Last updated: May 4, 2026
(Data Protection Inquiries: info@swisswowcow.ch)
We take the protection of your personal data seriously and treat your personal data confidentially and in accordance with the statutory provisions, in particular the revised Swiss Data Protection Act (revDSG, in force since September 1, 2023) and, where applicable, the EU General Data Protection Regulation (GDPR). The use of our website is generally possible without providing personal data.
Data Controller
The controller responsible for data processing on this website is:
Swiss Health & Nutrition AG
Spühlstrasse 4
CH-9016 St. Gallen
Switzerland
Email: info@swisswowcow.ch
Phone: +41 71 877 10 68
UID: CHE-157.641.272
What personal data do we process?
Depending on how you interact with our services, where you live, and as permitted or required by applicable law, we may collect or process the following categories of personal data:
-
Contact details such as name, postal address, billing and shipping address, phone number, and email address.
-
Financial data such as credit/debit card and financial account numbers, payment card information, transaction details, payment method, and payment confirmation.
-
Account information such as username, password, configurations, and settings.
-
Transaction information regarding items viewed, added to cart, purchased, returned, exchanged, or canceled, and your past transactions.
-
Communication data from your communication with us (e.g., customer support inquiries, chats, emails).
-
Device and connection data such as IP address, browser and device information, network connection, and other unique identifiers.
-
Usage information about your interaction with our services (e.g., when and how you browse our website).
Sources of personal data
We obtain personal data from the following sources:
-
Directly from you: when creating an account, placing an order, subscribing to a newsletter, making customer support inquiries, or other communication.
-
Automatically through our services: via your end device when visiting our website, and via cookies and similar technologies.
-
From our service providers: when they collect or process personal data on our behalf (e.g., payment, shipping, marketing service providers).
-
From our partners and other third parties: e.g., from marketing platforms, social networks, or advertising networks, as permitted by law.
How do we use your personal data?
We process your personal data for the following purposes:
-
Provision and improvement of our services: contract fulfillment, payment processing, order execution, shipping, returns, account management, personalization, and improvement of the shopping experience.
-
Marketing and advertising: sending marketing and advertising communications via email, SMS, or mail, as well as placing online advertisements – always within the scope of your consent or our legitimate interests.
-
Security and fraud prevention: authentication, protection against fraudulent or abusive activities, security of our services.
-
Customer communication: processing your inquiries, providing customer support, maintaining customer relationships.
-
Fulfillment of legal obligations: compliance with legal requirements, response to official requests, assertion or defense of legal claims.
Currency conversion
By using our website, you (the visitor) agree that third parties may process your IP address to determine your location for the purpose of currency conversion. You also agree that this currency will be stored in a session cookie in your browser (a temporary cookie that is automatically removed when you close your browser). We do this so that the selected currency remains selected and consistent when browsing our website, allowing prices to be converted into your local currency.
Cookies and similar technologies
Our website uses cookies to provide you with a better user experience. Cookies are small text files that are placed on your computer and stored by your browser. They cannot contain harmful code.
We use the following cookie categories:
-
Technically necessary cookies: Required for the operation of the website (e.g., shopping cart, login, language selection). Legal basis: Art. 6 para. 1 lit. b GDPR or Art. 31 para. 2 lit. a revDSG.
-
Functional cookies: Improve the user experience (e.g., currency selection, geo-localization). Legal basis: Consent (Art. 6 para. 1 lit. a GDPR).
-
Analytical cookies: Allow us to analyze usage behavior and improve the website. Legal basis: Consent.
-
Marketing cookies: Used for personalized advertising. Legal basis: Consent.
You can give, adjust, or withdraw your consent at any time via our cookie banner.
Hosting Provider and Server Log Files
The website provider automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These include:
- IP address
- Browser type and version
- Operating system used
- Referrer URL
- Hostname of the accessing computer
- Time of the server request
This data cannot be directly attributed to specific individuals. This data will not be merged with other data sources. We reserve the right to retrospectively examine this data if we become aware of concrete indications of unlawful use.
This data, as well as all data of this website, is stored with our hosting provider Shopify International Limited, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland. You can find Shopify's privacy policy at https://www.shopify.com/legal/privacy.
Relationship with Shopify (Joint Responsibility)
The services are hosted by Shopify, with Shopify collecting and processing personal data about your access to and use of the services to provide and improve the services for us. Data you submit to the services will be shared with Shopify and with third parties, who may be located in countries other than your country of residence.
To protect, expand, and improve our business, we also use certain advanced Shopify features (e.g., Shop Pay, Shopify Audiences, personalization features) that incorporate data and information from your interactions with our shop, with other Shopify merchants, and with Shopify itself. As part of these advanced features, Shopify partially processes personal data as a joint controller within the meaning of Art. 26 GDPR. In these cases, Shopify is also the contact person for requests to exercise your rights regarding these processing activities.
