Privacy Policy
Last Updated:
Data collection and retention
Types of data collected
Complete details on each type of personal data collected are provided in the dedicated sections of this privacy policy or by specific explanation texts displayed prior to the data collection.
Personal data encompassing usage data is collected automatically during the client's usage of the website. Personal data may also be freely provided by the user.
Unless explicitly stated, all data requested by this website must be provided. Failure to provide requested data may result in denial or inability to deliver services.
Users may refuse to transmit data that this website marks as not mandatory without any consequences to service availability and functionality.
If uncertain about whether a given set of personal data must be transmitted users may contact the owner.
Any use of cookies - or of other tracking tools - by this website or by the operators of third-party services employed by this website is done with the intent of providing the user the current service, in addition to any other purposes described in the present document.
Users are responsible for any third-party personal data obtained, published or shared through this website and confirm that they have the third party's consent to provide the data to the owner.
Methods, Location and Internal Authorisation of Data Processing
We take appropriate measures to keep personal data from being accessed, disclosed, altered or destroyed without authorisation: the site runs over HTTPS throughout, card details never reach us, the database is not publicly reachable, and the admin area is behind a password. One exception is worth naming rather than burying, because a blanket assurance would not be true of it — the photographs uploaded for a rug appraisal, which are described below.
All data processing is carried out using computers and IT infrastructure following strict organizational procedures.
We are a small company, and the honest description is that your data is seen by the people who need it to fulfil your order: the owner, the shop staff who prepare and hand over goods, and the carrier delivering to you. Beyond that, it is handled by the service providers we rely on to run the shop — our host, our database, our payment processor and our email sender.
Those providers are named individually further down this policy, under “Who else handles your data”, rather than left to a list you would have to request.
Legal basis of processing
The owner may process personal data relating to users if one of the following applies:
- The user has given their consent after being informed of the manner and purposes of data collection and treatment.
- The provision of data is necessary for the performance of an agreement with the user or for any pre-contractual obligations between the company and user.
- Data processing is statutorily enforced within the jurisdiction the company operates in.
- Data processing is carried out in the interest of the public and/or at the command of an official regulatory body.
- Data processing is a necessity for the commercial interests of the owner and/or an auxiliary third party.
In any case, the owner will gladly help to elucidate the specific legal basis that applies to the processing of data, and in particular whether the provision of personal data is a statutory and/or contractual requirement.
Jurisdictional / Border Laws
The data is strictly internally processed in situ, in our operating offices. Externally, it may be handled by third parties at legally recognised operational sites.
Contingent upon the user's location, data may have to be transferred across national borders. To find out more about the transnational processing of data, users are referred to the section on personal data processing.
Users are encouraged to inform themselves on the legal basis of data transfers to countries outside of the European Union. We also encourage users to inform themselves about international law within the context of E.U intra-border data regulation, namely the G.D.P.R.
Users may procure information about how their data is safeguarded by the company by reading the relevant sections of this document.
Inquiring with the owner via the information provided in the contact section is recommended if anything is unclear.
Data retention periods
Personal data that has been processed may be stored as long as is legally allowed. Exact data retention time varies contingent upon the purpose the data has been collected for.
In practice, the biggest single factor is Spanish accounting and tax law. Once you place an order, the record of that sale — who bought what, for how much, and where it was sent — becomes part of our books, and we are required to keep it: four years for tax purposes and six under the Commercial Code. We cannot delete it before then even if you ask us to, and it would be misleading to promise otherwise. We keep it for that period, we do not use it for anything else in the meantime, and we remove or anonymise it once it is no longer needed.
The following rights - right to access, right to erasure, right to rectification and the right to data portability - become technically unenforceable after expiration of the data retention period. This limitation arises from the factual absence of the data and not from the expiration of rights themselves. The data subject may - post facto - request to be informed about the nature of the data that was retained.
Data may be retained past the expiration date of a contract provided the customer's informed consent has been given.
If legally obliged by a relevant overseeing authority, the owner may retain certain data past the expiration point of a contract without having to inform the subject of said data.
