose and on what legal basis. It fulfils the information obligations under Art. 13 and 14 of the General Data Protection Regulation (GDPR) as well as the requirements of the Austrian Data Protection Act (DSG) and sec. 165 of the Austrian Telecommunications Act 2021 (TKG 2021).

Scope: This policy applies to the cozy-picks section (product recommendations, affiliate links) and to the Pinterest, social media and Amazon presences of the CozyVibe brand. For the Beauty Routine app itself (routines, appointments, settings, offline use) the app's privacy policy applies: beautyroutine.app/en/privacy.html. In both cases the controller is Robert Thalhammer.

1. The essentials first

2. Controller

The controller within the meaning of Art. 4 (7) GDPR is:

Robert Thalhammer
Grabengasse 13/3/2
2630 Ternitz
Niederösterreich, Austria
Phone: +43 650 666 06 09
E-mail: hello@beautyroutine.app

No data protection officer has been appointed because the statutory conditions of Art. 37 GDPR are not met. All data protection enquiries go directly to the address above.

3. Where CozyVibe takes place

CozyVibe has no domain of its own. The content runs via the site beautyroutine.app (the "cozy-picks" section), a Pinterest profile, an Amazon storefront and further social media channels.

This policy applies to the cozy-picks section and to the presences of the CozyVibe brand. For the Beauty Routine app itself (routines, appointments, settings, offline use) the app's privacy policy at beautyroutine.app/en/privacy.html applies. The privacy terms of the respective operators apply to the platforms themselves.

4. Hosting

This website is delivered via GitHub Pages, a service of GitHub, Inc., 88 Colin P Kelly Jr Street, San Francisco, CA 94107, USA. When a page is requested, technically necessary connection data (including IP address, time, requested file, browser type) is transmitted to GitHub and logged there for a short period. The legal basis is Art. 6 (1) (f) GDPR; the legitimate interest lies in the secure and reliable operation of the website.

The transfer to the USA is based on the European Commission's Standard Contractual Clauses pursuant to Art. 46 (2) (c) GDPR. GitHub is additionally certified under the EU-US Data Privacy Framework.

When a page is requested, technically necessary connection data arises at GitHub (IP address, time, requested file, browser type). These logs are held by GitHub and processed there under its own responsibility for operation and security; the provider has no access to them and cannot promise a deletion period of its own. GitHub's privacy terms apply.

5. Fonts

The fonts used are stored locally on our own web space and loaded from there. There is no connection to Google Fonts or any other external font server. No data is therefore transmitted to third parties when the fonts are loaded.

6. Cookies and consent

A consent banner is displayed when the website is first accessed. It lets you decide whether, in addition to the technically necessary storage, reach measurement with Google Analytics (section "Reach measurement with Google Analytics 4") may be switched on. Declining ("Only necessary") is just as easy as accepting; reach measurement is not pre-selected. No advertising cookies are used.

Until a decision is made, no non-essential cookies are set, no analytics data is collected and no connection to Google is established. The selection made is stored locally in the browser and can be changed or withdrawn at any time via the "Cookie settings" link in the footer. Withdrawal takes effect for the future.

The legal basis for reach measurement is Art. 6 (1) (a) GDPR in conjunction with sec. 165 (3) TKG 2021; for technically necessary storage (app settings, the choice saved in the banner) it is Art. 6 (1) (f) GDPR or sec. 165 (3) TKG 2021 (strictly necessary).

Change or withdraw consent:

7. Reach measurement with Google Analytics 4

Once consent has been given, Google Analytics 4 is used, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, with data processing also carried out by Google LLC, USA.

Google Analytics uses cookies and similar techniques to analyse use of the website. Google Analytics is only loaded after consent has been given. Without consent, no connection to Google is established. In Google Analytics 4, IP addresses are not logged or stored; they are used only to derive an approximate location at country level and are not retained in the process.

The legal basis is Art. 6 (1) (a) GDPR (consent) in conjunction with sec. 165 (3) TKG 2021. Consent can be withdrawn at any time via the cookie settings in the footer. The retention period for usage and event data is set to 14 months in the account. The transfer to the USA is based on the European Commission's adequacy decision on the EU-US Data Privacy Framework of 10 July 2023; Google LLC is certified under that framework.

Note: No advertising service such as Google AdSense is currently active. Should this change, this section will be supplemented before activation.

8. Visitor statistics (Cloudflare Web Analytics)

Cloudflare Web Analytics, a service of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, is used to measure reach.

Cloudflare Web Analytics works without cookies and without recognising individual persons. Only aggregated values such as page views, country of origin, approximate loading time and browser and device type are collected. No profile is created, no cross-device tracking takes place, and the IP address is not stored.

The legal basis is Art. 6 (1) (f) GDPR. The legitimate interest lies in understanding which content is in demand and whether the website is working correctly. The data is stored for a maximum of seven days. The transfer to the USA is based on the Standard Contractual Clauses pursuant to Art. 46 (2) (c) GDPR; Cloudflare is additionally certified under the EU-US Data Privacy Framework.

9. Affiliate links (Amazon Associates Programme)

These pages contain recommendation links to Amazon. Users incur no additional costs as a result.

