31 day money back guarantee Free shipping and free returns More than 88,000 unique rugs Since 1998: your expert for hand knotted oriental carpets
About us
Help area
Service
The details

Privacy and data protection

Data Protection Declaration

Unless explicitly stated otherwise below, the provision of your personal data is not legally or contractually required, nor necessary for the conclusion of a contract. You are under no obligation to provide your personal information. Not providing this data will not result in any consequences. This applies only where no other information is given in the processing descriptions below.
“Personal data” refers to all information relating to an identified or identifiable natural person.

Server Log Files

You may visit our websites without submitting any personal data.
Whenever our website is accessed, certain usage data is automatically transmitted to us or our hosting providers by your internet browser and saved in server log files. This information may include, for example, the name of the page accessed, date and time of access, IP address, volume of data transmitted, and the requesting provider.
The processing of this data is based on Article 6(1)(f) of the GDPR, arising from our legitimate interest in maintaining the technical functionality of the website and optimising our services.

Contact

Responsible Person

You can contact us at any time. The contact details of the entity responsible for data processing can be found in our legal notice.

Proactive Contact via Email

If you contact us on your own initiative via email, we will only collect the personal information you provide (such as your name, email address, and message content).
The purpose of processing this data is to respond to your inquiry.
If your contact relates to the initiation of a contract (e.g. product consultation, request for quotation) or to the fulfilment of an existing agreement, processing is based on Article 6(1)(b) GDPR.
For all other types of contact, data processing is carried out pursuant to Article 6(1)(f) GDPR, based on our legitimate interest in responding to customer enquiries. In such cases, you have the right to object at any time for reasons arising from your particular situation.
Your email address will only be used for handling your request. We will delete your data once your request has been resolved and no legal retention obligations apply, unless you have consented to further use.

Data Collection via Contact Form

When you use our contact form, we will collect your personal data (such as your name, email address, and message) only to the extent you provide it.
The purpose of this data collection is to process your inquiry.
If your message serves to initiate a business relationship or relates to an existing contract, processing is based on Article 6(1)(b) GDPR.
In all other cases, processing is based on our legitimate interest in accordance with Article 6(1)(f) GDPR. You may object to this processing at any time if there are reasons relating to your particular situation.
We will only use your email address to respond to your message. Your data will be deleted once processing is complete, unless you have given explicit consent for further use.

Customer Account / Orders

Customer Account

When you create a customer account, we collect the personal data that you voluntarily provide. The purpose of this data processing is to enhance your shopping experience and streamline the ordering process.
Processing is based on your consent in accordance with Article 6(1)(a) GDPR. You can revoke your consent at any time by contacting us. The revocation does not affect the lawfulness of any processing carried out prior to the withdrawal.
Following your withdrawal, your customer account will be deleted.

Collection, Processing and Transfer of Personal Data in Orders

When you place an order with us, we collect and process your personal data only to the extent necessary for the fulfilment and handling of your order and to respond to related queries.
Providing this data is required for the conclusion of a contract. Without it, we cannot process your order. The processing is based on Article 6(1)(b) GDPR and is necessary for the performance of a contract.
In the course of order processing, your data may be transferred to third parties such as shipping companies, dropshipping partners, payment service providers, fulfilment providers, and IT service providers, depending on your selections during the order process. In doing so, we strictly adhere to legal requirements and limit data sharing to the minimum necessary.

Advertising

Use of Your Email Address for Newsletter Distribution

If you have explicitly consented, we will use your email address outside the scope of contractual communications to send you our own promotional newsletters. Processing is carried out based on Article 6(1)(a) GDPR.
You can withdraw your consent at any time, without affecting the legality of processing carried out prior to the withdrawal. You may unsubscribe at any time via the unsubscribe link provided in each newsletter or by contacting us directly. Your email address will then be removed from the mailing list.

Use of Your Email Address for Direct Marketing

If we have received your email address in the context of a product or service sale, we may use it for direct advertising of our own similar products or services, unless you have objected to such use.
Providing your email address is necessary for the conclusion of a contract. Processing is based on our legitimate interest in direct marketing under Article 6(1)(f) GDPR.
You may object to the use of your email address for this purpose at any time, either via the contact details in our legal notice or using the unsubscribe link in the promotional email. You will not incur any costs beyond standard transmission charges.

