Skip to content
EN
New: Create GARAN labels for free, no sign-up, no watermarkCreate now
EU-Gewährleistungs-
und GARAN Label

Privacy policy

Translation for your convenience. Only the German version of this text is legally binding: Datenschutzerklärung. This English translation is provided for information only.

This policy applies to the website www.garantielabel.app. The Shopify app has its own privacy policy, which is linked in the Shopify App Store.

Controller

MMR Labs GmbH, Carl-Benz-Straße 6, 89269 Vöhringen, e-mail: info@liquiflow.app

In brief

  • We only keep visitor statistics with your consent (cookie banner), using our own tools and without storing your IP address. There are no advertising services. Fonts are hosted on our own server.
  • We set cookies for signing in to the customer area (technically necessary) and to store your choice in the cookie banner.
  • Data is only passed on to third parties where this is necessary for the respective function: Cloudflare (hosting, protection against abuse), Stripe (payment), Resend (sending the sign-in code and forwarding contact requests to us), Discord (internal notification without names and without full e-mail addresses), Crisp (live chat, only if you open it).

Hosting with Cloudflare

The website is delivered via Cloudflare Pages, a service of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. When a page is accessed, Cloudflare processes technically necessary data: IP address, time, address accessed, amount of data transferred, browser and operating system, and the page visited previously. This serves secure and fast delivery and protection against attacks. The legal basis is our legitimate interest in secure operation (Art. 6(1)(f) GDPR).

Cloudflare is certified under the EU-US Data Privacy Framework. A data processing agreement including standard contractual clauses is in place with Cloudflare. We store accounts, labels and purchases in a database at Cloudflare (D1) located in Western Europe. Cloudflare may request error reports on the browser’s network connection (Network Error Logging); they do not contain any page content.

Visitor statistics (only with consent)

If you consent in the cookie banner (“Yes, sure”), we evaluate page views with our own statistics, which run on our hosting at Cloudflare. Without your consent, none of this is recorded. When a page is accessed, your browser then sends the address of the page without parameters, the name of the website you came from (only the domain, such as google.com, never the exact address) and, where applicable, campaign information from the link (utm_source, utm_medium, utm_campaign, utm_term, ref; for ads, the information that you came via an ad, and the search term if the ad passes it in the link). In addition, we store the time, the country derived from the IP address and the device type (mobile or desktop). To group page views of the same day, we create an identifier from your IP address, the browser identifier and a random daily key. We delete the daily key after two days at the latest; after that, the identifier can no longer be traced back to an IP address. We do not store the IP address itself. We cannot link page views on different days. If you create the free label, we additionally store the brand, model and guarantee period for this visit.

If you are signed in to the customer area and have given your consent, we assign page views and actions (sign-in, creating and downloading labels, copying the embed or link code, starting a purchase, generating an API key) to your account. On your first sign-in, we store with your account the website, campaign and landing page through which you came to us that day. This shows us which paths lead to customers and where the operation gets stuck. Independently of this, we record purchases, refunds and chargebacks with the account, because we need them for billing and accounting anyway (Art. 6(1)(b) and (c) GDPR).

The legal basis for the statistics is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). We store your choice for 12 months in the cookie __Host-gl_statistik (“ja” or “nein”, meaning yes or no); this cookie is technically necessary for that purpose (§ 25(2) no. 2 TDDDG). You can withdraw your consent at any time with effect for the future via “Cookie settings” at the bottom of every page. We delete page views and events after 180 days, and the origin information on the account together with the account.

GDPR: General Data Protection Regulation (EU) 2016/679. TDDDG: German Telecommunications Digital Services Data Protection Act (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz).

Open cookie settings

Internal notifications

An internal channel on the Discord service (Discord Inc., USA) notifies us of new free labels, new labels in customer accounts, new accounts, purchases, refunds, entries in the producer directory and shop checks (checked address and result). The message only contains the details of the label (brand, model, guarantee period), the package purchased and the amount, the country, for the directory the producer name and website, and for accounts and purchases the domain of the e-mail address (such as company.com), never names or full e-mail addresses. If you have consented to the statistics, it also contains the origin of the visit and the pages viewed previously that day (see above). This involves a transfer of data to the USA. The legal basis is our legitimate interest in responding quickly to purchases, questions and approvals (Art. 6(1)(f) GDPR).