As an Amazon Associate I earn from qualifying purchases.

Clicking such a link opens the Amazon website. Amazon (Amazon Europe Core S.à r.l., 38 avenue John F. Kennedy, L-1855 Luxembourg, and affiliated companies, some of them in the USA) sets its own cookies and processes the resulting data under its own responsibility. We have no influence over that processing; Amazon's privacy policy applies.

The identity of the person who clicked the link is not transmitted to us. All that is reported back is that a purchase was made via a particular partner identifier. The legal basis for placing the links is Art. 6 (1) (f) GDPR.

10. Pinterest

Content is also distributed via a Pinterest profile. When visiting that profile or clicking a pin, the privacy policy of Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland, applies. We have no influence over that processing.

No Pinterest plug-ins, tracking pixels or buttons are embedded on our own website that would establish a connection to Pinterest simply by opening a page. Only ordinary text links are used.

11. Social media profiles and Amazon storefront

Profiles are operated on platforms such as Pinterest, Instagram, TikTok and YouTube, as well as a storefront on Amazon. The respective operators are responsible for data processing on these platforms; their privacy policies apply. Insofar as statistics on the reach of posts are retrieved, joint controllership pursuant to Art. 26 GDPR exists with the respective platform operator.

Posts in which products are recommended in return for commission are marked as advertising.

12. Contact form

A contact form is available on the website. It does not send anything to a server: when you submit it, the browser opens the e-mail program set up on your device and prepares a message containing the details you entered. You send it yourself. The details are neither stored on the web server nor transmitted to a form service.

The message therefore reaches the provider as an ordinary e-mail and is processed like any other e-mail (see the section "Contact by e-mail"). The legal basis is Art. 6 (1) (f) GDPR (interest in answering the enquiry), or Art. 6 (1) (b) GDPR for enquiries relating to a contract. Enquiries are deleted as soon as they have been dealt with conclusively and no retention obligation applies.

13. Contact by e-mail

Anyone who makes contact by e-mail thereby transmits their e-mail address and the content of the message. This information is used exclusively to process the enquiry.

The legal basis is Art. 6 (1) (b) GDPR for enquiries relating to a contract and Art. 6 (1) (f) GDPR for other enquiries. E-mail traffic is processed by the respective e-mail provider, who acts as a processor in this respect. Enquiries are deleted once they have been finally dealt with. Anything kept longer is kept only because a statutory retention obligation applies — which concerns solely business correspondence that serves as an accounting record and must be retained for seven years pursuant to sec. 132 of the Austrian Federal Fiscal Code (BAO).

14. No automated decision-making

No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.

15. Use by minors

The service is not specifically directed at children. Consent to non-essential cookies and analytics services is only valid from the age of 14 pursuant to Art. 8 GDPR in conjunction with sec. 4 (4) of the Austrian Data Protection Act (DSG). Younger persons should only activate these services with the consent of a parent or guardian.

16. Is providing data mandatory?

There is no statutory obligation to provide personal data.

17. Retention periods

Personal data is stored only for as long as is necessary for the respective purpose or as required by statutory retention obligations. The specific periods are stated with the individual processing operations above. In addition:

18. Recipients and transfers to third countries

Personal data is not sold and is not passed on to third parties for advertising purposes. Disclosure takes place only to the service providers named above and to public authorities where there is a statutory obligation to do so.

Where data is transferred to third countries outside the EU and the EEA, this takes place only on the basis of an adequacy decision of the European Commission or the Standard Contractual Clauses pursuant to Art. 46 (2) (c) GDPR. The applicable basis is stated with each affected processing operation above.

19. Rights of data subjects

Under the GDPR you have the following rights:

An informal message to the e-mail address above is sufficient to exercise these rights. A reply will be given within the statutory period of one month. To prevent misuse, proof of identity may be requested in case of doubt.

Separate notice of the right to object (Art. 21 GDPR)

You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data carried out on the basis of a legitimate interest under Art. 6 (1) (f) GDPR. Where your data is processed for direct marketing purposes, you may object at any time and without giving reasons; your data will then no longer be processed for that purpose. An informal objection to the e-mail address above is sufficient.

20. Right to lodge a complaint

Anyone who believes that the processing of their data infringes data protection law may lodge a complaint with the supervisory authority:

Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
Barichgasse 40-42, 1030 Wien, Austria
Phone: +43 1 52 152-0 · E-mail: dsb@dsb.gv.at · www.dsb.gv.at

21. Data security

The website is delivered exclusively over an encrypted TLS/HTTPS connection. Accounts are secured with strong, individual passwords and — where available — two-factor authentication. On the controller's side, only the controller has access. In addition, the service providers named above have access within the scope of their respective services, bound by confidentiality and — where they act as processors — by a contract pursuant to Art. 28 GDPR.

22. Changes to this privacy policy

This privacy policy is updated whenever the processing operations change — for example when a service is added or removed. The version published on this page is the one that applies.


Controller

Robert Thalhammer
Grabengasse 13/3/2
2630 Ternitz
Niederösterreich, Austria
Phone: +43 650 666 06 09
E-mail: hello@beautyroutine.app

Last updated: 3 September 2026

Last updated: 3 September 2026 · Version 1.1