Privacy

Last updated 23 July 2026

The short version

We set no cookies and record no sessions. There is no account and no newsletter. Your bag is kept on your own device. We hold personal data when you actively give it to us, for example when you write to us, ask for a download link or buy something. The details are set out below.

Controller

Marcellus Bartsch
c/o Online-Impressum.de #4905
Europaring 90
53757 Sankt Augustin
Germany
Email: hello@moonleaf.art

Hosting and delivery

The pages are delivered by Cloudflare, on servers close to you. When a page is requested, the connection data needed to deliver it, including the IP address, is processed for the duration of that delivery and to defend against attacks. The legal basis is Article 6 (1) (f) GDPR, our legitimate interest in operating the site securely. Cloudflare acts as our processor under Article 28 GDPR. Cloudflare may process data outside the European Economic Area. Its Data Processing Addendum includes the European Commission's Standard Contractual Clauses and supplementary safeguards. You can read Cloudflare's privacy policy and Data Processing Addendum.

Anonymous usage measurement

So that we can tell which pieces people find interesting, we measure usage with analytics we host ourselves on our own server. Nothing is passed to third parties. In detail:

None of this can be traced back to an individual. The legal basis is Article 6 (1) (f) GDPR, our legitimate interest in anonymous, cookie free measurement.

Email and contact

When you write to an address ending in @moonleaf.art, we process your email address, the message headers, the contents of your message and any attachments so that we can answer you. Depending on the reason for your message, the legal basis is Article 6 (1) (b) GDPR for contractual or precontractual communication, Article 6 (1) (f) GDPR for ordinary business communication, or Article 6 (1) (c) GDPR where the law requires us to keep or use the information.

Incoming mail is received by Cloudflare Email Routing and sent over an encrypted connection to a server operated for us by Hetzner Online GmbH in Germany. The complete message, including its metadata, is encrypted there with AES 256 GCM. Messages in the working mailbox are deleted automatically after 45 days. Messages that qualify as business correspondence or accounting records are also copied in their original form to a separate, access-controlled and searchable archive; the stored original message content is encrypted there. They are kept only for the applicable statutory period: generally six years for business correspondence, eight years for invoices and accounting records, and ten years for books and annual accounts. The period runs from the end of the relevant calendar year. Other messages are not moved to the long term archive. We can delete a message sooner when you ask us to, unless it is still needed for a contract, a legal obligation or a legal claim. If our server is temporarily unavailable, Cloudflare may hold an emergency copy for no more than 24 hours. A scheduled process retries every 15 minutes and removes that copy after a verified transfer.

Replies and transactional messages are sent through Brevo (Sendinblue SAS, Paris, France). Brevo receives the recipient address, the message and the delivery data needed to send it. Cloudflare, Hetzner and Brevo act as processors for these purposes. The Brevo Data Processing Agreement forms part of its Terms of Service. Hetzner's privacy information is available on its website.

Bag and checkout

When you put a piece in your bag, that bag is stored on your own device, in your browser's local storage. It holds only what you put there: the piece, the quantity and the price. It is never sent to us, and it is not an identifier. This storage is technically necessary for a bag to work at all, so it needs no consent under section 25 (2) no. 2 TDDDG. You can clear it by emptying the bag.

Payment is handled by Paddle (Paddle.com Market Ltd, London, United Kingdom), which acts as the seller of record. When you go to checkout, Paddle's payment window opens and Paddle processes the data you enter there, including your email address, payment details and the country needed for value added tax. Paddle is the controller for that payment data and issues the invoice; see paddle.com/legal/privacy. We receive from Paddle the transaction, the items bought and your email address, and we store them on our own systems to deliver the files, to send the download link and to keep the records that tax law requires. The legal basis is Article 6 (1) (b) GDPR, performance of the contract, and for the records Article 6 (1) (c) GDPR.

The download link we send is signed and expires after 72 hours. We log that a link was used, with the order it belongs to and the country of the request, so that we can see misuse.

Your rights

You have the right to access, rectification, erasure, restriction of processing, objection and data portability, and the right to complain to a data protection authority. Write to hello@moonleaf.art. Please note that if you have not given us your address, we hold no data that could identify you.

Changes

If what we do with data changes, we update this page and the date at the top.

Back to Moonleaf