Advertising Partners

To improve our advertising reach and efficiency, Nain Trading collaborates with a variety of social media platforms, search engines, and advertising networks (hereinafter “Advertising Partners”).
These may include platforms such as Facebook, Instagram, Pinterest, TikTok, and YouTube for social media campaigns, and Google Ads and the Google Marketing Platform for display advertising. We may also work with affiliate partners, including influencers, to drive traffic to our website.
Advertising Partners may use data provided by us or collected through cookies and similar technologies to personalise advertisements based on your interests – a method known as “retargeting”. This allows us to tailor marketing content and evaluate campaign performance more effectively.
To do so, we may share selected user information – such as a hashed (encrypted) email address or device ID – with our Advertising Partners. These identifiers are securely compared against the Advertising Partner’s databases. If a match is found, personalised ads may be displayed to you on third-party platforms. If not, the data is securely deleted.
All personal data is handled using secure cryptographic methods such as hashing, ensuring that your information is unreadable to anyone except the intended recipient and only for the stated purpose.
Each Advertising Partner is independently responsible for their part of the processing under data protection law, including the lawful transfer of personal data to countries outside the EEA, if applicable.

Analytics Providers

To better understand how users interact with our website and services, we make use of analytics tools. These services support us in improving our offerings by providing insights into user behaviour and website usage.
Information collected may include pages visited, session duration, and types of interactions. The data is typically anonymised and does not allow direct identification of individuals. It is stored within the EU in accordance with applicable data protection laws.

Shipping Companies

Forwarding Your Email Address to Shipping Providers

If you have explicitly agreed during the ordering process, we will pass your email address on to the selected shipping company. This is done to enable them to inform you via email about the current status of your delivery.
This processing is carried out based on your consent in accordance with Article 6(1)(a) GDPR. You may withdraw your consent at any time by contacting us or the shipping provider directly. The legality of the processing conducted prior to withdrawal remains unaffected.

Payment Service Providers / Credit Check

Use of PayPal

All PayPal transactions are subject to the PayPal Privacy Policy. You can view the full details at: https://www.paypal.com/de/webapps/mpp/ua/privacy-full?locale.x=en

Payment Options via Klarna

To offer you Klarna’s payment options, we will share certain personal data with Klarna, such as your contact and order details.
This data is used by Klarna to assess your eligibility for their payment methods and to tailor the payment options to suit your needs.
You can find general information about Klarna here. Klarna handles your personal data in accordance with applicable data protection regulations and their own privacy policy, which you can access here.

Cookies

Our website uses cookies. Cookies are small text files that are stored by your web browser on your device. When you visit our site, a cookie may be placed on your operating system. This file contains a unique string that allows your browser to be recognised during future visits.

Cookies are stored locally on your device, giving you full control over their use. You can configure your browser settings to notify you before cookies are placed, to allow or block cookies on a case-by-case basis, or to disable cookies entirely. Previously stored cookies can be deleted at any time.
Please note that disabling cookies may result in limited functionality of our website.

You can find instructions on managing cookies in common browsers at the links below:
Google Chrome
Microsoft Internet Explorer
Mozilla Firefox
Apple Safari

Technically Necessary Cookies

Unless stated otherwise in this privacy notice, we use only technically necessary cookies. These cookies help make our website more user-friendly, efficient, and secure. They allow our systems to recognise your browser after you switch pages, and enable the provision of essential functions. Some features of our website cannot function without these cookies.

The legal basis for this processing is Article 6(1)(f) GDPR, reflecting our legitimate interest in ensuring the functionality and usability of our website and services.
You have the right to object to the processing of your personal data based on Article 6(1)(f) GDPR for reasons related to your particular situation.

Analysis / Advertising Tracking

Use of Google Analytics

Our website uses the web analytics service Google Analytics, provided by Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). If you reside within the European Economic Area or Switzerland, the controller responsible for your data is Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland).
Google Ireland Limited is therefore the entity responsible for processing your data and for ensuring compliance with applicable data protection laws.

