Privacy policy

Last updated: 25 September 2026

This page explains what personal data we process when you visit thesingularbathroom.es, create an account, buy from us or contact us, what we use it for and what rights you have. Our terms of sale are in the Terms and conditions, and details of the website owner in the Legal notice.

1. Data controller

TISA SALAMANCA C.B. (The Singular Bathroom)
Tax ID (CIF): E37554698
Avda. Peña de Francia, nº 75, 37187 Aldeatejada (Salamanca), Spain
Telephone: (+34) 923 26 63 56
Email: [email protected]

2. Applicable law

We process your data in accordance with Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), Spanish Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD), and Spanish Law 34/2002 on Information Society Services and Electronic Commerce (LSSI).

3. What data we process

  • Account and order data: first and last name, delivery and billing address, email address, telephone number, tax details (ID or VAT number) if you request an invoice, the products you bought, amounts and order history.
  • Enquiries: the content of the messages you send us by email, telephone, contact form or WhatsApp, and any photos or measurements you give us for made-to-measure orders or spare parts.
  • Payment data: we never see or store your card details. Card and Bizum payments are entered directly on the payment provider's secure payment page; we only receive confirmation that the payment went through.
  • Browsing data: IP address, browser, pages visited and the date and time of access, which are kept in the server logs, and the page your visit came from (see section 9, Cookies).

4. Purposes and legal basis

  • Managing your account, orders, deliveries, returns and warranties: performance of the sales contract (Art. 6(1)(b) GDPR).
  • Answering your enquiries and preparing quotes: steps taken at your request before entering into a contract, or performance of the contract (Art. 6(1)(b) GDPR).
  • Issuing invoices and meeting our accounting and tax obligations: legal obligation (Art. 6(1)(c) GDPR).
  • Sending you marketing communications: your consent (Art. 6(1)(a) GDPR) or, if you are already a customer, our legitimate interest in telling you about products similar to those you bought (Art. 21(2) LSSI). You can object at any time by writing to [email protected] or using the link included in every communication.
  • Keeping the site secure and preventing fraud and abuse: legitimate interest (Art. 6(1)(f) GDPR).
  • Knowing, in aggregate, which channel brings the visits that end in an order (search engine, advert, another website): legitimate interest (Art. 6(1)(f) GDPR).

We do not take decisions based solely on automated processing that produce legal effects concerning you. If you choose to pay with seQura, seQura assesses the transaction (see section 5).

5. Recipients

We do not sell your data or share it for marketing purposes. We only disclose it where necessary:

  • Carriers (for example, Correos or SEUR): name, address and telephone number, to deliver your order.
  • Payment providers: our bank and Redsys, for card and Bizum payments.
  • seQura (Sequra Worldwide, S.A., Barcelona), only if you choose to pay in instalments or later with seQura: your identification, contact and order details, so that seQura can assess and manage the financing as an independent controller under its own privacy policy.
  • Public authorities (for example, the Spanish Tax Agency), where the law requires it.
  • Processors that provide services to us under contract and on our instructions: web and email hosting, and Cloudflare, which protects and speeds up the site and therefore processes visitors' IP addresses.
  • WhatsApp (Meta), only if you decide to write to us on WhatsApp; WhatsApp's own terms then also apply.

6. International transfers

Some providers (Cloudflare, Inc. and, if you write to us on WhatsApp, Meta Platforms, Inc.) may process data in the United States. Both companies participate in the EU-U.S. Data Privacy Framework, which the European Commission considers to provide an adequate level of protection, and they also apply the standard contractual clauses approved by the Commission.

7. Retention

We keep your data for as long as you keep your account or the business relationship lasts and, after that, for the periods required by law: generally six years for commercial and accounting records and four years for tax records. Data used for marketing communications is kept until you object or withdraw your consent. Server logs are deleted periodically.

8. Your rights

You can exercise your rights of access, rectification, erasure, objection, restriction of processing and data portability, and withdraw your consent at any time, by writing to [email protected] or by post to the address in section 1, stating which right you are exercising and proving your identity. We will reply within one month.

If you believe we have not handled your request properly, you can lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) or with the data protection authority of your country of residence.

9. Cookies

This site only uses first-party technical cookies that it needs in order to work, plus one session cookie that records which channel the visit came from. We do not use advertising or social media cookies.

  • Technical shop cookies (for example PHPSESSID, form_key, mage-cache-sessid, private_content_version, mage-messages, store): they keep your session, your basket, your chosen language and the security of forms. They are essential and do not require consent.
  • tsb_src (first-party, session): records which channel you came from (search engine, advert, another website), without identifying you personally, so that the order can be attributed to that channel. It is deleted when you close your browser.
  • Cloudflare may set technical security cookies (for example __cf_bm) to tell legitimate traffic apart from automated traffic.

If you choose seQura, its payment module is loaded from seQura's servers. You can delete or block cookies in your browser settings; if you block the technical ones, the basket or login may not work.

10. Children

The shop is not aimed at children under 14 and we do not knowingly collect their data.

11. Security

We apply appropriate technical and organisational measures to protect your data. All communication with the site is encrypted (HTTPS).

12. Changes to this policy

We may update this policy to reflect changes in the law or in our services. The date of the last update is shown at the top of the page.