Legal
Privacy Policy
As of launch, this Policy replaces the pre-launch privacy notice. The providers' DPF certifications (Vercel, Stripe, Cloudinary) were verified as active on dataprivacyframework.gov as of 02/07/2026; the blocking horizon for contractual liability is set at 10 years (Article 121-20 of the Código Civil de Cataluña).
Version: 1.1 · 13/07/2026
1. Data controller
NEGOCIS DIGITALS CANGERARD, S.L., NIF B88966775, Carrer de la Serra 46, 1-3, 08520 Les Franqueses del Vallès (Barcelona), Spain. Privacy contact: gerard@cangerard.cat. No Data Protection Officer has been appointed; the decision is documented and will be reviewed if the volume or nature of the processing so requires.
2. What data we process
If you visit the Site without registering: only the technical data strictly necessary to display the website to you securely. Our analytics (Vercel Analytics) does not use cookies and does not identify you: it works with aggregated metrics. See the Cookie Policy. If you register as a buyer: first name and surname(s), email address, password (encrypted), date of birth (to verify that you are over 18), shipping addresses with a contact telephone number — mandatory on the delivery address, because the carrier needs it to coordinate the delivery and its notifications —, order and return history, favourite products, reviews you post and communications with customer service. If you request a full invoice, your tax details (NIF and tax address). Payment data: handled directly by our payment provider, Stripe. CanGerard does not store your full card number; we receive only technical payment references (status, last digits, transaction identifiers). If you sign up as a seller: identification and contact details of the company or sole trader and of its contact persons, NIF, address, tax and invoicing details, declared sector registrations (e.g. health registry), verification and seal documentation, details of the connected Stripe account and activity on the platform. If you pre-registered before launch: the data covered by the pre-launch notice, which is merged into your account if you create one. Third-party data that you provide to us: if you give the delivery address of another person (e.g. a gift), you warrant that you have informed them of this Policy; we will use their data only to deliver that order. We do not deliberately process special categories of data or data of persons under 18 (Section 8).
3. Why we process your data and on what legal basis
Purposes and their legal basis (Article 6(1) GDPR): • Managing your registration, your account and your purchases, communicating your delivery details to the seller of each order and to the logistics provider and carrier performing the delivery (including your phone and email, to coordinate the delivery and its notifications), and sending you emails about the status of your orders: b) Performance of the contract. • Verifying that you are of legal age at registration and when purchasing “18+” products (alcohol, knives): c) Legal obligation, supported by f) legitimate interest in preventing sales to minors. • Issuing and retaining invoices (also on behalf of sellers) and complying with tax and commercial obligations: c) Legal obligation. • Verifying and managing sellers, their seals and the per-category requirements; handling notices of illegal content, moderation and product safety: c) Legal obligation (platform, consumer and product-safety legislation) and b) contract. • Preventing fraud and ensuring the security of the Site and of accounts: f) Legitimate interest. • Handling enquiries, complaints, returns and guarantees: b) Contract and c) legal obligation (consumer legislation). • Publishing your reviews of purchased products: b) Contract (a feature you activate when you post). • Sending you, if you agreed to it, communications about the launch and news from CanGerard: a) Consent (revocable in every email). • Producing aggregated usage statistics, without identifying you: f) Legitimate interest. • Responding to requests from authorities and defending against claims: c) Legal obligation and f) legitimate interest. We will not send you commercial communications without your prior consent, and you may withdraw it at any time via the unsubscribe link in every email.
4. Who we share your data with
With the sellers you buy from. So that they can prepare and deliver your order, we communicate to them only your name, the delivery address and your contact telephone number. Each seller acts as an independent controller of that processing and is contractually prohibited from using your data for its own marketing or from disclosing it to third parties other than its carriers. With service providers that help us operate (processors or equivalent): • Vercel, Inc. — application hosting and cookie-less analytics. • Supabase, Inc. — database, hosted in Frankfurt (Germany). • Resend, Inc. — sending of transactional emails. • SendCloud B.V. (the Netherlands) — label generation and shipment management for the shipping options contracted by the Platform. We communicate to it the recipient's name, delivery address, telephone number and email address, and the contact details of the seller dispatching the parcel, to generate the label, coordinate collection and delivery and issue tracking notifications; the carriers performing the delivery process your data as controllers of their own postal or transport service. • Cloudinary, Inc. — storage of the catalogue images and of the invoicing PDF documents in private folders, accessible only via signed links of limited validity. • Holded Technologies, S.L. (Barcelona, Spain) — the Platform's invoicing and accounting software: issuing the Platform's own invoices (seller commission and shipping service) and, if you request a full invoice, registering your tax contact so that it can be issued. With Stripe (Stripe Payments Europe, Ltd. and Stripe, Inc.) — payment processing, fraud prevention and compliance with its financial regulations, partly as an independent controller of those regulated processing operations. More information in Stripe's privacy policy. With public administrations and authorities (tax, consumer, judicial, digital services coordinator) where required by law. We do not sell your data or disclose it to third parties for advertising.
