Erinnerungen, die festgehalten werden.

Region and language

We detect your delivery country automatically. You can change the country and language at any time.

Final Version

As of: August 2, 2026

Privacy Policy

How LUMI processes and protects personal data when you visit the website, make a purchase, and use the digital memory world.

Only necessary technology without consent

Analysis only after your selection

Clear purposes and limited storage

This English version is a non-binding editorial translation for convenience. If it differs from the German original, the legally binding German version prevails.

Controller

The controller responsible for the processing described in this Privacy Policy is:

wazzl Schweiz GmbHMattenweg 21
3322 Urtenen-Schönbühl
Switzerland
UID: CHE-285.957.309
Email: hello@wazzl-schweiz.ch

For privacy enquiries, send a message to the email address above with as precise a description of your request as possible. We may request suitable proof of identity so that personal data is not disclosed to unauthorised persons.

Scope and Principles

This Policy applies to the LUMI website, online shop, customer accounts and memory worlds provided through LUMI. We process personal data for specified purposes, proportionately, transparently and with appropriate safeguards.

Swiss data-protection law applies to persons in Switzerland. Where we offer goods or digital services to persons in the European Economic Area, we additionally take the General Data Protection Regulation (“GDPR”) into account. In an EU/EEA context, depending on the purpose, we base processing on performance of a contract or pre-contractual measures, legal obligations, legitimate interests or consent.

Required fields are identifiable in the respective forms. Without the information needed for registration, ordering, payment or delivery, we cannot provide the requested service. Voluntary information and consent may be withheld without the shop’s basic functions becoming unavailable.

We do not use solely automated decisions that produce legal effects concerning you or similarly significantly affect you.

Website and Hosting

When the website is accessed, technically necessary connection and log data is processed. This may include the IP address, date and time, requested address, referrer, browser, device, language, screen size and error and security events. Processing serves to deliver the website, maintain stability, analyse errors, prevent misuse and ensure IT security.

The platform is provided using services from Butterfly Effect Pte. Ltd. (“Manus”), 109 North Bridge Road, #06-W112, Singapore 179097. Manus supports, in particular, hosting, technical infrastructure, integrated authentication, data storage and — only with consent — operator analytics. In an EU/EEA context, our legitimate interest lies in providing a secure and functional online service; when you are logged in, processing also serves to perform the contract.

LUMI fonts are delivered through our own managed storage. Accessing a page therefore does not create an additional connection to Google Fonts.

Cookies and Browser Storage

Necessary session

For logged-in areas, we use the technically necessary lumi_session cookie. It contains a random session key; only its hash is stored on the server. Customer sessions expire after no more than 30 days and staff sessions after no more than 12 hours. The session is revoked on logout.

Local browser storage

The basket is kept in local browser storage under erinnerungstier-cart-v1 so that it is retained between page views. The order data required is transmitted to our systems and Stripe only at checkout. We store your privacy choice under lumi_privacy_consent_v1. These entries remain until you change your choice, delete browser data or the respective function is technically renewed.

Necessary cookies and storage are required for functions you expressly request. Analytics technologies and external Instagram content are handled separately and are not loaded without consent.

Web Analytics and External Content

Web analytics

If you select “Accept all”, we load Manus Analytics. This may process the page address and title, referrer, hostname, language, screen size, device and browser information, time, IP-related connection data and session and visit identifiers. We use this information to evaluate reach, page flows and technical use in aggregate and to improve our service.

In an EU/EEA context, the legal basis is your consent. The website, including shop and account, remains usable without consent. You may change your choice at any time via “Privacy settings” in the footer or the control on this page. Withdrawal takes effect for the future; when analytics is disabled, the page reloads once so that the analytics script is fully stopped.

The local choice is stored until withdrawal or until you delete your browser data. Analytics data is retained only for as long as necessary for the configured aggregated evaluation; necessity is reviewed regularly.

Instagram content from Meta

The homepage contains an optional official profile embed for @pssst.mama on Instagram. Without consent, no Instagram script or media is loaded; only LUMI’s own profile notice and a direct external link remain visible.

If you select “Accept all”, your browser loads the official profile embed from instagram.com/pssst.mama/embed/. Meta may process, under its own responsibility, connection and device data such as your IP address, browser, operating system, referrer, time, language and any existing Instagram/Meta cookies or account information, and may transfer data to the USA or other countries. Further information is available in Meta’s Privacy Policy.

The legal basis in an EU/EEA context is your consent. You may withdraw it at any time through the privacy settings. When optional services are disabled, the page reloads once to remove loaded external content; the direct profile link remains available.

Account, Login and Security

When you register and use an account, we process, in particular, name, email address, login method, role, language, currency and — for password login — a non-reversible password hash. For sessions, failed logins, blocks and password resets, we additionally process token hashes, timestamps and hashed device or user-agent characteristics.

The data serves account creation, authentication, account management, misuse prevention, access recovery and protection of administrative areas. In an EU/EEA context, we base this on performance of the contract and our legitimate interest in secure accounts and systems.

Shop, Orders and Delivery

Depending on the type of order, we process the following data for the basket, checkout, conclusion of the contract, customer service, reversals and delivery:

  • product, quantity, configuration, currency, prices, taxes, discounts and order status;
  • name, email address, telephone number and billing and delivery address, including optional company and region;
  • order and guest references, order number, applicable Terms version and required confirmations;
  • shipping service, tracking number, delivery status and return and support information.

