Privacy policy


1. Introduction

gebana AG, Ausstellungsstrasse 21, 8005 Zurich ("gebana", "we", "us" or "our") is the operator of the website ("gebana website") and as well as the provider of the services offered thereon and is therefore responsible for the collection, processing and use of your personal data. The protection of your privacy is very important to us and we ensure that you feel safe as well as that your personal data is processed in accordance with the applicable data protection laws.

This statement on our handling of personal data ("privacy policy") applies when we collect and process personal data and data on the gebana website. This privacy policy describes how and why we process your personal data, what we do to protect your personal data and how you can exercise your rights. If you have any questions or comments about this privacy policy or the processing of your personal data, please feel free to contact us. Contact information can be found at the end of this privacy policy.


2. What information do we collect and what is this information used for?

We may process information about you for the following purposes:


2.1 Provision and administration of the customer account


If you wish to place orders on the gebana website, you can order products as a guest or open a customer account. If you open a customer account, we process information about you in order to register and manage the customer account.


Categories of personal data
  • First and last name
  • Address
  • E-mail address
  • Telephone and / or fax numbers
  • Password
  • Gender
  • Ordering information
  • Payment information


Legal basis

The collection and processing of your personal data is necessary to enable us to fulfil our obligations towards you as a customer pursuant to the contract concluded with you (Art. 6(1)(b) GDPR).


2.2 Administration and execution of your orders on the gebana website


We use your data to administer and execute your orders, to deliver the ordered products and to ensure correct payment. To process card payments, you will be redirected to the website of our payment service provider (Six Payment Services). gebana therefore does not obtain knowledge of your card data. With regard to the processing of your card information by the payment service provider, we ask you to consult and observe the terms and privacy policies of the payment service provider and your card issuer.

We may check the validity of the payment card, the ability to debit the order value and the accuracy of the purchaser's address details. We reserve the right to refuse purchases based on these checks.


Categories of personal data
  • First and last name
  • Gender
  • Billing address (and delivery address, if different)
  • Telephone and / or fax numbers
  • Customer account information, e.g. e-mail address and password (for registered customers)
  • Ordering information


Legal basis

The processing of your personal data is necessary to enable us to fulfil our obligations towards you as a customer pursuant to the contract concluded with you (Art. 6(1)(b) GDPR).

The processing is also necessary to comply with legal obligations to wich we are subject, e.g. the applicable accounting regulations (Art. 6(1)(c) GDPR).

The processing is also necessary to realise our legitimate interest in only accepting valid and covered payment cards as a means of payment (Art. 6(1)(f) GDPR).


2.3 Newsletter subscriptions


You have the option of subscribing to our newsletter, which is sent by e-mail or by letter. Newsletters are only sent by e-mail at your express request. You can cancel your subscription at any time, either via the link in the respective newsletter, by e-mail ( or by letter to the postal address given at the end of this privacy policy.


Categories of personal data
  • Title
  • First and last name
  • E-mail address
  • Postal address


Legal basis

The processing is based on your consent (Art. 6(1)(a) GDPR). Unless we have obtained your consent, we have a legitimate interest in informing our customers about gebana's work, products and news on the gebana website (Art. 6(1)(f) GDPR).


2.4 Administration of customer service


We process your personal data in order to handle customer service matters and to be able to answer your questions to our customer service (by phone or e-mail).


Categories of personal data
  • First and last name
  • Postal address and e-mail address
  • Phone number
  • Ordering information
  • Payment information and payment history
  • Other information that you provide to us in connection with the processing of your case


Legal basis

The processing is necessary to pursue our legitimate interest in handling customer service matters (Art. 6(1)(f) GDPR).


2.5 Cookies and Social Media  

2.5.1 Information on the use of cookies


The gebana website uses cookies that we place ourselves or that are placed by third parties. Cookies are small text files that your browser automatically stores on your computer or device to perform functions when you visit the gebana website.

