GDPR
Privacy policy
Last updated: 26 September 2026
This translation is provided for convenience. The Spanish version is the legally binding one and prevails in case of any discrepancy. Read the Spanish version
1. Data controller
- Controller: Darvano
- Privacy contact: info@darvano.es (subject “Data protection”)
We haven't appointed a data protection officer because it isn't required for our activity.
2. What data we process, why and on what legal basis
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Managing your orders and pre-orders: payment, shipping, invoicing, status emails | Name, email, phone, address, products, amount, payment method (never the card number) | Performance of the contract (art. 6.1.b GDPR) and legal tax and accounting obligations (art. 6.1.c) | For the duration of the relationship and then for the legal periods: 6 years (Commercial Code) and 4 years (tax law) |
| Your customer account: order history and favourites | Name, email, password (stored encrypted, never in plain text), favourites | Performance of the account contract (art. 6.1.b) | Until you ask us to delete it. If you don't confirm your email, the account is deleted after 24 hours |
| Handling withdrawals, returns and the warranty | Order details, reason, communications | Legal obligation (art. 6.1.c; Spanish consumer protection law) | During the legal warranty (3 years) and the periods for claims |
| Answering your enquiries (“Write to us” form, email, WhatsApp) | Name, email, phone (optional), order number, message | Your request and our legitimate interest in helping you (art. 6.1.b and 6.1.f) | Until the enquiry is resolved and 1 more year |
| Measuring use of the shop with our own statistics | Pages viewed, checkout steps, the website or campaign you came from, approximate country and city (worked out from your IP by our server, which doesn't store it), device type, browser and language. To avoid counting you twice on the same day, a code that changes daily and can't be reversed is used. No cookies | Legitimate interest in knowing how the shop is used (art. 6.1.f) | 13 months; the daily code can no longer be calculated the next day |
| Knowing which ads, networks or collaborations bring us sales | On your order: where the visit came from (ad, social network, campaign or website) and, if you answer, how you heard about us | Legitimate interest in measuring our advertising (art. 6.1.f). Answering is optional | Same as the order |
| Sending you the newsletter (news and offers) and your welcome code | Email, language, date and source of sign-up and proof of your consent (double opt-in) | Your express consent (art. 6.1.a GDPR and art. 21 LSSI-CE). You can unsubscribe with one click in every email | Until you unsubscribe. Unconfirmed sign-ups are deleted after 30 days |
| Letting you know once when a sold-out watch is back or opens for pre-order (“Notify me”) | Email, language and the watch you're waiting for | Your request and consent (art. 6.1.a) | Until we send the alert and 1 more year; at most 2 years if the watch doesn't come back |
| Asking you, once per order and some days after delivery, what you thought | Score, comment and, only if you allow it, your first name to publish the review | Legitimate interest in improving the service (art. 6.1.f). You can object with one click in the email itself | Same as the order |
| Analytics, ad measurement and personalised advertising with third-party cookies | Cookie identifiers, pages and watches viewed, purchases (amount, without your contact details), the ad you came from, device, approximate location | Your consent (art. 6.1.a), which you can withdraw at any time | According to the cookie policy |
| Proving your cookie choice | Random browser identifier, chosen option and date (no IP) | Legal obligation to prove consent (arts. 6.1.c and 7.1) | Up to 3 years |
| Shop security and fraud prevention | Technical access and sign-in logs | Legitimate interest (art. 6.1.f) | As long as strictly necessary, 1 year at most |
Data marked as required in forms is needed to process what you ask for; without it we can't do so. We don't send advertising by email without your prior express consent (art. 21 LSSI-CE). We don't make automated decisions or profile you with legal effects.
3. Who we share your data with
We don't sell your data. We only share it with providers who process it on our behalf, under contract and with GDPR safeguards, or when the law requires it:
- Web hosting and database: Vercel Inc. and Neon Inc.
- Payments: Stripe Payments Europe Ltd., PayPal (Europe) S.à r.l. et Cie, S.C.A. and Redsys/your bank for Bizum and card. You enter your payment details on their secure page; they also act as independent controllers to prevent fraud and comply with payment regulations.
- Sending order and newsletter emails: Resend (Plus Five Five, Inc.).
- Couriers: name, address and phone to deliver your order.
- Google sign-in, if you choose it: Google Ireland Ltd.
- Analytics, only with your consent: Google Tag Manager (Google Ireland Ltd.) and Google Analytics (Google Ireland Ltd.).
- Public authorities, judges and courts when there's a legal obligation (for example, the Spanish Tax Agency).
4. International transfers
Some of these providers are based or have servers in the United States. Transfers are covered by the adequacy decision on the EU-US Data Privacy Framework (10 July 2023) for participating companies and, failing that, by the standard contractual clauses approved by the European Commission.
5. Your rights
You can ask at any time for access to your data, its rectification or erasure, the restriction of processing, to object to it, the portability of the data you gave us and to withdraw your consent without affecting prior processing. Write to us at info@darvano.es stating which right you're exercising; if needed we'll ask you to prove your identity. We reply within one month at most.
If you think we haven't handled your request properly, you can complain to the Spanish Data Protection Agency (www.aepd.es, C/ Jorge Juan 6, 28001 Madrid) or to the authority of your country.
6. Minors
The shop isn't aimed at children under 14 and you must be an adult to buy. If we detect data of a child under 14 provided without their parents' or guardians' permission, we'll delete it.
7. Security
The website always uses an encrypted connection (HTTPS). Passwords are stored encrypted with an irreversible algorithm, access to the admin panel is restricted and card details never pass through our servers.
8. Cookies
What the shop stores in your browser and how to choose is explained in the cookie policy.
9. Changes to this policy
If we change how we process your data, we'll update this page and show the date of the last update. If the change is significant, we'll let you know.
