Privacy policy
PRIVACY POLICY
Effective Date: October 2025
This Privacy Policy explains how Hermosa HQ Ltd (“Hermosa”, “we”, “us”, or “our”) collects, uses, stores, shares, and protects your personal data when you use our website, purchase products from us, or otherwise interact with our business.
We are committed to protecting your privacy and handling personal data transparently and in accordance with the General Data Protection Regulation (GDPR), UK GDPR, and applicable Irish data protection laws.
1. Company Information
Hermosa HQ Ltd
Company Number: 789686
VAT Number: IE4697866UH
Registered Office: 20 Harcourt Street, Dublin 2, D02 H364, Ireland
Telephone: +353 (1) 902 6508
Email: support@hermosahq.ie
Hermosa HQ Ltd is the data controller responsible for your personal data.
2. Information We Collect
We may collect and process the following categories of personal data:
Identity & Contact Information
-
Name
-
Billing address
-
Shipping address
-
Email address
-
Telephone number
Transaction Information
-
Order history
-
Purchases
-
Refunds and returns
-
Customer service enquiries
-
Payment confirmations
Technical & Usage Information
-
IP address
-
Browser type
-
Device information
-
Operating system
-
Website interaction data
-
Referral sources
-
Pages visited
-
Time spent on pages
Marketing & Communication Information
-
Email subscription preferences
-
Marketing engagement data
-
Communication history
Payment Information
Payments are processed securely by trusted third-party providers including Shopify Payments, Stripe, PayPal, Klarna, or Afterpay.
Hermosa HQ Ltd does not store complete payment card details.
3. How We Use Your Information
We use your personal data to:
-
Process and deliver orders
-
Provide customer support
-
Manage payments and refunds
-
Communicate regarding purchases or enquiries
-
Improve our website, products, and customer experience
-
Prevent fraud and protect website security
-
Comply with legal, tax, and regulatory obligations
-
Send marketing communications where permitted or consented to
-
Analyse website performance and advertising effectiveness
4. Legal Basis for Processing
We process personal data under one or more of the following lawful bases:
Contractual Necessity
To fulfil orders, process payments, and provide requested services.
Legal Obligations
To comply with tax, accounting, fraud prevention, and regulatory requirements.
Legitimate Interests
To operate and improve our business, website functionality, customer experience, fraud prevention, marketing performance, and security.
Consent
Where legally required, including for certain marketing communications, cookies, and advertising technologies.
You may withdraw consent at any time.
5. Shopify Hosting & Platform Services
Our store is hosted on Shopify Inc. Shopify provides the ecommerce platform that allows us to sell our products and services.
Shopify may process customer data for:
-
website hosting
-
payment processing
-
fraud prevention
-
analytics
-
platform functionality
-
enhanced services
-
advertising and personalisation features
You can learn more about how Shopify processes personal data here:
6. Sharing Your Information
We do not sell or rent your personal data.
We may share information with trusted third parties including:
-
Payment processors
-
Shipping and logistics providers
-
Website hosting providers
-
IT and security providers
-
Analytics and advertising platforms
-
Email marketing platforms
-
Professional advisers
-
Regulatory authorities where legally required
This may include providers such as:
-
Shopify
-
Stripe
-
PayPal
-
Meta
-
Google
-
Klaviyo
-
Courier and logistics providers
Third-party providers only receive the information necessary to perform their services.
7. International Data Transfers
Some service providers may process personal data outside the European Economic Area (EEA) or United Kingdom.
Where this occurs, we ensure appropriate safeguards are implemented, including:
-
European Commission adequacy decisions
-
Standard Contractual Clauses (SCCs)
-
GDPR-compliant data processing agreements
8. Cookies & Tracking Technologies
Our website uses cookies, pixels, analytics tools, and similar technologies to:
-
Operate website functionality
-
Remember preferences
-
Analyse website traffic
-
Improve user experience
-
Measure advertising performance
-
Personalise marketing content
This may include technologies provided by:
-
Shopify
-
Google Analytics
-
Meta Pixel
-
Klaviyo
Where required by law, non-essential cookies and tracking technologies will only be activated after user consent has been obtained.
You may manage cookie preferences through your browser settings or our cookie consent tools.
9. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this policy, including:
-
Customer service
-
Legal compliance
-
Accounting obligations
-
Fraud prevention
-
Dispute resolution
Certain business and tax records may be retained for up to 7 years in accordance with Irish legal and accounting requirements.
10. Your GDPR Rights
Under the GDPR and applicable privacy laws, you may have the right to:
-
Access your personal data
-
Correct inaccurate data
-
Request deletion of your data
-
Restrict processing
-
Object to processing
-
Withdraw consent
-
Request data portability
-
Object to direct marketing
To exercise your rights, please contact:
support@hermosahq.ie
We may require verification of identity before processing certain requests.
11. Marketing Communications
Where permitted by law or where you have consented, we may send marketing communications regarding products, promotions, educational content, or updates.
You may unsubscribe from marketing communications at any time by:
-
Clicking the unsubscribe link in emails
-
Updating your account preferences
-
Contacting us directly
12. Security of Personal Data
We implement reasonable technical and organisational measures to protect personal data, including:
-
SSL encryption
-
Secure hosting infrastructure
-
Restricted staff access
-
Secure payment gateways
-
Account access controls
However, no internet transmission or electronic storage system can be guaranteed completely secure.
13. Children’s Privacy
Our website and products are not directed toward individuals under 18 years of age.
We do not knowingly collect personal data from children without appropriate parental consent.
14. Third-Party Websites
Our website may contain links to external websites or services operated by third parties.
We are not responsible for the privacy practices or content of third-party websites.
15. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect legal, regulatory, operational, or technological changes.
Updated versions will be published on this page together with the revised effective date.
16. Contact & Complaints
If you have questions regarding this Privacy Policy or how your personal data is handled, please contact:
Hermosa HQ Ltd
20 Harcourt Street
Dublin 2, D02 H364
Ireland
Email: support@hermosahq.ie
You also have the right to lodge a complaint with the Irish Data Protection Commission (DPC):