Privacy Policy
Last updated: April 2026
Lola's Garden operates this store and website, including all related information, content, features, tools, products, and services, to provide you with a personalized shopping experience (the "Services"). Lola's Garden uses Shopify to provide the Services. This Privacy Policy explains how we collect, use, and disclose your personal information when you visit, use, or make a purchase or other transaction via the Services, or communicate with us. In case of conflict between our Terms of Service and this Privacy Policy, this Privacy Policy will govern the collection, processing, and disclosure of your personal information.
By accessing or using the Services, you acknowledge that you have read this Privacy Policy and consent to the collection, use, and disclosure of your information as described here.
Personal Information We Collect
"Personal information" refers to data that identifies or can reasonably be linked to you. Anonymous or de-identified data is not considered personal information. Depending on your interaction with the Services, your location, and applicable law, we may collect or process:
-
Contact details: name, billing and shipping address, phone number, and email address.
-
Financial information: credit/debit card and bank account numbers, payment information, transaction details, and payment confirmations.
-
Account information: username, password, security questions, preferences, and settings.
-
Transaction information: products viewed, added to cart or wishlist, purchased, returned, exchanged, or canceled.
-
Communications with us: information included in customer support inquiries or other messages.
-
Device information: device, browser, network connection, IP address, and unique identifiers.
-
Usage information: how you interact with the Services, navigation, clicks, and behavior patterns.
Sources of Personal Information
We collect information from the following sources:
-
Directly from you: when creating an account, communicating with us, or interacting with the Services.
-
Automatically: via cookies, similar technologies, or device information.
-
Service providers: third parties acting on our behalf, including Shopify.
-
Business partners and third parties: to improve Services or marketing campaigns.
Purposes and Legal Bases for Processing
We use personal information for the following purposes, based on GDPR/LOPDGDD legal bases:
-
Providing, personalizing, and improving Services – Contractual necessity (Art. 6.1.b GDPR).
-
Marketing and advertising – Explicit consent (Art. 6.1.a GDPR).
-
Security and fraud prevention – Legitimate interests (Art. 6.1.f GDPR).
-
Communications and customer support – Contractual necessity and legitimate interests.
-
Legal compliance – Legal obligation (Art. 6.1.c GDPR).
Sensitive data (e.g., marketing preferences) is processed only with explicit consent.
Sharing Personal Information
We may share personal information with third parties in the following cases:
-
Shopify, service providers, logistics partners, fulfillment, analytics, customer support, and cloud storage.
-
Marketing partners for advertising campaigns, following privacy regulations.
-
With your consent, for product delivery, social media integration, or other services.
-
Affiliates within our corporate group.
-
In the event of a merger, acquisition, bankruptcy, or legal obligation.
International Transfers
Your data may be transferred and processed outside Spain and the EU. In such cases, we ensure adequate safeguards, such as Standard Contractual Clauses approved by the European Commission or equivalent recognized mechanisms.
Cookies and Similar Technologies
We use cookies and similar technologies to improve user experience, personalize content, and analyze traffic. You can configure your browser to block cookies, but some Services may not function properly.
User Rights (LOPDGDD & GDPR)
Depending on your residence, you have the right to:
-
Access and know: request a copy of your personal data.
-
Rectify: correct inaccurate personal data.
-
Erase: delete your personal data.
-
Data portability: receive your data in a structured format and transfer it to another controller.
-
Restriction of processing: request limitation of data use.
-
Object: object to processing for certain purposes, including direct marketing.
-
Withdraw consent: if data was processed based on consent.
You can exercise these rights by contacting us at contact@lolasgarden.com
We will not discriminate for exercising your rights. We may request identity verification before processing any request.
Children's Data
The Services are not directed at minors under the legal age. We do not knowingly collect personal data from children. Parents or guardians may request deletion of data provided by a minor.
Data Security and Retention
We take reasonable measures to protect your data, but cannot guarantee absolute security. Data is retained only as long as necessary for contractual, legal, regulatory, or dispute resolution purposes.
For details on how Shopify processes personal data, visit: Shopify Privacy Center
Meta Business Privacy Policy
Lola's Garden uses Facebook, Instagram, Messenger, and related Meta services (collectively, “Meta Services”) to provide a personalized experience, run ads, and measure performance. By interacting with our website or Meta platforms, your personal data may be collected, processed, and used as described below.
Data We Collect via Meta Services
We may collect the following types of information:
-
Interactions with Meta Services: clicks, likes, shares, comments, and other engagement.
-
Device and browser information: IP address, device type, operating system, browser type.
-
Activity on our website linked to Meta Services: pages viewed, products viewed or added to cart, and purchases (via Meta Pixel or SDK).
-
Identifiers from Meta Services: user ID, cookies, or similar identifiers.
Purpose of Processing
We use your data collected via Meta Services for:
-
Running targeted advertising and retargeting campaigns.
-
Measuring and analyzing the performance of our ads and website.
-
Personalizing the content and offers shown to you on Meta platforms.
-
Preventing fraud and ensuring security.
Legal Basis
Processing your data via Meta Services is based on:
-
Consent: for personalized ads and tracking (Art. 6.1.a GDPR).
-
Legitimate interest: for fraud prevention and basic analytics (Art. 6.1.f GDPR).
Data Sharing
Data collected via Meta Services may be shared with:
-
Meta Platforms, Inc. and their affiliates.
-
Service providers assisting with ads, analytics, and website functionality.
Meta may also use the data in aggregated form for ad targeting, analytics, and reporting.
Your Rights
If you are in the EU/Spain, you have rights under GDPR/LOPDGDD:
-
Access, rectification, or deletion of your personal data.
-
Restriction or objection to processing for certain purposes.
-
Opt-out of personalized advertising via Meta.