Skip to Content
MUSTcycle
  • Home
  • CAPRA Adventure Bike

    CAPRA Cresta

    CAPRA Vetta

    CAPRA Frameset
  • Experience CAPRA
  • CAPRA Parts

    Replacement and Wear Parts

    Components

    Accessories
  • 0
  • 0
  • Follow us
    Hier klicken, um Ihre sozialen Netzwerke zu konfigurieren
  • EN DE
  • Sign in
MUSTcycle
  • 0
  • 0
    • Home
    • CAPRA Adventure Bike
    • Experience CAPRA
    • CAPRA Parts
  • Follow us
    Hier klicken, um Ihre sozialen Netzwerke zu konfigurieren
  • EN DE
  • Sign in
Privacy Policy1. Responsible Party1. Geltungsbereich3. Legal Bases4. Hosting and operation of the website with Odoo5. Server log files6. Cookies and similar technologies7. Contact8. Customer Account9. Online Shop and Order Processing10. Payment Processing11. Shipping and Delivery12. Newsletter13. Google Analytics14. Google Ads and Conversion Tracking15. Google Maps16. YouTube Videos17. Social Media Presence and Links18. Adventure tours, test drives, and events19. Warranty, service, and repair inquiries20. Recipients of personal data21. Transfer to third countries22. Storage duration23. Data Security24. Rights of affected persons25. Withdrawal of consent26. Right to Object27. Right to Complain28. Automated Decisions29. Changes to this Privacy Policy​

Privacy Policy

MUSTcycle System Technology

As of: July 23, 2026

This privacy policy informs you about how personal data is processed when visiting our website, using our online shop, placing orders, making bookings, contacting us, and in the context of our marketing, service, and support offerings.

1. Responsible Party

The responsible party in the sense of the General Data Protection Regulation is:

MUSTcycle System Technology

Owner: 

Johannes Müller

Schillerstraße 63

6700 Bludenz

Austria

E-Mail: jmu@mustcycle.at

Web: www.mustcycle.at

If no data protection officer has been appointed, data protection inquiries should be directed to the email address provided above.

1. Geltungsbereich

This privacy policy applies in particular to:

  • the visit to our website,
  • the MUSTcycle online shop,
  • customer accounts,
  • product orders and payment processing,
  • inquiries via contact forms, email, or phone,
  • newsletters,
  • warranty, service, and repair inquiries,
  • adventure tours, test rides, and events,
  • Google Analytics and Google Ads,
  • embedded content such as Google Maps and YouTube,
  • links to Instagram, Facebook, and LinkedIn.

3. Legal Bases

We process personal data primarily on the following legal bases:

Art. 6 para. 1 lit. a GDPR – Consent

This particularly concerns newsletters, statistical and marketing services, as well as external content that is only loaded after your consent.

Art. 6 para. 1 lit. b GDPR – Contract and pre-contractual measures

This particularly concerns orders, product inquiries, tour bookings, customer accounts, payments, deliveries, as well as warranty, service, and repair requests.

Art. 6 para. 1 lit. c GDPR – Legal obligation

This particularly concerns tax, commercial, and accounting retention and documentation obligations.

Art. 6 para. 1 lit. f GDPR – Legitimate interests

This particularly concerns the secure and efficient operation of our website, the prevention of abuse, the processing of general business inquiries, as well as the enforcement or defense of legal claims.

4. Hosting and operation of the website with Odoo

Our website, our online shop, and other business processes are operated using services from Odoo.

The provider is, depending on the contractual and hosting structure used:

Odoo S.A.

Chaussée de Namur 40

1367 Grand-Rosière

Belgium

As part of the operation, the following data may be processed:

  • IP address,
  • date and time of access,
  • accessed pages,
  • browser type and browser version,
  • operating system,
  • referrer URL,
  • Session and cookie data,
  • Customer account and order data,
  • Communication and form data.

The processing is carried out to provide and secure the website, the online shop, and the associated functions.

Odoo offers, among other things, a platform for hosting its own Odoo databases and processes data that is necessary for providing and securing the services.