Cookies help in many ways to make your visit to the gebana website easier, more enjoyable and more meaningful. Some cookies on the gebana website collect personal information about you.

For example, we use cookies so that you may add products to your shopping cart and can temporarily store information. This way, when you fill out a form on the gebana website, you do not have to re-enter the information after visiting another sub-page. Cookies can also be used to identify you as a registered user after you have registered on the gebana website, without you having to log in again after you have visited another website. This may also help us, for example, to monitor the number of users of the gebana website and to understand how people interact with the gebana website. For more information about third-party cookies see below.


Categories of personal data
  • IP address of the connection device
  • Name of the owner of the IP address range (usually your ISP)
  • Date and time of access
  • Website from which the access was made (referrer URL), if applicable with the keywords used
  • Name and URL of downloaded files
  • Status codes (e.g. error messages)
  • Operating system of the device
  • Browser you use (type, version and language)
  • Transmission protocol used (e.g. HTTP / 1.1)
  • Your username from a registration / authentication


Legal basis

The processing is based on your consent (Art. 6(1)(a) GDPR). When processing cookies, we take into account the choices you made when using the gebana website (e.g. whether you accept cookies or not).


2.5.2 Cookies management

Most browsers enable cookie management through the browser settings. For example, you can set your browser to not store cookies on your device, to delete existing cookies, or to always receive a notification when you receive a new cookie. The following pages provide information on how to change browser settings for cookies in some of the most popular browsers. Please note that the links lead to third-party websites over which we have no control.


Please note that if you deactivate or restrict cookies, you might not be able to use all the functions on the gebana website.


2.5.3 Cookies we use Google Analytics and Google Remarketing

We use the web analysis service in Google Analytics to design and continuously optimize the gebana website according to your needs. The information generated by cookies about your use of the gebana website is transmitted to the servers of the providers of these services, stored there and processed for us. Among other things, we collect the following information:

  • IP address of the connection device,
  • Name of the owner of the IP address range (usually your ISP),
  • Date and time of access,
  • the website from which the website was accessed (referrer URL), with keywords if necessary,
  • Name and URL of the downloaded file,
  • Status code (e.g. error messages),
  • Device Operating System,
  • the browser you use (type, version and language),
  • the transmission protocol used (e.g. HTTP / 1.1),
  • Your user name from a registration / authentication,
  • Navigation path that a visitor takes on the website,
  • Time spent on the website or subpage,
  • the subpage on which visitors remain,
  • the country, region or city from which the access is made,
  • Device (type, version, color depth, resolution, width and height of the browser window) and
  • Whether the user is a returning or new visitor.


The information is used to evaluate the use of the gebana website, to compile reports on website activity and to provide other services related to website and internet usage, as well as to design the gebana website according to the needs of the users. This information may also be disclosed to third parties if required by law or if third parties process this information on our behalf.

The provider of Google Analytics is Google Inc Inc, 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, USA or Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"), a company of the holding company Alphabet Inc based in the USA. Before information is transmitted to the provider, the IP address is pseudonymised by activating IP anonymisation ("anonymizeIP") on gebana's website within the EU / EEA. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and truncated there. In these cases, we ensure that Google Inc. maintains an appropriate level of data protection through agreements. According to Google Inc., the IP address is not combined with other information about the user under any circumstances.

For more information about the web analytics service, please visit the Google Analytics website. For instructions on how to prevent the web analytics service from processing your information, please visit

The gebana website also uses Google Remarketing. Google uses stored cookies to display ads based on a user's previous visit to the gebana website. Google may also share this information with third parties where required to do so by law, or where such third parties process the information on Google's behalf. For more information on how to prevent cross-device remarketing/targeting, please visit: Alternatively, users can block third-party cookies by going to the Network Advertising Initiative's webpage. Please note, however, that in this case you may not be able to use all functions of the gebana website in full. Pixel for Facebook tracking

The gebana webshop uses communication tools of the social network Facebook, in particular the retargeting product Website Custom Audiences ("WCA"). The provider is Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. For more information, please visit .

