Privacy Policy (NEW DRAFT — for review)
PRIVACY POLICY
This Privacy Policy explains how TRIKKOBRAND, SL (CIF B67555359, Nou Cases 109, España) processes your personal data when you use trikkobrand.com or place an order. We comply with the EU General Data Protection Regulation (GDPR) and the Spanish LOPDGDD.
Data controller
TRIKKOBRAND, SL is the data controller. Contact: help@trikkobrand.com.
Data we collect
- Order data: name, email, shipping address, billing address, phone (optional), order history.
- Payment data: processed by our payment providers (Shopify Payments, PayPal, Klarna). We do not store full card numbers on our servers.
- Account data: if you create an account, your login and saved preferences.
- Browsing data: IP address, device, browser, pages viewed, cookies (see Cookies section).
- Marketing data: email and consent status if you subscribe to our newsletter.
Why we process your data
- To fulfil your order (contract): process payment, ship items, handle returns. Legal basis: art. 6(1)(b) GDPR.
- To comply with legal obligations: invoicing, tax records. Legal basis: art. 6(1)(c) GDPR.
- To improve the site and prevent fraud: analytics, security. Legal basis: legitimate interest, art. 6(1)(f) GDPR.
- To send you marketing (newsletter): only with your explicit consent, which you can withdraw at any time. Legal basis: art. 6(1)(a) GDPR.
Third parties we share data with
We share data only with providers who help us run the business. All are GDPR-compliant or covered by Standard Contractual Clauses for international transfers:
- Shopify (e-commerce platform, Canada) — store operations.
- Klarna (Sweden) — Buy Now Pay Later payments.
- PayPal (Luxembourg) — payment processing.
- UPS / Sendcloud (USA / Netherlands) — shipping and tracking.
- Klaviyo (USA) — email marketing platform.
- Google Analytics (USA) — anonymised site analytics.
- Meta (Facebook/Instagram) (Ireland) — advertising and pixel tracking.
How long we keep your data
- Order and invoicing data: 6 years (required by Spanish tax law, Ley 58/2003).
- Account data: until you ask us to delete your account.
- Marketing data: until you unsubscribe or withdraw consent.
- Analytics data: 26 months (Google Analytics default).
Your rights
Under GDPR you have the right to:
- Access your data
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Restrict or object to processing
- Data portability
- Withdraw consent at any time
- Lodge a complaint with the Spanish supervisory authority AEPD at aepd.es
To exercise any of these rights, email help@trikkobrand.com. We will respond within 30 days.
Cookies
We use cookies to make the site work, remember your preferences, and measure performance. When you first visit, you can accept all, reject non-essential, or customise your preferences in our cookie banner. You can change your preferences at any time by clearing your browser cookies for this site.
- Strictly necessary cookies: required for cart, checkout, login. Cannot be disabled.
- Analytics cookies: Google Analytics. Anonymised, helps us improve the site.
- Marketing cookies: Meta Pixel, Klaviyo, TikTok Pixel. Used for personalised advertising.
Children
We do not knowingly collect data from anyone under 14 years old. If you are a parent and believe we have collected your child's data, contact us at help@trikkobrand.com and we will delete it.
Updates to this policy
We may update this policy from time to time. The date below indicates the last update.