5. Server log files

When accessing our website, technical access data may be automatically collected. This may include:

  • IP address,
  • Time of access,
  • accessed page or file,
  • amount of data transferred,
  • browser and operating system,
  • referrer URL,
  • technical error and security information.

This data is processed to:

  • technically provide the website,
  • detect errors,
  • defend against attacks and abuse,
  • ensure the stability and security of the system.

The legal basis is Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in the secure and reliable operation of our website.

6. Cookies and similar technologies

Our website uses cookies and similar technologies.

Technically necessary cookies can be used without separate consent, as far as they are required to particularly:

  • maintain sessions,
  • store shopping cart contents,
  • enable logins,
  • store language settings,
  • To provide security features.

Statistics, analysis, and marketing cookies are only set with your consent.

Further information on the cookies used, cookie categories, and settings options can be found in our separate Cookie Policy.

You can change or revoke your consent at any time via the cookie settings of the website with effect for the future.

7. Contact

If you contact us via contact form, email, or phone, we process in particular:

  • Name,
  • Email address,
  • Phone number, if provided,
  • Content and timing of the request,
  • related product, order, or service data,
  • any additional information you voluntarily provide.

The processing is carried out to handle your request.

If your request relates to a contract or a potential order, the processing is based on Art. 6 para. 1 lit. b GDPR.

For general inquiries, it is based on our legitimate interest in proper business communication according to Art. 6 para. 1 lit. f GDPR.

8. Customer Account

You may create a customer account if necessary. In this context, the following may be processed:

  • First and last name,
  • Email address,
  • Password in encrypted or hashed form,
  • Billing and shipping address,
  • Phone number,
  • Order history,
  • Product and service data,
  • stored preferences.

The processing is carried out to provide and manage the customer account as well as to handle orders and service cases.

The legal basis is Art. 6 para. 1 lit. b GDPR.

You can request the deletion of your customer account. Legally required order, invoice, or payment data remains unaffected.

9. Online Shop and Order Processing

In the context of orders, we process in particular:

  • Name,
  • billing and delivery address,
  • Email address,
  • Phone number,
  • ordered products,
  • order and invoice data,
  • payment method and payment status,
  • delivery and shipping information,
  • communication regarding the order.

The processing is carried out for:

  • processing the order,
  • manufacturing and configuring ordered products,
  • payment processing,
  • delivery,
  • invoicing,
  • handling inquiries,
  • fulfillment of legal obligations,
  • execution of warranty, guarantee, and service services.

Legal bases are Art. 6 para. 1 lit. b and lit. c GDPR.

10. Payment Processing

When selecting a payment method, the data required for the payment is transmitted to the respective payment service provider.

MUSTcycle generally only receives those payment information that are necessary for the confirmation, allocation, and processing of the payment. Complete credit card details are usually processed directly by the payment service provider used.

10.1 PayPal

When paying with PayPal, personal data may be transmitted to the following provider:

PayPal (Europe) S.à r.l. et Cie, S.C.A.

Luxembourg

This may include, in particular:

  • Name,
  • Email address,
  • Billing and delivery data,
  • Order amount,
  • Currency,
  • Transaction number,
  • Payment status,
  • Device and security data.

PayPal may process additional data for payment processing, fraud prevention, identity verification, and compliance with legal obligations. PayPal also informs customers in the EEA and Switzerland about potential recipients and involved third parties.

The legal basis for the transmission by us is Art. 6 para. 1 lit. b GDPR.

10.2 Credit card payment via Stripe

For credit card payments in our online shop, we use the payment service provider Stripe.

Provider for customers in the European Economic Area is:

Stripe Payments Europe, Limited

1 Grand Canal Street Lower

Grand Canal Dock

Dublin D02 H210

Ireland

When selecting credit card payment (e.g. Visa, Mastercard, or other supported cards), the personal data required for payment processing will be transmitted directly to Stripe. This may include, in particular:

  • Name of the cardholder,
  • billing and delivery address,
  • Email address,
  • Payment amount and currency,
  • Order and transaction data,
  • IP address,
  • Device and browser information,
  • Information on fraud prevention and authentication (e.g., 3D Secure).

The complete credit card data is processed exclusively by Stripe. MUSTcycle does not receive complete credit card data, but only information necessary for confirming and allocating the payment (e.g., payment status or transaction ID).