If you select one of the functionalities provided and click on the Facebook icon, a direct connection is established between your browser and the Facebook server. This provides the network with the information that you have visited our website with your IP address and called up the link. If you call up a link to Facebook while you are logged into your Facebook account, the contents of our website can be linked to your profile. This means that Facebook can associate your visit to our website directly with your user account. If you want to prevent this, you should log out before clicking on the corresponding links. An assignment will take place in any case if you log in to Facebook after clicking on the link. For more information on the purpose and scope of data collection and further processing and use of data by Facebook, as well as your settings options for protecting your privacy, please refer to Facebook's privacy policy:

Logged-in Facebook users have the option to object to future retargeting via WCA by using the following link to stop targeted marketing: In addition, all users can block WCA cookies by blocking third-party cookies in their browser settings.

We also use Facebook's "conversion pixel". Facebook can use this tool to track the behaviour of users who have clicked on an ad in Facebook's closed members' area and then were redirected to the gebana website. With the help of a cookie, Facebook can recognise the user in Facebook's closed members' area and personalise advertising.

Facebook users can block the future processing of data by the Facebook product "Conversion Pixel" via: In addition, users can block cookies from third-party providers via their browser settings. Users can also edit settings for other providers via the website Facebook plug-in

Plug-ins for the social network Facebook are integrated on the gebana website. The provider of this plug-in is Facebook Ireland Ltd, 4 Gr-and Canal Square, Grand Canal Harbour, Dublin 2, Ireland. You can recognise Facebook plug-ins by looking out for the Facebook logo or the "Like" button on gebana's website. You can find an overview of Facebook plug-ins here:

When you visit the gebana website, the plug-in establishes a direct connection between your browser and Facebook's server. Facebook thus receives the information that you have visited the gebana website with your IP address. If you click on the Facebook "Like" button while logged into your Facebook account, you can link the content of our pages to your Facebook profile. In this way, Facebook can link your visit to the gebana website with your user account. Please note that we, as the provider of the gebana website, have no knowledge of the content of the transmitted information and its use by Facebook. For more information, please refer to Facebook's privacy policy at Twitter plug-in

We have integrated Twitter functions on the gebana website. These functions are provided by Twitter Inc., 795 Folsom Street, Suite 600, San Francisco, CA 94107, USA. With the help of Twitter and the "retweet" function, you can link the websites you visit to your Twitter account and share them with other users. Information such as IP address, browser type, domains visited, websites visited, mobile operator, device and application ID as well as search terms are transmitted to Twitter in the process. Please note that we, as the provider of the gebana website, have no knowledge of the content of the transmitted data and its use by Twitter. Information on updates to Twitter's privacy policy can be found in the latest version at .

You can change your Twitter privacy settings in your account settings at If you have any questions, please contact Instagram

Components of the service Instagram are integrated on the gebana website. Instagram is a service that allows users to share photos and videos and to redistribute such data in other social networks. The provider of the Instagram services is Instagram LLC, 1 Hacker Way, Building 14 First Floor, Menlo Park, CA, USA.

If you select one of the provided functionalities and click on the Instagram icon, a direct connection is established between your browser and the Instagram server. This provides Instagram with the information that you have visited our website with your IP address and called up the link. If you call up a link to Instagram while you are logged into your account on Instagram, the content of our website can be linked to your profile. This means that Instagram can assign your visit to our website directly to your user account. If you want to prevent this, you should log out before you click on corresponding links. An assignment will take place in any case if you log in to the relevant network after clicking on the link. If you do not want this information to be transmitted to Instagram, you can prevent this transmission by logging out of your Instagram account before accessing our website.

