Privacy policy
1. Data controller
In accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on the Protection of Personal Data and guarantee of digital rights (LOPDGDD), we inform you that the controller of the personal data you provide through the website https://praceira.com is:
- Identity: Praceira S.L. (placeholder) (Praceira)
- Tax ID (CIF): B00000000
- Address: Rúa da Praza, 1, 32001 Ourense (Galicia), España
- General email: hola@praceira.example
- Data protection contact: privacidad@praceira.example
2. What data we process
Depending on how you interact with us, we may process the following categories of data:
- Identification and contact details: name and surname, email, telephone, delivery and billing address.
- Purchase data: products bought, amounts, dates, chosen payment method, order history and incidents.
- Payment data: entered and processed directly by the payment gateway. Praceira only receives confirmation of payment and, where applicable, the last digits of the card; it never stores the full number.
- Business data (company name, tax ID, sector, estimated volume) when you request an invoice or ask about our trade and wholesale conditions.
- Communications: the content of the messages you send us by form, email, telephone or WhatsApp.
- Technical browsing data: IP address, browser and device type, access and error logs, needed for the security and operation of the site.
- Audience measurement: the page you open, the website and campaign you came from, the language, the type of device, whether your basket holds something, and what you search for when the shop finds nothing (dropping anything that looks like an email or a phone number), kept by the hour. Your IP address and browser are used on the spot to form a key that changes every day, and are not stored.
- Data from analytics or marketing cookies, only if you have accepted them (not currently active).
Fields marked as mandatory in each form are needed to handle your request; without them we cannot process it. You guarantee that the data you provide is accurate and undertake to tell us about any changes.
3. Purposes and legal bases
We process your data for the following purposes, each with its legal basis:
Processing purposes and legal bases
| Purpose | Legal basis (GDPR) | Data |
|---|---|---|
| Order management: preparation, shipping, delivery, incidents and order status communications. | Performance of a contract (art. 6.1.b). | Identification, contact, address, purchase. |
| Box subscriptions (The Box): managing the recurring box (deliveries, skips, pauses and cancellation), recurring billing through Stripe and emailing you the private link to manage it. | Performance of a contract (art. 6.1.b). | Identification, contact, address, subscription and billing data; for a gift, the delivery details of the person receiving it. |
| My account: signing in with a code sent to your email, and seeing and managing your orders, boxes, invoices, addresses and favourites. | Performance of a contract (art. 6.1.b). | Email, the devices you are signed in on (browser and system as your device sends them, and last visit), favourites and the data of your orders and boxes. |
| Invoicing, accounting and tax obligations. | Compliance with legal obligations (art. 6.1.c): Spanish General Tax Law, Commercial Code and invoicing rules. | Identification, tax, purchase. |
| Customer service: enquiries, complaints, guarantees and right of withdrawal. | Performance of a contract or pre-contractual measures (art. 6.1.b); legitimate interest in answering whoever writes to us (art. 6.1.f). | Identification, contact, communications. |
| Newsletter: start-of-season notice and news. | Consent (art. 6.1.a), revocable at any time via the unsubscribe link in every email. | Email, language. |
| Restock alerts ("Notify me when it's back"): a single email when the product or section you asked about is back. | Consent (art. 6.1.a), revocable at any time by writing to us. | Email, product or section requested, language. |
| Commercial communications to customers about products similar to those purchased. | Legitimate interest (art. 6.1.f) and art. 21.2 LSSI-CE. You can object in every email or by writing to us. | Email, purchase history. |
| Trade and wholesale (B2B) requests. | Pre-contractual measures at the request of the data subject (art. 6.1.b). | Company, tax ID, contact, estimated volume. |
| Site security, fraud prevention and defence against claims. | Legitimate interest (art. 6.1.f) and legal obligations regarding payments. | Browsing, transaction. |
| Measuring the shop's audience: how many people visit, which products they look at, how many add to the basket and reach checkout, without identifying them. | Legitimate interest (art. 6.1.f) in knowing how the shop is used. We have weighed it against your rights: we only see totals, and for the current day a page, a product or a source only when visitors from at least two addresses share it, with no cookies and no third parties, we do not follow you from one day to the next, and you can object with a browser setting. The AEPD treats this measurement as exempt from consent. | Browsing (page, origin, language, device); IP address and browser in memory only, to form daily keys deleted within the hour after midnight. |
| Usage analytics and marketing through cookies. | Consent (art. 6.1.a) via the cookie banner. Not currently active. | Browsing. |
Order management: preparation, shipping, delivery, incidents and order status communications.
- Legal basis (GDPR)
- Performance of a contract (art. 6.1.b).
- Data
- Identification, contact, address, purchase.
Box subscriptions (The Box): managing the recurring box (deliveries, skips, pauses and cancellation), recurring billing through Stripe and emailing you the private link to manage it.