For more information on how Shopify uses your personal data and what rights you have, please refer to the Shopify Privacy Policy for Consumers at https://www.shopify.com/legal/privacy/app-users and the Shopify Privacy Portal at https://privacy.shopify.com/en.
SSL/TLS Encryption
This website uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content. You can recognize an encrypted connection by the fact that the browser's address line changes from "http://" to "https://" and by the padlock symbol in your browser bar. When SSL/TLS encryption is enabled, the data you transmit to us cannot be read by third parties.
Order Processing and Payment Service Providers
To process your order, we collect the data required for contract fulfillment (name, shipping address, billing address, email, phone, payment details). Legal basis is Art. 6 para. 1 lit. b GDPR or Art. 31 para. 2 lit. a revDSG (contract fulfillment).
Payment Providers: Shopify Payments & Stripe
We use the service provider Shopify Payments (provided by Shopify International Ltd., Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, Ireland) for payment processing.
Within the scope of Shopify Payments, payment processing is carried out by the service provider Stripe Payments Europe Ltd. (1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland).
-
Data processed: This includes, among other things, name, address, account number, bank sort code, credit card number, invoice amount, currency, and transaction number.
-
Purpose: The data is passed on exclusively for the purpose of payment processing in accordance with Art. 6 para. 1 lit. b GDPR.
-
Fraud Prevention: To check accounts for fraud or other issues, data may also be used to employ services such as Sift.
More information on data protection for Shopify Payments can be found at: https://www.shopify.com/legal/privacy. For data protection information regarding Stripe Payments Europe Ltd., please see: https://stripe.com/de/privacy.
Other Payment Methods
TWINT, PostFinance, and other local payment methods: Processing is carried out directly by the respective provider in accordance with their data protection regulations.
Shipping and Logistics
To process shipping, we pass on your shipping address and contact details to our logistics partners:
-
DHL (DHL Express (Switzerland) AG, DHL Group, or the responsible DHL company in the destination country)
Legal basis: Art. 6 para. 1 lit. b GDPR or Art. 31 para. 2 lit. a revDSG (contract fulfillment).
Shipping Software: ShippyPro
To create shipping labels, transfer shipment data to shipping companies, and provide shipment tracking and return processes, we use the software ShippyPro from Italian Valley S.r.l., Piazza Francesca Morvillo 15, 50144 Firenze (FI), Italy (P.IVA 06587610483).
As part of order processing, shipping data (name, shipping address, email address, phone number for notifications, order details) is transmitted to ShippyPro and passed on to the respective shipping service provider. Processing is carried out exclusively for the purpose of shipping and shipment tracking.
We have concluded a data processing agreement (DPA) with ShippyPro. Legal basis: Art. 6 para. 1 lit. b GDPR or Art. 31 para. 2 lit. a revDSG. Privacy Policy: https://www.shippypro.com/en/privacy-policy.
Newsletter Data and Email/SMS Marketing (Shopify Messaging)
If you wish to receive our newsletter, we need your email address (or your phone number for SMS marketing) and your consent to receive the newsletter. We use this data exclusively for sending the newsletter and related marketing communications. You can revoke your consent to the storage of your contact details and their use for sending the newsletter at any time, for example, via the "Unsubscribe" link in the newsletter or by replying accordingly to a marketing SMS.
Subscription to our newsletter is done via a so-called double opt-in procedure. This means that after subscribing, you will receive an email (or SMS) asking you to confirm your subscription. This confirmation is necessary to ensure that no one can subscribe with someone else's contact details.
Newsletter subscriptions are logged so that we can prove that the subscription process took place in accordance with legal requirements. This includes storing the time of subscription and confirmation, as well as the IP address.
Shopify Messaging
The sending of our newsletters (email and SMS), marketing campaigns, and automations is done directly from our Shopify backend via the app Shopify Messaging from Shopify Inc., 151 O'Connor Street, Ottawa, ON K2P 2L8, Canada or Shopify International Limited, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland.
Since our shop is hosted on Shopify anyway, your contact details and newsletter-related data are processed within the existing Shopify infrastructure; no additional transmission to a separate third-party marketing provider takes place. Within Shopify Messaging, the following data is processed in particular: name, email address, phone number, physical address, geolocation, IP address, and browser and operating system information.
Shopify uses this information on our behalf to send and analyze our campaigns. To the extent that Shopify uses this data to provide and improve its own platform services, the supplementary information in the section "Relationship with Shopify (Joint Responsibility)" applies.
