Privacy Policy Agreement

Effective Date: August 5, 2026.

Last Updated: August 14, 2026

Version: 2.1 (GDPR‑Compliant 2026)

1. Who We Are

Website: https://dfnungaray.com

Business Name: dFNungaray

Business Type: E-commerce art gallery (WooCommerce platform) specializing in the sale and worldwide export of oil paintings and wood sculptures.

We are committed to protecting your personal data and respecting your privacy rights under the General Data Protection Regulation (GDPR) and applicable international data protection laws. This Privacy Policy explains how we collect, use, store, and protect your personal information when you visit our website, create an account, make a purchase, or interact with us in any way.

Primary Contact for Privacy Matters:

Email:

website.administrator@dfnungaray.com

Response Time: Within 30 calendar days

3. What Personal Data We Collect and Why

3.1 Orders and Billing Information

What we collect:
Full name (first and last name)
Billing address (street, city, postal code, country)
Shipping address (may differ from billing address)
Email address
Phone number
County of origin and destination
Invoice and order history
Why we collect it:
To process your order accurately
To arrange shipping and delivery
To generate invoice and comply with tax obligations
To contact you about your order status
To prevent fraud and verify customer identity

Legal Basis: Performance of contract (Article 6(1)(b)) and legal obligation for tax compliance (Article 6(1)(c))

3.2 Payment Information

What we collect:
Payment method type (credit card, GooglePay account, etc.)
Transaction amount and date
Payment status and receipt information
What we do NOT collect or store:
Full credit card numbers (PCI-DSS compliant)
Card security codes (CVV/CVC)
Full bank account details
Passwords for payment accounts
Why we collect it:
To process your transaction securely
To generate payment receipts
To reconcile accounts and prevent duplicate charges
To dispute fraudulent transactions if necessary

How it’s protected: Payments are processed exclusively through secure third-party payment processors (Stripe, Google Pay, Mercado Pago or similar PCI-DSS certified providers). These processors act as data processors on our behalf. We do not handle or store sensitive payment data on our servers. All payment transactions are encrypted using SSL/TLS 256-bit encryption.

Legal Basis: Performance of contract (Article 6(1)(b))

3.3 Account and Authentication Data

What we collect:
Username (chosen by you)
Email address (used for login)
Password (hashed and encrypted, one-way encryption)
Account creation date
Login history and IP addresses used to access the account
Account settings and preferences
Wishlist or saved items (if applicable)
Why we collect it:
To create and manage your account
To allow you to view your order history
To enable secure login
To prevent unauthorized account access
To help you recover your account if needed

How it’s protected: Passwords are hashed using industry-standard algorithms (bcrypt (default), SHA-384 pre-hashing, or Argon2ID) and are never stored in plain text. Only you and our system have access to your account. We never ask for your password via email.

Legal Basis: Performance of contract (Article 6(1)(b)) and fraud prevention (Article 6(1)(f))

3.4 Cookies and Tracking Technologies

What We Collect
Session cookies (temporary identifiers for your browsing session)
Persistent cookies (longer-term tracking for user preferences)
IP address and device identifiers
Browser type and operating system
Pages visited, products viewed, time spent on site
Referrer information (how you arrived at our site)
Cart contents and checkout behavior

Types of cookies we use:

Purpose

Duration

Shopping cart functionality, session management, security features, payment processing

Session (until browser closes) or up to 24 hours

Understand visitor behavior, page performance, traffic sources (WooCommerce, WooCommerce Stripe Gateway, Mercado Pago)

Up to 24 months

Language settings, theme preferences, currency selection

Up to 12 months

How to manage cookies:
You can refuse non-essential cookies when you first visit our site via our cookie consent banner
You can withdraw consent at any time via cookie settings on our website
You can control cookies via your browser settings (typically found under Privacy/History settings)
Disabling essential cookies may impair site functionality (e.g., shopping cart may not work)
We do not use cookies to build profiles for automated decision-making, tracking or marketing purposes

Third-party cookie notice: Some cookies are set by third-party partners. These partners have their own privacy policies. You should review their policies:

