Legal
Privacy Policy
Last updated: 21 March 2026
This Privacy Policy applies to kakao.guru, operated by kakao.guru (Spain). If you have questions, contact us at
hello@kakao.guru.
1. Who We Are
kakao.guru is an e-commerce and knowledge platform specialising in ethically sourced, fermented ceremonial cacao from Vietnam. Our website is located at https://kakao.guru and we are based in Spain. References to "we", "us", or "kakao.guru" in this policy refer to the operator of this website.
2. What Data We Collect
We collect the following categories of personal data:
- Contact data: Name, email address, and message content when you submit our contact form.
- Order data: Name, shipping address, email address, and payment information when you place an order. Payment data is processed directly by our payment provider and is not stored by us.
- Usage data: IP address, browser type, pages visited, time spent on pages, and referral source — collected automatically via Google Analytics 4 when you visit our website.
- Cookie data: See Section 6 (Cookies) below.
We do not collect sensitive personal data (health data, racial or ethnic origin, political opinions, etc.) and we do not knowingly collect data from children under 16.
3. How We Use Your Data
We use your personal data for the following purposes:
- Fulfilling orders: Processing and shipping your purchases, sending order confirmations and shipping updates. Legal basis: contract performance (Art. 6(1)(b) GDPR).
- Responding to enquiries: Replying to messages submitted via our contact form. Legal basis: legitimate interests (Art. 6(1)(f) GDPR).
- Website analytics: Understanding how visitors use our website to improve content and user experience via Google Analytics 4. Legal basis: consent (Art. 6(1)(a) GDPR) where required by law, or legitimate interests where not.
- Legal compliance: Retaining transaction records as required by applicable tax and commercial law. Legal basis: legal obligation (Art. 6(1)(c) GDPR).
4. Data Sharing & Third Parties
We share your data with the following categories of third parties, solely to the extent necessary for the purposes described above:
- Payment processors: Your payment data is processed by our payment provider (Stripe or equivalent). We do not store full card details. Their privacy policy governs payment data handling.
- Shipping providers: Your name and delivery address are shared with our courier partners to fulfil shipments.
- Google Analytics: Usage and cookie data is transmitted to Google LLC in the United States under Standard Contractual Clauses. Google Analytics is configured with IP anonymisation enabled.
- Hosting: Our website is hosted on Cloudflare Pages. Cloudflare processes server logs in accordance with their privacy policy.
We do not sell, rent, or trade your personal data to third parties for marketing purposes.
5. Data Retention
We retain personal data for as long as necessary for the purposes described above:
- Order data: 7 years from the transaction date, as required by Spanish and EU tax law.
- Contact form enquiries: Up to 2 years from the date of the enquiry, or until the matter is resolved.
- Analytics data: 14 months (Google Analytics default retention period, configured at account level).
6. Cookies
Our website uses the following categories of cookies:
- Strictly necessary cookies: Required for the website to function (e.g. Cloudflare security cookies). No consent required.
- Analytics cookies: Google Analytics 4 cookies (_ga, _ga_XXXXXXX) that collect anonymised usage data. These are only set after you consent via our cookie banner.
You can withdraw consent for analytics cookies at any time by clicking "Manage Cookies" in the footer of any page, or by clearing your browser cookies. You can also opt out of Google Analytics tracking globally via Google's opt-out tool.
7. Your Rights
Under GDPR, you have the following rights regarding your personal data:
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Request correction of inaccurate or incomplete data.
- Right to erasure: Request deletion of your personal data where no legal retention obligation applies.
- Right to restrict processing: Request that we limit how we use your data.
- Right to data portability: Receive your data in a structured, machine-readable format.
- Right to object: Object to processing based on legitimate interests.
- Right to withdraw consent: Withdraw any consent previously given (e.g. for analytics cookies).
To exercise any of these rights, contact us at hello@kakao.guru. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority (in Spain: AEPD — Agencia Española de Protección de Datos).
8. International Data Transfers
Some of our service providers (Google Analytics, Cloudflare) process data in the United States. These transfers are made under Standard Contractual Clauses approved by the European Commission, providing equivalent protection to EU data protection standards.
9. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. Our website is served over HTTPS (TLS encryption). However, no internet transmission is completely secure, and we cannot guarantee absolute security.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The date at the top of this page indicates when it was last revised. Continued use of our website after changes constitutes acceptance of the updated policy.
11. Contact
For any privacy-related questions or to exercise your data rights, contact us at:
kakao.guru
Email: hello@kakao.guru
Website: kakao.guru/contact/