Last Updated: September 21, 2025
1. Introduction (Who We Are)
Welcome to MEPG Fashion. We are committed to protecting your privacy and handling your personal data in an open and transparent manner. This Privacy Policy explains how we collect, use, share, and protect your personal information when you visit our website mepg.eu (“Website”) and purchase our products.
The data controller responsible for your personal data is:
- Legal Name: Kuzieva Mastura Fozilovna (Sole Proprietorship)
- Trading Name: MEPG Fashion
- Legal Address: Calle Rascon, 27, 28019, Madrid, Spain
- Tax ID Number (NIE): Y2930573L
- Contact Email: info@mepg.eu
This policy is drafted in compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR).
2. The Data We Collect
We collect information about you in a variety of ways to provide and improve our services. The types of personal data we collect are:
- Personal Identification and Contact Information: When you create an account, place an order, or contact us, we collect your full name, billing address, shipping address, email address, and phone number.
- Payment Information: We do not collect or store your full credit card numbers. All payments are processed securely through our third-party payment gateways, Stripe and PayPal, which are PCI-compliant. We only receive a transaction confirmation, the last four digits of your card, and the cardholder’s name.
- User-Generated Content: If you choose to leave product reviews or comments on our Website, we collect your name, email address, the content of your review/comment, and your IP address. The IP address is collected by the WordPress system primarily for spam detection.
- Communications Data: When you contact us via our contact form or by email, we collect your name, email address, and any information you provide in your message to us.
- Technical and Usage Data: We automatically collect certain information when you visit our Website. This includes data collected through cookies and similar technologies, such as your IP address, browser type, device type, operating system, pages viewed, and the time and duration of your visit. This data is largely anonymized and is used for analytics and site security.
3. How We Use Your Personal Data
We use the personal data we collect for the following purposes:
- To Process and Fulfill Your Orders: To manage your purchases, process payments, arrange for shipping, and provide you with order confirmations and invoices.
- To Manage Your Account: To create and manage your customer account, allowing you to view your order history and manage your preferences.
- To Provide Customer Support: To respond to your inquiries, requests, and provide you with support when you contact us.
- To Improve Our Website and Services: To analyze how users interact with our Website using tools like Google Analytics, helping us to improve user experience, product offerings, and business operations.
- For Marketing and Advertising: With your explicit consent, we may use your information to send you promotional emails about new products or special offers. We also use tracking technologies like the Facebook Pixel and Google Ads for remarketing purposes, to show you relevant ads on other websites.
- For Security and Fraud Prevention: To protect our Website and customers from fraudulent activities and to ensure the security of our IT systems.
- To Comply with Legal Obligations: To maintain records required by law, such as for tax and accounting purposes.
4. Legal Basis for Processing Your Data
Under GDPR, we must have a valid legal basis to process your personal data. We rely on the following bases:
- Performance of a Contract: We process your data (name, address, contact details, payment info) because it is necessary to fulfill our contractual obligations to you when you purchase a product.
- Consent: For marketing communications and the use of non-essential cookies (for analytics and advertising), we will only process your data based on your explicit and freely given consent. You can withdraw your consent at any time.
- Legitimate Interest: We process certain data for our legitimate interests, such as for improving our services, fraud prevention, and spam detection. We ensure that our legitimate interests do not override your rights and freedoms.
- Legal Obligation: We are required to process and retain certain information, such as invoices and transaction records, to comply with our legal and regulatory obligations (e.g., tax and commercial law in Spain).
5. Cookies and Tracking Technologies
Our Website uses cookies, which are small text files placed on your device, to enhance functionality and analyze traffic.
- Essential Cookies: These are necessary for the Website to function correctly. They enable core functionalities like maintaining your user session and managing your shopping cart. You cannot opt out of these cookies.
- Analytics Cookies: We use Google Analytics to collect anonymized information about how visitors use our site. This helps us understand user behavior and improve the Website.
- Marketing & Advertising Cookies: We use technologies like the Facebook Pixel and Google Ads cookies to deliver personalized advertising to you on other platforms (remarketing).
You will be asked for your consent to use non-essential cookies via a cookie banner upon your first visit. You can manage your cookie preferences at any time through your browser settings or our cookie consent tool.
6. Who We Share Your Data With
We do not sell your personal data. We only share your data with trusted third-party service providers who are essential for our operations:
- Payment Gateways: Stripe and PayPal, to securely process your payments.
- Shipping Carriers: Correos (and potentially other carriers), to deliver your orders. We provide them with your name, shipping address, and contact details.
- Analytics Providers: Google Analytics, to help us analyze website traffic and user behavior. The data shared is anonymized or pseudonymized.
- Advertising Platforms: Google and Facebook, for remarketing purposes, subject to your consent.
- Legal and Governmental Authorities: We may disclose your information if required to do so by law or in response to valid requests by public authorities.
7. International Data Transfers
Some of our third-party service providers (e.g., Google, Stripe, PayPal, Facebook) are based outside the European Economic Area (EEA). When we transfer your data to these providers, we ensure that your data is protected by appropriate safeguards as required by GDPR. These safeguards include relying on an Adequacy Decision from the European Commission or implementing Standard Contractual Clauses (SCCs) approved by the European Commission.
8. How Long We Retain Your Data
We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
- Order Information: In compliance with Spanish commercial law, we retain documents related to commercial transactions (such as invoices) for a period of 6 years.
- Customer Accounts: We retain your account information as long as your account remains active. If you delete your account, your data will be erased, subject to our legal retention obligations.
- Marketing Data: If you have consented to receive marketing materials, we will retain your data until you withdraw your consent.
9. Your Data Protection Rights under GDPR
As a data subject in the EU, you have the following rights regarding your personal data:
- The Right to Access: You can request a copy of the personal data we hold about you.
- The Right to Rectification: You can request that we correct any inaccurate or incomplete data.
- The Right to Erasure (‘Right to be Forgotten’): You can request that we delete your personal data, under certain conditions.
- The Right to Restrict Processing: You can request that we suspend the processing of your personal data in certain scenarios.
- The Right to Data Portability: You can request that we transfer your data to you or another service provider in a machine-readable format.
- The Right to Object: You can object to our processing of your personal data where we are relying on a legitimate interest.
- The Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority. In Spain, this is the Agencia Española de Protección de Datos (AEPD).
To exercise any of these rights, please contact us at info@mepg.eu.
10. Data Security
We have implemented appropriate technical and organizational security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorized way. Our website uses SSL (Secure Socket Layer) encryption to protect data transmitted to and from the site. Access to your personal data is limited to those employees and third parties who have a business need to know.
11. Children’s Privacy
Our services are not intended for individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without verification of parental consent, we will take steps to remove that information.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the “Last Updated” date. We encourage you to review this policy periodically.
13. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your rights, please do not hesitate to contact us:
Postal Address: Calle Rascon, 27, 28019, Madrid, Spain
Data Controller: Kuzieva Mastura Fozilovna
Email: info@mepg.eu