Privacy Policy
This Privacy Policy explains how BeeMotors S.L. ("BeeMotors", "we", "us") collects and processes personal data when you visit www.beemotors.com, place an order, contact us, or use our customer account features. We comply with the EU General Data Protection Regulation (GDPR) and applicable Spanish data-protection law.
On this page
1. Data controller
The data controller responsible for your personal data is BeeMotors S.L., registered office Calle Example 123, 08001 Barcelona, Spain, VAT ESB12345678. You can reach us at privacy@beemotors.com.
2. Data we collect
We only collect what we need to operate the shop and serve you well.
| Category | Examples |
|---|---|
| Account data | Email, password (hashed), name, preferred language. |
| Order data | Billing & shipping address, phone number, products ordered, order status, invoices, returns history. |
| Payment data | Card details are processed directly by Stripe in our embedded payment form. We never see or store full card numbers — only the last 4 digits and a token for refunds. |
| Cart & session | An anonymous cart ID stored in the cookie bm_cart_sid so your basket survives between visits. Authentication tokens from Supabase if you log in. |
| Communications | Messages you send through the contact form, the AI chat assistant, or by email; transactional emails we send via Resend. |
| Technical data | IP address, browser type, device, pages visited, referrer — collected by our hosting provider (Vercel) for security and performance. |
3. Why we use your data
- To create and manage your customer account.
- To process orders, payments, shipping and returns.
- To send transactional emails (order confirmations, shipping updates, refunds).
- To respond to your messages and provide customer support.
- To detect and prevent fraud, abuse or security incidents.
- To comply with our legal and tax obligations.
- To improve the storefront and our product catalogue.
4. Legal basis (GDPR Art. 6)
- Contract — to fulfil orders and provide your account.
- Legal obligation — invoicing, accounting, tax records.
- Legitimate interest — fraud prevention, securing the site, improving our services.
- Consent — for non-essential cookies and any future marketing communications. You can withdraw consent at any time.
5. Who we share data with
We do not sell your personal data. We share it only with carefully selected processors that help us run the business:
- Stripe — payment processing (Ireland / USA).
- Supabase — database and authentication (EU region).
- Vercel — hosting and CDN.
- Resend — transactional email delivery.
- Shipping carriers — DHL, UPS, GLS or local couriers, to deliver your order.
- BeeMotors internal platform (Beeplatform) — our staff access order, customer and inventory data through an internal CRM to fulfil orders and provide support. Access is role-based and audited.
- Authorities — when required by law (tax authorities, courts, police).
6. International transfers
Some processors (e.g. Stripe, Vercel) may store data in or transfer it to the United States. Where this happens, transfers are protected by the EU Standard Contractual Clauses and additional safeguards.
7. How long we keep data
- Account data — for as long as your account is active, plus 3 years.
- Order & invoice data — 6 years (Spanish commercial & tax law).
- Anonymous cart cookies — 30 days, or until you clear them.
- Support correspondence — up to 3 years from the last contact.
- Server logs — typically 30 days.
8. Your rights
Under GDPR you may at any time request to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase your data ("right to be forgotten"), subject to legal limits.
- Restrict or object to certain processing.
- Receive your data in a portable format.
- Withdraw any consent you have given.
- Lodge a complaint with the Spanish Data Protection Agency (AEPD).
You can manage most of this directly from your account area or by emailing privacy@beemotors.com.
9. Security
We use HTTPS everywhere, hashed passwords, role-based access, encrypted backups and regular dependency updates. Payment data is handled by PCI-DSS certified providers and never touches our own servers.
10. Children
Our storefront is intended for B2B and adult B2C buyers. We do not knowingly collect data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
11. Changes to this policy
We may update this policy from time to time. The "last updated" date at the top reflects the latest version. Material changes will be highlighted on the storefront.
12. Contact
Privacy enquiries: privacy@beemotors.com
General support: support@beemotors.com · contact form