Status: August 17, 2026

1. Controller

The controller for processing your personal data in connection with the B2B shop shop.marein.ch is:

Marein AG
Bahnhofstrasse 134
8957 Spreitenbach
Switzerland

UID: CHE-107.950.676
Email: info@marein.ch

2. Principles

We process personal data in accordance with the revised Swiss Data Protection Act (nDSG). Personal data is all information relating to an identified or identifiable natural person. In a B2B context, this particularly concerns the contact and communication data of the contact persons designated by our customers.

We process your data only to the extent necessary for contract fulfillment, compliance with legal obligations, or based on our legitimate interests (e.g., secure operation of the shop, fraud prevention, development of our services).

3. What data we process

3.1 Inventory Data (Registration and Customer Account)

  • Company/organization, if applicable UID number, commercial register extract
  • Name, first name, and function of the contact person(s)
  • Billing and delivery address
  • Email address, phone number
  • Access data (username, encrypted password)
  • Customer type (commercial / studio / school) and, if applicable, assigned discount level

3.2 Order and Contract Data

  • Order history, ordered products, quantities, prices
  • Invoice and payment status
  • Communication related to orders (emails, notes)

3.3 Communication Data

  • Content and metadata of emails or messages you send us
  • Information from support inquiries

3.4 Usage and Technical Data

When visiting shop.marein.ch, technical data is automatically collected:

  • IP address (shortened or anonymized)
  • Date and time of access
  • Pages viewed, browser used, operating system, referrer

This data serves for technical provision, security, and error analysis.

4. Purposes of Data Processing

We process your data for the following purposes in particular:

  • Verification of your registration and activation of the customer account
  • Processing of orders, delivery, and invoicing
  • Communication with you (order confirmations, inquiries, support)
  • Credit assessment and fraud prevention
  • Compliance with legal retention obligations (especially OR and MWSTG)
  • Secure and stable operation of the B2B shop
  • Assertion, exercise, and defense of legal claims

5. Cookies and Similar Technologies

On shop.marein.ch, we use only technically necessary cookies, which are essential for the operation of the shop (e.g., login session, shopping cart, language selection). No explicit consent is required for these cookies under Swiss law.

We do not use Google Analytics, Google Tag Manager, Meta pixels, or any other tracking or marketing cookies.

You can delete cookies or restrict their setting in your browser at any time. However, without technically necessary cookies, the shop will only function to a limited extent.

6. Disclosure to Third Parties

We only disclose your data to third parties if this is necessary for the stated purposes, you have given your consent, or we are legally obliged to do so. In particular, we cooperate with the following categories of processors:

6.1 Shop Infrastructure and Hosting

  • Shopify International Ltd. (Ireland) or Shopify Inc. (Canada) – Operation of the shop platform, hosting, storage of customer and order data. Shopify may transfer data to countries outside Switzerland and the EEA (see Section 7).
  • Cloudflare, Inc. (USA) – Content Delivery Network, DNS, and protection against attacks (DDoS, WAF).

6.2 ERP and Internal Systems

  • Microsoft Dynamics 365 Business Central – ERP system for order processing, invoicing, and customer management.

6.3 Shipping

  • Swiss Post AG
  • DPD (Schweiz) AG

These service providers receive the name and delivery address of recipients so they can deliver the shipments.

6.4 Other Recipients

If necessary, we may disclose data to:

  • Tax and legal advisors (to the extent permitted by law)
  • Authorities (if legally obliged)
  • Courts and collection service providers (in case of payment default or legal disputes)

All processors are contractually obliged to comply with Swiss data protection law.

7. Data Transfer Abroad

Some of the service providers mentioned above process data in countries outside Switzerland, particularly in the EU, Canada, and the USA. These countries do not always have a level of data protection equivalent to that of Switzerland.

We ensure adequate protection through:

  • Selection of service providers that have joined the Swiss-U.S. Data Privacy Framework (DPF), or
  • Conclusion of Standard Contractual Clauses (SCC) with the processors, supplemented by Swiss-specific adjustments.

8. Storage Duration

We store your data only for as long as necessary for the stated purposes or as required by legal retention obligations. In particular, the following apply:

  • Customer account: as long as your account is active, then deletion or anonymization
  • Order and invoice data: 10 years according to Art. 958f OR
  • Communication data: usually up to 24 months after completion of communication
  • Server log files: usually a maximum of 12 months

After expiry, the data will be deleted or anonymized, unless there is another legal retention obligation.

9. Your Rights

Under the nDSG, you have the following rights regarding your personal data:

  • Information about the data processed about you
  • Rectification of inaccurate data
  • Deletion or blocking of data, provided there is no legal retention obligation
  • Issuance or transfer of your data in a common electronic format
  • Objection to certain processing

To exercise your rights or for questions, please contact info@marein.ch. For security purposes, we may require proof of identity.

You also have the right to lodge a complaint with the competent supervisory authority. In Switzerland, this is the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, www.edoeb.admin.ch.

10. Data Security

We take appropriate technical and organizational measures to protect your data against unauthorized access, loss, misuse, or alteration. These include, in particular:

  • Encrypted transmission (SSL/TLS)
  • Access controls and authorization concepts
  • Regular backups
  • Protection against attacks (e.g., via Cloudflare WAF)
  • Obligation of our employees and service providers to confidentiality

Despite careful measures, complete security during data transmission over the Internet cannot be guaranteed.

11. Changes to this Privacy Policy

We reserve the right to adapt this privacy policy at any time to reflect changed legal or factual circumstances. The version published on shop.marein.ch applies.

12. Contact

For questions about data protection or to exercise your rights, please contact us at:

Marein AG
Bahnhofstrasse 134
8957 Spreitenbach
Switzerland

Email: info@marein.ch