- Legal basis (GDPR)
- Performance of a contract (art. 6.1.b).
- Data
- Identification, contact, address, subscription and billing data; for a gift, the delivery details of the person receiving it.
My account: signing in with a code sent to your email, and seeing and managing your orders, boxes, invoices, addresses and favourites.
- Legal basis (GDPR)
- Performance of a contract (art. 6.1.b).
- Data
- Email, the devices you are signed in on (browser and system as your device sends them, and last visit), favourites and the data of your orders and boxes.
Invoicing, accounting and tax obligations.
- Legal basis (GDPR)
- Compliance with legal obligations (art. 6.1.c): Spanish General Tax Law, Commercial Code and invoicing rules.
- Data
- Identification, tax, purchase.
Customer service: enquiries, complaints, guarantees and right of withdrawal.
- Legal basis (GDPR)
- Performance of a contract or pre-contractual measures (art. 6.1.b); legitimate interest in answering whoever writes to us (art. 6.1.f).
- Data
- Identification, contact, communications.
Newsletter: start-of-season notice and news.
- Legal basis (GDPR)
- Consent (art. 6.1.a), revocable at any time via the unsubscribe link in every email.
- Data
- Email, language.
Restock alerts ("Notify me when it's back"): a single email when the product or section you asked about is back.
- Legal basis (GDPR)
- Consent (art. 6.1.a), revocable at any time by writing to us.
- Data
- Email, product or section requested, language.
Commercial communications to customers about products similar to those purchased.
- Legal basis (GDPR)
- Legitimate interest (art. 6.1.f) and art. 21.2 LSSI-CE. You can object in every email or by writing to us.
- Data
- Email, purchase history.
Trade and wholesale (B2B) requests.
- Legal basis (GDPR)
- Pre-contractual measures at the request of the data subject (art. 6.1.b).
- Data
- Company, tax ID, contact, estimated volume.
Site security, fraud prevention and defence against claims.
- Legal basis (GDPR)
- Legitimate interest (art. 6.1.f) and legal obligations regarding payments.
- Data
- Browsing, transaction.
Measuring the shop's audience: how many people visit, which products they look at, how many add to the basket and reach checkout, without identifying them.
- Legal basis (GDPR)
- Legitimate interest (art. 6.1.f) in knowing how the shop is used. We have weighed it against your rights: we only see totals, and for the current day a page, a product or a source only when visitors from at least two addresses share it, with no cookies and no third parties, we do not follow you from one day to the next, and you can object with a browser setting. The AEPD treats this measurement as exempt from consent.
- Data
- Browsing (page, origin, language, device); IP address and browser in memory only, to form daily keys deleted within the hour after midnight.
Usage analytics and marketing through cookies.
- Legal basis (GDPR)
- Consent (art. 6.1.a) via the cookie banner. Not currently active.
- Data
- Browsing.
We do not make decisions based solely on automated processing that produce legal effects on you or significantly affect you, nor do we create profiles for that purpose.
4. Recipients
We do not sell or transfer your data to third parties for commercial purposes. Only the providers needed to deliver the service access it, as processors and under contract in accordance with Article 28 GDPR:
- Payment gateway: Stripe Payments Europe, Ltd. (Ireland), which processes card payments, including Apple Pay and Google Pay, and the recurring payments for The Box subscriptions. For fraud prevention Stripe acts as an independent controller under its own privacy policy.
- Carriers: the courier making the delivery receives your name, address, telephone and email in order to deliver the parcel and notify you.
- Web hosting and infrastructure: the hosting and storage providers on which the shop runs.
- Email delivery: Resend, Inc. (United States), which sends on our behalf the transactional emails (order confirmations and updates, the link to manage your subscription to The Box, restock alerts, the codes to sign in to your account) and the newsletter. The transfer to the United States relies on the safeguards described in section 5.
- Tax and accounting advisers, for compliance with legal obligations.
We will also disclose data to public authorities, courts or banks when required to do so by law.
5. International transfers
Some of our technology providers (hosting, email, payment gateway) may process data outside the European Economic Area, mainly in the United States. In those cases we make sure the transfer is covered by appropriate safeguards: an adequacy decision of the European Commission (such as the EU-US Data Privacy Framework for certified entities) or the standard contractual clauses approved by the European Commission (Decision (EU) 2021/914), together with any supplementary measures required. You can request a copy of those safeguards at privacidad@praceira.example.
6. Retention periods
- Orders and invoices: for the duration of the contractual relationship and, afterwards, for the period required by commercial and tax law: 6 years from the last entry (art. 30 of the Spanish Commercial Code) and in any case until tax obligations (4 years, art. 66 of the General Tax Law) and contractual liabilities are time-barred.
