Privacy policy
Last updated: 22 August 2026
What data of yours we handle, why, for how long, and what you can do about it. Written to comply with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
1. Who is responsible
- Controller: COMPANY NAME, S.L., NIF NIF
- Address: FULL ADDRESS, 30840 Alhama de Murcia, Murcia
- Data protection contact: privacidad@holaparcel.es
- Data Protection Officer: NOT APPOINTED / CONTACT DETAILS
2. What we collect
- Identity and contact: name, email address, mobile number.
- Property: your resort or community and your property reference, so we can tell two customers with the same name apart.
- Service data: your Hola ID, parcels received in your name, courier, arrival and collection times, pickup codes, and the alerts we sent.
- Financial: your plan, charges, receipts and invoices. Full card details are handled directly by our payment provider; we do not store them.
- Tax details, only if you ask for a full invoice: NIF/NIE and billing address.
- Technical: IP address and the browsing data needed to run the site securely.
3. Why we use it, and our legal basis
- To provide the service: open your account, issue your Hola ID, log the parcels your collection point receives and hands over, and alert you. Basis: performance of the contract (art. 6.1.b GDPR).
- To charge and invoice: payments, storage fees and invoices. Basis: performance of the contract and legal obligation (art. 6.1.b and 6.1.c).
- To meet tax and accounting obligations, including keeping invoices. Basis: legal obligation (art. 6.1.c).
- To answer you and, if something goes wrong with a parcel, give you the records you need to claim from the courier, seller or collection point responsible. Basis: performance of the contract.
- Security and fraud prevention, including wrongful collection. Basis: legitimate interests (art. 6.1.f).
- To email you about the service if you opted in when registering. Basis: consent (art. 6.1.a). You can withdraw it at any time without affecting the service.
4. Who else sees your data
Only those who need to for the service to work. We have a data processing agreement (art. 28 GDPR) with each of them:
- The shop acting as your collection point: sees your name, your Hola ID and the parcels it is holding for you. It does not see your email, phone number or payment details.
- Payment provider (Stripe): to take payment and store your payment method securely.
- SMS provider (Twilio) and email provider (Resend): to send your alerts.
- Hosting and database providers, so the service stays available.
- Public authorities, where the law requires it: for example the Spanish tax agency in relation to invoicing.
5. Transfers outside the EEA
Some of our providers are US-headquartered. Where that involves an international transfer, it relies on the European Commission's Standard Contractual Clauses or on the EU-US Data Privacy Framework, depending on the provider. You can ask us for a copy of the safeguards in place.
6. How long we keep it
Important: if you ask us to delete your data, we will delete what we can, but not invoices and their associated billing records, because the law requires us to keep them (art. 17.3(b) GDPR). They are blocked and used only to respond to the authorities or the courts.
- Account data: while your account is active, and afterwards for as long as needed to handle any claim.
- Parcel history: 3 years from collection, as a record in case of a dispute.
- Invoices and billing records: 6 years, under the Spanish Commercial Code, plus applicable tax periods.
- Marketing data: until you withdraw consent.
7. Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction and portability by writing to privacidad@holaparcel.es, saying which right you are exercising and proving your identity. We reply within one month.
If you think we have handled your request badly, you can complain to the Spanish Data Protection Agency (www.aepd.es), C/ Jorge Juan 6, 28001 Madrid.
8. Security and children
We apply technical and organisational measures to protect your data, including encryption in transit and role-based access control. The service is not aimed at under-14s and we do not open accounts in a child's name.
9. Changes to this policy
If we change something significant we will tell you by email or in your account before it takes effect. The date at the top of this page shows the last update.