Users that wish to find out about the legitimate commercial interests pursued by the owner in relation to their data may do so by consulting the relevant sections of this document or directly contacting the owner.
Online withdrawal function (contract withdrawals)
When you use the online withdrawal function on our returns policy page to withdraw from a purchase contract, we process the data you enter there — your name, your order number and your email address — together with the date and time your declaration reached us. We use this data exclusively to receive your withdrawal declaration, to send you the legally required acknowledgement of receipt by email, and to process the withdrawal itself (arranging the return and the reimbursement).
The legal basis for this processing is Art. 6(1)(c) GDPR — compliance with a legal obligation to which we are subject, namely the obligation to provide an online withdrawal function and to acknowledge its use under Article 11a of Directive 2011/83/EU (as inserted by Directive (EU) 2023/2673) and its national implementations.
Withdrawal declarations are stored together with the order they relate to and are retained for as long as the processing of the withdrawal requires and, thereafter, for as long as statutory limitation periods and commercial and tax record-keeping obligations demand (in Spain, generally up to six years).
The rights of users
Users may exercise certain rights regarding their processed data.
- Withdrawal of Consent - Users may rescind consent to data processing and retention where it has been previously granted.
- Objection to Data Processing - Users have the right to object to the processing of their data if they suspect the processing is carried out on a legal basis other than consent. Further details are provided in the dedicated section below.
- Data Access and Inquiry into the Processing Procedure - Users have the right to learn if data is being processed by the owner, alongside the scope and methodology of said processing. Users may also procure a copy of their data that is being processed.
- Accuracy Verification and Rectification - Users have the right to verify the accuracy of their data and request it to be updated or corrected.
- Restrict Data Processing - Users have the right, under certain circumstances, to restrict the processing of their data. In this case, the owner will not process their data for any purpose, resorting to only storing it.
- Receive their Data and Transfer it to another Controller - Users have the right to receive their data in a structured, commonly used and machine readable format and, if technically feasible, to have it transmitted to another controller without any hindrance. This provision is applicable provided that the data is processed by automated means and that the processing is based on the user's consent, on a contract which the user is part of or on pre-contractual obligations thereof.
- Legal Complaints - Users have the right to file a claim before their competent data protection authority.
Details about the right to object to processing
Users should be aware that their personal data may be accessed by a relevant authority, which may subpoena or otherwise compel the data controller to disclose it. Users retain the right to object to such disclosure by providing reasonable grounds related to their particular situation.
Users should also know that should their personal data be processed for direct marketing purposes, they can object to its processing at any time without having to provide a justification.
To learn whether the owner is processing personal data for direct marketing purposes, users may refer to the relevant sections of this document.
How to exercise these rights
Any requests to exercise user rights can be directed to the owner through the contact details provided in this document. These requests can be exercised free of charge and will be addressed by the owner as early as possible and always within one month.
Legal action
The user's personal data may be used for legal purposes by the owner in court or in stages potentially leading up to legal action arising from improper use of this website or its related services. The user is hereby informed that the owner may be required to reveal personal data upon request of public authorities.
Additional information about user's personal data
In addition to the information contained in this privacy policy, this website may provide the user with additional and contextual information concerning particular services or the collection and processing of personal data upon request.
System logs and maintenance
To keep the site running and to investigate faults, our host records ordinary server logs of the requests it serves, and these can include IP addresses. We also record our own crash reports when a page fails in your browser: those keep the error message, the page path, the language and a shortened browser description, and deliberately keep no IP address, no cookies and no query strings. Individual crash records are deleted after thirty days; only the anonymous count of how often each fault occurred is kept beyond that.
Information not contained in this policy
More details concerning the collection or processing of personal data may be requested from the owner at any time. Please consult the contact information at the end of this document.
How Do Not Track
requests are handled
This website does not act on Do Not Track
or Global Privacy Control signals, and we would rather tell you that than let you assume otherwise. The reason is that there is nothing here for such a signal to switch off: we set no advertising cookies and no cross-site identifiers, and our page-view counting stores nothing in your browser, so a Do Not Track
request would have nothing to disable. The one third party that does store something is Stripe, at checkout, and how Stripe treats these signals is governed by its own policy.
