Privacy Policy
Last updated: June 7, 2026
1. Data controller
- Owner: Encarnación Bravo Aranda
- NIF: 53107763G
- Address: Alcorcón, España
- Email: info@thionashop.com
- Trade name: ThionaShop
2. Processing purposes
| Purpose | Legal basis | Retention |
|---|---|---|
| User account management | Performance of contract (Art. 6.1.b GDPR) | While the account is active |
| Order and shipping processing | Performance of contract (Art. 6.1.b GDPR) | 4 years (tax obligation) |
| Payment processing | Performance of contract (Art. 6.1.b GDPR) | 4 years (tax obligation) |
| Fraud prevention (reCAPTCHA) | Legitimate interest (Art. 6.1.f GDPR) | Session duration |
| Aggregate measurement of visits per page | Strictly necessary site administration (Art. 22.2 LSSI-CE) | 24 months |
| Aggregate measurement of catalog demand and gaps | Legitimate interest in improving the catalog (Art. 6.1.f GDPR) | 30 days if it does not reach 3 repetitions; otherwise, 24 months |
| Detailed browsing and search analytics | Consent (Art. 6.1.a GDPR) | 90 days or until consent is withdrawn |
| Sending commercial communications | Consent (Art. 6.1.a GDPR) | Until consent is withdrawn |
3. Personal data collected
- Account data: username, email, password (encrypted)
- Profile data: first name, last name, phone
- Shipping data: address, city, postal code, province, country
- Payment data: processed by Stripe (we do not store card data)
- Technical data: IP address, user agent (for security)
- Aggregate audience analytics: page, country, and date, without identifiers, IP address, or session data
- Aggregate catalog analytics: normalized query, date, whether results existed, identifier of the first relevant product, and counter, after discarding potentially personal patterns
- Optional analytics: pages visited and searches associated with a session when consent has been given
4. Data recipients
We may disclose your data to providers of services required to operate the store, such as technology hosting, payments, fraud prevention, logistics and communications. These providers will process the data solely to provide those services and with the safeguards required by applicable law.
5. International transfers
When a provider processes data outside the European Economic Area, the safeguards provided for by the GDPR will apply, together with additional measures where necessary to protect your personal data.
6. Data subject rights
In accordance with the GDPR, you have the right to:
- Access (Art. 15): Obtain a copy of your personal data
- Rectification (Art. 16): Correct inaccurate data
- Erasure (Art. 17): Request the deletion of your data
- Restriction (Art. 18): Restrict the processing of your data
- Portability (Art. 20): Receive your data in a structured format
- Objection (Art. 21): Object to the processing of your data
To exercise these rights, contact us at info@thionashop.com or from your user panel in the "My data & privacy" section.
7. Right to lodge a complaint
If you consider that the processing of your data does not comply with regulations, you can file a complaint with the Spanish Data Protection Agency (AEPD) — www.aepd.es.
8. Security measures
- Passwords encrypted with bcrypt
- Communications encrypted via HTTPS/TLS
- Session cookies with HttpOnly, Secure and SameSite attributes
- Login attempt limiting (rate limiting)
- Bot protection (reCAPTCHA)