The purpose of this data processing is to analyse user behaviour on our website and to support marketing and advertising efforts. Google processes this data on our behalf to evaluate your website usage, compile reports on website activity, and provide related services.
Information that may be collected includes your IP address, the time and date of your visit, the pages you accessed, your click path, browser type, device details, referring website, geographic location, and purchasing behaviour.
Google Analytics uses technologies such as cookies, browser storage, and tracking pixels to enable this analysis. The data collected is generally transmitted to and stored on servers operated by Google in the USA. Google relies on standard contractual clauses to ensure adequate protection of personal data. More details are available at: https://policies.google.com/privacy/frameworks.

IP anonymisation is activated on this website. This means that Google will truncate your IP address before storing it if you are located within an EU or EEA country. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and truncated there.
Google may combine this information with other data they hold about you, including search history, personal accounts, usage patterns across devices, and other services you have used.

The use of cookies and similar technologies is based on § 15 para. 3 sentence 1 of the German Telemedia Act (TMG). The legal basis for processing personal data is Article 6(1)(f) GDPR, based on our legitimate interest in optimising and tailoring our website to user needs.
You have the right to object to this processing at any time for reasons relating to your specific situation.

You can prevent Google Analytics from collecting and processing your data (including your IP address) by installing the browser plugin available at: https://tools.google.com/dlpage/gaoptout?hl=en.
To disable tracking across all devices, you can set an opt-out cookie. This must be done on each device and browser you use. If you delete your cookies, the opt-out will need to be activated again.

Further information about how Google Analytics handles data and the applicable terms can be found at:
https://www.google.com/analytics/terms/
https://policies.google.com/privacy
https://policies.google.com/technologies/cookies

Use of Facebook Pixel

Our website uses the remarketing function “Custom Audiences” by Meta Platforms Inc. (1601 S. California Ave, Palo Alto, CA 94304, USA; formerly Facebook Inc.).
For users in the European Economic Area or Switzerland, Meta Platforms Ireland Ltd. (4 Grand Canal Square, Dublin 2, Ireland) is the responsible entity.
Nain Trading and Meta Ireland act as joint controllers for the collection and transmission of data when this service is implemented. The roles and responsibilities are defined in the joint controller agreement, available at: https://www.facebook.com/legal/controller_addendum.
We are particularly responsible for fulfilling information obligations under Articles 13 and 14 GDPR, ensuring the security of implementation (Art. 32 GDPR), and reporting any data breaches (Art. 33/34 GDPR), where such duties fall within our area of responsibility. Meta Ireland is responsible for enabling data subject rights (Art. 15–20 GDPR) and ensuring the security of processing related to the Facebook infrastructure.

We use the Facebook remarketing tag (Meta Pixel) to deliver interest-based ads to users who have visited our site. When you visit our website, this tag establishes a direct connection with Facebook's servers, transmitting information about your visit. This is linked to your Facebook profile and may be used to display tailored advertising to you on the Facebook platform.
Your data may be transmitted to servers in the USA. Meta relies on standard contractual clauses to safeguard data transfers.

Processing is based on our legitimate interest in targeted, interest-based advertising in accordance with Article 6(1)(f) GDPR. You may object to this processing at any time for reasons relating to your personal situation.

You can opt out of the “Custom Audiences” feature here.
Further details on how Meta processes your data, and your privacy rights, can be found at: https://www.facebook.com/about/privacy/.

Use of Google Ads Conversion Tracking

Our website uses the online marketing tool “Google Ads” including conversion tracking, provided by Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA).
If you are based in the European Economic Area or Switzerland, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is the controller responsible for your data and for ensuring compliance with data protection laws.

When you click on one of our Google Ads, a cookie is set for conversion tracking. These cookies do not contain personal data and expire after a short period. They enable us to determine whether you interacted with our ad and were redirected to our website. Each Google Ads customer receives a unique cookie, so that cookies cannot be tracked across different advertisers' websites.
The data collected is used to generate aggregated conversion statistics, showing how many users clicked on our ads and completed a defined action. Personal identification of users is not possible.
Your data may be transmitted to the USA. Google uses standard contractual clauses to ensure appropriate protection during such transfers.