GARAN label generator

To prevent abuse, we briefly count requests per connection and per e-mail address, for example how many free labels have been created today, likewise only as a salted hash value, deleted when the time window expires (24 hours at most). We do not store the IP address itself. The legal basis is our legitimate interest in fair use free of abuse (Art. 6(1)(f) GDPR).

To protect against automated abuse, we use Cloudflare Turnstile (Cloudflare, Inc.) for the free label, sign-in, the shop check and the contact form. Turnstile is only loaded when you submit one of these forms. It checks technical characteristics of your browser, may store information in your browser for this purpose, does not set any cookies for advertising purposes and only shows a box to tick if there is a suspicion. The legal basis is § 25(2) no. 2 TDDDG (strictly necessary for the function you have requested) and Art. 6(1)(f) GDPR (protection against abuse).

A CSV file that you select in the generator is only read in your browser and is not transmitted to us. We only receive the brand, model and guarantee period of the labels you create and store them with your account so that repeated retrievals remain free of charge. If you fill in a guarantee statement, we store its details (guarantor, address, contact, conditions) with the label so that you can download it again under “My labels”. On request, we delete them together with your account. Your browser remembers your choice between table and tile view under “My labels” in local storage (localStorage, key “gl-konto-ansicht”); it does not leave your device (§ 25(2) no. 2 TDDDG). After a label created without signing in, your browser stores its details and a receipt signed by us in local storage (key “gl-gratis-label”) so that the label is transferred to “My labels” free of charge after you sign in. The entry is deleted on transfer; the receipt is valid for 30 days at most (§ 25(2) no. 2 TDDDG).

Producer directory

The directory is voluntary. If you create a producer profile, we publish the producer name, website and the labels that you individually mark as public (guarantee period, brand, model). Your e-mail address is not published. We check every entry by hand before it becomes public. You can hide labels and delete the entry at any time; it is then immediately no longer visible. The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time with effect for the future by deleting the entry or writing to us.

Widget for online shops

If shops embed our widget, the browser of the shop’s visitors loads the script and the official graphics from our server at Cloudflare. In doing so, Cloudflare processes the technical data listed above under hosting. If a brand with a model is specified in the widget, it queries our producer directory for this; only brand and model are transmitted. The widget does not set cookies, does not store anything in the browser and does not create usage profiles. The respective shop is responsible for embedding it on its website.

Shop check

For the shop check, we retrieve the public page you specify once, evaluate it and discard the content immediately; it is not cached. We store neither the address nor the result in our database, only short-lived counters against abuse. We report the address and the result to our internal channel (see “Internal notifications”) so that we can respond to questions about the integration (Art. 6(1)(f) GDPR). In the customer area, your browser remembers the address last checked, the result and the selected shop system in local storage (keys “gl-konto-shopcheck” and “gl-konto-system”) so that the status appears in the overview; they do not leave your device (§ 25(2) no. 2 TDDDG). On the public page, we use Cloudflare Turnstile here too; in the customer area, being signed in is sufficient.

Payment, sign-in and account

If you buy credits, payment is processed by Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland). Stripe processes payment data as an independent controller and issues the invoice on our behalf; data may be transferred to Stripe, Inc. in the USA in the process (EU-US Data Privacy Framework, standard contractual clauses). We receive your e-mail address, billing address, your VAT ID if applicable and the payment status (Art. 6(1)(b) GDPR). When you make a purchase, we also store when you confirmed that you are buying as a business and which version of the Terms applied. When you sign in, we store your e-mail address as an account and send you the sign-in code via the e-mail service Resend (Resend, Inc., USA; EU standard contractual clauses). When you request a code, we set a technically necessary cookie (__Host-gl_login) for 15 minutes, which binds the code to your browser. After you sign in, we set a technically necessary session cookie (__Host-gl_sitzung, 30 days) so that you stay signed in. Neither is used for tracking. On your first purchase, we create a customer at Stripe for your account so that your purchases and invoices are kept together. Providing your e-mail address is required for sign-in and purchase; without it, you can only create the free label.