Changes to this Privacy Policy
The owner reserves the right to make amendments to this privacy policy at any time by notifying its users via this page, the website itself, or – as far as technically and legally feasible – via sending a notice to users through any contact information recorded by the owner.
It is strongly recommended to check this page often, referring to the date of the last modification listed at the top of the document.
Should the changes affect processing activities performed on the basis of the user's consent, the owner shall collect new consent from the user, where required.
Marketing email, and why you will not get any
We do not run a newsletter, we do not operate customer accounts, and there is no mailing list to be added to. Placing an order does not sign you up for anything. The only email we send you is about the transaction you actually started: an order confirmation, a shipping or status update, a withdrawal acknowledgement, or a reply to a message you sent us.
If we ever decide to send commercial email, we will ask you to opt in first, and it will be a box you tick rather than one you find already ticked. Until then, an email from us always refers to something you did.
When you write to us
The contact form sends us your name, your email address, the subject you picked, your message, and your company name if you fill that field in. It is delivered to our own mailbox by email and is not written to any database — so the copy that exists is the message sitting in our inbox, which we keep so that we can answer you and look back at what was agreed. Nothing about it is added to a mailing list, because we do not have one.
We handle it on the basis of our legitimate interest in answering people who contact us, and, where your message is about an order, in performing that contract. If you would like the message deleted once we have dealt with it, say so and we will delete it.
Photographs you send for a rug appraisal
If you order an appraisal, you upload photographs of the rug — and, if you have it, of the purchase receipt. Those are the most revealing things this site ever asks for: a photograph of a rug is usually a photograph of a room in your home, and a receipt normally carries a name, an address, a date and a price. We would rather set out exactly how they are handled than leave you to assume.
They are uploaded to our file store under a long, randomly-suffixed folder name and are reachable by that address alone. The address is not published anywhere and is not guessable in practice, but it is not password-protected either: anyone you forwarded it to could open it. The only places it appears are the notification email that reaches us and the order in our own admin area.
If you abandon or cancel the checkout, the photographs are deleted straight away. If the appraisal goes ahead, they are deleted automatically 90 days after upload — long past the 24 to 48 hours the appraisal itself takes, and far enough out to cover any question or payment dispute that follows. You can ask us to delete them sooner and we will.
Hosting and analytics
This website is built and hosted on Vercel, and its servers run in the European Union (Frankfurt). Every page you load, every image, every typeface and every form you submit is served by Vercel on our behalf, so Vercel processes the technical details of your request — including your IP address — in order to deliver the page to you.
Vercel also provides the only analytics on this site, Vercel Web Analytics, which counts page views without cookies and without building an identifier for you. Vercel derives approximate details from the request itself — country, browser and device type — and does not associate the measurements with your IP address. You can read Vercel's privacy policy for their side of the arrangement.
Cloudflare provides our domain's DNS, and nothing more. Our records are deliberately left unproxied, which means Cloudflare answers the question "where does yourcarpet.com live?" and then steps out of the way: your connection goes directly to Vercel, Cloudflare never sees the pages you request, never inspects or stores your traffic, and sets no cookie on this site. An earlier version of this policy described Cloudflare as filtering all of our traffic and collecting analytics. That was never accurate, and we have corrected it.
Who else handles your data
Rather than tell you the list is available on request, here it is. These are the companies that may process personal data on our behalf, and the only reason each one exists:
- Vercel — hosting, page delivery and our page-view analytics. Servers in the EU (Frankfurt).
- Supabase — the database holding products, orders and customer records.
- Stripe — payment processing and fraud prevention. Stripe receives your payment and billing details directly and is a data controller in its own right for that.
- Google — receives your IP address and the referring page if, and only if, you open one of our store maps. Google also stores our product photographs, listed separately below.
- hCaptcha (Intuition Machines) — a bot check that Stripe may load inside its own payment frame. We do not install it and cannot switch it off from here.