More information and Instagram's applicable privacy policy can be found at Hotjar

We use Hotjar in order to better understand our users’ needs and to optimize this service and experience. Hotjar is a technology service that helps us better understand our users’ experience (e.g. how much time they spend on which pages, which links they choose to click, what users do and don’t like, etc.) and this enables us to build and maintain our service with user feedback. Hotjar uses cookies and other technologies to collect data on our users’ behavior and their devices. This includes a device's IP address (processed during your session and stored in a de-identified form), device screen size, device type (unique device identifiers), browser information, geographic location (country only), and the preferred language used to display our website. Hotjar stores this information on our behalf in a pseudonymized user profile. Hotjar is contractually forbidden to sell any of the data collected on our behalf.

For further details, please see the ‘about Hotjar’ section of Hotjar’s support site. Linkster

On this page we use the tracking technology of Linkster GmbH, Colonnaden 5, 20354 Hamburg, to measure and visualize insights into partnerships and advertising channels. This is a function for measuring the efficiency of the corresponding advertising measures.  

Furthermore, the information enables us to assign advertising successes for billing with corresponding advertising partners. If you click on an advertising integration, cookies are set in your browser, which are read out in the event of a transaction. At every touch point, your browser sends an HTTP request to the Linkster server with which certain information is transmitted. This information includes the URL of the website on which advertising material is placed (referrer URL), the browser identifier (user agent) of your end device (including information about the device type and the operating system), the IP address of the end device (This IP address is anonymized and hashed by us before storage), HTTP header (data packet automatically transmitted by your browser with various technical information), the time of the request and, if previously saved on the device, the cookie with its Content. 

A cookie is a small data packet that is exchanged between your browser and the server. The information relevant to the web application can be stored and transmitted in this data package, e.g. the content of a virtual shopping cart. 

The tracking technology stores cookies on your end device to document actions. A 24-digit, anonymous ID is stored in the cookie. Linked to this ID, the data is encrypted in our database on the server. This contains information about the last touch points (i.e. when a particular advertising material was displayed or clicked on by a device). The stored touch points can, if necessary, be combined to form a sequence chain (user journey). 

With an action request, the order number and the shopping cart value of your order are usually also transmitted and saved by us. 

The cookies saved by Linkster GmbH are deleted after 30 days at the latest. The information transmitted to us and the cookies only serve the purpose of correctly assigning the success of an advertising medium and the corresponding billing and is in line with our legitimate interests in accordance with Art. 6 Para. 1 S. 1 lit. f GDPR. 

If you do not want cookies to be stored in your browser, you can do this by setting your browser accordingly. You can deactivate the storage of cookies in your browser under Extras / Internet options, restrict them to certain websites or set your browser so that it notifies you as soon as a cookie is sent. Please note, however, that in this case you will have to reckon with a limited display of online offers and limited user guidance. You can also delete cookies at any time. In this case, the information stored in it will be removed from your device. 

The collection and processing of tracking data can also be deactivated by clicking on this tracking optout link: 


Viewing your data: 


The following overview shows which cookies are used by our tracking technology: 

  • TRS: Unique, 24-digit identifier (ID) for tracking partnerships. This cookie is stored in the client browser and identifies database records that contain the touchpoint data. 
  • TRSCJ: Fallback cookie with the rudimentary touchpoint data for tracking partnerships. This cookie contains all touchpoint data encrypted on the client browser. 
  • trs_db_optout: When you click on the tracking opt-out link, a special cookie is written, which deactivates tracking in the current web browser of the end device. However, tracking is reactivated as soon as you     delete the tracking opt-out cookie. Plausible Analytics

On the webpage, we use the Plausible Analytics tool to record general usage trends on our website. Plausible Analytics only collects aggregated information that does not allow us to identify individual visitors to our website.

Plausible Analytics collects information about the page URL accessed, the HTTP referrer, the browser used, the operating system, the device and the country/region/city of access. The IP address is not recorded.

For more information, see the Plausible Analytics Privacy Policy.

