Privacy Policy
- Information on the collection of personal data and contact details of the data controller
1.1 We are pleased that you are visiting our website and thank you for your interest. Below, we inform you about the processing of your personal data when using our website. Personal data is any data with which you can be personally identified.
1.2 The data controller on this website, within the meaning of the General Data Protection Regulation (GDPR), is Ximena Tulum. The controller is the natural or legal person who decides, alone or jointly with others, on the purposes and means of processing personal data. Contact email: help@ximena-tulum.com
1.3 This website uses, for security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the controller), an SSL or TLS encrypted connection. You can recognize an encrypted connection by the "https://" string and the padlock symbol in your browser bar.
- Data collection when visiting our website
When you use our website for informational purposes only, i.e., if you do not register or otherwise transmit information to us, we only collect the data that your browser transmits to our server (so-called "server log files").
When accessing our website, we collect the following data:
- Website visited
- Date and time of access
- Amount of data transferred in bytes
- Source/reference from which you reached the page
- Browser used
- Operating system used
- IP address used (where applicable: in anonymized form)
Processing is carried out in accordance with Art. 6(1)(f) GDPR, based on our legitimate interest in improving the stability and functionality of our website.
- Cookies
To make visiting our website attractive and to enable the use of certain functions, we use cookies.
Some cookies are deleted when you close your browser ("session cookies"), while others remain on your device ("persistent cookies").
Cookies may collect:
- Browser information
- Location data
- IP addresses
Legal basis:
- Art. 6(1)(b) GDPR (contract performance)
- Art. 6(1)(f) GDPR (legitimate interest)
You can configure your browser to accept or reject cookies.
- Contact
When contacting us (form or email), personal data is collected to handle your request.
Legal basis:
- Art. 6(1)(f) GDPR (legitimate interest)
- Art. 6(1)(b) GDPR (if a contract exists)
Data is deleted after the inquiry is resolved, unless required by law.
- Customer account and contracts
We collect personal data when you:
- Open an account
- Place an order
Purpose: contract management.
You can delete your account at any time by writing to: help@ximena-tulum.com
Data will be retained in accordance with tax and legal obligations.
- Use of data for direct advertising
6.1 Newsletter
If you subscribe, you will receive offers by email.
Required data: email System: Double Opt-in
You can unsubscribe at any time.
6.2 Advertising to existing customers
We may send similar offers if you have already made a purchase.
Legal basis:
- Art. 6(1)(f) GDPR
You can object at any time by writing to: help@ximena-tulum.com
- Data processing for orders
7.1 Shipping and payment
Data is shared with:
- Shipping company
- Bank
Legal basis:
- Art. 6(1)(b) GDPR
7.2 Payment providers
PayPal — Data is sent to PayPal to process the payment.
Klarna / SOFORT — Data is sent solely to handle the payment.
- Review reminder
We may send an email asking you to review your purchase if you give consent.
- Social media (Plugins)
We use buttons from:
Using the Shariff system (no automatic connection).
- Online marketing
10.1 Google DoubleClick — Displays personalized ads using cookies.
10.2 Google Ads Conversion Tracking — Allows measuring the effectiveness of advertising campaigns.
- Web analytics
Google Analytics — Analyzes website usage via cookies.
- Anonymized IP
- Statistical data
You can disable it in your browser.
- Remarketing
Facebook Pixel — Allows measuring Facebook ads.
Google Remarketing — Displays ads based on your browsing behavior.
- User rights
You have the right to:
- Access (Art. 15)
- Rectification (Art. 16)
- Erasure (Art. 17)
- Restriction (Art. 18)
- Portability (Art. 20)
- Withdraw consent (Art. 7(3))
- Lodge a complaint with an authority (Art. 77)
- Right to object
You can object to the use of your data at any time.
- Data retention
Data is retained in accordance with:
- Legal obligations
- Contractual necessity
Afterwards, it is deleted automatically.