Last updated: [PENDIENTE: fecha de publicación de este texto]
This policy explains what personal data you process [PENDIENTE: razón social completa de la empresa] (Neky Market, www.nekymarket.com), why, who you share them with, how long you keep them, and what rights you have. It applies to who visits the site, who buys, and who picks up orders.
Data WE process
- Your contact and account details: name, email, phone, address and a password that we keep encrypted.
- Details of the person picking up the order: name, telephone, province, municipality, address and identity document number. The document is sensitive personal data under California law (CPRA).
- Order data: products, amounts, the chosen collection warehouse and the proof of payment that you upload, which can show the name of the holder and part of the bank account data.
- Technical data: IP address, browser type, pages visited and access security logs (e.g. failed login attempts).
- Your messages and communication preferences. If you write to us on WhatsApp -for example, to buy wholesale-, the conversation also goes through that service, which is from Meta and has its own privacy policy.
We obtain them from you directly, automatically when you use the site and, in the case of the picker, from the person placing the order, who agrees to have their permission.
What we use them for
- Manage your account and orders, verify payments, and notify you of every step.
- Identify who picks up from the warehouse. The identity document is only used for that and to comply with legal obligations; in the emails and in your account it is shown masked.
- Attend to you when you write to us.
- Protect the site and prevent fraud.
- Comply with the law: tax and accounting obligations, sanctions controls and export and record keeping.
- Send you promotions, only if you accept it. You can unsubscribe at any time from the link in each email or from “My details” in your account (CAN-SPAM Act).
Who we share them with
We do not sell your personal data or share it for advertising based on your activity on other sites, and we have not done so in the last 12 months. We only communicate them to:
- Suppliers who work for us under contract and only with our instructions: web hosting ([PENDIENTE: proveedor de hosting]Send emails[PENDIENTE: proveedor de correo]) and transportation and warehouses ([PENDIENTE: empresas de transporte y almacenaje]).
- Authorities, when a law, a court order or a valid requirement obliges us.
- An eventual buyer or successor of the business, with the same guarantees.
We also do not disclose data to third parties for their own direct marketing (California “Shine the Light” law, Cal. Civ. Code § 1798.83).
Cookies and Privacy Signals
We only use the cookies necessary for the site to function; the detail is in the Cookie Policy. We don’t follow your activity on other sites. We respect your browser’s Global Privacy Control (GPC) signal as an opt-out request; for the “Do Not Track” signal there is no common standard, and as we do not track between sites nothing changes in our operation (Cal. Bus. & Prof. Code § 22575).
How long we keep them
- Orders, invoices and payment vouchers: [PENDIENTE: plazo, según la normativa fiscal y la de sanciones (31 CFR § 501.601)].
- Identity document of the collector: [PENDIENTE: plazo tras la recogida, salvo obligación legal de conservarlo más].
- Account: as long as you keep it open; closing it deletes or anonymizes what we should not keep by law.
- Safety record [PENDIENTE: plazo].
How we protect them
The site always works with an encrypted connection (HTTPS). Dashboard access requires two-step verification, we limit login attempts, and only staff who need it access the data. We do not store card details or bank credentials. No system is foolproof: If there is a breach affecting your data, we will notify you as required by state breach notification laws.
Your rights
You can ask us, free of charge:
- know what data we process about you and receive a copy in a format that you can take with you;
- correct those that are inaccurate;
- erase them, except those that the law requires us to keep;
- limit the use of your sensitive data – such as your identity document – to what is essential (we already use it only for that);
- not be subject to sale or exchange of data (we do not sell or share it, but you can still request it);
- not be treated differently for exercising these rights.
These rights are recognized, among others, by California law (CCPA/CPRA, Cal. Civ. Code § 1798.100 et seq.) and the privacy laws of other states, such as Virginia, Colorado, Connecticut, Texas, or Oregon; we serve them for anyone, wherever they live. You can exercise them from Your privacy options or by writing to [PENDIENTE: correo para asuntos legales y de privacidad]. We will verify your identity before responding, we will respond in a maximum of 45 days (extendable another 45 if necessary, notifying you) and, if we reject your request, you can appeal that decision by writing to the same address. You may also act through an authorized representative.
Kinder
The site is not directed to children under the age of 13 and we do not knowingly collect your information (Coppa, 15 U.S.C. § 6501). To buy, you must be over 18 years old. If you think a minor has given us data, please write to us and we will delete it.
Stored Where?
The data is stored on servers located in [PENDIENTE: país donde están los servidores del hosting]. If you write to us from another country, your data will be processed there.
Changes and contact
If we change this policy, we’ll update the date above and, if the change is important, we’ll let you know. Responsible: [PENDIENTE: razón social completa de la empresa], [PENDIENTE: dirección postal completa]. Mail: [PENDIENTE: correo para asuntos legales y de privacidad].