Third-party Privacy Policies
WordPress Privacy Policy
LiteSpeed Tech Privacy Policy
SureForms Privacy Policy
Automattic Privacy Policy
Stripe Privacy Policy
Mercado Pago Declaración de Privacidad
Google Privacy and Terms
Google Pay & Wallet Console Terms of Service
Hostinger Privacy Policy

Legal basis: Consent (Article 6(1)(a)) for non-essential cookies; legitimate interest or legal requirement (Article 6(1)(f) or (c)) for essential cookies

3.5 Customer Support and Communication Data

What we collect:
Email address
Name
Message content and attachments
Phone number (if provided)
Inquiry topic and timestamp
Why we collect it:
To respond to your questions or complaints
To provide customer support
To track support tickets and resolutions
To improve our service quality

Legal basis: Performance of contract (Article 6(1)(b)) and legitimate interest (Article 6(1)(f))

3.6 IP Address and Device Information

What we collect:
IP address (Internet Protocol address)
Device type (desktop, mobile, tablet)
Browser type and version
Operating system
Device identifiers
Approximate geolocation (based on IP)
Why we collect it:
To prevent fraud and unauthorized access
To diagnose technical issues and optimize site performance
To understand traffic sources and user demographics
To comply with security and legal obligations
To detect and prevent cyberattacks or suspicious activity

Legal basis: Legitimate interest (Article 6(1)(f)) and legal obligation (Article 6(1)(c))

4. Who We Share Your Data With

We only share your personal data with third parties when necessary to fulfill your order, comply with legal obligations, or with your explicit consent. All third parties act as data processors or joint controllers under GDPR and must sign Data Processing Agreements (DPAs) with us.

4.1 Data Processors (Third-Party Service Providers)

Service Provider

Data Shared

Purpose

Location

DPA in Place

Stripe, Mercado Pago, Google Pay

Payment information, transaction details, card type (not full card number)

Payment processing

USA, Chile, Finland, Taiwan, Netherlands, Brazil, and India (global)

✅ Yes

Hostinger, WordPress, and Verisign

All customer data (hosting and platform services)

Website hosting, database management, security

Arizona, USA (secured through CDN in worldwide servers)

✅ Yes

Shipping Providers (DHL, FedEx, UPS, local carriers)

Full name, address, phone, artwork details, package weight and size, value

Order delivery and tracking

Global (varies by destination)

✅ Yes

WooCommerce Tax, tax and accounting software

Shipping address, order details, shipping charges, tax rate, and tax ammount

Tax compliance, invoicing, financial record-keeping

USA (Standard Contractual Clauses apply)/ EU data centers (configurable)

✅ Yes

Automattic, Elementor, Proton, Hostinger

Name, username, email, phone, order information, payment preferences, sales history

Account administration, mail notifications, password management>

USA / EU (varies)

✅ Yes

SureForms, Elementor, Proton, Hostinger

Name, username, email, communication inquiries

Contact form

USA / EU (varies)

✅ Yes

Customs and Border Authorities, SAT (Sistema de Administración Tributaria)

Full name, address, artwork description, value, payment, HS codes

International shipping compliance and customs declarations

Mexico, destination country

Legal obligation

Important: We only share the minimum data necessary with each provider. For example, payment processors receive payment information but not your full address history; shipping providers receive your address but not your payment details.

4.2 Data Controllers and Joint Controllers

We may work with partners who act as joint controllers of your data (meaning they determine the purposes and means of processing alongside us). These currently include:

Payment processors
For payment fraud detection

When you use these services, their privacy policies apply in parallel to ours.

4.4 Sub-Processors List

Our primary data processors may use sub-processors (sub-contractors). We maintain a current list of sub-processors:

Current sub-processors
Auttomatic sub-processors: AWS (Amazon Web Services)
Stripe’s payment partner networks
Mercado Pago as Mercado Libre subsidiary
Google Pay sub-processors’ list

Access Sub-Processor List: For the most current list of sub-processors, please email website.administrator@dfnungaray.com

International Data Transfer

DFNungaray ArtStore is a mexican webstore hosted in USA, secured through CDN through worldwide servers. Since you purchase from us globally your personal data may be transferred to and processed in countries outside the European Union/European Economic Area (EU/EEA).