The processing is carried out for the purpose of payment processing, authentication of the cardholder, and fraud prevention.

Legal basis

Art. 6 para. 1 lit. b GDPR (contract fulfillment)

Insofar as Stripe processes personal data outside the European Union, this is done based on the applicable data protection regulations, particularly appropriate safeguards according to Chapter V GDPR.

Further information on data processing by Stripe can be found at:

https://stripe.com/privacy

10.3 Amazon Pay

When paying with Amazon Pay, data may be transmitted to the following provider:

Amazon Payments Europe S.C.A.

38 avenue J. F. Kennedy

L-1855 Luxembourg

This may include, in particular:

  • Name,
  • Email address,
  • Billing and delivery data,
  • Payment and transaction data,
  • Order amount,
  • security and device information.

Amazon Payments Europe processes data primarily for payment processing, authentication, fraud prevention, and compliance with legal requirements. Amazon points out that the specific company may depend on the registration time and contract structure. For European merchants, Amazon Payments Europe S.C.A. based in Luxembourg is mentioned.

The legal basis for the data transmission by us is Art. 6 para. 1 lit. b GDPR.

11. Shipping and Delivery

For the delivery of orders, necessary data may be transmitted to shipping and logistics companies.

This includes, in particular:

  • Name,
  • Delivery address,
  • Phone number or email address, as required for delivery,
  • Package and shipment data.

The legal basis is Art. 6 para. 1 lit. b GDPR.

The specific shipping service provider depends on the country of delivery, shipping method, product, and availability.

12. Newsletter

You can subscribe to our newsletter.

In this context, we process, in particular:

  • Email address,
  • if applicable, name,
  • time of registration,
  • proof of consent,
  • if applicable, open and click rates,
  • technical information for shipping.

Registration should be done via a double opt-in procedure. After registration, you will receive a confirmation message. Only after confirmation will your address be activated for newsletter dispatch.

The legal basis is your consent according to Art. 6 para. 1 lit. a GDPR.

You can revoke your consent at any time via the unsubscribe link in the newsletter or by sending a message to jmu@mustcycle.at revoke.

The revocation does not affect the lawfulness of the processing before the revocation.

Consents for newsletters must be verifiable in case of doubt. The Austrian Data Protection Authority also explicitly points this out.

13. Google Analytics

We use Google Analytics, provided you have consented via our cookie banner.

Provider is:

Google Ireland Limited

Gordon House

Barrow Street

Dublin 4

Ireland

Google Analytics helps us understand how visitors use our website.

In particular, the following may be processed:

  • shortened or complete IP address, depending on the configuration,
  • Device and browser information,
  • accessed pages,
  • duration of stay,
  • source of the visit,
  • click and interaction data,
  • approximate location information,
  • campaign and conversion data,
  • cookie and device identifiers.

The legal basis is your consent according to Art. 6 para. 1 lit. a GDPR.

Google states in its privacy policy that websites may use Google Analytics, advertising services, and embedded YouTube content, among other things.

Consent given can be revoked at any time through the cookie settings.

14. Google Ads and Conversion Tracking

We use Google Ads and, if applicable, Google Conversion Tracking, provided you have consented.

This allows us to determine whether users perform specific actions on our website after clicking on an ad, for example:

  • visiting a product page,
  • sending a request,
  • booking a tour,
  • completing an order.

In particular, the following may be processed:

  • cookie and device identifiers,
  • IP address,
  • browser and device data,
  • accessed pages,
  • clicks on ads,
  • conversion events,
  • time and value of an order or request.

The legal basis is Art. 6 para. 1 lit. a GDPR.

Consent can be revoked at any time through the cookie settings.

15. Google Maps

Google Maps may be embedded on our website.

Provider is:

Google Ireland Limited

Gordon House

Barrow Street

Dublin 4

Ireland

When loading the map, the following data may be transmitted to Google:

  • IP address,
  • Browser and device information,
  • the page accessed,
  • Time of access,
  • possibly location data,
  • cookie or device identifiers.

Google Maps is only loaded if you have previously consented to the processing by external media or similar services.

The legal basis is Art. 6 para. 1 lit. a GDPR.

