Skip to content
Policy · Política de Privacidad

Privacy Policy

Last updated: June 5, 2026

Last updated: June 5, 2026

This Privacy Policy explains how Andrés Felipe Duque Alvarez (autónomo), NIF ES-60928520W (hereinafter "the Controller", "we", or "us"), processes personal data collected through the website shishax.eu (the "Site") and related services.

This policy applies to all visitors and customers of the Site and complies with Regulation (EU) 2016/679 (General Data Protection Regulation, "GDPR") and Spanish Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD).

Data Controller

Andrés Felipe Duque Alvarez (autónomo)

Email: info@shishax.eu

Categories of Personal Data We Collect

We may collect and process the following categories of personal data:

  • Identification data: first and last name
  • Contact data: postal address, email address, telephone number
  • Transactional data: order history, products purchased, order value
  • Payment data: payment is processed directly by our payment provider (Stripe Payments Europe Ltd.). We do not store full payment card details on our systems
  • Technical data: IP address, browser type, device information, pages visited
  • Marketing data: communication preferences, consent records

We do not knowingly collect personal data from individuals under 21 years of age.

Legal Bases for Processing

We process your personal data on the following legal bases under Article 6 GDPR:

Purpose Legal basis To process and fulfil your orders Performance of a contract (Art. 6.1.b) To send order-related transactional emails Performance of a contract (Art. 6.1.b) To send marketing communications Your consent (Art. 6.1.a), which you may withdraw at any time To comply with legal obligations (tax records, consumer protection) Legal obligation (Art. 6.1.c) To analyse Site traffic and improve our services Legitimate interest (Art. 6.1.f) To prevent fraud and abuse Legitimate interest (Art. 6.1.f)

Recipients of Personal Data

We may share your personal data with the following categories of recipients, all of whom act as data processors on our behalf under contractual safeguards:

  • Shopify International Ltd. (Ireland) and Shopify Inc. (Canada) — e-commerce platform infrastructure
  • Stripe Payments Europe Ltd. (Ireland) — payment processing
  • Google LLC (United States) — Google Workspace email infrastructure and, where applicable, analytics
  • Resend, Inc. (United States) — transactional email delivery
  • Shipping carriers (varies by destination) — order delivery
  • Spanish customs broker and tax advisors — only when strictly necessary for legal compliance

We do not sell, rent, or trade your personal data to third parties for their own marketing purposes.

International Data Transfers

Some of our processors are located outside the European Economic Area, primarily in the United States. Where personal data is transferred outside the EEA, we rely on:

  • Standard Contractual Clauses approved by the European Commission, or
  • Adequacy decisions where applicable, or
  • Other appropriate safeguards under Chapter V of the GDPR

You may request a copy of the safeguards in place by writing to info@shishax.eu.

Retention Periods

We retain your personal data only for as long as necessary for the purposes set out above:

  • Order and transactional data: 6 years from the end of the financial year in which the transaction occurred, as required by Spanish tax law
  • Marketing data: until you withdraw your consent
  • Account data: until you request deletion, or 3 years from your last interaction
  • Technical and analytics data: up to 14 months

Your Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right of access (Art. 15): to obtain confirmation of whether we process your data and a copy of that data
  • Right to rectification (Art. 16): to correct inaccurate or incomplete data
  • Right to erasure (Art. 17): to request deletion of your data in certain circumstances
  • Right to restriction of processing (Art. 18): to limit how we use your data
  • Right to data portability (Art. 20): to receive your data in a structured, machine-readable format
  • Right to object (Art. 21): to object to processing based on legitimate interest or direct marketing
  • Right to withdraw consent at any time, without affecting the lawfulness of processing before withdrawal
  • Right not to be subject to automated decision-making (Art. 22)

To exercise any of these rights, contact us at info@shishax.eu with a copy of your identification document.

Right to Lodge a Complaint

You have the right to lodge a complaint with the Spanish Data Protection Authority:

Agencia Española de Protección de Datos (AEPD) C/ Jorge Juan, 6, 28001 Madrid, Spain Telephone: 901 100 099 / 912 663 517 Website: www.aepd.es

Cookies

Our Site uses cookies and similar technologies to operate the Site, remember your preferences, and analyse traffic. You can manage your cookie preferences via the cookie banner on first visit and at any time through your browser settings. Disabling cookies may limit Site functionality. See our separate Cookie Notice for details.

Security

We apply appropriate technical and organisational measures to protect your personal data, including TLS encryption for data in transit, restricted access controls, and contractual safeguards with our processors. However, no transmission over the internet is fully secure, and we cannot guarantee absolute security.

Age Restriction

shishax.eu and the products sold through it are intended exclusively for adults aged 21 and over. We do not knowingly process personal data from individuals under 21. If you believe that a person under 21 has provided us with personal data, please contact us immediately and we will delete it.

Changes to This Policy

We may update this Privacy Policy from time to time. The current version is always available on this page with the date of last update. Material changes will be communicated by email to registered customers or through a prominent notice on the Site.

Contact

For any questions about this Privacy Policy or to exercise your rights, contact us at:

Andrés Felipe Duque Alvarez (autónomo) 

Email: info@shishax.eu