1. Data controller
- Controller: Jairo Serrano Alvarez
- Tax ID: 58447714E
- Address: Camin de la Estacion 759
- Email: aretewears@gmail.com
- Data Protection Officer: not appointed (mandatory criteria of GDPR Art 37 and LOPDGDD Art 34 do not apply).
In compliance with the EU General Data Protection Regulation (Regulation 2016/679, GDPR) and the Spanish LOPDGDD, this Privacy Policy informs you about the processing of your personal data.
2. Purposes
- Account creation and management.
- Processing payments and unlocking premium content.
- Transactional emails (access confirmation, account recovery, service notices).
- Customer support and complaints handling.
- Affiliate commission tracking and payouts.
- Compliance with legal obligations (accounting, tax, fraud prevention).
- With your express consent, marketing communications about new features or products.
3. Legal basis
- Contract performance (Art 6.1.b GDPR).
- Legal obligation (Art 6.1.c): accounting, tax, evidence preservation.
- Legitimate interest (Art 6.1.f): site security, fraud prevention, service improvements (right to object available).
- Consent (Art 6.1.a): non-essential cookies and marketing. Withdrawable at any time without retroactive effect.
4. Data we process
| Category | Data | Source |
|---|---|---|
| Identification | Email, name (if via Google) | Data subject |
| Payment | Stripe session ID (NO card data is stored) | Stripe |
| Technical | IP, browser, OS, access date/time, language | Server |
| Usage | Country, last seen, aggregate locations browsed | Server |
| Affiliate referrer | Affiliate code that brought you (if any) | Entry URL |
We do not process special categories of data (GDPR Art 9). If you submit such data by mistake, we will delete it upon detection.
5. Minimum age
The service is intended for users aged 14 or above (minimum age to consent to data processing under Article 7 LOPDGDD in Spain). Younger users require parental authorization.
6. Automated decision-making and profiling
No solely automated decisions producing legal or significantly affecting effects (Art 22 GDPR) are taken.
7. Recipients and processors
- Supabase Inc. — auth and database (EU instance).
- Stripe Payments Europe Ltd. — payment gateway (Standard Contractual Clauses).
- Vercel Inc. — hosting/CDN (SCCs and EU–US DPF).
- Google LLC — OAuth, AdSense, fonts (SCCs and EU–US DPF).
We do not sell or share your data with third parties for their own commercial purposes.
8. International transfers
Some processors are based outside the EEA (mainly the United States). Transfers rely on:
- EU Standard Contractual Clauses (Commission Decision 2021/914).
- EU–US Data Privacy Framework (adequacy decision of 10 July 2023).
9. Retention
| Data type | Period | Basis |
|---|---|---|
| Active account | Lifetime of the relationship | Contract |
| Accounting/invoicing | 6 years from last operation | Spanish Commerce Code Art 30 |
| Tax data | 4 years (general) / 10 years (corrections) | General Tax Law |
| Security logs | 12 months | Legitimate interest |
| Support / comms | 12 months after last interaction | Legitimate interest |
| Affiliate records | 6 years from last payout | Accounting |
10. Your rights
- Access, rectification, erasure, restriction, objection, portability (GDPR Arts 15–22).
- No automated decisions with legal effects.
- Withdraw consent at any time without retroactive effect.
How to exercise
Email aretewears@gmail.com:
- Subject: "GDPR — [right exercised]"
- Your full name and registered email
- Copy of ID or equivalent for identity verification
We will respond within one month, extendable to two for complex cases (Art 12.3 GDPR).
11. Right to lodge a complaint
Spanish Data Protection Agency (AEPD): aepd.es · or your local EU supervisory authority.
12. Deceased persons' data
Per Article 3 LOPDGDD, relatives, heirs and persons linked by family or factual ties may request access, rectification or erasure of the deceased's data, unless the deceased expressly prohibited it or law provides otherwise.
13. Security
- TLS 1.3 encryption on all communications.
- OAuth or bcrypt-hashed passwords.
- Role-based access control (Row Level Security).
- Audit logs of sensitive operations.
- Encrypted backups with periodic rotation.
14. Cookies
See the Cookie Policy for details.
15. Changes
We may amend this Policy. Substantial changes are notified on the site and, for registered users, by email. The current version is the one published on this page.