2 patterns −10% · 3 or more −15%

Last updated: 1 September 2026 · Version: 2.0

1. Who is responsible for your data

Controller: Kenya Rodríguez Ramírez · Trading name: ShowroomCrochet
Tax ID (NIF): 23276206E
Registered address: C/ Antonio Campos Mula El Toribio, 3, Bloque 7/1, Piso A — 30880 Águilas (Murcia), Spain
Email: hola@showroomcrochet.com · Telephone: +34 623 025 368

The owner is a sole trader. She decides what is done with your personal data and why, which is what makes her the controller under article 4(7) of Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”), read together with Ley Orgánica 3/2018, de protección de datos personales y garantía de los derechos digitales (“LOPDGDD”).

There is no Data Protection Officer, and none is required. Article 37 GDPR calls for one only where the core activity is large-scale regular monitoring of people, or large-scale processing of special categories of data. This is a small shop selling digital crochet patterns; it does neither. Any question about your data goes straight to the address above, and is answered by the owner herself.

2. What this policy covers

This policy explains what happens to the personal data collected through this website.

Three companion documents cover the rest, and the four are meant to be read as one set: the Legal Notice governs use of the website, the Terms & Conditions govern purchases, and the Cookie Policy covers cookies and similar technologies. The Cookie Policy forms part of this one: what it says about what is stored on your device, and for how long, is not repeated here.

3. What data is collected, and when

  • When you place an order: your name, email address, billing address and country, what you ordered, the order number, date, amount and tax. This is required — without it there is no contract and no invoice.
  • When you pay: the payment provider handles the payment. Your full card number and its security code never reach this shop. What comes back is the method you used, the last four digits, the result and a transaction reference.
  • When you ask for an immediate download: the exact wording of the confirmation you ticked, with its date, time and order number. This one is required by law — article 103.m TRLGDCU makes that record the condition of the download.
  • When you create an account: a username, your email address, a password — stored hashed, and unreadable even to the owner — and your order history. An account is optional: you can buy without one.
  • When you subscribe to emails: your email address, and your first name if you give it. Entirely optional.
  • When you leave a review: your display name, the rating, what you write, and whether the purchase can be verified. Reviews are published, so write yours as something public.
  • When you write to the shop: your email address and whatever you put in the message.
  • When you watch course video: viewing data handled by the video platform named in section 5.
  • Whenever anyone visits, automatically: IP address, browser and device information, the pages visited, and the security and performance logs of the server and of the network in front of it.

No special categories of data are collected — nothing about health, beliefs, origin or anything else listed in article 9 GDPR. Please do not send any.

4. Why it is used, and on what legal basis

  • Taking your order, giving you the files and supporting you afterwards — performance of a contract, article 6(1)(b).
  • Issuing and keeping the invoice, and the accounting and tax records — legal obligation, article 6(1)(c), with Ley 37/1992 (VAT), Ley 58/2003 (the General Tax Act) and article 30 of the Código de Comercio. This one survives a deletion request, and section 8 explains why.
  • Keeping the record of the confirmation you ticked before downloading — legal obligation, article 6(1)(c), with articles 97.1, 98.7 and 103.m TRLGDCU. It protects you as much as it protects the shop: it is the proof of what you were told.
  • Sending you emails you asked for — your consent, article 6(1)(a), with article 21 of Ley 34/2002 (“LSSI”). Withdrawable at any time, from any email or by writing. Withdrawing does not affect what was lawful before.
  • Publishing your review beside the product — your consent, article 6(1)(a). Ask, and it comes down.
  • Cookies and similar technologies that are not strictly necessary — your consent, article 22.2 LSSI. Refusable, and changeable later.
  • Keeping the site up, safe and fast — server logs, abuse and fraud prevention: legitimate interest, article 6(1)(f). You can object, and section 8 says how.
  • Keeping a record of an unsubscribe so that it is actually honoured — legitimate interest, article 6(1)(f). The only reason any trace is kept after you leave is to make sure you are not contacted again.
  • Bringing or defending a legal claim — legitimate interest, article 6(1)(f), and article 17(3)(e) GDPR. Only for as long as the claim is live.

Nothing here is sold. Personal data from this shop is not sold, rented or traded, and is not shared for anyone else’s advertising.

5. Who else sees your data

Everyone below acts on the owner’s instructions, under the contract article 28 GDPR requires, unless it says otherwise.

