Privacy Policy
Last updated: September 2026
This site is a small print shop, not an advertising business. We collect what we need to make your print, get it to you and keep our books straight — and nothing beyond that. We do not sell or rent personal data, we do not profile visitors, and we run no advertising or tracking cookies.
1. Who is responsible for your data
The controller of your personal data is:
Sirilak Chaiyarat, trading as founder and owner, the Canary Islands, Spain.
Email: info@palepiece.com · Telephone: +34 620 330 685
NIE nr. X5748564J
For any question about this policy or your data, email info@palepiece.com
2. What we collect, why, and on what legal basis
| Data | Why we have it | Legal basis (GDPR) |
|---|---|---|
| Name, email, delivery and billing address, telephone (if given) | To accept your order, produce your print, deliver it and communicate about it | Performance of the contract, Art. 6(1)(b) |
| Order contents, prices, IGIC or VAT, order number | To fulfil the order and to issue and keep the invoice | Contract, Art. 6(1)(b); legal obligation, Art. 6(1)(c) |
| Payment confirmation, last four digits and card brand, payment method, transaction reference | To confirm payment, handle refunds and chargebacks. We never receive your full card number | Contract, Art. 6(1)(b) |
| Name, email, subject and message from the contact form | To answer your enquiry | Legitimate interest in responding to enquiries, Art. 6(1)(f) — or contract, where the enquiry concerns an order |
| Invoices and order records | Spain tax law requires business records to be kept | Legal obligation, Art. 6(1)(c) |
| IP address, browser and server log data, security events | To keep the site available and to detect and prevent fraud and abuse | Legitimate interest in security, Art. 6(1)(f) |
We do not ask for and do not want any special-category data. Please do not include health, political, religious or similar information in a contact form message.
Providing your name, address and email is necessary to buy from us: without them we cannot make or deliver a print. Providing a telephone number is optional and only helps couriers reach you.
3. Who else processes your data
We use a small number of service providers. Each acts on our instructions under a data processing agreement, except where noted.
| Recipient | Role | What they receive |
|---|---|---|
| PRINTING PARTNER — theprintspace Ltd, United Kingdom, with production facilities in the UK, Germany and the United States | Printing and fulfilment (processor) | Your name, delivery address, telephone if given, and the order details needed to produce and ship the print |
| Stripe (Stripe Payments Europe Ltd, Ireland, with group companies in the United States) | Payment processing. Stripe is an independent controller for payment and fraud-prevention data, under its own privacy policy | Your payment details, billing address, email, amount and transaction data |
| HOSTING PROVIDER | Website and database hosting (processor) | Everything stored on the site, including order records |
| TRANSACTIONAL EMAIL PROVIDER | Sending order, dispatch and contact-form emails (processor) | Your name, email address and the content of those messages |
| ACCOUNTANT / BOOKKEEPER | Bookkeeping and tax filings (processor or joint professional obligation) | Invoice data |
We also disclose data where we are legally required to — for example to a tax authority or in response to a valid legal order.
**We use no analytics provider, no advertising network and no social media tracking pixels.**
4. Transfers outside the European Economic Area
Two transfers are relevant, and both are a consequence of how prints are made:
- If your delivery address is in the United States or Canada, your name and
address are sent to our printing partner’s lab in Brooklyn, New York, so the print can be produced and posted locally. If your address is in the UK, the same applies to their London lab.
- Some of our providers have group companies in the United States.
Where personal data leaves the EEA, the transfer is covered by the European Commission’s Standard Contractual Clauses, by an adequacy decision (the UK benefits from one), or by the recipient’s certification under the **EU–US Data Privacy Framework**, together with any additional safeguards the transfer requires. You can ask us for details of the mechanism used for a specific provider. 5. How long we keep it
| Data | Retention |
|---|---|
| Invoices and order administration | 5 years from the end of the financial year, as required by Spain tax law |
| Order correspondence | 2 years after the order, so we can handle later questions and warranty claims |
| Contact form messages that do not lead to an order | 12 months |
| Server and security logs | 30 days, unless retained longer for an active security investigation |
| Newsletter subscription | Until you unsubscribe, plus 12 months to evidence that consent existed |
After these periods data is deleted or irreversibly anonymised.
6. Cookies
This site sets only strictly necessary cookies. They do what the shop cannot work without:
- remembering the contents of your basket between pages;
- keeping your checkout session alive;
- security tokens that protect forms against cross-site request forgery;
- Stripe cookies used for payment processing and fraud prevention during checkout.
Because none of these are used for analytics, advertising or tracking, no consent banner is required and you will not see one. They are session or short-lived cookies and are not used to build a profile of you.
You can block or delete cookies in your browser, but the basket and checkout will stop working if you block the necessary ones.
7. Automated decision-making
We do not make decisions about you by automated means alone. Stripe applies automated fraud screening to payments, which can result in a payment being declined; if that happens you can contact us and we will look at it manually.
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you, and receive a copy;
- rectify data that is inaccurate or incomplete;
- erasure, where we no longer have a valid reason to keep it — note that
invoice data must be retained for the statutory period;
- restriction of processing, while a dispute about accuracy or legitimacy is
resolved;
- object to processing based on our legitimate interests;
- data portability for data you provided to us, in a machine-readable format;
- withdraw consent at any time, where consent is the basis.
To exercise any of these, email info@palepiece.com. We will respond within one month. We may ask you to confirm your identity first — usually simply from the email address used for the order — and we will not charge you for a reasonable request.
If you are not satisfied with how we handle your request, you can complain to the Spain supervisory authority, or to the supervisory authority in your own EU country of residence. You may also go to court.
9. Security
The site runs over HTTPS. Access to the shop administration is limited to named accounts with strong authentication, software is kept up to date, and backups are encrypted and stored separately. Card data never touches our systems: Stripe handles it directly.
No system is perfect. If a data breach occurs that is likely to present a risk to you, we will notify the supervisory authority within 72 hours and inform you without undue delay where the law requires it.
10. Children
This shop is not aimed at children and we do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, email us and we will delete it.
11. Changes to this policy
We may update this policy — for example when we add a service provider. The date at the top shows when it last changed. Material changes will be announced on the site, and if a change requires your consent we will ask for it before it takes effect.
Contact
Pale Piece, Sirilak Chaiyarat, Camino Charco Redondo, 25 Bajo 38627 Arona, Santa Cruz de Tenerife, Spain. Mail: info@palepiece.com – Telephone: +34 620 330 685
NIE number: X56785764J