Privacy policy

This policy explains what personal data we process, why, for how long, who we share it with and what you can do about it. It is written to be understood. If anything is unclear, write to us at info@zapatoideal.com.

1. Who processes your data

  • Controller: Herederos de José Aguilera Moreno S.L. ("Zapato Ideal")
  • Tax ID (NIF): B53338844
  • Address: Calle Almansa 65 (Nave 3), 03206 Elche, Alicante, Spain
  • Email: info@zapatoideal.com
  • Phone: +34 644 744 072
  • Companies Register: Alicante, Volume 2187, Book 0, Sheet 96, Section 8, Page A 51235, Entry 1, dated 05/03/1999

For anything related to your personal data, the contact channel is info@zapatoideal.com.

2. What data we process, why, and on what legal basis

We only process data you give us yourself: when you buy, create an account, write to us or subscribe to our newsletter. We do not buy databases and we do not obtain your data from third parties.

Purpose Data Legal basis Retention
Managing your order: preparing it, shipping it, charging it and handling returns or warranty claims Name and surname, tax ID if you request an invoice, delivery and billing address, phone, email, order details Performance of the sales contract (Art. 6(1)(b) GDPR) For as long as the relationship lasts. Afterwards, blocked while liabilities may still arise: up to 3 years of legal guarantee plus 5 years to bring a claim
Issuing and keeping invoices and meeting tax and accounting obligations Tax and billing data Legal obligation (Art. 6(1)(c) GDPR) 6 years from the last entry (Art. 30 of the Spanish Commercial Code) and 4 years for tax purposes (Art. 66 of the Spanish General Tax Act)
Maintaining your customer account and order history Registration data, saved addresses, orders Performance of the contract (Art. 6(1)(b) GDPR) Until you ask us to close the account
Answering your enquiries by form, email or phone Name, email, phone if you give it to us, content of the message Your consent when contacting us, or our legitimate interest in replying (Art. 6(1)(a) and 6(1)(f) GDPR) Until the enquiry is resolved and, afterwards, as long as needed in case of a claim
Sending you news and offers by email Name and email Your consent (Art. 6(1)(a) GDPR). If you are already a customer, Art. 21.2 of the Spanish LSSI allows us to tell you about products similar to those you bought Until you unsubscribe. You can do so at any time, using the link in every email or by writing to us
Measuring how the website is used and showing you ads for our products on other sites Cookie identifiers, pages visited, device and browser, IP address Your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time The lifetime of each cookie. See our cookie policy
Preventing payment fraud Transaction data provided by the payment gateway Our legitimate interest in preventing fraud and the legal obligations of payment institutions (Art. 6(1)(f) and 6(1)(c) GDPR) The same periods as the purchase documentation

The fields marked as required in each form are the minimum we need in order to help you. If you do not provide them, we cannot process the order or the enquiry.

We do not take automated decisions that significantly affect you, nor do we build profiles for that purpose.

3. Who we share your data with

We do not sell your data and we do not pass it to third parties so they can advertise to you on their own account. We do share it with the companies we need in order to operate, and only what is strictly necessary:

  • Carriers. MRW for deliveries within mainland Spain and Portugal, and TNT / FedEx for deliveries to the rest of Europe. They receive your name, address, phone and email so they can deliver the parcel and notify you.
  • Payment gateways. Redsys for card payments. Your card details are entered in their secure environment: we never see or store them.
  • Email marketing. Mailchimp (Intuit / The Rocket Science Group LLC, United States), which sends our newsletter.
  • Analytics and advertising. Google (Google Analytics and Google Ads), only if you have accepted the corresponding cookies.
  • Web hosting. OVH, which hosts the shop and its backups.
  • Public authorities, banks and courts, where the law requires it.

With all of them, except public authorities, we have signed the data processing agreement required by Article 28 GDPR.

4. International transfers

Mailchimp and Google are United States companies and may process data outside the European Economic Area.

Google LLC and Mailchimp (The Rocket Science Group LLC, part of Intuit) are certified under the EU-U.S. Data Privacy Framework, and both also maintain the European Commission's standard contractual clauses as a fallback safeguard.

The other providers listed above process data within the European Economic Area.

5. Your rights

You can exercise these rights at any time, free of charge:

  • Access: find out what data of yours we hold and get a copy.
  • Rectification: correct data that is inaccurate or incomplete.
  • Erasure: ask us to delete data that is no longer needed.
  • Objection: object to processing based on our legitimate interest, and in all cases to marketing.
  • Restriction: ask us to stop using your data, while keeping it, until a disagreement is settled.
  • Portability: receive the data you gave us in a commonly used format, or have us send it to another company.
  • Withdraw your consent at any time, without affecting the lawfulness of what we did before you withdrew it.

How to ask. Write to info@zapatoideal.com or by post to Herederos de José Aguilera Moreno S.L., Calle Almansa 65 (Nave 3), 03206 Elche, Alicante, Spain. Tell us which right you want to exercise. We will only ask for an identity document if we have reasonable doubts about who you are.

When we reply. Within one month of receiving your request. If the request is complex we may extend that by a further two months, and we will tell you.

6. Complaining to the supervisory authority

If you believe we have not handled your data properly, we would appreciate hearing from you first so we can put it right. In any case, you have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD):

If you live in another EU country, you may also complain to the supervisory authority of your place of residence.

7. Data security

We apply technical and organisational measures to protect your data against loss, unauthorised access and misuse: the website runs over an encrypted connection (HTTPS), access to data is restricted to those who need it, and we keep backups. No system is infallible, but if a security breach ever posed a high risk to you, we would inform you and notify the AEPD as required by the GDPR.

8. Minors

This shop is intended for people aged 18 or over. We do not knowingly collect data from minors. If we find that someone under that age has registered, we will close the account.

9. Changes to this policy

We may update this policy when the law or the way we work changes. The version in force is always the one published on this page, with its update date at the bottom.


Last updated: 27 August 2026.