Legal
Privacy Policy
Last updated: September 1, 2026.
This policy explains how we process personal data across our online store, contact forms, order requests, and customer reviews.
1. Data Controller
VerdeRaíz Botanical Wellness Collection is the commercial identity of this site. Contact email: [email protected]. Address: 18 Olivo Sereno St., 2nd Fl., Apt B, 29008 Málaga, Spain.
2. Data We Process
For orders, we process first name, last name, phone number, optional email, country, city, address, postal code, comments, items, bundle selections, and totals. For contact inquiries, we process name, email, optional phone, subject, and message. For reviews, we process public display name, rating, text, and an irreversible hash of the email; the email is never shown publicly. Browser sessions store shopping cart items and security tokens.
3. Purposes & Legal Basis
We process order data to manage pre-contractual steps, verify product availability, and coordinate order details without online payment. Contact messages are processed based on consent and legitimate interest in providing customer care. Customer reviews are published with user consent and may be moderated for security, legality, or relevance.
4. Data Retention
Order records are retained for as long as necessary to process requests and satisfy applicable legal obligations. Contact messages are deleted when no longer required. Customer reviews remain published until removed or requested for deletion. Cookie preferences remain in your browser until cleared or modified.
5. Recipients
We do not sell your personal data. Hosting, infrastructure, and delivery service providers may process data strictly as necessary under appropriate data protection safeguards. In this site version, there is no payment gateway and no credit card data processing.
6. International Data Transfers
If a service provider processes data outside the European Economic Area, appropriate legal mechanisms and safeguards will be verified prior to activation. This site does not assume unverified third-party transfers.
7. Your Rights
You may request access, rectification, erasure, restriction, objection, or data portability where applicable by contacting [email protected]. You may also withdraw consent at any time without affecting prior lawful processing, or file a complaint with the appropriate Data Protection Authority.
8. Security Measures
Our application uses PHP sessions, CSRF protection tokens, server-side input validation, output escaping, file locking on writes, and directory access restrictions on storage and configuration folders. While no online system is completely risk-free, we minimize stored data and review access controls regularly.
9. Minors
Our products are not directed to minors, and we do not knowingly collect personal data from children. If data from a minor is detected without a valid legal basis, it will be deleted.
10. Policy Changes
Material updates to this policy will be published on this page with a revised date. When required by law, renewed consent will be requested.