Retention periods

  • Sign-in codes: 10 minutes, then deleted.
  • Messages sent via the contact form: in our database for 180 days at most, then deleted automatically; the forwarded e-mail for as long as it is needed for your enquiry.
  • Session cookie and session: 30 days or until you sign out.
  • Counters against abuse: until the time window expires, 24 hours at most.
  • Visitor statistics (with consent): page views and events 180 days, daily key two days at most; origin information on the account until the account is deleted; cookie with your choice 12 months.
  • Account, labels, guarantee statements and directory entry: until you request deletion.
  • Invoices and accounting records: 8 years (§ 147(3) AO, § 257(4) HGB), then deleted. AO: German Fiscal Code (Abgabenordnung); HGB: German Commercial Code (Handelsgesetzbuch).
  • Server logs at Cloudflare: according to Cloudflare’s periods, usually a few days.

Deleting your account: Write to us from the e-mail address of your account at info@liquiflow.app or via the contact form (topic “Data protection”). We will then delete the account, labels, guarantee statements and directory entry; any unused credit is forfeited as a result (section 5 of the Terms). We keep invoices and accounting records for 8 years because of the statutory obligations.

Links to the Shopify App Store or to EU pages lead to third-party websites. Only when you follow such a link do their privacy policies apply there. The links to the App Store contain an identifier showing which campaign of this website they come from (UTM parameters), but no information about you as a person.

Contact form

If you write to us via the contact form, we process the topic, name, e-mail address, optionally your company, and the message in order to answer your enquiry (Art. 6(1)(b) GDPR for questions about a contract or purchase, otherwise Art. 6(1)(f) GDPR). The message is forwarded to us as an e-mail via Resend (Resend, Inc., USA; EU standard contractual clauses) and, for security, stored in our database at Cloudflare. To protect against abuse, we use Cloudflare Turnstile and briefly count requests per connection as a salted hash value. We do not send you a confirmation e-mail.

Live chat (Crisp)

You can write to us in the chat at the bottom right of every page. The chat is provided by Crisp (Crisp IM SAS, France). As long as you do not click “Chat”, nothing is loaded from Crisp: no connection to Crisp, no cookies. Only when you click does your browser load the chat from Crisp. Crisp then processes your IP address, information about your browser and device, the page visited and everything you write in the chat, such as your name or e-mail address if you provide them. So that the conversation is preserved when you change pages, Crisp stores an identifier in cookies and in your browser’s storage; on our side, the browser remembers until the tab is closed that you have opened the chat. The legal basis is your enquiry (Art. 6(1)(b) GDPR for questions about a contract or purchase, otherwise Art. 6(1)(f) GDPR); we base access to your terminal device on § 25(2) no. 2 TDDDG, because you expressly call up the chat. We delete chat histories when they are no longer needed to answer you and there is no obligation to retain them.

Contact by e-mail

If you write to us, we process your details in order to answer your enquiry (Art. 6(1)(b) or (f) GDPR) and delete them when they are no longer needed for this and there is no obligation to retain them.

Your rights

You have the right of access, rectification, erasure, restriction of processing and data portability (Art. 15 to 20 GDPR). You can withdraw consent at any time with effect for the future (Art. 7(3) GDPR).

Right to object: Where we process data on the basis of our legitimate interest (Art. 6(1)(f) GDPR), you can object at any time on grounds relating to your particular situation (Art. 21 GDPR). An informal e-mail is sufficient.

You can also lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Bavarian State Office for Data Protection Supervision (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA), Promenade 18, 91522 Ansbach, Germany.

Last updated: 8 October 2026