  • Card payments and tax calculation — Stripe. Stripe Payments Europe, Limited (Ireland), with Stripe, LLC (Delaware, United States). It processes your payment on the owner’s instructions, and acts as a controller in its own right for fraud prevention and its own legal duties.
  • PayPal payments. PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg. The same split as Stripe.
  • Web hosting. DigitalOcean, LLC (United States), through Cloudways. It runs this website and its database.
  • Network security and delivery — Cloudflare. Cloudflare, Inc. (United States). It sits in front of this website: it terminates the encrypted connection and sees the IP address of every visitor.
  • Email platform — Encharge. PXCH Holding I, LLC, a United States company, with the application data hosted in Ireland. It sends the emails you subscribed to and holds the record of that consent. Please read section 6 about this one, which says something you are entitled to know.
  • Video platform — Vadoo. Vadoo Internet Services Private Limited, India. It hosts and delivers course video. Section 6 applies to this one too.
  • If you sign in with Facebook or Google. Choosing “Continue with Facebook” or “Continue with Google” tells that provider — Meta Platforms Ireland Limited or Google Ireland Limited — that you signed in here, and sends your name and email address back. They act as controllers in their own right for what they then do with it, under their own privacy policies. You never have to use them: an ordinary email and password works, and so does buying with no account at all.
  • Analytics and Pinterest. Google Tag Manager (Google Ireland Limited) and Pinterest for WooCommerce (Pinterest Europe Ltd., Dublin). These are governed by the cookie banner: the Cookie Policy lists what each one stores, and you can refuse them from the banner, or later from the cookie settings link in the footer.
  • The cookie banner. Run by software installed on this website itself. Your consent record is stored in this site’s own database and does not leave it, so no third party is involved in that step.

Beyond that, your data is disclosed only where the law requires it — to a court, a public authority or the tax administration — and to the owner’s accountant, bound by professional secrecy, for the invoices.

If the business is ever sold or merged, personal data may pass to the buyer as part of that transaction, and only so far as the law allows. You would be told before it happened, not after.

6. Where your data goes

Some of those providers process data outside the European Economic Area. Where that happens, the transfer has to rest on a safeguard from Chapter V GDPR — and this is which one, provider by provider, rather than the useless “one of the mechanisms provided for by law”.

  • Stripe — Ireland to the United States, under the EU-US Data Privacy Framework, with Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) as a fallback.
  • PayPal — Luxembourg, under Binding Corporate Rules approved by the competent supervisory authorities. Not the Data Privacy Framework: PayPal does not claim it, and this page does not claim it for them.
  • Web hosting — DigitalOcean, LLC is established in the United States, under the EU-US Data Privacy Framework, with Standard Contractual Clauses as a fallback.
  • Cloudflare — the United States and Europe, under the EU-US Data Privacy Framework, with Standard Contractual Clauses as a fallback. Cloudflare states both of these itself.
  • Google and Pinterest — from their Irish entities to the United States, under the EU-US Data Privacy Framework, with Standard Contractual Clauses as a fallback.

Two providers where the honest answer is uncomfortable

This page could have listed a safeguard for these two and moved on. It does not, because it would not be true, and a privacy policy that is not true is worth nothing to you.

  • The email platform (Encharge). Its application data is hosted in Ireland, but its contracting entity is a United States company. The only transfer mechanism it names in its public documentation is the EU-US Privacy Shield, which the Court of Justice of the European Union invalidated in July 2020 and which therefore cannot cover anything today. It has been asked, in writing, which mechanism actually applies. This page will be updated with its answer, and if there is no valid answer, the provider will be replaced.
  • The video platform (Vadoo). It states that data is transferred outside Europe, including to India and the United States. India has no adequacy decision from the European Commission, and the provider publishes no data processing agreement, no Standard Contractual Clauses and no sub-processor list. It has been asked in writing, and the same applies: this page will be updated, or the provider will be replaced.

You can ask for a copy of the safeguard that applies to any specific provider by writing to hola@showroomcrochet.com. That is your right under article 13(1)(f) GDPR, not a favour.

7. How long it is kept

  • Invoices and accounting records — six years, under article 30 of the Código de Comercio.
  • Order and tax data — four years from the end of the filing period, which is the limitation period for tax liabilities under article 66 of Ley 58/2003.
  • The download confirmation record — as long as the order it belongs to. It is the evidence for that order, and useless separated from it.
  • Account data — until you close the account, and then deleted, except what the two rules above require to be kept.
  • Subscriber data — until you withdraw your consent, and no longer. Consent that has been withdrawn is not a basis for anything.
  • The record that you unsubscribed — kept, and kept minimal: only what is needed to recognise that you must not be contacted. The alternative is forgetting you left and emailing you again.
  • Reviews — until you ask for removal.
  • Support emails — until the matter is closed, and then for the limitation period of any claim arising from it. The Terms & Conditions set out those periods.
  • Security and consent logs — as set out in the Cookie Policy, and for security logs no longer than is needed to investigate an incident.

