This Privacy Policy describes how Dailybedset (“we”, “us”, or “our”) collects, uses, discloses, and protects your personal data when you visit or make a purchase from www.dailybedset.com (the “Site”).
We operate from Mexico and sell products to customers in Europe and the United Kingdom. We are committed to processing your personal data responsibly, lawfully, and in strict compliance with applicable data protection legislation, including the European Union General Data Protection Regulation (EU GDPR), the UK General Data Protection Regulation (UK GDPR), and applicable Mexican data protection laws (Ley Federal de Protección de Datos Personales en Posesión de los Particulares).
—
1. DATA CONTROLLER
For the purposes of applicable data protection laws, the data controller responsible for your personal information processed via this Site is:
Brand / Business Identity: Dailybedset
Website: www.dailybedset.com
Contact Email: secops@dailybedset.com
If you have any questions regarding this Privacy Policy or our privacy practices, please contact us at the email address provided above.
—
2. PERSONAL DATA WE COLLECT
When you visit or interact with the Site, we may collect certain categories of personal data necessary to provide our services, process orders, and fulfill legal obligations.
A. Information Provided Directly by You
Contact Information: Full name, billing address, shipping address, and email address.
Order Details: Information regarding the specific bed set items purchased, transaction history, and communication preferences.
Customer Support Data: Any communications, inquiries, or instructions sent directly to our support email.
B. Information Collected Automatically
Device and Usage Data: IP address, browser type, operating system, language preferences, referring URLs, time zone settings, and general interaction data with the Site.
Cookies and Tracking Technologies: Data collected via necessary cookies to ensure basic functionality, store cart items, and maintain security.
—
3. LEGAL BASIS FOR PROCESSING
We process personal data belonging to European Union and United Kingdom residents under the following legal bases established under Article 6 of the GDPR:
1. Performance of a Contract (Art. 6(1)(b) GDPR): Processing is necessary to manage orders, fulfill purchases, deliver products to your specified address, and provide customer service.
2. Compliance with Legal Obligations (Art. 6(1)(c) GDPR): Processing is required to fulfill accounting, tax, custom declaration, and statutory bookkeeping requirements.
3. Legitimate Interests (Art. 6(1)(f) GDPR): Processing is necessary for our legitimate interests in protecting the security of our Site, preventing fraudulent activities, and maintaining commercial records, provided your fundamental rights do not override these interests.
4. Consent (Art. 6(1)(a) GDPR): Where required by law, we rely on your explicit consent for non-essential cookies and marketing communications. You may withdraw consent at any time.
—
4. PAYMENT PROCESSING VIA STRIPE
We use Stripe as our third-party payment service provider to handle financial transactions securely.
When you complete a transaction on the Site, your payment card details, billing address, and transaction amount are transmitted directly to Stripe for payment verification and processing.
Role of Payment Processor: Stripe processes your payment data as an independent data controller or processor in compliance with global security standards, including the Payment Card Industry Data Security Standard (PCI-DSS).
Data Access: We do not store or process your full payment card numbers or CVV/CVC codes on our own servers.
Stripe Privacy Policy: To understand how Stripe handles, retains, and protects your payment information, please review the Stripe Privacy Policy.
—
5. SHARING AND DISCLOSURE OF PERSONAL DATA
We strictly limit access to your personal information. We do not sell, rent, or trade personal data. We disclose personal data only to third-party service providers bound by strict contractual obligations to handle data lawfully and securely:
Payment Processors: Stripe (for payment processing and fraud prevention).
Logistics and Delivery Partners: Third-party postal and courier services to dispatch and deliver physical goods.
Technical Infrastructure Providers: Hosting, web maintenance, and security providers necessary to operate the Site.
Legal and Regulatory Authorities: Where required by applicable law, search warrants, court orders, or statutory regulations.
—
6. INTERNATIONAL DATA TRANSFERS
As we operate from Mexico and server infrastructures may be located outside the European Economic Area (EEA) and the United Kingdom, your personal data may be transferred to and stored in jurisdictions outside the EEA/UK.
When cross-border transfers occur, we implement appropriate safeguards to ensure your personal data receives a level of protection comparable to European standard requirements, such as:
Standard Contractual Clauses (SCCs) approved by the European Commission or UK authorities.
Ensuring third-party vendors adhere to certified international compliance frameworks.
—
7. DATA RETENTION PERIODS
We retain your personal data only for as long as is strictly necessary to fulfill the purposes set out in this Privacy Policy, resolve disputes, and maintain compliance with legal, tax, and accounting requirements under European and Mexican law.
Specific retention criteria include:
Transactional and Order Data: Retained for 7 years following transaction completion to satisfy legal, statutory, tax, and audit obligations under international commercial standards.
Customer Inquiry Communications: Retained for up to 24 months from the date of final resolution to manage follow-up support requests and maintain service records.
Site Technical Logs: Retained for up to 6 months for security auditing and server maintenance purposes before automatic deletion or anonymisation.
Consent-Based Data: Retained until you withdraw your consent or request data deletion, subject to ongoing legal verification obligations.
Once personal data is no longer required for legal or operational purposes, it is securely deleted or permanently anonymised.
—
8. YOUR DATA PROTECTION RIGHTS (EEA & UK RESIDENTS)
Under European and UK data protection laws, consumers possess specific statutory rights regarding their personal data:
Right of Access: The right to request copies of the personal data held about you.
Right to Rectification: The right to request correction of inaccurate or incomplete personal information.
Right to Erasure (“Right to be Forgotten”): The right to request deletion of your personal data where legal obligations no longer require its retention.
Right to Restrict Processing: The right to request that we temporarily or permanently stop processing some or all of your personal data.
Right to Data Portability: The right to receive your personal data in a structured, commonly used, and machine-readable format.
Right to Object: The right to object to processing based on legitimate interests at any time.
Right to Withdraw Consent: Where processing relies on your consent, you may withdraw it at any time without affecting the lawfulness of processing conducted prior to withdrawal.
To exercise any of these rights, please contact us at secops@dailybedset.com. We will evaluate and respond to your request within one calendar month as required by law.
European customers also hold the right to lodge a complaint with their local supervisory authority for data protection.
—
9. INFORMATION SECURITY MEASURES
We maintain robust physical, electronic, and administrative safeguards designed to restrict unauthorised access, modification, disclosure, or destruction of your personal information.
While we employ industry-recognised technical controls, network safeguards, and encryption protocols to protect data during transmission and storage, no online platform or internet communication transmission system can guarantee complete immunity against every security risk. Users acknowledge this inherent risk when submitting information online.
—
10. COOKIES AND TRACKING TECHNOLOGIES
The Site utilizes basic operational and analytical cookies necessary for browsing navigation, maintaining active sessions, and securely completing order checkout procedures.
You can control cookie settings through your internet browser preferences. Disabling strictly necessary cookies may impact certain functionality and features of the Site.
—
11. THIRD-PARTY LINKS
The Site may contain links to external sites or third-party features. We do not control and are not responsible for the privacy practices, content, or compliance of third-party websites. We encourage you to review the privacy policies of any third-party websites you visit.
—
12. CHANGES TO THIS PRIVACY POLICY
We reserve the right to modify or update this Privacy Policy at any time to reflect changes in our operational practices, technical infrastructure, or legal requirements. Updated versions will be published on this page with an updated “Last updated” date. Continued use of the Site following updates constitutes acknowledgment of the revised terms.
—
13. CONTACT INFORMATION
For questions, requests, or privacy-related concerns, please contact us:
Brand: Dailybedset
Website: www.dailybedset.com
* Email: secops@dailybedset.com
