Legal

Privacy policy

Last updated: 2026-09-01

This policy explains what we do with your personal data when you browse this site, create an account, place an order or subscribe to our emails. It follows the EU General Data Protection Regulation (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).

Who is responsible

Legal name
Trade name
Óvalo Fashion
Tax ID
Registered address
Barcelona, Spain
Email

For anything about your data, write to . We have not appointed a Data Protection Officer; we are not required to.

What we collect, why, and on what basis

Placing an order

Name, email, phone number and shipping address, plus what you bought and for how much. Basis: performance of a contract. Without this we cannot prepare or send an order. Note that there is no online payment on this site, so we never see or store card or bank details.

Your account

Email, a password we never see in plain text, and your name if you give it. Basis: performance of a contract — it is what lets you sign in and see your order history.

Newsletter

Your email address, when you confirmed it and where you signed up from. Basis: your consent, which you give by ticking the box and then confirming the link we email you (double opt-in). Every email we send carries an unsubscribe link, and withdrawing your consent is as easy as giving it.

Audience measurement

Page views, with an anonymous daily identifier derived from technical data. Basis: legitimate interest in knowing which pages are used. It sets no cookies, does not follow you to other sites, and page addresses are sent without their query string. See the cookie policy.

Error reports

When something breaks, our servers send a technical report — the error, the page, the browser. Basis: legitimate interest in keeping the shop working. These reports are scrubbed before they leave: no cookies, no email addresses, no addresses, no order tokens.

Who else sees your data

These are our processors and the recipients of the data. We do not sell your data to anyone.

  • Supabase — database and authentication. Our project is hosted in London (United Kingdom), a country the European Commission has recognised as providing adequate protection.
  • Vercel Inc. (United States) — hosting and audience measurement, under Standard Contractual Clauses.
  • Resend (United States) — sending transactional and newsletter emails, under Standard Contractual Clauses.
  • Meta Platforms — because orders are confirmed over WhatsApp, the message you send us (with your order details) goes through WhatsApp and is governed by their own terms. If you would rather not use WhatsApp, email us instead and we will confirm the order that way.
  • Carriers, to deliver your parcel, and our accountants and the tax authority where the law requires it.

How long we keep it

  • Orders and invoices: six years, which is what Spanish commercial and tax law requires.
  • Account data: while your account exists, and deleted when you close it.
  • Newsletter: until you unsubscribe. We then keep a record that you unsubscribed, so we do not email you again by mistake.
  • Sign-ups that are never confirmed: they stay unconfirmed and unused, and we never email them again.
  • Error reports and audience data: short-lived, and never tied to your identity.

Your rights

You can ask us for access to your data, for it to be corrected or deleted, for processing to be restricted, for a copy in a portable format, and you can object to processing based on legitimate interest. You can withdraw consent for the newsletter at any time, which does not affect what we sent before.

Write to and we will answer within one month. If you think we have got it wrong, you can complain to the Spanish Data Protection Agency (Agencia Española de Protección de Datos, aepd.es).

Security

Traffic is encrypted in transit. Passwords are stored hashed by our authentication provider and are never visible to us. Access to the shop's admin panel is restricted, and the database enforces those restrictions itself rather than trusting the application. New passwords are checked against known breach lists before we accept them.

Children

This shop is not aimed at children under 14. If you believe a minor has given us data, write to us and we will delete it.

Changes

If we change this policy we will update the date at the top of the page, and we will tell subscribers by email if the change is significant.

This page is a structural draft prepared with the shop. Have it reviewed by a lawyer before the store opens to the public.