Privacy Policy
1. Data Controller
- Responsible: Guillermo Ramos Sánchez (“the Responsible”)
- NIF: 50215502Q
- Address: C/ Gaztambide 48 3E 28015 Madrid
- Contact email: info@goldeorovintage.com
2. Personal data we collect
We may process the following categories of data, depending on your use of the site:
- Identification and contact: name, surname, email, telephone.
- Shipping and billing: address, country, province, postal code, VAT/Tax ID (if applicable), company details if provided.
- Purchase information: products, amounts, history, incidents, returns, communications with support.
- Technical data: IP address, device, browser, identifiers, security and anti-fraud logs.
- Preferences: language, country/currency, wish lists if applicable.
- Marketing: consent for newsletters and commercial communications (where applicable).
3. Purposes and legal bases
We process your data for:
- Managing orders and providing the service (processing, shipping, returns, customer service). Basis: performance of the contract (Art. 6.1.b GDPR).
- Managing payments and fraud prevention (validations, risk control, security). Basis: performance of the contract and/or legitimate interest (art. 6.1.by 6.1.f).
- Compliance with legal obligations (tax, accounting, consumer, safety). Basis: legal obligation (art. 6.1.c).
- Commercial communications (newsletter, news, promotions). Basis: consent (art. 6.1.a). You can unsubscribe at any time.
e) Service improvement, analytics and quality (aggregate measurement, performance, incidents).
- Basis: legitimate interest and/or consent where required (especially for cookies/marketing).
4. Data retention
- Purchase and billing data: for the periods required by tax/accounting regulations and to address potential liabilities.
- Customer account details (if any): while you maintain the account or until you request its deletion, without prejudice to blocked retention.
- Marketing: until you withdraw your consent or request to unsubscribe.
- Technical records: the time required for security, auditing, and service improvement.
5. Recipients and processors
We may share or allow access to your data with:
- Technology providers (e.g., e-commerce platform, hosting, support).
- Payment gateways (e.g., Shopify Payments, PayPal) to process the transaction.
- Transport and logistics companies to deliver orders and manage returns.
- Email/marketing providers if you subscribe to communications.
- Consulting/management services and banking entities when necessary.
- Public authorities when there is a legal obligation.
These third parties act as independent processors or controllers as the case may be.
6. International Transfers
When using technology providers that may be located outside the European Economic Area, international data transfers may occur. In such cases, appropriate safeguards will be applied (e.g., Standard Contractual Clauses or other mechanisms valid under the GDPR).
7. Rights of persons
You can exercise your rights of: access, rectification, erasure, opposition, limitation, portability and no longer being subject to automated decisions, by sending a request to [EMAIL] indicating “Data Protection” and proving your identity when necessary.
If you believe that we have not properly addressed your rights, you can file a complaint with the Spanish Data Protection Agency (AEPD) .
8. Security measures
We apply reasonable technical and organizational measures to protect personal data against loss, misuse, unauthorized access or alteration.
9. Minors
This website is not intended for children under 14 years of age. If you are under 14, do not provide personal information without parental/guardian authorization.
10. Changes in policy
We may update this Policy to adapt to regulatory or service changes. The current version will be the one published on the website.