16. YouTube Videos

Videos from YouTube can be directly embedded on our website.

Provider is:

Google Ireland Limited

Gordon House

Barrow Street

Dublin 4

Ireland

When playing or possibly even when loading a video, the following may be processed:

  • IP address,
  • Device and browser information,
  • the page accessed,
  • Video and playback data,
  • cookie or device identifiers,
  • possibly information from an existing Google account.

Embedded videos should only be loaded after your consent.

The legal basis is Art. 6 para. 1 lit. a GDPR.

A simple link to YouTube will only result in data transmission to YouTube when you actively click the link.

17. Social Media Presence and Links

We maintain presences on:

  • Instagram,
  • Facebook,
  • LinkedIn.

17.1 Pure Links

If there are only links to the platforms on our website, data will only be transmitted to the respective provider when you click the link.

From this point on, the privacy policies of the respective platform operator apply.

17.2 Instagram and Facebook

Instagram and Facebook are offered by companies of the Meta group.

When accessing our profiles or interacting with our posts, Meta may process the following data in particular:

  • Profile and account data,
  • IP address,
  • Device information,
  • Usage and interaction data,
  • Messages and comments,
  • Cookie and advertising data.

Meta describes the processing of personal data for Facebook, Instagram, and other services in its privacy policy.

To the extent that Meta provides us with anonymized statistics about the use of our pages, there may be joint responsibility under Art. 26 GDPR.

17.3 LinkedIn

Provider for users in the European Economic Area is:

LinkedIn Ireland Unlimited Company

Ireland

When using our LinkedIn presence, profile, device, usage, interaction, and communication data may be processed in particular.

LinkedIn Ireland refers to itself as the data controller for users in the EU, EEA, and Switzerland for data provided or collected in connection with its services.

18. Adventure tours, test drives, and events

When booking or participating in adventure tours, test drives, or events, the following may be processed in particular:

  • Name,
  • Contact and booking data,
  • Payment information,
  • Date and event,
  • Number of participants,
  • Equipment or product information,
  • voluntarily provided organizational information,
  • Communication related to the event.

The processing is carried out for the organization, execution, and billing of the event.

The legal basis is Art. 6 para. 1 lit. b GDPR.

Health data should only be requested via the website when it is actually necessary. Since health data enjoys special protection, explicit consent in accordance with Art. 9 para. 2 lit. a GDPR may be required for its processing.

19. Warranty, service, and repair inquiries

In warranty, service, or repair cases, we particularly process:

  • Name and contact details,
  • Proof of purchase and invoice,
  • Serial number and product data,
  • Description of errors and damages,
  • Photos or videos,
  • Previous maintenance and repair information,
  • Shipping and return data,
  • Communication regarding the service case.

The processing is carried out for:

  • Examination of warranty or guarantee claims,
  • Execution of repairs,
  • Technical error analysis,
  • Customer communication,
  • Documentation of safety-relevant product processes,
  • Enforcement or defense of legal claims.

Legal bases are Art. 6 para. 1 lit. b, lit. c, and lit. f GDPR.

20. Recipients of personal data

Personal data may be transmitted, as far as necessary, particularly to the following recipients:

  • Odoo and employed hosting service providers,
  • Payment service providers,
  • Banks,
  • Shipping and logistics companies,
  • Tax advisors and accounting,
  • IT and support service providers,
  • Newsletter and marketing service providers,
  • Google,
  • Meta,
  • LinkedIn,
  • Authorities and courts in case of legal obligation,
  • Lawyers, insurance companies, and experts in legal or damage cases.

Data transfer occurs only if it is:

  • necessary for the fulfillment of the contract,
  • legally required,
  • based on consent or
  • permissible for the protection of legitimate interests.

21. Transfer to third countries

Some of the providers we use may process data outside the European Union or the European Economic Area.

This particularly concerns internationally active providers such as:

  • Google,
  • Meta,
  • LinkedIn,
  • PayPal,
  • Amazon,
  • possibly other payment or IT service providers.

A transfer occurs only if the legal requirements are met, particularly based on:

  • a decision of adequacy by the European Commission,
  • appropriate safeguards such as standard contractual clauses,
  • the EU-U.S. Data Privacy Framework, as long as the respective recipient is effectively certified,
  • or another permissible legal basis.

