Privacy Policy
PRIVACY POLICY
The García Family — San Antonio
1. Information About the Collection of Personal Data
1.1 General Information
We are pleased that you are visiting the website of The García Family — San Antonio and appreciate your interest in our boutique.
Protecting your personal data is important to us. This Privacy Policy explains how we collect, use, and protect your personal information when you use our website.
Personal data refers to any information that can be used to identify you directly or indirectly.
1.2 Data Controller
The data controller responsible for processing personal data on this website within the meaning of the General Data Protection Regulation (GDPR) is:
The García Family — San Antonio
Email: support@thegarciafamilysanantonio.com
The data controller determines the purposes and means of processing personal data.
1.3 Data Security
For security reasons and to protect the transmission of confidential content such as orders or inquiries, this website uses SSL or TLS encryption.
You can recognize an encrypted connection by the https:// address in your browser and the lock icon in the address bar.
2. Data Collection When Visiting Our Website
When you visit our website without registering or providing information, we automatically collect certain technical data transmitted by your browser.
This may include:
Pages visited on our website
Date and time of access
Amount of data transferred
Referring website (if applicable)
Browser type and version
Operating system
IP address (anonymized where applicable)
This data is processed based on our legitimate interest in ensuring the stability, functionality, and security of the website (Art. 6(1)(f) GDPR).
The data is not used to personally identify you.
3. Cookies
Our website uses cookies to improve user experience and enable certain website features.
Cookies are small text files stored on your device.
Some cookies are deleted automatically after your browser session ends (session cookies), while others remain stored on your device (persistent cookies).
Cookies may collect information such as:
Browser type
IP address
Device information
Website usage behavior
Cookies help us to:
Remember shopping cart contents
Save user preferences
Improve website functionality
Analyze website performance
Deliver relevant advertisements
You may disable cookies through your browser settings. However, doing so may limit certain website functions.
4. Contacting Us
If you contact us via email or contact form, we collect personal data for the purpose of responding to your inquiry.
This may include:
Name
Email address
Message content
Legal basis:
Art. 6(1)(f) GDPR – Legitimate interest in responding to inquiries
Art. 6(1)(b) GDPR – If the inquiry relates to a contract
Your data will be deleted once your inquiry has been fully resolved unless legal retention obligations apply.
5. Customer Accounts & Order Processing
When you place an order or create an account, we process personal data required for contract fulfillment.
This may include:
Name
Billing and shipping address
Email address
Payment information
Order details
Legal basis: Art. 6(1)(b) GDPR (contract performance).
After completion of the contract, personal data may be stored according to legal retention obligations and then deleted.
You may request deletion of your account at any time.
6. Email Marketing
6.1 Newsletter Subscription
If you subscribe to our newsletter, we will use your email address to send promotional content and updates.
We use a double opt-in procedure, meaning you must confirm your subscription via email.
Legal basis: Art. 6(1)(a) GDPR (consent).
You can unsubscribe at any time via the unsubscribe link included in every email.
6.2 Email Marketing to Existing Customers
If you have purchased products from The García Family — San Antonio, we may send you emails regarding similar products or offers, unless you opt out.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest).
You may unsubscribe from marketing emails at any time.
7. Order Processing & Payment Providers
To process orders and payments, we may share necessary personal data with trusted service providers.
This may include:
Shipping carriers
Payment providers
Technical service providers
Legal basis: Art. 6(1)(b) GDPR.
Payment providers may include:
PayPal
Klarna
Credit card processors
Shopify Payments
These providers process data according to their own privacy policies.
8. Review Requests
With your consent, we may send a one-time email asking you to review a product you purchased.
Legal basis: Art. 6(1)(a) GDPR (consent).
You may withdraw your consent at any time.
9. Social Media Links
Our website may contain links to social media platforms such as:
These links are implemented as secure HTML links. Data is only transferred to the respective platform once you click the link.
The privacy policies of the respective social media platforms apply.
10. Online Marketing & Advertising
We may use marketing tools such as:
Google Ads (Conversion Tracking & Remarketing)
Facebook Pixel
Instagram Ads
These technologies help us:
Measure advertising effectiveness
Analyze website traffic
Display relevant advertisements
Legal basis:
Art. 6(1)(f) GDPR – legitimate interest
Art. 6(1)(a) GDPR – consent where required
You may manage tracking preferences via:
Browser settings
Google Ads settings
Facebook ad preferences
Cookie consent settings
11. Web Analytics
We may use analytics tools to understand how visitors interact with our website.
Analytics may collect information about:
Website traffic
User behavior
Device information
Performance metrics
IP anonymization may be applied where applicable.
12. Retargeting & Remarketing
We may use retargeting technologies such as:
Facebook Pixel
Google Ads Remarketing
These tools allow us to show relevant advertisements to visitors who previously interacted with our website.
Legal basis: Art. 6(1)(a) GDPR (consent).
You may withdraw your consent at any time through your browser or cookie settings.
13. Your Rights Under GDPR
Under the GDPR, you have the right to:
Access your personal data (Art. 15 GDPR)
Rectify inaccurate data (Art. 16 GDPR)
Request deletion of your data (Art. 17 GDPR)
Restrict processing (Art. 18 GDPR)
Data portability (Art. 20 GDPR)
Withdraw consent (Art. 7(3) GDPR)
File a complaint with a supervisory authority (Art. 77 GDPR)
Right to Object
If personal data is processed based on legitimate interest (Art. 6(1)(f) GDPR), you have the right to object at any time.
If personal data is used for direct marketing purposes, you may object at any time without providing a reason.
14. Data Retention Period
Personal data will only be stored for as long as necessary for:
Contract fulfillment
Legal retention requirements
Legitimate business interests
Once the applicable retention period expires, the data will be deleted.