Privacy Policy
Privacy Policy
How Eternas Beauty collects, uses, stores and protects your personal information — written in clear English, structured by topic, with all your rights laid out section by section.
1. Who we are
This Privacy Policy describes how KRIEGER GLOBAL SLU ("Eternas Beauty", "we", "us", "our") processes personal information collected through the Eternas Beauty website (eternas.beauty and any associated subdomains) and related services.
C/Pedánea Mariluz Cerezo Teruel 12, 30107 Guadalupe, Murcia, Spain
Email: support@eternas.beauty.com
For the purposes of the European General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), the Brazilian Lei Geral de Proteção de Dados (LGPD), and other applicable privacy frameworks, KRIEGER GLOBAL SLU is the entity that determines the purposes and means of processing your personal data.
2. What information we collect
We only collect data we genuinely need. Categories of personal information we may process include:
| Category | Examples | Source |
|---|---|---|
| Identity data | First name, last name, country | Provided by you at checkout / account creation |
| Contact data | Email, phone number, shipping & billing address | Provided by you |
| Order data | Order number, items, amount, currency, payment method | Generated when you place an order |
| Payment data | Last 4 digits of card, card brand, transaction reference | Provided by payment processor — we do not store full card details |
| Technical data | IP address, browser, device, OS, language, timezone | Automatically collected when you visit the site |
| Usage data | Pages visited, time on site, products viewed, search terms | Cookies & analytics |
| Marketing data | Preferences, email subscription status, ad interactions | Provided by you, plus cookies if consented |
| Communication data | Customer support messages, returns claims, reviews | Provided by you |
What we do not collect
- We do not collect biometric data.
- We do not collect health, medical, religious or political data.
- We do not store full credit card details — they are handled exclusively by our PCI-DSS compliant payment processors (Shopify Payments, Stripe, PayPal).
- We do not knowingly collect data from minors under 18 (see section 12).
3. How we collect your information
We collect personal data through three channels:
- Directly from you: when you place an order, create an account, subscribe to our newsletter, submit a contact form, leave a product review, request a return, or contact customer support.
- Automatically: when you browse our website, through cookies, server logs and similar technologies.
- From third parties: from payment processors, shipping carriers, fraud-prevention services, advertising platforms (with consent), and trustworthy review platforms.
4. Why we use your information
Every category of data above has a clear purpose. We do not "collect for the sake of it".
Fulfilling your orders
Processing payment, preparing shipment, generating invoices, sending shipping notifications, providing tracking, handling returns and refunds.
Customer support
Answering your questions, resolving order issues, processing warranty claims, managing complaints.
Account management
Creating and maintaining your customer account, allowing you to view order history and saved addresses.
Communications
Transactional emails (order confirmation, shipping, returns) and — only with your consent — marketing emails about new products, restocks and offers.
Site improvement
Understanding which products and pages perform well, fixing bugs, improving load speed and checkout flow.
Marketing & advertising
Only with your consent, we use marketing data to show relevant ads on platforms like Meta and Google.
Fraud prevention
Detecting and preventing fraudulent orders, chargebacks, account takeovers and abuse of refund policies.
Legal compliance
Complying with tax, accounting, consumer protection and other legal obligations.
5. Legal basis for processing
Under GDPR and equivalent regulations, every purpose above must rely on a valid legal basis. Here are ours:
- Contract performance: processing necessary to fulfill our purchase contract with you (order, shipping, returns, warranty).
- Legal obligation: compliance with tax, accounting, consumer protection and product safety regulations.
- Legitimate interest: fraud prevention, site security, basic analytics, improving our products and services. We only invoke this basis when our interest is balanced against your rights.
- Consent: marketing emails, non-essential cookies, advertising tracking. You can withdraw consent at any time.
6. Who we share your data with
We share your personal data only with carefully selected service providers ("processors") who help us deliver our service. We never sell your data.
| Recipient category | Purpose | Examples |
|---|---|---|
| E-commerce platform | Hosting, order management, checkout | Shopify Inc. |
| Payment processors | Card processing, fraud screening | Shopify Payments, Stripe, PayPal |
| Shipping carriers | Delivering your orders | USPS, DHL, Royal Mail, Correos Express, AU Post, Aramex, etc. |
| Email service providers | Sending transactional & marketing emails | Shopify Email, Klaviyo |
| Analytics | Site performance and behavior analysis | Google Analytics 4, Shopify Analytics |
| Advertising platforms | Targeted ads (with consent) | Meta (Facebook, Instagram), Google Ads, TikTok |
| Customer support tools | Ticket management, live chat | Shopify Inbox |
| Review platforms | Collecting and displaying product reviews | Judge.me |
| Tracking apps | Order tracking visibility | Track123 |
| Tax authorities | Legal compliance | Spanish Tax Agency, EU OSS portal |
All processors operate under data processing agreements (DPAs) that bind them to use your data only for the contracted purpose, apply appropriate security measures, and assist us in honoring your rights.