Canada – where the app provider Shopify Inc. is based – has an adequacy decision from the EU Commission and a corresponding recognition decision from the Swiss Federal Council; data transfer there is therefore permitted without further guarantees. For more information, see the Shopify Privacy Policy at https://www.shopify.com/legal/privacy.
Statistical Surveys and Analyses in the Newsletter
Our newsletters may contain a so-called web beacon, i.e., a pixel-sized file that is retrieved from Shopify servers when the newsletter is opened. During this retrieval, technical information, such as information about the browser and your system, as well as your IP address and the time of retrieval, are collected. This information is used for the technical improvement of the services – either through the technical data or through analyses of target groups and their reading behavior, based on access locations or access times.
Statistical surveys also include determining whether newsletters are opened, when they are opened, and which links are clicked. For SMS campaigns, click and conversion data are also analyzed.
Cancellation / Withdrawal
You can cancel the receipt of our newsletter at any time, i.e., withdraw your consent. This simultaneously revokes your consent to the sending of the newsletter and to statistical analyses. You will find a link to cancel the newsletter at the end of each newsletter; for SMS messages, you can unsubscribe by replying as indicated in the respective message (usually with "STOP").
Legal Bases
Consent to send newsletters is based on Art. 6 para. 1 lit. a and Art. 7 GDPR or Art. 6 para. 6 revDSG. The use of Shopify Messaging as the sending infrastructure, the execution of statistical surveys and analyses, and the logging of the registration process are based on our legitimate interests in accordance with Art. 6 para. 1 lit. f GDPR or Art. 31 para. 2 lit. d revDSG.
Web Analysis and Advertising
Google Analytics 4
This website uses Google Analytics 4 (GA4), a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. GA4 uses cookies and similar technologies that enable an analysis of your use of the website. The information generated by the cookie about your use of this website is usually transferred to Google servers and stored there; transfer to the USA may occur.
GA4 anonymizes IP addresses by default and does not store them. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity, and to provide other services related to website and internet usage to the website operator.
Legal basis: Consent via the cookie banner (Art. 6 para. 1 lit. a GDPR). Transfer to the USA is based on the EU-U.S. Data Privacy Framework and Standard Contractual Clauses. You can revoke your consent at any time via the cookie settings.
More information: https://policies.google.com/privacy.
Google Ads and Conversion Tracking
We use Google Ads to advertise our products. As part of this, conversion tracking cookies are used to measure the effectiveness of our advertising campaigns. The provider is Google Ireland Limited. Legal basis: Consent via the cookie banner.
Meta Pixel (Facebook/Instagram) and Conversion API
We use the Meta Pixel and the Conversion API from Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. With these, we measure the effectiveness of our advertisements on Facebook and Instagram and can define target groups for advertising purposes (Custom Audiences, Lookalike Audiences).
Server-side conversion data is transmitted via Stape.io (Stape Solutions LLC, USA) as a server-side tagging provider on our behalf.
Legal basis: Consent via the cookie banner (Art. 6 para. 1 lit. a GDPR). Transfer to the USA based on the EU-U.S. Data Privacy Framework and Standard Contractual Clauses. Meta Privacy Policy: https://www.facebook.com/privacy/policy. Stripe Privacy Policy: https://stape.io/privacy-policy.
Google Shopping / Multifeeds (WoolyTech)
To provide our product catalog on Google Shopping, Meta platforms, and other marketing channels, we use the app Multiple Google Shopping Feeds (Multifeeds) from WoolyTech Pty Ltd, Australia. The app generates and transmits our product catalog in the form of structured product data feeds to the respective platforms (Google Merchant Center, Meta Commerce Manager, etc.).
As part of this service, product-related data (product title, description, price, availability, image URLs, etc.) is processed, but no direct personal data of end customers. To the extent that the app serves pixel-based marketing tags in the user's browser (e.g., Meta Pixel events), the respective information on these third-party providers applies.
Legal basis: Legitimate interest in effective product marketing (Art. 6 para. 1 lit. f GDPR) or consent via the cookie banner, to the extent that marketing pixels are served. WoolyTech Privacy Policy: https://woolytech.com/privacy-policy/.
Fonts (Google Fonts / locally integrated)
Fonts are used on this website which, as far as technically possible, are integrated locally on our server, so that no connection to Google servers is established. In individual cases where fonts are dynamically loaded by Google, your browser transmits your IP address to Google Ireland Limited. More information: https://developers.google.com/fonts/faq/privacy.