5. International transfers
Your data is hosted in the European Union (database in Frankfurt; application functions executed in an EU region). However, some of our providers are US companies or belong to groups headquartered in the US, so access or processing may take place from that country. Safeguards applied, provider by provider: • Vercel, Inc.: certified under the EU-U.S. Data Privacy Framework (European Commission adequacy decision). • Stripe, Inc.: certified under the EU-U.S. Data Privacy Framework; its transfer addendum also incorporates standard contractual clauses as a fallback mechanism. • Supabase, Inc.: European Commission standard contractual clauses incorporated into its data processing agreement, with a transfer impact assessment. • Resend, Inc.: standard contractual clauses (controller-to-processor module) incorporated into its data processing agreement. • Cloudinary, Inc.: certified under the EU-U.S. Data Privacy Framework (European Commission adequacy decision). Holded Technologies, S.L. is a Spanish company: no international transfer is involved. You may request additional information or a copy of the safeguards at gerard@cangerard.cat.
6. How long we keep your data
• Buyer or seller account: for as long as it remains active. If you delete it (or we delete it), your data is erased subject to blocking (Article 32 LOPDGDD): it is no longer used and remains available exclusively to judges, courts and public administrations for the applicable limitation periods, after which it is destroyed. • Orders, invoices and accounting documentation: blocked for the tax and commercial retention periods (as a general rule, 4 years for tax purposes and 6 years for the retention of commercial documentation) and for as long as contractual liability may arise — 10 years, the limitation period for contractual claims under Article 121-20 of the Código Civil de Cataluña, applied as the more protective standard. • Consent for communications: until you withdraw it; we keep the minimum evidence of your opt-out so as not to contact you again. • Support and complaints: while they are being handled and for the associated limitation periods. • Notices of illegal content and moderation decisions: for the applicable limitation periods, for evidentiary and supervisory purposes. • Technical security logs: a maximum of 12 months, unless an incident is under investigation. • Pre-registrations not converted into an account: a maximum of 3 months after launch.
7. Your rights
You may exercise, free of charge, your rights of access, rectification, erasure, objection, restriction of processing and portability, and withdraw your consents, by writing to gerard@cangerard.cat or from your account, proving your identity where reasonable doubt exists. We will respond within a maximum of one month. If you consider that we have not properly handled your rights, you may lodge a complaint with the Agencia Española de Protección de Datos (www.aepd.es). If your request concerns processing that a seller carries out as an independent controller (e.g. its shipping records), we will forward it to the seller and inform you accordingly.
8. Minors
The Site is reserved for persons aged 18 or over. We do not allow minors to register and do not knowingly process their data; if we detect an account belonging to a minor, we will delete it. If you are a parent or guardian and believe that a minor has provided us with data, please contact us.
9. Automated decisions and profiling
We do not make automated decisions that produce legal effects concerning you, nor do we build personalised profiles: the “related products” carousels depend on the product you are viewing, not on your history. The payment provider's anti-fraud system may automatically analyse transactions in order to authorise or decline them for security reasons; if a payment is declined, you can contact us or try another payment method.
10. Security
We apply technical and organisational measures appropriate to the risk: encryption of communications, hashed passwords, role-based access control, separation of environments, backups, activity logging and providers with recognised security certifications. We have an internal security-breach management procedure which includes, where applicable, notification to the AEPD within 72 hours and communication to the affected individuals.
11. Reviews and public content
Reviews you post will be publicly visible together with your name or the alias you set in your account. Bear in mind that you must not include personal data about yourself or third parties in them; we may remove any that we detect.
12. Changes to this Policy
We will publish any update here and, if the changes are substantial, we will notify you by email or on your next sign-in. The version date appears in the header.