Processing is necessary for pre-contractual measures, performance of the contract, delivery and statutory records. Order and address data may be transmitted to the specific shipping provider used insofar as necessary for delivery.

Payment Processing

Payments are processed through Stripe. At checkout, Stripe processes, in particular, name, email address, billing and delivery address, payment information, product, quantity, amount, currency, time, payment status and data used to prevent fraud and loss. We do not receive complete card or account data, but in particular Stripe session and Payment Intent identifiers, status, amounts and, where applicable, error and refund information.

Depending on the payment method, recipients may include Stripe Payments Europe, Ltd., Ireland, Stripe, Inc. or Stripe, LLC, USA, affiliated Stripe companies, financial institutions and the selected payment provider. Depending on the processing, Stripe acts as our service provider or under its own responsibility for its statutory, regulatory and security purposes. Further information is available in Stripe’s Privacy Policy.

In an EU/EEA context, payment processing serves performance of the contract; statutory documentation and audit obligations and legitimate interests in preventing fraud may also apply.

Memory Worlds and Invitations

To activate and manage a memory world, we process internal and public TAG identifiers, activation status, owner assignment, title, visibility, status and timestamps for deletion requests and deletion. For invitations, we process the invited person’s email address, role, invitation status and a hashed access key.

This data serves to assign the physical memory animal, provide the protected digital area, manage permissions and handle deletion requests. The memory world is private by default. Access is granted only to authorised accounts or validly invited persons.

An upload function for photographs, videos, audio or free-form memory text is not currently enabled. Before such content processing is activated, we will provide information about the types of data concerned, storage rules and rights.

Communications

We use contact data for necessary transactional messages, such as registration, password resets, order confirmation, payment and shipping status, invitations, security notices and responses to enquiries. The recipient address, template, delivery status, time, technical provider ID and error information may be logged.

We send marketing messages only on the basis of valid consent or where expressly permitted by law. Consent may be withdrawn at any time with effect for the future through the method provided in the message or by emailing us.

Recipients and Processors

Internally, access is limited to persons who need it for operations, support, order processing, security or statutory duties. Externally, we disclose data only for specified purposes and to the extent required, in particular to:

  • Manus or Butterfly Effect Pte. Ltd. for hosting, infrastructure, authentication, storage and consent-based analytics;
  • Meta Platforms Ireland Limited and affiliated Meta companies for the optional Instagram profile embed, only after consent;
  • Stripe and participating payment and financial service providers for checkout, payment, refunds and fraud prevention;
  • shipping and logistics companies for delivery;
  • communications and IT service providers for transactional messages, maintenance and security;
  • authorities, courts or other bodies where there is a legal obligation or claims must be protected.

Processors are contractually bound to documented purposes, confidentiality, appropriate safeguards and support for data-protection rights.

Processing Abroad

Data may be processed in Switzerland, the European Economic Area, Singapore, the USA and — depending on the documented subprocessors of the services used — other countries. A country outside Switzerland or the EEA may provide a lower statutory level of data protection.

Safeguards for international transfers

We base transfers on recognised adequacy decisions, certifications such as the Swiss–U.S. Data Privacy Framework, adapted EU Standard Contractual Clauses, contractual data-protection guarantees and, where necessary, supplementary technical safeguards. The Manus data-processing agreement covers the Swiss Data Protection Act and incorporates EU Standard Contractual Clauses for restricted transfers. For transfers from Switzerland to the USA, Stripe refers to the Swiss–U.S. Data Privacy Framework and, additionally, adapted Standard Contractual Clauses.

Information about the safeguards used for a specific transfer may be requested through our privacy contact; legally protected business and security information may be redacted.

Retention and Deletion

We store personal data only for as long as required by the respective purpose, a contract, consent, system security or statutory retention and evidentiary obligations. We then delete or anonymise the data unless continued retention is permitted.

  • Account and profile data is generally stored until the account is deleted or the business relationship ends.
  • Order, payment, accounting and business records are retained in accordance with applicable commercial and tax-law periods, typically for up to ten years.
  • Sessions end on logout or revocation, or no later than their technical lifetime; reset and invitation keys are retained only until expiry or use.
  • Security and audit logs are retained for as long as necessary to investigate misuse, demonstrate accountability and protect claims.
  • Deletions scheduled for memory worlds are carried out in accordance with the displayed process, subject to mandatory retention or necessary backups.

Backups are overwritten in accordance with operational backup cycles. Until then, deleted data is no longer used in production and is processed only where necessary for recovery or security.

Your Rights

Depending on the applicable law, you may in particular request information about your personal data, correction of inaccurate data, deletion, restriction of processing, provision or portability of data, and object to certain processing. You may withdraw consent at any time with effect for the future.

In an EU/EEA context, where processing is based on legitimate interests, you have a right to object on grounds relating to your particular situation; you may object to direct marketing at any time without giving reasons. Rights may be limited by statutory exceptions, the rights of other persons and mandatory retention obligations.

You may lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC). Persons in the EU/EEA may additionally contact the data-protection supervisory authority at their habitual residence, place of work or the place of the alleged infringement.

Security and Changes

We use appropriate technical and organisational measures. These include role-based access, hashed passwords and session keys, encrypted transmission, logging of security-relevant events, restricted administrative permissions and contractual requirements for service providers. No online process can, however, guarantee absolute security.

We update this Privacy Policy when functions, service providers or legal requirements change materially. The current version is always available at /en/datenschutz. In the event of material changes, we additionally provide information in an appropriate form, such as in the account or by email, where required.