Privacy
Privacy Policy of Mable GmbH
§ 1 Introduction
By using Mable’s services, you grant us access to certain data, which we handle in accordance with the General Data Protection Regulation (GDPR) and other relevant data protection laws of the European Union.
This Privacy Policy explains what data we collect, how we use it, and your rights in relation to it.
§ 2 Data Controller Information
Mable GmbH acts as the Data Controller for all personal data collected and processed through its services.
The Mable GmbH is based at Bahnhofplatz 12, 76137 Karlsruhe, Germany.
§ 3 Categories of Data We Process
We may process the following categories of data:
Contact details (e.g., email address)
Authentication credentials (e.g., encrypted passwords)
Analytics and advertising data (e.g., Google Analytics, Meta Ads, TikTok, Pinterest)
E-commerce transaction data (e.g., Shopify and Shopware order details)
Web and application usage data
Web and application usage data
Support interaction data (e.g., helpdesk tickets, chat transcripts, feedback forms)
§ 4 Legal Basis for Processing
We process your data based on the following legal grounds:
Your explicit consent (Art. 6(1)(a) GDPR): For example, when you opt into email marketing or allow integration with external services.
Contractual necessity (Art. 6(1)(b) GDPR): For the performance of a contract, such as providing the Mable service to you.
Compliance with legal obligations (Art. 6(1)(c) GDPR): Where we are required by law to retain certain records or cooperate with lawful investigations.
Legitimate interests (Art. 6(1)(f) GDPR): For purposes such as improving our services, prevention of fraud, internal analytics, and ensuring platform security. When relying on this basis, we always assess and balance our interests against your fundamental rights and freedoms.
Protection of vital interests (Art. 6(1)(d) GDPR): In rare cases, such as where data processing is necessary to protect someone’s life or physical integrity.
Public interest or official authority (Art. 6(1)(e) GDPR): Only applicable if processing is required for a task carried out in the public interest or the exercise of official authority.
We always ensure transparency and maintain clear documentation of our processing activities as required by GDPR.
§ 5 Secure Data Transfer and Storage
Data is transferred via secure (SSL/TLS) connections to protect it during transmission. All data storage is encrypted both in transit and at rest. We use industry-leading cloud infrastructure providers including Google Cloud, AWS, and Oracle, all of which adhere to stringent international security standards such as ISO/IEC 27001.
All our data is stored and processed in the European Economic Area (EEA). Our data centers are protected through physical and logical access controls, continuous monitoring, and routine security audits. Access to stored data is strictly limited to authorized Mable personnel and select contractors who are bound by confidentiality obligations.
Data backups are performed regularly and encrypted to ensure business continuity and disaster recovery capabilities. We also employ firewall protection, role-based access control, and security incident response procedures to ensure a high level of protection for your personal data.
§ 6 Email and Passwords
Your email is used for support and limited product announcements (opt-out possible).
Passwords are stored in encrypted form.
§ 7 Authentication and Integrations
Google Login: Grants access to name, profile image, email, and Google Analytics properties.
Pinterest, TikTok, META Login: May provide access to profile and performance data necessary for integration.
We never use login data for profiling or sell it to third parties.
§ 8 Analytics and Performance Data
Google Analytics: Used to display site performance, develop internal analytics, and create anonymized benchmarks (minimum cohort size: 10).
TikTok, Pinterest & Meta (Facebook/Instagram) and Google Ads: Access is limited to campaign performance data and meta-information, such as cost, impressions, and engagement rates.
Data from all analytics platforms is used only for customer services or benchmarking in anonymous form.
§ 9 Shopify and Shopware Integration
We access and process only non-personal order data (order ID, amount, product). When transferring personally identifiable information (PII) to destinations like Segment.com, it is passed directly without storage. PII refers to any data that can be used to identify an individual, such as names, email addresses, or phone numbers.
§ 10 Advertising Platforms Access
We access the following data for service analytics only:
Account meta-information
Ad performance data (costs, clicks)
Associated identifiers
This includes Meta Ads, TikTok Ads, Pinterest Ads and Google.
§ 11 Use of Google OAuth & User Data
We do not collect or store PII via Google OAuth. Any data accessed is application-specific (e.g., conversion metrics).
This data is stored temporarily and deleted within 60 days of account closure or inactivity.
§ 12 Cookies and Tracking Technologies
We use cookies only where necessary to provide core functionality or with your explicit consent.
You may manage your cookie preferences via our Cookie Consent Manager.
§ 13 Data Sharing and Processors
Your data may be shared with the following categories of recipient:
Cloud infrastructure providers (e.g., Google Cloud, AWS, Oracle)
Internal staff and contractors (bound by NDAs)
Legal authorities (where required)
We do not sell your data to third parties.
§ 14 International Data Transfers
All personal data is exclusively stored and processed within the European Union (EU) and European Economic Area (EEA).
We do not transfer data to third countries outside the EU/EEA.
§ 15 Data Retention
Application-specific and anonymized data: retained as long as necessary for service provision.
User data: deleted within 60 days after account closure or inactivity.
§ 16 Your Rights Under GDPR
You have the right to:
Access your personal data
Rectify inaccurate or incomplete data
Erase your data (“right to be forgotten”)
Restrict or object to processing
Data portability
Withdraw consent at any time
Lodge a complaint with a supervisory authority
To exercise any of these rights, please contact us at data-privacy@mable.ai
§ 17 Changes to This Privacy Policy
We reserve the right to update this Privacy Policy.
Material changes will be notified to users via email or platform notification.
§ 18 Contact Information
Mable GmbH Bahnhofplatz 12
76137 Karlsruhe, Germany
E-Mail: data-privacy@mable.ai
Data Protection Officer:
Mr. Thomas Ott
kolbcom GmbH P7, 22, 68161 Mannheim
E-Mail: info@kolbcom.de
Effective Date: 18.06.2025
Version: 2.3