Free EU & UK delivery over €35 · Handmade to order in Spain 🇪🇸

Privacy Policy

This policy explains what personal data HeheCorner collects when you visit our shop or place an order, why we collect it, who else touches it and how long we keep it. We are a two-person studio, not an advertising business — we collect what an order needs, and not much more.

Last updated:

1. Who is responsible for your data

The data controller is HeheCorner, trading as HeheCorner, tax number (NIF/CIF) available on request from support@hehecorner.com, registered address Spain — full postal address on request from support@hehecorner.com.

For anything about your data, email support@hehecorner.com. Put "Privacy" in the subject line and we will treat it as a formal request.

We are established in Spain, so our lead supervisory authority is the Spanish data protection authority, the Agencia Española de Protección de Datos (AEPD). We are not required to appoint a Data Protection Officer, and we have not appointed one.

This policy applies to hehecorner.com and to the emails we send about orders. It does not apply to other websites we link to, including social media platforms, which have their own policies.

2. What this policy covers, and the law behind it

We process personal data under the EU General Data Protection Regulation (GDPR) and Spanish data protection law (LOPDGDD). For customers in the United Kingdom, we also apply the UK GDPR and the Data Protection Act 2018.

Every use of your data below is tied to a lawful basis. In plain terms there are three we rely on: we need it to perform your contract, we have a legitimate interest in running the shop properly, or you have given consent — and where it is consent, you can withdraw it at any time.

We do not sell personal data. We do not use automated decision-making or profiling that produces legal effects for you.

3. What we collect and why

When you place an order (lawful basis: performance of a contract, Art. 6(1)(b)):

  • Your name, email address, delivery address and, where a carrier requires it, a phone number.
  • The items ordered, the colour chosen and the personalisation text you typed.
  • The order number, order date, amounts, currency and delivery method.
  • Confirmation from our payment provider that the payment succeeded, plus a payment reference and the card type and last digits. We never receive your full card number.

When you create an account (contract, plus our legitimate interest in keeping your details safe): your email address, a securely hashed password, and your saved addresses and order history.

When you email us (legitimate interest, Art. 6(1)(f) — answering customers and keeping a record of what was agreed): your email address, your message, and any photographs you attach.

When you subscribe to our newsletter (consent, Art. 6(1)(a)): your email address, and the date and time you subscribed. That is the whole record — we do not log the IP address you subscribed from, and there is no confirmation step beyond the sign-up itself.

When you browse the site (essential cookies: contract and legitimate interest; everything else: consent): your basket contents, your language preference, your consent choices, and — only if you agree — analytics and advertising identifiers as described in our Cookie Policy.

Automatically, on our server (legitimate interest in security and fraud prevention): IP address, browser type and the pages requested, in short-lived technical logs.

We also keep records of orders, invoices and tax data because the law requires us to (legal obligation, Art. 6(1)(c)).

There is no customer-review feature on this site, so we hold no review data at all.

4. Your personalisation text

When you type a name, an age or a date into the personalisation box, that text becomes part of your order. We treat it as order data, because we cannot make the product without it.

It is often personal data about someone else — a child, a partner, a friend. We only use it to make and check your topper, to answer questions about your order, and to keep the legally required record of what we sold.

We never use personalisation text for marketing, we never build profiles from it, and we never publish it. If we use a photograph of a finished topper on our website or social media, we either use a sample we made ourselves or we ask you first.

The lawful basis is performance of your contract. If you would like the text removed from our systems earlier than our standard retention period, email us — we can usually redact it once the legal record-keeping obligation no longer requires the full detail.

5. Payments

Card payments, Apple Pay and Google Pay are processed by SumUp, a licensed payment provider. You are taken to their secure payment page or field to enter your details.

Your card number, expiry date and security code go to SumUp, not to us. We never see them and we cannot store them.

SumUp acts as an independent controller for the payment itself, because financial and anti-money-laundering law obliges it to keep its own records. Its own privacy notice governs what it does with that data.

