Data protectionMartín de Prado

Privacy policy

How Martín de Prado uses personal data connected with browsing, accounts, enquiries and online purchases.

Version 1.0 · Effective from 31 August 2026

1. Data controller

The controller is PRISMA, INICIATIVAS GOURMETS EXTREMEÑAS, S.L. —Martín de Prado—, tax identification number B06472062, with registered office at Polígono Industrial Arroyo Caballo, calle 1, 93-95, 10200 Trujillo (Cáceres), Spain.

For privacy enquiries or to exercise your rights, email info@martindeprado.es or write to the postal address above.

2. Data processed and sources

  • Account and identity: first name, surname, email, user identifiers and authentication data managed by Supabase Auth; Martín de Prado does not know your password.
  • Purchase and delivery: contact details, telephone, addresses, optional tax number or company, basket, products, amounts, order, incidents, returns and payment references; full card details are not stored.
  • Customer service: data included in enquiries, requests, complaints or communications by email, telephone or an enabled channel.
  • Technical and security data: IP address and minimum request or event metadata where needed to protect, diagnose and operate the service.
  • Preferences and device: language, opaque guest-basket identifier, authenticated session and temporary storage described in the Cookie policy.

Data comes from you, your browsing and use of the service and, when you choose Google sign-in or make a payment, from the providers involved in that operation.

3. Purposes and legal bases

Purposes and legal bases for processing
PurposeLegal basis
Create and manage an account, authenticate and recover accessSteps taken at your request before entering into a contract or performance of the requested service
Maintain the basket and manage purchase, payment, delivery, returns and after-sales supportPerformance of a contract and pre-contractual steps
Invoicing, accounting, taxation, consumer duties and responses to authoritiesCompliance with legal obligations
Respond to enquiries and complaintsPerformance of a contract or legitimate interest in handling and documenting the request
Prevent abuse, fraud, unauthorised access and failures; retain minimum traceabilityLegitimate interest in protecting the service, the company and its users
Send marketing communications, if enabledSeparate, voluntary and withdrawable consent

Accepting the Terms of purchase or creating an account does not constitute consent to receive advertising.

4. Required data and automated decisions

Fields marked as required are necessary to provide the requested service. Without them, it may not be possible to create an account, answer a request, or complete and deliver an order. Optional fields are identified as such.

Martín de Prado does not make decisions based solely on automated processing that produce legal or similarly significant effects. Stripe, financial institutions or identity providers may apply their own authentication and fraud controls under their respective policies.

5. Recipients and processors

Data is disclosed only where necessary for the stated purpose, required by law or requested by you. The main categories are:

  • Supabase, for database, authentication and storage services.
  • Google, only when you choose to sign in through Google OAuth.
  • Stripe and participating financial institutions, to process and protect payment.
  • Resend, to deliver account and order transactional emails.
  • TIPSA, to deliver and manage order incidents.
  • Hosting, technical support, security and professional advisory providers acting under instructions and confidentiality.
  • Public authorities, courts or regulators where required by law.

6. International transfers

Some technology providers may process data from countries outside the European Economic Area. Where this occurs, Martín de Prado will require a valid basis, such as an adequacy decision, European Commission standard contractual clauses or another safeguard permitted by the GDPR.

You may request additional information or a reference to the applicable safeguards at info@martindeprado.es.

7. Retention

  • Account: while active and afterwards for the period needed to meet obligations or handle claims.
  • Guest or authenticated basket without a purchase: 30 days from its last update.
  • Orders, invoices and business records: for the applicable statutory periods; business documentation is generally retained for six years and tax documentation at least for its limitation periods.
  • Enquiries and complaints: while they are handled and for any resulting liability periods.
  • Technical and security logs: for the time strictly necessary to prevent, detect and resolve incidents and, afterwards, for any period required by a legal obligation or potential liability.
  • Consent-based data: until consent is withdrawn, without affecting the lawfulness of prior processing.

When data is no longer needed, it will be deleted or blocked and restricted to handling liabilities required by law.

8. Your rights

You may request access, rectification, erasure, objection, restriction and portability where applicable, and withdraw consent without retroactive effect. A request must identify you and specify the right concerned; additional information may be requested only where needed to verify identity.

Contact info@martindeprado.es or the controller's postal address. You may also lodge a complaint with the Spanish Data Protection Agency if you believe that processing does not comply with the law.

9. Security and children

Martín de Prado applies technical and organisational measures proportionate to risk, including access controls, encrypted communications, least privilege, limited incident logging and database security policies. No system can remove all risk.

The shop is intended for adults with legal capacity to contract. Personal data is not knowingly collected from children for product sales. If data supplied without a valid basis is detected, appropriate steps will be taken to delete it.

10. Updates and related policies

This policy will be updated when processing, providers or applicable requirements change. Material changes will be communicated proportionately and will never retroactively reduce rights connected with a completed operation.