This processing, especially the use of cookies, is carried out on the basis of Article 6(1)(f) GDPR due to our legitimate interest in personalised, effective marketing. You may object to this processing at any time if it concerns your specific situation.

You can disable personalised advertising in your Google settings: https://support.google.com/ads/answer/2662922?hl=en
You can also deactivate third-party cookie usage via the Network Advertising Initiative at: https://www.networkadvertising.org/choices/

Further details on data usage by Google can be found at: https://www.google.com/policies/privacy/

Use of Google Remarketing / Similar Audiences

Our website uses the remarketing and “similar audiences” function provided by Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA).
If you are a resident of the European Economic Area or Switzerland, the controller responsible for your data is Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland).

This feature is used to analyse visitor behaviour and interests, allowing us to display tailored advertising to users across the Google Display Network.
Google uses cookies to analyse usage patterns, helping to generate interest-based advertising. Visits to the website and anonymised usage data may be recorded, but personal data is not stored. If you later visit another website that is part of the Google Display Network, ads may be shown based on your prior interactions with our site.
Your data may be transmitted to servers in the USA. Google applies standard contractual clauses to ensure data protection during such transfers.

The processing of data, particularly the use of cookies, is carried out on the basis of Article 6(1)(f) GDPR, due to our legitimate interest in displaying interest-based advertising.
You have the right to object at any time to this data processing, for reasons related to your personal situation.

You can permanently disable interest-based ads by Google using this browser plugin: https://support.google.com/ads/answer/7395996?hl=en
Alternatively, you can deactivate third-party cookies via the Network Advertising Initiative opt-out page: https://www.networkadvertising.org/choices/

Further information on Google’s remarketing services and data protection policy can be found at: https://www.google.com/privacy/ads/

Use of Microsoft Advertising

We use Microsoft Advertising, a service from Microsoft Corporation (One Microsoft Way, Redmond, WA 98052-6399, USA), to support our online marketing efforts.
This service allows us to measure the effectiveness of our ads (conversion tracking) and better understand user interaction with them. When you click on an ad served via Microsoft, a conversion tracking cookie is placed on your device. These cookies are time-limited and do not contain any personally identifiable information.
If you visit specific pages on our website while the cookie is still valid, Microsoft and Nain Trading can recognise that you clicked the ad and were redirected to our site. Data collected in this process may include your IP address, browser and device data, Microsoft-assigned identifiers, referrer URL, and the URL of the page visited.
Your data may be transmitted to servers in the USA. Microsoft applies appropriate safeguards for international data transfers.

The processing is carried out in accordance with Article 6(1)(f) GDPR, based on our legitimate interest in targeted advertising and performance measurement.
You have the right to object to this processing at any time for reasons relating to your personal situation.

You can prevent the use of cookies by adjusting your browser settings accordingly. Please note that doing so may limit some website functionalities, and you may not be included in the conversion statistics.
For more details about Microsoft’s privacy practices and cookies used by Microsoft Advertising, visit: https://privacy.microsoft.com/en-us/privacystatement

Use of the Pinterest Tag

We use the Pinterest tag from Pinterest Europe Limited (Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland; “Pinterest”) on our website.

This tool allows us to display interest-based advertisements to website visitors on the Pinterest platform. To enable this, a conversion tag from Pinterest is integrated into our website. When you access our site, this tag establishes a direct connection to Pinterest’s servers and transmits information about which pages you have visited.
If you are logged into your Pinterest account, this activity may be linked to your user profile and used to display personalised ads on Pinterest.

If you access our website via a Pin on Pinterest, a cookie for conversion tracking may be placed on your device. These cookies are valid for a limited time and do not contain personal identifiers. If you visit specific pages during this period, we and Pinterest can recognise that you interacted with the Pin and visited the respective content.
This data helps generate conversion statistics and optimise our site’s performance. Information that may be processed includes the number of users who clicked on our Pins, visited subpages (such as product or category pages), used the search function, added products to their cart, or completed purchases.