What comes back to us is a payment reference, the amount, the currency, the result, and the card type and last four digits, so that we can match the payment and process refunds. The lawful basis is performance of your contract, and compliance with our accounting obligations.

6. Emails we send you

Transactional emails — order confirmation, dispatch confirmation with your tracking link, refund confirmation, and replies to your questions — are sent because they are part of your contract. You cannot unsubscribe from these, because they are the order. Your order confirmation is also your copy of the contract, so it is worth keeping.

Marketing emails are only sent if you asked for them. The newsletter is occasional, and it is about new designs and seasonal ideas — it does not carry a signup discount code, and we do not pretend otherwise to collect addresses.

You can unsubscribe from every marketing email with the link at the bottom, or by emailing us, and we act on it immediately.

All of our email is sent through Mailgun, using its EU region, so message content and recipient addresses are stored on servers in Europe.

Our email system records whether a message was delivered and whether it bounced, so that we can tell when an order confirmation has not reached someone. That is a legitimate interest in making sure the contract actually works.

7. Analytics and advertising

We use Google Analytics 4 to understand which pages and products people actually find useful. The Google tag is not loaded at all until you have accepted analytics cookies. Before that moment no script from Google runs on the page, no cookie is written, and nothing whatsoever is sent to Google — not an event, not a page view, not an anonymous or cookieless signal of any kind.

Once you have accepted analytics cookies and the tag loads, IP anonymisation is switched on, so your IP address is truncated before it is stored, and we have set Google's user-level data retention to 14 months.

The same is true of the TikTok and Pinterest advertising tags. They are not loaded until you have accepted marketing cookies. Until then, those companies receive nothing at all from your visit. Once loaded, they let us see whether an advert led to a sale, and let those platforms show our adverts to relevant audiences.

The lawful basis for all analytics and advertising is your consent. Nothing in this section runs if you choose "Essential only", and you can change your mind at any time using the "Cookie settings" link in the footer. If you withdraw consent, we stop loading the tag again from that moment on.

The full list of cookies, with names and durations, is in our Cookie Policy.

8. Who we share your data with

We share data only with the suppliers we need in order to run the shop. Each is bound by a data processing agreement, and none of them may use your data for their own purposes unless noted below.

  • Our hosting provider: the shop runs on Medusa, self-hosted on a server located in Europe.
  • Our database provider: a managed PostgreSQL service located in Europe, which stores orders, accounts and personalisation text.
  • Mailgun (EU region): sends all of our transactional and newsletter email, from servers in Europe.
  • SumUp: processes payments, and is an independent controller for the payment itself.
  • Carriers: receive your name, delivery address and, where required, a phone number or email address, so that they can deliver the parcel and send tracking updates. They are independent controllers for the delivery.
  • Google (Google Analytics 4): only after consent to analytics cookies. Before that consent, the tag is not loaded and Google receives nothing.
  • TikTok and Pinterest: only after consent to marketing cookies. Before that consent, neither tag is loaded and neither company receives anything.
  • Professional advisers, such as our accountant, and public authorities where the law requires disclosure.

We do not sell, rent or trade your data. If the business were ever sold or restructured, your data could pass to the buyer, who would be bound by this policy; we would tell you before that happened.

9. Where your data is stored, and international transfers

Our hosting, our database and our transactional email are all located in Europe, so the core of your order data stays in Europe. We describe it that way deliberately: we can tell you the region with confidence, and we would rather do that than name a legal bloc we have not verified for every box.

Some suppliers may transfer data outside the EEA. Where that happens, we rely on the safeguards the GDPR requires: an adequacy decision by the European Commission, or the European Commission's Standard Contractual Clauses (SCCs) combined with the supplier's own technical measures.

In particular: Google, TikTok and Pinterest may transfer data to the United States and other countries, under Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. These transfers only ever happen after you have consented to the relevant cookies, because before that their tags are not loaded and no data leaves your browser for them.

For customers in the United Kingdom, transfers to and from the UK rely on the UK adequacy regulations or on the UK International Data Transfer Addendum to the SCCs.

