This page says, in plain words, which personal data Hoor collects when you visit or buy on this site, why, who receives it and what you can do about it.
Last updated: 4 October 2026
The data controller is the seller of this shop:
For any question about your data, or to use your rights, write to contact@hoor-hijab.com.
| Data | Why we use it | Kept for |
|---|---|---|
| Your order Name, delivery and billing address, email, phone number, the items you bought and what you paid. |
To deliver your order, send you its confirmation and tracking, and handle returns and guarantee claims. Legal basis: the contract of sale (GDPR art. 6(1)(b)), and for invoices a legal obligation (art. 6(1)(c)). | 6 years from the order: Spanish law (Commercial Code, art. 30) obliges a business to keep its records that long. After that we delete or anonymise the order. |
| Your payment The payment reference, amount and status. Your card number is typed into a form that belongs to our payment provider: we never see or store it. |
To receive payment and to prevent fraud. Legal basis: the contract of sale, and our legitimate interest in not being defrauded (art. 6(1)(f)). | As long as the order. |
| Your account (optional) Email, name, saved addresses and your password, which is stored hashed so that nobody can read it. |
So that you can follow your orders and check out faster. Legal basis: the contract for the account you asked for (art. 6(1)(b)). | Until you ask us to delete the account. |
| Newsletter (optional) Your email address, the date you subscribed and the form you used. |
To send you news and offers. Legal basis: your consent (art. 6(1)(a)), which you can withdraw at any time. | Until you unsubscribe. |
| Messages you send us Your email address and what you write. |
To answer you. Legal basis: the contract when it is about an order, otherwise our legitimate interest in answering customers (art. 6(1)(f)). | 2 years after our last reply. |
| Technical data Your IP address, browser type and the pages requested, in the security logs of our hosting provider. |
To keep the site running and secure. Legal basis: legitimate interest (art. 6(1)(f)). | Kept by the hosting provider for its own short security period. We do not copy these logs or link them to your orders. |
| How you reached us The site or campaign you came from, your type of device and the first page you saw. |
To know which channels bring customers. Legal basis: legitimate interest (art. 6(1)(f)). You can object by writing to us, or block the cookies listed below. | As long as the order it is saved with. Nothing is kept if you do not order. |
At checkout, the fields marked as required are the ones we need to deliver your order; without them we cannot sell to you. Everything else is optional.
We do not sell your data, we do not buy data about you and we do not build a profile of you. We make no automated decisions about you. Our payment provider does run automatic fraud checks and can decline a payment; if that happens to you, write to us and a person will look into it.
We count how often the products suggested under "Complete Your Look" are clicked. These are totals per product and are not linked to you.
We share data only with the companies that help us run the shop, and only what each one needs:
| Who | Where | What they receive and why |
|---|---|---|
| Hostinger | European Union (servers in France) | Hosts this website and our email. Everything stored on the site (orders, accounts, newsletter list) sits on its servers. |
| Hostinger Reach | European Union | Sends our newsletter: your email address, if you subscribed. |
| WooPayments (Automattic), Stripe | Ireland and United States | Take your payment: card details (typed straight into their form), name, email, billing address, amount and your IP address. |
| Sift, hCaptcha | United States | Fraud and bot checks during payment, for the payment provider: your IP address and details of your device and browser. |
| Apple Pay, Google Pay | Ireland and United States | Only if you choose to pay with them: they confirm the payment to our payment provider. |
| The carrier that delivers your order | Spain and the country of delivery | Name, delivery address, phone number and email, to deliver the parcel and send you tracking messages. |
| Google Fonts | Ireland and United States | Your browser downloads the fonts of this site from Google, which therefore sees your IP address. No cookie is set. |
| Frankfurter (frankfurter.dev) | Cloudflare network | Your browser asks this open-source service for today's exchange rates for the currency selector. It receives your IP address, which it says it does not log, and nothing about you or your order. |
| Tax office, courts and police | Spain | Only when the law obliges us, for example invoices in a tax inspection. |
Companies in the United States receive data under the safeguards the GDPR accepts: the EU–US Data Privacy Framework or the European Commission's standard contractual clauses (GDPR arts. 45 and 46).
A cookie is a small file that a website stores in your browser. These are the ones you get on this site:
| Cookie | Set by | What it does | Lasts | Needed to shop? |
|---|---|---|---|---|
wp_woocommerce_session_… |
Hoor | Keeps your cart as you move between pages. | Up to 7 days | Yes |
woocommerce_items_in_cart, woocommerce_cart_hash |
Hoor | Tell the site that your cart has items, so every page shows the right cart. | Until you close the browser | Yes |
hoor_lang |
Hoor | Remembers the language you chose. | 1 year | Yes |
wordpress_logged_in_…, wordpress_sec_… |
Hoor | Keep you signed in to your account. Only set when you log in. | Until you close the browser, or 14 days if you tick "Remember me" | Yes |
_lscache_vary |
Hoor | Lets our page cache show you your own language and cart instead of a stored copy. | 2 days | Yes |
__stripe_mid, __stripe_sid, m |
Stripe | Fraud prevention for card payments. Set on the cart and checkout pages only. | 30 minutes to 13 months | Yes |
__ssid |
Sift | Fraud screening of payments, run for our payment provider. Set on the cart and checkout pages only. | Up to 13 months | Yes |
__cf_bm (hcaptcha.com) |
hCaptcha | Checks that a payment is made by a person and not a bot. Checkout page only. | 30 minutes | Yes |
__cf_bm (hostinger.com) |
Hostinger | Bot protection for the script of our newsletter tool. | 30 minutes | No |
sbjs_… |
Hoor | Record how you reached the shop (the site or campaign you came from, your type of device and the first page you saw). If you order, this is saved with the order. | Until you close the browser | No |
We use no advertising cookies and no analytics service such as Google Analytics or a Meta pixel.
The site also keeps a few preferences in your browser's own storage: the currency you chose with the day's exchange rates, the grid or list view of the shop, and a copy of your cart so that pages load faster. They stay in your browser.
You can delete or block cookies in your browser settings. Without the ones marked "Yes", the cart, the checkout and your account stop working. The ones marked "No" can be blocked with no effect on your purchase.
The GDPR gives you these rights over your data:
To use any of them, write to contact@hoor-hijab.com from the email address of your order or account. It is free, and we answer within one month (GDPR art. 12). With an account you can also correct your details and switch marketing emails off yourself under My account.
If you think we have handled your data wrongly, you can complain to the Spanish Data Protection Agency (AEPD, www.aepd.es) or to the data protection authority of your country. We would be grateful for the chance to put it right first.
This shop is not aimed at children. We do not knowingly collect data from anyone under 14, the age from which Spanish law (LOPDGDD, art. 7) lets a person consent to the use of their data. If you believe a child has given us data, write to us and we will delete it.
The whole site is served over an encrypted connection (HTTPS). Passwords are stored hashed. Card details never reach our servers. Only the people who run the shop can see orders, and only to fulfil them.
If a security breach put your data at risk, we would tell you and the AEPD without delay, as the GDPR requires (arts. 33 and 34).
When we change how we use data, we update this page and its date. If the change affects data you have already given us, we tell you by email before it applies.