An embeddable widget for consumer withdrawals — backed by a tamper-evident cryptographic audit: SHA-256 → Merkle tree → RFC 3161 timestamp. Installed in minutes, GDPR-compliant, hosted in Frankfurt.
Everything you need to make consumer withdrawals legally watertight — without touching your shop's theme.
Every withdrawal becomes an immutable proof: SHA-256 fingerprint → Merkle tree → RFC 3161 qualified timestamp (gerichtsfest).
Compliant with § 356a BGB and § 126b BGB (durable medium) from the very first request — no legal homework.
PII encrypted with AES-256-GCM, AVV under Art. 28, automatic retention deletion, EU hosting in Frankfurt.
A single ≤5 KB script tag in a closed Shadow DOM. It never conflicts with your shop's CSS or theme.
One flat plan at €9/month. No setup fees, no per-request charges, no hidden costs.
Made for German, Austrian and Swiss e-commerce law — the widget speaks German to your customers by default.
Each withdrawal turns into a court-proof, immutable record in four steps.
The consumer withdraws with three fields (name, order no., e-mail) right inside your shop — no reason, no marketing opt-in.
A reproducible SHA-256 fingerprint is built from the canonical record — forgery-proof and verifiable at any time.
All fingerprints of a day are aggregated into a single Merkle root that secures every entry at once.
The Merkle root is anchored by a qualified timestamp (RFC 3161) — court-proof evidence of receipt and time.
From a risky manual process to an automatic notarized log.
One plan with everything included. Cancel anytime.
No setup fees · no hidden costs · cancel anytime
Add one script tag before </body>. Pick your platform for step-by-step instructions.
Add this tag before </body>:
<script src="https://www.widerruf-widget.de/widget.min.js" data-api-key="YOUR_API_KEY" data-api="https://www.widerruf-widget.de" defer></script>Replace YOUR_API_KEY with the key from your dashboard once your subscription is active.
The service supports the statutory right of withdrawal under § 356a BGB and provides confirmation on a durable medium per § 126b BGB. PII processing is covered by an AVV (Art. 28 GDPR).
All data is hosted exclusively in the EU (Frankfurt, eu-central-1). Personal data is encrypted at the field level with AES-256-GCM.
Personal data is automatically anonymized after the configured retention period. The cryptographic proof (hash) remains, so the record stays verifiable without exposing PII.
Any website where you can add a script tag: Shopware 6, JTL-Shop, Shopify, WooCommerce/WordPress, Wix, Squarespace, Webflow, Google Tag Manager and custom HTML.
No. The widget renders in a closed Shadow DOM with all:initial, so your theme's CSS can't leak in and the widget can't leak out.
Yes. The plan is €9/month with no minimum term. The widget stops rendering as soon as the subscription is no longer active.
About five minutes. Copy the script tag, paste it before </body>, and the button appears once your subscription is active.
Set up your organization, copy the snippet, and integrate the withdrawal button in minutes.
Go to Dashboard