8. Your rights

You have all of these, they are free to exercise, and the answer comes within one month (article 12(3) GDPR — extendable by two further months for genuinely complex requests, in which case you are told why within the first month).

  • Access — a copy of the personal data held about you.
  • Rectification — correcting anything wrong or incomplete.
  • Erasure — deletion, except where the law requires the data to be kept. Invoices are the usual example: they cannot be deleted on request, and this page says so plainly rather than promising otherwise.
  • Restriction — freezing the use of your data while something is contested.
  • Portability — receiving the data you provided, in a structured, commonly used, machine-readable format, or having it sent straight to another controller where that is technically feasible.
  • Objection — to anything based on legitimate interest. The processing then stops unless there are compelling legitimate grounds that override your interests. For marketing there is no such exception: it stops, full stop.
  • Withdrawing consent — at any time, as easily as it was given, without affecting the lawfulness of what came before.
  • Not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. No such decisions are made here — see section 11.

How to use them: write to hola@showroomcrochet.com and say which one. Your identity is checked only where there is real doubt, and only with what is strictly needed — you will not be asked for a copy of your ID as a matter of routine.

If you are not satisfied, you can complain to the Spanish supervisory authority, the Agencia Española de Protección de Datos — C/ Jorge Juan 6, 28001 Madrid, www.aepd.es — or to the supervisory authority of the country where you live or work. You do not have to complain here first, although it is usually faster.

9. Security

Rather than claim in general terms that the measures taken are appropriate, here is what is specifically true:

  • Your card details never reach this shop. They are entered directly with the payment provider.
  • Passwords are stored hashed, not as text. Nobody here can read yours — which is why a forgotten password is reset and never sent back to you.
  • The whole site is served over an encrypted connection, terminated by the security network in front of it.
  • Access to the administration of this site is limited to the owner and the people who work on it.

If there is ever a personal data breach likely to result in a risk to you, the Agencia Española de Protección de Datos is notified within 72 hours (article 33 GDPR); and where the risk to you is high, you are told directly and without undue delay (article 34).

10. Cookies

What is stored on your device, by whom and for how long is set out in the Cookie Policy, which forms part of this one. You can change your mind at any time from the cookie settings link in the footer.

11. Marketing, profiling and automated decisions

If you subscribe, the emails you receive may be influenced by what you have opened or clicked before. That is how the email platform works, and it is profiling within the meaning of article 4(4) GDPR. It is used to send fewer and more relevant emails — never to set a different price for you, and never to decide anything about your order.

No decision producing legal effects, or similarly significant effects, is taken about you by automated means alone (article 22 GDPR). Prices are the same for everyone, as the Terms & Conditions also say.

You can stop the profiling and keep the emails, or stop both. Write and say which.

12. Children

This shop is not directed at children. Under article 7 LOPDGDD a minor in Spain may consent to the processing of their own data from the age of 14; below that, a parent or guardian must consent. Nothing here is designed for or aimed at anyone under 14, and no data is knowingly collected from them. If you believe a child has provided data, write to hola@showroomcrochet.com and it will be deleted.

13. If you are in the United States

This shop is established in Spain and applies the GDPR to everyone, wherever you live. The rights in section 8 are offered to all customers, not only to those in Europe, and they go further than most United States state laws require.

The California Consumer Privacy Act does not apply to this business, which meets none of its thresholds: annual revenue far below the statutory floor, well under 100,000 consumers, and no revenue at all from selling or sharing personal information. Personal data from this shop is never sold, and never shared for cross-context behavioural advertising, so there is nothing to opt out of — but the rights in section 8 are yours regardless.

14. Changes to this policy

This policy may be amended to reflect changes in the law, in the providers used, or in how the shop works. The version in force is the one published on this page, with its update date. If a change materially affects how your data is used, you will be told before it takes effect, by email where the shop has your address.

15. Contact

For anything at all relating to your personal data — a question, a request or a complaint: hola@showroomcrochet.com, or by post to the address in section 1. It is read and answered by the owner.

Item added to cart.
0 items - €0.00
ShowroomCrochet EN