SendLabel Legal
Privacy Policy
Information under the GDPR/DSGVO for the use of SendLabel.
1. Controller
Depha GmbH, Steinriedendamm 15, Halle 1, Eingang 1, 38108 Braunschweig, Germany, Local Court Braunschweig HRB 203187, VAT ID: DE275113400, EORI: DE1536699.
Bank Details
Sparkasse Celle-Gifhorn-Wolfsburg, IBAN: DE60 2695 1311 0161 6616 32, BIC: NOLADE21GFW.
2. Contact
Email: info@sendlabel.de
Phone: +49 151 4581 6823
2a. Data Protection Contact
Privacy-related requests can be sent to info@sendlabel.de and will be handled by our responsible internal team.
3. Purposes of Processing and Legal Bases
We process personal data to operate our platform for collecting shipping data, ordering/creating shipping labels, and providing tracking and document downloads such as labels, QR codes and invoices.
The legal bases include in particular Art. 6(1)(b) GDPR (contract performance / pre-contractual measures), Art. 6(1)(c) GDPR (legal obligations such as tax and commercial retention duties), and Art. 6(1)(f) GDPR (legitimate interests such as abuse/fraud prevention, IT security and error analysis).
4. What Data We Process
Depending on your use of the platform, we may process: account data (email address, password hash, login data); shipment data (sender/recipient name, address, optional email/phone, parcel details, and customs data for international shipments); order and payment data (order status, amounts, currency, payment references such as Stripe checkout/payment references); communication data; and usage/technical data such as IP address, timestamps, device/browser information and server logs.
If a visitor separately consents to the analytics category, we also process anonymous visit-analytics data such as page paths, visit timestamps, referrer data, UTM parameters, language, country code and browser-level anonymous visitor/session identifiers. This data is used for operations analysis, attribution and website optimization and is not activated before consent.
4a. HS Code / TARIC Assistance
When you use our international customs-assistance features, we may additionally process item descriptions, selected or suggested HS code / TARIC values, goods value, country-of-origin data and language preferences in order to provide matching, smart suggestions, automatic form filling and multilingual display.
To improve the experience for German-, English- and Chinese-speaking users, official nomenclature descriptions may be machine-translated and stored in our internal reference database. Such translations and suggestions are provided for search and data-entry assistance only and do not replace your own responsibility to verify the correct customs classification and declaration.
4b. Automated Decision-Making and Risk Assessment
To prevent abuse, fraud and misdeclaration, we may perform automated risk assessments on orders based on order data (for example the difference between declared and measured weight/dimensions), payment behaviour, address information and order history (for example to identify possible high-risk or under-declaration cases).
The legal basis for this processing is Art. 6(1)(b) GDPR (performance of contract) and Art. 6(1)(f) GDPR (legitimate interests, in particular fraud prevention and abuse detection).
Where automated assessment leads to a decision that produces legal effects concerning you or similarly significantly affects you (for example suspension of service or additional charges), you have the right to obtain human review, express your point of view and contest the decision (Art. 22 GDPR). You can exercise this right by contacting us at info@sendlabel.de.
5. Recipients and Processors
To provide our services, we use service providers and transfer data where necessary, for example to shipping carriers (such as DHL Paket, Deutsche Post International, DPD), payment providers (such as Stripe / PayPal where enabled), hosting/IT providers, email delivery providers, and the relevant identity provider where you actively choose external sign-in (such as Google or Microsoft).
6. Third-Country Transfers
Some service providers may also process data outside the EU/EEA, for example the payment provider Stripe, as well as the relevant identity provider where you actively choose Google or Microsoft external sign-in, which may process data in the United States.
Such transfers are carried out on the basis of an adequacy decision under Art. 45 GDPR (EU-US Data Privacy Framework) or standard contractual clauses under Art. 46 GDPR.
7. Storage Period
We store personal data only for as long as necessary for the stated purposes. Invoices and tax/commercial records are retained for 10 years pursuant to Section 147 AO and Section 257 HGB; general order and contract data are retained for 6 years pursuant to Section 147 AO.
Server log data is kept only for a short period as technically necessary and is then deleted or anonymized. Login session data is retained for the duration of the session; password reset tokens are valid only for a short period and expire afterwards.
8. Cookies and Similar Technologies
We primarily use technically necessary cookies or similar technologies to operate the platform, for example for login sessions, security, language preference, guest-cart flows and anti-forgery checks for external sign-in.
The public website now provides a consent-management flow. Analytics and marketing categories are disabled by default and are only activated after active visitor consent; visitors may later withdraw that consent at any time.
Once analytics consent is granted, we activate anonymous visit analytics to record page views, referrer data, UTM campaign parameters, language, country code and anonymous browser identifiers. If consent is not granted or is later withdrawn, those non-essential analytics do not start or are stopped immediately.
As of this version, the marketing category is not yet used for active advertising or remarketing cookies; if activated later, it would still require prior consent.
For a more specific overview of cookie names, purposes and retention periods, please see /cookies.
9. Your Rights
Under the GDPR, you have rights including access, rectification, erasure, restriction of processing, data portability, objection to processing based on Art. 6(1)(e)/(f) GDPR, and withdrawal of consent with effect for the future.
To exercise these rights, you can contact us at info@sendlabel.de. To avoid disclosure to unauthorized third parties, we may request reasonable information to verify identity.
10. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates the GDPR (Art. 77 GDPR).
11. Security
We implement appropriate technical and organizational measures to protect your data against loss, manipulation and unauthorized access.
Version: 2026-08-10