2.6 Miscellaneous

You are not obliged to provide us with your personal data. However, if you refuse to provide us with the requested information, this may result, for example, in us not being able to conclude an agreement with you, not being able to fulfil agreements already concluded or not being able to fulfil our legal obligations. In addition, your refusal may also impair the functionalities and thus your use of the gebana website.

In addition to the personal information you provide to us, we may obtain information about you from third parties, such as government agencies or public registers.

If we intend to process personal data for a purpose other than that for which we initially collected the data, we will inform you.


3 Use of the website

When you send a postcard using the PostCard Creator web application by Swiss Post on the website, we collect the following data:

  • First and last name
  • Postal address
  • Email address

This data is collected and processed for the purpose of sending a postcard to political decision-makers as part of the Angry Gorilla campaign

In addition, we use the data to periodically send you information about the campaign or about our company by email or by post. You are only subscribed to our newsletter, which is published once or twice a week, if you expressly request it. You can object to the use of the data for these purposes at any time by clicking on a link in the corresponding newsletter, by email ( or by post. You can also have your contact details deleted.

The picture you upload and your recipient address information will be forwarded to Swiss Post for the creation and sending of the postcard.

By uploading pictures and graphics to the website, you grant us the non-exclusive, worldwide, perpetual and royalty-free rights to use this content. You grant us the right to store and publish this content (texts, pictures) and forward it to third parties for publication insofar as this serves the purposes of gebana AG. Furthermore, we shall have the right to use or forward the uploaded pictures and graphics in whole or in modified form, on their own or in combination with our own content.

4 Transmission of personal data

4.1 Disclosure to third parties

We may disclose your data to third parties, if we are obliged to do so. Disclosure of personal data might take place to the extent that it is necessary to provide and maintain the functions of the gebana website, to ensure our customer service and customer communication or to process your orders. It may happen, for example, that we disclose your personal data to:

  • the provider of transport services who has been commissioned with the delivery of the ordered products,
  • the service providers who, for example, provide us with payment services (Six Payment Services, Hardturmstrasse 201, CH-8021 Zurich, Switzerland), logistics services such as warehousing, etc. (Maier Spedition GmbH, Carl-Benz-Str. DE-78224 Singen, Germany) or web hosting (Google Ireland Limited, Gordon House, Barrow Street Dublin 4, Ireland) or operate our CRM systems (Descartes Systems (Deutschland) GmbH, Walter-Gropius-Str. 15, D-80807 Munich, Germany) or e-mail programs (CleverReach GmbH & Co. KG, Mühlenstr. 43, DE-26180 Rastede, Germany),
  • the external collection agency (Creditreform Egeli Zürich AG, Binzmühlestrasse 13, CH-8050 Zurich), to which we hand over invoices for collection after unsuccessful reminders,
  • third parties to whom we are legally obliged to disclose your personal data (e.g. competent authorities),
  • in connection with legal proceedings or future legal proceedings, and
  • to exercise our legal rights and defend ourselves in lawsuits.

The data you enter for the purpose of creating and sending a postcard, along with the photos and graphics you upload on, will be forwarded to Swiss Post's PostCard Creator web application.

Swiss Post will store this data for one year and keep it available for use with any new orders, after which it will be deleted without further notice to the customer. Furthermore, the data protection regulations of Swiss Post apply.


4.2 Creditworthiness checks in particular


If we make advance performances, e.g. in the case of a purchase on account, we may obtain a credit report from CRIF AG (Hagenholzstrasse 81, CH-8050 Zurich). The credit report may contain probability values (score values), which are calculated on the basis of scientifically recognized mathematical-statistical methods and indicate the likelihood of a payment default.


Categories of personal data
  • First and last name
  • Postal address
  • Information about rejection of a credit application
  • Information on arrears
  • Information about card misuse
  • Further information from public registers


Legal basis

The processing is necessary to realise our legitimate interest in only entering into a contractual relationship with customers if they are likely to meet their financial obligations (Art. 6(1)(f) GDPR).