7. International data transfers
Some of our service providers are based outside the European Economic Area, including the United States and Canada. When we transfer personal data internationally, we ensure adequate safeguards through:
- EU Standard Contractual Clauses (SCCs) approved by the European Commission;
- Adequacy decisions where applicable (e.g. UK, Canada, Switzerland);
- EU-US Data Privacy Framework certification, where the receiving party is certified.
You can request a copy of the safeguards in place by emailing us.
8. How long we keep your information
| Data category | Retention period |
|---|---|
| Order & invoice data | 10 years (Spanish accounting & tax law) |
| Customer account data | Until account deletion, then archived for 1 year |
| Customer support tickets | 3 years from closure |
| Marketing data & subscription | Until you unsubscribe, then 1 year for audit |
| Analytics data | 14 months (Google Analytics default) |
| Cookies | Per cookie — see section 11 |
| Anti-fraud signals | 3 years from order placement |
At the end of the relevant period, data is either anonymized (so it can no longer identify you) or securely deleted.
9. How we protect your data
We apply industry-standard technical and organizational safeguards:
- Encryption in transit: all communication with our website uses TLS 1.2+ (HTTPS).
- Encryption at rest: sensitive data is encrypted on our processor's infrastructure (AES-256).
- Access control: staff access to personal data is role-based and audit-logged.
- PCI-DSS compliance: payment data flows directly to PCI-DSS Level 1 processors; we never see your full card number.
- Regular audits: our platform partners (Shopify, Stripe, etc.) undergo independent security audits.
- Incident response: in the unlikely event of a data breach, we will notify affected users and the competent authority within 72 hours, as required by GDPR.
10. Your rights
You have substantial control over your personal data. Specifically, you have the right to:
Access
Request a copy of the personal data we hold about you.
Rectification
Correct any inaccurate or incomplete personal data.
Erasure
Request deletion of your personal data (where there is no overriding legal obligation to retain it).
Restriction
Ask us to restrict processing while you contest accuracy or object to processing.
Portability
Receive your personal data in a structured, machine-readable format, or have it transferred to another controller.
Object
Object to processing based on legitimate interest, including profiling and direct marketing.
Withdraw consent
Withdraw consent at any time, without affecting the lawfulness of prior processing.
Complaint
Lodge a complaint with a supervisory authority — for Spain, the AEPD (aepd.es).
How to exercise your rights
Email support@eternas.beauty.com with the subject "Privacy rights request" and tell us which right you wish to exercise. We will respond within 30 days as required by GDPR (extendable by two further months for complex requests, with notice).
For California residents (CCPA), Brazilian residents (LGPD), Canadian residents (PIPEDA, Quebec Law 25), Japanese residents (APPI), South African residents (POPIA), Singapore/Australian/New Zealand residents (PDPA/APA/NZPA), please also see our dedicated regional pages linked in the footer of our website.
11. Cookies & tracking technologies
We use cookies and similar technologies to make our website work, understand how it's used, and (with your consent) personalize your experience.
| Type | Examples | Duration |
|---|---|---|
| Strictly necessary | Cart contents, checkout, login session, security tokens | Session – 1 year |
| Performance / analytics | Google Analytics, Shopify Analytics | 14 months |
| Functional | Language & currency preference, recently viewed | 1 year |
| Marketing | Meta Pixel, Google Ads tag, TikTok Pixel | 3 – 12 months |
On your first visit, our consent banner lets you accept all cookies, reject non-essential cookies, or customize per category. You can change your preferences at any time via the "Cookie settings" link in our website footer, or by deleting cookies in your browser settings.
12. Children's privacy
Our website and products are not directed at children under 18. We do not knowingly collect personal data from anyone under 18. If you become aware that a minor has provided us with personal data without parental consent, please contact us and we will delete the information promptly.
13. Changes to this policy
We review this Privacy Policy at least once a year and whenever we materially change our data practices. The "Last updated" date at the bottom of this page reflects the latest revision. For substantive changes, we will give clear advance notice by email or a banner on the website. Continued use of our services after changes take effect constitutes acceptance.
14. Contact & complaints
Subject line: "Privacy" — for faster routing.
Postal address KRIEGER GLOBAL SLU
C/Pedánea Mariluz Cerezo Teruel 12
30107 Guadalupe, Murcia, Spain
Supervisory authority (Spain) Agencia Española de Protección de Datos (AEPD)
aepd.es
Get in Touch
Have a question or need assistance? We'd love to hear from you.