TradesSpain

Privacy Policy

Last updated: December 2025

1. Introduction

TradesSpain ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website tradesspain.com.

2. Information We Collect

Personal Information

  • Name and username
  • Email address
  • Phone number (for business accounts)
  • Business address and details (for business accounts)
  • Payment information (processed securely by Stripe)

Automatically Collected Information

  • Browser type and version
  • Pages visited and time spent
  • IP address (anonymized)
  • Device information

3. How We Use Your Information

  • To provide and maintain our services
  • To process transactions and send related information
  • To send promotional communications (with your consent)
  • To respond to inquiries and provide customer support
  • To monitor and analyze usage patterns
  • To detect, prevent, and address technical issues

4. Data Sharing

We may share your information with:

  • Service Providers: Payment processors (Stripe), email services, and hosting providers
  • Business Partners: When you contact a business through our platform, your contact details are shared with that business
  • Legal Requirements: When required by law or to protect our rights

We do not sell your personal information to third parties.

5. Data Security

We implement appropriate technical and organizational measures to protect your personal information, including encryption, secure servers, and regular security assessments. However, no method of transmission over the Internet is 100% secure.

6. Your Rights (GDPR)

Under the General Data Protection Regulation (GDPR), you have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Request correction of inaccurate data
  • Erasure: Request deletion of your data ("right to be forgotten")
  • Portability: Receive your data in a portable format
  • Object: Object to certain processing of your data
  • Withdraw Consent: Withdraw consent at any time

You can exercise these rights in two ways:

  • Self-service (recommended): Sign in and go to Account Security → click Download my data for export, or Erase my account to anonymise your PII.
  • By email: Contact us at support@tradesspain.com

When you erase your account, your personal data (name, contact details, identification documents, vehicle registrations, visitor logs) is permanently removed. Financial, meeting and ticket records are retained in fully anonymised form for the period required by Spanish accounting law (5 years) and Spanish horizontal property law (until the resolution is acted upon), with no link back to your identity.

6a. ResortOS — Community Operations Data

If you use TradesSpain's ResortOS module as a resident, owner, tenant, committee member, president, contractor or security staff member of a residential community, this section applies in addition to the rest of this policy.

What we collect

  • Identity verification documents you upload (passport, NIE, DNI, proof of address, proof of ownership, tenancy agreement) — stored encrypted in restricted-access storage; visible only to your community administrator and TradesSpain's super administrators.
  • Property linkage (which unit you own or rent), quota share, and meeting votes (with optional secret-ballot mode that decouples your identity).
  • Visitor pre-authorisations and vehicle registrations you create.
  • Maintenance issues you report (including any photos / GPS coordinates you choose to attach).
  • Phone number, if you verify it via SMS code (optional).
  • Web push notification endpoints, if you opt in (per device).
  • Two-factor authentication secret and recovery code hashes, if you enable 2FA.

Legal basis

Performance of a contract (residency / ownership relationship with your community), legal obligation (Spanish horizontal property law — Ley 49/1960 — and accounting law), and your explicit consent for optional features (push notifications, SMS verification, secret ballot opt-out).

Who acts as controller

Your community of owners (Comunidad de Propietarios) is the data controller for community-operations data. TradesSpain Labs S.L. acts as data processor on the community's behalf, under a Data Processing Agreement signed by both parties when the community subscribes to ResortOS. You can request a copy of the DPA at any time.

Sharing within the community

Other residents only see your name on tickets, notices, votes (unless secret), meeting attendance, and marketplace posts. They never see your identity documents, financial balance, phone number, or address unless you explicitly include them in a post. Contractors assigned to your ticket see your name and the ticket's content; they do not see your contact details unless you provide them.

Retention

  • Identity documents: until your resident record ends, or you erase your account — whichever is sooner. Deleted from disk on erasure.
  • Meeting votes & actas (minutes): 5 years (Spanish accounting law) — votes anonymised on erasure.
  • Financial ledger entries (cuotas, payments): 5 years (Spanish accounting law) — anonymised on erasure.
  • Tickets: 2 years from closure for the community's records — anonymised on erasure.
  • Push subscriptions: until you disable on that device.
  • Audit log: 7 years (security & dispute resolution).

Security measures

  • TLS 1.2+ encryption in transit.
  • Identity documents stored outside the public document tree, served only to authorised admin/super-admin sessions.
  • Two-factor authentication available for all users and recommended for community administrators.
  • Per-community data isolation enforced at every API endpoint (RBAC + scope check).
  • Tamper-evident audit log on every state-changing administrative action.
  • Daily off-site backups; documented disaster recovery procedure.

Sub-processors

  • Stripe (payments — EU/US)
  • Twilio (SMS, WhatsApp, phone verification — EU/US)
  • Cloudinary (image storage — EU/US)
  • Resend / Mailtrap (transactional email — EU/US)
  • Sentry (error monitoring — EU)
  • OpenAI / Anthropic / Google (AI features — US, EU-customer data not used for model training)

All transfers outside the EEA rely on the EU Standard Contractual Clauses or an EU-recognised adequacy decision.

7. Cookies

We use cookies and similar technologies to enhance your experience. These include:

  • Essential Cookies: Required for the website to function
  • Analytics Cookies: Help us understand how visitors use the site
  • Preference Cookies: Remember your settings and preferences

You can control cookies through your browser settings.

8. Data Retention

We retain your personal information for as long as your account is active or as needed to provide services. We may retain certain information for legal or business purposes.

9. Children's Privacy

Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children.

10. International Transfers

Your information may be transferred to and processed in countries other than Spain. We ensure appropriate safeguards are in place for such transfers.

11. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of significant changes by posting the new policy on this page.

12. Contact Us

For questions or concerns about this Privacy Policy, please contact us at:

TradesSpain

Email: support@tradesspain.com

Website: tradesspain.com