Social Media Links
Our website contains links to our profiles on social networks (Facebook/Meta, Instagram, LinkedIn, YouTube, Vimeo). These are pure links, not embedded plug-ins. Data is only transferred to the respective providers when you actively click on the corresponding link and are redirected to the platform. The data protection regulations of the respective provider apply on the respective platform:
Embedded Videos (Vimeo / YouTube)
Where we embed videos from the platforms Vimeo or YouTube, this is done in the enhanced privacy mode ("Privacy Enhanced Mode") or only after your consent via the cookie banner. When playing, data (including IP address) is transmitted to the respective platform. Legal basis: Consent (Art. 6 para. 1 lit. a GDPR).
Content Delivery Network (Cloudflare)
To deliver static content and protect against attacks, we partly use Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. When you access our site, connection data (including IP address) is transmitted to Cloudflare. Legal basis: Legitimate interest in security and performance (Art. 6 para. 1 lit. f GDPR). Transfer to the USA based on the EU-U.S. Data Privacy Framework and Standard Contractual Clauses. Privacy Policy: https://www.cloudflare.com/privacypolicy/.
Translation and Multilingualism (Hextom)
Our website is available in multiple languages. For this, we use the app Hextom Translate & Adapt from Hextom Inc., USA. Hextom does not process personal data of end customers, but exclusively content and configuration data of our shop.
Third Country Transfers
Some of the services mentioned above are based or process data in countries outside of Switzerland and the EU/EEA, particularly in the USA. In such cases, we base the transfer on:
-
Adequacy decision of the EU Commission or recognition decision of the Federal Council (e.g., EU-U.S. Data Privacy Framework / Swiss-U.S. Data Privacy Framework, if the provider is certified), or
-
Standard Contractual Clauses (SCC) of the EU Commission in accordance with Art. 46 GDPR or the standard contractual clauses recognized by the FDPIC, or
-
Your explicit consent in accordance with Art. 49 para. 1 lit. a GDPR or Art. 17 para. 1 lit. a revDSG.
Children's Data
Our services are not directed at children. We do not knowingly collect personal data from children who are not of legal age in their country or are under 16 years of age. If you are a parent or guardian of a child who has provided us with personal data, please contact us at info@swisswowcow.ch, so we can delete the data.
We do not knowingly "sell" or "share" personal data of individuals under 16 years of age within the meaning of applicable data protection laws.
Security of Your Data
We employ technical and organizational measures to protect your personal data against unauthorized access, loss, misuse, or alteration (including SSL/TLS encryption, access controls, data processing agreements with our service providers). However, please note that no security measure can guarantee absolute security. There are residual risks, especially when transmitting data over the internet. Avoid transmitting sensitive or confidential information via insecure communication channels.
Storage Duration
We store personal data only for as long as is necessary for the respective purposes or as required by statutory retention periods (in particular, commercial and tax retention periods of up to 10 years according to Art. 958f OR). Newsletter data is stored until consent is withdrawn.
Your Rights
Under Swiss revDSG and EU GDPR, you have the following rights regarding your personal data:
-
Right of access (Art. 25 revDSG / Art. 15 GDPR): You have the right at any time to free access to your stored personal data, its origin, recipients, and the purpose of data processing.
-
Right to rectification (Art. 32 revDSG / Art. 16 GDPR)
-
Right to erasure (Art. 32 revDSG / Art. 17 GDPR)
-
Right to restrict processing (Art. 18 GDPR)
-
Right to data portability (Art. 28 revDSG / Art. 20 GDPR)
-
Right to object to processing (Art. 30 revDSG / Art. 21 GDPR)
-
Withdrawal of granted consents with effect for the future
To exercise your rights, please contact info@swisswowcow.ch. We may request further information for identity verification.
Opt-out of Sale/Sharing for Targeted Advertising
Depending on your place of residence, you may have the right to object to the "sale" or "sharing" of your personal data for targeted advertising purposes. You can exercise this right via the following page.
Global Privacy Control (GPC)
If you visit our website with Global Privacy Control (GPC)-signal enabled in your browser, we will – to the extent relevant based on your location – automatically treat this as an opt-out request for the device and browser you are using to visit the website. If we can associate the signal with an existing account, we will also apply the opt-out request to that account. You can find more information about Global Privacy Control at https://globalprivacycontrol.org. We do not process other "Do Not Track" signals.
Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority:
Changes to this Privacy Policy
We reserve the right to adapt this privacy policy to reflect changes in legal circumstances or in our services and data processing. The current version can be found on this page.
Contact
If you have questions about our data protection practices or this privacy policy, or if you wish to exercise any of your rights, please contact:
Swiss Health & Nutrition AG
Spühlstrasse 4
CH-9016 St. Gallen
Switzerland
Email: info@swisswowcow.ch
Phone: +41 71 877 10 68
Within the meaning of the applicable data protection laws, we are the controller of your personal data.