Privacy policy
At Ginger & Velvet we treat your personal data with the same care we put into the jewellery: we ask for the minimum, we use it for what we tell you, and we sell it to no one. Here is exactly what we do with it, in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
1. Who the controller is
- Controller: Juan José Villanúa, sole trader operating under the trade name Ginger & Velvet
- Spanish tax ID: 20257766X
- Address: C/ Alameda 4, 28014 Madrid (Spain)
- Data protection contact: info@gingervelvet.com
2. What data we process
- Identification and contact data: name and surname, shipping and billing address, email and phone number.
- Order and payment data: products purchased, amount, date and transaction identifier. We do not store your full card details: payment is handled directly by the payment providers.
- Customer account data, if you choose to create one: order history and saved addresses.
- Browsing data: IP address, device and browser type, pages visited and products viewed, collected through cookies and similar technologies, only where you have given your consent.
- Your communications with us: what you write to us through the contact form, by email or via WhatsApp.
3. What we use it for, and on what legal basis
- Managing your order — processing it, charging for it, shipping it, handling exchanges and returns and answering your questions. Basis: performance of the sales contract (art. 6.1.b GDPR).
- Meeting legal obligations — invoicing, accounting and tax obligations. Basis: legal obligation (art. 6.1.c GDPR).
- Managing your customer account, if you create one. Basis: performance of the contract (art. 6.1.b GDPR).
- Sending you our newsletter and commercial communications about new collections, promotions and events. Basis: your express consent (art. 6.1.a GDPR), requested through a specific checkbox and withdrawable at any time. If you have already been a customer, we may write to you about products similar to those you bought, always with the option to unsubscribe in every message (art. 21.2 LSSI-CE).
- Measuring and improving the store — usage analytics, statistics and personalised advertising. Basis: your consent, given through the cookie banner (art. 6.1.a GDPR).
- Preventing fraud and protecting the security of the store and of payments. Basis: legitimate interest (art. 6.1.f GDPR).
Creating an account or placing an order does not mean agreeing to receive advertising: these are separate consents.
4. How long we keep it
- Order and invoicing data: for the duration of the relationship and, afterwards, for the applicable statutory limitation periods — 4 years for tax purposes and 6 years for the commercial retention of records.
- Customer account data: until you ask us to delete it.
- Newsletter data: until you withdraw your consent or unsubscribe.
- Browsing data and cookies: for the period stated for each cookie, up to a maximum of 24 months, after which we ask for your consent again.
- Enquiries and emails: for as long as needed to deal with them, plus one year.
5. Who else has access to your data
We do not sell or transfer your data to third parties for commercial purposes. We do work with providers who process it on our behalf, under a data processing agreement:
- Shopify International Ltd. — e-commerce platform and hosting of the store.
- Shopify Payments and PayPal — payment processing.
- Transport and courier companies — delivery of orders.
- Mailrelay — sending the newsletter.
- Google Ireland Ltd. — web analytics and advertising (Google Analytics, Google Ads, Merchant Center).
- Meta Platforms Ireland Ltd. — advertising and measurement on Facebook and Instagram.
- Dondy — WhatsApp button and conversations from the website.
We also disclose data to the tax authorities and other public bodies where a legal provision requires us to.
6. International transfers
Some of these providers process data outside the European Economic Area, mainly in the United States and Canada. Those transfers rely on the standard contractual clauses approved by the European Commission and, where applicable, on the adequacy decision for the EU–US Data Privacy Framework, together with the additional security measures applied by those providers.
7. Your rights
- Access — to know what data of yours we process.
- Rectification — to correct data that is inaccurate or incomplete.
- Erasure — to ask us to delete it when it is no longer needed.
- Objection — to object to certain processing, including advertising.
- Restriction — to ask us to keep the data but not use it while a claim is being resolved.
- Portability — to receive your data in a structured, commonly used format, or to have us send it to another controller.
- Withdrawal of consent at any time, without affecting the lawfulness of processing carried out beforehand.
8. How to exercise them
Write to us at info@gingervelvet.com stating which right you wish to exercise. We may ask you to prove your identity. We will reply within one month of receiving your request, extendable to two months if the request is particularly complex, and exercising these rights is free of charge.
If you have a customer account, you can view and update your details and addresses directly from your account. To unsubscribe from the newsletter, just use the link at the bottom of any of our emails.
9. Complaints
If you believe we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Agency (C/ Jorge Juan 6, 28001 Madrid — www.aepd.es). We would be grateful if you wrote to us first so we can try to resolve it.
10. Minors
The store is not aimed at children under 14 and we do not knowingly collect their data. If we find that we have processed the data of a child under that age without the consent of a parent or guardian, we will delete it.
11. Cookies
We use our own and third-party cookies. The technical ones are essential for the store to work; analytics and advertising cookies are only activated if you accept them. You can accept them, reject them or change your mind at any time from the GDPR compliance page.
12. Security and changes
We apply reasonable technical and organisational measures to protect your data against unauthorised access, loss or alteration, and we undertake to keep it confidential.
We may update this policy if the law or the way we work changes. The version in force is always the one published on this page.
Last updated: 2 September 2026.