You can ask us for more detail about a specific transfer by emailing support@hehecorner.com.

10. How long we keep things

We keep data only as long as we need it, and then delete it. Concretely:

  • Order records, invoices and accounting data: 6 years from the end of the financial year in which the order was placed, because Spanish commercial and tax law requires it.
  • Personalisation text: kept with the order record for the same period. On request we will redact the text from our working systems earlier, keeping only what the legal record requires.
  • Customer accounts: until you close the account. If you ask us to close it, we delete the account within 30 days, keeping only the order records above. If an account goes unused for 3 years, we close and delete it ourselves.
  • Baskets that are never checked out: deleted after 90 days.
  • Customer service emails: 24 months from the last message in the thread, so that we can see the history if you write again.
  • Newsletter subscription: until you unsubscribe. We then keep a minimal record of the subscription and the unsubscribe for 3 years, to prove we stopped when you asked.
  • Consent records (the hc_consent cookie and its server-side record): 180 days, after which we ask you again.
  • Technical server logs: 30 days.
  • Google Analytics user-level data: 14 months, set within Google Analytics.

Anything held beyond these periods because of a live legal claim is kept only until that claim is resolved.

11. Your rights

Under the GDPR and UK GDPR you have the following rights, free of charge:

  • Access — ask us for a copy of the personal data we hold about you.
  • Rectification — have inaccurate data corrected. (Note: this does not oblige us to re-print a topper with a different spelling free of charge — see our Terms — but we will always correct our records.)
  • Erasure — ask us to delete your data, where we do not have a legal reason to keep it.
  • Restriction — ask us to pause our use of your data while a dispute about it is resolved.
  • Portability — receive the data you gave us in a common machine-readable format, or have it sent to another provider.
  • Objection — object to processing based on our legitimate interests, including direct marketing. If you object to direct marketing, we stop, always and immediately.
  • Withdraw consent — for cookies, newsletters or anything else based on consent, at any time. Withdrawing consent does not undo what was lawfully done before you withdrew it.

To exercise any of these, email support@hehecorner.com from the address linked to your order, or tell us your order number so that we can identify you. We reply within one month; if a request is unusually complex we may extend that by two further months and will tell you why.

We will not charge you or treat you worse for exercising a right. We may ask for proof of identity if we genuinely cannot tell who you are.

12. Complaining to a supervisory authority

If you think we have handled your data badly, please tell us first — we would much rather fix it than have you go elsewhere frustrated.

You also have the right to complain to a data protection authority. In Spain that is the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, www.aepd.es.

In the United Kingdom, it is the Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow SK9 5AF, www.ico.org.uk.

If you live elsewhere in the EU, you may complain to the authority in your own country or in the country where the problem occurred.

13. Children's data

Our shop is aimed at adults. We do not knowingly collect personal data from children, and we do not market to them.

Cake toppers are often bought for children, so a child's first name and age may appear in your personalisation text. That data comes from you, the adult placing the order, and we use it only to make and record the product. We never use it for marketing or profiling.

If you believe a child has given us personal data directly — for example by subscribing to the newsletter — email support@hehecorner.com and we will delete it.

Our toppers are decorations, not children's toys, and they should be kept away from young children when not on the cake.

14. Keeping data secure

The site runs over HTTPS. Passwords are stored hashed, never in plain text. Access to the shop's admin and database is limited to the two of us, protected by strong, unique credentials.

Our hosting and database providers keep data encrypted at rest and take backups. Card data never reaches our systems at all.

No system is perfect. If a data breach ever occurred that was likely to risk your rights and freedoms, we would notify the AEPD within 72 hours and tell affected customers directly, in plain language, without waiting to be asked.

15. Changes to this policy

We update this policy when what we do changes — a new supplier, a new tool, a change in the law.

The date of the last update is shown at the top of the page. Material changes will be flagged on the site, and if a change affects processing based on your consent we will ask for consent again.

The current version always governs. Earlier versions are available on request by emailing support@hehecorner.com.