- Apple and Google — only if you pay with Apple Pay or Google Pay. The wallet handles the card and returns the payment and address details it holds for you.
- Resend — sending transactional email such as order confirmations. Delivery runs through Amazon SES in the EU (Ireland).
- Namecheap PrivateEmail — our own mailboxes, so any message you email us is stored there.
- Google Firebase Storage — stores our product photographs. Our own server fetches them and passes them to you, so it does not receive your IP address while you browse.
- Vercel Blob — stores the files you upload, such as the photographs submitted with a rug appraisal. This store is located in the United States (Washington, D.C.).
- Upstash — a short-lived counter store used for rate limiting and internal alerts. IP addresses reach it only as a one-way hash that expires within minutes.
- Cloudflare — DNS resolution only, as described above. It handles no visitor traffic.
- Telegram — sends a notification to the owner's phone when an order is paid. That message contains the order number and the buyer's name.
- OpenStreetMap (Nominatim and OSRM) — used only in the cleaning-service booking, to turn the collection address you type into a distance so the transport fee can be calculated.
- CartoCiudad and Photon — the address suggestions offered while you type an address. Requests pass through our own server, and only the fragment you have typed is sent.
Each of these is used only for the purpose listed. Several are US-headquartered companies. The database and the servers that render this site are in the European Union (Frankfurt), and our transactional email is sent from within the EU (Ireland); the file store that holds uploaded photographs is in the United States (Washington, D.C.), so those files do leave the European Economic Area. Where personal data travels outside the Area we rely on the data-protection terms that provider publishes — for the main ones, the European Commission's Standard Contractual Clauses. If you want to know exactly what one of them holds about you, or which safeguard covers a particular transfer, ask us and we will tell you rather than send you away with a form.
Usage data
Some information arrives automatically simply because your browser has to ask our server for a page. Our host records the usual technical details of that request — the IP address it came from, the time, the address requested, the response status, and the browser and operating system reported by your browser — in its own server logs. We do not build profiles from these logs; they exist so that faults can be diagnosed and abuse can be stopped, and we read them only for that.
Separately, our page-view analytics records the address of the page, the time, and the address of the site that referred you, if any. It sets no cookie, stores nothing in your browser and creates no identifier. It does not measure how long you spend on a page, does not record mouse movement, and cannot follow you to another website. Identifying details are stripped from the page address before it is sent, so the confirmation link for an order never reaches our analytics.
User
The individual using this website who, unless otherwise specified, coincides with the data subject.
Data subject
The natural person to whom the personal data refers.
Data processor (or data supervisor)
The natural or legal person, public authority, agency or other body which processes personal data on behalf of the Controller, as described in this privacy policy.
Data controller (or owner)
The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data, including the security measures concerning the operation and use of this website. The data controller, unless otherwise specified, is the owner of this website.
Data application
The means by which the personal data of the user is collected and processed on the YourCarpet.com domain.
Service
Any service provided to the user upon accessing the YourCarpet.com domain.
European Union (or EU)
Unless otherwise specified, all references made within this document to the European Union include all current member states to the European Union and the European Economic Area.
Legal information
This privacy statement has been based on provisions of multiple legislations, including Article 5, Article 6, Article 13 and Article 14 of Regulation of the (EU) 2016/679 (General Data Protection Regulation). If you would like to look up any section of the GDPR you may do so on the GDPR.eu website.
Contact Us
- Trading Name
- YourCarpet.com / Magic Carpets
- Legal Entity
- The Magic Carpets Company S.L.
- Business Registration Number
- B04941183
- VAT Number
- ESB04941183
- Registered / Trading Address
- Av. Luis Braille 18, 29670 Marbella, Málaga, Spain
- info@yourcarpet.com
- Phone
- +34 644 529 368
- Support Hours
- Mon–Fri 10:00–20:00, Sat 10:30–15:00, Sun closed (CET/CEST, Madrid time)
- Response Time
- Within 1 business day
- Website
- yourcarpet.com