Despite such protective mechanisms, it cannot be completely ruled out that authorities in third countries may access data under national law.

22. Storage duration

We store personal data only as long as necessary for the respective purpose or as required by legal retention obligations.

In particular, the following principles apply:

  • Requests are generally stored until the processing is completed and beyond that only as long as necessary for evidence or legal claims.
  • Contract, order, invoice, and payment data are stored in accordance with the statutory retention periods.
  • Customer accounts are stored until the account is deleted, provided that no legal obligations oppose this.
  • Newsletter data is stored until the consent is revoked.
  • Proof of consent may also be stored to demonstrate lawful processing.
  • Warranty, service, and repair data may be retained for the duration of product use, warranty and guarantee periods, as well as possible liability and limitation periods.
  • Cookie and analysis data are stored according to the durations specified in the cookie banner and cookie policy.

The Austrian Data Protection Authority describes as a common principle that data may be stored until the end of a business relationship or until the expiration of relevant warranty, guarantee, limitation, and retention periods.

23. Data Security

We take appropriate technical and organizational measures to protect personal data, in particular against:

  • loss,
  • abuse,
  • unauthorized access,
  • alteration,
  • disclosure,
  • destruction

.

These may include, among other things:

  • encrypted data transmission,
  • Access restrictions,
  • User and role management,
  • secure passwords,
  • regular updates,
  • data backups,
  • logging of security-relevant events.

However, a completely risk-free data transmission or storage cannot be guaranteed.

24. Rights of affected persons

You have the right to:

  • information,
  • correction,
  • deletion,
  • restriction of processing,
  • data portability,
  • objection,
  • withdrawal of consent,
  • complaint to a supervisory authority,
  • protection against solely automated decisions, provided that the legal requirements are met.

The Austrian Data Protection Authority particularly emphasizes the rights to information, access, correction, deletion, restriction, data portability, and objection.

To exercise your rights, please contact us at:

jmu@mustcycle.at

For processing, we may require suitable proof of identity if there are legitimate doubts about your identity.

25. Withdrawal of consent

Consent given can be withdrawn at any time with effect for the future.

The withdrawal does not affect the lawfulness of processing based on consent before the withdrawal.

Cookie consents can be changed through the cookie settings. Newsletter consents can be withdrawn via the unsubscribe link or by email.

26. Right to Object

If processing is carried out on the basis of Art. 6 para. 1 lit. f GDPR, you may object to the processing for reasons arising from your particular situation.

If personal data is processed for direct marketing, you may object to this processing at any time.

27. Right to Complain

You have the right to lodge a complaint with a data protection supervisory authority.

For Austria:

Austrian Data Protection Authority

Barichgasse 40–42

1030 Vienna

Austria

E-Mail: dsb@dsb.gv.at

The data protection authority confirms that complaints can be submitted by email, letter, or via an online form.

28. Automated Decisions

Exclusively automated decision-making, including profiling in the sense of Art. 22 GDPR, does not generally take place through MUSTcycle.

However, payment service providers may conduct automated checks as part of fraud prevention, credit assessment, or payment authorization. The respective payment service provider is responsible for this processing.

29. Changes to this Privacy Policy

We may adjust this privacy policy if:

  • legal requirements,
  • our website,
  • services used,
  • payment methods,
  • business processes, or
  • technical framework conditions

change.

The current version published on our website applies.


Discover
  • Home
  • About MUSTcycle
  • FAQ
  • Dealer Login
General Information
  • Terms and Conditions
  • Warranty
  • Safety and Usage Instructions
  • Privacy Policy
  • Imprint


Follow Us
  • Facebook
  • LinkedIn
  • Instagram
Contact Us
  • jmu@mustcycle.at
  • +43 677 618 934 91
  • Contact
Company

Schillerstrasse 63 
6700 Bludenz 
Austria
Location


Copyright © MUSTcycle
English (US) | Deutsch
Powered by Odoo - The #1 Open Source eCommerce

We use cookies to provide you a better user experience on this website. Cookie Policy

Only essentials I agree