Your data may be transferred to the USA. Please note that there is no adequacy decision from the European Commission for the USA. However, such transfers rely on appropriate safeguards, such as standard contractual clauses issued by the European Commission: Standard Contractual Clauses.

The use of cookies or similar technologies is based on § 15 para. 3 sentence 1 of the German Telemedia Act (TMG). The legal basis for processing your personal data is Article 6(1)(f) GDPR, reflecting our legitimate interest in providing interest-based and targeted advertising.
You may object to this processing at any time if you have reasons related to your particular situation.

You can disable personalised advertising in your Pinterest settings or via the AdChoices opt-out platform at: https://optout.aboutads.info/
You can also prevent the storage of cookies by adjusting your browser settings. Please note that this may affect the full functionality of our website.

For more information about Pinterest’s data practices, please refer to their privacy policy: https://policy.pinterest.com/en/privacy-policy

Plug-ins

Use of Google Tag Manager

We use Google Tag Manager, a tag management system provided by Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). For users located in the European Economic Area or Switzerland, the responsible entity is Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland).

Google Tag Manager is used to manage JavaScript and HTML tags for integrating tools such as tracking and analytics. The tool itself does not store cookies or process personal data. However, it may trigger tags that collect and process personal data under their own responsibility.

You can find further information about Google Tag Manager’s terms of use and privacy policy at: https://www.google.com/intl/en/tagmanager/use-policy.html

Use of YouTube

Our website integrates YouTube videos using the embedding feature provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; “YouTube”), a subsidiary of Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA).

The videos are embedded using YouTube’s "enhanced privacy mode", which prevents YouTube from collecting visitor information unless a video is played. Only when you start a video, data such as your IP address and usage behaviour may be transmitted to YouTube and stored.
Your data may be transferred to the USA. Google uses standard contractual clauses to ensure a suitable level of data protection.

The legal basis for this processing is Article 6(1)(f) GDPR, based on our legitimate interest in enhancing user experience with multimedia content. You may object to this processing at any time for reasons related to your personal situation.
More details on data handling and privacy settings can be found in YouTube’s privacy policy: https://www.youtube.com/t/privacy

Use of Google Fonts

We use Google Fonts provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) to display fonts consistently across our website.

When accessing the website, your browser connects to Google’s servers to download the fonts. During this process, your IP address and browser-related information are transmitted to Google. This data is not associated with your Google account.
Your data may be transferred to the USA. Although no EU adequacy decision exists for the USA, data transfers are protected by standard contractual clauses: https://policies.google.com/privacy/frameworks

The use of such technologies is based on § 15 para. 3 sentence 1 TMG. The data processing is carried out on the basis of Article 6(1)(f) GDPR due to our legitimate interest in a visually optimised and user-friendly website design.
You may object to this processing at any time for reasons specific to your situation.
More information about Google Fonts and data protection can be found at: https://www.google.com/policies/privacy/ and https://developers.google.com/fonts/faq

Rights of Data Subjects and Storage Duration

Storage Duration

After the conclusion of contractual processing, your personal data will be retained for the duration of any applicable warranty period and subsequently in accordance with statutory retention obligations, particularly those required under tax and commercial law.
Once these periods have expired, the data will be deleted unless you have given explicit consent for continued processing and use.

Your Rights

If the legal conditions are met, you have the following rights under Articles 15 to 20 of the General Data Protection Regulation (GDPR):

In addition, under Article 21(1) GDPR, you have the right to object to processing based on Article 6(1)(f) GDPR, and specifically to processing for direct marketing purposes.

Right to Lodge a Complaint

According to Article 77 GDPR, you have the right to lodge a complaint with a supervisory authority if you believe your personal data is not being processed in accordance with legal requirements.

Right to Object

Where data processing is based on our legitimate interests under Article 6(1)(f) GDPR, you may object to such processing at any time on grounds relating to your particular situation, with effect for the future.
If your objection is successful, we will cease processing your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

Where your personal data is processed for direct marketing purposes, you have the right to object at any time without providing a specific reason. If you object, we will stop processing your data for such purposes.