Privacy Policy

Privacy Policy

Last updated: 15/04/2026

This Privacy Policy explains how Dreamy Store (dreamystore.eu) collects, uses, and protects the personal data of visitors and customers. We are committed to handling your data in accordance with the EU General Data Protection Regulation (GDPR) and Spanish data protection law (LOPDGDD).

1. Who We Are

Dreamy Store is an independent online shop selling handmade and K-pop merchandise, operated as an unregistered sole trader based in Valencia, Spain. For any privacy-related questions, contact us at: [email protected]

2. What Data We Collect

We collect personal data only when it is necessary to process your order or improve your experience on our website. This includes:

  • Name and surname
  • Shipping address
  • Email address
  • Phone number (if provided)
  • Payment information (processed securely by Stripe — we do not store card details)
  • IP address and browsing data (collected anonymously via Google Analytics)

3. Why We Collect It (Legal Basis)

  • Order fulfilment: We process your name, address, and contact details to ship your order and manage customer communication. Legal basis: contract performance (Art. 6.1.b GDPR).
  • Legal obligations: We may retain certain order records as required by Spanish tax law. Legal basis: legal obligation (Art. 6.1.c GDPR).
  • Analytics: We use Google Analytics to understand how visitors use our site. Data is collected anonymously. Legal basis: legitimate interest (Art. 6.1.f GDPR) and, where required, your consent.

4. How We Share Your Data

We do not sell your personal data. We share it only with the following third parties, strictly for operational purposes:

  • Stripe – payment processing (stripe.com/privacy)
  • Shipping carriers – to deliver your order (name and address only)
  • Google Analytics – website analytics, data anonymised (policies.google.com/privacy)
  • WooCommerce / WordPress – our shop platform (automattic.com/privacy)

5. Data Retention

We keep your order data for as long as legally required under Spanish law (generally 5 years for commercial records, 4 years for tax records). Analytics data is retained for 14 months by default in Google Analytics. You may request deletion of your personal data at any time, subject to legal retention obligations.

6. Your Rights Under GDPR

As an EU resident, you have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data (right to be forgotten)
  • Object to or restrict processing
  • Withdraw consent at any time (where processing is based on consent)
  • Lodge a complaint with the Spanish data protection authority (AEPD) at aepd.es

To exercise any of these rights, email us at [email protected]. We will respond within 30 days.

7. Cookies

We use cookies on this website. For full details, please see our Cookie Policy.

8. Data Security

We take reasonable technical and organisational measures to protect your personal data. Payments are processed by Stripe using industry-standard encryption. We do not store payment card details on our servers.

9. Changes to This Policy

We may update this Privacy Policy from time to time. The date at the top of this page will always reflect the latest version. Continued use of the site after any update constitutes acceptance of the revised policy.