Privacy Policy
Last updated: June 2026
1. Who We Are
Brand New Clothes (“we”, “us”, “our”) operates the website brandnewclothes.shop. We are based in Spain and subject to the General Data Protection Regulation (GDPR/RGPD) and Spanish Organic Law 3/2018 on Data Protection (LOPDGDD).
Contact: victorlatorreuceda@gmail.com
2. What Data We Collect
We collect the following personal data:
When you place an order: name, email address, shipping address, billing address, phone number, payment information (processed by our payment providers — we do not store card details).
When you create an account: name, email address, password (encrypted).
When you subscribe to our newsletter: email address.
When you browse our site: IP address, browser type, device type, pages visited, time on site. This data is collected via cookies and analytics tools (see our Cookie Policy).
When you contact us: name, email address, and any information you include in your message.
3. Why We Collect Your Data (Legal Basis)
- To fulfil your order: processing is necessary for the performance of a contract (Art. 6(1)(b) GDPR).
- To send you marketing communications: based on your consent (Art. 6(1)(a) GDPR). You can withdraw consent at any time.
- To improve our website and services: based on our legitimate interest (Art. 6(1)(f) GDPR) in understanding how visitors use our site.
- To comply with legal obligations: such as tax and accounting requirements (Art. 6(1)(c) GDPR).
4. Who We Share Your Data With
We share your data only with third parties necessary to operate our business:
- Payment processors: Stripe, PayPal — to process your payments securely.
- Shipping providers: to deliver your orders.
- Analytics tools: Google Analytics 4, Hotjar/Contentsquare — to understand site usage.
- Marketing tools: HubSpot — to manage email communications and CRM.
- Hosting provider: Hostinger — to host our website.
We do not sell your personal data to third parties.
5. International Transfers
Some of our service providers (Google, HubSpot) are based in the United States. These transfers are protected by Standard Contractual Clauses (SCCs) approved by the European Commission, or the EU-US Data Privacy Framework where applicable.
6. How Long We Keep Your Data
- Order data: 5 years (Spanish tax law requirement).
- Account data: until you delete your account.
- Newsletter subscribers: until you unsubscribe.
- Analytics data: 14 months (Google Analytics default retention).
- Inactive accounts: deleted after 36 months of inactivity.
7. Your Rights
Under the GDPR, you have the right to:
- Access your personal data.
- Rectify inaccurate data.
- Erase your data (“right to be forgotten”).
- Restrict processing of your data.
- Data portability — receive your data in a machine-readable format.
- Object to processing based on legitimate interest.
- Withdraw consent at any time for marketing communications.
To exercise any of these rights, contact us at victorlatorreuceda@gmail.com. We will respond within 30 days.
You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD): www.aepd.es.
8. Security
We implement appropriate technical and organisational measures to protect your personal data, including SSL encryption, secure payment processing, and access controls.
9. Children
Our website is not directed at children under 16. We do not knowingly collect personal data from children.
10. Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with an updated date.
