Data Handling Policy
Volver Lover — Carril Torre Molina 31, Murcia, MU, 30009, Spain
Contact: volverlover@gmail.com
Version 1.1 · Effective 30 July 2026 · Reviewed at least annually
This policy describes how we collect, process, store, use, share, and dispose of personal data that we handle when we fulfil orders placed with us, including orders placed through online marketplaces such as Amazon. It supplements our Privacy Policy.
1. What we collect
To ship an order we handle only the data required to deliver the parcel: the buyer's name, the shipping address, the order line items, and the order identifier. For marketplace orders, this information is retrieved solely from the marketplace's own official API — we do not obtain it from any external or third-party source. We retrieve it one order at a time, only for orders we are obliged to ship. We do not collect payment card data, and we do not collect buyer data for any purpose other than fulfilment.
2. How we process it
Processing is automated and takes place entirely within our cloud environment. When an order notification is received, our integration retrieves the order and its shipping address, creates the corresponding order in our own Shopify back office, produces a shipping label, and then confirms the shipment and tracking number back to the marketplace. No data is downloaded to laptops, mobile devices, or removable media — the application provides no bulk export path.
3. Where we store it
Order data is stored in Amazon DynamoDB in the AWS eu-west-1 (Ireland) region, with encrypted backup copies in eu-central-1 (Frankfurt). Both are within the European Union; we do not transfer this data outside the EU. Data is encrypted at rest (AES-256) and in transit (TLS 1.2 or higher) on every connection. Access is restricted to a single named operator using multi-factor authentication and least-privilege permissions; there are no shared logins and no publicly reachable databases or file servers.
4. How we use it
We use this data exclusively to pick, pack, label, and ship the specific order it belongs to, and to confirm that shipment to the marketplace. We do not use it for marketing, advertising, profiling, customer segmentation, analytics, credit assessment, or any other secondary purpose, and we do not combine marketplace buyer data with our own retail marketing data.
5. Who we share it with
We share the shipping address only with the delivery carrier, strictly so the parcel can be delivered, and with Shopify, which operates as our order-management back office and acts as a processor on our instructions. We do not sell, rent, license, or otherwise disclose this data to any other party, and we do not share it with advertising or analytics partners.
6. How long we keep it and how we dispose of it
Order records containing personal data are automatically and permanently deleted within 30 days. Deletion is enforced by the database itself through a time-to-live attribute set when the record is written, so it does not depend on manual action. Encrypted backup copies expire automatically on a rolling 30-day schedule. Our application logs are restricted to non-personal identifiers (order number, product SKU, marketplace, status) and never contain buyer names, addresses, or contact details, so log retention does not extend the retention of personal data.
7. How we protect it
Our controls include: encryption in transit and at rest; least-privilege access with multi-factor authentication; a password policy requiring a 14-character minimum with mixed case, numbers and symbols, annual rotation, and reuse prevention; continuous threat detection (Amazon GuardDuty); a tamper-evident audit trail of all administrative and data-access activity retained for more than 12 months (AWS CloudTrail); automated alerting to the operator on processing failures and anomalous activity; daily encrypted backups replicated to a second, geographically separate EU region; and testing of all changes in isolated non-production environments that never contain real buyer data.
8. Security incidents
We maintain a documented incident-response plan with defined roles, reviewed every six months. If a security incident affects personal data, we contain it, investigate its scope using our audit trail, and notify the affected marketplace within 24 hours of detection, the Spanish supervisory authority (AEPD) within 72 hours, and affected individuals where required by law.
9. Your rights
You may request access to, correction of, or erasure of your personal data, and you may object to or request restriction of its processing, by writing to volverlover@gmail.com. Because we delete order data within 30 days, most order information is already erased shortly after delivery. You also have the right to lodge a complaint with the Agencia Española de Protección de Datos (AEPD).
10. Changes to this policy
We review this policy at least annually and whenever our data flows or systems materially change. The version and effective date at the top of this page reflect the current revision.