4.3 Transfer of data to third countries

We may transfer your personal data to a country outside the EU / EEA, e.g. to service providers, so that they can carry out the data processing described in this Privacy Policy. In the case of such transfers, we will take reasonable technical and legal measures to ensure the integrity of the personal data transferred and to ensure that an adequate level of protection and security is provided in accordance with applicable data protection law.

For the sake of completeness, we would like to point out to users who are resident or domiciled in the EU / EEA or Switzerland that the surveillance measures carried out by US authorities allow the storage of all personal data of all persons whose data is transferred from the EU / EEA or Switzerland to the USA. This is done without any differentiation, limitation or exception based on the objective pursued and without any objective criterion. Accordingly, it is neither possible to limit US authorities' access to the data nor their subsequent use of data to specific, strictly limited purposes that would be capable of justifying the intrusion associated with both the access to these data and their use. In addition, we would like to point out that in the USA there are no legal remedies available to Swiss or EU /EEA data subjects that allow them to obtain access to the data concerning them or to obtain their correction or deletion, and that there is no effective judicial legal protection against general access rights of US authorities.

We would like to point out to customers or users located in the EU / EEA or Switzerland that the US does not have an adequate level of data protection from the perspective of the EU, EEA countries and Switzerland, partly due to the issues identified in this section. Where we have indicated in this privacy policy that recipients of data (such as Google) are located in the US, we will ensure that your data is protected with an adequate level of security, usually through contractual agreements with these companies.


5 Security measures

We use suitable and appropriate technical and organisational security measures to protect your personal data stored with us against manipulation, partial or complete loss and unauthorised access by third parties. Our security measures are continuously adapted and improved in line with technological developments.

You should always keep your access data confidential and close the browser window when you have finished communicating with us, especially if you share your device with others.

We take internal data protection very seriously. Our employees and the service companies commissioned by us have been obligated to keep information received confidential and to comply with the provisions of data protection law.


6 How long will the data be stored?

We store personal data only for as long as this is necessary to fulfil the purposes for which they are processed or as long as it is required by law (e.g. for storage periods prescribed by accounting regulations or tax regulations). The data is then deleted or made anonymous. To determine the retention periods for personal data we take into account applicable data protection laws, recommendations from authorities and applicable industry practice.


7 Your rights

In accordance with the provisions of the applicable data protection law, you have the right:

  • To obtain information on personal data concerning you (you have the right to obtain data in a standard file format);
  • Have incorrect information concerning you corrected;
  • To request that we stop processing your personal data and erase the data or that processing be restricted (legal obligations that prevent us from immediately erasing certain information remain reserved);
  • Object to the processing of personal data (we reserve the right to invoke a legitimate interest on our part in the continued processing of your data);
  • Refuse to give consent or withdraw consent given to the extent that we process your personal data on the basis of consent (note that in the latter case past processing activities that were based on your consent do not become unlawful as a result);
  • To exercise your right to data portability, provided that the legal requirements are met, by transferring the personal data provided to us to another controller;
  • To contact a competent data protection authority at any time if you believe that we are processing your personal data in breach of data protection laws.

You may contact us for the above purposes at the email address We may, at our discretion, require proof of identity in order to process your requests.


8 Changes to the privacy policy

We reserve the right to change or amend this privacy policy.

The current privacy policy can be found on gebana's website. You should check this information from time to time to ensure that you are happy with the changes. However, we will notify you as a registered customer of any material changes to this personal data policy, provided we have your email address.

This Personal Data Policy was last updated on February 27, 2023.

9 Third-party websites

The gebana website contains links to third-party websites. We have no control over these websites and this privacy policy cannot and does not intended to determine how and in what way these websites handle and process personal data.

10 Contact information

gebana AG

Ausstellungsstrasse 21
8005 Zurich
+41 (0) 43 366 65 00



Subscribe to gebana News