- Guarantees and complaints: for the legal guarantee period of the products and the limitation period of the corresponding actions.
- Newsletter: until you unsubscribe or withdraw consent. We keep proof of your subscription and unsubscription to demonstrate compliance.
- Contact forms and B2B requests: 12 months from the last communication if no commercial relationship is established.
- Browsing data and security logs: a maximum of 12 months, unless needed to investigate an incident.
- Audience measurement: the detail of each visit, by the hour, up to 30 days (the daily keys are deleted within the hour after midnight; backup copies keep them until they are renewed, under 12 months); daily totals, 25 months. On a day with very few visits those totals can describe a single person.
- Cookies and local storage: the periods stated in the Cookie policy.
Once these periods have elapsed, data will be deleted or anonymised. While a legal retention obligation persists, data will be kept blocked and available only to the competent authorities.
7. Your account
If you sign in to My account (with your email and a code we send you, no password), besides the data of your orders and boxes we keep:
- The sign-in codes we email you, stored as an encrypted fingerprint and never as the code itself, for at most 48 hours after they expire (the daily clean-up deletes them once 24 hours have passed). Each code expires after 15 minutes and works once.
- The devices you are signed in on: the browser and system as your device sends them (a text of up to 200 characters) and the date of your last visit, so you can see them in My details and sign out of any of them.
- Your favourites, if you mark them while signed in, so you have them on all your devices.
Purpose and legal basis: letting you see and manage your orders, boxes, invoices and addresses. It is the performance of your contract with us (art. 6.1.b GDPR).
Retention: each session ends 60 days after you last sign in or change something in My account and never lasts more than one year from when you signed in; after that you sign in again with a code. Your favourites and the rest of your account data are kept until you delete the account.
Your rights, without writing to us: in My details you can download a copy of your data (rights of access and portability) and delete your account (right to erasure). Deleting it removes your name, phone, addresses, favourites and sessions; orders and invoices are kept without your name for the period the law requires (section 6). If you have a paid order that has not left yet or an active box, you can delete the account once the order leaves or you cancel the box.
The cookie that keeps you signed in is described in the Cookie policy.
8. Your rights
You can exercise the following rights at any time:
- Access: find out which of your data we process and obtain a copy.
- Rectification: correct inaccurate or incomplete data.
- Erasure: ask us to delete your data when it is no longer needed. Invoices already issued are not deleted: they are kept, blocked, for the period required by tax and commercial law (art. 17.3.b GDPR).
- Objection: object to processing based on legitimate interest, including commercial communications.
- Restriction: ask us to restrict processing in the cases provided for by law.
- Portability: receive your data in a structured, commonly used format, or have it transmitted to another controller.
- Withdraw consent given, without affecting the lawfulness of prior processing.
- Not to be subject to automated decisions that produce legal effects or significantly affect you.
To exercise them, write to privacidad@praceira.example or by post to Rúa da Praza, 1, 32001 Ourense (Galicia), España, stating the right you are exercising. If we have reasonable doubts about your identity we may ask for a document proving it. We will reply within one month, extendable by two further months in complex cases, of which we would inform you.
You can object to the audience measurement without writing to us: turn on "Global Privacy Control" or "Do Not Track" in your browser and you will not be counted. Once the daily keys are deleted (within the hour after midnight), the visit records carry nothing that identifies you. Until then, on a day with a single order they could be linked to it by the hour; we never cross them.
If you believe we have not handled your rights correctly, you can lodge a complaint with the Spanish Data Protection Agency (AEPD), C/ Jorge Juan 6, 28001 Madrid, or through its electronic office at www.aepd.es. We would appreciate the chance to resolve it first.
9. Security measures
We apply technical and organisational measures appropriate to the risk of the processing, in accordance with Article 32 GDPR: encrypted communications (TLS), access control to systems, minimisation of the data collected, backups, access logging and processing agreements with all our providers. Payment data is entered directly into the PCI DSS-certified payment gateway; Praceira never sees or stores your full card number.
In the event of a security breach posing a high risk to your rights and freedoms, we will inform you without undue delay, in addition to notifying the AEPD.
10. Minors
The website is not aimed at children under 14 and we do not knowingly collect data from them. You must be over 18 to make purchases. If we discover that we have received data from a minor without the authorisation of their parents or guardians, we will delete it. If you are a parent or guardian and believe a minor in your care has given us data, please contact us.
11. Social media
Praceira has profiles on social networks (Instagram, TikTok, YouTube). The processing of data of those who interact with those profiles is governed by each platform's privacy policy; Praceira S.L. (placeholder) only accesses the information the platforms make available to business accounts and uses it solely to reply to your comments and messages.
12. Changes to this policy
We may update this policy to adapt it to regulatory changes or changes in our processing. We will publish the current version on this page with its update date and, if the change is substantial, we will let you know through the usual channels.